The Bank for International Settlements (BIS) and central banks recently published a paper on legal issues and the design of CBDC systems. The participating central banks include the Bank of Canada, the Bank of England, the Bank of Japan, the European Central Bank, the Board of Governors of the Federal Reserve, the Swedish Central Bank and the Swiss National Bank.
One of the debates is whether the CBDC system adopts a centralized or decentralized model. In a two-tier system, one option is to adopt a hub-and-spoke model, where updates are controlled by the central bank but data ownership is decentralized. Or a peer-to-peer design can be adopted, with shared update permissions.
The paper points out that centralized systems are less resilient, have single points of failure, and may even become bottlenecks. However, they do not think it is appropriate to decentralize the core settlement power of the CBDC system. In a modular design, the core settlement can be centralized, while other aspects (such as identity) can be decentralized.
In addition, privacy is a big issue facing CBDC. While privacy can be achieved using existing technologies, some newer privacy-enhancing technologies (PETs), such as secure multi-party computation (SMPC) or zero-knowledge proofs (ZKP), can provide greater flexibility.
However, based on the experience of two central banks and the BIS Innovation Hub, they are not yet convinced that PET is ready and question its real-time execution capabilities, complexity and reliability.
Other topics explored in the paper include cybersecurity, offline CBDC and compatibility with existing point-of-sale systems.