The BBS Signature Scheme
This document describes the BBS Signature scheme, a secure, multi-message digital signature protocol, supporting proving knowledge of a signature while selectively disclosing any subset of the signed messages. Concretely, the scheme allows for signing multiple messages whilst producing a single, constant size, digital signature. Additionally, the possessor of a BBS signatures is able to create zero-knowledge, proofs of knowledge of a signature, while selectively disclosing subsets of the signed messages. Being zero-knowledge, the BBS proofs do not reveal any information about the undisclosed messages or the signature itself, while at the same time, guaranteeing the authenticity and integrity of the disclosed messages.¶ This note is to be removed before publishing as an RFC.¶ Source for this draft and an issue tracker can be found at https://github.com/decentralized-identity/bbs-signature.¶ This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.¶ I
The BBS Signature Scheme Internet-Draft The BBS Signature Scheme July 2025 Looker, et al. Expires 8 January 2026 [Page] Workgroup: CFRG Internet-Draft: draft-irtf-cfrg-bbs-signatures-latest Published: 7 July 2025 Intended Status: Informational Expires: 8 January 2026 Authors: T. Looker MATTR V. Kalos MATTR A. Whitehead Portage M. Lodder CryptID The BBS Signature Scheme Abstract This document describes the BBS Signature scheme, a secure, multi-message digital signature protocol, supporting proving knowledge of a signature while selectively disclosing any subset of the signed messages. Concretel
Explore this link on the map →related reading
- BBS per Verifier Linkabilityietf.org
- thesis.pdfaayushg.com
- BLS Multi-Signatures With Public-Key Aggregationcrypto.stanford.edu
- BLS Signature Aggregation: Under the Hood — stumirror.xyz
- Math & Engineeringxn--2-umb.com
- Privacy-preserving Solution Using BBS+ for Digital Identity and Walletblog.worldline.tech
- Zero Knowledge Proofs: An illustrated primer – A Few Thoughts on Cryptographic Engineeringblog.cryptographyengineering.com
- ProofsArgsAndZK.pdfpeople.cs.georgetown.edu
- Lecture 14: Zero knowledge proofsboazbarak.org
- Digital Signatures | Computer Securitytextbook.cs161.org
- Sigma Protocolsietf.org
- Zero-knowledge proof - Wikipediaen.wikipedia.org