← Latest papers
💻 computer science

Quantum-Resilient Banking Transaction Security using DW-HKEM: A Hybrid RSA/ML-KEM Cryptographic Gateway with Real-Time

This paper presents and validates a practical, low-overhead hybrid cryptographic gateway (DW-HKEM) that combines RSA-256 and ML-KEM-768 to secure banking transactions against both current and future quantum threats while maintaining backward compatibility and real-time performance monitoring.

Original authors: Siddhaarth S Prabhu, Aswani Kumar Cherukuri

Published 2026-07-21
📖 6 min read🧠 Deep dive

Original authors: Siddhaarth S Prabhu, Aswani Kumar Cherukuri

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a giant, bustling post office where everyone sends secret letters. For decades, the only way to keep these letters safe was to lock them in a specific type of metal box called "RSA." This lock is so complex that even the world's fastest supercomputers would take millions of years to pick it. But there's a catch: scientists have discovered a new kind of machine, a "quantum computer," that might one day be able to pick these locks in a blink of an eye. The scary part isn't just that these machines might arrive tomorrow; it's that bad guys are already stealing our locked letters today and hiding them in a vault, waiting for that future day when they can finally open them. This is called "Harvest Now, Decrypt Later."

To make matters trickier, the people who run the banks often treat their security systems like magic black boxes. They know the letters go in and come out, but they can't see inside to check if the locks are working correctly, if someone is trying to swap the lock for a weaker one, or if the system is getting tired. This paper steps into this high-stakes game of digital hide-and-seek to propose a new way to lock our letters that is safe from both today's thieves and tomorrow's quantum machines, while also giving the bank managers a pair of "X-ray glasses" to watch the locks in action.


The Paper's Big Idea: The Double-Lock System

The authors of this paper are worried about two things: the future threat of quantum computers and the current lack of visibility into how banking security actually works. To solve this, they built a new security gateway called DW-HKEM (which sounds like a robot's name, but stands for "Dual-Wrap Hybrid Key Encapsulation Mechanism").

Think of your bank transaction as a precious diamond you need to mail. In the old system, you'd put the diamond in a single, very strong metal box (the RSA lock). The paper argues this is risky because if a quantum computer shows up later, that single box can be smashed open, and the diamond is lost forever.

Instead, the authors propose a "Double-Lock" strategy. Imagine putting your diamond in a metal box, but then wrapping that entire box inside a second, invisible, super-tough force field made of a different material (called ML-KEM).

  1. The First Lock (RSA): This is the old, familiar metal box. It keeps things safe from today's hackers and works with all the existing banking systems.
  2. The Second Lock (ML-KEM): This is the new, quantum-resistant force field. It's based on a math puzzle that even quantum computers are expected to struggle with.
  3. The Secret Sauce: To open the package, you need both keys. The system mixes the secrets from both locks together to create a single, super-strong key for the actual transaction.

The paper explains that even if a bad guy steals the "Harvest Now" data and waits for a quantum computer to break the first metal box, they still can't get the diamond because the second force field remains unbreakable. Conversely, if the new force field ever has a flaw, the old metal box is still there to protect the diamond. It's a "belt and suspenders" approach to security.

The "X-Ray Glasses" (Real-Time Monitoring)

The second half of the paper tackles the "black box" problem. The authors built a dashboard called CryptoX. Imagine a control panel for the bank's security that doesn't just say "All Good," but shows a live video feed of every single lock being clicked, how long it takes to click, and if any lock is clicking slower than usual.

If a hacker tries to slow down the system or swap a strong lock for a weak one, the dashboard would instantly show a spike in time or a weird pattern. This allows the bank's security team to spot trouble immediately, rather than waiting for a breach to happen.

What They Found (The Numbers)

The authors tested their new system by running it through 100 different trials, simulating real banking transactions. Here is what they measured:

  • Speed: The new double-lock system is incredibly fast. While generating the old RSA key took about 103.96 ms (milliseconds), the new quantum-safe part only took 0.63 ms.
  • The Cost: Adding the second lock to the system only added about 1.58 ms of total time to a transaction. The authors note that this is so fast that a human user would never notice it; it's like adding a fraction of a second to a video game loading screen.
  • Size: The trade-off is that the "envelope" gets a bit bigger. The new system's data packet is about 1,392 bytes, compared to the old 256 bytes. However, the authors argue that on modern internet connections, this extra size is so tiny that it doesn't slow down the transfer.

What They Don't Claim

It is important to note what this paper does not say. The authors do not claim that quantum computers are here today; they are preparing for a future where they might be. They also do not claim that their system is perfect forever; they admit that if the new "force field" math (MLWE) is ever cracked, the system relies on the old RSA lock as a backup. They measured this on a standard computer to show it can work, but they acknowledge that real-world banking servers are even more complex.

The Takeaway

This paper suggests that banks don't have to choose between "staying safe today" and "being safe tomorrow." By using this hybrid double-lock system, they can protect their customers' money from future quantum attacks without slowing down the internet or breaking their current systems. Plus, by adding the CryptoX dashboard, they finally get to see inside the black box, ensuring that every lock clicks exactly the way it should. It's a practical, measured step toward a future where your digital secrets stay secret, no matter how powerful the computers of the future become.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →