Fair Oo-line E-cash Made Easy
نویسندگان
چکیده
The major considerations in designing a secure system are (1) simplicity of the algorithms involved, (2) eeciency of the implementation, and (3) provable security; these attributes contribute to the \elegance" of a system, easing its implementation (and limiting the possibility of errors) and the burden on system resources. Anonymous oo-line electronic cash (e-cash) systems provide transactions that retain the anonymity of the payer, similar to physical cash exchanges, without requiring the issuing bank to be on-line at payment. Fair oo-line e-cash extend this capability to allow a qualiied third party (a \trustee") to revoke this anonymity under a warrant or other speciied \suspicious" activity. In fair oo-line e-cash, simplicity and eeciency are of high importance, as the systems are inherently complex and prone to design and implementation errors. Security must also be guaranteed yet, to date, there have been no systems that ooer provable security. In this work we make a step towards \elegant" fair oo-line e-cash by proposing a system which is provably anonymous (i.e., secure for legitimate users) while its design is simple and its eeciency is similar to the most eecient systems to date. Security for the bank and shops is unchanged from the security of non-traceable e-cash. We also present ways to adapt the functionality of \fairness" into existing (legacy) e-cash systems in a modular way, thus easing advancement and maintaining version compatibility ; these extensions are also provably anonymous. We prove anonymity based on the decision Diie-Hellman assumption. This assumption has been used recently for other purposes, such as implementations of unconditionally-hiding hash functions.
منابع مشابه
\indirect Discourse Proofs": Achieving Eecient Fair Oo-line E-cash
Cryptography has been instrumental in reducing the involvement of overhead third parties in protocols. For example; a digital signature scheme assures a recipient that a judge who is not present at message transmission will nevertheless approve the validity of the signature. Similarly, in oo-line electronic cash the bank (which is oo-line during a purchase) is assured that if a user double spen...
متن کاملEecient Scalable Fair Cash with Oo-line Extortion Prevention
There have been many proposals to realize anonymous electronic cash. Although these systems ooer high privacy to the users, they have the disadvantage that the anonymity might be misused by criminals to commit perfect crimes. The recent research focuses therefore on the realization of fair electronic cash systems where the anonymity of the coins is revocable by a trustee in the case of fraudule...
متن کاملA Thesis for the Degree of Master A Study on Fair Electronic Cash System with and without TTP
The research on off-line electronic cash(e-cash) schemes has drawn much attention since Chaum etc [8] presented the first off-line anonymous electronic cash scheme in 1988. However, anonymous electronic cash schemes also facilitate fraud and criminal activities [32], such as money laundering, blackmailing and illegal purchases. Frankel etc [13]. first introduces the concept of fair electronic c...
متن کاملMis-representation of Identities in E-cash Schemes and how to Prevent it
In Crypto '93, S. Brands presented a very eecient oo-line electronic cash scheme based on the representation problem in groups of prime order. In Crypto '95 a very eecient oo-line divisible e-cash scheme based on factoring Williams integers was presented by T. Okamoto. We demonstrate one eecient attack on Okamoto's scheme and two on Brands' scheme which allow users to misrepresent their identit...
متن کاملRetrofitting Fairness on the Original RSA-Based E-cash
The notion of fair e-cash schemes was suggested and implemented in the last decade. It balances anonymity with the capability of tracing users and transactions in cases of crime or misbehavior. The issue was raised both, in the banking community and in the cryptographic literature. A number of systems were designed with an off-line fairness, where the tracing authorities get involved only when ...
متن کامل