This is an old revision of the document!
Are there additional ways to manage potential risks associated with CBDC that were not raised in this paper?
By all descriptions, the U.S. CBDC is primarily a large System-of-Systems (SoS) or even an SoS of SoSs. Some of these would ideally already exist and some will need to be created. The new systems are predominately a Software (SW) effort. Yes, there will be some specialized Hardware(HW) required, but the primary focus appears to be Software (including Commercial-Off-The-Shelf (COTS), Government Off-The-Shelf (GOTS), or Modified Off-The-Shelf (MOTS). This software will ultimately need to be Managed and Modified.
An important way to make sure the Security Planning is adequate is to design it into the U.S. CBDC from the onset, especially if the U.S. CBDC adopts the use of Distributed Technologies currently in wide use in cryptocurrencies. First, it is important to detail what needs to be secure and why. See Table 1.
For a more detailed discussion, see the OMG DIDO-RA section on Non-Functional requirements for Securability.
All too often, projects try to “bolt-on” security after products are built. When building as essential and critical to the U.S. as a new financial mechanism such as CBDC, it is essential to think about it at every stage of the development, starting at the specification of requirements and at each layer of securability. See Figure 1 and Table 2
Securability is also a layered stack. At each layer, there are different steps that need to be taken to secure the system. For example, Culture Security it may just mean having employees hold a security clearance and/or take Drug Tests. For Physical Security it may mean having a locked facility to house the computers and network devices. Data Security might be software and cultural procedures such as encrypting all data stored in a disk drive and using software to access the data.
Data can exist in many states depending on how it is being used. Each of the different Data States poses its own risks of compromising data. The primary concern with data is that it compromises End User Privacy. See section 45_privacy.
The risks and concerns about Data in each of the different states are also important. Often, the primary focus for understanding data is to concentrate on Data-at-Rest. Although this data is relatively static, it can change over time. In the past, there was little concern for Data-in-Motion , which can have serious effects on Reliability, Maintainability, and Availability (RAM), as well as, Securability and can leave a system vulnerable to breaches. With the advent of HTTPS, these vulnerabilities are mitigated. The latest issue has become the need to secure Data-In-Use. A recent WhatsApp data breach 2) found that switching data between image filters could cause memory corruption followed by a crash that left data exposed.
Figure 2 graphically represents the different Data States within a system. Most systems are now able to handle the Data-in-Motion and the Data-at-Rest issues but have traditionally relied on physical security to protect Data-in-Use.
Any risk assessment must include the Security Infrasture and the state of data:
Metadata is data about data. Although this data can provide specific insight into personal data such as Personal Identifiable Information (PII) (see Privacy Concerns), there is also a problem with hackers gaining access to Metadata.
For example, knowing your name, address, phone number, and credit card details can be used to make illegal purchases in your name. This is a Criminal Activity in itself, but gaining information about your behavior and habits is a different kind of privacy violation. This information can be used to target you for advertisements or more nefariously specific scams. For instance, the metadata can now be used to determine that an individual is visiting a well-known cancer clinic and target the person for “miracle cures”.
Another example might be the discovery that a well-known founder and CEO of a publicly-traded company has visited the same well-known cancer clinic. This information is then used to in essence glean insider information about the company and make stock trades.
The use of Metadata is the primary engine for companies such as Google, Facebook, Microsoft, Apple, etc. However, this is done using their own mechanism to collect the data and users sign their rights away with the Service Level Agreements (SLAs), etc they “sign” when they choose to use these products. It is another thing to use government-provided data.
Therefore, Metadata not only contains Data about Data, but it can also contain information about the association of data elements together. Sometimes this activity is referred to as Triangulation.
There is an assumption that Bitcoin transactions are anonymous, the reality is that they are anonymized. The following article by John Bohannon highlights the issue:4)
In this case, it was the “good guys” who used the Metadata, but this could also have been used for nefarious activities and a U.S. CBDC needs to protect this kind of data.
Some government business processes need to be kept confidential, secret, or even top-secret when it comes to trying to audit or discover illegal or criminal activities. The reason is that if the processes were made readily available to the public, then the business process can be “gamed” to avoid detection. In these situations, the government is involved in an “arms race” so to speak with those who want to avoid detection. The government business processes are continuously refined and honed to detect illegal or criminal activity, while the “bad guys” continuously test the system to find its weaknesses.
As an example, the process of trying to “reverse engineer” the “rules” of a government business process for determining if an individual return gets audited run rampant when it comes to triggering an audit by the Internal Revenue Service (IRS).5)
More and more government business processes are using Artificial Intelligence (AI) to aid in the flow of the business process. Many of these AI processes are data-driven either through parameters or by using learning datasets continuously refined based on previous runs through the process. This means that either the original parameters or the learning data sets are subject to hacking attempts.
If the government business processes are hacked, then the ability for illegal or criminal activities to go undetected is advanced.
Another problem would be if the government's business processes themselves were “hacked” to disable the government process or change the algorithms or parameters of the process to provide an unfair advantage. A simple example might be adding an exclusion for a certain individual within the process.