A Review of Attribute-Based Credentials for Secure and Privacy-Preserving Identity Management
Abstract
Attribute-Based Credentials (ABCs) are cryptographic credential systems that enable holders to selectively disclose certified attributes or prove predicates over them, thereby supporting privacy-preserving identity verification while limiting unnecessary information exposure. This paper presents a review of the system model, core security and privacy properties, classification, comparative analysis, and practical deployment challenges of ABCs. It develops a two-dimensional taxonomy consisting of a construction dimension and an extension dimension. The construction dimension covers publicly verifiable signature-based, keyed-verification and MAC-based, and general-purpose ZKP-based ABC constructions, while the extension dimension covers issuer-hiding, threshold and multi-authority, and dynamic-lifecycle ABCs. The resulting comparison shows that these categories exhibit different trade-offs in verifier openness, proof flexibility, privacy guarantees, trust requirements, lifecycle support, and practical deployment requirements. The review further examines key challenges related to the efficiency and scalability of multi-attribute management, privacy-preserving credential lifecycle management, inference risks in selective disclosure, interoperability, post-quantum security, and holder binding. Finally, it synthesizes recent trends and identifies research directions toward efficient, interoperable, privacy-preserving, and practically deployable ABC systems that strengthen digital trust and support trustworthy digital identity infrastructures.