Authors: Marten Trolin


We propose a scheme for electronic cash based on symmetric primitives.
The scheme is secure in the framework for universal composability
assuming the existence of a symmetric CCA2-secure encryption scheme,
a CMA-secure signature scheme, and a family of one-way,
collision-free hash functions. In particular, the security proof is
not in the random-oracle model. Due to its high efficiency,
the scheme is well-suited for devices such as smart-cards and mobile
phones. We also show how the proposed scheme can be used as a group
signature scheme with one-time keys.

