Anonymous Tokens with Stronger Metadata Bit Hiding from Algebraic MACs
Melissa Chase, F. Betül Durak, Serge Vaudenay
Abstract
On the one hand, the web needs to be secured from malicious activities such as bots or DoS attacks; on the other hand, such needs ideally should not justify services tracking people’s activities on the web. Anonymous tokens provide a nice tradeoff between allowing an issuer to ensure that a user has been vetted and protecting the users’ privacy. However, in some cases, whether or not a token is issued reveals a lot of information to an adversary about the strategies used to distinguish honest users from bots or attackers. In this work, we focus on designing an anonymous token protocol between a client and an issuer (also a verifier) that enables the issuer to support its fraud detection mechanisms while preserving users’ privacy. This is done by allowing the issuer to embed a hidden (from the client) metadata bit into the tokens. We first study an existing protocol from CRYPTO 2020 which is an extension of Privacy Pass from PoPETs 2018; that protocol aimed to provide support for a hidden metadata bit, but provided a somewhat restricted security notion. We demonstrate a new attack, showing that this is a weakness of the protocol, not just the definition. In particular, the metadata bit hiding is weak in the setting where the attacker can redeem some tokens and get feedback on whether the bit extraction succeeded. We then revisit the formalism of anonymous tokens with private metadata bit, consider the more natural notion, and design a scheme which achieves it. In order to design this new secure protocol, we base our construction on algebraic MACs instead of PRFs. Our security definitions capture a realistic threat model where adversaries could, through direct feedback or side channels, learn the embedded bit when the token is redeemed. Finally, we compare our protocol with one of the CRYPTO 2020 protocols. We obtain 20% more efficient performance.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers4
- Non-interactive Anonymous Tokens with Private Metadata BitFoteini Baldimtsi, Lucjan Hanzlik, Quan Nguyen, Aayush YadavCCS 2026 · 5 citations
- sigma-rs: A Modular Approach for Keyed-Verification Anonymous CredentialsMichele Orrù, Lindsey Tulloch, Victor Snyder-Graf, Ian GoldbergUSENIX Security 2026 · 2 citations
- Anonymous Tokens with Designated-Reader Metadata BitAisha Tu, Meng Jia, Kun He, Jing Chen et al.USENIX Security 2026
- Security Analysis of Privately Verifiable Privacy PassKonrad Hanff, Anja Lehmann, Cavit ÖzbayCCS 2025
Related papers
- Anonymous Tokens with Private Metadata BitBen Kreuter, Tancrède Lepoint, Michele Orrù, Mariana RaykovaCRYPTO 2020 · 35 citations
- No Honor Among Crooks: Non-Transferable Anonymous Tokens from BetrayabilityDavid Kretzler, Yong LiS&P 2026
- On the Security of Rate-limited Privacy PassHien Chu, Khue Do, Lucjan HanzlikCCS 2023 · 4 citations
- Non-Transferable Anonymous Tokens by Secret BindingF. Betül Durak, Laurane Marco, Abdullah Talayhan, Serge VaudenayCCS 2024 · 6 citations
- zk-creds: Flexible Anonymous Credentials from zkSNARKs and Existing Identity InfrastructureMichael Rosenberg, Jacob D. White, Christina Garman, Ian MiersS&P 2023
