1 of 54

BBS+ Signatures

Vasilis Kalos

2 of 54

What are BBS+??

3 of 54

Signature Algorithm

Message

Message

Regular Signatures

 

4 of 54

Regular Signatures

Signature Algorithm

Message

Message

Verification Algorithm

 

 

5 of 54

BBS+ Signature Algorithm

BBS+ Signatures

Message 1

Message 2

Message 3

Message L

 

Message 1

Message 2

Message 3

Message L

 

 

(Also, deterministic)

Constant size

(112 bytes for BLS12-381)

6 of 54

BBS+ Signatures

BBS+ Signature Algorithm

Message 1

Message 2

Message 3

Message L

 

Message 1

Message 2

Message 3

Message L

 

BBS+ Verification Algorithm

Proves:

    • Integrity
    • Authenticity
    • Ownership

…of the signed message

s

 

 

7 of 54

BBS+ Signatures

BBS+ Signature Algorithm

Message 1

Message 2

Message 3

Message L

 

Message 1

Message 2

Message 3

Message L

 

BBS+ Verification Algorithm

Message 1

Message 2

Message 3

Message L

 

BBS+ Proof Algorithm

BBS+ Proof Verification Algorithm

 

Message 1

Message L

 

8 of 54

BBS+ Signatures

Message 1

Message 2

Message 3

Message L

 

BBS+ Proof Algorithm

BBS+ Proof Verification Algorithm

 

Message 1

Message L

Proves:

    • Integrity
    • Authenticity

…of the revealed messages

    • Ownership

…of the whole list of signed messages

AND the signature

9 of 54

BBS+ Signatures

Message 1

Message 2

Message 3

Message L

 

BBS+ Proof Algorithm

BBS+ Proof Verification Algorithm

 

Message 1

Message L

Size linear to the number of hidden messages

(272 + no_hidden_msgs * 32 bytes for BLS12-381)

10 of 54

BBS+ Signatures

Message 1

Message 2

Message 3

Message L

 

BBS+ Proof Algorithm

BBS+ Proof Verification Algorithm

 

Message 1

Message L

Non-Interactive Zero-Knowledge proof

(NIZK)

  • Un-likable presentations
  • No information regarding the non-disclosed messages is leaked
  • Proofs of knowledge

11 of 54

BBS+ Signatures Ecosystem

Issuer

Holder

Verifier

Message 1

Message 2

Message 3

Message L

 

Signature

12 of 54

BBS+ Signatures Ecosystem

Issuer

Holder

Verifier

Message 1

Message 2

Message 3

Message L

 

Signature

 

13 of 54

BBS+ Signatures Ecosystem

Issuer

Holder

Verifier

Message 1

Message L

 

14 of 54

BBS+ Blind Signatures

Issuer

Holder

Verifier

Commitment Proof

Committed msg 1

 

Committed msg K

Commitment

Blind the committed messages in a commitment

Proof that the commitment is correctly formed

15 of 54

BBS+ Blind Signatures

Issuer

Holder

Verifier

Commitment Proof

Committed msg 1

 

Committed msg K

Check that the commitment is correctly formed

Commitment

Commitment

16 of 54

BBS+ Blind Signatures

Issuer

Holder

Verifier

Committed msg 1

 

Committed msg K

Commitment

Known msg 1

Known msg 2

Known msg 2

 

Signature

17 of 54

BBS+ Blind Signatures

Issuer

Holder

Verifier

Committed msg 1

 

Committed msg K

Known msg 1

Known msg 2

Known msg 2

 

Signature

Commitment

Un-blind the commitment

Signature on all the messages

18 of 54

BBS+ Blind Signatures

Issuer

Holder

Verifier

Committed msg 1

 

Committed msg K

Known msg 1

Known msg 2

Known msg 2

 

Signature

 

19 of 54

BBS+ Blind Signatures

Issuer

Holder

Verifier

 

Committed msg K

Known msg 1

20 of 54

Why BBS+??

Part of an emerging pairing cryptography ecosystem

    • Hash to curve
    • BLS signatures
    • Pairing friendly curves

Efficient, few-parameters.

    • Keys and signature sizes similar to ECDSA
    • Performance also close to ECDSA

Strong research line behind BBS+

    • Multiple research papers have been published and reviewed over a long period of time

Easily extendable with reach features

    • blind signatures
    • group signatures
    • range proofs

21 of 54

Pairings

 

 

 

 

 

 

 

 

 

Subgroup of an elliptic curve with prime order

A different subgroup of an elliptic curve with prime order

Subgroup of a large group with prime characteristic

 

 

22 of 54

Pairings

 

 

 

 

 

 

 

 

 

 

23 of 54

Pairings

 

 

 

 

 

 

 

 

24 of 54

Pairings

 

 

 

 

 

 

 

 

 

 

Exponents are multiplied out of the pairing

25 of 54

Pairings

 

 

 

 

 

 

 

 

 

 

 

 

You can switch them around

26 of 54

Pairings

 

 

 

 

 

 

 

 

 

 

 

 

Put them inside the paring in reverse order

27 of 54

Pairings

 

 

 

 

 

 

 

 

 

 

 

 

Encrypt/Sign with this!

Decrypt/Verify with this!

28 of 54

BBS+ Standardization

29 of 54

BBS+ Spec Scope

Core Spec

(BBS+ Core Signatures Spec)

Spec Extensions

(Blind BBS+ Signatures, etc.)

Cryptographic Specs

Representation Leyer

(VCs, JOSE, CBOR, JWP, etc.)

Interface (URDNA, JWP, …)

Protocol/Application Leyer

(Identity, Authn/Authz, IoT, etc.)

Sign, Verify, Proof Generation, Proof Verification, etc.

Commitment Generation, Commitment Verification, Blind Signing etc.

30 of 54

Signing Public Parameters

message 1

message 2

message 3

message L

 

 

 

 

 

 

Points of the Elliptic Curve

Need to be trusted by the Verifier

31 of 54

Signing Public Parameters

message 1

message 2

message 3

message L

 

 

 

 

 

 

 

 

 

 

 

Seed

 

32 of 54

Signing Public Parameters

message 1

message 2

message 3

message L

 

 

 

 

 

 

 

 

 

 

 

Seed

All the generators will be trusted

33 of 54

Signing Public Parameters

message 1

message 2

message 3

message L

 

 

 

 

 

 

 

 

 

 

 

Seed

All the generators will be trusted

NOT The Same

The signature specific generators will be trusted

34 of 54

Signing Public Parameters

message 1

message 2

message 3

message L

 

 

 

 

 

 

 

 

 

 

 

Seed

All the generators will be trusted

NOT The Same

The signature specific generators will be trusted

How the papers solves the problem??

 

  • This makes sense when it comes to the notation of the papers
  • However, it is highly impractical (for each signature the signer would need a different PK)

35 of 54

Signing Public Parameters

message 1

message 2

message 3

message L

 

 

 

 

 

 

Domain

 

 

Signature

Extra, always revealed, message

36 of 54

Signing Public Parameters

message 1

message 2

message 3

message L

 

 

 

 

 

 

Domain

 

Signature

Public parameters that the Verifier MUST trust

Extra, always revealed, message

 

37 of 54

Signing Public Parameters

message 1

message 2

message 3

message L

 

 

 

 

 

 

Domain

 

 

Signature

Additional representation or application specific information

This could be:

  • Domain information

(blind vs non-blind signatures etc.)

Extra, always revealed, message

  • Always disclosed messages.
  • Or other relative info that needs to be protected

38 of 54

Signing Public Parameters

Verifier

Holder

Message 1

Message 2

Message 3

Message L

 

Signature

Domain

 

39 of 54

Signing Public Parameters

Verifier

Holder

Message 1

Message 2

Message 3

Message L

 

Signature

Domain

 

Signature specific parameters

 

 

 

 

Domain

Message 1

Message 2

40 of 54

Signing Public Parameters

Verifier

Message 1

Message 2

 

Domain

 

 

Signature specific parameters

 

  • Signature specific parameters can be supplied by the Holder without worrying that they may forge them (we NEVER trust the Holder).
  • The Verifier trusts them because they were signed by the Issuer.
  • We can also support signature domain separation and cryptographically enforced “always revealed messages” as well.

41 of 54

Holder Binding

Message 1

Message 2

Message 3

Message L

 

BBS+ Proof Algorithm

BBS+ Proof Verification Algorithm

 

Message 1

Message L

Proves:

    • Integrity
    • Authenticity

…of the revealed messages

    • Ownership

…of the whole list of signed messages

AND the signature

42 of 54

Holder Binding

Message 1

Message 2

Message 3

Message L

 

BBS+ Proof Algorithm

BBS+ Proof Verification Algorithm

 

Message 1

Message L

Proves:

    • Integrity
    • Authenticity

…of the revealed messages

    • Ownership

…of the whole list of signed messages

AND the signature

43 of 54

Holder Binding

Issuer

Verifier

Holder

44 of 54

Holder Binding

Issuer

Holder

Verifier

45 of 54

Holder Binding

Verifier

Holder

NIZK Proof

NIZK Proof

NIZK Proof

NIZK Proof

46 of 54

Holder Binding

Verifier

Holder

What's the problem?

NIZK Proof

NIZK Proof

NIZK Proof

NIZK Proof

  • There is nothing binding a specific credential to a specific Holder.
  • Usual solutions (like signing the revealed messages, DPoP etc.) introduce correlation vectors and should be avoided (or at least they should not be required).

47 of 54

Holder Binding

Issuer

Verifier

Holder

“commit” to a value:

1

2

Create a signature including:

Holder Secret

Holder Secret

Holder Secret

Message 1

 

Signature

Message L

48 of 54

Holder Binding

Issuer

Verifier

Holder

“commit” to a value:

1

2

Create a signature including:

Holder Secret

Holder Secret

Holder Secret

Message 1

 

Signature

Message L

3

Create proof hiding:

Holder Secret

 

49 of 54

Holder Binding

Issuer

Verifier

Holder

“commit” to a value:

1

2

Create a signature including:

Holder Secret

Holder Secret

Message 1

 

4

Validate the proof

3

Create proof hiding:

Holder Secret

50 of 54

Holder Binding

Issuer

Verifier

Holder

“commit” to a value:

1

2

Create a signature including:

Holder Secret

Holder Secret

4

Validate the proof

Idea:

  • The NIZK Proof is a proof of knowledge for the whole list of messages.
  • This includes the “Holder Secret”.
  • Non other than the Holder (the one knowing the “Holder Secret”) will be able to create the proof.

3

Create proof hiding:

Holder Secret

51 of 54

Holder Binding

Issuer

Verifier

Holder

“commit” to a value:

1

2

Create a signature including:

Holder Secret

Holder Secret

4

Validate the proof

Proposals for committing a value:

  • Blind Signatures
    • Can “technically work” but the intent is different.
    • Hard to force the “Holder Secret” to be treated differently (i.e., as a secret key).
  • BLS Public Keys
    • The commitment will be the public key and the “Holder Secret” the corresponding secret key.
    • Will require additional “non-standard” point definitions (a new cipher suite for bls signatures).
  • A BLS PoK
    • Avoids the above problems but is the least studied when it comes to security.

3

Create proof hiding:

Holder Secret

52 of 54

Holder Binding

Issuer

Verifier

Holder

“commit” to a value:

1

2

Create a signature including:

Holder Secret

Holder Secret

4

Validate the proof

Proposals for committing a value:

  • Bind Signatures
  • BLS Public Keys
  • A BLS PoK

In scope OR out of scope?

3

Create proof hiding:

Holder Secret

53 of 54

Conclusion

  • Standardization has resulted to a clear layering as well as efficient and practical solutions to aid with the wide and secure adoption of BBS+ signatures.
  • Although still in draft, there been massive progress towards a complete spec.
  • BBS+ Signatures provide efficient, privacy-preserving, multi-message signatures and ZK proofs using selective disclosure.
  • Always exiting seen people engaging with the spec! Let’s discuss!! `

54 of 54

Thank You!!