Paper 2026/2246

Binding Humans to Keys: A Secure Decentralized Proof of Personhood Protocol

Bilel Zaghdoudi, Sorbonne University
Gewu BU, Université Clermont Auvergne, Clermont Auvergne INP
Frederic Hayek, Antonine University
Pascal Lafourcade, Université Clermont Auvergne, Clermont Auvergne INP
Maria Potop-Butucaru, Sorbonne University
Abstract

Decentralised proof of personhood, cryptographically binding a digital identity to a unique living human without a trusted central authority, is a foundational problem in permissionless networks. We present a novel protocol, Secure-GYID (S-GYID), resilient to Identity Theft Attack (i.e., adversarial authorities substitute a victim's biometric fingerprint under a malicious public key) and Ghost Key Attack (i.e., colluding authorities fabricate a registration for a non-existent user). Our protocol closes both vulnerabilities by replacing raw biometric transmission with an encryption-based digital fingerprint derivation $F = E(pk_u, P_u)$ computed under a one-way, chosen-plaintext-secure, deterministic scheme, so that no authority can substitute or forge a binding pair without knowledge of the user's secret key. S-GYID further introduces a three-stratum generational authority hierarchy with bounded tenure and VRF-based session selection to limit long-term collusion structurally. We prove Identity Theft Resistance, Biometric Detectability, and Ghost Key Resistance under standard cryptographic assumptions, and provide a hypergeometric session-capture analysis that establishes concrete parameter design rules for both the key activation and authority promotion thresholds.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
Distributed IdentityProof of PersonhoodSecurity Analysis
Contact author(s)
bilel zaghdoudi @ lip6 fr
gewu bu @ uca fr
frederic hayek @ ext uca fr
pascal lafourcade @ uca fr
maria potop-butucaru @ lip6 fr
History
2026-09-30: approved
2026-09-28: received
See all versions
Short URL
https://ia.cr/2026/2246
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2246,
      author = {Bilel Zaghdoudi and Gewu BU and Frederic Hayek and Pascal Lafourcade and Maria Potop-Butucaru},
      title = {Binding Humans to Keys: A Secure Decentralized Proof of Personhood Protocol},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2246},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2246}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.