Threshold BBS+ Signatures for Distributed Anonymous Credential Issuance
Jack Doerner, Yashvanth Kondi, Eysa Lee, Abhi Shelat, LaKyah Tyner
Abstract
We propose a secure multiparty signing protocol for the BBS+ signature scheme; in other words, an anonymous credential scheme with threshold issuance. We prove that due to the structure of the BBS+ signature, simply verifying the signature produced by an otherwise semi-honest protocol is sufficient to achieve composable security against a malicious adversary. Consequently, our protocol is extremely simple and efficient: it involves a single request from the client (who requires a signature) to the signing parties, two exchanges of messages among the signing parties, and finally a response to the client; in some deployment scenarios the concrete cost bottleneck may be the client’s local verification of the signature that it receives. Furthermore, our protocol can be extended to support the strongest form of blind signing and to serve as a distributed evaluation protocol for the Dodis-Yampolskiy Oblivious VRF. We validate our efficiency claims by implementing and benchmarking our protocol.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3b5ce45c-910e-4083-b927-bec9fbeac3c4Cited by top-tier papers7
- PEReDi: Privacy-Enhanced, Regulated and Distributed Central Bank Digital CurrenciesAggelos Kiayias, Markulf Kohlweiss, Amirreza SarenchehCCS 2022 · 33 citations
- Aggregate Signatures with Versatile Randomization and Issuer-Hiding Multi-Authority Anonymous CredentialsOmid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya et al.CCS 2023 · 29 citations
- Breaking Omertà: On Threshold Cryptography, Smart Collusion, and WhistleblowingMahimna Kelkar, Aadityan Ganesh, Aditi Partap, Joseph Bonneau et al.CCS 2025 · 1 citation
- How to Bind Anonymous Credentials to HumansJulia Hesse, Nitin Singh, Alessandro SorniottiUSENIX Security 2023
- Secure Multiparty Computation of Threshold Signatures Made More EfficientHarry W. H. Wong, Jack P. K. Ma, Sherman S. M. ChowNDSS 2024
Builds on10
- MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious TransferMarcel Keller, Emmanuela Orsini, Peter SchollCCS 2016 · 487 citations
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 220 citations
- Coconut: Threshold Issuance Selective Disclosure Credentials with Applications to Distributed LedgersAlberto Sonnino, Mustafa Al-Bassam, Shehar Bano, Sarah Meiklejohn et al.NDSS 2019 · 218 citations
- Authenticated Garbling and Efficient Maliciously Secure Two-Party ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 212 citations
- Secure Two-party Threshold ECDSA from ECDSA AssumptionsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2018 · 171 citations
Related papers
- Multi-Holder Anonymous Credentials from BBS SignaturesAndrea Flamini, Eysa Lee, Anna LysyanskayaCRYPTO 2025 · 6 citations
- Robot: Robust Threshold BBS+ in Two RoundsGuofeng Tang, Tian Qiu, Bowen Jiang, Haiyang Xue et al.S&P 2026
- Revisiting BBS SignaturesStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 58 citations
- Blind Multisignatures for Anonymous Tokens with Decentralized IssuanceIoanna Karantaidou, Omar Renawi, Foteini Baldimtsi, Nikolaos Kamarinakis et al.CCS 2024 · 7 citations
- Stronger Security for Threshold Blind SignaturesAnja Lehmann, Phillip Nazarian, Cavit ÖzbayEUROCRYPT 2025 · 10 citations
