Decentralized, offline, and privacy-preserving e-cash could fulfil the need for both scalable and byzantine fault-resistant payment systems. Existing offline anonymous e-cash schemes are unsuitable for distributed environments due to a central bank. We construct a distributed offline anonymous e-cash scheme, in which the role of the bank is performed by a quorum of authorities, and present its two instantiations. Our first scheme is compact, i.e. the cost of the issuance protocol and the size of a wallet are independent of the number of coins issued, but the cost of payment grows linearly with the number of coins spent. Our second scheme is divisible and thus the cost of payments is also independent of the number of coins spent, but the verification of deposits is more costly. We provide formal security proof of both schemes and compare the efficiency of their implementations.
翻译:分散式、离线式和隐私保护式电子现金可以满足对可缩放式和反占式防过错支付系统的需要。现有的离线匿名电子现金计划由于中央银行的缘故不适合分布式环境。我们建立了一个分散式的离线匿名电子现金计划,在该计划中,银行的作用由当局的法定人数来履行,并提出了两种即时因素。我们的第一个计划是契约,即发行协议的费用和钱包的大小与发行的硬币数量无关,但付款费用随着所花的硬币数量而直线增长。我们的第二个计划是可分化的,因此支付费用也与所花的硬币数量无关,但是对存款的核查费用更高。我们为这两个计划提供正式的安全证明,并比较其实施效率。</s>