Applications such as e-commerce payment protocols, elec-tronic contract signing, and certi¯ed e-mail delivery require that fair exchange be assured. A fair-exchange protocol al-lows two parties to exchange items in a fair way so that either each party gets the other's item, or neither party does. We describe a novel method of constructing very ef-¯cient fair-exchange protocols by distributing the computa-tion of RSA signatures. Speci¯cally, we employ multisig-natures based on the RSA-signature scheme. To date, the vast majority of fair-exchange protocols require the use of zero-knowledge proofs, which is the most computationally intensive part of the exchange protocol. Using the intrinsic features of our multisignature model, we constr...