Lecture 10: Designs of Financial Infrastructure Utilizing Encryption
Watch on YouTube →
Overview
Robert Townsend explores financial infrastructure designs using encryption, focusing on three applications: encrypted auctions, hybrid credit/insurance mechanisms, and order book matching. He details how homomorphic encryption and multi-party computation (MPC) can eliminate trusted third parties in auctions and enable private information sharing for risk pooling in credit/insurance scenarios. The lecture also covers implementing these concepts on blockchains, highlighting ongoing challenges and advancements by companies like Zama and Sunscreen.
Key takeaways
- Homomorphic encryption and multi-party computation enable auctions without trusted third parties by allowing computations on encrypted bids.
- In credit and insurance markets, encryption can facilitate risk-sharing by allowing agents to conceal their balance sheet states while participating in insurance contracts.
- A generalized MPC scheme for auctions with N agents involves a central server combining public keys, performing FHE computations, and agents partially decrypting results.
- The core challenge in encrypted financial infrastructure is balancing the need for computation with the requirement to keep sensitive data private from all parties, including the computing agent.
- Implementing advanced encryption schemes directly on blockchains faces computational and validation hurdles, though companies like Zama and Sunscreen are making progress.
- The use of noise in BFV encryption (Ring LWE) is crucial for security, preventing outsiders from deciphering secrets even when performing operations like Gaussian elimination on encrypted data.
Chapters
- Lecture focuses on designs for financial infrastructure utilizing encryption.
- Three examples to be covered: auctions, hybrid credit/insurance, and market implementation.
- Goal is to reduce reliance on trusted third parties through cryptographic methods.
- First scheme involves bidders using their own servers.
- Bidders encrypt bids using public-private key pairs.
- Encrypted messages are exchanged among bidders without a third party.
- Second scheme uses a third-party server acting as a contract node (pseudo-agent).
- Communication goes through the server, which doesn't see private values.
- The server executes code to process encrypted messages.
- Introduction to the BFV encryption algorithm (Ring Learning With Errors).
- Public key: (a, delta); Secret keys: (s, e).
- Noise is added to ciphertext to prevent decryption of underlying secrets.
- Example of a system of linear equations where the secret (red) needs protection.
- Adding a noise vector (blue) makes deciphering the secret difficult.
- Gaussian elimination can solve the system, but noise complicates it.
- Recap of MPC with secret sharing and noise addition.
- Each participant adds noise to their secret before passing it on.
- Summing up noisy secrets obscures individual values.
- Agent A encrypts bid using public key (a, delta) and own secret key.
- Agent B does the same, sending encrypted bids to each other.
- Each agent adds their own secret key pair to the received ciphertext.
- Agents take the difference of their transformed ciphertexts.
- Result is delta times the difference of the bids.
- This scheme reveals bids to both players, which is not always ideal.
- Introduces a pseudo-agent (contract code) on a third-party server.
- Agents send encrypted bids and encrypted sums of private keys to the pseudo-agent.
- The pseudo-agent performs computations on encrypted data without seeing secrets.
- Each agent generates key pairs; public keys are submitted to the server.
- Server combines public keys into a joint public key, distributed to agents.
- Agents encrypt private data using the joint public key and send to server.
- Server performs computations on encrypted data (FHE).
- Encrypted result is sent back to agents for partial decryption using private keys.
- Partial decryptions are sent back to the server for final decryption.
- Method 1: Pairwise comparisons between agents.
- Method 2: Subdividing agents into subgroups to compute averages and reduce comparisons.
- Examples: M-Pesa in Kenya, commercial banks in Indonesia, New York repo markets.
- Common element: agents with balance sheets experiencing random shocks (e.g., liquidity shortages).
- Motivation: enabling risk-sharing (insurance) without revealing balance sheet states.
- Two agents (A, B) with utility functions subject to private shocks over two periods.
- Planner (third party) collects information and allocates endowments.
- Revelation principle: agents can be assumed to report truthfully.
- Agents experience shocks in both periods affecting utility.
- Endowments are deterministic and known, sequestered as collateral.
- Planner maximizes weighted sum of utilities subject to constraints.
- Agent A goes first (date 0), B second (date 1).
- Utility functions are power functions with potentially random parameters (e.g., 0.2 or 0.9).
- Fully revealed communication damages insurance possibilities due to information leakage.
Summary, takeaways, and chapters were generated by AI from the video's transcript and may contain errors. The video belongs to its creator, MIT OpenCourseWare.