BBS per Verifier Linkability
The BBS Signatures scheme describes a multi-message digital signature, that supports selectively disclosing the messages through unlinkable presentations, build using zero-knowledge proofs. Each BBS proof reveals no information other than the signed messages that the Prover chooses to disclose in that specific instance. As such, the Verifier (i.e., the recipient) of the BBS proof, may not be able to track those presentations over time. Although in many applications this is desirable, there are use cases where that require from the Verifier, to be able to track the BBS proofs they receive from the same entity. Examples include monitoring the use of access credentials for abnormal activity, monetization etc.. This document presents the use of pseudonyms with BBS proofs. A pseudonym, is a value that will remain constant each time a Prover presents a BBS proof to the same Verifier, but will be different (and unlinkable), when the Prover interacts with different parties. This provides a way for a recipient to track the presentations intended for them, while also hindering them from tracking the Prover's interactions with other Verifiers.
BBS per Verifier Linkability Internet-Draft BBS per Verifier Linkability March 2024 Kalos & Bernstein Expires 19 September 2024 [Page] Workgroup: CFRG Internet-Draft: draft-vasilis-bbs-per-verifier-linkability-00 Published: 18 March 2024 Intended Status: Informational Expires: 19 September 2024 Authors: V. Kalos MATTR G. Bernstein Grotto Networking BBS per Verifier Linkability Abstract The BBS Signatures scheme describes a multi-message digital signature, that supports selectively disclosing the messages through unlinkable presentations, build using zero-knowledge proofs. Each BBS proof reveal
Explore this link on the map →related reading
- The BBS Signature Schemeidentity.foundation
- thesis.pdfaayushg.com
- Privacy-preserving Solution Using BBS+ for Digital Identity and Walletblog.worldline.tech
- Zero Knowledge Proofs: An illustrated primer – A Few Thoughts on Cryptographic Engineeringblog.cryptographyengineering.com
- Lecture 14: Zero knowledge proofsboazbarak.org
- Zero-knowledge proof - Wikipediaen.wikipedia.org
- ProofsArgsAndZK.pdfpeople.cs.georgetown.edu
- eudi-doc-standards-and-technical-specifications/docs/technical-specifications/ts4-zkp.md at main · eu-digital-identity-wallet/eudi-doc-standards-and-technical-specifications · GitHubgithub.com
- BLS Multi-Signatures With Public-Key Aggregationcrypto.stanford.edu
- Using ZK Proofs to Fight Disinformation | by Dan Boneh | Mediummedium.com
- Designated Verifier Signatures - zk-s[nt]arks - Ethereum Researchethresear.ch
- BLS Signature Aggregation: Under the Hood — stumirror.xyz