Paper 2026/1189

Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record Certification

Kasra Edalatnejad, Technical University of Darmstadt
Sebastian Faust, Technical University of Darmstadt
Jonas Hofmann, Technical University of Darmstadt
Philipp-Florens Lehwalder, Technical University of Darmstadt
Thomas Schneider, Technical University of Darmstadt
Abstract

A key challenge in digital credential systems is revocation, that is, the ability to revoke credentials post-issuance and verify their status upon presentation. While anonymous credentials enhance privacy over classical credentials (e.g., by providing unlinkability), they complicate revocation. Existing revocation schemes for anonymous credentials often suffer from high client or verifier computation, long delays before revocation takes effect (e.g., epoch-based settings), or require updates to all users with each revocation. We present an efficient, real-time revocation system for anonymous credentials with decentralized revocation authorities based on a novel primitive called Private Record Certification (PRC). PRC enables users to obtain a certificate for a record stored in a server-managed database without the servers learning which record was requested. This primitive is of independent interest, and we construct it by combining techniques from private information retrieval and secure multi-party computation. Our revocation scheme outsources its costs to the revocation authorities and has minimal overhead for clients and verifiers, while ensuring the communication costs are sublinear in the number of credentials for the revocation authorities. We build a prototype and demonstrate that our system achieves sub-second real-time latency at a scale of over 1 billion credentials, with an online operational cost of 2.5$ per server for processing 1 million PRC queries.

Note: Added artifact appendix & updated references

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. USENIX Security 2026
Keywords
revocationanonymous credentialsmulti-party computationscalability
Contact author(s)
edalat @ encrypto cs tu-darmstadt de
sebastian faust @ tu-darmstadt de
jonas hofmann1 @ tu-darmstadt de
philipp-florens lehwalder @ tu-darmstadt de
schneider @ encrypto cs tu-darmstadt de
History
2026-08-12: revised
2026-06-06: received
See all versions
Short URL
https://ia.cr/2026/1189
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1189,
      author = {Kasra Edalatnejad and Sebastian Faust and Jonas Hofmann and Philipp-Florens Lehwalder and Thomas Schneider},
      title = {Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record Certification},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1189},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1189}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.