[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: cut & choose



-----BEGIN PGP SIGNED MESSAGE-----

Alex Strasheim <[email protected]> writes:

>I don't understand why anyone would use the cut and choose protocol over 
>denominated keys.  Chaum's method seems a lot cleaner to me and more 
>secure.  It obviously uses less bandwidth.  What am I missing here?

Schneier's examples are meant to be instructional in nature rather than
practical, showing how it would be done with paper envelopes and such.
The only example he has which is cryptographic is the "off-line" version
where Alice's identity is encoded in the cash in such a way that it is
revealed if she double-spends.  Chaum's off-line protocol also relies on
cut and choose for this (Chaum, Fiat, Naor, Crypto 88).  That is the
major improvement in Brands' scheme, that you don't have to use cut and
choose for his off-line cash system.

Hal

-----BEGIN PGP SIGNATURE-----
Version: 2.6

iQBVAwUBLuiNKxnMLJtOy9MBAQH1HgH/SycFuvD/vud4ZHUU8b8WDV+KgsfoyxbT
4Immhq478EcLhbLPrjriinyue17lc4fChQDPhm7Wg/i3w9rkaQQwGg==
=hyg3
-----END PGP SIGNATURE-----