Lattice-Based Accumulator and Application to Anonymous Credential Revocation

  • Victor Youdom Kemmoe, Brown University; Betül Durak, Microsoft

An accumulator is a cryptographic system for compactly representing a set of elements such that every element in the set has a short membership witness. A dynamic accumulator, furthermore, allows elements to be added to and deleted from the accumulator. Camenisch and Lysyanskaya (CRYPTO’02) constructed the first dynamic accumulator under the strong-RSA assumption and showed how it can be used to enable revocation of anonymous credentials. In this talk, I will present a communication-efficient cryptographic accumulator based on the Module-SIS assumption, which is an accumulator that allows adding elements from a set without the need to update membership witnesses, and show how it can be used in the context of anonymous credential revocation.

Joint work with Anna Lysyanskaya and Ngoc Khanh Nguyen. Link: https://ia.cr/2025/1099

Series: Cryptography Talk Series