Solutions for DDoS protection employed by content delivery networks often burden honest users, especially those using privacy-enhancing tools like VPNs, by forcing them to solve many CAPTCHAs. Helping users avoid repeated CAPTCHAs, anonymous tokens (ATs) now offer a practical alternative to traditional anonymous credentials (ACs). Evolution of ATs, driven by IETF standardization, introduced features like the private metadata bit (Crypto ’20, Eurocrypt ’22), which encrypts challenge results for verifiers, preventing automated CAPTCHA solver. Regrettably, recent designs overlooked the original goal (PoPETS ’18) of batch-issuing tokens along with efficient batch proofs for validation. Moreover, most solutions lack post-quantum security, except a direct adaptation from ACs (ePrint ’23) that lacks private metadata support. Adopting lattice-based cryptography in existing AT designs is non-trivial, as they often employ intricate algebraic structures to ensure efficiency. Notably, a lattice-based AT in the keyed-verification setting that supports both batch proofs and private metadata bit remains absent. For the first time, we propose a batch anonymous MAC token system from lattices, integrating techniques from verifiable oblivious pseudorandom function (PKC ’21) and practical zero-knowledge proof (Crypto ’22). Extending this design, our AT system supports public metadata (Eurocrypt ’22, FC ’22, PoPETS ’25) with minimal computational overhead. In practice, our AT is only 432 bytes with optimized parameters.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Batch Anonymous MAC Tokens from Lattices

  • Yingfei Yan,
  • Sherman S. M. Chow,
  • Lucien K. L. Ng,
  • Harry W. H. Wong,
  • Yongjun Zhao,
  • Baocang Wang

摘要

Solutions for DDoS protection employed by content delivery networks often burden honest users, especially those using privacy-enhancing tools like VPNs, by forcing them to solve many CAPTCHAs. Helping users avoid repeated CAPTCHAs, anonymous tokens (ATs) now offer a practical alternative to traditional anonymous credentials (ACs). Evolution of ATs, driven by IETF standardization, introduced features like the private metadata bit (Crypto ’20, Eurocrypt ’22), which encrypts challenge results for verifiers, preventing automated CAPTCHA solver. Regrettably, recent designs overlooked the original goal (PoPETS ’18) of batch-issuing tokens along with efficient batch proofs for validation. Moreover, most solutions lack post-quantum security, except a direct adaptation from ACs (ePrint ’23) that lacks private metadata support. Adopting lattice-based cryptography in existing AT designs is non-trivial, as they often employ intricate algebraic structures to ensure efficiency. Notably, a lattice-based AT in the keyed-verification setting that supports both batch proofs and private metadata bit remains absent. For the first time, we propose a batch anonymous MAC token system from lattices, integrating techniques from verifiable oblivious pseudorandom function (PKC ’21) and practical zero-knowledge proof (Crypto ’22). Extending this design, our AT system supports public metadata (Eurocrypt ’22, FC ’22, PoPETS ’25) with minimal computational overhead. In practice, our AT is only 432 bytes with optimized parameters.