Practical UC-Secure Delegatable Credentials with Attributes and Their Application to Blockchain
Jan Camenisch, Manu Drijvers, Maria Dubovitskaya
Abstract
Certification of keys and attributes is in practice typically realized by a hierarchy of issuers. Revealing the full chain of issuers for certificate verification, however, can be a privacy issue since it can leak sensitive information about the issuer's organizational structure or about the certificate owner. Delegatable anonymous credentials solve this problem and allow one to hide the full delegation (issuance) chain, providing privacy during both delegation and presentation of certificates. However, the existing delegatable credentials schemes are not efficient enough for practical use. In this paper, we present the first hierarchical (or delegatable) anonymous credential system that is practical. To this end, we provide a surprisingly simple ideal functionality for delegatable credentials and present a generic construction that we prove secure in the UC model. We then give a concrete instantiation using a recent pairing-based signature scheme by Groth and describe a number of optimizations and efficiency improvements that can be made when implementing our concrete scheme. The latter might be of independent interest for other pairing-based schemes as well. Finally, we report on an implementation of our scheme in the context of transaction authentication for blockchain, and provide concrete performance figures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d205d2c0-71e9-40db-8185-388da4ced382Cited by top-tier papers4
- Lift-and-Shift: Obtaining Simulation Extractable Subversion and Updatable SNARKs GenericallyBehzad Abdolmaleki, Sebastian Ramacher, Daniel SlamanigCCS 2020 · 31 citations
- PriSrv: Privacy-Enhanced and Highly Usable Service Discovery in Wireless CommunicationsYang Yang, Robert H. Deng, Guomin Yang, Yingjiu Li et al.NDSS 2024
- How to Bind Anonymous Credentials to HumansJulia Hesse, Nitin Singh, Alessandro SorniottiUSENIX Security 2023
- Strong Authentication without Temper-Resistant Hardware and Application to Federated IdentitiesZhenfeng Zhang, Yuchen Wang, Kang YangNDSS 2020
Related papers
- Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record CertificationKasra EdalatNejad, Sebastian Faust, Jonas Hofmann, Philipp-Florens Lehwalder et al.USENIX Security 2026 · 1 citation
- Doubly Aggregatable SignaturesGeorg Fuchsbauer, Pranav Garimidi, Joachim Neu, Guru-Vamsi Policharla et al.CCS 2026
- k-out-of-n Proofs and Applications to Privacy-Preserving CryptocurrenciesMin Zhang, Yu Chen, Xiyuan FuEUROCRYPT 2026
- With a Little Help from My Friends: Constructing Practical Anonymous CredentialsLucjan Hanzlik, Daniel SlamanigCCS 2021 · 52 citations
- Aggregate Signatures with Versatile Randomization and Issuer-Hiding Multi-Authority Anonymous CredentialsOmid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya et al.CCS 2023 · 29 citations
