The E-cash schemes that are revocable anonymous with the help of trusted third party (TTP) cause additional costs and the level of anonymity is uncertain. Kulger et al adopted auditable tracing to control deanonymization without TTP, but the users have to audit the tracing frequently. A loss reportable e-cash scheme without TTP based on ECC is presented in this paper. In our scheme bank demands user to self-decrypt the e-coin when tracing is needed, so that the user and coin can be linked together and then user is certain about tracing. So the scheme resolves the problem of e-cash anonymity control without TTP simply and practically. Moreover, the scheme permit user to report the loss of and recover the lost e-cash, thus user is refrained from economic losses for accident or carelessness.
展开▼