Paper 2026/1855

Delegatable Anonymous Credentials from Legacy Credentials using Recursive zk-SNARKs

Leandro Rometsch, Hamburg University of Technology
Philipp-Florens Lehwalder, TU Darmstadt
Sebastian Faust, TU Darmstadt
Stefan Schulte, Technical University of Berlin
Abstract

Digital identity systems are becoming increasingly prevalent, driven by regulatory efforts such as the European Digital Identity (EUDI) Wallet. Yet these systems usually do not achieve strong privacy guarantees as offered by anonymous credentials, since they rely on standardized curves and widespread signature schemes like ECDSA that are incompatible with pairing-based primitives underpinning most anonymous credential constructions. Recent work bridges this gap by retrofitting such legacy credentials with anonymous-credential properties via zero-knowledge proofs, requiring no issuer-side modifications. However, none of these constructions supports delegation: the ability for users to pass on a restricted credential derived from their own to another party, while all parties along the delegation chain maintain full anonymity. Delegatable anonymous credentials (DACs) provide exactly these guarantees, but are likewise incompatible with existing deployments. We present the first DAC scheme built directly on top of legacy credentials. Our construction requires no issuance infrastructure changes, and yields constant-size credentials independent of delegation depth, with full unlinkability along the chain and selective attribute disclosure at every level. We instantiate it for credentials based on JSON Web Tokens (JWTs) signed with ECDSA using Plonky2 as the recursive proving backend, contributing a secure in-circuit JWT parser that closes vulnerabilities in prior work and a Plonky2 extension for cyclic recursion with per-step zero-knowledge. At 64 attributes, delegation takes 1.2 s and verification only 3.3 ms, with a constant proof size across all delegation levels

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
delegatable anonymous credentialsanonymous credentialsJWTECDSAzk-SNARKsrecursive zk-SNARKs
Contact author(s)
leandro rometsch @ tuhh de
philipp-florens lehwalder @ tu-darmstadt de
sebastian faust @ tu-darmstadt de
schulte @ tu-berlin de
History
2026-09-03: approved
2026-09-01: received
See all versions
Short URL
https://ia.cr/2026/1855
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1855,
      author = {Leandro Rometsch and Philipp-Florens Lehwalder and Sebastian Faust and Stefan Schulte},
      title = {Delegatable Anonymous Credentials from Legacy Credentials using Recursive zk-{SNARKs}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1855},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1855}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.