Skip to content

Vouched Anonymity

Version
v4 · 2026-08-30 · History
Prime #
1477
Origin domain
Communication & Media Studies
Subdomain
mediated trust → Communication & Media Studies
Aliases
Intermediary Vouched Anonymity, Verified Hidden Source, Reputation Backed Anonymity
Related primes
Trust, Information Asymmetry

Core Idea

Vouched anonymity is an arrangement in which one party attests to a property of a second party — membership, eligibility, vantage, first-hand knowledge — for a third party that never learns who the second party is. The relying party acts on the attested property; the attesting party holds, or once held, the link back to a person. Trust crosses the boundary and identity does not, and the two come apart because concealment here is directional rather than absolute. [1]

Six roles carry the structure: a subject whose identity is withheld, a relying party that must decide without it, a voucher holding privileged and verified knowledge of the subject, an attested predicate delivered in place of a name, a stake the voucher forfeits if the predicate is false, and a rule governing when the link may be opened or the subject's standing withdrawn. Strip out the stake and the attestation is an unsupported assertion; strip out the predicate and the relying party has nothing to act on; strip out the privileged link and what remains is ordinary concealment with an endorsement pinned to it.

The property generating every other is that identity is relocated rather than destroyed. Relocation is what makes verified concealment possible at all, and it installs the voucher as a load-bearing dependency for two guarantees nothing in the structure requires to be held by the same competent hands: the credibility of the claim, which fails if the voucher lies or checks carelessly, and the concealment of the subject, which fails if the voucher discloses, is compelled, or is breached. [2]

Structural Signature

A subject hidden from a relying party + a voucher holding privileged, verified knowledge of that subject + an attested predicate carried to the relying party in place of a name + a stake the voucher forfeits if the predicate proves false + a stated rule for opening the link or withdrawing the subject's standing → the relying party acts on the subject's contribution without identifying it, while the voucher is at once guarantor of the claim and the one party able to break the concealment.

The formula is stated over a predicate and a named observer, never over a person alone. A description calling a party anonymous without saying to whom, or vouched without saying what was checked and what follows if the check was wrong, has not located the prime. [2]

Recurring features:

  • Directional concealment. The subject is opaque to one audience and transparent to another by design; the boundary is a chosen artifact, not a limit of anyone's knowledge.[1]
  • A predicate standing in for a name. What crosses is a claim about a property — held this role, saw this event, meets this threshold — and the arrangement's usefulness is bounded by what that property licenses.[3]
  • A staked guarantor. Some exposure of the voucher's own — licence, mandate, standing — sits behind the predicate, which is what separates vouching from relaying.[4]
  • A link either retained or destroyed, never neutrally. Keeping the identity supports revocation and conditional opening; destroying it defeats compulsion. Schemes tend to pick one and inherit the matching failure.
  • An anonymity set rather than a binary. Protection is the number of parties consistent with everything the relying party learns, a quantity that can only shrink as attested or leaked details accumulate.[2]
  • Two failure modes with different remedies. A false attestation harms the relying party and is answered by heavier screening and larger stakes; a disclosure harms the subject and is answered by holding less and resisting demands. This entry reads the two directions of hardening as pulling against each other; that trade-off is its own claim, and Chaum's design thesis runs the other way — that a scheme can be built to serve the subject's privacy and the relying party's security at once. [1]

What It Is Not

The prime does not claim the subject is unknown. Somebody knows exactly who they are — that is the point, and what separates a vouched contribution from a note pushed under a door. Objections of the form "an anonymous report cannot be followed up" attack an arrangement in which nobody holds the link.

It does not claim the attestation is true, or that the voucher is competent, disinterested, or careful. The prime classifies a structure and warrants nothing about performance. A voucher that verifies little and signs everything still instantiates the pattern, so recognising an instance begins an assessment rather than concluding one.

It does not claim the concealment is permanent or technically irreversible. Most instances are built to be opened under stated conditions and many are opened under conditions nobody stated. Durability comes from retention practice, legal exposure, and the size of the surviving candidate set, none of which the structure supplies.

It does not claim the hidden party is the one being protected. Concealment sometimes shields the contributor, sometimes a judgment from the pull of a name, sometimes a process from the appearance of favour; the same roles appear in all three, and reading protective intent off the structure reliably misidentifies whose interest a scheme serves. Nor need the voucher know a legal name — a body confirming that a caller holds a certification, without learning who holds it, is vouching in the full sense.

Finally, it takes no position on legitimacy. The structure serves protected disclosure and organized deniability equally well, and the criterion separating them lies outside the relation.

Broad Use

The arrangement recurs wherever a contribution is worth having only if its source can be checked and can only be made if its source stays hidden. Newsrooms run it as routine: an editor establishes who a source is and what access they had, readers learn neither, and what the reader relies on is the publication's standing. Double-blind review inverts the beneficiary, concealing the assessor from the assessed, the editor who chose that assessor supplying the warrant. Courts interpose themselves between a witness and a party with an interest in locating them, sealing what they hold under a rule for opening it. Confidential incident-reporting schemes in aviation, medicine and industrial safety place a neutral body between the person who made or saw an error and the employer that would otherwise act on it. Ethics hotlines, mutual-aid sponsorship, and references given on condition of non-attribution keep the same roles in the same relation. [5]

Engineered systems rebuild the shape without the vocabulary. Attribute-based credential schemes let an issuer certify that a holder satisfies a condition, which the holder then demonstrates to a verifier that learns the condition and nothing more. Group signatures let any member of a defined set sign on the set's behalf, so a verifier learns membership while a designated opener, and only that party, can recover the individual. Invitation trees and stake-backed sponsorship resist duplicate accounts by making an existing member's standing the collateral for a newcomer's admission. Marketplaces screen sellers so a buyer relies on the platform's vetting rather than on a counterparty it could not investigate. What varies is who may open the link, on what showing, and what the voucher loses when wrong; what stays constant is that the relying party's confidence is anchored in an institution it can identify, on behalf of a contributor it cannot. [6]

Clarity

The confusion this prime dissolves is the treatment of anonymity as a scalar property of a person. In ordinary argument a contributor either is anonymous or is not, and the degree of concealment is assumed to trade against how far anyone can rely on them: the more hidden, the less accountable, the less worth acting on. Almost every step in that chain is unindexed, and indexing it breaks the chain, because concealment is a relation between a subject and a particular observer rather than a state the subject occupies. [2]

Once the observer is named, accountable anonymity stops being a paradox and becomes a design question: which party holds the link, under what rule may it be opened, and who carries the consequence meanwhile. The standing objection that hidden-origin contributions cannot be relied upon turns out to concern a different arrangement, one with no holder at all, and the matching reassurance that a contribution is safe because the channel was anonymous rests on retention facts nobody has checked.

A second muddle goes with the first: the belief that concealment is accomplished by removing a name. A name is one identifier among many, and an attested property is itself an identifier whenever few parties satisfy it. Redacting the name from a report filed by the only person occupying a given role on a given night removes nothing, and mistaking redaction for protection is how schemes expose the people they were built to shelter.

Manages Complexity

What the arrangement lets a relying party stop tracking is the contributor. Without it, anyone wishing to act on a hidden-origin contribution must stand up a verification apparatus of their own — that the source exists, had the access claimed, has no disqualifying interest, and is not three other sources wearing different hats — and rebuild it for every contributor.[7] Vouching converts a burden scaling as relying parties times contributors into one scaling as their sum, since each contributor is checked once and each relying party evaluates a single institution. [8]

Two further reductions follow. Concealment stops being a property every handler must maintain and becomes one enforced at a single boundary: rather than a chain of parties each responsible for an identity it holds, one party holds it and the others never have it to lose. And the relying party's assessment stabilises across contributions instead of reopening at each one, because what it judges — screening practice, incentives, track record — changes slowly while the contributions change constantly.

Abstract Reasoning

The prime supports an ordered diagnostic in which any step can terminate the analysis on its own verdict.

First, index the concealment. Ask who cannot identify the subject and who can. If nobody can, the case is unverified anonymity and the vouching questions are idle; if the relying party can, the concealment has already failed and what remains is ceremony. [2]

Second, state the predicate exactly — existence, role, presence at an event, distinctness from other contributors, absence of a disqualification. Arrangements routinely leave this unsaid, and the gap between what a relying party believes was checked and what was checked is where most of them come apart.

Third, find the stake. Ask what the voucher loses if the predicate is false, whether that loss is likely enough to bite, and whether it falls on whoever made the judgment. A voucher with no exposure is a conduit.

Fourth, size the anonymity set. Take everything the relying party learns — predicate, timing, routing, phrasing, surrounding context — and ask how many parties satisfy all of it at once. That number is the protection actually delivered, and in arrangements confidently called anonymous it is often in single digits.

Fifth, run the abuse and compulsion cases together, since both turn on the same retained record. Ask who may withdraw a subject's standing, whether withdrawal requires naming them, and whether withdrawing points backwards at their earlier contributions; then ask what the voucher holds, who can demand it, and what the subject was told about that before relying on it.

Two counterfactuals sharpen the verdict. The withdrawal test asks whether the relying party's decision would change if the attestation were removed and the contribution left as it stands; if not, the vouch was decorative. The disclosure test asks whether the subject would still have come forward knowing the relying party could identify them; if yes, concealment is not load-bearing and the case is an ordinary verified contribution with a preference attached.

Knowledge Transfer

What moves intact between substrates is the role skeleton, the indexing of concealment to a named observer, the split of the voucher's obligations into an integrity duty owed to the relying party and a discretion duty owed to the subject, the arithmetic by which attested properties intersect to shrink a candidate set, and the recognition that revocation and compulsion are where a design is tested. An editor weighing a single-source story, a review chair assigning a manuscript, and an engineer specifying what an issuer may retain are working the same object, and the set-size question is the first thing worth carrying into an unfamiliar domain.

What stays behind is nearly everything the roles get filled with. Who may serve as a voucher, and on what authority, is fixed locally — a professional body, a court, a certificate issuer, an existing member in good standing — and an intuition carried across that line yields attestations nobody is obliged to honour. The compulsion environment does not travel at all and is often the whole substance of a design: what a party can be made to produce, by whom, and on what showing differs by jurisdiction and instrument. Sanctions do not travel, and neither do the terms of art, since first-hand knowledge, good standing and eligibility each mean something field-specific.

The most reliable failure is importing a guarantee across the cryptographic–institutional boundary in either direction. Credential constructions can offer unlinkability, so repeated presentations cannot be tied together even by the issuer, and institutional vouching has never had that property: a desk vouching twice for one source knows it is one source. Institutional vouchers weigh vantage, motive, conflict and plausibility, and no scheme that checks a signature has purchase on any of it. Assuming either property because the roles matched is how a transfer fails while appearing to succeed.

Examples

Formal/abstract

Model the relying party's state as a set. Before any attestation it holds a population of parties who could conceivably be the source. An attestation asserts a property and the candidate set contracts to those satisfying it; a second property intersects again, as does every unattested detail leaking through timing, phrasing or routing. Protection is the size of the surviving set, which makes concealment a quantity rather than a state, and is why deleting a name changes nothing once the intersection is a singleton. [9]

The uncomfortable part is that assurance is computed from that same intersection. What makes the contribution worth acting on is precisely that the survivors are parties who could know what it claims — the narrower the set, the better the warrant and the worse the subject's position. The two are not merely in tension; they are one measurement read with opposite signs, which is why no drafting reconciles them and every working design picks a point on the curve.

Two structural escapes exist and each is paid for elsewhere. The first attests membership in a deliberately large class instead of a rare property, buying set size with a weaker claim. The second severs issuance from use, so the party that verified the subject cannot recognise the occasion on which its verification is presented; this preserves set size without weakening the claim, and relocates the residual exposure to whatever the relying party infers from context.

Mapped back: the population and its intersections are the anonymity set the signature names; the asserted property is the predicate standing in for a name; the sign inversion is the assurance-against-exposure trade the arrangement manages; and the issuance-from-use separation is the retained-or-destroyed link stated formally. It also explains the diagnostic ordering, since sizing the set must follow enumerating everything attested — the leak is nearly always in a term nobody counted as an attestation.

Applied/industry

A regulator wants to learn about near-misses its own enforcement powers currently suppress, and contracts a neutral body to run a confidential reporting scheme. A crew member files under their own name. The body confirms that the reporter held the role they claim on the operation they describe, that the account is consistent with recorded data, and that the filing arrived inside the window conferring protection from enforcement. It then strips direct identifiers and passes the account to regulator and operator with an attestation of its own: first-hand, verified, filed in time. [5]

Run the procedure. The concealment is indexed — opaque to operator and regulator, transparent to the body. The predicate does real work, since an unverified account of the same events would be treated as rumour and no aircraft grounded on it. The stake is the body's mandate and the confidence of the population it depends on for future filings, both lost if it passes fabrications or is once seen to have exposed a reporter.

Set size is where the scheme is actually decided. Across a large fleet the account could have come from hundreds; on a route flown twice weekly by one crew the survivors number three, and redaction accomplishes nothing. The body's protective instrument is therefore the coarsening of the operational particulars that shrink the set — and every particular withheld is one the operator needed to fix the problem. Revocation and compulsion complete the picture: a reporter filing fabrications must lose standing without the operator learning who they were and without the withdrawal pointing back at their earlier filings, while the enforcement-protection provision obliges the body to retain proof of filing time — precisely the record a later investigation will demand.

Mapped back: the body is the voucher holding the privileged link, its statement of verified first-hand status is the predicate substituting for identity, and the operator's willingness to act is trust that arrived through the body rather than from the reporter. Safety value and reporter exposure both rise with detail, which is the formal trade in operational dress. The retained filing record is the link kept rather than destroyed, and it is why the scheme's integrity turns on the body's capacity to resist a demand.

Structural Tensions

T1 — The voucher answers to two masters with opposite appetites. The relying party wants a voucher that checks hard, records what it checked, and can be held to it afterwards; the subject wants one that holds as little as possible and can be compelled to produce nothing. Both wants are reasonable and both operate on the same file. Strengthening the evidentiary basis of an attestation is the same act as building the dossier that endangers the person it protects, and no governance arrangement makes the two demands point the same way.

T2 — Assurance and exposure are one measurement. Every property attested narrows the field of parties who could have contributed, which is simultaneously what gives the relying party warrant and what gives an adversary a search. The instinctive fix, attesting less, buys concealment by spending exactly the credibility the arrangement existed to supply; the opposite fix buys credibility by spending concealment. Designers experience this as a drafting problem and it is not one, because the curve is a property of the structure rather than of the wording.

T3 — Accountability must reach a party nobody may name. When a vouched subject abuses the arrangement, sanction has three places to land and none is right. It can fall on the voucher, which mis-sites the incentive and drives screening so conservative that the marginal legitimate contributor is excluded. It can fall on the subject through withdrawal of standing, which the subject may barely feel. Or it can fall through conditional deanonymisation, the one instrument that genuinely deters and the one whose mere availability degrades the promise for everyone who abused nothing.

T4 — Revocation needs the identifier it is forbidden to use. Withdrawing one subject's standing must be visible enough to take effect and invisible enough not to say who was withdrawn. Every withdrawal is at least one bit about the population, and bits accumulate: a relying party watching which attestations stop being honoured can often reconstruct which contributions belonged to whom. Rotating an entire cohort hides the individual event at the cost of re-verifying everybody, and schemes that cannot afford the rotation quietly stop revoking at all.

T5 — Concentration is both the design and the vulnerability. The arrangement earns its keep by replacing many verification relationships with one, so the voucher is a chokepoint by construction — a chokepoint holding the credibility of every attestation it has issued and the identity of everyone it has ever vouched for. Compulsion, capture, subversion or a single breach fails both properties at once and retroactively. Distributing the role across several parties repairs the exposure and reintroduces the coordination cost the arrangement was built to remove.

T6 — Concealment decays through the same use that builds credibility. A stable handle is what lets a record accumulate, and the record is what makes a vouched contributor worth more than a stranger. That same accumulation is a fingerprint: topics, timing, phrasing and the pattern of which claims get made narrow the field with every appearance. Discarding the handle restores concealment and discards the record with it. Ordinary successful operation therefore walks the arrangement out of its own viable range, and nothing internal to it pushes back.

Structural–Framed Character

Vouched Anonymity sits on the framed side of the structural–framed spectrum, labeled mixed-framed with an aggregate of 0.5, every diagnostic reading at half. The skeleton that travels is a trust substitution: a contributor hidden from the recipient, an intermediary with privileged access who verifies identity or qualifications, a recipient-facing attestation backed by the intermediary's staked reputation, and rules for disclosure or revocation.

Human-practice-bound explains the placement best, at half. The relation is constitutively social: the recipient knowingly substitutes trust in the intermediary for direct inspection, and the intermediary must stake visible reputation or accountability. The entry is explicit that anonymous credentials can implement the arrangement cryptographically without being the whole social relation, which keeps the criterion at half.

Vocabulary travel is half — vouching, attestation and credential carry the tint of journalism, review and law, though the four roles are statable plainly. Evaluative weight is half: trust, reputation and accountability are loaded terms, but the prime describes an arrangement rather than endorsing it, naming intermediary capture and trust contagion as characteristic failures. Institutional origin is half: blind review, protected witnesses and credential systems are natural homes, and institutional stake is one form the intermediary's exposure takes. Import-vs-recognize is half: in journalism one imports the vouching frame; in an anonymous marketplace one recognizes the structure already implemented.

The grade means the roles port but the frame ports with them — check that the intermediary's stake is real, and do not extend the name to ordinary anonymity, which has no verifying bridge, or to pseudonymity, which gives persistent identity without vouching.

Substrate Independence

Vouched Anonymity is a highly substrate-independent prime — composite 4 / 5 on the substrate-independence scale. The invariant is a relocation of identity rather than its destruction: a subject opaque to the relying party, a voucher holding the verified link, a predicate carried across in place of a name, a stake the voucher forfeits if the predicate is false, and a stated rule for opening the link. Whistleblower channels, protected witnesses, blind review, escrowed marketplaces, source protection, credential schemes and custodial research data share every role. What holds it below the ceiling is the width of the band: each instance is an arrangement among parties that can keep a secret, be compelled to break it, and lose standing, so nothing outside governed social and technical systems instantiates it.

  • Composite substrate independence — 4 / 5
  • Domain breadth — 4 / 5
  • Structural abstraction — 4 / 5
  • Transfer evidence — 4 / 5

Relationships to Other Abstractions

Local relationship map for Vouched AnonymityParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Vouched AnonymityPRIMEPrime abstraction: Information Asymmetry — presupposesInformationAsymmetryPRIMEPrime abstraction: Trust — presupposesTrustPRIMEDomain-specific abstraction: Anonymous Sourcing — is a kind ofAnonymousSourcingDOMAIN

Current abstraction Vouched Anonymity Prime

Parents (2) — more general patterns this builds on

  • Vouched Anonymity presupposes Information Asymmetry Prime

    The architecture exists because identity and source-vantage knowledge are unequally distributed between contributor, intermediary, and final recipient.

  • Vouched Anonymity presupposes Trust Prime

    The recipient must accept vulnerability under incomplete contributor monitoring based on positive expectations of the intermediary's competence and integrity.

Children (1) — more specific cases that build on this

  • Anonymous Sourcing Domain-specific is a kind of Vouched Anonymity

    Anonymous Sourcing is a strict specialization of Vouched Anonymity.

Hierarchy paths (2) — routes to 2 parentless roots

Neighborhood in Abstraction Space

Vouched Anonymity sits in a sparse region of abstraction space (95th percentile for distinctiveness): few abstractions share its structure, so a faithful description tends to retrieve it precisely rather than landing on a neighbor.

Family — Argumentative Traps & Framing Fallacies (15 primes)

Nearest neighbors

Computed from structural-signature embeddings · 2026-09-10

Not to Be Confused With

The nearest neighbour is Certification, in which a trusted third party evaluates an entity against a standard and issues a portable token that downstream parties accept instead of repeating the evaluation. The token normally names its holder, and much of its force comes from a relying party being able to check it against a register. Here the holder stays unnamed, so nothing can be looked up and the issuer's own standing carries the entire load. A certification scheme that conceals its holders has become an instance of this prime.

Attestation is the mechanism rather than the arrangement: a tamper-evident, principal-binding mark by which a third party confirms who committed to what. Its force comes from binding a principal to a statement, and that binding is normally what a reader is meant to see. This prime points the binding at one audience and withholds it from another, so the mark is present while its identifying force is aimed.

Authentication binds an asserted identity to admissible evidence and ends by establishing who someone is to whoever ran the procedure. The prime contains an authentication step and then declines to propagate its result: the voucher authenticates, the relying party never does. Reading the prime as a species of authentication produces the recurring design error of exporting the authentication result downstream merely because it happens to be available.

Blinding severs a specific bias channel by keeping one item from a decision-maker so a judgment cannot be contaminated by it. The two frequently co-occur and answer different questions: blinding concerns the quality of a judgment, this prime the safety of a contributor and the warrant of a relying party. A blinded assessor's name is withheld to protect the assessment; a whistleblower's to protect the whistleblower. Blinding also needs no party who holds the withheld item and stakes anything on it.

Zero-Knowledge Proof convinces a verifier that a claim holds while revealing nothing beyond its truth, and is the strongest available implementation of the predicate-in-place-of-a-name feature. It differs in what it removes: such a construction can eliminate the trusted holder entirely, leaving no link for compulsion to reach. This prime requires no such thing, and most of its instances have a voucher who knows precisely who the subject is. Equating the two imports a guarantee institutional vouching cannot deliver.

Confidentiality binds an authorised holder's use of protected content. The voucher's obligation toward the subject is usually such a duty, so the two nest rather than compete: this prime describes an assurance architecture, and the duty describes what the voucher may do with the identity that architecture obliges it to hold. They separate cleanly — a party can be bound with no attesting function at all, and a scheme that destroys the link leaves nothing for a duty to govern.

Reputation aggregates past behaviour into a signal shaping how others treat an agent, and normally attaches to whoever produced it. The distinctive move here is substituting the voucher's reputation for the subject's, which is why the voucher's exposure is constitutive rather than incidental. A subject accumulating its own reputation under a persistent handle has started building something else.

Provenance documents origin and successive custody so authenticity can be established and accountability assigned. It works by making a chain inspectable to whoever must rely on it, which is exactly what this prime withholds; the closest reading is a chain with one link opaque to the reader and legible to a custodian. Trusted Intermediary Compromise belongs to the risk analysis rather than the boundary analysis, naming what happens when this chokepoint is subverted. Trust and Information Asymmetry are the parents: the prime reduces neither the trust required nor the knowledge gap, but redistributes both onto a role the relying party can name.

Solution Archetypes

No catalogued solution archetypes reference this prime yet.

Notes

The placement under trust predicts where these arrangements break. Nothing in the structure reduces the trust required; it relocates it, from a contributor the relying party cannot assess onto a voucher it can. Effort therefore pays where the voucher's position is decided — its incentives, its independence, its capacity to refuse to hold a record, its exposure when wrong — and pays poorly on the mechanics of stripping identifiers from a document. Managing unequal knowledge rather than removing it also leaves the voucher knowing more than either party it serves, which is at once the operating capital and the standing hazard.

References

[1] Chaum, David. "Security without Identification: Transaction Systems to Make Big Brother Obsolete". Communications of the ACM 28(10), 1985, 1030-1044. Describes an individual holding a different digital pseudonym with each organization, so that a receiving organization can verify a credential issued elsewhere without learning who holds it or which other pseudonyms belong to the same person. registry ↩a ↩b ↩c

[2] Pfitzmann, Andreas, and Marit Hansen. "A Terminology for Talking about Privacy by Data Minimization: Anonymity, Unlinkability, Undetectability, Unobservability, Pseudonymity, and Identity Management". Technical report v0.34, TU Dresden and ULD Kiel, 2010. Defines anonymity as a subject's non-identifiability within an anonymity set from a stated attacker's perspective, so anonymity is relative to a named observer rather than a property of a person, and defines pseudonymity with an identity broker able to reveal the civil identity under well-defined circumstances. registry ↩a ↩b ↩c ↩d ↩e

[3] Camenisch, Jan, and Anna Lysyanskaya. "An Efficient System for Non-transferable Anonymous Credentials with Optional Anonymity Revocation." In EUROCRYPT 2001, 93–118. Supports only that a credential can be shown "without revealing anything more than the fact that she owns such a credential" — a property crossing in place of a name; that the arrangement's usefulness is bounded by what the property licenses is this entry's inference. registry

[4] Regulation (EU) No 910/2014 (eIDAS), Art. 13(1), 2014. Supports only that under this instrument trust service providers "shall be liable for damage caused intentionally or negligently" — one legal regime in which the voucher carries exposure of its own. It does not establish that staked exposure is what separates vouching from relaying, which is this entry's definition, nor that other vouching arrangements are so structured. registry

[5] U.S. Federal Aviation Administration. Aviation Safety Reporting Program. Advisory Circular AC 00-46F, 2021. NASA serves as a third party to receive and process reports, all information that might establish the identity of the filer or of parties named in a report is deleted, and a report delivered within 10 days of the occurrence bars civil penalty or certificate suspension for an inadvertent violation. registry ↩a ↩b

[6] Chaum, David, and Eugène van Heyst. "Group Signatures". Advances in Cryptology - EUROCRYPT '91, Lecture Notes in Computer Science 547, Springer, 1991, 257-265. Only members of the group can sign, the receiver can verify that a signature is a valid group signature but cannot discover which member produced it, and the signature can if necessary be opened so that the signer is revealed. registry

[7] Douceur, John R. "The Sybil Attack." In Peer-to-Peer Systems (IPTPS 2002), LNCS 2429, 251–260. Supports only the multiple-identities check and its dependence on a certifying authority — "without a logically centralized authority, Sybil attacks are always possible except under extreme and unrealistic assumptions." The other checks this sentence lists — that the source exists, had the access claimed, and has no disqualifying interest — are this entry's enumeration and are not covered by it. registry

[8] Diamond, Douglas W. "Financial Intermediation as Delegated Monitoring: A Simple Example." FRB Richmond Economic Quarterly, vol. 82, no. 3 (1996): 51–66. Supports the duplication-versus-delegation saving in Diamond's own example — "Duplicated monitoring by each of m investors would cost mK" against a single delegated cost — for one monitored party and m delegators. The generalisation to a burden scaling as relying parties times contributors collapsing to their sum is this entry's formalisation of that example, not a result Diamond states. registry

[9] Sweeney, Latanya. "k-Anonymity: A Model for Protecting Privacy". International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems 10(5), 2002, 557-570. Shows that combinations of a few quasi-identifying attributes often single out individuals, so data stripped of explicit identifiers can still be re-identified by linking, and defines protection as indistinguishability within a set of at least k records. registry