Dec 2025· IEEE Transactions on Networking· Vol 34, pp. 6502-6515· 0 citations· 44 references
Computer Science
TL;DR
A flexible credential model that employs vector commitments with a padding strategy to unify credentials from heterogeneous issuers, enabling privacy-preserving authentication without enforcing a global static attribute set or verifier-defined policies is proposed.
Abstract
Anonymous credentials (ACs) are a crucial cryptographic tool for privacy-preserving authentication in decentralized networks, allowing holders to prove eligibility without revealing their identity. However, a major limitation of standard ACs is the disclosure of the issuer’s identity, which can leak sensitive contextual information about the holder. Issuer-hiding ACs address this by making a credential’s origin indistinguishable among a set of issuers. Despite this advancement, existing solutions suffer from practical limitations that hinder their deployment in decentralized environments: inflexible credential models that restrict issuer and holder autonomy, flawed revocation mechanisms that compromise security, and weak attribute hiding that fails to meet data minimization principles. This paper introduces a new scheme called IRAC to overcome these challenges. We propose a flexible credential model that employs vector commitments with a padding strategy to unify credentials from heterogeneous issuers, enabling privacy-preserving authentication without enforcing a global static attribute set or verifier-defined policies. Furthermore, we design a secure decentralized revocation mechanism where holders prove non-revocation by demonstrating their credential’s hash lies within a gap in the issuer’s sorted revocation list while maintaining issuer anonymity. IRAC also strengthens attribute hiding by utilizing zk-SNARKs and vector commitments, allowing holders to prove statements about their attributes without disclosing the attributes themselves or the credential structure. Security analysis and performance evaluations demonstrate its practical feasibility for decentralized networks, where a credential presentation can be generated within 1 second.
The rapid growth of digital services has increased the demand for identity systems that provide strong authentication while minimizing unnecessary disclosure of personal information. Conventional identity management architectures generally depend on centralized identity providers and frequently require users to disclose complete identity attributes even when a service requires only a limited assertion. Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) provide an alternative model in which identity holders can manage cryptographically verifiable credentials independently of a centralized identity provider. However, the privacy guarantees of decentralized identity systems depend substantially on the cryptographic proof mechanism used during credential presentation.
Zero-Knowledge Proofs (ZKPs) enable a prover to demonstrate knowledge of a secret or the validity of a statement without revealing the underlying secret. Different ZKP and selective-disclosure mechanisms exhibit significantly different characteristics with respect to proof size, generation time, verification time, communication overhead, computational requirements, privacy guarantees, interoperability, and implementation complexity. Consequently, selecting a single proof mechanism for every decentralized identity scenario can result in unnecessary computational cost or inadequate privacy protection.
This paper proposes an Adaptive ZKP Selection Framework (AZSF) for privacy-preserving decentralized identity using DIDs and Verifiable Credentials. The framework dynamically selects an appropriate proof mechanism according to the privacy sensitivity of requested attributes, disclosure requirements, verifier trust conditions, computational resources, proof-generation latency, communication constraints, interoperability requirements, and unlinkability requirements. The proposed architecture introduces a policy-driven decision layer between the credential wallet and proof-generation subsystem. It evaluates candidate mechanisms including selective-disclosure signatures, BBS-based proofs, SD-JWT-based selective disclosure, and general-purpose succinct zero-knowledge proof systems such as zk-SNARK/PLONK-style approaches.
A formal multi-criteria decision model is developed to represent the selection process. The framework defines privacy, performance, communication, interoperability, and deployment criteria and computes an adaptive suitability score for each candidate proof mechanism. A threat model covering credential theft, replay, correlation, malicious verifiers, issuer compromise, metadata leakage, and proof substitution is presented. The paper further proposes an experimental methodology for evaluating proof generation time, verification time, proof size, communication overhead, privacy leakage, unlinkability, and resource consumption. The proposed framework provides a systematic foundation for choosing cryptographic proof mechanisms according to application requirements instead of adopting a one-size-fits-all approach.
Index Terms— Decentralized Identity, Decentralized Identifiers, Verifiable Credentials, Zero-Knowledge Proofs, Privacy-Preserving Identity, Selective Disclosure, BBS Signatures, SD-JWT, Self-Sovereign Identity, Privacy Engineering, Adaptive Cryptography.
Sanchita Shukla· International Journal of Cre...· 0 citations
Threshold attribute-based anonymous credentials improve the security of traditional credentials systems by distributing the power of credential issuance across multiple independent issuers, and have attracted widespread attention, particularly for decentralized systems such as blockchain. However, existing solutions still exhibit shortcomings in terms of scalability, security, flexibility, and practicality. In this paper, we introduce EDT-ABC, an expressive dynamic threshold attribute-based anonymous credential system with succinct showing. Specifically, EDT-ABC allows each issuer to generate the secret key independently without relying on distributed key generation protocols or a trusted party. The thresholds can be dynamically adjusted, enabling verifiers to flexibly define thresholds for different services. Meanwhile, EDT-ABC achieves more expressive and practical selective disclosure by supporting non-possession proofs. By putting forth two novel primitives called universal set commitments and structure-preserving multi-signatures on equivalence classes with randomizable tags, which may both be of independent interest, we design a generic construction of EDT-ABC with provable security and provide an efficient instantiation. Comprehensive performance evaluation on personal computer and Raspberry Pi demonstrates that, compared to existing solutions, our EDT-ABC decreases the running time for issuing and showing the credentials by at least 67.44% and 28.78%, respectively, while achieving a token size reduction of over 82.10%.
Hang Liu, Mingshuai Yang, Chenhao Wang et al.· IEEE Transactions on Informa...· 0 citations
Attribute-Based Credentials (ABCs) are cryptographic credential systems that enable holders to selectively disclose certified attributes or prove predicates over them, thereby supporting privacy-preserving identity verification while limiting unnecessary information exposure. This paper presents a review of the system model, core security and privacy properties, classification, comparative analysis, and practical deployment challenges of ABCs. It develops a two-dimensional taxonomy consisting of a construction dimension and an extension dimension. The construction dimension covers publicly verifiable signature-based, keyed-verification and MAC-based, and general-purpose ZKP-based ABC constructions, while the extension dimension covers issuer-hiding, threshold and multi-authority, and dynamic-lifecycle ABCs. The resulting comparison shows that these categories exhibit different trade-offs in verifier openness, proof flexibility, privacy guarantees, trust requirements, lifecycle support, and practical deployment requirements. The review further examines key challenges related to the efficiency and scalability of multi-attribute management, privacy-preserving credential lifecycle management, inference risks in selective disclosure, interoperability, post-quantum security, and holder binding. Finally, it synthesizes recent trends and identifies research directions toward efficient, interoperable, privacy-preserving, and practically deployable ABC systems that strengthen digital trust and support trustworthy digital identity infrastructures.
A flexible privacy-preserving framework that combines the scalability of broadcast encryption with the fine-grained access control of Attribute-Based Encryption through a novel pseudo-layer encryption model, and achieves confidentiality, forward and backward secrecy, and collusion resistance.
Seyyed Mohammad Safi, Mahnaz Rafie, Sarina Sadat Mirmohammadi· Journal of Supercomputing· 0 citations
A privacy model for searchable symmetric encryption protocols that makes adversarial power a central parameter and induces four privacy levels giving rise to a privacy lattice is proposed, enabling reasoning about how privacy guarantees change under different adversarial capabilities.
Manuela Horduna· International Conference on...· 0 citations
PEACE is presented, an authentication mechanism for blockchains that combines the practicality of traditional Web systems with decentralization and privacy-preservation, building on a recent groundbreaking zkLogin protocol.
Stefan Dziembowski, Shahriar Ebrahimi, Paweł K. ̨edzior et al.· International Conference on...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.