Paper 2025/430
Non-interactive Anonymous Tokens with Private Metadata Bit
Abstract
Anonymous tokens with private metadata bit (ATPM) have received increased interest as a method for anonymous user authentication while also allowing the issuer to embed trust signals inside the token that are only readable by the authority who holds the secret key. However, all existing ATPM protocols require interaction during issuance as the client must send a blinded request and wait for the issuer to sign, introducing latency and scalability bottlenecks. In this work, we present the first Non-interactive Anonymous Token (NIAT) scheme with a private metadata bit. Our design builds on structure-preserving signatures on equivalence classes (SPS-EQ) and recent advances in non-interactive blind signatures. With NIAT, tokens can be issued without any online interaction, enabling asynchronous pre-computation and drastically reducing issuer workload. We formalize NIAT security definitions, propose an efficient construction under standard assumptions and experimentally evaluate its performance. We also present an extension to our NIAT construction that allows the identification of clients who attempt to double-spend a token (i.e., present the same token twice) and argue that non-interactive schemes are uniquely positioned to offer this essential feature.
Note: The new version includes updated security definitions.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Minor revision. ACM CCS 2026 (to appear)
- Keywords
- anonoymous tokensnon-interactive protocolspairing-based cryptography
- Contact author(s)
-
foteini @ gmu edu
hanzlik @ cispa de
qnguye31 @ gmu edu
ayadav5 @ gmu edu - History
- 2026-08-20: last of 2 revisions
- 2025-03-06: received
- See all versions
- Short URL
- https://ia.cr/2025/430
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/430,
author = {Foteini Baldimtsi and Lucjan Hanzlik and Quan Nguyen and Aayush Yadav},
title = {Non-interactive Anonymous Tokens with Private Metadata Bit},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/430},
year = {2025},
url = {https://eprint.iacr.org/2025/430}
}