eCash
David Chaum · 密码学论文与电子现金系统Cryptography paper and electronic cash system
1982 年提出盲签名方案 · 1983 年论文出版 · 1994 年网络演示Blind-signature proposal in 1982 · paper published in 1983 · network demonstration in 1994
先分清论文与产品A paper and a later payment system
盲签名方案见于 CRYPTO ’82 的《用于不可追踪支付的盲签名》,论文集在 1983 年出版。DigiCash 后来将相关技术用于 eCash;1994 年的网络演示与 CyberBucks 试用属于产品阶段,不能把它们的上线时间写成 1982 年。
The blind-signature proposal appears in Blind Signatures for Untraceable Payments at CRYPTO ’82; the proceedings were published in 1983. DigiCash later applied related technology in eCash. Its 1994 network demonstration and CyberBucks trial belong to the product's history, not to a product launch in 1982.
Chaum 想解决什么The problem Chaum addressed
支付记录能够暴露一个人的行踪、交往和生活习惯。Chaum 希望电子付款既能防止伪造,又不必让经手交易的机构完整掌握付款人的消费轨迹。这是把现金的部分隐私特性带入电子支付的尝试。
Payment records can expose a person's movements, relationships and habits. Chaum sought electronic payments that resist forgery without giving the institutions handling them a complete record of the payer's spending. The aim was to bring some of physical cash's privacy properties into electronic payments.
依据Sources [1]
盲签名怎样工作How blind signatures work
用户先用随机数把代表电子现金的数据遮蔽,再请银行签名。移除遮蔽后,银行的有效签名仍然保留,但银行难以把付款时看到的现金与之前的提款对应起来。商家将现金交给银行核验,银行检查它是否已经花过。
The user masks data representing electronic cash with a random value and asks the bank to sign it. Removing the mask leaves a valid bank signature, while preventing the bank from matching the resulting cash to its withdrawal. The merchant submits the cash to the bank, which checks whether it has already been spent.
依据Sources [6]
隐私并不消除对发行方的依赖Privacy does not remove the issuer
这里介绍的是在线盲签名支付模型:银行仍负责签发、核验与兑付,系统需要它持续服务。盲签名减少了提款与付款之间的可关联性,却没有把发行权或双重支付检查变成一个无需银行的公共网络。
This is the online blind-signature payment model: the bank still issues, validates and redeems the cash, so its continued operation matters. Blind signatures reduce the link between withdrawal and payment; they do not turn issuance or double-spending checks into a public network independent of a bank.
与 Bitcoin 的关系:有比较记录,机制不同Bitcoin: a documented comparison, different mechanisms
2009 年 2 月 12 日,中本聪回应读者时明确比较了 Chaum 式现金:两者都使用数字签名,但隐私和防止双重支付的方法不同,Bitcoin 也不设中央服务器。这能证明他了解并讨论过该路线,不能据此写成 Bitcoin 直接采用了 eCash 的盲签名机制。
On February 12, 2009, Satoshi explicitly compared Bitcoin with Chaumian cash: both use digital signatures, but their privacy and double-spending mechanisms differ, and Bitcoin has no central server. This documents his awareness and discussion of that approach; it does not establish that Bitcoin adopted eCash's blind-signature mechanism.
依据Sources [7]
作者小传About the author
David Chaum
密码学与支付隐私研究者,获加州大学伯克利分校计算机科学博士学位,创办 DigiCash。他的研究还涉及匿名通信与电子投票。
A researcher in cryptography and payment privacy, Chaum earned a computer science PhD at UC Berkeley and founded DigiCash. His research also includes anonymous communication and electronic voting.
原文摘录Source excerpt
David Chaum · [1]
个人能够提供付款证明
Ability of individuals to provide proof of payment
原始资料与核对来源Original documents and sources
- Blind Signatures for Untraceable Payments ↗
作者保存的论文原文Original paper preserved by its author
- Springer: Blind Signatures for Untraceable Payments ↗
出版社书目信息:1983 年、199–203 页Publisher metadata: 1983, pages 199–203
- David Chaum — Publications ↗
作者书目:CRYPTO ’82 论文集Author bibliography: proceedings of CRYPTO ’82
- David Chaum — eCash ↗
作者整理的历史资料与当年公告入口Author's historical collection and contemporary announcements
- DigiCash: World's first electronic cash payment over computer networks ↗
1994 年 5 月 27 日演示公告Demonstration announcement dated May 27, 1994
- Security without Identification: Card Computers to make Big Brother Obsolete ↗
作者对盲签名支付过程的详细说明Author's detailed explanation of blind-signature payments
- Satoshi Nakamoto: Bitcoin open source implementation of P2P currency ↗
2009 年 2 月 12 日中本聪比较 Chaum 式现金的邮件存档Archived February 12, 2009 email comparing Bitcoin with Chaumian cash
- Stanford Security Seminar — David Chaum ↗
受邀学者人物简介Invited speaker biography
- David Chaum — Author website ↗
作者研究与经历简介Author's research and biographical profile