Hardware enclaves protect central bank data in use
BIS Paper

Hardware enclaves protect central bank data in use

Hardware-anchored trusted execution environments can secure cross-border collaboration and supervisory analytics for central banks without widening third-party trust, according to a research paper published by the Bank for International Settlements.

Shielding sensitive computations

Trusted execution environments protect sensitive “data in use” by enforcing code authenticity, runtime integrity and confidentiality inside a bounded computing base, according to research by Christof Fetzer, Co-Pierre Georg, Jack Ho, Bingle Kruger, Julius Wetzel and Jakub Demski.

The technology allows monetary authorities to process confidential datasets without exposing raw inputs to host platforms or cloud vendors.

The authors identify cross-border data collaboration, joint supervisory analytics and operational resilience as the most immediate operational use cases for central banks seeking deeper cross-institutional intelligence.

Engineering hurdles and governance

The publication emphasizes that hardware isolation is not a standalone solution.

Deploying hardware enclaves requires disciplined engineering, auditability and evidence-based governance to prevent expanding the circle of trusted entities.

The analysis evaluates operational trade-offs across performance, procurement hurdles and software portability while comparing enclaves to alternative cryptographic techniques.

Central banks must establish strict oversight standards before integrating enclaves into core infrastructure.

Promising tech, heavy governance

Hardware enclaves solve a genuine cryptographic hurdle for cross-border central bank data sharing.

Yet relying on proprietary silicon shifts operational risk directly toward hardware vendors and vendor lock-in.

Without vendor-neutral standards, adoption among cautious central banks will remain confined to pilot projects.

Source: Trusted execution environments for central banks

IN:

Report an error