Privacy-Preserving Inventory Matching Using Segmented Axe Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for inventory matching in financial markets compromise privacy by revealing inventory and trading intentions, making firms vulnerable to adverse price movements and increased trading costs.
Innovation Solution
A privacy-preserving inventory matching system that uses cryptographic protocols, such as Pedersen schemes and arithmetized comparison circuits, to enable secure and anonymous axe submissions, quantity commitments, and trade executions, ensuring that only minimal quantity integers are revealed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If banks publish axe lists to incentivize trading and achieve internalization, then trading activity increases and internalization improves, but the bank's inventory and clients' trading intentions are revealed, making them vulnerable to adverse price movements
Solution Approach 1:
The axe list is segmented into two separate lists: a public list containing only security identifiers and directions (without quantities), and a private list containing the actual quantity commitments. This segmentation allows the bank to publish trading intentions to incentivize activity while protecting the sensitive inventory information that would otherwise be exposed.
Solution Approach 2:
A cryptographic commitment mechanism acts as an intermediary between the public announcement and private inventory data. The commitment allows others to verify the existence and direction of axes without revealing the actual quantities, serving as a mediator that enables partial information disclosure while preserving privacy.
2Adaptability or versatility
If the bank aggregates internal firm inventory with risk inventory to construct axe lists, then internalization capability improves, but the bank leaks its own axe and trading intentions to the market
Solution Approach 1:
The harmful element (quantity information) is extracted from the published axe list. The bank publishes only the non-sensitive portions (security identifiers and directions) while taking out and protecting the sensitive quantity data through cryptographic commitments, thereby maintaining internalization capability without exposing inventory to market manipulation.
Solution Approach 2:
Different parts of the axe list have different quality levels of information disclosure. The public list contains coarse-grained information (direction and security type) suitable for market transparency, while the private list contains fine-grained sensitive information (quantities) that requires protection. This local differentiation of information quality resolves the contradiction between transparency and privacy.
3Loss of information
If anonymized axe lists are published to protect privacy, then some information is concealed, but trading activity of contributing clients is still implicitly revealed through continual publication
Solution Approach 1:
Cryptographic commitments are created in advance before any publication or matching occurs. These commitments bind the quantity information from the outset, ensuring that even with continual publication of axe lists, the actual trading intentions remain cryptographically protected and cannot be reverse-engineered from the published data.
Data Source
AI summary
A method for privacy-preserving inventory matching may include: (1) receiving a plurality of axe submissions; (2) arranging the parties into data structures based on a direction in the party's axe submission; (3) sending each party's commitment to the other party; (4) receiving, from each party, output secret-shares of an arithmetized comparison circuit; (5) verifying that the output secret-shares of the arithmetized comparison circuit received from the parties match commitments to the output secret-shares sent by the respective opposite party; (6) identifying a minimal party based on the outputs of the arithmetized comparison circuit; (7) generating and sending a proof of the minimal party identification to the minimal party; (8) receiving a minimal quantity integer from the minimal party; (9) revealing the minimal quantity integer to the first party and the second party; and (10) executing the trade for the minimal quantity integer.


