Paper 2008/539

An Accumulator Based on Bilinear Maps and Efficient Revocation for Anonymous Credentials

Jan Camenisch, Markulf Kohlweiss, and Claudio Soriente

Abstract

The success of electronic authentication systems, be it e-ID card systems or Internet authentication systems such as CardSpace, highly depends on the provided level of user-privacy. Thereby, an important requirement is an efficient means for revocation of the authentication credentials. In this paper we consider the problem of revocation for certificate-based privacy-protecting authentication systems. To date, the most efficient solutions for revocation for such systems are based on cryptographic accumulators. Here, an accumulate of all currently valid certificates is published regularly and each user holds a {\em witness} enabling her to prove the validity of her (anonymous) credential while retaining anonymity. Unfortunately, the users' witnesses must be updated at least each time a credential is revoked. For the know solutions, these updates are computationally very expensive for users and/or certificate issuers which is very problematic as revocation is a frequent event as practice shows. In this paper, we propose a new dynamic accumulator scheme based on bilinear maps and show how to apply it to the problem of revocation of anonymous credentials. In the resulting scheme, proving a credential's validity and updating witnesses both come at (virtually) no cost for credential owners and verifiers. In particular, updating a witness requires the issuer to do only one multiplication per addition or revocation of a credential and can also be delegated to untrusted entities from which a user could just retrieve the updated witness. We believe that thereby we provide the first authentication system offering privacy protection suitable for implementation with electronic tokens such as eID cards or drivers' licenses.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Full version of the paper accepted at PKC 2009
Keywords
dynamic accumulatorsanonymous credentialsrevocation
Contact author(s)
csorient @ ics uci edu
History
2008-12-28: received
Short URL
https://ia.cr/2008/539
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2008/539,
      author = {Jan Camenisch and Markulf Kohlweiss and Claudio Soriente},
      title = {An Accumulator Based on Bilinear Maps and Efficient Revocation for Anonymous Credentials},
      howpublished = {Cryptology {ePrint} Archive, Paper 2008/539},
      year = {2008},
      url = {https://eprint.iacr.org/2008/539}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.