Paper 2026/2295

Context-Blind Device-Bound Anonymous Credentials from Signatures and Proofs

Mark Manulis, Research Institute CODE, Universität der Bundeswehr München
Alan Pulval-Dady, Research Institute CODE, Universität der Bundeswehr München
Daniel Slamanig, Research Institute CODE, Universität der Bundeswehr München
Dave Wittig, Universität der Bundeswehr München
Abstract

Anonymous credentials enable privacy preserving authentication, but their transferability motivates binding each credential to a key protected by a secure element (SE). Such binding should preserve privacy even when the SE is remote or corrupted: every presentation must require fresh SE participation without revealing its context to the SE (Friedrichs et al., EC'26). Existing so called context-blind device-bound constructions rely on classical assumptions, whereas existing plausibly post-quantum anonymous credentials do not provide this functionality. We give a modular construction of context blind device-bound anonymous credentials from a position-binding vector commitment, a signature scheme, a round-optimal blind signature, and a non-interactive zero-knowledge argument. We prove correctness, one-more unforgeability, unlinkability against a colluding issuer, verifier, and fully corrupted SE, and SE-obliviousness. We instantiate the construction with the CAPSS framework (Feneuil and Rivain, TCHES'26), Griffin/Jive Merkle commitments, and an Aurora-based proof of the complete presentation relation. We benchmark this concrete instantiation in one representative setting with 16 attributes and four disclosed attributes. Our non optimized prototype produces a $214.65$ KB presentation proof and requires $13.18$ s for the user and $1.37$ s for verification on our benchmark platform. We complement this benchmark with published results to explore the proof-size/proving-time trade-offs offered by alternative transparent plausibly post-quantum proof systems for relations of comparable size. To the best of our knowledge, this is the first concrete construction and evaluation of context-blind device-bound anonymous credentials assembled entirely from plausibly post-quantum components.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Anonymous credentialsDevice bindingPost-Quantum Cryptography
Contact author(s)
mark manulis @ unibw de
alan pulval-dady @ unibw de
daniel slamanig @ unibw de
davewittig @ t-online de
History
2026-10-04: approved
2026-10-01: received
See all versions
Short URL
https://ia.cr/2026/2295
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2295,
      author = {Mark Manulis and Alan Pulval-Dady and Daniel Slamanig and Dave Wittig},
      title = {Context-Blind Device-Bound Anonymous Credentials from Signatures and Proofs},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2295},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2295}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.