Paper 2026/766

Dynamic Group Time-based One-time Passwords

Xuelian Cao, Southwest University
Zheng Yang, Southwest University
Jianting Ning, Fujian Normal University
Chenglu Jin, Centrum Wiskunde & Informatica, Amsterdam, Netherlands
Zhiming Liu, Southwest University
Jianying Zhou, Singapore University of Technology and Design
Abstract

Group time-based one-time passwords (GTOTP) is a novel lightweight cryptographic primitive for achieving anonymous client authentication, which enables the efficient generation of time-based one-time passwords on behalf of a group without revealing any information about the actual client's identity beyond their group membership. The security properties of GTOTP regarding anonymity and traceability have been formulated in a static group management setting (where all group members should be determined during the group initialization phase), yet, a formal treatment for real-world dynamic groups (i.e., group members may join and leave at any time) is still an open question. It is non-trivial to construct an efficient GTOTP scheme that can provide a lightweight password generation procedure run by group members and support dynamic group management, allowing group members to join and leave without affecting other members' states (non-disruptively). To address the above challenge, we first define the notion and the security model of dynamic group time-based one-time passwords (DGTOTP) in this work. We then present an efficient DGTOTP construction that can generically transform an asymmetric time-based one-time passwords scheme into a DGTOTP scheme utilizing a chameleon hash function family and a Merkle tree scheme. Within our construction, we particularly tailor an outsourcing solution realizing an issue-first-and-join-later (IFJL) strategy, enabling smooth joining and revocation without disrupting other group members. Moreover, our scheme minimizes symmetric cryptographic operations and maintains constant storage for group members, compared to the linear storage cost that grows rapidly with respect to the lifetime of the GTOTP instance in the previous static GTOTP scheme. Our DGTOTP scheme satisfies stronger security guarantees in a dynamic group management setting without random oracles. Our experimental results confirm the efficiency of our DGTOTP scheme.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published elsewhere. Major revision. IEEE Transactions on Information Forensics and Security
Keywords
Group Time-based One-Time PasswordsDynamic Group ManagementAnonymityTraceabilityAuthenticationSecurity Model
Contact author(s)
xueliancao7 @ email swu edu cn
youngzheng @ swu edu cn
jtning88 @ gmail com
chenglu jin @ cwi nl
Zhimingliu88 @ swu edu cn
jianying_zhou @ sutd edu sg
History
2026-04-21: approved
2026-04-18: received
See all versions
Short URL
https://ia.cr/2026/766
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/766,
      author = {Xuelian Cao and Zheng Yang and Jianting Ning and Chenglu Jin and Zhiming Liu and Jianying Zhou},
      title = {Dynamic Group Time-based One-time Passwords},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/766},
      year = {2026},
      url = {https://eprint.iacr.org/2026/766}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.