Next-Generation Cryptographic Migration Framework for Real-Time Payment Processing Systems

Authors

  • Arjun Mehta Department of Computer Science, Indian Institute of Technology Bombay, Mumbai, India Author
  • Priya Shankar School of Information Security, National University of Singapore, Singapore Author
  • David O’Sullivan FinTech Research Lab, University College Dublin, Dublin, Ireland Author
  • Lena Fischer Chair for Applied Cryptography, Technical University of Munich, Germany Author

DOI:

https://doi.org/10.64235/y90t0y82

Keywords:

Next-generation cryptographic migration; real-time payment processing; post-quantum cryptography; ML-KEM; ML-DSA; NIST FIPS 203/204/205; TLS 1.3 hybrid KEM; ISO 8583; SWIFT MX; CBDC security; quantum-resilient infrastructure; cryptographic agility

Abstract

Contemporary real-time payment processing systems rely on classical asymmetric cryptographic primitives — RSA, Elliptic Curve Diffie-Hellman (ECDH), and ECDSA — that will become computationally vulnerable with the advent of cryptographically relevant quantum computers (CRQCs). This paper introduces NGCMF (Next-Generation Cryptographic Migration Framework), a comprehensive, seven-layer methodology engineered to guide payment processors, card networks, and financial institutions through a structured, auditable transition to NIST-standardised post-quantum cryptography (PQC). NGCMF spans the full cryptographic lifecycle: from automated cryptographic asset discovery and quantum risk classification, through hybrid classical/PQC architecture design and phased production rollout, to long-term cryptographic agility governance. The framework addresses the HARVEST NOW, DECRYPT LATER (HNDL) threat model — wherein adversaries archive encrypted transaction data today for future quantum decryption — as a primary migration driver, alongside conventional forward-secrecy and integrity requirements. We instantiate NGCMF across four real-world payment system archetypes: an ISO 8583 card network switch, an open-banking REST API hub, a CBDC settlement node, and a cross-border SWIFT MX messaging gateway. Performance evaluations demonstrate that ML-KEM-768 (FIPS 203) introduces TLS 1.3 handshake overhead of 1.4–2.3 ms, within real-time SLA tolerances, while ML-DSA (FIPS 204) requires HSM horizontal scaling for high-frequency signing workloads. Regulatory mapping confirms alignment with PCI DSS v4.0, ISO 27001:2022, EU DORA, and NIST SP 800-57 Part 1 Rev. 5. The NGCMF provides financial institutions with a practitioner-oriented, standards-grounded roadmap for achieving quantum-resilient payment infrastructure within a 12–18 month deployment horizon.

Downloads

Published

2026-06-01

How to Cite

Next-Generation Cryptographic Migration Framework for Real-Time Payment Processing Systems. (2026). Journal of Cyber-Physical Security and Robotics, 2(01), 40-47. https://doi.org/10.64235/y90t0y82

Similar Articles

1-10 of 25

You may also start an advanced similarity search for this article.