Doubly Aggregatable Signatures
Georg Fuchsbauer, Pranav Garimidi, Joachim Neu, Guru-Vamsi Policharla, Max Resnick, Ertem Nusret Tas
摘要
Attribute-based anonymous credentials offer users fine-grained access control in a privacy-preserving manner. However, in such schemes obtaining a user's credentials requires knowledge of the issuer's public key, which obviously reveals the issuer's identity that must be hidden from users in certain scenarios. Moreover, verifying a user's credentials also requires the knowledge of issuer's public key, which may infer the user's private information from their choice of issuer. In this article, we introduce the notion of double issuer-hiding attribute-based credentials (<inline-formula><tex-math notation="LaTeX"></tex-math><alternatives>mml:math<mml:mi mathvariant="sans-serif">DIHAC</mml:mi></mml:math><inline-graphic xlink:href="yang-ieq1-3314019.gif"/></alternatives></inline-formula>) to tackle these two problems. In our model, a central authority can issue public-key credentials for a group of issuers, and users can obtain attribute-based credentials from one of the issuers without knowing which one it is. Then, a user can prove that their credential was issued by one of the authenticated issuers without revealing which one to a verifier. We provide a generic construction, as well as a concrete instantiation for <inline-formula><tex-math notation="LaTeX"></tex-math><alternatives>mml:math<mml:mi mathvariant="sans-serif">DIHAC</mml:mi></mml:math><inline-graphic xlink:href="yang-ieq2-3314019.gif"/></alternatives></inline-formula> based on structure-preserving signatures on equivalence classes (JOC's 19) and a novel primitive which we call <inline-formula><tex-math notation="LaTeX"></tex-math><alternatives>mml:mathmml:mrowmml:mit</mml:mi>mml:mia</mml:mi>mml:mig</mml:mi></mml:mrow></mml:math><inline-graphic xlink:href="yang-ieq3-3314019.gif"/></alternatives></inline-formula>-<inline-formula><tex-math notation="LaTeX"></tex-math><alternatives>mml:mathmml:mrowmml:mib</mml:mi>mml:mia</mml:mi>mml:mis</mml:mi>mml:mie</mml:mi>mml:mid</mml:mi></mml:mrow></mml:math><inline-graphic xlink:href="yang-ieq4-3314019.gif"/></alternatives></inline-formula> <inline-formula><tex-math notation="LaTeX"></tex-math><alternatives>mml:mathmml:mrowmml:mia</mml:mi>mml:mig</mml:mi>mml:mig</mml:mi>mml:mir</mml:mi>mml:mie</mml:mi>mml:mig</mml:mi>mml:mia</mml:mi>mml:mit</mml:mi>mml:mia</mml:mi>mml:mib</mml:mi>mml:mil</mml:mi>mml:mie</mml:mi></mml:mrow></mml:math><inline-graphic xlink:href="yang-ieq5-3314019.gif"/></alternatives></inline-formula> <inline-formula><tex-math notation="LaTeX"></tex-math><alternatives>mml:mathmml:mrowmml:mim</mml:mi>mml:mie</mml:mi>mml:mir</mml:mi>mml:mic</mml:mi>mml:miu</mml:mi>mml:mir</mml:mi>mml:mii</mml:mi>mml:mia</mml:mi>mml:mil</mml:mi></mml:mrow></mml:math><inline-graphic xlink:href="yang-ieq6-3314019.gif"/></alternatives></inline-formula> <inline-formula><tex-math notation="LaTeX"></tex-math><alternatives>mml:mathmml:mrowmml:mis</mml:mi>mml:mii</mml:mi>mml:mig</mml:mi>mml:min</mml:mi>mml:mia</mml:mi>mml:mit</mml:mi>mml:miu</mml:mi>mml:mir</mml:mi>mml:mie</mml:mi>mml:mis</mml:mi></mml:mrow></mml:math><inline-graphic xlink:href="yang-ieq7-3314019.gif"/></alternatives></inline-formula>. Our construction is efficient without relying on zero-knowledge proofs. We provide rigorous evaluations on personal laptop and smartphone platforms, respectively, to demonstrate its practicability.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- Fractal: Post-quantum and Transparent Recursive Proofs from HolographyAlessandro Chiesa, Dev Ojha, Nicholas SpoonerEUROCRYPT 2020 · 被引用 162 次
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 被引用 147 次
- Halo Infinite: Proof-Carrying Data from Additive Polynomial CommitmentsDan Boneh, Justin Drake, Ben Fisch, Ariel GabizonCRYPTO 2021 · 被引用 62 次
- Threshold and Multi-signature Schemes from Linear Hash FunctionsStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 被引用 48 次
- hinTS: Threshold Signatures with Silent SetupSanjam Garg, Abhishek Jain, Pratyay Mukherjee, Rohit Sinha 等S&P 2024 · 被引用 48 次
相关 Paper
- Aggregate Signatures with Versatile Randomization and Issuer-Hiding Multi-Authority Anonymous CredentialsOmid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya 等CCS 2023 · 被引用 29 次
- With a Little Help from My Friends: Constructing Practical Anonymous CredentialsLucjan Hanzlik, Daniel SlamanigCCS 2021 · 被引用 52 次
- Practical UC-Secure Delegatable Credentials with Attributes and Their Application to BlockchainJan Camenisch, Manu Drijvers, Maria DubovitskayaCCS 2017 · 被引用 76 次
- Ring Referral: Efficient Publicly Verifiable Ad hoc Credential Scheme with Issuer and Strong User Anonymity for Decentralized Identity and MoreThe-Anh Ta, Xiangyu Hui, Sid Chi-Kin ChauS&P 2025
- zk-creds: Flexible Anonymous Credentials from zkSNARKs and Existing Identity InfrastructureMichael Rosenberg, Jacob D. White, Christina Garman, Ian MiersS&P 2023
