Paper 2026/2295
Context-Blind Device-Bound Anonymous Credentials from Signatures and Proofs
Abstract
Anonymous credentials enable privacy preserving authentication, but their transferability motivates binding each credential to a key protected by a secure element (SE). Such binding should preserve privacy even when the SE is remote or corrupted: every presentation must require fresh SE participation without revealing its context to the SE (Friedrichs et al., EC'26). Existing so called context-blind device-bound constructions rely on classical assumptions, whereas existing plausibly post-quantum anonymous credentials do not provide this functionality. We give a modular construction of context blind device-bound anonymous credentials from a position-binding vector commitment, a signature scheme, a round-optimal blind signature, and a non-interactive zero-knowledge argument. We prove correctness, one-more unforgeability, unlinkability against a colluding issuer, verifier, and fully corrupted SE, and SE-obliviousness. We instantiate the construction with the CAPSS framework (Feneuil and Rivain, TCHES'26), Griffin/Jive Merkle commitments, and an Aurora-based proof of the complete presentation relation. We benchmark this concrete instantiation in one representative setting with 16 attributes and four disclosed attributes. Our non optimized prototype produces a $214.65$ KB presentation proof and requires $13.18$ s for the user and $1.37$ s for verification on our benchmark platform. We complement this benchmark with published results to explore the proof-size/proving-time trade-offs offered by alternative transparent plausibly post-quantum proof systems for relations of comparable size. To the best of our knowledge, this is the first concrete construction and evaluation of context-blind device-bound anonymous credentials assembled entirely from plausibly post-quantum components.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- Anonymous credentialsDevice bindingPost-Quantum Cryptography
- Contact author(s)
-
mark manulis @ unibw de
alan pulval-dady @ unibw de
daniel slamanig @ unibw de
davewittig @ t-online de - History
- 2026-10-04: approved
- 2026-10-01: received
- See all versions
- Short URL
- https://ia.cr/2026/2295
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2295,
author = {Mark Manulis and Alan Pulval-Dady and Daniel Slamanig and Dave Wittig},
title = {Context-Blind Device-Bound Anonymous Credentials from Signatures and Proofs},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2295},
year = {2026},
url = {https://eprint.iacr.org/2026/2295}
}