Welcome to Journal of University of Chinese Academy of Sciences,Today is

›› 2006, Vol. 23 ›› Issue (3): 403-406.DOI: 10.7523/j.issn.2095-6134.2006.3.019

• 简报 • Previous Articles     Next Articles

Two Remarks on a Forword-Secure E-cash System

Cao Zheng-Jun   

  1. Key Laboratory of Mathematics Mechanization, Institute of Systems Science,
    Academy of Mathematics and Systems Science, Chinese Academy of Sciences. Beijing, China. 100080
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-03-15

Abstract: The paper shows that there are two errors in the E-cash system [1]. (1) In the setup phase, the factors p1, p2 of modulus n are not published. This makes the user and the bank cannot make valid signatures in the withdraw phase. (2) The shop M must directly obtain those data (h, h1, h2, h3) used in payment phase in a secure way, instead of receiving them from a signature offered by a user U. Otherwise, the adversary can forge signatures in the payment phase. Therefore, there are four redundant data among the signature (z, a, b, r, j, h, h1, h2, h3) offered by a user.

Key words: forward-secure, electronic cash, discrete logarithm problem, blind signature, redundant data.

CLC Number: