USENIX Security2023Top-tier venue
How to Bind Anonymous Credentials to Humans
Julia Hesse, Nitin Singh, Alessandro Sorniotti
Abstract
Digital and paper-based authentication are the two predominant mechanisms that have been deployed in the real world to authenticate end-users. When verification of a digital credential is performed in person (e.g. the authentication that was often required to access facilities at the peak of the COVID global pandemic), the two mechanisms are often deployed together: the verifier checks government-issued ID to match the picture on the ID to the individual holding it, and then checks the digital credential to see that the personal details on it match those on the ID and to discover additional attributes of the holder. This pattern is extremely common and very likely to remain in place for the foreseeable future. However, it poses an interesting problem: if the digital credential is privacy-preserving (e.g. based on BBS+ on CL signatures), but the holder is still forced to show an ID card or a passport to verify that the presented credential was indeed issued to the holder, what is the point of deploying privacy-preserving digital credential? In this paper we address this problem by redefining what an ID card should show and force a minimal but mandatory involvement of the card in the digital interaction. Our approach permits verifiers to successfully authenticate holders and to determine if they are the rightful owners of the digital credential. At the same time, optimal privacy guarantees are preserved. We design our scheme, formally define and analyse its security in the Universal Composability (UC) framework, and implement the card component, showing the running time to be below 200ms irrespective of the number of certified attributes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 403a68ca-8c0e-4b11-b8fe-1f50c5cf53baCited by top-tier papers1
Ask how each one uses itBuilds on4
- Coconut: Threshold Issuance Selective Disclosure Credentials with Applications to Distributed LedgersAlberto Sonnino, Mustafa Al-Bassam, Shehar Bano, Sarah Meiklejohn et al.NDSS 2019 · 218 citations
- Practical UC-Secure Delegatable Credentials with Attributes and Their Application to BlockchainJan Camenisch, Manu Drijvers, Maria DubovitskayaCCS 2017 · 76 citations
- With a Little Help from My Friends: Constructing Practical Anonymous CredentialsLucjan Hanzlik, Daniel SlamanigCCS 2021 · 52 citations
- Threshold BBS+ Signatures for Distributed Anonymous Credential IssuanceJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi Shelat et al.S&P 2023
Related papers
- Strong Authentication without Temper-Resistant Hardware and Application to Federated IdentitiesZhenfeng Zhang, Yuchen Wang, Kang YangNDSS 2020
- Fast IDentity Online with Anonymous Credentials (FIDO-AC)Wei-Zhu Yeoh, Michal Kepkowski, Gunnar Heide, Dali Kaafar et al.USENIX Security 2023
- FeIDo: Recoverable FIDO2 Tokens Using Electronic IDsFabian Schwarz, Khue Do, Gunnar Heide, Lucjan Hanzlik et al.CCS 2022 · 9 citations
- zk-creds: Flexible Anonymous Credentials from zkSNARKs and Existing Identity InfrastructureMichael Rosenberg, Jacob D. White, Christina Garman, Ian MiersS&P 2023
- Device-Bound Anonymous Credentials With(out) Trusted HardwareKarla Friedrichs, Franklin Harding, Anja Lehmann, Anna LysyanskayaEUROCRYPT 2026 · 1 citation
