-----BEGIN PGP SIGNED MESSAGE----- Alex Strasheim <alex@omaha.com> writes:
I don't understand why anyone would use the cut and choose protocol over denominated keys. Chaum's method seems a lot cleaner to me and more secure. It obviously uses less bandwidth. What am I missing here?
Schneier's examples are meant to be instructional in nature rather than practical, showing how it would be done with paper envelopes and such. The only example he has which is cryptographic is the "off-line" version where Alice's identity is encoded in the cash in such a way that it is revealed if she double-spends. Chaum's off-line protocol also relies on cut and choose for this (Chaum, Fiat, Naor, Crypto 88). That is the major improvement in Brands' scheme, that you don't have to use cut and choose for his off-line cash system. Hal -----BEGIN PGP SIGNATURE----- Version: 2.6 iQBVAwUBLuiNKxnMLJtOy9MBAQH1HgH/SycFuvD/vud4ZHUU8b8WDV+KgsfoyxbT 4Immhq478EcLhbLPrjriinyue17lc4fChQDPhm7Wg/i3w9rkaQQwGg== =hyg3 -----END PGP SIGNATURE-----