论文部分内容阅读
In order to decrease crimes such as money laundering, blackmailing etc. inelectronic cash systems, fair electronic cash has been a major focus of academic research inelectronic commence. When a bank finds some dubious cash or owner, the trusted entity ortrustee can help him to revoke the anonymity of the cash. In the previous protocols, the trusteeknows all the information of the cash whether he is trusted or not, that is, he can trace the useror cash unconditionally. Furthermore, the dishonest trustee may deceive a user, which meansthat he may withdraw cash while tracing other users. Such cases are unfair to the honest users.A new fair electronic cash protocol based on untrustworthy trustees is proposed in thispaper. The key idea is that the coin structure should include the signatures of both the trusteeand the bank so that the trustee shares the information of the cash with the bank, while we donot use the secret sharing scheme. In contrast with the previous protocols, neither the trusteenor the bank can trace the money without the help of the other entity. In this way, the privacyof the user is protected furthest. Also, the trustee is off-line in the protocol, which meansthat he will not be involved in withdrawing the cash. Therefore, the protocol is efficient forimplementation.