Privacy Computing Unit for Secure AML Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-money laundering (AML) systems face challenges in accurately sharing and combining AML risk information across different financial institutions, leading to inconsistent STR crime labels and money-laundering risk levels for the same users, which hampers effective AML audit capabilities.

Innovation Solution

An information sharing method and system utilizing a privacy computing unit to match user IDs and combine AML risk information from multiple institutions, leveraging blockchain technology for secure and accurate data sharing, while ensuring privacy protection through trusted execution environments and decentralized identity services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If AML risk information is shared across multiple financial institutions, then the accuracy of AML audit capability is improved, but data privacy and security risks increase

Engineering Contradiction:
ImproveAML audit capability accuracyVSAvoiddata privacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a privacy computing unit as an intermediary between financial institutions. This unit performs secure multi-party computation to match user IDs and combine AML risk information without exposing raw data. The privacy computing unit acts as a trusted mediator that enables accurate AML auditing while protecting data privacy through cryptographic techniques and trusted execution environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If AML risk information from multiple institutions is combined, then comprehensive risk assessment is improved, but system complexity increases

Engineering Contradiction:
Improverisk assessment comprehensivenessVSAvoidinformation sharing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The privacy computing unit serves as a centralized coordinator that simplifies the overall system architecture. Instead of requiring direct peer-to-peer connections between multiple institutions, the privacy computing unit centralizes the matching and combination operations, reducing communication overhead and system complexity while enabling comprehensive risk assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system divides functionality into distinct modules: institutions submit data, the privacy computing unit performs matching and combination, and results are returned to participants. This segmentation allows each component to be optimized independently and facilitates easier maintenance and scaling of the system.

Inventive Principle:
Principle #1Segmentation

3Stability of the object's composition

If user ID matching is performed across institutions, then consistent identification is improved, but computational overhead increases

Engineering Contradiction:
Improveuser identification consistencyVSAvoidcomputational overhead
Core Design Contradiction:
Stability of the object's compositionVSUse of energy by moving object

Solution Approach 1:

The system performs user ID matching as a preliminary step before combining AML risk information. By pre-matching user IDs across institutions, the system establishes consistent identification early in the process, avoiding redundant computational work later and enabling efficient data combination only for matched records.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11954686B2Information sharing methods and systems
Publication Date: 2024.04.09 ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
  • US11954686B2 patent drawing
  • US11954686B2 patent drawing
  • US11954686B2 patent drawing

AI summary

Examples in this application disclose information sharing methods, media, and systems. One example computer-implemented method includes receiving, by a trusted execution environment (TEE), a first sharing request from a first institution and a second sharing request from a second institution, where the first sharing request comprises a user identity of a first user and first anti-money laundering (AML) risk information and the second sharing request comprises a user identity of a second user and second AML risk information, comparing the user identity of the first user with the user identity of the second user, in response to that the user identity of the first user is the same as the user identity of the second user, combining the first AML risk information and the second AML risk information, and sending the combined first AML risk information and second AML risk information to the first institution and the second institution.