International Association for Cryptologic Research

International Association
for Cryptologic Research


Anonymous Tokens with Private Metadata Bit

Ben Kreuter , Google
Tancrède Lepoint , Google
Michele Orrù , ENS, CNRS, PSL University, Paris
Mariana P. Raykova , Google
DOI: 10.1007/978-3-030-56784-2_11 (login may be required)
Search ePrint
Search Google
Presentation: Slides
Conference: CRYPTO 2020
Abstract: We present a cryptographic construction for anonymous tokens with private metadata bit, called PMBTokens. This primitive enables an issuer to provide a user with a lightweight, single-use anonymous trust token that can embed a single private bit, which is accessible only to the party who holds the secret authority key and is private with respect to anyone else. Our construction generalizes and extends the functionality of Privacy Pass (PETS’18) with this private metadata bit capability. It provides unforgeability, unlinkability, and privacy for the metadata bit properties based on the DDH and CTDH assumptions in the random oracle model. Both Privacy Pass and PMBTokens rely on non-interactive zero-knowledge proofs (NIZKs). We present new techniques to remove the need for NIZKs, while still achieving unlinkability. We implement our constructions and we report their efficiency costs.
Video from CRYPTO 2020
  title={Anonymous Tokens with Private Metadata Bit},
  author={Ben Kreuter and Tancrède Lepoint and Michele Orrù and Mariana P. Raykova},