BBS+ Signatures
Vasilis Kalos
What are BBS+??
Signature Algorithm
Message
Message
Regular Signatures
Regular Signatures
Signature Algorithm
Message
Message
Verification Algorithm
BBS+ Signature Algorithm
BBS+ Signatures
Message 1
Message 2
Message 3
Message L
Message 1
Message 2
Message 3
Message L
(Also, deterministic)
Constant size
(112 bytes for BLS12-381)
BBS+ Signatures
BBS+ Signature Algorithm
Message 1
Message 2
Message 3
Message L
Message 1
Message 2
Message 3
Message L
BBS+ Verification Algorithm
Proves:
…of the signed message
s
BBS+ Signatures
BBS+ Signature Algorithm
Message 1
Message 2
Message 3
Message L
Message 1
Message 2
Message 3
Message L
BBS+ Verification Algorithm
Message 1
Message 2
Message 3
Message L
BBS+ Proof Algorithm
BBS+ Proof Verification Algorithm
Message 1
Message L
BBS+ Signatures
Message 1
Message 2
Message 3
Message L
BBS+ Proof Algorithm
BBS+ Proof Verification Algorithm
Message 1
Message L
Proves:
…of the revealed messages
…of the whole list of signed messages
AND the signature
BBS+ Signatures
Message 1
Message 2
Message 3
Message L
BBS+ Proof Algorithm
BBS+ Proof Verification Algorithm
Message 1
Message L
Size linear to the number of hidden messages
(272 + no_hidden_msgs * 32 bytes for BLS12-381)
BBS+ Signatures
Message 1
Message 2
Message 3
Message L
BBS+ Proof Algorithm
BBS+ Proof Verification Algorithm
Message 1
Message L
Non-Interactive Zero-Knowledge proof
(NIZK)
BBS+ Signatures Ecosystem
Issuer
Holder
Verifier
Message 1
Message 2
Message 3
Message L
Signature
BBS+ Signatures Ecosystem
Issuer
Holder
Verifier
Message 1
Message 2
Message 3
Message L
Signature
BBS+ Signatures Ecosystem
Issuer
Holder
Verifier
Message 1
Message L
BBS+ Blind Signatures
Issuer
Holder
Verifier
Commitment Proof
Committed msg 1
Committed msg K
Commitment
Blind the committed messages in a commitment
Proof that the commitment is correctly formed
BBS+ Blind Signatures
Issuer
Holder
Verifier
Commitment Proof
Committed msg 1
Committed msg K
Check that the commitment is correctly formed
Commitment
Commitment
BBS+ Blind Signatures
Issuer
Holder
Verifier
Committed msg 1
Committed msg K
Commitment
Known msg 1
Known msg 2
Known msg 2
Signature
BBS+ Blind Signatures
Issuer
Holder
Verifier
Committed msg 1
Committed msg K
Known msg 1
Known msg 2
Known msg 2
Signature
Commitment
Un-blind the commitment
Signature on all the messages
BBS+ Blind Signatures
Issuer
Holder
Verifier
Committed msg 1
Committed msg K
Known msg 1
Known msg 2
Known msg 2
Signature
BBS+ Blind Signatures
Issuer
Holder
Verifier
Committed msg K
Known msg 1
Why BBS+??
Part of an emerging pairing cryptography ecosystem
Efficient, few-parameters.
Strong research line behind BBS+
Easily extendable with reach features
Pairings
Subgroup of an elliptic curve with prime order
A different subgroup of an elliptic curve with prime order
Subgroup of a large group with prime characteristic
Pairings
Pairings
Pairings
Exponents are multiplied out of the pairing
Pairings
You can switch them around
Pairings
Put them inside the paring in reverse order
Pairings
Encrypt/Sign with this!
Decrypt/Verify with this!
BBS+ Standardization
BBS+ Spec Scope
Core Spec
(BBS+ Core Signatures Spec)
Spec Extensions
(Blind BBS+ Signatures, etc.)
Cryptographic Specs
Representation Leyer
(VCs, JOSE, CBOR, JWP, etc.)
Interface (URDNA, JWP, …)
Protocol/Application Leyer
(Identity, Authn/Authz, IoT, etc.)
Sign, Verify, Proof Generation, Proof Verification, etc.
Commitment Generation, Commitment Verification, Blind Signing etc.
Signing Public Parameters
message 1
message 2
message 3
message L
Points of the Elliptic Curve
Need to be trusted by the Verifier
Signing Public Parameters
message 1
message 2
message 3
message L
Seed
Signing Public Parameters
message 1
message 2
message 3
message L
Seed
All the generators will be trusted
Signing Public Parameters
message 1
message 2
message 3
message L
Seed
All the generators will be trusted
NOT The Same
The signature specific generators will be trusted
Signing Public Parameters
message 1
message 2
message 3
message L
Seed
All the generators will be trusted
NOT The Same
The signature specific generators will be trusted
How the papers solves the problem??
Signing Public Parameters
message 1
message 2
message 3
message L
Domain
Signature
Extra, always revealed, message
Signing Public Parameters
message 1
message 2
message 3
message L
Domain
Signature
Public parameters that the Verifier MUST trust
Extra, always revealed, message
Signing Public Parameters
message 1
message 2
message 3
message L
Domain
Signature
Additional representation or application specific information
This could be:
(blind vs non-blind signatures etc.)
Extra, always revealed, message
Signing Public Parameters
Verifier
Holder
Message 1
Message 2
Message 3
Message L
Signature
Domain
Signing Public Parameters
Verifier
Holder
Message 1
Message 2
Message 3
Message L
Signature
Domain
Signature specific parameters
Domain
Message 1
Message 2
Signing Public Parameters
Verifier
Message 1
Message 2
Domain
Signature specific parameters
Holder Binding
Message 1
Message 2
Message 3
Message L
BBS+ Proof Algorithm
BBS+ Proof Verification Algorithm
Message 1
Message L
Proves:
…of the revealed messages
…of the whole list of signed messages
AND the signature
Holder Binding
Message 1
Message 2
Message 3
Message L
BBS+ Proof Algorithm
BBS+ Proof Verification Algorithm
Message 1
Message L
Proves:
…of the revealed messages
…of the whole list of signed messages
AND the signature
Holder Binding
Issuer
Verifier
Holder
Holder Binding
Issuer
Holder
Verifier
Holder Binding
Verifier
Holder
NIZK Proof
NIZK Proof
NIZK Proof
NIZK Proof
Holder Binding
Verifier
Holder
What's the problem?
NIZK Proof
NIZK Proof
NIZK Proof
NIZK Proof
Holder Binding
Issuer
Verifier
Holder
“commit” to a value:
1
2
Create a signature including:
Holder Secret
Holder Secret
Holder Secret
Message 1
Signature
Message L
Holder Binding
Issuer
Verifier
Holder
“commit” to a value:
1
2
Create a signature including:
Holder Secret
Holder Secret
Holder Secret
Message 1
Signature
Message L
3
Create proof hiding:
Holder Secret
Holder Binding
Issuer
Verifier
Holder
“commit” to a value:
1
2
Create a signature including:
Holder Secret
Holder Secret
Message 1
4
Validate the proof
3
Create proof hiding:
Holder Secret
Holder Binding
Issuer
Verifier
Holder
“commit” to a value:
1
2
Create a signature including:
Holder Secret
Holder Secret
4
Validate the proof
Idea:
3
Create proof hiding:
Holder Secret
Holder Binding
Issuer
Verifier
Holder
“commit” to a value:
1
2
Create a signature including:
Holder Secret
Holder Secret
4
Validate the proof
Proposals for committing a value:
3
Create proof hiding:
Holder Secret
Holder Binding
Issuer
Verifier
Holder
“commit” to a value:
1
2
Create a signature including:
Holder Secret
Holder Secret
4
Validate the proof
Proposals for committing a value:
In scope OR out of scope?
3
Create proof hiding:
Holder Secret
Conclusion
Thank You!!