Dates are inconsistent

Dates are inconsistent

206 results sorted by ID

2026/1315 (PDF) Last updated: 2026-06-25
VERDICT: A Cryptographically Verifiable Framework for Secure Data Lineage in Decentralized DAGs
Bilel Zaghdoudi, Maria Potop Butucaru
Foundations

Ensuring the integrity and traceability of data transformations in distributed systems presents significant challenges, particularly in environments where data privacy and decentralization are paramount. This paper introduces a novel secure lineage verification system based on Directed Acyclic Graphs (DAGs) and homomorphic hash functions, VERDICT. Our approach represents data artifacts and their transformations as two interconnected DAGs: a Data DAG tracking data dependencies and an...

2026/1268 (PDF) Last updated: 2026-06-16
Decentralized Multi-Authority (Attribute-Based) Traitor Tracing
Pratish Datta, Robert Schädlich, Erkan Tairi
Public-key cryptography

We initiate the study of multi-authority traitor tracing (MA-TT), a decentralized variant of traitor tracing in which tracing capabilities are distributed across multiple independent authorities rather than concentrated in a single trusted entity. Ciphertexts are associated with tracing policies over a collection of authorities, specifying which subsets of authorities are authorized to jointly accuse a user of contributing to a pirate decoder. This enables fine-grained control over tracing...

2026/1213 (PDF) Last updated: 2026-06-09
Another Look at Non-Frameability in Group Signatures for Anonymous Auctions
Cao Shiqi, Keita Emura
Cryptographic protocols

In addition to anonymity and traceability, which are the primary security properties of group signatures, non‑frameability is also defined (Bellare-Shi-Zhang, CT-RSA 2005). This property guarantees that even an adversary colluding with all authorities (the opener and the issuer) cannot produce a signature that frames an honest user, and it is regarded as a security notion that protects users. In this short note, we introduce a new perspective on non-frameability, namely that it can also...

2026/1076 (PDF) Last updated: 2026-05-28
Decentralizing Traitor Tracing: A Multi-Authority Approach
Rishab Goyal, Alex Snyder, Saikumar Yadugiri
Public-key cryptography

Traitor tracing [Chor-Fiat-Naor; CRYPTO'94] has historically been formalized through the lens of a $\textit{single}$ trusted authority that samples the master keys and that, therefore, can read every ciphertext on its own. This $\textit{key escrow}$ problem makes traditional traitor tracing fundamentally incompatible with end-to-end encrypted broadcast networks. In this work, we study introduce $\textit{multi-authority traitor tracing}$ (MA-TT) [Goyal-Yadugiri; ePrint] a new decentralized...

2026/1059 (PDF) Last updated: 2026-05-26
Threshold Traitor Tracing with Partial-Insider Resilience
Jan Bormet, Hussien Othman
Public-key cryptography

Threshold traitor tracing (Boneh et al. Crypto'24) addresses collusion in threshold encryption by tracing parties who collude to build illegal decryption devices called decoders. However, the original definition does not capture settings where adversaries can access partial decryptions published during normal system operation. In such settings, decoders sold to external buyers could depend on inputting additional partial decryptions from honest parties. Moreover, colluders may exploit...

2026/766 (PDF) Last updated: 2026-04-18
Dynamic Group Time-based One-time Passwords
Xuelian Cao, Zheng Yang, Jianting Ning, Chenglu Jin, Zhiming Liu, Jianying Zhou
Public-key cryptography

Group time-based one-time passwords (GTOTP) is a novel lightweight cryptographic primitive for achieving anonymous client authentication, which enables the efficient generation of time-based one-time passwords on behalf of a group without revealing any information about the actual client's identity beyond their group membership. The security properties of GTOTP regarding anonymity and traceability have been formulated in a static group management setting (where all group members should be...

2026/697 (PDF) Last updated: 2026-04-09
Post-Quantum Secure k-Times Traceable Ring Signature
Vishal Pareek, Aditi Kar Gangopadhyay, Sugata Gangopadhyay

Ring signatures are cryptographic primitives that enable a user to sign a message on behalf of a group of users in an anonymous manner. The anonymity of the signer is the fundamental security property of ring signatures. However, unrestricted anonymity can be misused, as a malicious signer could use it to send spam or excessive messages. To address this issue, a controlled restriction on signer anonymity is required, which makes such schemes more practical. In this paper, we propose a...

2026/595 (PDF) Last updated: 2026-03-26
Registration-Optimized Dynamic Group Time-based One-time Passwords for Mobile Access
Jiaqing Guo, Xuelian Cao, Zengpeng Li, Yong Zhou, Zheng Yang, Jianying Zhou
Cryptographic protocols

Mobile access within public finance and enterprise environments often requires lightweight anonymous authentication, allowing users to prove authorization without disclosing their identities. Group Time-based One-Time Passwords (GTOTP) has recently been proposed as a lightweight primitive meeting this need with post-quantum security. To address dynamic group membership, Cao et al. introduced DGTOne, the first dynamic GTOTP construction. It employs chameleon hashes to precompute a fixed set...

2026/435 (PDF) Last updated: 2026-03-03
Information-Theoretic Strong Traceable Secret Sharing Schemes
Oriol Farràs, Miquel Guiot
Cryptographic protocols

Traceable secret sharing complements traditional schemes by enabling the identification of parties who sell their shares. Recently, two independent works extended traceable secret sharing to general access structures. Goyal, Jain, and Partap [EC'26] introduced a model in which a reconstruction box is augmented with a label $I \subseteq [n]$ and is only required to distinguish between two secrets when queried with the shares of parties in $I$. Based on how this label relates to the...

2026/405 (PDF) Last updated: 2026-03-02
Group Encryption with Oblivious Traceability
Khoa Nguyen, Yanhong Xu, Nam Tran, Willy Susilo, Huaxiong Wang
Cryptographic protocols

We revisit Group Encryption (GE)—an encryption analogue of group signatures introduced by Kiayias et al. (Asiacrypt 2007). A GE system simultaneously provides anonymity and traceability for receivers who are certified group members, enabling a range of privacy-preserving applications. While prior work has extensively addressed \emph{how} to trace receivers in GE, the question of \emph{why} a ciphertext should be traceable remains unexplored. Unlike group signatures, where opening can be...

2026/402 (PDF) Last updated: 2026-03-03
Conditionally Linkable Attribute-Based Signatures
Minh Pham, Khoa Nguyen, Slim Bettaieb, Mukul Kulkarni, Willy Susilo
Cryptographic protocols

Attribute-Based Signatures (ABS) enable users to authenticate messages under expressive attribute policies while remaining anonymous. Existing ABS variants, however, treat linkability as a static, system-wide property: signatures are either always unlinkable, as in standard ABS, or globally linkable, as in traceable or accountable extensions. This rigid dichotomy fails to capture scenarios where correlation should arise only under explicitly declared conditions. This work introduces...

2026/282 (PDF) Last updated: 2026-02-17
Unforgeable Watermarks for Language Models via Robust Signatures
Huijia Lin, Kameron Shahabi, Min Jae Song
Foundations

Language models now routinely produce text that is difficult to distinguish from human writing, raising the need for robust tools to verify content provenance. Watermarking has emerged as a promising countermeasure, with existing work largely focused on model quality preservation and robust detection. However, current schemes provide limited protection against false attribution. We strengthen the notion of soundness by introducing two novel guarantees: unforgeability and recoverability....

2026/181 (PDF) Last updated: 2026-02-06
Towards Public Tracing: Collaborative Traceable Secret Sharing
Pousali Dey, Rittwik Hajra, Subha Kar, Soumit Pal
Cryptographic protocols

In a $(t,n)$-threshold secret sharing scheme, secrecy holds as long as fewer than $t$ servers collude. If $f < t$ parties are corrupt and they sell their shares, there is no mechanism to hold them accountable in classical secret sharing schemes. Goyal–Song–Srinivasan [CRYPTO'21] introduced Traceable Secret Sharing ($\mathsf{TSS}$) and later Boneh–Partap–Rotem [CRYPTO'24] made it practical: $f<t$ corrupt servers produce a reconstruction box $\mathcal{R}$ that, given $t-f$ extra shares,...

2025/2261 (PDF) Last updated: 2026-06-16
TSS-PV: Traceable Secret Sharing with Public Verifiability
Duc Anh Luong, Jong Hwan Park, Changmin Lee, Hyoseung Kim
Cryptographic protocols

High-value custodial systems require both Public Verifiability to audit key distribution and Traceability to identify insider leakage via black-box \textit{reconstruction boxes}. Existing schemes achieve one property but not both, leaving practical systems exposed to either undetectable dealer misbehavior or untraceable share leakage. Combining these properties introduces the Provenance Paradox: a verifiability-aware reconstruction box with access to verification predicates and public...

2025/2187 (PDF) Last updated: 2025-12-02
Abuse Resistant Traceability with Minimal Trust for Encrypted Messaging Systems
Zhongming Wang, Tao Xiang, Xiaoguo Li, Guomin Yang, Biwen Chen, Ze Jiang, Jiacheng Wang, Chuan Ma, Robert H. Deng
Applications

Encrypted messaging systems provide end-to-end security for users but obstruct content moderation, making it difficult to combat online abuses. Traceability offers a promising solution by enabling platforms to identify the originator/spreader of messages, yet this capability can be abused for mass surveillance of innocent messages. To mitigate this risk, existing approaches restrict traceability to (problematic) messages that are reported by multiple users or are on a predefined blocklist....

2025/2154 (PDF) Last updated: 2026-02-27
Optimal Threshold Traitor Tracing
Sourav Das, Pratish Datta, Aditi Partap, Swagata Sasmal, Mark Zhandry
Public-key cryptography

Threshold encryption distributes decryption capability across $n$ parties such that any $t$ of them can jointly decrypt a ciphertext, while smaller coalitions learn nothing. However, once $t$ or more parties collude, traditional threshold schemes provide no accountability: a coalition of $t$ or more parties can pool its keys into a pirate decoder that enables unrestricted decryption, all without any risk of being exposed. To address this, Boneh, Partap, and Rotem [CRYPTO '24] introduced...

2025/2089 (PDF) Last updated: 2025-11-13
Traceable Bottom-Up Secret Sharing and Law & Order on Community Social Key Recovery (Full Version)
Rittwik Hajra, Subha Kar, Pratyay Mukherjee, Soumit Pal
Cryptographic protocols

A recent work by Kate et al. [EPRINT 2025] proposes a community-based social recovery scheme (SKR), where key-owners can use a subset of other community members as guardians, and in exchange, they play guardians to support other participants' key recovery. Their construction relies on a new concept called bottom-up secret sharing (BUSS). However, they do not consider a crucial feature, called traceability, which ensures that if more than a threshold number of the guardians collude, at least...

2025/1986 (PDF) Last updated: 2025-11-10
Anonymous Authentication and Key Agreement, Revisited
Yanqi Zhao, Xiangyu Liu, Min Xie, Xiaoyi Yang, Jianting Ning, Baodong Qin, Haibin Zhang, Yong Yu
Cryptographic protocols

In NDSS 2024, Yu~et al. proposed AAKA, an Anonymous Authentication and Key Agreement scheme designed to protect users' privacy from mobile tracking by Mobile Network Operators (MNOs). AAKA aims to provide both anti-tracking privacy and traceability (lawful de-anonymization), allowing subscribers to access the network via anonymous proofs while enabling a Law Enforcement Agency (LEA) to trace the real identity if misbehaviors are detected. However, we identify that the AAKA scheme in NDSS...

2025/1980 (PDF) Last updated: 2026-03-17
Traceable Secret Sharing Revisited
Vipul Goyal, Abhishek Jain, Aditi Partap
Foundations

In a secret sharing scheme for a monotone access structure $\mathcal{A}$, one can share a secret among a set of parties such that all subsets of parties authorized by $\mathcal{A}$ can reconstruct the secret while all other subsets learn nothing. However, what if an unauthorized subset of parties collude and offer their shares for sale? Specifically, suppose that the parties pool their shares to create a reconstruction box that reveals the secret upon receiving enough additional shares as...

2025/1873 (PDF) Last updated: 2025-10-08
Threshold Reporting Protocol for Traceability in Anonymous Social Networks
Olivier Blazy, Lola-Baie Mallordy
Cryptographic protocols

As anonymous social networks continue to grow in popularity, they raise serious challenges around abuse, misinformation, and harmful behavior. While traditional de-anonymization techniques can address misuse, they often come at the cost of user privacy. Protecting honest users' privacy while keeping malicious ones accountable remains a complex challenge. A promising alternative is conditional deanonymization, where anonymity is lifted only when abuse is collectively reported and verified...

2025/1807 (PDF) Last updated: 2025-10-02
Traceable Ring Signatures Revisited: Extended Definitions, $O(1)$ Tracing, and Efficient Log-Size Constructions
Xiangyu Liu
Public-key cryptography

Traceable Ring Signatures (TRS) were introduced by Fujisaki and Suzuki~[PKC'07], where a trace algorithm can publicly check if two signatures with the same event label were generated by the same signer (linkability). In addition, if the two signatures correspond to different messages, then the signer's identity is revealed (traceability). Following [PKC'07], most subsequent works adopt the same definitions and consider three security properties, anonymity, linkability, and exculpability....

2025/1752 (PDF) Last updated: 2025-09-26
Foundations of Dynamic Group Signatures: The Case of Malicious Openers and Issuers
Stephan Krenn, Kai Samelin, Daniel Slamanig
Applications

Group signatures enable users to sign on behalf of a group while preserving anonymity, with accountability provided by a designated opener. The first rigorous model for dynamic groups (Bellare, Shi, Zhang, CT--RSA '05) captured anonymity, non-frameability, and traceability, later extended with trace-soundness (Sakai et al., PKC '12) and non-claimability (introduced as ``opening-soundness'' by Bootle et al., ACNS '16 & JoC '20). In practice, issuer and opener are often distinct entities,...

2025/1659 (PDF) Last updated: 2025-09-13
Hurricane Mixer: The Eye in the Storm—Embedding Regulatory Oversight into Cryptocurrency Mixing Services
Zonglun Li, Wangze Ni, Shuhao Zheng, Junliang Luo, Weijie Sun, Lei Chen, Xue Liu, Tianhang Zheng, Zhan Qin, Kui Ren
Applications

While transaction transparency is fundamental, it introduces privacy vulnerabilities for blockchain users requiring confidentiality. Existing privacy mixers, intended to mitigate the issue by offering obfuscation of transactional links, have been leveraged to evade emerging financial regulations in DeFi and facilitate harmful practices within the community. Regulatory concerns, driven by prosocial intentions, are raised to ensure that mixers are used responsibly complying with regulations....

2025/1561 (PDF) Last updated: 2025-08-31
A Traceable Threshold Asmuth--Bloom Secret Sharing Scheme
Maria Leslie, Ratna Dutta
Cryptographic protocols

In a t-out-of-n threshold secret sharing scheme, accountability is crucial when a subset of f < t servers collude to leak secret shares. Traceable Threshold Secret Sharing (TTSS) ensures that leaked shares can be traced back to the compromised servers while preventing false accusations through non-imputability. In Crypto’24, Boneh et al. proposed new definitions and more practical constructions for TTSS based on Shamir’s and Blakley’s secret sharing schemes, removing the practical limitation...

2025/1524 (PDF) Last updated: 2025-08-29
AUPCH: Auditable Unlinkable Payment Channel Hubs
Pedro Moreno-Sanchez, Mohsen Minaei, Srinivasan Raghuraman, Panagiotis Chatzigiannis, Duc V. Le
Applications

Cryptocurrencies, which have gained significant adoption in recent years, face ongoing challenges in scalability and privacy. Payment Channel Hubs (PCHs) constitute a solution to both issues by shifting transactions off the public ledger. Various PCH constructions have been proposed, offering different degrees of unlinkability, efficiency, and inter- operability. However, regulatory compliance remains a significant con- cern, particularly under emerging frameworks like the EU’s Markets...

2025/1347 (PDF) Last updated: 2025-07-24
Public Traceability in Threshold Decryption
Sébastien Canard, Nathan Papon, Duong Hieu Phan
Cryptographic protocols

Tracing techniques have been used to identify users who have leaked their decryption keys in a secure multi-receiver encryption system. Very recently, in the field of distributed cryptography, where trust is distributed, Boneh et al. extended traitor tracing to the framework of threshold decryption, where a single user doesn't hold the whole secret to decrypt but needs to collaborate with others. However, the tracing capacity in their collusion-secure codes-based schemes is still...

2025/1321 (PDF) Last updated: 2025-09-29
Threshold Receipt-Free Voting with Server-Side Vote Validation
Thi Van Thao Doan, Olivier Pereira, Thomas Peters
Cryptographic protocols

Proving the validity of ballots is a central element of verifiable elections. Such proofs can however create challenges when one desires to make a protocol receipt-free. We explore the challenges raised by validity proofs in the context of protocols where threshold receipt-freeness is obtained by secret sharing an encryption of a vote between multiple authorities. In such contexts, previous solutions verified the validity of votes by decrypting them after passing them through a mix-net....

2025/1120 (PDF) Last updated: 2026-02-24
Traceable Secret Sharing Schemes for General Access Structures
Oriol Farràs, Miquel Guiot
Cryptographic protocols

Traceable secret sharing complements traditional schemes by enabling the identification of parties who sell their shares. In the model introduced by Boneh, Partap, and Rotem [CRYPTO’24], a group of corrupted parties generates a reconstruction box $R$ that, given enough valid shares as input, reconstructs the secret. The goal is to trace $R$ back to at least one of the corrupted parties using only black-box access to it. While their work provides efficient constructions for threshold...

2025/760 (PDF) Last updated: 2026-05-07
DGSP: An Efficient Scalable Fully Dynamic Group Signature Scheme Using $\rm{SPHINCS}^+$
Mojtaba Fadavi, Seyyed Arash Azimi, Sabyasachi Karati, Samuel Jaques
Cryptographic protocols

A group signature scheme enables users of a group to anonymously sign messages on behalf of the group, while a designated authority can revoke anonymity when needed to ensure user accountability. Among group signature schemes, fully dynamic ones are particularly desirable as they allow new users to join and misbehaved existing users to be revoked without requiring system-wide updates. This paper introduces DGSP, a post-quantum fully dynamic group signature scheme that addresses key...

2025/730 (PDF) Last updated: 2025-10-29
Tetris! Traceable Extendable Threshold Ring Signatures and More
Gennaro Avitabile, Vincenzo Botta, Dario Fiore
Public-key cryptography

Traceable ring signatures enhance ring signatures by adding an accountability layer. Specifically, if a party signs two different messages within the protocol, their identity is revealed. Another desirable feature is $\textit{extendability}$. In particular, $\textit{extendable threshold}$ ring signatures (ETRS) allow to $\textit{non-interactively}$ update already finalized signatures by enlarging the ring or the set of signers. Combining traceability and extendability in a single scheme...

2025/544 (PDF) Last updated: 2025-03-24
Security Analysis of Covercrypt: A Quantum-Safe Hybrid Key Encapsulation Mechanism for Hidden Access Policies
Théophile Brézot, Chloé Hébant, Paola de Perthuis, David Pointcheval
Cryptographic protocols

The ETSI Technical Specification 104 015 proposes a framework to build Key Encapsulation Mechanisms (KEMs) with access policies and attributes, in the Ciphertext-Policy Attribute-Based Encryption (CP-ABE) vein. Several security guarantees and functionalities are claimed, such as pre-quantum and post-quantum hybridization to achieve security against Chosen-Ciphertext Attacks (CCA), anonymity, and traceability. In this paper, we present a formal security analysis of a more generic...

2025/364 (PDF) Last updated: 2025-02-26
Traitor Tracing in Multi-sender Setting ($\textsf{TMCFE}$: Traceable Multi-client Functional Encryption)
Xuan Thanh Do, Dang Truong Mac, Ky Nguyen, Duong Hieu Phan, Quoc-Huy Vu
Cryptographic protocols

Traitor tracing is a traditional cryptographic primitive designed for scenarios with multiple legitimate receivers. When the plaintext - that is, the output of decryption - is leaked and more than one legitimate receiver exists, it becomes imperative to identify the source of the leakage, a need that has motivated the development of traitor tracing techniques. Recent advances in standard encryption have enabled decryption outcomes to be defined in a fine-grained manner through the...

2025/342 (PDF) Last updated: 2025-09-17
Traceable Threshold Encryption without a Trusted Dealer
Jan Bormet, Jonas Hofmann, Hussien Othman
Cryptographic protocols

The fundamental assumption in $t$-out-of-$n$ threshold encryption is that the adversary can only corrupt fewer than $t$ parties. However, this may be unrealistic in practical scenarios where shareholders could have financial incentives to collude. Boneh, Partap, and Rotem (Crypto'24) addressed the case where $t$ or more shareholders collude, adding a traceability mechanism to identify at least one colluder. Their constructions require a trusted dealer to distribute secret shares, but it is...

2025/341 (PDF) Last updated: 2025-07-06
CCA-Secure Traceable Threshold (ID-based) Encryption and Application
Rishiraj Bhattacharyya, Jan Bormet, Sebastian Faust, Pratyay Mukherjee, Hussien Othman
Cryptographic protocols

A recent work by Boneh, Partap, and Rotem [Crypto'24] introduced the concept of traceable threshold encryption, in that if $t$ or more parties collude to construct a decryption box, which performs decryptions, then at least one party's identity can be traced by making a few black-box queries to the box. This has important applications, e.g., in blockchain mempool privacy, where collusion yields high financial gain through MEVs without any consequence - the possibility of tracing discourages...

2025/318 (PDF) Last updated: 2025-02-21
Traceable Verifiable Secret Sharing and Applications
Karim Baghery, Ehsan Ebrahimi, Omid Mirzamohammadi, Mahdi Sedaghat
Cryptographic protocols

A secret sharing scheme allows a trusted dealer to divide a secret among multiple parties so that a sufficient number of them can recover the secret, while a smaller group cannot. In CRYPTO'21, Goyal, Song, and Srinivasan introduced Traceable Secret Sharing (TSS), which enhances traditional secret sharing by enabling the identification of parties involved in secret reconstruction, deterring malicious behavior like selling shares. Recently, Boneh, Partap, and Rotem (CRYPTO'24) presented two...

2025/312 (PDF) Last updated: 2025-02-21