A Description of Protocols for Private Credentials.
Ariel Glenn, Ian Goldberg, Frédéric Légaré, Anton Štiglić · 2001
This document provides a short description of practical protocols for private credential systems. 1 We explain the basic concepts and mechanisms behind issuing and showing of private credentials and e-cash. The goal is to describe concisely how practical private credential systems can be achieved and not to provide intuition or motivation for the technology; for information on these subjects, see [1, 2, 3]. We give the details of one specific type of practical protocols for private credentials; other choices of functionalities and optimizations are possible. The reader is assumed to have general knowledge of basic concepts of cryptography such as the Discrete Logarithm problem, basic group theory and hash functions. For security proofs and more elaborate descriptions of the techniques used we refer the reader to [2]. 2 Basic Tools 2.1 Notation denotes that the value is in the set . \t - denotes the choice of a uniform and independent random value from the set . denotes the set , ! denotes the set "# for a prime . %$'& denotes the assigning to of the value of & . (*)& denotes the definition of as the value of . Let be a large prime number, for which \t+ has a large prime factor , . (In practice, will be around 1024 bits long, and , will be around 160 bits long.) For the rest of the paper, we assume operations in a subgroup of - of order , , which we denote by .0/21 . All calculations involving elements of this subgroup are assumed to be mod , and all calculations involving the field of exponents are assumed to be mod , . (Note that this is similar to the setup of DSA.) 1 Note that this technology is patented. 1 2.2 DL...