2024-09-09-IMF-中央银行数字货币生态系统的网络弹性(英)_53页_1mb
报告摘要
Cyber Resilience of the Central Bank Digital Currency Ecosystem Summary
As analyzed by IMF researchers:
1. Report Background
- Central banks exploring digital currencies must consider cyber risk, which is highly interconnected: security ensures trust, without trust there is no currency.
2. Cyber Risk Overview
- Key risk principle: CIA Triad (Confidentiality, Integrity, Availability)
- Attacks originate from various threat actors (Nation-states, Organized Crime, Insiders, Hacktivists)
- Economic/operational risks from cyber incidents: reputational damage, financial loss, reduced trust - systemically impactful.
- Offline/outage scenarios require special solutions.
- Current challenges include insufficient testing for CBDC cyber resilience.
3. Core Design Options & Security Considerations
3.1. Distribution Model
- Single-tier (direct): Centralized control, private keys, but complex; handbooks recommend delegation to intermediaries.
- Two-tier (decentralized): Leverages private sector while central bank maintains core responsibility
3.2. Token vs Account-Based
- Token-based: Resembles physical cash, accessible purely digitally via cryptographic ledgers
- Account-based: Follows traditional banking models but uses digital authentication
⚠️ Problems:- Key management challenges
- Token validity concerns
- Especially with programmability and side chains
3.3. Ledger Types
- Centralized Ledger Tech (CLT): Proven, but single-point failure risks
- Distributed Ledger Tech (DLT): More distributed but complex implementation
⚠️ Problems: - Requires complex consensus mechanisms
- Vulnerable to 51% attacks in permissioned networks
- Regulatory gaps
3.4. Offline Functionality
- For connectivity-limited regions important, but technical challenges remain
- Solutions limited mainly due to counterfeiting/malware risks
- DLT-based approaches face 'torn transactions'
3.5. Third-Party Use (Cloud)
- Cloud services offer scalability & cost savings but introduce trust issues
⚠️ Problems:- Shared responsibility models unclear
- Less resilient nations may lack proper national alternatives
- Lessons mainly from developed-market AWS/Azure providers
4. Foundational Requirements & Cyber Resilience
4.1. High-Level Principles
- CBDC resilience must meet or exceed existing payment systems
- Security measures should be proportional to systemic risk
- Attack surface must be minimized
- Comprehensive resilience measures required
4.2. Foundational Technical Requirements
- Air-gapped core infrastructure with real-time replication
- Zero-Trust architecture for endpoints
- Quantum-resistant cryptographic algorithms (being developed)
- Payment system-grade availability (expediting via DLT might conflict with security)
4.3. Evolving Threat Landscape
- Adversarial focus increasing
- New threats like AI-enabled attacks
- Compounding factors include 5G networks, cross-border transactions
Why This Analysis is Important
It shows CBDC implementation is complex and security-by-design is crucial. While some technical solutions exist, comprehensive ecosystem requirements must account for both technological implementation and institutional capability.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载