Aggregate Signatures with Versatile Randomization and Issuer-Hiding Multi-Authority Anonymous Credentials
Omid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya, Daniel Slamanig
Abstract
Anonymous credentials (AC) offer privacy in user-centric identity management. They enable users to authenticate anonymously, revealing only necessary attributes. With the rise of decentralized systems like self-sovereign identity, the demand for efficient AC systems in a decentralized setting has grown. Relying on conventional AC systems, however, require users to present independent credentials when obtaining them from different issuers, leading to increased complexity. AC systems should ideally support being multi-authority for efficient presentation of multiple credentials from various issuers. Another vital property is issuer hiding, ensuring that the issuer's identity remains concealed, revealing only compliance with the verifier's policy. This prevents unique identification based on the sole combination of credential issuers. To date, there exists no AC scheme satisfying both properties simultaneously. This paper introduces Issuer-Hiding Multi-Authority Anonymous Credentials (IhMA), utilizing two novel signature primitives: Aggregate Signatures with Randomizable Tags and Public Keys and Aggregate Mercurial Signatures. We provide two constructions of IhMA with different trade-offs based on these primitives and believe that they will have applications beyond IhMA. Besides defining the notations and rigorous security definitions for our primitives, we provide provably secure and efficient constructions, and present benchmarks to showcase practical efficiency. CCS CONCEPTS • Security and privacy → Cryptography; Privacy-preserving protocols.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c66075d0-ea8a-44c0-a4cc-17e86654a574Cited by top-tier papers1
Ask how each one uses itBuilds on8
- Coconut: Threshold Issuance Selective Disclosure Credentials with Applications to Distributed LedgersAlberto Sonnino, Mustafa Al-Bassam, Shehar Bano, Sarah Meiklejohn et al.NDSS 2019 · 218 citations
- Revisiting BBS SignaturesStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 58 citations
- One TPM to Bind Them All: Fixing TPM 2.0 for Provably Secure Anonymous AttestationJan Camenisch, Liqun Chen, Manu Drijvers, Anja Lehmann et al.S&P 2017 · 58 citations
- With a Little Help from My Friends: Constructing Practical Anonymous CredentialsLucjan Hanzlik, Daniel SlamanigCCS 2021 · 52 citations
- Anonymous Tokens with Private Metadata BitBen Kreuter, Tancrède Lepoint, Michele Orrù, Mariana RaykovaCRYPTO 2020 · 35 citations
Related papers
- Doubly Aggregatable SignaturesGeorg Fuchsbauer, Pranav Garimidi, Joachim Neu, Guru-Vamsi Policharla et al.CCS 2026
- Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record CertificationKasra EdalatNejad, Sebastian Faust, Jonas Hofmann, Philipp-Florens Lehwalder et al.USENIX Security 2026 · 1 citation
- Practical UC-Secure Delegatable Credentials with Attributes and Their Application to BlockchainJan Camenisch, Manu Drijvers, Maria DubovitskayaCCS 2017 · 76 citations
- Multi-Holder Anonymous Credentials from BBS SignaturesAndrea Flamini, Eysa Lee, Anna LysyanskayaCRYPTO 2025 · 6 citations
- zk-creds: Flexible Anonymous Credentials from zkSNARKs and Existing Identity InfrastructureMichael Rosenberg, Jacob D. White, Christina Garman, Ian MiersS&P 2023
