Paper 2026/1229

Invisible Traces: Subversion Attacks on Batch-Issued Credentials

Anna-Birgitta Burmeister, Hasso Plattner Institute, University of Potsdam
Anna Fennig, Hasso Plattner Institute, University of Potsdam
Andreas Franke, Hasso Plattner Institute, University of Potsdam
Karla Friedrichs, Hasso Plattner Institute, University of Potsdam
Anja Lehmann, Hasso Plattner Institute, University of Potsdam
Kurt-Kester Leißering, Hasso Plattner Institute, University of Potsdam
Konrad Letz, Hasso Plattner Institute, University of Potsdam
Cavit Özbay, Hasso Plattner Institute, University of Potsdam
Abstract

All EU member states are required to roll out a digital identity system - the European Digital Identity (EUDI) wallet - by the end of 2026. Strong privacy is at the core of the underlying regulation, which mandates the EUDI wallet to support selective disclosure and unlinkability. The wallet currently being developed relies on the batch issuance of one-time ECDSA credentials that sign attributes through individually salted hashes for selective disclosure. This solution is known to achieve only a weak form of unlinkability, where the credential issuer must be honest: a malicious issuer could trace users through the salted hashes it signs and the signature value itself. But such a tracing attack requires the issuer to store all signed data and communicate with the verifying parties for tracing, which can be argued to be too cumbersome or obvious to happen in reality. In this work, we therefore initiate the study of a more subtle type of subversion attacks. Therein, the issuer can deviate from the issuance protocol, with two goals: (i) enabling verifiers in possession of a short tracing key to de-anonymize users and (ii) keeping this deviation undetectable from users. We formalize unlinkability against such subversion attacks, and show that batch-issued credentials with salted hashes do not achieve that form of privacy. We present several undetectable subversion attacks against batch-issued ECDSA credentials and suggest lightweight mechanisms to provably mediate them.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
batch-issued credentialsunlinkabilityprivacysubversionEUDI
Contact author(s)
anna-birgitta burmeister @ student hpi de
anna fennig @ student hpi de
andreas franke @ student hpi de
karla friedrichs @ hpi de
anja lehmann @ hpi de
kurt leissering @ student hpi de
konrad letz @ student hpi de
cavit oezbay @ hpi de
History
2026-06-11: approved
2026-06-10: received
See all versions
Short URL
https://ia.cr/2026/1229
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1229,
      author = {Anna-Birgitta Burmeister and Anna Fennig and Andreas Franke and Karla Friedrichs and Anja Lehmann and Kurt-Kester Leißering and Konrad Letz and Cavit Özbay},
      title = {Invisible Traces: Subversion Attacks on Batch-Issued Credentials},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1229},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1229}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.