Counterintuitive cryptography
It’s not hard to understand why <a href="https://bitcomme.com/springfield-school-officials-discuss-next-steps-in-tackling-cybersecurity-incident/” title=”Springfield school officials discuss next steps in tackling cybersecurity incident”>cybersecurity has become a board-level priority. The UK National Cyber Security Centre’s 2025 review states that “the challenge we face is growing at an order of magnitude” and “the new normal is that cyber criminals will target organizations of all sizes, operating in any sector.”1 The risks are often higher for financial services firms.
One of the most damaging things hackers can do is steal sensitive data. The good news is that new techniques are emerging to help keep data more private—a class of security building blocks that the influential payments commentator David Birch calls “counterintuitive cryptography.” That is, proven cryptographic approaches that allow corporates to perform actions that seem impossible: ways of processing and getting value from sensitive data without actually exposing the data itself.
Making fraud prevention a business decision
From signup to refunds, every e-commerce touchpoint is a doorway you’ve sized—and fraudsters are testing every one. See how a trusted banking partner can help keep them on the outside.
Three in particular are likely to gain increasing prominence as they continue to mature, and each addresses a different business problem.
The first is homomorphic encryption (HE), which lets organizations process data without seeing it. Think of it as a locked spreadsheet that others can run formulas on without opening the file. This allows a third party—an auditor, say, or an analytics vendor—to perform calculations directly on encrypted data and return an encrypted result that only the data owner can decrypt. As a basic example, they could add an encrypted two to an encrypted two to produce an encrypted four without ever knowing what the values actually are. If an organization wants to let a partner run a risk or marketing model on its customer data, HE enables that without giving the partner access to the raw information. The processes involved are becoming computationally more efficient, and HE seems likely to become a standard part of the future business toolkit.
The second is zero-knowledge proofs. This is a means of allowing organizations to trust claims—“I am over 18” or “I have enough funds”—without seeing the confidential evidence behind that claim. Described as “the closest cryptography gets to magic,” it means that sending a driver’s license or sharing a bank balance is unnecessary, preserving privacy and reducing the corporate liability around holding that data.2 The method involves the user’s system generating a cryptographic proof that could only be produced if the claim were true. The verifier then checks this proof before it moves ahead. This has the added benefit of improving customer experience, because it can be more seamless to generate such a proof than to scan and share documentation.
Finally, there is secure multiparty computation, which lets several organizations or devices compute a result together, without revealing their individual inputs. This can be helpful for tasks such as detecting financial fraud, where fraudulent behavior is only obvious when data points from multiple institutions are combined. Or it could allow hospitals, for example, to improve disease prediction models using patient data, without any hospital actually seeing another’s records. As the European Data Protection Supervisor says, it is “a deceptively simple yet powerful idea.”3 In essence, the data is split up and indecipherable chunks of it are circulated to others in the group. Each of those entities does mathematical work on its own chunk, and then all the results are combined to produce a final answer.
The potential of counterintuitive cryptography is vast—but businesses need to keep a few principles firmly in mind as they explore this territory. The first is to remember that these are privacy-enhancing technologies, not substitutes for baseline security and governance. They complement, but do not replace, core controls. Also note that this is an embryonic space and currently has trade-offs: Implementation can be challenging, standards are often lacking, and the processes can be computationally demanding. But as serious cyberthreats increasingly look like business as usual, expect to see growing efforts to address these issues as companies innovate to stay ahead.
https://www.jpmorgan.com/payments/payments-unbound/sources
Illustration: Lauren Joseph
Read client success stories
Explore Payments solutions
View Payments Newsroom
