I first saw them used with Clouflare's Privacy Pass https://www.hcaptcha.com/privacy-pass, they've also been used with Google's trust token proposal.
I first saw them used with Clouflare's Privacy Pass https://www.hcaptcha.com/privacy-pass, they've also been used with Google's trust token proposal.
For those interested, here’s the related paper covering it:
https://www.petsymposium.org/2018/files/papers/issue3/popets...
And yes, my understanding was tokens entered a pool of one-time tokens and neither the government or endpoint was able to cross reference them to a specific user.
Which to me might mean it might address if user is refused new tokens, it might not account for if the tokens are revoked or the authorizing entity ceased to exist, but the attribute was uniform, for example age.
https://privacypass.github.io/protocol/
All and all, at very least, appears to be an extensive and extendable standard, assuming those involved are reasonable and there’s no conflicting interests.