How can e-cash, even on-line cleared, protect payee identity?

Bryce wilcoxb at nag.cs.colorado.edu
Mon Oct 23 13:24:32 PDT 1995



-----BEGIN PGP SIGNED MESSAGE-----

 An entity calling itself "Simon Spero" <ses at tipper.oit.unc.edu> 
 allegedly wrote:
>
> I can't remember off hand, but isn't blinding transitive?


Blinding and unblinding is just multiplication and division in
modular arithmetic, right?  So it oughta be transitive, right?
I actually don't know, and I am eager to find out.


 "'Simon Spero'":
>
> If so, there's 
> an obvious way to get two way anonymity with an on-line system. If Alice 
> wants to pay Bob $10, then Bob could prepare the usual squillion copies 
> of the note, each with a serial number known only to Bob, then blind them 
> and send them to Alice. 
> 
> Alice would then reblind them and send them to Nick, the banker. Nick
> would then pick one of the notes, and ask Alice for the blinders for the
> rest. Alice would then ask Bob for his blinders for the rejected notes,
> and would forward both sets on to Nick, who would check them, and if
> they're legit, sign the remaning copy, and return it to Alice.  
> Alice cound then remove her blinding factor, and sent the result on to
> Bob. Bob then removes his blinding factor, and can now spend the coin. 


You mean he can now deposit the note with the bank for credit?  
Although he won't actually deposit it until later, some random 
amount of time after this transaction is finished.
  He *could* give the note to Charles, who would deposit it, but
Charles would not be able to protect his own identity when
accepting it.  Bob might as well just turn it in to the bank.


 "'Simon Spero'":
>
> Since Alice doesn't know the serial number, she can't reveal it to Nick 
> so that he can find out who deposits the coin. Also, since Nick doesn't 
> know the serial number, he can't collaborate with Bob to find out who 
> Alice is. 
> 
> Does this work, or am I missing something?


It sounds good to me.  Bob will check the note for the bank's sig
after he has unblinded it.  Thus he knows that Alice didn't cheat
him.


Can a more astute mathematician than myself evaluate this scheme for
us?


Bryce

signatures follow

            "To strive, to seek, to find and not to yield."   
    <a href="http://ugrad-www.cs.colorado.edu/~wilcoxb/Niche.html">

                          bryce at colorado.edu                   </a>


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: Auto-signed under Unix with 'BAP' Easy-PGP v1.01

iQCVAwUBMIv5vfWZSllhfG25AQHlsAP/SL7IxwVQ/J5k3OdbZm/B6GCl/ZpvKgV6
iyaHJKp4p3zGM6rlq9x0mj/hWedxeCgSA9x/ptcMoVY8A5l/wpGPSZhVRrb4/NRV
LDjwGb9g9g3/u5bHsK2dGo1FqnvCa0fBur2TzC07CvAFHlP1hzFPtEsemd1OB7fj
mWToHOYPDKY=
=fFvb
-----END PGP SIGNATURE-----






More information about the cypherpunks-legacy mailing list