Paper 2026/389

Frontdoors, Not Backdoors: Accountable Anonymity for National Digital Identity

Shailesh Mishra, EPFL
Roxanne Chevalley, EPFL
Martin Burkhart, armasuisse
Bryan Ford, EPFL
Abstract

Anonymous credentials (ACs) let users prove identity claims with strong privacy guarantees, and national systems built on them $-$ EUDI and the Swiss e-ID $-$ go live soon. Due to these guarantees, however, AC systems cannot detect proof proxy attacks, where malicious users "lend" their identity by presenting their credentials on behalf of other users, exposing a fundamental gap between privacy and accountability. For instance, users could sell anonymous legal age proofs online and get away with it. This lack of accountability will act as an obstacle for AC adoption on grounds of "national safety", as exemplified by the recurring push towards chat control in the EU. Consequently, issuing authorities may well settle for less-than-ideal privacy guarantees of current solutions (e.g., batch issuance of one-show credentials). In this paper, we advocate the need for integrated accountability in ACs and introduce the cryptographic forensic trail (CFT). A CFT is a randomized encryption of a user's identity that they produce alongside each credential presentation; only when credential misuse, e.g., a proof proxy attack, is detected can the CFT be decrypted for accountability. The design of CFT is based on a legal process requiring probable cause for anonymity revocation. It enforces separation of powers between law enforcement, a judicial body, and a digital privacy advocate (NGO) using privacy-enhancing technologies. The protocol mimics checks and balances of a healthy democracy, in which neither law enforcement nor justice can track people as they will. Even if both branches colluded, the NGO can detect the misuse and block further use. We implement a prototype of CFT based on both hardware-compatible and zero-knowledge-friendly elliptic curves. Our evaluations show that CFT adds only $13-16\%$ computation overhead to credential shows on the user's end, indicating that deployment in smartphone wallets is within reach.

Note: - updated abstract

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
anonymous credentialsprivacyaccountabilityelectronic identity systems
Contact author(s)
shailesh mishra @ epfl ch
roxanne chevalley @ epfl ch
martin burkhart @ armasuisse ch
bryan ford @ epfl ch
History
2026-08-11: last of 3 revisions
2026-02-25: received
See all versions
Short URL
https://ia.cr/2026/389
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/389,
      author = {Shailesh Mishra and Roxanne Chevalley and Martin Burkhart and Bryan Ford},
      title = {Frontdoors, Not Backdoors: Accountable Anonymity for National Digital Identity},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/389},
      year = {2026},
      url = {https://eprint.iacr.org/2026/389}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.