[credentials] Provable anonymous credentials

One of our payment credentials requirements is to enable
privacy-enhancing credentials. The Web Payments CG and Credentials CG
has been searching for solutions in this space for years. We just
stumbled across one that's pretty exciting.

Thanks to Anders, Tim Holborn, and Eric Korb for pushing on IBM's
BlueMix project. It's led to a pretty exciting discovery called the
Camenisch-Lysyanskaya (CL) signature scheme, which stems from a paper
that's almost 13 years old now:

An Efficient System for Non-transferable Anonymous Credentials with
Optional Anonymity Revocation

http://groups.csail.mit.edu/cis/pubs/lysyanskaya/cl01a.pdf

This could address a number of the privacy concerns that we have around
credentials. IBM based their BlueMix credentialing solution off of it.

We need to dig a bit deeper to see if it's patent encumbered and speak
with the paper's authors to see if it's practical to apply it to our
work on credentials. The one thing that concerns me is that the
discovery is almost 13 years old at this point. In any case, it's an
exciting lead.

-- manu

-- 
Manu Sporny (skype: msporny, twitter: manusporny, G+: +Manu Sporny)
Founder/CEO - Digital Bazaar, Inc.
blog: Web Payments: The Architect, the Sage, and the Moral Voice
https://manu.sporny.org/2015/payments-collaboration/

Received on Tuesday, 9 June 2015 05:35:08 UTC