<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.irtf-cfrg-bbs-signatures" target="https://datatracker.ietf.org/doc/html/draft-irtf-cfrg-bbs-signatures-10">
   <front>
      <title>The BBS Signature Scheme</title>
      <author initials="T." surname="Looker" fullname="Tobias Looker">
         <organization>MATTR</organization>
      </author>
      <author initials="V." surname="Kalos" fullname="Vasilis Kalos">
         <organization>MATTR</organization>
      </author>
      <author initials="A." surname="Whitehead" fullname="Andrew Whitehead">
         <organization>Portage</organization>
      </author>
      <author initials="M." surname="Lodder" fullname="Mike Lodder">
         <organization>CryptID</organization>
      </author>
      <date month="January" day="8" year="2026" />
      <abstract>
	 <t>   This document describes the BBS Signature scheme, a secure, multi-
   message digital signature protocol, supporting proving knowledge of a
   signature while selectively disclosing any subset of the signed
   messages.  Concretely, the scheme allows for signing multiple
   messages whilst producing a single, constant size, digital signature.
   Additionally, the possessor of a BBS signatures is able to create
   zero-knowledge, proofs of knowledge of a signature, while selectively
   disclosing subsets of the signed messages.  Being zero-knowledge, the
   BBS proofs do not reveal any information about the undisclosed
   messages or the signature itself, while at the same time,
   guaranteeing the authenticity and integrity of the disclosed
   messages.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-irtf-cfrg-bbs-signatures-10" />
   
</reference>
