Trustee Tokens - PowerPoint PPT Presentation

1 / 38
About This Presentation
Title:

Trustee Tokens

Description:

Simple and Practical Anonymous Digital Coin Tracing. Ari Juels. RSA Laboratories ... Conditionally anonymous digital coin. Observe: No change in coin ... – PowerPoint PPT presentation

Number of Views:45
Avg rating:3.0/5.0
Slides: 39
Provided by: arij2
Category:
Tags: anon | tokens | trustee

less

Transcript and Presenter's Notes

Title: Trustee Tokens


1
Trustee Tokens
  • Simple and Practical Anonymous Digital Coin
    Tracing

Ari Juels RSA Laboratories
2

3

PK
SK
Alice -1
Anonymous digital 1 coin
4

PK
SK
mod n
r, x
5

An Application for Anonymous E-Cash
An Application for Anonymous E-Cash

6
Improved Computer Virus
Edgar
7
Improved Computer Virus
8

9
Hard Disk
10
PK
Files
11
Ransom Note
12

Oh, my files!
Alice -1
13
HETTINGA SUCCEEDS GREENSPAN AT FED
14
Anonymous coin
Edgar
15
How can we prevent this?
16
The Idea Trustee Tracing
Anonymous coin
17
Tracing Basic Idea
Anonymous coin
Judge
18
Coin is anonymous unlesstrustee traces it
19
Many Trustee-based Tracing Schemes
  • Brickell et al. ( 95)
  • Stadler et al. (95)
  • Jakobsson and Yung (96, 97)
  • Camenisch et al., Frankel et al. (96)
  • Davida et al. (97)

20
Trend in schemes
Trustee Flexibility
Security Features
Computational Efficiency
Simplicity
21
How our scheme works
22
Two stages
Token withdrawal
1.
Coin withdrawal
2.
23
Token withdrawal
Checks that coin contains AlicePK
24
Trustee Token
Checks that x contains AlicePK
25

Coin withdrawal
SK
Conditionally anonymous digital coin
26
Observe No change in coinstructure or
underlying withdrawal protocol
27
Tracing
Trustee Token scheme guarantees that coins
contain creator identity
28
Blackmail scenario
  • Edgar registers his coin and gets caught or
  • Alice cant make the withdrawal for Edgar

29
Enhancements
30
No coin storage
  • Alice can pseudo-randomly generate coins and
    blinding factors -- no coin storage

31
Bulk token withdrawal
  • Alice can withdraw many tokens at once and store
    prior to coin withdrawals

32
One token - multiple coins
33
Result of Enhancements
  • Little interaction with Trustee

34
Pros and Cons
35
Advantages over other schemes
  • Very simple
  • Provably secure
  • No change in coin structure, underlying protocol
  • Seamless incorporation with DigiCashTM

36
Disadvantages
  • Trustee interaction needed
  • Security with multiple trustees needs trusted
    dealer
  • Seamless incorporation with DigiCashTM - but no
    DigiCashTM

37
But...
  • Can be used for general blind RSA
  • E.g., X-cash
  • Method can perhaps be extended to other e-cash
    systems (?)

38
Questions?
Write a Comment
User Comments (0)
About PowerShow.com