A Universally Composable Scheme for Electronic Cash

Marten Trolin

Abstract: We propose a scheme for electronic cash based on symmetric primitives. The scheme is secure in the framework for universal composability assuming the existence of a symmetric CCA2-secure encryption scheme, a CMA-secure signature scheme, and a family of one-way, collision-free hash functions. In particular, the security proof is not in the random-oracle model. Due to its high efficiency, the scheme is well-suited for devices such as smart-cards and mobile phones. We also show how the proposed scheme can be used as a group signature scheme with one-time keys.

Category / Keywords: cryptographic protocols / electronic cash

Publication Info: Extended abstract at Indocrypt 2005. This is the full version.

Date: received 19 Sep 2005, last revised 11 Oct 2005

Contact author: marten at nada kth se

Version: 20051011:134740 (All versions of this report)

