Revisiting BBS Signatures
Stefano Tessaro, Chenzhi Zhu
Abstract
BBS signatures were implicitly proposed by Boneh, Boyen, and Shacham (CRYPTO ’04) as part of their group signature scheme, and explicitly cast as stand-alone signatures by Camenisch and Lysyanskaya (CRYPTO ’04). A provably secure version, called BBS+, was then devised by Au, Susilo, and Mu (SCN ’06), and is currently the object of a standardization effort which has led to a recent RFC draft. BBS+ signatures are suitable for use within anonymous credential and DAA systems, as their algebraic structure enables efficient proofs of knowledge of message-signature pairs that support partial disclosure.
BBS+ signatures consist of one group element and two scalars. As our first contribution, we prove that a variant of BBS+ producing shorter signatures, consisting only of one group element and one scalar, is also secure. The resulting scheme is essentially the original BBS proposal, which was lacking a proof of security. Here we show it satisfies, under the q-SDH assumption, the same provable security guarantees as BBS+. We also provide a complementary tight analysis in the algebraic group model, which heuristically justifies instantiations with potentially shorter signatures.
Furthermore, we devise simplified and shorter zero-knowledge proofs of knowledge of a BBS message-signature pair that support partial disclosure of the message. Over the BLS12-381 curve, our proofs are 896 bits shorter than the prior proposal by Camenisch, Drijvers, and Lehmann (TRUST ’16), which is also adopted by the RFC draft.
Finally, we show that BBS satisfies one-more unforgeability in the algebraic group model in a scenario, arising in the context of credentials, where the signer can be asked to sign arbitrary group elements, meant to be commitments, without seeing their openings.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 08da38bd-8bd0-4c47-8fd1-e379ffe9d446Cited by top-tier papers5
- Aggregate Signatures with Versatile Randomization and Issuer-Hiding Multi-Authority Anonymous CredentialsOmid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya et al.CCS 2023 · 29 citations
- Tight Security for BBS SignaturesRutchathon Chairattana-Apirom, Dennis Hofheinz, Stefano TessaroEUROCRYPT 2026 · 1 citation
- Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record CertificationKasra EdalatNejad, Sebastian Faust, Jonas Hofmann, Philipp-Florens Lehwalder et al.USENIX Security 2026 · 1 citation
- Efficient Proofs of Possession for Legacy SignaturesAnna P. Y. Woo, Alex Ozdemir, Chad Sharp, Thomas Pornin et al.S&P 2025
- Revisiting Keyed-Verification Anonymous CredentialsMichele OrrùCCS 2025
Related papers
- Multi-Holder Anonymous Credentials from BBS SignaturesAndrea Flamini, Eysa Lee, Anna LysyanskayaCRYPTO 2025 · 6 citations
- Threshold BBS+ Signatures for Distributed Anonymous Credential IssuanceJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi Shelat et al.S&P 2023
- Server-Aided Anonymous CredentialsRutchathon Chairattana-Apirom, Franklin Harding, Anna Lysyanskaya, Stefano TessaroCRYPTO 2025 · 10 citations
- Robot: Robust Threshold BBS+ in Two RoundsGuofeng Tang, Tian Qiu, Bowen Jiang, Haiyang Xue et al.S&P 2026
- Playing Tag with Okamoto-Schnorr: Three-Move Pairing-Free Blind Signatures from DDHRutchathon Chairattana-Apirom, Michael Reichle, Stefano TessaroCRYPTO 2026
