On the Security of Rate-limited Privacy Pass
Hien Chu, Khue Do, Lucjan Hanzlik
Abstract
The privacy pass protocol allows users to redeem anonymously issued cryptographic tokens instead of solving annoying CAPTCHAs. The issuing authority verifies the credibility of the user, who can later use the pass while browsing the web using an anonymous or virtual private network. Hendrickson et al. proposed an IETF draft (privacypass-rate-limit-tokens-00) for a rate-limiting version of the privacy pass protocol, also called rate-limited Privacy Pass(RlP). Introducing a new actor called a mediator makes both versions inherently different. The mediator applies access policies to rate-limit users' access to the service while, at the same time, should be oblivious to the website/origin the user is trying to access. In this paper, we formally define the rate-limited Privacy Pass protocol and propose a game-based security model to capture the informal security notions introduced by Hendrickson et al.. We show a construction from simple building blocks that fulfills our security definitions and even allows for a post-quantum secure instantiation. Interestingly, the instantiation proposed in the IETF draft is a specific case of our construction. Thus, we can reuse the security arguments for the generic construction and show that the version used in practice is secure.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f4584045-e65a-4e81-93b0-89023373f8dcCited by top-tier papers1
Ask how each one uses itRelated papers
- Anonymous Tokens with Stronger Metadata Bit Hiding from Algebraic MACsMelissa Chase, F. Betül Durak, Serge VaudenayCRYPTO 2023 · 12 citations
- Anonymous Tokens with Private Metadata BitBen Kreuter, Tancrède Lepoint, Michele Orrù, Mariana RaykovaCRYPTO 2020 · 35 citations
- Non-Transferable Anonymous Tokens by Secret BindingF. Betül Durak, Laurane Marco, Abdullah Talayhan, Serge VaudenayCCS 2024 · 6 citations
- No Honor Among Crooks: Non-Transferable Anonymous Tokens from BetrayabilityDavid Kretzler, Yong LiS&P 2026
- Non-interactive Blind Signatures from RSA Assumption and MoreLucjan Hanzlik, Eugenio Paracucchi, Riccardo ZanottoEUROCRYPT 2025 · 4 citations
