Paper 2026/1648

Deniability for Signed Credentials: Revisiting the Authenticated Channel vs. Signed Data Debate in the EUDI Wallet

Magdalena Bertram, Fraunhofer AISEC
Anja Lehmann, Hasso Plattner Institute
Abstract

The European Digital Identity Wallet (EUDI Wallet) is currently adopting ECDSA-based signed credentials as part of its core architecture, which raised concerns that such designs inherently lack plausible deniability compared to authenticated-channel approaches such as the German electronic identity card. This paper revisits this perceived trade-off and argues that it is not a property of signature schemes themselves, but of the credential presentation protocol. We show that standard cryptographic techniques - specifically lightweight OR-proofs over the native ECDSA verification equation - can be used to transform signed credential presentations into non-transferable, verifier-bound transcripts. Our contribution is not a new cryptographic primitive, but a careful instantiation of well-established techniques within the EUDI context, showing that deniability can be added to signed credentials while preserving their deployment advantages.

Note: This is an extended version of a paper accepted for publication in \emph{Availability, Reliability and Security --- ARES 2026 Workshops}, Lecture Notes in Computer Science, vol.~16900, Springer Nature. This version includes full security proofs as additional material.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Major revision. Availability, Reliability and Security - ARES 2026 Workshops, LNCS vol. 16900, Springer
Contact author(s)
magdalena bertram @ aisec fraunhofer de
anja lehmann @ hpi de
History
2026-08-15: approved
2026-08-10: received
See all versions
Short URL
https://ia.cr/2026/1648
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1648,
      author = {Magdalena Bertram and Anja Lehmann},
      title = {Deniability for Signed Credentials: Revisiting the Authenticated Channel vs. Signed Data Debate in the {EUDI} Wallet},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1648},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1648}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.