Advances in Cryptology - EUROCRYPT 2007

Volume 4515 of the series Lecture Notes in Computer Science pp 482-497

Divisible E-Cash Systems Can Be Truly Anonymous

  • Sébastien CanardAffiliated withLancaster UniversityFrance Télécom R&D
  • , Aline GougetAffiliated withLancaster UniversityGemalto


This paper presents an off-line divisible e-cash scheme where a user can withdraw a divisible coin of monetary value 2 L that he can parceled and spend anonymously and unlinkably. We present the construction of a security tag that allows to protect the anonymity of honest users and to revoke anonymity only in case of cheat for protocols based on a binary tree structure without using a trusted third party. This is the first divisible e-cash scheme that provides both full unlinkability and anonymity without requiring a trusted third party.