Dynamic Universal Accumulators for DDH Groups and Their Application to Attribute-Based Anonymous Credential Systems Dartmouth Technical Report TR2009-643 Man Ho Au Patrick P. Tsang Willy Susilo Yi Mu Date: April 2009 URL (PDF): (372KB) Abstract: We present the first dynamic universal accumulator that allows (1) the accumulation of elements in a DDH-hard group G and (2) one who knows x such that y=g^x has --- or has not --- been accumulated, where g generates G, to efficiently prove her knowledge of such x in zero knowledge, and hence without revealing, e.g., x or y. We introduce the Attribute-Based Anonymous Credential System (ABACS), which allows the verifier to authenticate anonymous users according to any access control policy expressible as a formula of possibly negated boolean user attributes. We construct the system from our accumulator. Note: This report is the extended version of the paper to appear in CT-RSA '09 under the same title.