Papers
Topics
Authors
Recent
Search
2000 character limit reached

Renewable Anonymous Certificate Scheme

Updated 10 July 2026
  • Renewable Anonymous Certificate Scheme is a framework for refreshing temporary credentials that preserve user anonymity while allowing controlled traceability by designated authorities.
  • It employs diverse cryptographic techniques such as ECC, lattice, and hash-based methods to securely generate and renew short-term keys without exposing long-term identifiers.
  • Practical implementations like NOINS and NTRU demonstrate measurable performance and scalability benefits in high-demand environments such as V2X and IoV.

The surveyed literature suggests that a renewable anonymous certificate scheme is best understood as a credential architecture in which a relying party can verify a short-term anonymous or pseudonymous certified public key, while the holder can refresh, rotate, or regenerate such credentials over time without exposing a stable long-term identifier. In the strongest formulations, renewal is local or non-interactive after one authority-issued parent credential; in weaker formulations, renewal means repeated issuance from one initial enrollment, periodic pseudonym replacement, or session-evolving anonymous authenticators. The same literature also shows an important boundary condition: several systems supply anonymous-authentication building blocks or privacy-enhanced trading records, but do not constitute full anonymous certificate schemes with explicit renewal, expiry, reissuance, and revocation semantics (Liu et al., 2024).

1. Definition and scope

A renewable anonymous certificate scheme is not a single standardized primitive across the surveyed papers. Rather, the literature separates into three technical strata.

First, there are direct renewable anonymous-certificate mechanisms. NOINS, for example, starts from an SCMS-style implicit certificate and lets a vehicle autonomously derive many fresh short-term anonymous implicit certificates and keypairs from one CA-issued authorization package, without re-contacting the authority for each refresh (Liu et al., 2024). The NTRU-based scheme likewise lets an end entity generate one initial key pair once and then have the infrastructure derive multiple different public keys and issue certificates containing those keys (Chen, 2 Jan 2026). The ECC/X.509 construction for anonymous voting similarly derives a new anonymous X.509-certified key KK from an ordinary certified key I=iGI=iG by two additive blinding steps, although each new anonymous certificate still requires RA and CA participation (Chen, 2024).

Second, there are adjacent anonymous-authentication systems whose operational behavior resembles renewable anonymous certificates but whose credential model is not certificate-based. In VANETs, a self-organized certificateless ring-signature scheme periodically generates new short-lived pseudonym certificates and authenticates them anonymously, yet it does not define a CA-driven renewable certificate lifecycle (Jiang et al., 2014). An IoV certificateless short-signature construction provides encrypted pseudonyms and regional key rotation, but explicitly lacks vehicle credential expiry, renewal, and reissuance (Liu et al., 2018). Registration-list and certificate-free V2V systems similarly provide evolving pseudonyms and revocation, but not anonymous certificates in the PKI sense (Aghabagherloo et al., 2020, Sehrawat et al., 2020).

Third, there are systems whose use of the word “certificate” belongs to a different domain. Blockchain-based Renewable Energy Certificate trading addresses REC provenance, privacy-enhanced trading, and auditability, but it is not an anonymous credential scheme in the cryptographic sense; its privacy layer is based on DIDs, encrypted messaging, and proxy or temporary accounts rather than formal anonymous certificates (Liu et al., 13 Jan 2026).

2. Credential models and issuance architectures

The credential object varies sharply across the literature, and this variation largely determines whether “renewable anonymous certificate” is an accurate label.

Construction Core credential mechanism Relation to renewability
NOINS (Liu et al., 2024) CA-issued implicit certificate plus derivation material {cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\} Direct non-interactive local regeneration of short-term anonymous certificates
NTRU expansion (Chen, 2 Jan 2026) Expanded public keys w(x)=h(x)r(x)w(x)=h(x)r(x), u(x)=h(x)d(x)u(x)=h(x)d(x), v(x)=u(x)r(x)v(x)=u(x)r(x) embedded in certificates Repeated certificate issuance from one initial NTRU key pair
X.509 key expansion (Chen, 2024) Anonymous X.509 certificate over K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G Repeated issuance is plausible by rerunning RA/CA protocol
PQCWC / HBKE (Chen, 2024) Certificate contains derived hash-based public key B′B' or B′′B'', not original BB Supports rotating pseudonymous certified keys via expansion
Ring-signature VANET scheme (Jiang et al., 2014) Short-lived pseudonym certificate body I=iGI=iG0 plus ring-signature endorsement Operational analogue of renewable anonymous certificates
IoV CLSS scheme (Liu et al., 2018) Certificateless keys plus encrypted pseudonym I=iGI=iG1 Anonymous authentication building block, not full renewal

In NOINS, the CA issues a parent implicit certificate associated with a cocoon public key I=iGI=iG2, then sends encrypted derivation material

I=iGI=iG3

That package functions as a renewable authorization substrate: the vehicle can later derive many child certificates and keypairs locally, with immutable policy fields preserved by I=iGI=iG4 and editable fields refreshed via sanitization and re-randomization (Liu et al., 2024).

The NTRU line is structurally different. It is not a full anonymous credential system with selective disclosure or presentation privacy; instead, it is a repeated pseudonymous certificate-issuance architecture. In the direct CA-only version, the CA computes

I=iGI=iG5

inserts I=iGI=iG6 into the certificate, and the end entity decrypts the returned certificate using the original private key. In the RA/CA split version, the caterpillar-to-cocoon-to-butterfly chain is

I=iGI=iG7

again yielding multiple distinct certified public keys from one initial enrollment (Chen, 2 Jan 2026).

The X.509 construction stays within Internet PKI syntax. The end entity begins with a standard certificate over I=iGI=iG8, the RA computes

I=iGI=iG9

the CA computes

{cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}0

and the end entity reconstructs

{cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}1

The resulting anonymous X.509 certificate contains {cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}2, while neither the RA nor the CA alone knows the full linkage {cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}3 (Chen, 2024).

3. Renewal mechanisms

Renewability appears in several technically distinct forms.

The strongest form is non-interactive local renewal. NOINS explicitly allows vehicles themselves to generate short-term keypairs and anonymous implicit certificates on demand. For each new short-term certificate {cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}4, the vehicle computes a fresh linkage surrogate

{cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}5

re-randomizes the reconstruction value

{cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}6

re-randomizes the shared sanitization key

{cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}7

forms a new sanitizable signature component

{cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}8

and derives

{cert,sig1,sig2,sks,r2}\{\mathit{cert},\mathit{sig}^1,\mathit{sig}^2,\mathit{sks},r^2\}9

This is an explicit parent-to-child credential-renewal model under immutable metadata (Liu et al., 2024).

A second form is repeated issuance from one enrollment. The NTRU scheme states that the end device only needs to generate a key pair once, after which the CA can expand multiple different public keys. The same private key w(x)=h(x)r(x)w(x)=h(x)r(x)0 decrypts certificates addressed to any expanded public key w(x)=h(x)r(x)w(x)=h(x)r(x)1 or w(x)=h(x)r(x)w(x)=h(x)r(x)2, as shown by the decryption equalities in equations (10)–(12) and (16)–(18) (Chen, 2 Jan 2026). The X.509 construction also supports repeated anonymous certificate issuance by rerunning the additive expansion protocol with fresh w(x)=h(x)r(x)w(x)=h(x)r(x)3 and w(x)=h(x)r(x)w(x)=h(x)r(x)4, although the paper does not formalize autonomous renewal or local rerandomization (Chen, 2024).

A third form is renewable pseudonym rotation rather than renewable certificates. The ring-signature VANET scheme generates a fresh transient keypair w(x)=h(x)r(x)w(x)=h(x)r(x)5, embeds w(x)=h(x)r(x)w(x)=h(x)r(x)6 and expiration into w(x)=h(x)r(x)w(x)=h(x)r(x)7, and outputs pseudonym certificate

w(x)=h(x)r(x)w(x)=h(x)r(x)8

with

w(x)=h(x)r(x)w(x)=h(x)r(x)9

Pseudonyms have a short life cycle and are regenerated “from time to time,” which operationally resembles renewable anonymous certificates, but the renewal is self-generated rather than authority-issued (Jiang et al., 2014).

By contrast, some schemes are explicit about what they do not provide. The IoV CLSS construction has revocation and periodic regional RSU key rotation, but not vehicle credential expiration, periodic OBU key renewal, partial private-key refresh, pseudonym certificate replenishment, or forward-secure updates (Liu et al., 2018). The registration-list VANET scheme updates session pseudonyms u(x)=h(x)d(x)u(x)=h(x)d(x)0 and session keys u(x)=h(x)d(x)u(x)=h(x)d(x)1, but lacks explicit certificate validity periods and reissuance semantics (Aghabagherloo et al., 2020).

4. Cryptographic constructions

The renewable-anonymous-certificate literature spans pairings, ECC, lattices, and hash-based PQC.

In SCMS-oriented work, implicit certification and sanitizable signatures form a compact renewal substrate. NOINS splits certificate content into an immutable part, bound to the CA by

u(x)=h(x)d(x)u(x)=h(x)d(x)2

and an editable part, bound by

u(x)=h(x)d(x)u(x)=h(x)d(x)3

Receivers reconstruct the short-term public key as

u(x)=h(x)d(x)u(x)=h(x)d(x)4

so certificate verification and public-key recovery are fused (Liu et al., 2024).

In PKI-compatible ECC constructions, anonymity is derived by additive key expansion. The X.509 anonymous-voting protocol preserves standard certificate validation at a high level because the output remains an X.509 certificate signed by a CA, but the certified key is u(x)=h(x)d(x)u(x)=h(x)d(x)5, not the stable long-term public key u(x)=h(x)d(x)u(x)=h(x)d(x)6 (Chen, 2024).

In post-quantum settings, the NTRU construction replaces ECC butterfly expansion with multiplicative polynomial expansion in u(x)=h(x)d(x)u(x)=h(x)d(x)7. The privacy claim is not zero-knowledge unlinkability; it is the one-wayness of reversing the expansion chain from u(x)=h(x)d(x)u(x)=h(x)d(x)8, u(x)=h(x)d(x)u(x)=h(x)d(x)9, or v(x)=u(x)r(x)v(x)=u(x)r(x)0 to the original v(x)=u(x)r(x)v(x)=u(x)r(x)1, together with RA/CA role separation (Chen, 2 Jan 2026).

PQCWC adopts a different post-quantum route by starting from Winternitz one-time signatures. If the original public key is

v(x)=u(x)r(x)v(x)=u(x)r(x)2

then model 1 expands to

v(x)=u(x)r(x)v(x)=u(x)r(x)3

while model 2 uses a pseudorandom expansion vector v(x)=u(x)r(x)v(x)=u(x)r(x)4 and computes

v(x)=u(x)r(x)v(x)=u(x)r(x)5

In the hash-based butterfly extension, RA and CA apply independent expansion vectors v(x)=u(x)r(x)v(x)=u(x)r(x)6 and v(x)=u(x)r(x)v(x)=u(x)r(x)7, yielding the final certificate key v(x)=u(x)r(x)v(x)=u(x)r(x)8 without exposing the original key v(x)=u(x)r(x)v(x)=u(x)r(x)9 to the public certificate (Chen, 2024).

5. Privacy, traceability, and verification boundaries

The literature converges on conditional anonymity rather than absolute anonymity. Verification should hide the long-term identity from ordinary verifiers, but a designated authority, or a structured set of authorities, should still support tracing, revocation, or accountability.

In anonymous SSO, the credential is a ticket K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G0 containing service-designated tags K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G1 and a special K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G2. Each tag is verifiable only by its intended verifier through a designated-verifier check such as

K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G3

while the central verifier can recover both the user public key and verifier public keys by

K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G4

This is a strong anonymous authorization mechanism, but it lacks revocation, refresh, or defined ticket renewal; repeated use requires new tickets or multiple tags per verifier (Han et al., 2018).

In certificate-free V2V anonymity, the credential analogue is a secret polynomial share K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G5 and a message-specific pseudonym

K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G6

together with

K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G7

This achieves per-message pseudonym refresh, public verification without certificate chains, and tracing by the Authentication Authority, but the scheme is centralized and does not define anonymous certificates as such (Sehrawat et al., 2020).

A consistent limitation is that formal anonymity often lags behind engineering intuition. The IoV CLSS paper claims existential unforgeability in the random oracle model, but omits the full proof due to page limitation and gives only informal unlinkability and tracking-resistance arguments (Liu et al., 2018). The NTRU public-key expansion scheme does not formally prove unlinkability among multiple expanded public keys from the same base key and does not analyze RA–CA collusion (Chen, 2 Jan 2026). The X.509 anonymous-voting construction explicitly depends on non-collusion between RA and CA and leaves revocation and renewal unspecified (Chen, 2024). PQCWC provides correctness derivations for expanded Winternitz keys, but not game-based anonymity or revocation proofs (Chen, 2024). NOINS is stronger on formalization, with games for immutability, unlinkability, fraud-resistance, and unforgeability, but its unforgeability argument assumes non-collusion and its discussion identifies collusion handling as future work (Liu et al., 2024).

6. Performance, misconceptions, and open design constraints

A recurrent motivation for renewable anonymous certificates is operational scale. Standard download-based pseudonym provisioning can be stressed by dense V2X communication, frequent pseudonym rotation, and storage constraints. NOINS makes this point explicit and reports, for obtaining K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G8 certificates in a small or large city, communication time of K=I+rRAG+rCAGK=I+r_{RA}G+r_{CA}G9 s for certificate acquisition and B′B'0 s for total obtaining-and-using time, compared with B′B'1 s and B′B'2 s for explicit SCMS (Liu et al., 2024). Its computational trade-off is equally explicit: CA cost depends on the number of base certificates B′B'3 rather than the total number of usable short-term certificates B′B'4, while vehicle and receiver incur extra local derivation and proof-verification costs.

The NTRU expansion scheme motivates renewability through key-generation asymmetry rather than communication. On Raspberry Pi 4 with SageMath and Python, it reports expansion times far below fresh key-pair generation, including B′B'5: key pair B′B'6 ms, expansion B′B'7 ms; B′B'8: key pair B′B'9 ms, expansion B′′B''0 ms; and B′′B''1: key pair B′′B''2 ms, expansion B′′B''3 ms (Chen, 2 Jan 2026). PQCWC, by contrast, emphasizes that anonymity is achieved “without increasing key length, signature length, key generation time, signature generation time, or signature verification time,” because anonymity derives from expanded public keys rather than larger certificate or signature objects (Chen, 2024).

A major misconception concerns the word “renewable.” In cryptography, it refers to refreshable anonymous credentials or pseudonym certificates. In energy markets, Renewable Energy Certificates represent proof that one megawatt-hour of renewable electricity was generated by a certified generator. The DAG-based REC trading paper addresses pseudonymous trading, auditability, and privacy protection for market participants, and reports lower transaction time by B′′B''4 and energy consumption by B′′B''5 compared to proof-of-stake, but it does not provide anonymous credentials, zero-knowledge unlinkability, or cryptographically anonymous certificates (Liu et al., 13 Jan 2026).

The surveyed works also indicate several unresolved design constraints. A full renewable anonymous certificate scheme would ideally combine explicit validity intervals, unlinkable refresh across epochs, scalable revocation, authority-split tracing, quota control on derivable child certificates, and either formal or system-level guarantees against collusion. This suggests that current constructions are strongest when read as one of three things: a complete renewable implicit-certificate mechanism with delegated local generation, as in NOINS; an efficient repeated pseudonymous certificate-issuance method from one enrollment, as in NTRU, X.509 key expansion, and PQCWC; or a collection of anonymous-authentication building blocks that can inform, but do not by themselves instantiate, a full renewable anonymous certificate lifecycle (Liu et al., 2024, Chen, 2 Jan 2026, Chen, 2024).

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Renewable Anonymous Certificate Scheme.