The Bank for International Settlements has published a paper assessing how trusted execution environments could let central banks process sensitive data without expanding access to plaintext information. The paper finds that these hardware backed environments can help protect data during processing and verify which code and configuration are running, but their effectiveness depends on disciplined engineering, governance and layered security controls. Potential applications include cross-border statistical analysis, systemic stress testing, fraud detection, anti-money laundering and countering the financing of terrorism checks, digital asset wallets and cyber resilience. The paper recommends binding access to remote attestation, restricting outputs through approved policies and retaining auditable evidence. It also calls for strong software supply chain controls, prompt revocation, independent logs, hardware security modules for critical root keys and safeguards against side channels, rollback, output inference and vendor concentration. The proposed adoption path starts with isolated machines or single-service confidential virtual machines before moving to more complex deployments. Procurement should support independent verification, portability, incident response and algorithm agility, while performance testing should cover the full process from attestation and key release through computation, output enforcement and recovery.
2026-09-25Bank for International Settlements
Bank for International Settlements paper assesses trusted execution environments for central banks
The Bank for International Settlements has published a paper assessing how trusted execution environments could help central banks process sensitive data without widening access to plaintext records. It identifies applications in collaborative analytics, compliance, digital asset wallets and cyber resilience, but stresses that benefits depend on attestation, strict output controls, auditable governance and layered safeguards. The paper recommends staged adoption and procurement measures addressing software supply chains, revocation, portability and vendor concentration.