# Information Security and Cryptography Research Group

## Digital Payment Systems with Passive Anonymity-Revoking Trustees

### Jan Camenisch, Ueli Maurer, and Markus Stadler

Journal of Computer Security, vol. 5, no. 1, pp. 69–89, 1997, Preliminary version: [CaMaSt96].

Anonymity of the participants is an important requirement for some applications in electronic commerce, in particular for payment systems. Because anonymity could be in conflict with law enforcement, for instance in cases of blackmailing or money laundering, it has been proposed to design systems in which a trustee or a set of trustees can selectively revoke the anonymity of the participants involved in suspicious transactions. From an operational point of view, it can be an important requirement that such trustees are neither involved in payment transactions nor in the opening of an account, but only in case of a justified suspicion. In this paper we present the first efficient anonymous digital payment systems satisfying this requirement. The described basic protocol for anonymity revocation can be used in on-line or off-line payment systems.

Keywords: Digital payment systems, electronic money, cryptography, privacy, anonymity revocation.

## BibTeX Citation

@article{CaMaSt97,
author       = {Jan Camenisch and Ueli Maurer and Markus Stadler},
title        = {Digital Payment Systems with Passive Anonymity-Revoking Trustees},
journal      = {Journal of Computer Security},
pages        = 69--89,
number       = 1,
volume       = 5,
year         = 1997,
note         = {Preliminary version: \cite{CaMaSt96}},
}