A secure network for financial infrastructure: SCION and the Secure Swiss Finance Network (SSFN)
Summary
Financial market infrastructures depend critically on communication networks that remain available and secure even during outages and cyber-attacks. SCION is an internet architecture that strengthens resilience by giving users greater control over network paths and allowing traffic to switch rapidly between independently operated providers. The Secure Swiss Finance Network (SSFN), launched by the Swiss National Bank (SNB) and SIX in 2021, shows that this approach works in practice.
- Issue:
- 07
- Pages:
- 8
- Keywords:
- Financial market infrastructures, SCION, SSFN, Cyber security
- Year:
- 2026
Financial market infrastructures (FMIs) are the plumbing of the financial system: they allow payments and financial transactions to be settled safely and efficiently. Central banks play several roles in relation to them. They provide central bank money for final settlement and liquidity, operate or oversee critical systems, and promote safe, resilient, and efficient market arrangements. Among the most important FMIs are real-time gross settlement (RTGS) systems, through which financial institutions settle payments with one another in central bank money. These systems form a central link between the banking system, financial markets, and the implementation of monetary policy.
In Switzerland, this role is performed by the Swiss Interbank Clearing (SIC) payment system. The Swiss National Bank (SNB) is involved in two ways. It commissions SIX to operate SIC and acts as system manager, reflecting its statutory task of facilitating and securing cashless payment systems. It also oversees SIC as part of its statutory task of contributing to financial stability. As a systemically important infrastructure, SIC is subject to the CPMI-IOSCO Principles for Financial Market Infrastructures, the international standards for critical payment, clearing, and settlement systems. These standards are issued jointly by the Committee on Payments and Market Infrastructures (CPMI), which brings together central banks and other payment system authorities, and the International Organization of Securities Commissions (IOSCO), which brings together securities regulators. The SNB is a member of CPMI.
FMIs have particularly demanding communication requirements. An interruption to communication services can prevent financial institutions from settling transactions, with possible consequences for the financial system more broadly. For an FMI, the availability and resilience of its communication infrastructure are therefore important security objectives in their own right. Recent CPMI-IOSCO guidance treats the resilience of communication networks as part of the broader cyber resilience framework for FMIs (CPMI-IOSCO 2026). The challenge of maintaining such resilience is becoming more acute as cyber-attacks become faster and increasingly automated, leaving less time to detect and respond to disruptions (Crisanto et al. 2026).
Existing approaches to connectivity involve trade-offs. The public internet provides broad connectivity across independently operated networks, but users have little control over the routes their data takes. Dedicated private networks offer a more controlled environment but can create dependence on individual telecommunication providers and their infrastructure. For critical financial infrastructure, these limitations matter.
SCION (Scalability, Control and Isolation On Next-generation networks) offers a different approach. Developed at ETH Zurich, it is a relatively new but proven internet architecture that allows independently operated networks to interconnect securely while giving users greater control over the paths their data takes from sender to receiver. It also makes it easier to keep several independent paths open at once and to switch rapidly if one becomes unavailable. In addition, groups of networks can establish common trust and governance arrangements that define which authorities they recognize and which networks may participate.
These properties are particularly valuable for critical infrastructure. The Secure Swiss Finance Network (SSFN), launched in 2021 by the SNB and SIX, is a production implementation of SCION for the Swiss financial market (SNB 2023). This note explains how SCION works; how its approach to routing, trust, and governance contributes to security and resilience; and how the technology may also be relevant for emerging financial infrastructures based on distributed ledger technology (DLT).
The problem with today's internet
The internet is not one network. It consists of tens of thousands of interconnected networks operated by telecommunication companies, cloud providers, universities, corporations, and other organizations. Data sent across the internet typically travels through several of these networks before reaching its destination. The routes between them are determined by the Border Gateway Protocol (BGP).
Under BGP, neighboring networks tell one another which internet addresses they can reach and through which networks. Other networks use this information to decide where to forward traffic. One can think of this as similar to sending a letter: the sender specifies the destination, but the postal system decides how the letter gets there.
This architecture has been extraordinarily successful in allowing the internet to grow. But BGP was not designed with security as a primary objective. It provides no means of verifying that an advertised path is genuine, and the sender has little control over which networks the data passes through. This also affects where data travels geographically: even if both sender and recipient are in Switzerland, the data may be routed through networks in other countries.
This leaves room for routing errors and attacks. In a BGP hijack, for example, a network falsely advertises reachability to internet addresses belonging to another network, thereby attracting traffic intended to go elsewhere. The traffic may then be disrupted, intercepted, or redirected. One partial remedy, the Resource Public Key Infrastructure (RPKI), allows networks to verify that an organization is authorized to announce a particular range of internet addresses. But RPKI primarily validates the origin of a route announcement rather than the entire path, and deployment remains incomplete. Routing attacks can therefore still occur.
Even without an attack, the sender has limited influence over the networks or jurisdictions through which its data passes. For most uses of the internet, this is acceptable. For critical financial infrastructure, however, the route taken by a message and the ability to maintain communication during an attack or outage are important elements of cyber resilience.
How SCION routing works
SCION is a general architecture for routing between networks (Perrig et al. 2017). It can be used alongside the public internet, but it can also be used to build a controlled network across several interconnected telecommunication providers, as in the SSFN. Unlike a conventional private network operated by a single provider, such a network can offer several authorized routes across independently operated providers while remaining within a controlled environment.
A bank communicating with a financial market infrastructure (FMI) might, for example, have the following alternatives:
- Path A: Bank → Provider A → Provider B → FMI
- Path B: Bank → Provider C → Provider D → FMI
These paths cannot be assembled arbitrarily. Participating networks announce path segments that they are willing to make available, using cryptographically authenticated routing information. Senders obtain these path segments and combine them into complete end-to-end paths. A sender can therefore construct a path only from segments that the networks concerned have themselves offered.
The sender, or a gateway acting on its behalf, chooses among these paths. The choice can reflect not only speed but also criteria such as reliability, telecommunication provider, geographical route, or organizational policy. Instead of specifying only where a message should go, the sender can also influence how it gets there. Several paths can remain available simultaneously, allowing traffic to switch rapidly to an alternative if the path currently in use becomes unavailable.
Participants do not have to modify their applications. A SCION-IP gateway (SIG) at the edge of their network translates between conventional internet traffic, carried by the Internet Protocol (IP), and SCION, selecting paths according to a configured policy. This allows institutions to adopt SCION incrementally without modifying their applications.
SCION also changes what happens once a route has been selected. In conventional IP networks, forwarding decisions are made 'hop by hop': each router consults its own routing information to decide where to send the data next. In SCION, information about the selected path is carried in the packet itself. Each network along that path has cryptographically authorized the segment through its own network. A network can therefore verify that a packet is following an authorized path rather than simply relying on routing information supplied by another network.
Isolation Domains and trust
Another distinctive feature of SCION is the Isolation Domain (ISD): a group of networks that share a common framework for routing and trust. Each ISD has a Trust Root Configuration, which specifies the certification authorities recognized within the domain and who is responsible for governing the trust framework. The SSFN, described below, is one such domain: SIX issues the certificates that participants need to access the network, while the SSFN's rules determine who may participate.
Different communities can therefore establish their own trust arrangements. A community operating critical infrastructure can, for example, define which authorities and networks it trusts and establish governance rules appropriate to its security requirements.
Isolation Domains can also limit dependencies between different parts of the network. Routing failures or incorrect routing information in one ISD do not spread automatically to others and, conversely, problems elsewhere do not necessarily disrupt routing within the domain. This allows a community to retain greater control over the authorities and networks on which its communication depends.
An ISD is not necessarily a closed or private network, however. SCION provides the technical architecture, while the rules of each ISD determine which networks and users may participate and how the domain connects to others. This distinction is important for understanding the SSFN. Its controlled nature comes from combining SCION's technical architecture with the SSFN's own participation rules. Compared with a traditional private network operated by a single telecommunication provider, the SSFN establishes a common trust framework across networks operated by several different providers.
How SCION improves cybersecurity and resilience
The features described above strengthen security and resilience at the network layer in four main ways:
- Routing information is authenticated and paths are authorized. The information from which paths are built is signed by the networks that provide it, and each network authorizes the use of the segment through its own network. This addresses the routing attacks described above: an attacker cannot fabricate an authorized route, or insert, remove, or rearrange networks along an authorized path.
- Routes are transparent and controllable. The sender knows which networks the data will pass through and can choose among alternatives. This makes it possible to avoid networks or jurisdictions that are untrusted, compromised, or behaving suspiciously, reducing exposure to interception, traffic analysis, or disruption. SCION also gives defenders more information about where incoming traffic has come from. Rather than relying only on a packet's source address, which can be forged, they can distinguish traffic by the network path over which it arrived. This can help identify and filter suspicious traffic during an attack.
- Several routes can be available at the same time. If one route fails, another is selected immediately, reducing the risk of a prolonged interruption. This strengthens availability against both outages and attacks: traffic can be moved away from a failed link or provider, or from a path that is congested or under a denial-of-service (DDoS) attack, without waiting for the network to recompute its routes. This resilience becomes increasingly important as financial infrastructure moves towards continuous operation and instant settlement, as in instant payment systems.
- Trust can be organized through Isolation Domains. Communities operating critical infrastructure can define their own governance arrangements and determine which authorities they trust. This reduces dependence on a single global trust framework and gives the community greater control over the network infrastructure on which it relies.
Together, these features address important weaknesses in conventional internet routing. They can also strengthen controlled private networks, by giving users greater control over routes and making it easier to use several independent telecommunication providers.
The SSFN: a production implementation of SCION
The Secure Swiss Finance Network (SSFN) shows that this architecture can be used in production for critical financial infrastructure. The SNB and SIX launched it in 2021, in cooperation with telecommunication providers and participants in the Swiss financial market. The SSFN operates as a standalone ISD with its own Trust Root Configuration. Participation is governed by the SSFN rules, and SIX issues the certificates required to access the network. Because access is restricted to authorized participants, the SSFN is not directly reachable from the public internet. This reduces the attack surface and limits who can send traffic into the network, thereby reducing exposure to denial-of-service (DDoS) attacks.
The SSFN combines controlled participation with connectivity through several telecommunication providers. For greater redundancy, SIX recommends that participants connect through two providers. If one connection or provider fails, traffic can automatically switch to another, without requiring the application itself to establish a new connection.
SIX began using the SSFN as a production gateway to its infrastructure services in June 2022. At the end of June 2024, the SSFN replaced Finance IPNet, the previous private IP network, as the means of connecting to SIC. Finance IPNet was decommissioned as a gateway to SIX infrastructure services more generally at the end of September 2024. Since then, all domestic and foreign participants directly connected to SIC, as well as many of those connecting through a service bureau, have used the SSFN.
Today, more than 100 participants in the Swiss financial market are connected to the SSFN. They can use it to communicate with SIX, with other financial market infrastructures, and with one another. The SSFN therefore provides a practical example of a controlled network that connects several telecommunication providers under common rules while allowing participants to choose among alternative authorized routes.
SCION and distributed ledger technology (DLT)
SCION can also be relevant for financial infrastructure based on distributed ledgers, including blockchains. Such ledgers are decentralized in the sense that transactions are validated by many independent computers, known as validators, rather than by a single central operator. Yet these validators generally communicate with one another over the conventional internet.
The security and availability of the ledger therefore depend partly on the communication network beneath it. A routing attack cannot forge or alter the messages that validators sign, but it can prevent those messages from being delivered, and so isolate validators from one another. If enough validators are affected, transaction processing or consensus can be delayed or even halted.
SCION can provide protection at this layer. Validators can communicate over paths that every network along the way has authorized, and can keep alternative paths in reserve in case one becomes unavailable. Because SCION can operate alongside the conventional internet, it can also be introduced gradually rather than requiring all participants to adopt it at once.
Cimaszewski et al. (2025) examine this possibility for DLT-based cross-border payments. Using the Sui blockchain as a case study, they simulate routing attacks and find that, without SCION, more than 80% of them would halt the network's transaction confirmation. Where validators representing around half of the total stake in the consensus mechanism are connected via SCION, more than half of these attacks fail. Where validators representing more than two-thirds of the stake are connected, none of the attacks succeed.
Isolation Domains may provide a further benefit in a cross-border setting. Different jurisdictions or groups of regulated institutions could establish their own trust and governance arrangements while still communicating with participants in other domains. The network layer could thereby provide controls over connectivity that are difficult to implement at the level of a permissionless blockchain itself.
Conclusion
Cybersecurity is usually associated with protecting computers, authenticating users, and encrypting data. SCION addresses another layer: the paths connecting those computers. Compared with the public internet, SCION gives users greater control over the paths their data takes and ensures that every network along a path has authorized its segment.
Compared with conventional private networks, it makes it possible to connect several independent telecommunication providers within a common trust framework while allowing users to choose among alternative paths and switch rapidly if one becomes unavailable.
These features matter particularly for financial market infrastructures, where communication must remain available even during failures and attacks. The SSFN shows that SCION can support such infrastructure in production, combining controlled access with connectivity through several independent providers. Its potential application to distributed ledgers illustrates a broader point: new financial infrastructures may employ sophisticated cryptography at the application and ledger layers, but they still depend on an underlying communication network. Strengthening the security and resilience of that network therefore strengthens the resilience of the infrastructure built on top of it.
References
Cimaszewski, Grace, Francesco Da Dalt, Thomas Moser and Adrian Perrig (2025), SCION and cross-border payments: Enhancing security and compliance in distributed ledger networks, SNB Working Papers, 15/2025.
CPMI-IOSCO (2026), Cyber resilience toolkit: practical considerations for FMIs, Committee on Payments and Market Infrastructures and Board of the International Organization of Securities Commissions, September.
Crisanto, Juan Carlos, Adrien Currat and Jeffery Yong (2026), When machines attack: frontier AI cyber threats and policy responses in the financial sector, FSI Occasional Paper No. 28, Bank for International Settlements, September.
Perrig, Adrian, Pawel Szalachowski, Raphael M. Reischuk and Laurent Chuat (2017), SCION: A Secure Internet Architecture, Springer.
Swiss National Bank (2023), The Secure Swiss Finance Network, 115th Annual Report 2022, Box, p. 86.
- Disclaimer - SNB Economic Notes represent the views, opinions, findings, and conclusions of the authors. They do not necessarily reflect the views of the Swiss National Bank.
- Copyright© - The Swiss National Bank (SNB) respects all third-party rights, in particular rights relating to works protected by copyright (information or data, wordings and depictions, to the extent that these are of an individual character). SNB publications containing a reference to a copyright (© Swiss National Bank/SNB, Zurich/year, or similar) may, under copyright law, only be used (reproduced, used via the internet, etc.) for non commercial purposes and provided that the source is mentioned. Their use for commercial purposes is only permitted with the prior express consent of the SNB. General information and data published without reference to a copyright may be used without mentioning the source. To the extent that the information and data clearly derive from outside sources, the users of such information and data are obliged to respect any existing copyrights and to obtain the right of use from the relevant outside source themselves.
- Limitation of liability - The SNB accepts no responsibility for any information it provides. Under no circumstances will it accept any liability for losses or damage which may result from the use of such information. This limitation of liability applies, in particular, to the topicality, accuracy, validity and availability of the information.
- © 2026 by Swiss National Bank, Börsenstrasse 15, P.O. Box, CH-8022 Zurich