{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T14:12:28Z","timestamp":1785420748815,"version":"3.56.0"},"reference-count":54,"publisher":"International Association for Cryptologic Research","issue":"3","license":[{"start":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T00:00:00Z","timestamp":1751846400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,9,2]]},"abstract":"<jats:p>An anonymous credential (AC) system with partial disclosure allows users to prove possession of a credential issued by an issuer while selectively disclosing a subset of their attributes to a verifier in a privacy-preserving manner. In keyed-verification AC (KVAC) systems, the issuer and verifier share a secret key. Existing KVAC schemes rely on computationally expensive zero-knowledge proofs during credential presentation, with the presentation size growing linearly with the number of attributes. In this work, we propose two highly efficient KVAC constructions that eliminate the need for zero-knowledge proofs during the credential presentation and achieve constant-size presentations.<\/jats:p>\n                  <jats:p>Our first construction adapts the approach of Fuchsbauer, Hanser and Slamanig (JoC'19), which achieved constant-size credential presentation in a publicly verifiable setting using their proposed structure-preserving signatures on equivalence classes (SPS-EQ) and set commitment schemes, to the KVAC setting. We introduce structure-preserving message authentication codes on equivalence classes (SP-MAC-EQ) and designated-verifier set commitments (DVSC), resulting in a KVAC system with constant-size credentials (2 group elements) and presentations (5 group elements). To avoid the bilinear groups and pairing operations required by SP-MAC-EQ, our second construction uses a homomorphic MAC with a simplified DVSC. While this sacrifices constant-size credentials (n+2 group elements, where n is the number of attributes), it retains constant-size presentations (2 group elements) in a pairingless setting.<\/jats:p>\n                  <jats:p>We formally prove the security of both constructions and provide open-source implementation results demonstrating their practicality. We extensively benchmarked our KVAC protocols and, additionally, bechmarked the efficiency of our SP-MAC-EQ scheme against the original SPS-EQ scheme, showcasing significant performance improvements.<\/jats:p>","DOI":"10.62056\/aey7n59p1","type":"journal-article","created":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T18:49:52Z","timestamp":1759776592000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":2,"title":["Keyed-Verification Anonymous Credentials with Highly Efficient Partial Disclosure"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-4908-649X","authenticated-orcid":false,"given":"Omid","family":"Mirzamohammadi","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"COSIC, KU Leuven","place":["Kasteelpark Arenberg 10, Leuven, 3001, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9704-2124","authenticated-orcid":false,"given":"Jan","family":"Bobolz","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01nrxwf90","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Edinburgh","place":["10 Crichton Street, Edinburgh, EH8 9AB, UK"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1507-6927","authenticated-orcid":false,"family":"Mahdi Sedaghat","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"COSIC, KU Leuven","place":["Kasteelpark Arenberg 10, Leuven, 3001, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3352-6968","authenticated-orcid":false,"given":"Emad","family":"Beni","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"COSIC, KU Leuven","place":["Kasteelpark Arenberg 10, Leuven, 3001, Belgium"]},{"id":[{"id":"https:\/\/ror.org\/04xze1462","id-type":"ROR","asserted-by":"publisher"}],"name":"Nokia Bell Labs","place":["Copernicuslaan 50, Antwerp, 2018, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5128-3608","authenticated-orcid":false,"given":"Aysajan","family":"Abidin","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"COSIC, KU Leuven","place":["Kasteelpark Arenberg 10, Leuven, 3001, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9084-698X","authenticated-orcid":false,"given":"Dave","family":"Singel\u00e9e","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"COSIC, KU Leuven","place":["Kasteelpark Arenberg 10, Leuven, 3001, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2005-9651","authenticated-orcid":false,"given":"Bart","family":"Preneel","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/05f950310","id-type":"ROR","asserted-by":"publisher"}],"name":"COSIC, KU Leuven","place":["Kasteelpark Arenberg 10, Leuven, 3001, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,10,6]]},"reference":[{"key":"ref1:C:Chaum82","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/978-1-4757-0602-4_18","article-title":"Blind Signatures for Untraceable Payments","author":"David Chaum","year":"1982"},{"key":"ref2:EC:CamLys01","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/3-540-44987-6_7","article-title":"An Efficient System for Non-transferable Anonymous\n  Credentials with Optional Anonymity Revocation","volume":"2045","author":"Jan Camenisch","year":"2001"},{"key":"ref3:CCS:ChaMeiZav14","doi-asserted-by":"publisher","first-page":"1205","DOI":"10.1145\/2660267.2660328","article-title":"Algebraic MACs and Keyed-Verification Anonymous\n  Credentials","author":"Melissa Chase","year":"2014"},{"key":"ref4:CCS:ChaPerZav20","doi-asserted-by":"publisher","first-page":"1445","DOI":"10.1145\/3372297.3417887","article-title":"The Signal Private Group System and Anonymous Credentials\n  Supporting Efficient Verifiable Encryption","author":"Melissa Chase","year":"2020"},{"key":"ref5:SAC:BBDT16","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"360","DOI":"10.1007\/978-3-319-69453-5_20","article-title":"Improved Algebraic MACs and Practical Keyed-Verification\n  Anonymous Credentials","volume":"10532","author":"Amira Barki","year":"2016"},{"key":"ref6:PKC:CouRei19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1007\/978-3-030-17253-4_3","article-title":"Non-interactive Keyed-Verification Anonymous Credentials","volume":"11442","author":"Geoffroy Couteau","year":"2019"},{"key":"ref7:DBLP:conf\/sec\/CamenischDDH19","series-title":"IFIP Advances in Information and Communication\n  Technology","doi-asserted-by":"publisher","first-page":"286","DOI":"10.1007\/978-3-030-22312-0_20","article-title":"Fast Keyed-Verification Anonymous Credentials on Standard\n  Smart Cards","volume":"562","author":"Jan Camenisch","year":"2019"},{"key":"ref8:C:AttCra20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1007\/978-3-030-56877-1_18","article-title":"Compressed $\\varSigma$-Protocol Theory and Practical\n  Application to Plug & Play Secure Algorithmics","volume":"12172","author":"Thomas Attema","year":"2020"},{"key":"ref9:JC:FucHanSla19","doi-asserted-by":"publisher","first-page":"498","DOI":"10.1007\/s00145-018-9281-4","article-title":"Structure-Preserving Signatures on Equivalence Classes and\n  Constant-Size Anonymous Credentials","volume":"32","author":"Georg Fuchsbauer","year":"2019","journal-title":"Journal of Cryptology"},{"key":"ref10:eprint:Orru","volume-title":"Revisiting Keyed-Verification Anonymous Credentials","author":"Michele Orr\u00f9","year":"2024"},{"key":"ref11:RSA:LNguyen05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1007\/978-3-540-30574-3_19","article-title":"Accumulators from Bilinear Pairings and Applications","volume":"3376","author":"Lan Nguyen","year":"2005"},{"key":"ref12:ASIACCS:BEKSS20","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1145\/3320269.3384769","article-title":"Privacy-Preserving Incentive Systems with Highly Efficient\n  Point-Collection","author":"Jan Bobolz","year":"2020"},{"key":"ref13:SPS-EQ-AGM","isbn-type":"print","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-981-96-0888-1_1","article-title":"On Security Proofs of\u00a0Existing Equivalence Class Signature\n  Schemes","author":"Balthazar Bauer","year":"2025","ISBN":"https:\/\/id.crossref.org\/isbn\/9789819608881"},{"key":"ref14:github","volume-title":"KVACs, SPS-EQ and SP-MAC-EQ Implementations","author":"Emad Heydari Beni","year":"2025"},{"key":"ref15:PoPETS:TulGol23","doi-asserted-by":"publisher","first-page":"494","DOI":"10.56553\/popets-2023-0029","article-title":"Lox: Protecting the Social Graph in Bridge Distribution","volume":"2023","author":"Lindsey Tulloch","year":"2023","journal-title":"PoPETs"},{"key":"ref16:cryptoeprint:2025\/619","volume-title":"Making BBS Anonymous Credentials eIDAS 2.0 Compliant","author":"Nicolas Desmoulins","year":"2025"},{"key":"ref17:ServerAided","isbn-type":"print","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1007\/978-3-032-01887-8_10","article-title":"Server-Aided Anonymous Credentials","author":"Rutchathon Chairattana-Apirom","year":"2025","ISBN":"https:\/\/id.crossref.org\/isbn\/9783032018878"},{"key":"ref18:SCN:CamLys02","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"268","DOI":"10.1007\/3-540-36413-7_20","article-title":"A Signature Scheme with Efficient Protocols","volume":"2576","author":"Jan Camenisch","year":"2003"},{"key":"ref19:C:CamLys04","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1007\/978-3-540-28628-8_4","article-title":"Signature Schemes and Anonymous Credentials from Bilinear\n  Maps","volume":"3152","author":"Jan Camenisch","year":"2004"},{"key":"ref20:CCS:BalLys13","doi-asserted-by":"publisher","first-page":"1087","DOI":"10.1145\/2508859.2516687","article-title":"Anonymous credentials light","author":"Foteini Baldimtsi","year":"2013"},{"key":"ref21:ASIACCS:LMPY16","doi-asserted-by":"publisher","first-page":"511","DOI":"10.1145\/2897845.2897898","article-title":"Practical \u201cSignatures with Efficient Protocols\u201d from\n  Simple Assumptions","author":"Beno\u00eet Libert","year":"2016"},{"key":"ref22:RSA:PoiSan16","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-319-29485-8_7","article-title":"Short Randomizable Signatures","volume":"9610","author":"David Pointcheval","year":"2016"},{"key":"ref23:AC:CKPSS23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"348","DOI":"10.1007\/978-981-99-8724-5_11","article-title":"Threshold Structure-Preserving Signatures","volume":"14439","author":"Elizabeth C. Crites","year":"2023"},{"key":"ref24:AC:HanSla14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"491","DOI":"10.1007\/978-3-662-45611-8_26","article-title":"Structure-Preserving Signatures on Equivalence Classes and\n  Their Application to Anonymous Credentials","volume":"8873","author":"Christian Hanser","year":"2014"},{"key":"ref25:RSA:CriLys19","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"535","DOI":"10.1007\/978-3-030-12612-4_27","article-title":"Delegatable Anonymous Credentials from Mercurial\n  Signatures","volume":"11405","author":"Elizabeth C. Crites","year":"2019"},{"key":"ref26:IMA:PutMar23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-031-47818-5_10","article-title":"Selective Delegation of Attributes in Mercurial Signature\n  Credentials","volume":"14421","author":"Colin Putman","year":"2023"},{"key":"ref27:CCS:HanSla21","doi-asserted-by":"publisher","first-page":"2004","DOI":"10.1145\/3460120.3484582","article-title":"With a Little Help from My Friends: Constructing Practical\n  Anonymous Credentials","author":"Lucjan Hanzlik","year":"2021"},{"key":"ref28:PKC:ConLafPer22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"409","DOI":"10.1007\/978-3-030-97121-2_15","article-title":"Improved Constructions of Anonymous Credentials from\n  Structure-Preserving Signatures on Equivalence Classes","volume":"13177","author":"Aisling Connolly","year":"2022"},{"key":"ref29:SCN:BauFuc20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-030-57990-6_18","article-title":"Efficient Signatures on Randomizable Ciphertexts","volume":"12238","author":"Balthazar Bauer","year":"2020"},{"key":"ref30:PETS:BadSedWal24","doi-asserted-by":"publisher","first-page":"226","DOI":"10.56553\/POPETS-2024-0115","article-title":"Unlinkable Policy-Compliant Signatures for Compliant and\n  Decentralized Anonymous Payments","volume":"2024","author":"Christian Badertscher","year":"2024","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"ref31:AC:CDHK15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"262","DOI":"10.1007\/978-3-662-48800-3_11","article-title":"Composable and Modular Anonymous Credentials: Definitions\n  and Practical Constructions","volume":"9453","author":"Jan Camenisch","year":"2015"},{"key":"ref32:PKC:Sanders20","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"628","DOI":"10.1007\/978-3-030-45388-6_22","article-title":"Efficient Redactable Signature and Application to Anonymous\n  Credentials","volume":"12111","author":"Olivier Sanders","year":"2020"},{"key":"ref33:C:BonBoySha04","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-540-28628-8_3","article-title":"Short Group Signatures","volume":"3152","author":"Dan Boneh","year":"2004"},{"key":"ref34:JC:BonBoy08","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1007\/s00145-007-9005-7","article-title":"Short Signatures Without Random Oracles and the SDH\n  Assumption in Bilinear Groups","volume":"21","author":"Dan Boneh","year":"2008","journal-title":"Journal of Cryptology"},{"key":"ref35:PKC:FucGay18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1007\/978-3-319-76581-5_6","article-title":"Weakly Secure Equivalence-Class Signatures from Standard\n  Assumptions","volume":"10770","author":"Georg Fuchsbauer","year":"2018"},{"key":"ref36:C:BlaKilPan14","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"408","DOI":"10.1007\/978-3-662-44371-2_23","article-title":"(Hierarchical) Identity-Based Encryption from Affine\n  Message Authentication","volume":"8616","author":"Olivier Blazy","year":"2014"},{"key":"ref37:GALBRAITH20083113","doi-asserted-by":"publisher","first-page":"3113","DOI":"10.1016\/j.dam.2007.12.010","article-title":"Pairings for cryptographers","volume":"156","author":"Steven D. Galbraith","year":"2008","journal-title":"Discrete Applied Mathematics","ISSN":"https:\/\/id.crossref.org\/issn\/0166-218X","issn-type":"electronic"},{"key":"ref38:C:CamSta97","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1007\/BFb0052252","article-title":"Efficient Group Signature Schemes for Large Groups (Extended\n  Abstract)","volume":"1294","author":"Jan Camenisch","year":"1997"},{"key":"ref39:C:AGHO11","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"649","DOI":"10.1007\/978-3-642-22792-9_37","article-title":"Optimal Structure-Preserving Signatures in Asymmetric\n  Bilinear Groups","volume":"6841","author":"Masayuki Abe","year":"2011"},{"key":"ref40:CCS:BBDE19","doi-asserted-by":"publisher","first-page":"1671","DOI":"10.1145\/3319535.3354223","article-title":"Updatable Anonymous Credentials and Applications to\n  Incentive Systems","author":"Johannes Bl\u00f6mer","year":"2019"},{"key":"ref41:DistanceBounding","isbn-type":"print","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-41227-1_1","article-title":"On Modeling Terrorist Frauds","author":"Serge Vaudenay","year":"2013","ISBN":"https:\/\/id.crossref.org\/isbn\/9783642412271"},{"key":"ref42:arkworks","volume-title":"zkSNARK ecosystem","author":"Arkworks contributors","year":"2022"},{"key":"ref43:EC:DKPW12","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"355","DOI":"10.1007\/978-3-642-29011-4_22","article-title":"Message Authentication, Revisited","volume":"7237","author":"Yevgeniy Dodis","year":"2012"},{"key":"ref44:TCC:Klooss21","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"558","DOI":"10.1007\/978-3-030-90459-3_19","article-title":"On Expected Polynomial Runtime in Cryptography","volume":"13042","author":"Michael Kloo\u00df","year":"2021"},{"key":"ref45:C:Schnorr89","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/0-387-34805-0_22","article-title":"Efficient Identification and Signatures for Smart Cards","volume":"435","author":"Claus-Peter Schnorr","year":"1990"},{"key":"ref46:AFRICACRYPT:Maurer09","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"272","DOI":"10.1007\/978-3-642-02384-2_17","article-title":"Unifying Zero-Knowledge Proofs of Knowledge","volume":"5580","author":"Ueli M. Maurer","year":"2009"},{"key":"ref47:C:FiaSha86","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/3-540-47721-7_12","article-title":"How to Prove Yourself: Practical Solutions to\n  Identification and Signature Problems","volume":"263","author":"Amos Fiat","year":"1987"},{"key":"ref48:EC:Shoup97","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/3-540-69053-0_18","article-title":"Lower Bounds for Discrete Logarithms and Related Problems","volume":"1233","author":"Victor Shoup","year":"1997"},{"key":"ref49:maurer2005abstract","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11586821_1","article-title":"Abstract models of computation in cryptography","author":"Ueli Maurer","year":"2005"},{"key":"ref50:EPRINT:BonBoyGoh05","volume-title":"Hierarchical Identity Based Encryption with Constant Size\n  Ciphertext","author":"Dan Boneh","year":"2005"},{"key":"ref51:IDbasedEncryption","isbn-type":"print","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1007\/11426639_26","article-title":"Hierarchical Identity Based Encryption with Constant Size\n  Ciphertext","author":"Dan Boneh","year":"2005","ISBN":"https:\/\/id.crossref.org\/isbn\/9783540320555"},{"key":"ref52:TCC:LipParSii23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"363","DOI":"10.1007\/978-3-031-48624-1_14","article-title":"Algebraic Group Model with Oblivious Sampling","volume":"14372","author":"Helger Lipmaa","year":"2023"},{"key":"ref53:CiC:BFHK24","doi-asserted-by":"publisher","first-page":"31","DOI":"10.62056\/anr-zoja5","article-title":"The Uber-Knowledge Assumption: A Bridge to the AGM","volume":"1","author":"Balthazar Bauer","year":"2024","journal-title":"CiC"},{"key":"ref54:AC:BelFucSca16","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"777","DOI":"10.1007\/978-3-662-53890-6_26","article-title":"NIZKs with an Untrusted CRS: Security in the Face of\n  Parameter Subversion","volume":"10032","author":"Mihir Bellare","year":"2016"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T20:22:49Z","timestamp":1759782169000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/3\/15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,6]]},"references-count":54,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,10,6]]}},"URL":"https:\/\/doi.org\/10.62056\/aey7n59p1","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,6]]},"assertion":[{"value":"2025-07-07","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-3-17"}}