The self-blindable U-Prove scheme by Hanzlik and Kluczniak is forgeable.

Eric R. Verheul, Sietse Ringers, Jaap-Henk Hoepman · 2015

In [HK14] an unlinkable version of the U-Prove attribute-based credential scheme is proposed. Unfortunately, the new scheme is forgeable: if sufficiently many users work together then they can construct new credentials, containing any set of attributes of their choice, without any involvement of the issuer. In this note we show how they can achieve this and we point out the error in the unforgeability proof. 1

Read the paper · More papers on PaperTik