PRETTINESS -- Privacy pResErving aTTrIbute maNagEment SyStem
The paper proposes and proves the security of a generic, full end-to-end credential revocation system for European Digital Identity Wallets, relying on a single server and secure channels.
Abstract
More Like ThisEuropean Digital Identity (EUDI) Wallet aims to provide end users with a way to get attested credentials from issuers, and present them to different relying parties. An important property mentioned in the regulatory frameworks is the possibility to revoke a previously issued credential. While it is possible to issue a short-lived credential, in some cases it may be inconvenient, and a separate revocation service which allows to revoke a credential at any time may be necessary. In this work, we propose a full end-to-end description of a generic credential revocation system, which technically relies on a single server and secure transmission channels between parties. We prove security of the proposed revocation functionality in the universal composability model, and estimate its efficiency based on a proof-of-concept implementation.