"..blinding is done by the customers, who blind their coins before transmitting them to the central bank for signature."
"..to be sure that the coin has not been copied and already redeemed by another payee (i.e., has not been “double-spent”), the merchant must deposit the coin so that the central bank can check the coin against a file of redeemed coins."
The paper claims that the CBDC is proposes is "a genuine digital bearer instrument" but to my mind, "a genuine digital bearer instrument" should not be entirely reliant on a centralized trusted third party.
Several years ago, we (the Zcash team) came up with a proposal for a wholesale CBDC for use by commercial banks, that has strong privacy protections (based on the zero-knowledge proofs-based protocol that underpins Zcash) that would prevent other CBDC users from being able to observe transaction details or balances, while allowing the central bank to monitor activity on the CBDC ledger. It's designed to sit alongside and provide a decentralized alternative/backup to existing RTGS systems (which would have been useful during the FedWire outage yesterday!). Several major central banks showed enough interest to sit through the presentation but nobody was interested in doing a proof-of-concept or a pilot. ¯\_(ツ)_/¯
You can see a diagram outlining how it would work here: https://twitter.com/JackGavigan/status/1364669769639690246