Hybrid post-quantum key exchange on a live UPI payment switch
Migrating a tier-1 payment path to ML-KEM without a maintenance window, and proving the classical fallback still holds.
The situation
The bank could name its certificate authorities but not its certificates. A first-pass inventory built from configuration management data accounted for roughly a third of what was actually in use; the rest lived in application keystores, appliance configurations and one memorable hard-coded constant in a settlement batch job written in 2011.
Regulatory language had shifted from encouragement to expectation, and the internal risk committee had asked a question nobody could answer: which of our long-lived confidential data flows would be readable if the traffic captured today were decrypted in 2032?
What constrained the design
The payment switch handles millions of transactions daily across critical banking rails. Any architectural intervention had to respect strict operational boundaries:
- —No maintenance window was available on the payment switch. Any change had to be reversible within one request cycle.
- —Hardware security modules in the settlement path had no post-quantum firmware track and would not for at least two more release cycles.
- —Several counterparties would remain classical-only for years, so a clean break was never an option.
- —Every cryptographic change had to produce an audit artefact the regulator could read without a briefing.
What we deployed
Discovery ran first: passive TLS observation across 1,900 hosts plus static scanning of build artefacts produced a cryptographic bill of materials with an owner, an expiry and an exposure score against every entry. Exposure was scored on data lifetime rather than asset criticality, which reordered the migration queue substantially — several low-tier systems moved to the front because the data they carried stayed sensitive for two decades.
The switch then ran hybrid X25519 with ML-KEM-768 in shadow mode for ninety-four days. Shadow traffic exercised the post-quantum path in full while the classical result remained authoritative, so a failure in the new path could not affect a settlement. Only after two full quarter-end peaks did the hybrid result become authoritative.
What it cost to run
Median handshake latency rose by 3.1 ms and the 99th percentile by 8.4 ms, comfortably inside the switch's existing budget. Certificate sizes grew enough to matter for the constrained ATM fleet, which was handled by keeping that segment classical for the present and scheduling it against the hardware refresh already funded for the following year.
Where it stands now
Crypto-agility drills run quarterly: the bank rotates an algorithm in a controlled segment and measures the blast radius. The point is not that ML-KEM is the answer. The point is that the next answer can be adopted without another eleven-month programme.
Publications behind this deployment
Client identities held under strict non-disclosure.
AdviQ · Sovereign assurance protocol
Every metric published across our engineering dossiers was generated by the client’s own operational instrumentation, reviewed jointly under bilateral NDA, and cleared for anonymised release. Technical architecture blueprints and direct peer reference calls with engineering leadership are available to verified counterparties under matching NDA terms.
Production performance figures captured directly from client cloud monitoring and verified against SLA targets.
Direct peer briefings with enterprise CTO, VP Engineering, or Security leadership arranged under bilateral non-disclosure.
Unredacted component topologies, schema definitions, and migration playbooks available for qualified in-house review.
Engagement Dossier Facts
Start with the Inventory, not the algorithm.
AdviQ · Post-Quantum Readiness Framework
- ◆Exhaustive Cryptographic Bill of Materials (CBOM)
- ◆Post-quantum vulnerability exposure ranking
- ◆Hardware-neutral algorithm assessment
- ◆Phased migration roadmap with operational safeguards
