Paper 2026/570

iToken: One-Time-Use Anonymous Token with Issuance Hiding

Zengpeng Li, Shandong University
Xiangyu Su, Institute of Science Tokyo
Dongfang Wei, Shandong University
Guangyu Liao
Mei Wang, Shandong University
Abstract

Privacy-Enhancing Know Your Customer (KYC) integrates one-time-use anonymous tokens (OTATs) into self-sovereign identity frameworks, such as the EU Digital Identity (EUDI) Wallet, Apple’s Private Access Tokens, and W3C’s Privacy-Preserving Advertising proposals (e.g., Private State Tokens), to enable regulatory compliance while preserving user anonymity. To mitigate targeted denial-of-service (DoS) attacks and prevent token misuse (e.g., farming and replay), this paper designs a new OTAT, iToken, that first achieves issuer hiding not only at verification but also throughout issuance, thereby strengthening both OTAT’s resilience and user privacy. We introduce a new primitive, a canonical blind ring signature (BRS), that adopts a blind-and-ring pattern, ensuring the ring structure is present from the outset and is initiated by the signer within the interactive blind signing protocol. We also provide two generic constructions, one from a linear function (LF) and homomorphic encryption, and another from an LF and a commit-and-prove sum argument. We finally prototype BRS and iToken, achieving efficient signing bandwidth and competitive computational performance.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Anonymous TokenBlind Ring SignatureAuthorization
Contact author(s)
zengpengliz @ gmail com
su x 4029 @ m isct ac jp
202437117 @ mail sdu edu cn
guangyuliao1 @ gmail com
wangmeiz @ email sdu edu cn
History
2026-03-22: approved
2026-03-22: received
See all versions
Short URL
https://ia.cr/2026/570
License
Creative Commons Attribution-ShareAlike
CC BY-SA

BibTeX

@misc{cryptoeprint:2026/570,
      author = {Zengpeng Li and Xiangyu Su and Dongfang Wei and Guangyu Liao and Mei Wang},
      title = {{iToken}: One-Time-Use Anonymous Token with Issuance Hiding},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/570},
      year = {2026},
      url = {https://eprint.iacr.org/2026/570}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.