Compact e-cash from bounded accumulator

  • Authors:
  • Man Ho Au;Qianhong Wu;Willy Susilo;Yi Mu

  • Affiliations:
  • Center for Information Security Research, School of Information Technology and Computer Science, University of Wollongong, Wollongong, Australia;Center for Information Security Research, School of Information Technology and Computer Science, University of Wollongong, Wollongong, Australia;Center for Information Security Research, School of Information Technology and Computer Science, University of Wollongong, Wollongong, Australia;Center for Information Security Research, School of Information Technology and Computer Science, University of Wollongong, Wollongong, Australia

  • Venue:
  • CT-RSA'07 Proceedings of the 7th Cryptographers' track at the RSA conference on Topics in Cryptology
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Known compact e-cash schemes are constructed from signature schemes with efficient protocols and verifiable random functions. In this paper, we introduce a different approach. We construct compact e-cash schemes from bounded accumulators. A bounded accumulator is an accumulator with a limit on the number of accumulated values. We show a generic construction of compact e-cash schemes from bounded accumulators and signature schemes with certain properties and instantiate it using an existing pairing-based accumulator and a new signature scheme. Our scheme revokes the secret key of the double-spender directly and thus supports more efficient coin tracing. The new signature scheme has an interesting property that is has the message space of a cyclic group $\mathbb{G}_1$ equipped with a bilinear pairing, with efficient protocol to show possession of a signature without revealing the signature nor the message. We show that the new scheme is secure in the generic group model. The new signature scheme may be of independent interest.