Non-Transferable Anonymous Tokens by Secret Binding
Non-transferability (NT) is a security notion which ensures that credentials are only used by their intended owners. Despite its importance, it has not been formally treated in the context of anonymous tokens (AT) which are lightweight anonymous cre- dentials. In this work, we consider a client who “buys” access to- kens which are forbidden to be transferred although anonymously redeemed. We extensively study the trade-offs between privacy (ob- tained through anonymity) and security in AT through the notion of non-transferability. We formalise new security notions, design a suite of protocols with various flavors of NT, prove their security, and implement the protocols to assess their efficiency. Finally, we study the existing anonymous credentials which offer NT, and show that they cannot automatically be used as AT without security and complexity implications.
2024-12-09
New York, United States
979-8-4007-0636-3
2460
2474
REVIEWED
EPFL
Event name | Event acronym | Event place | Event date |
CCS'24 | Salt Lake Ciry, UT, USA | 2024-10-14 - 2024-10-18 | |