No Honor Among Crooks: Non-Transferable Anonymous Tokens from Betrayability
David Kretzler, Yong Li
Abstract
In anonymous token protocols, clients obtain access tokens by proving eligibility for the usage of a resource and later get access to the resource by redeeming the token. The server verifying eligibility and providing the resource cannot link the token issuance to its redemption. To prevent ineligible clients from accessing resources, it is crucial to prevent the transfer or sale of tokens. Durak et al. (CCS'24) propose binding tokens to valuable insurance secrets, which must be known to redeem the tokens. The value of the insurance secret deters the vendor from transferring the secret to the token buyer, who cannot redeem the token without the secret. However, the authors do not consider scenarios, where the token vendor assists the buyer during the token redemption. Their construction, therefore, falls short to guarantee non-transferability when facing a vendor-aided token redemption. We address this gap by introducing the concept of anonymous tokens with betrayability. Our notion ensures that a token buyer, that is able to redeem a bought token, either knows the insurance secret or is able to betray the vendor in a vendoraided redemption. The betrayal allows the buyer to steal the insurance secret without being detected. This way, we make the support in the token redemption equivalent to a transfer of the insurance secret and, hence, inherit the transfer deterrence of the insurance secret even when considering a vendor-aided token redemption. We formalize our new security notion, present a protocol for anonymous tokens with betrayability, prove its security, and provide an implementation and experimental evaluation.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 907619e2-018d-47a1-9b99-da467f9c9010Related papers
- Non-Transferable Anonymous Tokens by Secret BindingF. Betül Durak, Laurane Marco, Abdullah Talayhan, Serge VaudenayCCS 2024 · 6 citations
- Anonymous Tokens with Stronger Metadata Bit Hiding from Algebraic MACsMelissa Chase, F. Betül Durak, Serge VaudenayCRYPTO 2023 · 12 citations
- Anonymous Tokens with Designated-Reader Metadata BitAisha Tu, Meng Jia, Kun He, Jing Chen et al.USENIX Security 2026
- Security Analysis of Privately Verifiable Privacy PassKonrad Hanff, Anja Lehmann, Cavit ÖzbayCCS 2025
- Anonymous Tokens with Private Metadata BitBen Kreuter, Tancrède Lepoint, Michele Orrù, Mariana RaykovaCRYPTO 2020 · 35 citations
