Paper 2025/1995

Device-Bound Anonymous Credentials With(out) Trusted Hardware

Karla Friedrichs, Hasso Plattner Institute
Franklin Harding, Brown University
Anja Lehmann, Hasso Plattner Institute
Anna Lysyanskaya, Brown University
Abstract

Anonymous credentials enable unlinkable and privacy-preserving user authentication. To ensure non-transferability of credentials among corrupt users, they can additionally be device-bound. Therein, a credential is tied to a key protected by a secure element (SE), usually a hardware component, and any presentation of the credential requires a fresh contribution of the SE. Interestingly, despite being a fundamental aspect of user credentials, device binding for anonymous credentials is relatively unstudied. Existing constructions either require multiple calls to the SE, or need the SE to keep a credential-specific state -- violating core design principles of shielded SEs. Further, constructions that are compatible with the most mature credential scheme BBS rely on the honesty of the SE for privacy, which is hard to vet given that SEs are black-box components. In this work, we thoroughly study and solve the problem of device-bound anonymous credentials (DBACs). We model DBACs to ensure the unforgeability and non-transferability of credentials, and to guarantee user privacy at the same time. Our definitions cover a range of SE trust levels, including the case of a subverted or fully corrupted SE. We also define blind DBACs, in which the SE learns nothing about the credential presentations it helped compute. This targets the design of a remote, cloud-based SE which is a deployment model considered for the EU Digital Identity (EUDI) wallet to address the fact that most user phones are not equipped with a sufficiently secure SE. Finally, we present three simple and round-optimal constructions for device binding of BBS credentials, and prove their security in the AGM+ROM and privacy unconditionally. The SE therein is extremely lightweight: it only has to compute a BLS or Schnorr signature in a single call. We also give the BLS-based construction in a blind variant, yielding the first protocol that enables privacy-preserving device binding for anonymous credentials when being used with a remote SE.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in EUROCRYPT 2026
Keywords
Device BindingAnonymous CredentialsBBS Signatures
Contact author(s)
karla friedrichs @ hpi de
franklin_harding @ brown edu
anja lehmann @ hpi de
anna_lysyanskaya @ brown edu
History
2026-07-01: last of 3 revisions
2025-10-24: received
See all versions
Short URL
https://ia.cr/2025/1995
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1995,
      author = {Karla Friedrichs and Franklin Harding and Anja Lehmann and Anna Lysyanskaya},
      title = {Device-Bound Anonymous Credentials With(out) Trusted Hardware},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1995},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1995}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.