The BBS Signature Scheme
draft-irtf-cfrg-bbs-signatures-10
| Document | Type |
Expired Internet-Draft
(cfrg RG)
Expired & archived
|
|
|---|---|---|---|
| Authors | Tobias Looker , Vasilis Kalos , Andrew Whitehead , Mike Lodder | ||
| Last updated | 2026-07-20 (Latest revision 2026-01-08) | ||
| Replaces | draft-looker-cfrg-bbs-signatures | ||
| RFC stream | Internet Research Task Force (IRTF) | ||
| Intended RFC status | Informational | ||
| Formats | |||
| Additional resources | Mailing list discussion | ||
| Stream | IRTF state | Active RG Document | |
| Consensus boilerplate | Unknown | ||
| Document shepherd | (None) | ||
| IESG | IESG state | Expired | |
| Telechat date | (None) | ||
| Responsible AD | (None) | ||
| Send notices to | (None) |
This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:
Abstract
This document describes the BBS Signature scheme, a secure, multi- message digital signature protocol, supporting proving knowledge of a signature while selectively disclosing any subset of the signed messages. Concretely, the scheme allows for signing multiple messages whilst producing a single, constant size, digital signature. Additionally, the possessor of a BBS signatures is able to create zero-knowledge, proofs of knowledge of a signature, while selectively disclosing subsets of the signed messages. Being zero-knowledge, the BBS proofs do not reveal any information about the undisclosed messages or the signature itself, while at the same time, guaranteeing the authenticity and integrity of the disclosed messages.
Authors
Tobias Looker
Vasilis Kalos
Andrew Whitehead
Mike Lodder
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)