Paper 2023/011

Using the RSA or RSA-B accumulator in anonymous credential schemes

Sietse Ringers
Abstract

We review the two RSA-based accumulators introduced by Camenisch and Lysyanskaya in 2002 in the setting of revocation for anonymous credential schemes, such as Idemix or BBS+. We show that in such a setting, the lower and upper bounds placed on the accumulated values in the paper are unnecessarily strict; they can be removed almost entirely (up to the group order of the credential scheme). This allows the accumulators to be used on elliptic curves of ordinary sizes, such as the ones on which BBS+ is commonly implemented. We also offer some notes and optimizations for implementations of anonymous credential schemes that use these accumulators to enable revocation.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
accumulatorsanonymous credentialselliptic curve cryptosystemIdemixBBS+
Contact author(s)
mail @ sietseringers net
History
2023-09-14: last of 5 revisions
2023-01-03: received
See all versions
Short URL
https://ia.cr/2023/011
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2023/011,
      author = {Sietse Ringers},
      title = {Using the RSA or RSA-B accumulator in anonymous credential schemes},
      howpublished = {Cryptology ePrint Archive, Paper 2023/011},
      year = {2023},
      note = {\url{https://eprint.iacr.org/2023/011}},
      url = {https://eprint.iacr.org/2023/011}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.