Paper 2025/1795
No Honor Among Crooks: Non-transferable Anonymous Tokens from Betrayability
Abstract
In anonymous token protocols, clients obtain access tokens by proving eligibility for the usage of a resource and later get access to the resource by redeeming the token. The server verifying eligibility and providing the resource cannot link the token issuance to its redemption. To prevent ineligible clients from accessing resources, it is crucial to prevent the transfer or sale of tokens. Durak et al. (CCS'24) propose binding tokens to valuable insurance secrets, which must be known to redeem the tokens. The value of the insurance secret deters the vendor from transferring the secret to the token buyer, who cannot redeem the token without the secret. However, the authors do not consider scenarios, where the token vendor assists the buyer during token redemption. Their construction, therefore, falls short to guarantee non-transferability when facing a vendor-aided token redemption. We address this gap by introducing the concept of anonymous tokens with betrayability. Our notion ensures that a token buyer, that is able to redeem a bought token, either knows the insurance secret or is able to betray the vendor in a vendor-aided redemption. The betrayal allows the buyer to steal the insurance secret without being detected. This way, we make the support in the token redemption equivalent to a transfer of the insurance secret and, hence, inherit the transfer deterrence of the insurance secret even when considering a vendor-aided token redemption. We formalize our new security notion, present a protocol for anonymous tokens with betrayability, prove its security, and provide an implementation and experimental evaluation.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Anonymous tokensNon-transferabilityBetrayability
- Contact author(s)
-
david kretzler @ huawei com
yong li1 @ huawei com - History
- 2025-10-08: approved
- 2025-10-01: received
- See all versions
- Short URL
- https://ia.cr/2025/1795
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2025/1795,
author = {David Kretzler and Yong Li},
title = {No Honor Among Crooks: Non-transferable Anonymous Tokens from Betrayability},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1795},
year = {2025},
url = {https://eprint.iacr.org/2025/1795}
}