원문정보
초록
영어
Divisible e-cash allows the user to withdraw a single divisible coin and spends the any sub-coins by dividing the value of the coin. The first divisible e-cash system in the standard model was proposed by Izabachene and Libert. However, the efficiency of the spending protocol and the deposit protocol is very low. In this paper, we construct an efficient divisible e-cash scheme without random oracle by using the Groth-Sahai (GS) proof system and bound accumulators. Our scheme is on-line and truly anonymous without a trusted third party. Comparing to Izabachene and Libert's work, we improve the efficiency of the spending protocol and deposit protocol by introducing a new generational algorithm. Moreover, the bank only needs to look up the coin's serial number in a table of previously spent coins. We give the NIZK proofs of bounded accumulator in the standard model. Some security properties of our scheme, such as anonymity, unforgeability and exculpability, are proved in the standard model.
목차
1. INTRODUCTION
2. Preliminaries
2.1 Mathematical Definitions and Assumptions
2.2. Useful Tools
2.3. Algorithms
2.4. Security Notions
3. Construction of Divisible E-Cash
3.1. Bounded Accumulators
3.2. New Binary Tree Structure
3.3. Construction
4. Efficiency Analysis
5. Security Analysis
6. Conclusion
Acknowledgements
References
