Advances in Cryptology — EUROCRYPT’ 92

Volume 658 of the series Lecture Notes in Computer Science pp 390-407


Transferred Cash Grows in Size

  • David ChaumAffiliated withCWI
  • , Torben Pryds PedersenAffiliated withAarhus University


All known methods for transferring electronic money have the disadvantages that the number of bits needed to represent the money after each payment increases, and that a payer can recognize his money if he sees it later in the chain of payments (forward traceability). This paper shows that it is impossible to construct an electronic money system providing transferability without the property that the money grows when transferred. Furthermore it is argued that an unlimited powerful user can always recognize his money later. Finally, the lower bounds on the size of transferred electronic money are discussed in terms of secret sharing schemes.