\title{Refreshing Coins for Giving Change and Refunds \\ in Chaum-style Anonymous Payment Systems}

\begin{abstract}
This paper introduces {\em Taler}, a Chaum-style digital payment system that enables anonymous payments while ensuring that entities that receive
payments are auditable and thus taxable.  Taler differs from existing
digital payment systems in that it is not a new currency, but uses
modern cryptography to make transactions with existing currencies, such
as Dollars, Euros or Bitcoins, more secure.  Taler combines the
advantages of cash and electronic payments: it is fast and easy to use
for customers, provides cryptographic evidence of payment for merchants,
and is taxable.  Taler is practical and can be incrementally deployed,
as it does not require a global consensus on a transaction history.
Taler's cryptographic protocols ensure that a customer's transaction
history remains private, and that the exchange can be audited by
financial regulators.  This paper describes the key protocols and
security properties of Taler, and shows how the system can be used to
provide change and refunds while maintaining anonymity for customers
and adequately balances the state's need for monetary control with the
citizen's needs for private economic activity.
\end{abstract}

\section{Introduction}

The design of payment systems shapes economies and societies.  Strong,
anonymous digital payment systems can empower citizens and provide
safeguards for civil liberties.  However, they also carry the danger
of facilitating tax evasion, money laundering, and other illicit
business.  This paper introduces {\em Taler}, a new digital payment
system that provides anonymity for customers, while ensuring that
merchants can be held accountable by governments.  Taler is thus
taxable and auditable, while still providing privacy for customers.
Taler is efficient, as it does not require expensive proof-of-work
calculations.  Taler is practical, as it can be incrementally deployed
and does not require a global consensus on a transaction history.
Taler is secure, as it uses modern cryptography and does not require
customers to risk their financial details.  Taler is libre, as it is
free software that can be studied, modified and run by anyone.  Taler
provides fair exchange and exculpability via cryptographic proofs.

\section{Related Work}