{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T17:08:09Z","timestamp":1778864889522,"version":"3.51.4"},"reference-count":141,"publisher":"Association for Computing Machinery (ACM)","issue":"12","license":[{"start":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T00:00:00Z","timestamp":1778803200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"the National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62272350, 62325209, U23A20302, and 12441101"],"award-info":[{"award-number":["62272350, 62325209, U23A20302, and 12441101"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"the National Key Research and Development Program of China","award":["2022YFB3102400"],"award-info":[{"award-number":["2022YFB3102400"]}]},{"name":"the Fundamental Research Funds for the Central Universities","award":["2042023KF0203, and 2042024KF1013"],"award-info":[{"award-number":["2042023KF0203, and 2042024KF1013"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,9,30]]},"abstract":"<jats:p>\n                    As modern cryptography advances, digital signatures with versatility are developed to accommodate various requirements of specific applications. This renders them particularly interesting for more complex privacy-preserving protocol designs, including anonymous credentials and group signatures. Significant effort has been devoted to the study of different powerful variants of digital signatures that allow controlled transformations of message-signature pairs without destroying the validity of signatures. In this article, we provide an extensive survey of the state-of-the-art constructions of signatures with randomization features in key-message-signature-triples. We categorize existing relevant signatures into two major types: with\n                    <jats:italic toggle=\"yes\">unchanged<\/jats:italic>\n                    keys and with\n                    <jats:italic toggle=\"yes\">randomizable<\/jats:italic>\n                    keys, and revisit contributions in terms of security notions and efficiency. Furthermore, we suggest open questions and challenges for future research on signatures with randomization features.\n                  <\/jats:p>","DOI":"10.1145\/3806201","type":"journal-article","created":{"date-parts":[[2026,4,15]],"date-time":"2026-04-15T11:34:06Z","timestamp":1776252846000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["SoK: Signatures With Randomization Features"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1683-0255","authenticated-orcid":false,"given":"Yulin","family":"Liu","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University","place":["Wuhan, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2446-7436","authenticated-orcid":false,"given":"Debiao","family":"He","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University","place":["Wuhan, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2145-9713","authenticated-orcid":false,"given":"Zijian","family":"Bao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University","place":["Wuhan, China"]},{"name":"The Hong Kong Polytechnic University","place":["Wuhan, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9958-3255","authenticated-orcid":false,"given":"Cong","family":"Peng","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University","place":["Wuhan, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7165-398X","authenticated-orcid":false,"given":"Jianting","family":"Ning","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University","place":["Wuhan, China"]},{"name":"The Faculty of Data Science, City University of Macau","place":["Wuhan, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,5,15]]},"reference":[{"key":"e_1_3_3_2_2","unstructured":"2019. Hyperledger Aries. Retrieved July 10 2024 from https:\/\/lf-hyperledger.atlassian.net\/wiki\/spaces\/ARIES"},{"key":"e_1_3_3_3_2","unstructured":"2022. Hyperledger AnonCreds. Retrieved July 10 2024 from https:\/\/www.lfdecentralizedtrust.org\/projects\/anoncreds"},{"key":"e_1_3_3_4_2","first-page":"1987","volume-title":"Proceedings of the CCS","author":"Abdolmaleki Behzad","year":"2020","unstructured":"Behzad Abdolmaleki, Sebastian Ramacher, and Daniel Slamanig. 2020. Lift-and-shift: Obtaining simulation extractable subversion and updatable SNARKs generically. In Proceedings of the CCS. 1987\u20132005."},{"key":"e_1_3_3_5_2","first-page":"209","volume-title":"Proceedings of the CRYPTO","author":"Abe Masayuki","year":"2010","unstructured":"Masayuki Abe, Georg Fuchsbauer, Jens Groth, Kristiyan Haralambiev, and Miyako Ohkubo. 2010. Structure-preserving signatures and commitments to group elements. In Proceedings of the CRYPTO. 209\u2013236."},{"key":"e_1_3_3_6_2","first-page":"649","volume-title":"Proceedings of the CRYPTO","author":"Abe Masayuki","year":"2011","unstructured":"Masayuki Abe, Jens Groth, Kristiyan Haralambiev, and Miyako Ohkubo. 2011. Optimal structure-preserving signatures in asymmetric bilinear groups. In Proceedings of the CRYPTO. 649\u2013666."},{"key":"e_1_3_3_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-018-9300-5"},{"key":"e_1_3_3_8_2","first-page":"390","volume-title":"Proceedings of the CRYPTO","author":"Abe Masayuki","year":"2014","unstructured":"Masayuki Abe, Jens Groth, Miyako Ohkubo, and Mehdi Tibouchi. 2014. Structure-preserving signatures from type II pairings. In Proceedings of the CRYPTO. 390\u2013407."},{"key":"e_1_3_3_9_2","first-page":"688","volume-title":"Proceedings of the Theory of Cryptography Conference","author":"Abe Masayuki","year":"2014","unstructured":"Masayuki Abe, Jens Groth, Miyako Ohkubo, and Mehdi Tibouchi. 2014. Unified, minimal and selectively randomizable structure-preserving signatures. In Proceedings of the Theory of Cryptography Conference. 688\u2013712."},{"key":"e_1_3_3_10_2","article-title":"Signing on Elements in Bilinear Groups for Modular Protocol Design","author":"Abe Masayuki","year":"2010","unstructured":"Masayuki Abe, Kristiyan Haralambiev, and Miyako Ohkubo. 2010. Signing on Elements in Bilinear Groups for Modular Protocol Design. Cryptology ePrint Archive, Paper 2010\/133. Retrieved from https:\/\/eprint.iacr.org\/2010\/133","journal-title":"Cryptology ePrint Archive, Paper 2010\/133"},{"key":"e_1_3_3_11_2","first-page":"69","volume-title":"Proceedings of the ASIACRYPT","author":"Abe Masayuki","year":"2024","unstructured":"Masayuki Abe, Masaya Nanri, Octavio Perez Kempner, and Mehdi Tibouchi. 2024. Interactive threshold mercurial signatures and applications. In Proceedings of the ASIACRYPT. 69\u2013103."},{"key":"e_1_3_3_12_2","first-page":"1","volume-title":"Proceedings of the ESORICS","author":"Abe Masayuki","year":"2025","unstructured":"Masayuki Abe, Masaya Nanri, Miyako Ohkubo, Octavio Perez-Kempner, Daniel Slamanig, and Mehdi Tibouchi. 2025. A certified-input mixnet from two-party mercurial signatures on randomizable ciphertexts. In Proceedings of the ESORICS. 1\u201321."},{"key":"e_1_3_3_13_2","first-page":"1","volume-title":"Proceedings of the Theory of Cryptography","author":"Ahn Jae Hyun","year":"2012","unstructured":"Jae Hyun Ahn, Dan Boneh, Jan Camenisch, Susan Hohenberger, abhi shelat, and Brent Waters. 2012. Computing on authenticated data. In Proceedings of the Theory of Cryptography. 1\u201320."},{"key":"e_1_3_3_14_2","first-page":"1017","volume-title":"Proceedings of the CCS","author":"Alkadri Nabil Alkeilani","year":"2020","unstructured":"Nabil Alkeilani Alkadri, Poulami Das, Andreas Erwig, Sebastian Faust, Juliane Kr\u00e4mer, Siavash Riahi, and Patrick Struck. 2020. Deterministic wallets in a quantum world. In Proceedings of the CCS. 1017\u20131031."},{"key":"e_1_3_3_15_2","doi-asserted-by":"crossref","first-page":"441","DOI":"10.1007\/978-3-030-57808-4_22","volume-title":"Proceedings of the Applied Cryptography and Network Security","author":"Alkim Erdem","year":"2020","unstructured":"Erdem Alkim, Paulo S. L. M. Barreto, Nina Bindel, Juliane Kr\u00e4mer, Patrick Longa, and Jefferson E. Ricardini. 2020. The lattice-based digital signature scheme qTESLA. In Proceedings of the Applied Cryptography and Network Security. 441\u2013460."},{"key":"e_1_3_3_16_2","first-page":"92","volume-title":"Proceedings of the CCS","author":"Ateniese Giuseppe","year":"2005","unstructured":"Giuseppe Ateniese, Jan Camenisch, and Breno de Medeiros. 2005. Untraceable RFID tags via Insubvertible Encryption. In Proceedings of the CCS. 92\u2013101."},{"key":"e_1_3_3_17_2","article-title":"Practical Group Signatures without Random Oracles","author":"Ateniese Giuseppe","year":"2005","unstructured":"Giuseppe Ateniese, Jan Camenisch, Susan Hohenberger, and Breno de Medeiros. 2005. Practical Group Signatures without Random Oracles. Cryptology ePrint Archive, Paper 2005\/385. Retrieved from https:\/\/eprint.iacr.org\/2005\/385","journal-title":"Cryptology ePrint Archive, Paper 2005\/385"},{"key":"e_1_3_3_18_2","first-page":"159","volume-title":"Proceedings of the ESORICS","author":"Ateniese Giuseppe","year":"2005","unstructured":"Giuseppe Ateniese, Daniel H. Chou, Breno de Medeiros, and Gene Tsudik. 2005. Sanitizable signatures. In Proceedings of the ESORICS. 159\u2013177."},{"key":"e_1_3_3_19_2","first-page":"367","volume-title":"Proceedings of the ASIACRYPT","author":"Attrapadung Nuttapong","year":"2012","unstructured":"Nuttapong Attrapadung, Beno\u00eet Libert, and Thomas Peters. 2012. Computing on authenticated data: New privacy definitions and constructions. In Proceedings of the ASIACRYPT. 367\u2013385."},{"key":"e_1_3_3_20_2","first-page":"386","volume-title":"Proceedings of the PKC","author":"Attrapadung Nuttapong","year":"2013","unstructured":"Nuttapong Attrapadung, Beno\u00eet Libert, and Thomas Peters. 2013. Efficient completely context-hiding quotable and linearly homomorphic signatures. In Proceedings of the PKC. 386\u2013404."},{"key":"e_1_3_3_21_2","first-page":"405","volume-title":"Proceedings of the ASIACRYPT","author":"Backes Michael","year":"2018","unstructured":"Michael Backes, Lucjan Hanzlik, Kamil Kluczniak, and Jonas Schneider. 2018. Signatures with flexible public key: Introducing equivalence classes for public keys. In Proceedings of the ASIACRYPT. 405\u2013434."},{"key":"e_1_3_3_22_2","first-page":"2181","volume-title":"Proceedings of the CCS","author":"Backes Michael","year":"2019","unstructured":"Michael Backes, Lucjan Hanzlik, and Jonas Schneider-Bensch. 2019. Membership privacy for fully dynamic group signatures. In Proceedings of the CCS. 2181\u20132198."},{"key":"e_1_3_3_23_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-90456-2_12"},{"key":"e_1_3_3_24_2","article-title":"Unlinkable Policy-Compliant Signatures for Compliant and Decentralized Anonymous Payments","author":"Badertscher Christian","year":"2023","unstructured":"Christian Badertscher, Mahdi Sedaghat, and Hendrik Waldner. 2023. Unlinkable Policy-Compliant Signatures for Compliant and Decentralized Anonymous Payments. Cryptology ePrint Archive, Paper 2023\/1070. Retrieved from https:\/\/eprint.iacr.org\/2023\/1070","journal-title":"Cryptology ePrint Archive, Paper 2023\/1070"},{"key":"e_1_3_3_25_2","first-page":"355","volume-title":"Proceedings of the PKC","author":"Barthe Gilles","year":"2015","unstructured":"Gilles Barthe, Edvard Fagerholm, Dario Fiore, Andre Scedrov, Benedikt Schmidt, and Mehdi Tibouchi. 2015. Strongly-optimal structure preserving signatures from type II pairings: Synthesis and lower bounds. In Proceedings of the PKC. 355\u2013376."},{"key":"e_1_3_3_26_2","doi-asserted-by":"crossref","first-page":"359","DOI":"10.1007\/978-3-030-57990-6_18","volume-title":"Proceedings of the Security and Cryptography for Networks","author":"Bauer Balthazar","year":"2020","unstructured":"Balthazar Bauer and Georg Fuchsbauer. 2020. Efficient signatures on randomizable ciphertexts. In Proceedings of the Security and Cryptography for Networks. 359\u2013381."},{"key":"e_1_3_3_27_2","first-page":"3","volume-title":"Proceedings of the PKC","author":"Bauer Balthazar","year":"2024","unstructured":"Balthazar Bauer, Georg Fuchsbauer, and Fabian Regen. 2024. On proving equivalence class signatures secure from non-interactive assumptions. In Proceedings of the PKC. 3\u201336."},{"key":"e_1_3_3_28_2","first-page":"3","volume-title":"Proceedings of the ASIACRYPT","author":"Bauer Balthazar","year":"2024","unstructured":"Balthazar Bauer, Georg Fuchsbauer, and Fabian Regen. 2024. On security proofs of existing equivalence class signature schemes. In Proceedings of the ASIACRYPT. 3\u201337."},{"key":"e_1_3_3_29_2","first-page":"245","volume-title":"Proceedings of the ASIACRYPT","author":"Benhamouda Fabrice","year":"2023","unstructured":"Fabrice Benhamouda, Mariana Raykova, and Karn Seth. 2023. Anonymous counting tokens. In Proceedings of the ASIACRYPT. 245\u2013278."},{"key":"e_1_3_3_30_2","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1007\/978-3-030-44223-1_8","volume-title":"Proceedings of the International Conference on Post-Quantum Cryptography","author":"Beullens Ward","year":"2020","unstructured":"Ward Beullens and Cyprien Delpech de Saint Guilhem. 2020. LegRoast: Efficient post-quantum signatures from the legendre prf. In Proceedings of the International Conference on Post-Quantum Cryptography. 130\u2013150."},{"key":"e_1_3_3_31_2","first-page":"227","volume-title":"Proceedings of the ASIACRYPT","author":"Beullens Ward","unstructured":"Ward Beullens, Thorsten Kleinjung, and Frederik Vercauteren. 2019. CSI-FiSh: Efficient isogeny based signatures through class group computations. In Proceedings of the ASIACRYPT. 227\u2013247."},{"key":"e_1_3_3_32_2","first-page":"403","volume-title":"Proceedings of the PKC","author":"Blazy Olivier","year":"2011","unstructured":"Olivier Blazy, Georg Fuchsbauer, David Pointcheval, and Damien Vergnaud. 2011. Signatures on randomizable ciphertexts. In Proceedings of the PKC. 403\u2013422."},{"key":"e_1_3_3_33_2","first-page":"319","volume-title":"Proceedings of the AsiaCCS","author":"Bobolz Jan","year":"2020","unstructured":"Jan Bobolz, Fabian Eidens, Stephan Krenn, Daniel Slamanig, and Christoph Striecks. 2020. Privacy-preserving incentive systems with highly efficient point-collection. In Proceedings of the AsiaCCS. 319\u2013333."},{"key":"e_1_3_3_34_2","first-page":"56","volume-title":"Proceedings of the EUROCRYPT","author":"Boneh Dan","year":"2004","unstructured":"Dan Boneh and Xavier Boyen. 2004. Short signatures without random oracles. In Proceedings of the EUROCRYPT. 56\u201373."},{"key":"e_1_3_3_35_2","first-page":"514","volume-title":"Proceedings of the ASIACRYPT","author":"Boneh Dan","year":"2001","unstructured":"Dan Boneh, Ben Lynn, and Hovav Shacham. 2001. Short signatures from the weil pairing. In Proceedings of the ASIACRYPT. 514\u2013532."},{"key":"e_1_3_3_36_2","first-page":"947","volume-title":"Proceedings of the IEEE S&P","author":"Bowe Sean","year":"2020","unstructured":"Sean Bowe, Alessandro Chiesa, Matthew Green, Ian Miers, Pratyush Mishra, and Howard Wu. 2020. ZEXE: Enabling decentralized private computation. In Proceedings of the IEEE S&P. 947\u2013964."},{"key":"e_1_3_3_37_2","first-page":"262","volume-title":"Proceedings of the ASIACRYPT","author":"Camenisch Jan","year":"2015","unstructured":"Jan Camenisch, Maria Dubovitskaya, Kristiyan Haralambiev, and Markulf Kohlweiss. 2015. Composable and modular anonymous credentials: Definitions and practical constructions. In Proceedings of the ASIACRYPT. 262\u2013288."},{"key":"e_1_3_3_38_2","doi-asserted-by":"crossref","first-page":"268","DOI":"10.1007\/3-540-36413-7_20","volume-title":"Proceedings of the Security in Communication Networks","author":"Camenisch Jan","year":"2003","unstructured":"Jan Camenisch and Anna Lysyanskaya. 2003. A signature scheme with efficient protocols. In Proceedings of the Security in Communication Networks. 268\u2013289."},{"key":"e_1_3_3_39_2","first-page":"56","volume-title":"Proceedings of the CRYPTO","author":"Camenisch Jan","year":"2004","unstructured":"Jan Camenisch and Anna Lysyanskaya. 2004. Signature schemes and anonymous credentials from bilinear maps. In Proceedings of the CRYPTO. 56\u201372."},{"key":"e_1_3_3_40_2","first-page":"160","volume-title":"Proceedings of the Financial Cryptography and Data Security","author":"Celi Sof\u00eda","year":"2024","unstructured":"Sof\u00eda Celi, Scott Griffy, Lucjan Hanzlik, Octavio Perez-Kempner, and Daniel Slamanig. 2024. SoK: Signatures with randomizable keys. In Proceedings of the Financial Cryptography and Data Security. 160\u2013187."},{"key":"e_1_3_3_41_2","first-page":"1614","volume-title":"Proceedings of the CCS","author":"Chaidos Pyrros","year":"2016","unstructured":"Pyrros Chaidos, V\u00e9ronique Cortier, Georg Fuchsbauer, and David Galindo. 2016. BeleniosRF: A non-interactive receipt-free electronic voting scheme. In Proceedings of the CCS. 1614\u20131625."},{"key":"e_1_3_3_42_2","first-page":"1825","volume-title":"Proceedings of the CCS","author":"Chase Melissa","year":"2017","unstructured":"Melissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi, Sebastian Ramacher, Christian Rechberger, Daniel Slamanig, and Greg Zaverucha. 2017. Post-quantum zero-knowledge and sgnatures from symmetric-key primitives. In Proceedings of the CCS. 1825\u20131842."},{"key":"e_1_3_3_43_2","doi-asserted-by":"crossref","first-page":"199","DOI":"10.1109\/CSF.2014.22","volume-title":"Proceedings of the 2014 IEEE 27th Computer Security Foundations Symposium","author":"Chase Melissa","year":"2014","unstructured":"Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya, and Sarah Meiklejohn. 2014. Malleable signatures: New definitions and delegatable anonymous credentials. In Proceedings of the 2014 IEEE 27th Computer Security Foundations Symposium. 199\u2013213."},{"key":"e_1_3_3_44_2","first-page":"45","volume-title":"Proceedings of the INDOCRYPT","author":"Chatterjee Sanjit","year":"2019","unstructured":"Sanjit Chatterjee and R. Kabaleeshwaran. 2019. Rerandomizable signatures under standard assumption. In Proceedings of the INDOCRYPT. 45\u201367."},{"issue":"13","key":"e_1_3_3_45_2","doi-asserted-by":"crossref","first-page":"1311","DOI":"10.1016\/j.dam.2011.04.021","article-title":"On cryptographic protocols employing asymmetric pairings \u2013 The role of  \\(\\psi\\)  revisited","volume":"159","author":"Chatterjee Sanjit","year":"2011","unstructured":"Sanjit Chatterjee and Alfred Menezes. 2011. On cryptographic protocols employing asymmetric pairings \u2013 The role of \\(\\psi\\) revisited. Discrete Applied Mathematics 159, 13 (2011), 1311\u20131322.","journal-title":"Discrete Applied Mathematics"},{"key":"e_1_3_3_46_2","first-page":"286","volume-title":"Proceedings of the ASIACRYPT","author":"Chatterjee Sanjit","year":"2015","unstructured":"Sanjit Chatterjee and Alfred Menezes. 2015. Type 2 structure-preserving signature schemes revisited. In Proceedings of the ASIACRYPT. 286\u2013310."},{"key":"e_1_3_3_47_2","first-page":"2871","volume-title":"Proceedings of the CCS","author":"Chu Hien","year":"2023","unstructured":"Hien Chu, Khue Do, and Lucjan Hanzlik. 2023. On the security of rate-limited privacy pass. In Proceedings of the CCS. 2871\u20132885."},{"key":"e_1_3_3_48_2","first-page":"691","volume-title":"Proceedings of the PKC","author":"Cini Valerio","year":"2021","unstructured":"Valerio Cini, Sebastian Ramacher, Daniel Slamanig, Christoph Striecks, and Erkan Tairi. 2021. Updatable signatures and message authentication codes. In Proceedings of the PKC. 691\u2013723."},{"key":"e_1_3_3_49_2","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/978-3-030-62576-4_1","volume-title":"Proceedings of the Provable and Practical Security: 14th International Conference, ProvSec","author":"Clarisse R\u00e9mi","year":"2020","unstructured":"R\u00e9mi Clarisse and Olivier Sanders. 2020. Group signature without random oracles from randomizable signatures. In Proceedings of the Provable and Practical Security: 14th International Conference, ProvSec. 3\u201323."},{"key":"e_1_3_3_50_2","first-page":"249","volume-title":"Proceedings of the INDOCRYPT","author":"Connolly Aisling","year":"2022","unstructured":"Aisling Connolly, J\u00e9r\u00f4me Deschamps, Pascal Lafourcade, and Octavio Perez Kempner. 2022. Protego: Efficient, revocable and auditable anonymous credentials with applications to hyperledger fabric. In Proceedings of the INDOCRYPT. 249\u2013271."},{"key":"e_1_3_3_51_2","first-page":"409","volume-title":"Proceedings of the PKC","author":"Connolly Aisling","year":"2022","unstructured":"Aisling Connolly, Pascal Lafourcade, and Octavio Perez Kempner. 2022. Improved constructions of anonymous credentials from structure-preserving signatures on equivalence classes. In Proceedings of the PKC. 409\u2013438."},{"key":"e_1_3_3_52_2","doi-asserted-by":"crossref","first-page":"367","DOI":"10.1109\/CSF.2019.00032","volume-title":"Proceedings of the 2019 IEEE 32nd Computer Security Foundations Symposium (CSF)","author":"Cortier V\u00e9ronique","year":"2019","unstructured":"V\u00e9ronique Cortier, Alicia Filipiak, and Joseph Lallemand. 2019. BeleniosVS: Secrecy and verifiability against a corrupted voting device. In Proceedings of the 2019 IEEE 32nd Computer Security Foundations Symposium (CSF). 367\u201336714."},{"key":"e_1_3_3_53_2","doi-asserted-by":"crossref","first-page":"214","DOI":"10.1007\/978-3-030-19052-1_14","article-title":"Belenios: A simple private and verifiable electronic voting system","author":"Cortier V\u00e9ronique","year":"2019","unstructured":"V\u00e9ronique Cortier, Pierrick Gaudry, and St\u00e9phane Glondu. 2019. Belenios: A simple private and verifiable electronic voting system. Foundations of Security, Protocols, and Equational Reasoning: Essays Dedicated to Catherine A. Meadows (2019), 214\u2013238.","journal-title":"Foundations of Security, Protocols, and Equational Reasoning: Essays Dedicated to Catherine A. Meadows"},{"key":"e_1_3_3_54_2","first-page":"535","volume-title":"Proceedings of the CT-RSA","author":"Crites Elizabeth C.","year":"2019","unstructured":"Elizabeth C. Crites and Anna Lysyanskaya. 2019. Delegatable anonymous credentials from mercurial signatures. In Proceedings of the CT-RSA. 535\u2013555."},{"key":"e_1_3_3_55_2","first-page":"441","volume-title":"Proceedings on Privacy Enhancing Technologies Symposium","volume":"2021","author":"Crites Elizabeth C.","year":"2021","unstructured":"Elizabeth C. Crites and Anna Lysyanskaya. 2021. Mercurial signatures for variable-length messages. Proceedings on Privacy Enhancing Technologies Symposium 2021, 4 (2021), 441\u2013463."},{"key":"e_1_3_3_56_2","first-page":"856","volume-title":"Proceedings of the Asia CCS","author":"Das Poulami","year":"2025","unstructured":"Poulami Das, Andreas Erwig, Sebastian Faust, Philipp-Florens Lehwalder, Julian Loss, Ziyan Qu, and Siavash Riahi. 2025. BIP32-compatible threshold wallets. In Proceedings of the Asia CCS. 856\u2013872."},{"key":"e_1_3_3_57_2","first-page":"1020","volume-title":"Proceedings of the CCS","author":"Das Poulami","year":"2021","unstructured":"Poulami Das, Andreas Erwig, Sebastian Faust, Julian Loss, and Siavash Riahi. 2021. The exact security of BIP32 wallets. In Proceedings of the CCS. 1020\u20131042."},{"key":"e_1_3_3_58_2","first-page":"522","volume-title":"Proceedings of the Asia CCS","author":"Das Poulami","year":"2024","unstructured":"Poulami Das, Andreas Erwig, Michael Meyer, and Patrick Struck. 2024. Efficient post-quantum secure deterministic threshold wallets from isogenies. In Proceedings of the Asia CCS. 522\u2013532."},{"key":"e_1_3_3_59_2","first-page":"651","volume-title":"Proceedings of the CCS","author":"Das Poulami","year":"2019","unstructured":"Poulami Das, Sebastian Faust, and Julian Loss. 2019. A formal treatment of deterministic wallets. In Proceedings of the CCS. 651\u2013668."},{"key":"e_1_3_3_60_2","volume-title":"PRISMACLOUD D4.4: Overview of Functional and Malleable Signature Schemes","author":"Demirel Denise","year":"2015","unstructured":"Denise Demirel, David Derler, Christian Hanser, Henrich P\u00f6hls, Daniel Slamanig, and Giulia Traverso. 2015. PRISMACLOUD D4.4: Overview of Functional and Malleable Signature Schemes."},{"key":"e_1_3_3_61_2","unstructured":"Frank Denis Edward Eaton Tancr\u00e8de Lepoint and Christopher A. Wood. 2022. Key Blinding for Signature Schemes. Retrieved March 2025 from https:\/\/www.ietf.org\/archive\/id\/draft-irtf-cfrg-signature-key-blinding-02.html"},{"key":"e_1_3_3_62_2","first-page":"551","volume-title":"Proceedings of the AsiaCCS","author":"Derler David","year":"2018","unstructured":"David Derler and Daniel Slamanig. 2018. Highly-efficient fully-anonymous dynamic group signatures. In Proceedings of the AsiaCCS. 551\u2013565."},{"issue":"6","key":"e_1_3_3_63_2","doi-asserted-by":"crossref","first-page":"1373","DOI":"10.1007\/s10623-018-0535-9","article-title":"Key-homomorphic Signatures: Definitions and applications to multiparty signatures and non-interactive zero-knowledge","volume":"87","author":"Derler David","year":"2019","unstructured":"David Derler and Daniel Slamanig. 2019. Key-homomorphic Signatures: Definitions and applications to multiparty signatures and non-interactive zero-knowledge. Designs, Codes and Cryptography 87, 6 (2019), 1373\u20131413.","journal-title":"Designs, Codes and Cryptography"},{"key":"e_1_3_3_64_2","doi-asserted-by":"crossref","first-page":"365","DOI":"10.1145\/3549993.3550007","volume-title":"Proceedings of the Democratizing Cryptography: The Work of Whitfield Diffie and Martin Hellman","author":"Diffie Whitfield","year":"2022","unstructured":"Whitfield Diffie and Martin E. Hellman. 2022. New directions in cryptography. In Proceedings of the Democratizing Cryptography: The Work of Whitfield Diffie and Martin Hellman. 365\u2013390."},{"key":"e_1_3_3_65_2","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2018.i1.238-268"},{"key":"e_1_3_3_66_2","article-title":"Security Analysis of Signature Schemes with Key Blinding","author":"Eaton Edward","year":"2023","unstructured":"Edward Eaton, Tancr\u00e8de Lepoint, and Christopher A. Wood. 2023. Security Analysis of Signature Schemes with Key Blinding. Cryptology ePrint Archive, Paper 2023\/380. Retrieved from https:\/\/eprint.iacr.org\/2023\/380","journal-title":"Cryptology ePrint Archive, Paper 2023\/380"},{"key":"e_1_3_3_67_2","doi-asserted-by":"crossref","first-page":"273","DOI":"10.1007\/978-3-031-09234-3_14","volume-title":"Proceedings of the International Conference on Applied Cryptography and Network Security","author":"Eaton Edward","year":"2022","unstructured":"Edward Eaton, Sajin Sasy, and Ian Goldberg. 2022. Improving the privacy of Tor onion services. In Proceedings of the International Conference on Applied Cryptography and Network Security. 273\u2013292."},{"key":"e_1_3_3_68_2","first-page":"67","volume-title":"Proceedings of the LATINCRYPT","author":"Eaton Edward","year":"2021","unstructured":"Edward Eaton, Douglas Stebila, and Roy Stracovsky. 2021. Post-quantum Key-blinding for authentication in anonymity networks. In Proceedings of the LATINCRYPT. 67\u201387."},{"key":"e_1_3_3_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1985.1057074"},{"key":"e_1_3_3_70_2","first-page":"487","volume-title":"Proceedings of the ESORICS","author":"Erwig Andreas","year":"2022","unstructured":"Andreas Erwig and Siavash Riahi. 2022. Deterministic wallets for adaptor signatures. In Proceedings of the ESORICS. 487\u2013506."},{"key":"e_1_3_3_71_2","first-page":"405","volume-title":"Proceedings of the ESORICS","author":"Fiore Dario","year":"2022","unstructured":"Dario Fiore, Lydia Garms, Dimitris Kolonelos, Claudio Soriente, and Ida Tucker. 2022. Ring signatures with user-controlled linkability. In Proceedings of the ESORICS. 405\u2013426."},{"key":"e_1_3_3_72_2","first-page":"301","volume-title":"Proceedings of the PKC","author":"Fleischhacker Nils","year":"2016","unstructured":"Nils Fleischhacker, Johannes Krupp, Giulio Malavolta, Jonas Schneider, Dominique Schr\u00f6der, and Mark Simkin. 2016. Efficient unlinkable sanitizable signatures from signatures with Re-randomizable keys. In Proceedings of the PKC. 301\u2013330."},{"issue":"5","key":"e_1_3_3_73_2","first-page":"1","article-title":"Falcon: Fast-fourier lattice-based compact signatures over NTRU","volume":"36","author":"Fouque Pierre-Alain","year":"2018","unstructured":"Pierre-Alain Fouque, Jeffrey Hoffstein, Paul Kirchner, Vadim Lyubashevsky, Thomas Pornin, Thomas Prest, Thomas Ricosset, Gregor Seiler, William Whyte, Zhenfei Zhang, et\u00a0al. 2018. Falcon: Fast-fourier lattice-based compact signatures over NTRU. Submission to the NIST\u2019s Post-quantum Cryptography Standardization Process 36, 5 (2018), 1\u201375.","journal-title":"Submission to the NIST\u2019s Post-quantum Cryptography Standardization Process"},{"key":"e_1_3_3_74_2","first-page":"224","volume-title":"Proceedings of the EUROCRYPT","author":"Fuchsbauer Georg","year":"2011","unstructured":"Georg Fuchsbauer. 2011. Commuting signatures and verifiable encryption. In Proceedings of the EUROCRYPT. 224\u2013245."},{"key":"e_1_3_3_75_2","article-title":"Breaking Existential Unforgeability of a Signature Scheme from Asiacrypt 2014","author":"Fuchsbauer Georg","year":"2014","unstructured":"Georg Fuchsbauer. 2014. Breaking Existential Unforgeability of a Signature Scheme from Asiacrypt 2014. Cryptology ePrint Archive, Paper 2014\/892. Retrieved from https:\/\/eprint.iacr.org\/2014\/892","journal-title":"Cryptology ePrint Archive, Paper 2014\/892"},{"key":"e_1_3_3_76_2","first-page":"153","volume-title":"Proceedings of the PKC","author":"Fuchsbauer Georg","year":"2018","unstructured":"Georg Fuchsbauer and Romain Gay. 2018. Weakly secure equivalence-class signatures from standard assumptions. In Proceedings of the PKC. 153\u2013183."},{"key":"e_1_3_3_77_2","first-page":"88","volume-title":"Proceedings of the PKC","author":"Fuchsbauer Georg","year":"2017","unstructured":"Georg Fuchsbauer, Romain Gay, Lucas Kowalczyk, and Claudio Orlandi. 2017. Access control encryption for equality, comparison, and more. In Proceedings of the PKC. 88\u2013118."},{"key":"e_1_3_3_78_2","first-page":"391","volume-title":"Proceedings of the Security and Cryptography for Networks","author":"Fuchsbauer Georg","year":"2016","unstructured":"Georg Fuchsbauer, Christian Hanser, Chethan Kamath, and Daniel Slamanig. 2016. Practical round-optimal blind signatures in the standard model from weaker assumptions. In Proceedings of the Security and Cryptography for Networks. 391\u2013408."},{"key":"e_1_3_3_79_2","first-page":"233","volume-title":"Proceedings of the CRYPTO","author":"Fuchsbauer Georg","year":"2015","unstructured":"Georg Fuchsbauer, Christian Hanser, and Daniel Slamanig. 2015. Practical round-optimal blind signatures in the standard model. In Proceedings of the CRYPTO. 233\u2013253."},{"key":"e_1_3_3_80_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-018-9281-4"},{"key":"e_1_3_3_81_2","article-title":"EUF-CMA-secure structure-preserving signatures on equivalence classes","author":"Fuchsbauer Georg","year":"2014","unstructured":"Georg Fuchsbauer, Christian H. Hanser, and Daniel Slamanig. 2014. EUF-CMA-secure structure-preserving signatures on equivalence classes. Cryptology ePrint Archive (2014). Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:17538503","journal-title":"Cryptology ePrint Archive"},{"key":"e_1_3_3_82_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.dam.2007.12.010"},{"key":"e_1_3_3_83_2","first-page":"1541","volume-title":"Proceedings of the CCS","author":"Ge Zhonghui","year":"2023","unstructured":"Zhonghui Ge, Jiayuan Gu, Chenke Wang, Yu Long, Xian Xu, and Dawu Gu. 2023. Accio: Variable-amount, optimized-unlinkable and NIZK-free off-chain payments via hubs. In Proceedings of the CCS. 1541\u20131555."},{"key":"e_1_3_3_84_2","doi-asserted-by":"publisher","DOI":"10.1145\/1374376.1374407"},{"key":"e_1_3_3_85_2","first-page":"25","volume-title":"Proceedings of the ASIACRYPT","author":"Gerbush Michael","year":"2012","unstructured":"Michael Gerbush, Allison Lewko, Adam O\u2019Neill, and Brent Waters. 2012. Dual form signatures: An approach for proving security from static assumptions. In Proceedings of the ASIACRYPT. 25\u201342."},{"key":"e_1_3_3_86_2","doi-asserted-by":"crossref","first-page":"330","DOI":"10.1007\/978-3-642-39059-3_23","volume-title":"Proceedings of the Information Security and Privacy","author":"Ghadafi Essam","year":"2013","unstructured":"Essam Ghadafi. 2013. Formalizing group blind signatures and practical constructions without random oracles. In Proceedings of the Information Security and Privacy. 330\u2013346."},{"key":"e_1_3_3_87_2","first-page":"305","volume-title":"Proceedings of the CT-RSA","author":"Ghadafi Essam","year":"2016","unstructured":"Essam Ghadafi. 2016. Short structure-preserving signatures. In Proceedings of the CT-RSA. 305\u2013321."},{"key":"e_1_3_3_88_2","first-page":"43","volume-title":"Proceedings of the ESORICS","author":"Ghadafi Essam","year":"2017","unstructured":"Essam Ghadafi. 2017. More efficient structure-preserving signatures-Or: By passing the type-III lower bounds. In Proceedings of the ESORICS. 43\u201361."},{"key":"e_1_3_3_89_2","doi-asserted-by":"crossref","first-page":"284","DOI":"10.1007\/978-3-030-78372-3_11","volume-title":"Proceedings of the Applied Cryptography and Network Security","author":"Ghadafi Essam","year":"2021","unstructured":"Essam Ghadafi. 2021. Partially structure-preserving signatures: Lower bounds, constructions and more. In Proceedings of the Applied Cryptography and Network Security. 284\u2013312."},{"key":"e_1_3_3_90_2","doi-asserted-by":"publisher","DOI":"10.1137\/0217017"},{"key":"e_1_3_3_91_2","first-page":"473","volume-title":"Proceedings of the CCS","author":"Green Matthew","year":"2017","unstructured":"Matthew Green and Ian Miers. 2017. Bolt: Anonymous payment channels for decentralized currencies. In Proceedings of the CCS. 473\u2013489."},{"key":"e_1_3_3_92_2","article-title":"Non-Interactive Threshold Mercurial Signatures with Applications to Threshold DAC","author":"Griffy Scott","year":"2025","unstructured":"Scott Griffy, Nicholas Jankovic, Anna Lysyanskaya, and Arup Mondal. 2025. Non-Interactive Threshold Mercurial Signatures with Applications to Threshold DAC. Cryptology ePrint Archive, Paper 2025\/2134. Retrieved from https:\/\/eprint.iacr.org\/2025\/2134","journal-title":"Cryptology ePrint Archive, Paper 2025\/2134"},{"key":"e_1_3_3_93_2","first-page":"296","volume-title":"Proceedings of the ASIACRYPT","author":"Griffy Scott","year":"2025","unstructured":"Scott Griffy, Anna Lysyanskaya, Omid Mir, Octavio Perez Kempner, and Daniel Slamanig. 2025. Delegatable anonymous credentials from mercurial signatures with stronger privacy. In Proceedings of the ASIACRYPT. 296\u2013325."},{"key":"e_1_3_3_94_2","first-page":"239","volume-title":"Proceedings of the ASIACRYPT","author":"Groth Jens","year":"2015","unstructured":"Jens Groth. 2015. Efficient fully structure-preserving signatures for large messages. In Proceedings of the ASIACRYPT. 239\u2013259."},{"key":"e_1_3_3_95_2","first-page":"415","volume-title":"Proceedings of the EUROCRYPT","author":"Groth Jens","year":"2008","unstructured":"Jens Groth and Amit Sahai. 2008. Efficient non-interactive proof systems for bilinear groups. In Proceedings of the EUROCRYPT. 415\u2013432."},{"key":"e_1_3_3_96_2","doi-asserted-by":"publisher","DOI":"10.5555\/88314.88372"},{"key":"e_1_3_3_97_2","first-page":"146","volume-title":"Proceedings of the ESORICS","author":"Hanser Christian","year":"2015","unstructured":"Christian Hanser, Max Rabkin, and Dominique Schr\u00f6der. 2015. Verifiably encrypted signatures: Security revisited and a new construction. In Proceedings of the ESORICS. 146\u2013164."},{"key":"e_1_3_3_98_2","first-page":"491","volume-title":"Proceedings of the ASIACRYPT","author":"Hanser Christian","year":"2014","unstructured":"Christian Hanser and Daniel Slamanig. 2014. Structure-preserving signatures on equivalence classes and their application to anonymous credentials. In Proceedings of the ASIACRYPT. 491\u2013511."},{"key":"e_1_3_3_99_2","first-page":"722","volume-title":"Proceedings of the EUROCRYPT","author":"Hanzlik Lucjan","year":"2023","unstructured":"Lucjan Hanzlik. 2023. Non-interactive blind signatures for random messages. In Proceedings of the EUROCRYPT. 722\u2013752."},{"key":"e_1_3_3_100_2","first-page":"2004","volume-title":"Proceedings of the CCS","author":"Hanzlik Lucjan","year":"2021","unstructured":"Lucjan Hanzlik and Daniel Slamanig. 2021. With a little help from my friends: Constructing practical anonymous credentials. In Proceedings of the CCS. 2004\u20132023."},{"key":"e_1_3_3_101_2","first-page":"597","volume-title":"Proceedings of the PKC","author":"H\u00e9bant Chlo\u00e9","year":"2020","unstructured":"Chlo\u00e9 H\u00e9bant, Duong Hieu Phan, and David Pointcheval. 2020. Linearly-homomorphic signatures and scalable mix-nets. In Proceedings of the PKC. 597\u2013627."},{"key":"e_1_3_3_102_2","volume-title":"Rate-Limited Token Issuance Protocol","author":"Hendrickson Scott","year":"2022","unstructured":"Scott Hendrickson, Jana Iyengar, Tommy Pauly, Steven Valdez, and Christopher A. Wood. 2022. Rate-Limited Token Issuance Protocol. IETF Privacy Pass Working Group. Retrieved from https:\/\/datatracker.ietf.org\/doc\/draft-ietf-privacypass-rate-limit-tokens\/00\/"},{"key":"e_1_3_3_103_2","first-page":"21","volume-title":"Proceedings of the CRYPTO","author":"Hofheinz Dennis","year":"2008","unstructured":"Dennis Hofheinz and Eike Kiltz. 2008. Programmable hash functions and their applications. In Proceedings of the CRYPTO. 21\u201338."},{"key":"e_1_3_3_104_2","unstructured":"Nicholas Hopper. 2013. Proving Security of Tor\u2019s Hidden Service Identity Blinding Protocol. The Tor Project. https:\/\/api.semanticscholar.org\/CorpusID:7118792"},{"key":"e_1_3_3_105_2","article-title":"Post-Quantum Secure Deterministic Wallet: Stateless, Hot\/Cold Setting, and More Secure","author":"Hu Mingxing","year":"2023","unstructured":"Mingxing Hu. 2023. Post-Quantum Secure Deterministic Wallet: Stateless, Hot\/Cold Setting, and More Secure. Cryptology ePrint Archive, Paper 2023\/062. Retrieved from https:\/\/eprint.iacr.org\/2023\/062","journal-title":"Cryptology ePrint Archive, Paper 2023\/062"},{"key":"e_1_3_3_106_2","first-page":"33","volume-title":"Proceedings of the CRYPTO","author":"Jaeger Joseph","year":"2018","unstructured":"Joseph Jaeger and Igors Stepanovs. 2018. Optimal channel security against fine-grained state compromise: The safety of messaging. In Proceedings of the CRYPTO. 33\u201362."},{"key":"e_1_3_3_107_2","doi-asserted-by":"publisher","DOI":"10.1007\/s102070100002"},{"key":"e_1_3_3_108_2","first-page":"244","volume-title":"Proceedings of the CT-RSA","author":"Johnson Robert","year":"2002","unstructured":"Robert Johnson, David Molnar, Dawn Song, and David Wagner. 2002. Homomorphic signature schemes. In Proceedings of the CT-RSA. 244\u2013262."},{"key":"e_1_3_3_109_2","doi-asserted-by":"crossref","unstructured":"Simon Josefsson and Ilari Liusvaara. 2017. Edwards-Curve Digital Signature Algorithm (EdDSA). Retrieved April 2025 from https:\/\/www.rfc-editor.org\/info\/rfc8032","DOI":"10.17487\/RFC8032"},{"key":"e_1_3_3_110_2","first-page":"159","volume-title":"Proceedings of the EUROCRYPT","author":"Jost Daniel","year":"2019","unstructured":"Daniel Jost, Ueli Maurer, and Marta Mularczyk. 2019. Efficient ratcheting: Almost-optimal guarantees for secure messaging. In Proceedings of the EUROCRYPT. 159\u2013188."},{"key":"e_1_3_3_111_2","first-page":"1","volume-title":"Proceedings of the ASIACRYPT","author":"Jutla Charanjit S.","year":"2013","unstructured":"Charanjit S. Jutla and Arnab Roy. 2013. Shorter quasi-adaptive NIZK proofs for linear subspaces. In Proceedings of the ASIACRYPT. 1\u201320."},{"key":"e_1_3_3_112_2","first-page":"383","volume-title":"Proceedings of the ASIACRYPT","author":"Katsumata Shuichi","year":"2023","unstructured":"Shuichi Katsumata, Michael Reichle, and Yusuke Sakai. 2023. Practical round-optimal blind signatures in the ROM from standard assumptions. In Proceedings of the ASIACRYPT. 383\u2013417."},{"key":"e_1_3_3_113_2","first-page":"155","volume-title":"Proceedings of the CCS","author":"Katz Jonathan","year":"2003","unstructured":"Jonathan Katz and Nan Wang. 2003. Efficiency improvements for signature schemes with tight security reductions. In Proceedings of the CCS. 155\u2013164."},{"key":"e_1_3_3_114_2","first-page":"63","volume-title":"Proceedings of the ASIACRYPT","author":"Khalili Mojtaba","year":"2019","unstructured":"Mojtaba Khalili, Daniel Slamanig, and Mohammad Dakhilalian. 2019. Structure-preserving signatures on equivalence classes from standard assumptions. In Proceedings of the ASIACRYPT. 63\u201393."},{"key":"e_1_3_3_115_2","first-page":"685","volume-title":"Proceedings of the EUROCRYPT","author":"Lehmann Anja","year":"2018","unstructured":"Anja Lehmann and Bj\u00f6rn Tackmann. 2018. Updatable encryption with post-compromise security. In Proceedings of the EUROCRYPT. 685\u2013716."},{"key":"e_1_3_3_116_2","first-page":"511","volume-title":"Proceedings of the AsiaCCS","author":"Libert Beno\u00eet","year":"2016","unstructured":"Beno\u00eet Libert, Fabrice Mouhartem, Thomas Peters, and Moti Yung. 2016. Practical signatures with efficient protocols from simple assumptions. In Proceedings of the AsiaCCS. 511\u2013522."},{"key":"e_1_3_3_117_2","first-page":"609","volume-title":"Proceedings of the EUROCRYPT","author":"Libert Beno\u00eet","year":"2012","unstructured":"Beno\u00eet Libert, Thomas Peters, and Moti Yung. 2012. Scalable group signatures with revocation. In Proceedings of the EUROCRYPT. 609\u2013627."},{"key":"e_1_3_3_118_2","first-page":"296","volume-title":"Proceedings of the CRYPTO","author":"Libert Beno\u00eet","year":"2015","unstructured":"Beno\u00eet Libert, Thomas Peters, and Moti Yung. 2015. Short group signatures via structure-preserving signatures: Standard model security from simple assumptions. In Proceedings of the CRYPTO. 296\u2013316."},{"key":"e_1_3_3_119_2","first-page":"738","volume-title":"Proceedings of the EUROCRYPT","author":"Lyubashevsky Vadim","year":"2012","unstructured":"Vadim Lyubashevsky. 2012. Lattice signatures without trapdoors. In Proceedings of the EUROCRYPT. 738\u2013755."},{"key":"e_1_3_3_120_2","first-page":"128","volume-title":"Proceedings of the ASIACRYPT","author":"Malavolta Giulio","year":"2017","unstructured":"Giulio Malavolta and Dominique Schr\u00f6der. 2017. Efficient ring signatures in the standard model. In Proceedings of the ASIACRYPT. 128\u2013157."},{"key":"e_1_3_3_121_2","first-page":"30","volume-title":"Proceedings of the CCS","author":"Mir Omid","year":"2023","unstructured":"Omid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya, and Daniel Slamanig. 2023. Aggregate signatures with versatile randomization and issuer-hiding multi-authority anonymous credentials. In Proceedings of the CCS. 30\u201344."},{"key":"e_1_3_3_122_2","doi-asserted-by":"crossref","first-page":"488","DOI":"10.56553\/popets-2023-0093","article-title":"Practical delegatable anonymous credentials from equivalence class signatures","volume":"2023","author":"Mir Omid","year":"2023","unstructured":"Omid Mir, Daniel Slamanig, Balthazar Bauer, and Rene Mayrhofer. 2023. Practical delegatable anonymous credentials from equivalence class signatures. Proceedings on Privacy Enhancing Technologies 2023, 3 (2023), 488\u2013513.","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"e_1_3_3_123_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF02113297"},{"key":"e_1_3_3_124_2","first-page":"111","volume-title":"Proceedings of the CT-RSA","author":"Pointcheval David","year":"2016","unstructured":"David Pointcheval and Olivier Sanders. 2016. Short randomizable signatures. In Proceedings of the CT-RSA. 111\u2013126."},{"key":"e_1_3_3_125_2","first-page":"319","volume-title":"Proceedings of the CT-RSA","author":"Pointcheval David","year":"2018","unstructured":"David Pointcheval and Olivier Sanders. 2018. Reassessing security of randomizable signatures. In Proceedings of the CT-RSA. 319\u2013338."},{"key":"e_1_3_3_126_2","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1007\/978-3-031-47818-5_10","volume-title":"Proceedings of the Cryptography and Coding","author":"Putman Colin","year":"2024","unstructured":"Colin Putman and Keith M. Martin. 2024. Selective delegation of attributes in mercurial signature credentials. In Proceedings of the Cryptography and Coding. 181\u2013196."},{"key":"e_1_3_3_127_2","first-page":"2462","volume-title":"Proceedings of the IEEE S&P","author":"Qin Xianrui","year":"2023","unstructured":"Xianrui Qin, Shimin Pan, Arash Mirzaei, Zhimei Sui, O\u011fuzhan Ersoy, Amin Sakzad, Muhammed F. Esgin, Joseph K. Liu, Jiangshan Yu, and Tsz Hon Yuen. 2023. BlindHub: Bitcoin-compatible privacy-preserving payment channel hubs supporting variable amounts. In Proceedings of the IEEE S&P. 2462\u20132480."},{"key":"e_1_3_3_128_2","first-page":"1126","volume-title":"Proceedings of the AsiaCCS","author":"Sanders Olivier","year":"2022","unstructured":"Olivier Sanders. 2022. EPID with efficient proof of non-revocation. In Proceedings of the AsiaCCS. 1126\u20131138."},{"key":"e_1_3_3_129_2","first-page":"177","volume-title":"Proceedings of the CT-RSA","author":"Sanders Olivier","year":"2021","unstructured":"Olivier Sanders and Jacques Traor\u00e9. 2021. EPID with malicious revocation. In Proceedings of the CT-RSA. 177\u2013200."},{"key":"e_1_3_3_130_2","first-page":"239","volume-title":"Proceedings of the CRYPTO","author":"Schnorr C. P.","year":"1990","unstructured":"C. P. Schnorr. 1990. Efficient identification and signatures for smart cards. In Proceedings of the CRYPTO. 239\u2013252."},{"key":"e_1_3_3_131_2","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/978-3-030-92548-2_1","volume-title":"Proceedings of the International Conference on Cryptology and Network Security","author":"Sedaghat Mahdi","year":"2021","unstructured":"Mahdi Sedaghat and Bart Preneel. 2021. Cross-domain attribute-based access control encryption. In Proceedings of the International Conference on Cryptology and Network Security. 3\u201323."},{"key":"e_1_3_3_132_2","article-title":"Double issuer-hiding attribute-based credentials from tag-based aggregatable mercurial signatures","author":"Shi Rui","year":"2023","unstructured":"Rui Shi, Yang Yang, Yingjiu Li, Huamin Feng, Guozhen Shi, Hwee Hwa Pang, and Robert H. Deng. 2023. Double issuer-hiding attribute-based credentials from tag-based aggregatable mercurial signatures. IEEE Transactions on Dependable and Secure Computing 21, 4 (2023), 2585\u20132602.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_3_133_2","first-page":"256","volume-title":"Proceedings of the EUROCRYPT","author":"Shoup Victor","year":"1997","unstructured":"Victor Shoup. 1997. Lower bounds for discrete logarithms and related problems. In Proceedings of the EUROCRYPT. 256\u2013266."},{"key":"e_1_3_3_134_2","first-page":"285","volume-title":"Proceedings of the Information Security and Cryptology","author":"Steinfeld Ron","year":"2002","unstructured":"Ron Steinfeld, Laurence Bull, and Yuliang Zheng. 2002. Content extraction signatures. In Proceedings of the Information Security and Cryptology. 285\u2013304."},{"key":"e_1_3_3_135_2","first-page":"1834","volume-title":"Proceedings of the IEEE S&P","author":"Tairi Erkan","year":"2021","unstructured":"Erkan Tairi, Pedro Moreno-Sanchez, and Matteo Maffei. 2021. A2L: Anonymous atomic locks for scalability in payment channel hubs. In Proceedings of the IEEE S&P. 1834\u20131851."},{"key":"e_1_3_3_136_2","doi-asserted-by":"crossref","unstructured":"Giulia Traverso Denise Demirel and Johannes Buchmann. 2016. Homomorphic Signature Schemes: A Survey. Vol. 1. Springer International Publishing 11\u201321.","DOI":"10.1007\/978-3-319-32115-8_2"},{"key":"e_1_3_3_137_2","doi-asserted-by":"crossref","first-page":"444","DOI":"10.1007\/978-3-030-51280-4_24","volume-title":"Proceedings of the Financial Cryptography and Data Security","author":"Wahby Riad S.","year":"2020","unstructured":"Riad S. Wahby, Dan Boneh, Christopher Jeffrey, and Joseph Poon. 2020. An airdrop that preserves recipient privacy. In Proceedings of the Financial Cryptography and Data Security. 444\u2013463."},{"key":"e_1_3_3_138_2","first-page":"748","volume-title":"Proceedings of the IEEE S&P","author":"Wang Xiuhua","year":"2021","unstructured":"Xiuhua Wang and Sherman S. M. Chow. 2021. Cross-domain access control encryption: Arbitrary-policy, constant-size, efficient. In Proceedings of the IEEE S&P. 748\u2013761."},{"key":"e_1_3_3_139_2","first-page":"114","volume-title":"Proceedings of the EUROCRYPT","author":"Waters Brent","year":"2005","unstructured":"Brent Waters. 2005. Efficient identity-based encryption without random oracles. In Proceedings of the EUROCRYPT. 114\u2013127."},{"key":"e_1_3_3_140_2","article-title":"FDAAC-CR: Practical delegatable attribute-based anonymous credentials with fine-grained delegation management and chainable revocation","author":"Xie Min","year":"2025","unstructured":"Min Xie, Peichen Ju, Yanqi Zhao, Zoe L Jiang, Man Ho Au, Junbin Fang, Yong Yu, and Xuan Wang. 2025. FDAAC-CR: Practical delegatable attribute-based anonymous credentials with fine-grained delegation management and chainable revocation. IEEE Transactions on Information Forensics and Security 20 (2025), 7572\u20137587.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_3_141_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2025.104058"},{"key":"e_1_3_3_142_2","first-page":"419","volume-title":"Proceedings of the International Conference on Frontiers in Cyber Security","author":"Zhou Jiacheng","year":"2023","unstructured":"Jiacheng Zhou and Zhenhua Liu. 2023. An improved updatable signature scheme with weakened token. In Proceedings of the International Conference on Frontiers in Cyber Security. 419\u2013438."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3806201","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T16:09:49Z","timestamp":1778861389000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3806201"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,15]]},"references-count":141,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2026,9,30]]}},"alternative-id":["10.1145\/3806201"],"URL":"https:\/\/doi.org\/10.1145\/3806201","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,15]]},"assertion":[{"value":"2025-05-13","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-24","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-15","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}