Comment by teravor
2 hours ago
when you unblind a blind signature all the signer knows is that it's a signature they signed at some point, they know nothing (true zero knowledge) about when or where they signed it among all the other signatures.
2 hours ago
when you unblind a blind signature all the signer knows is that it's a signature they signed at some point, they know nothing (true zero knowledge) about when or where they signed it among all the other signatures.
Yes, and then you have a signed piece of data that others can verify. How does that help you with preventing duplication of signatures?
E-cash depends on the secrecy of the signed data, and immediate redemption with the issuer once it's been spent/accepted. This is a terrible model for physical cash.
not when everything is now online.
also the obvious way such cash would work is that "redemption" is just the new minting of coin. the central authority will mint a new coin by blindly signing your secret after you "destroy" the spent coin by giving them the unblinded signature.
This thread is about printing QR codes on physical cash. GGP explicitly said:
> That's really neat! Seems potentially adaptable to paper currency--a verifiable QR code digital signature of the bill's serial number creates a cryptographically hard obstacle to counterfeiting!
I don't see how any e-cash solutions can help here.