Paper 2025/1724

Efficient Aggregate Anonymous Credentials for Decentralized Identity

Rebekah Mercer
Kaoutar El Khiyaoui
Angelo De Caro
Elli Androulaki
Abstract

Anonymous credential schemes allow users to prove claims about themselves in a privacy-preserving manner. Put simply, a user can prove that she has an attribute value (e.g., she is a citizen) without revealing any other information about herself. Traditional schemes (including those with multiple credential issuers) operate under the assumption that each recognized issuer produces credentials for all user attributes. This assumption, however, is not practical: in the real world, no such issuer exists; an identity provider today issues a user credentials for a subset of user attributes, not all. A promising approach to support this setting is aggregate anonymous credentials, which allow a user to receive credentials from several issuers such that she can aggregate them and prove various claims about her attribute values in one shot. In this paper, we first introduce what we call aggregate tag-based signatures and describe an efficient instantiation. We then leverage the latter together with structure-preserving signatures and signatures of knowledge to construct an efficient aggregate anonymous credential scheme. We finally, formally evaluate the security of the proposed schemes and run benchmarks to showcase the practicality of the resulting scheme and its relevance for decentralized identity applications.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
anonymous credentialsaggregate signatures
Contact author(s)
rebekah mercer @ ibm com
History
2025-11-25: revised
2025-09-22: received
See all versions
Short URL
https://ia.cr/2025/1724
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1724,
      author = {Rebekah Mercer and Kaoutar El Khiyaoui and Angelo De Caro and Elli Androulaki},
      title = {Efficient Aggregate Anonymous Credentials for Decentralized Identity},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1724},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1724}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.