# Introduction to Multilateral Trade Credit Set-off in MPC by Enrico Bottazzi | Devcon SEA

- Speakers: [Enrico Bottazzi](https://streameth.org/speakers/enrico-bottazzi)
- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-09
- Duration: 11:20
- Topics: Science & Technology
- Watch: https://streameth.org/watch/yt-OCEEe8azbR8
- YouTube: https://www.youtube.com/watch?v=OCEEe8azbR8

## Description

Multilateral Trade Credit Set-off is a process for collecting outstanding invoices from a network of firms and detecting cycles. A cycle is a circular pattern of due payments that connects businesses. Removing a cycle yields liquidity savings for the firms involved. This process is done by a central agency that collects the invoices and performs the netting. Instead, we leverage MPC to perform the set-ff while preserving the privacy of sensitive financial data of the firms

Speaker(s): Enrico Bottazzi
Skill level: Intermediate
Track: Applied Cryptography
Keywords: finance

Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon
Learn more about devcon: https://www.devcon.org/
Learn more about ethereum: https://ethereum.org/ 

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more.

Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. 
Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024.
Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

## Transcript

[Music] hi guys oh sorry so my name ISO batti and today I'm going to introduce you to multilateral Trade Credit set off in MPC which is an application of MPC and this is a work joined with my colleagues and researcher Nam and masato which are also part of the PSC team inside theum foundation so let's jump into that first of all I want to introduce you the concept of a payment Network so as you can see here the payment Network involves three firms each firm as a balance and each arrow in this graph represent an obligation like some amount of money that a firm owes to another and the problem of this payment network is that they are kind of stuck because each firm given their balance they cannot pay another firm so for example firm one cannot pay firm two because they are waiting firm three to pay thems and the same goes for the other two firms and apparently the only way to solve this problem is to use uh external liquidity which we know that is expensive but actually there's another solution to solve this problem which is multilateral Trade Credit set off and we can see how we apply that from the figure on the left left to the figure on the right and you can also intuitively understand this thinking about like if you owe money to your friend Alice Alice owes money to your friend Bob and Bob owes you money you don't need to make free payments to settle everything you can just remove the depth from the system and another example that might help people understanding it is how the application split splitwise works so what we achieved is a way to remove obligation from a payment Network without uh leveraging expensive external injection of liquidity so this is uh an example of multilateral Trade Credit setup on a big scale apply on the network in in Sardinia in Italy and the cool thing that you can see is that the more are the firms participating it the bigger the higher the chance to detect these cycles of credit and depb and therefore the greater are the liquidity savings for the firms involved into the payment Network so this is actually something that exists in the real world like the flag that you see on the top right is the one of Slovenia country in Europe and this is how the process works so the firms that decide to join the system will send their Credit Data to this third party agency managed by the government and this agency will reconstruct the graph perform this set off so remove these cycles and return the updated data to the firms while it works in practice there's a very low participation rate and this leads us to our research thesis we believe that the limited participation is due to the fact that these firms have basically to give up all the information The View on their sensitive Trade Credit Data to this government agency and we also believe that if we could build the same system we privacy embedded into that the participation will be higher and this will also yield as we said before greater and um higher liquidity savings for the firms involved in the system so what do we mean by privacy first of all we want to hide the balances of the firms we want to hide the amount of each obligation and we also want to hide the topology of this payment Network so in practice in means that we also do not want to reveal the fact that there's a specific obligation between two firms in this network and how does this work we basically replace like U before you had like the the government agency there now this is replaced by a set of MPC servers that are able to perform this operation somehow obliviously so unfortunately I don't have time to go through like the details of MPC and the algorithm that we construct but I want just to bring the most significant results of our research so we were able to significantly reduce the asymptotic complexity of this algorithm to be performed in a MPC environment and we did that mostly through two techniques one is secure graph anonymization that allows this servers this uh multiparty nodes to anonymize the graph for opening its shape and the second contribution is the secure network network Simplex which is a um Network flow algorithm and we build its corresponding and efficient version in MPC so we are going to publish a paper related to what I describ soon and you can check my blog to be notified or also follow me on Twitter to see the result published thanks for your attention thank you enrio anyone has any questions raise your hand I can see you and I can throw this to you hopefully okay this one is close all right uh my question is what happens if party one has a higher interest rate than party two is that able to factor in interest rates yeah uh we we we didn't get into this part basically so we are just uh tling this problem from a cryptographic perspective not getting too much into the details of the of the process uh hey uh great use case um how do you do the like can you touch a bit the secure graph anonymization like are you using something like an oblivious Ram like what's the what's the actual NPC technique to anonymize the connections yes so basically we for that we bought a technique from this field in Academia that is called graph anonymization that is not related to cryptography and this is mostly used by like when a when a company for example wants to open source some some graph but they also want to add the data uh behind the graph what they do is they use like this kind of obfuscation or a a perturbation technique to the graph and for example we use a technique that is very simple it's called like random add and deletion so you basically just randomly add some Edge in the graph and randomly delete some Edge in the graph and what you get out of that is a a new graph which basically like the entropy generated by this uh by this mechanism is high enough such that you cannot infer information from that so I I guess that it's also correct to mention the tradeoff because since we are also deleting Edge we are somehow sacrificing some of the optimality in the algorithm because basically some obligation will disappear but I think this is a trade-off that we are willing uh to accept we have one more question left one minute thank you um is there does it relate to blockchain in some uh possible applications uh no not yet oh maybe one more oh there's a question at the front is the lady here oh sorry thank you yeah thank you for the talk so basically it creates an equivalent graph from the initial graph and then what what happens after that it's being reconstructed uh and it looks like the algorithm that you described is basically like AC encryption where some row being vated and then switched with each other or something like this so there are supposed to be Key by you can revert the procedure and then do something with it or yes yes so I have seven seconds like the idea is that after the graph is anonymized this parties of the MPC will have an open version of the graph that doesn't really conceive any meaningful information and what they will do from then they will perform this uh algorithm which specifically is uh about like solving the minimum cost flow problem over this graph in a MP see like um linear secret sharing way so it basically means that all the values that are part of this graph are split between parties so every time they do I don't know an addition a multiplication or a comparison between secret Share value they will also get as a result another secret Share value and uh in order to reconstruct this value in order to see what's behind the real data basically all this party need to collude and recompose the value from the shares so that's how we guarantee the Privacy basically oh we have time for one more question um so the results are some is a chain of liquidations right uh so can this result be used to reconstruct the initial debts so for example if uh if I get 100 uh liquidated and my friend also gets 100 liquidated and another friend gets 100 liquidated that means that there were some relations between us and people could just use this to reconstruct the original Debs which want to hide yes yes that's true I mean like the one of the assumption that we make uh in this um in this construction is that the firm itself are not malicious so a firm is interested in protecting their own data and they're not trying to collude with other firms to fetch like I don't know some uh intermediary party in this uh in this cycle and uh what I what I would argue is that they could do this anyway even without this uh this system so it's not that we are trying to solve the problem of u a FM not being able to see if there's a some intermediary party between uh between them so probably I didn't explain it very well but like in our um let's say threat model we don't consider the firms as a as a potential attacker we only consider this uh NPC server a potential as a as a potential attack attacker that tries to fetch information from from this graph okay thank you
