Security

Indian stock exchange finally encrypting all messages to traders

Requests for pricing will soon be encrypted, after implementation deadline was extended


India's Bombay Stock Exchange (BSE) has told market participants they need to adopt encryption – which, shockingly, isn't already implemented – for certain messages sent to its trading platforms when using its Enhanced Trading Interface (ETI).

ETI is the bourse's interface for traders, and sent out its directive last Monday.

"In this implementation, all the messages exchanged between member application and trading engine will require to be encrypted by the sender and decrypted by the receiver," specified the notice.

"All" is the key word here. Sources familiar with BSE processes tell The Register that most communications between BSE and brokers were already encrypted – as one would expect in 2024.

The new policy covers brokers requesting price quotes from the platform – an act that is a potentially valuable source of info, as the mere fact of asking for a price indicates a possible trade that could move the market. It is therefore surprising that they were not already encrypted.

The order to market participants comes after India's Securities and Exchange Board mandated encryption for comms with stock exchanges that fall under its purview.

BSE will use the AES 256 encryption algorithm for the price info. It began testing the protocol on March 28, making encrypted and non-encrypted channels available in parallel.

It then set a date to discontinue the non-encrypted channel on May 13, but that date came and went before being extended to June 8. Market participants who met the first deadline were encouraged not to wait before migrating applications to the encrypted channel.

"All existing applications working on non-encryption channel will not be able to connect to simulation post June 8, 2024. Thus, all member applications are requested to complete the development of encryption before the discontinuation date," the bourse has advised participants.

"Encryption is important for trading because it keeps your data confidential between your company and the exchange," co-founder of commodity trading platform Topaz, Jo Finnigan, told The Reg. She included prices at which traders wish to buy or sell securities among information that a broker might not want others to see.

She added that unencrypted data can be manipulated en route, so an attacker could change the information sent in requests.

According to Finnigan, encryption is certainly the norm when it comes to both stock exchange and commodity trading.

The COO and co-founder allowed it is possible BSE has used other layers of security to mitigate risks when it comes to the communications that were not included in encryption.

According to a December 2023 ETI manual, some encryption already provided includes TLS encrypted payload connections for its low frequency (LF) sessions via a dedicated TLS port. An ETI LF session is typically used for providing functionalities like order management, market data access, and trade confirmation.

But when it comes to the unencrypted exchanges, Deutsche Börse – the developer of the Xetra ETI platform behind BSE's ETI platform – told The Register that component of the Indian exchange's app is its own responsibility.

Industry insiders told The Reg "any encryption or decryption will require some time in terms of processing" – which was likely the main deterrent for not implementing encryption on all BSE messages until now. ®

Send us news
2 Comments

Alibaba Cloud closing Australian and Indian datacenters

Prioritizing Mexico and Southeast Asia

China warns citizens to stop posting info about spy satellites on social media

Plus: Singapore launches global regulatory blockchain; China gets new SciTech boss; India spectrum auction fizzles

Indian govt probes claims Foxconn won't hire married women

Cultural traditions clash with manufacturing ambitions

India to build re-usable launch vehicle after nailing third landing of mini-spaceplane

Next: more work on crewed mission, including space yoga for astronauts

Infosys CEO to pay a whole $30K in penance for non-disclosure that enabled insider trading

Staff were told of lucrative partnership before the rest of us

Japan's space junk cleaner hunts down major target

Plus: Australia to age limit social media; Hong Kong's robo-dogs; India's new tech minister

After 13 years, Atlassian delivers custom domain names for Jira

Customers aren't thrilled at double subdomain or need for Premium license

India's IT minister defeated in bid for lower house seat

Probably won't cost him his job, meaning India's messy tech to-do list remains his problem

China lands probe Chang'e-6 on the far side of the Moon

PLUS: Singapore intros AI safety tools; Satya Nadella fined by Indian gov; China stops influencers flaunting bling

Google goes shopping for Indian e-commerce dominance … at Walmart

Invests $350 million in Flipkart

Zoom adds 'post-quantum' encryption for video nattering

Guess we all have imaginary monsters to fear

EMEA enterprise folks scrutinize deals more closely – and it's hurting Workday

Pesky 'macro' stuff forces SaaS biz to yank revenue forecast, share price plunges double digits