Secure and Anonymous Electronic Commerce: Providing Legal Certainty in Open Digital Systems Without Compromising Anonymity

The growing importance of conducting legal transactions over open digital systems creates new requirements for these systems. They have to be designed in such a way that the users remain anonymous to one another and their activities cannot be observed by uninvolved parties. At the same time, the systems have to guarantee the necessary legal certainty for the transactions being carried out. It will be demonstrated (Section 1) that legal regulation alone is not sufficient to ensure that these requirements are dependably met.
For this reason, known technical methods and new proposals from the field of information technology are presented as a complement to legal regulation. On the one hand, these proposals guarantee unobservability and anonymity when using the system (Section 2) and, on the other hand, they provide sufficient legal certainty for the conduct of typical business processes over the open system without sacrificing anonymity (Section 3). Due to their particular importance, two issues are presented in more detail: two methods to prevent fraud during the exchange of values between anonymous parties (e.g., an information service offered in exchange for payment) (Section 4), and an anonymous digital payment system and variants of it (Section 5). The paper concludes with an overview of open problems and a practical evaluation of the issues (Section 6).

By: Birgit Pfitzmann, Michael Waidner, Andreas Pfitzmann

Published in: RZ3232 in 2000

LIMITED DISTRIBUTION NOTICE:

This Research Report is available. This report has been submitted for publication outside of IBM and will probably be copyrighted if accepted for publication. It has been issued as a Research Report for early dissemination of its contents. In view of the transfer of copyright to the outside publisher, its distribution outside of IBM prior to publication should be limited to peer communications and specific requests. After outside publication, requests should be filled only by reprints or legally obtained copies of the article (e.g., payment of royalties). I have read and understand this notice and am a member of the scientific community outside or inside of IBM seeking a single copy only.

rz3232.pdf

Questions about this service can be mailed to reports@us.ibm.com .