Blocklistable Anonymous Credential for Circuits with Post-quantum Security
摘要
A blocklistable anonymous credential system (BLAC) allows a service provider to decide if it would like to accept an anonymous user according to his historical behaviors. Security of such systems requires that 1) a user can be authenticated if and only if his historical behaviors satisfy a given policy and that 2) no additional information (besides the result of the authentication) is revealed to the service provider. Existing constructions of BLAC only consider very restricted access policies, e.g., blocking a user if he has an authentication record that is marked as misbehaved. Besides, most of them are constructed from number theoretical assumptions, which are vulnerable to the quantum attacks. In this work, we advance the state-of-the-art for BLAC. First, we present the notion of BLAC for circuits, where the service provider can use general policies that are represented by any boolean circuits and admit a user if and only if his historical records satisfy the circuit. Then, we construct BLAC systems for arbitrary circuits from lattice assumptions, which offer post-quantum security. To obtain our constructions, we propose efficient lattice-based zero-knowledge arguments for various relations, which may be of independent interest. Besides, we demonstrate the practicality of our constructions by providing an estimation of the communication cost of our system.