Composable Anonymous Credentials from Global Random Oracles

Manu Drijvers · Repository for Publications and Research Data (ETH Zurich) · 2018

Authentication is a key aspect of digital security.However, users must authenticate frequently and are often asked to reveal more information than neccessary in the process.Not only does this hurt the privacy of users, it also negatively impacts security, e.g., by increasing the risk of identity theft.Anonymous credentials allow for privacy-friendly authentication, by revealing only minimal information, and by guaranteeing unlinkability of multiple authentications.The most efficient anonymous credential schemes today work in the so-called random-oracle model, in which a hash function is idealized as an oracle implementing a random function.In this thesis, we work towards composable anonymous credentials from random oracles, which means that the security remains in tact if we run an instance of this protocol alongside many other protocols.As authentication is typically just one building block of a larger system, composability is a very important property.First, we investigate the power of global random oracles in the generalized universal composability framework.Global random oracles capture the setting in which a single idealized hash function can be used by many different protocols.Consequently, a protocol secure with a global random oracle avoids the unreasonable requirement of an idealized hash function specific to every protocol instance.So far, this seemed to come with a price, and protocols proven secure w.r.t.global random oracles are much less efficient than their counterparts from local random oracles.We show that global random oracles are much more powerful than previously known, by proving that some of the most practical and efficient primitives known can be proven secure with respect to different formulations of global random oracles, without losing efficiency compared to local random oracles.Second, building on our first set of results, we construct the first composable delegatable anonymous credential scheme, which also offers First and foremost, I want to express my gratitude to my supervisor Dr. Jan Camenisch, for teaching me the foundations of cryptography and table soccer.It has been a fantastic experience working under his guidance, Jan's experience and intuition provided a seemingly endless stream of topics to work on, while motivating me with his optimism.

Read the paper · More papers on PaperTik