Blind Certificate Authorities
Liang Wang, Gilad Asharov, Rafael Pass, Thomas Ristenpart, Abhi Shelat
Abstract
We explore how to build a blind certificate authority (CA). Unlike conventional CAs, which learn the exact identity of those registering a public key, a blind CA can simultaneously validate an identity and provide a certificate binding a public key to it, without ever learning the identity. Blind CAs would therefore allow bootstrapping truly anonymous systems in which no party ever learns who participates. In this work we focus on constructing blind CAs that can bind an email address to a public key. To do so, we first introduce secure channel injection (SCI) protocols. These allow one party (in our setting, the blind CA) to insert a private message into another party's encrypted communications. We construct an efficient SCI protocol for communications delivered over TLS, and use it to realize anonymous proofs of account ownership for SMTP servers. Combined with a zero-knowledge certificate signing protocol, we build the first blind CA that allows Alice to obtain a X.509 certificate binding her email address alice@domain.com to a public key of her choosing without ever revealing ``alice'' to the CA. We show experimentally that our system works with standard email server implementations as well as Gmail.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get dee4dbf5-62a6-40f3-a97e-69f5c5e5bdf1Cited by top-tier papers2
- DECO: Liberating Web Data Using Decentralized Oracles for TLSFan Zhang, Deepak Maram, Harjasleen Malvai, Steven Goldfeder et al.CCS 2020 · 110 citations
- Finding Safety in Numbers with Secure Allegation EscrowsVenkat Arun, Aniket Kate, Deepak Garg, Peter Druschel et al.NDSS 2020
Related papers
- YouChoose: A Lightweight Anonymous Proof of Account OwnershipAarav Varshney, Prashant Agrawal, Mahabir Prasad JhanwarWWW 2026 · 1 citation
- Device-Bound Anonymous Credentials With(out) Trusted HardwareKarla Friedrichs, Franklin Harding, Anja Lehmann, Anna LysyanskayaEUROCRYPT 2026 · 1 citation
- Braid: Sybil-Resistant Decentralized Identity with Trustless Key Recovery and Non-Transferable Anonymous CredentialsRui Song, Tianyu Zheng, Shang Gao, Guyue Li et al.CCS 2026
- Sabot: Efficient and Strongly Anonymous Bootstrapping of Communication ChannelsChristoph Coijanovic, Laura Hetz, Kenneth G. Paterson, Thorsten StrufeCCS 2025
- Non-interactive Blind Signatures for Random MessagesLucjan HanzlikEUROCRYPT 2023 · 17 citations
