Security Analysis of Privately Verifiable Privacy Pass
Konrad Hanff, Anja Lehmann, Cavit Özbay
Abstract
Privacy Pass is an anonymous authentication protocol which was initially designed by Davidson et al. (PETS'18) to reduce the number of CAPTCHAs that TOR users must solve. It issues single-use authentication tokens with anonymous and unlinkable redemption guarantees. The issuer and verifier of the protocol share a symmetric key, and tokens are privately verifiable. The protocol has sparked interest from both academia and industry, which led to an Internet Engineering Task Force (IETF) standard. While Davidson et al. formally analyzed the original protocol, the IETF standard introduces several changes to their protocol. Thus, the standardized version's formal security remains unexamined. We fill this gap by analyzing the IETF standard's privately verifiable Privacy Pass protocol.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3081583d-3933-4b1d-a726-18c12ab36d9aBuilds on6
- Anonymous Tokens with Private Metadata BitBen Kreuter, Tancrède Lepoint, Michele Orrù, Mariana RaykovaCRYPTO 2020 · 35 citations
- A Fast and Simple Partially Oblivious PRF, with ApplicationsNirvan Tyagi, Sofía Celi, Thomas Ristenpart, Nick Sullivan et al.EUROCRYPT 2022 · 28 citations
- The 2Hash OPRF Framework and Efficient Post-quantum InstantiationsWard Beullens, Lucas Dodgson, Sebastian H. Faller, Julia HesseEUROCRYPT 2025 · 14 citations
- Anonymous Tokens with Stronger Metadata Bit Hiding from Algebraic MACsMelissa Chase, F. Betül Durak, Serge VaudenayCRYPTO 2023 · 12 citations
- Non-Transferable Anonymous Tokens by Secret BindingF. Betül Durak, Laurane Marco, Abdullah Talayhan, Serge VaudenayCCS 2024 · 6 citations
Related papers
- On the Security of Rate-limited Privacy PassHien Chu, Khue Do, Lucjan HanzlikCCS 2023 · 4 citations
- No Honor Among Crooks: Non-Transferable Anonymous Tokens from BetrayabilityDavid Kretzler, Yong LiS&P 2026
- Anonymous Tokens with Designated-Reader Metadata BitAisha Tu, Meng Jia, Kun He, Jing Chen et al.USENIX Security 2026
- Verifying Indistinguishability of Privacy-Preserving ProtocolsKirby Linvill, Gowtham Kaki, Eric WustrowOOPSLA 2023 · 2 citations
- Revisiting Keyed-Verification Anonymous CredentialsMichele OrrùCCS 2025
