industry · quantum risk
Is Open banking Quantum Proof? Industry Quantum Risk
Verdict
Open banking APIs are not quantum-proof while eIDAS-style and TLS certificates remain classical. TPP ecosystems multiply certificate inventory.
Overview
Open banking relies on strong client authentication and TLS. Those controls are classical PKI in most deployments today.
Inventory bank APIs, TPP certs, and token signing algorithms together.
Cryptographic profile
- Signatures: API mTLS and OAuth/OIDC tokens, QSealC/QWAC-class certificates where required, TPP and bank TLS
- Hash: Token and request signing as deployed
- Public-key exposure: High-assurance certificates and third-party provider integrations.
- Vertical: banking
What breaks
- Long-lived QWAC/QSealC classical certs
- OAuth tokens on classical-only signatures
- Untracked sandbox vs production crypto differences
Mitigations
- Certificate inventory for open-banking PKI
- Align with hybrid TLS and identity federation PQC plans
- Third-party TPP questionnaires
FAQ
Qualified certificates = quantum-safe?
Qualified status is a trust framework—not automatically post-quantum algorithms.
Related?
/is-quantum-proof/mtls and /is-quantum-proof/oidc-quantum
Key concepts (technical dictionary)
Terms used on this page — open a definition: