%% You should probably cite draft-irtf-cfrg-bbs-signatures-09 instead of this revision. @techreport{irtf-cfrg-bbs-signatures-07, number = {draft-irtf-cfrg-bbs-signatures-07}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-irtf-cfrg-bbs-signatures/07/}, author = {Tobias Looker and Vasilis Kalos and Andrew Whitehead and Mike Lodder}, title = {{The BBS Signature Scheme}}, pagetotal = 117, year = , month = , day = , abstract = {This document describes the BBS Signature scheme, a secure, multi- message digital signature protocol, supporting proving knowledge of a signature while selectively disclosing any subset of the signed messages. Concretely, the scheme allows for signing multiple messages whilst producing a single, constant size, digital signature. Additionally, the possessor of a BBS signatures is able to create zero-knowledge, proofs-of-knowledge of a signature, while selectively disclosing subsets of the signed messages. Being zero-knowledge, the BBS proofs do not reveal any information about the undisclosed messages or the signature it self, while at the same time, guarantying the authenticity and integrity of the disclosed messages.}, }