Skip to content

LibraryPrivacy2016Design paperCorpus record

BBS+ Signatures and Selective Disclosure

BBS signatures. Jan Camenisch, Manu Drijvers and Anja Lehmann.

A BBS-family signature can be proved in zero knowledge so a holder reveals only some messages and produces an unlinkable presentation.

A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.

A selective-disclosure pitch should say which signature, which fields are hidden, and whether two presentations can be tied together.

The five-minute read

The defect

A signed credential that must be shown in full teaches the verifier every field, and links every presentation to the same signature.

The rule

A BBS-family signature can be proved in zero knowledge so a holder reveals only some messages and produces an unlinkable presentation.

How it is put together

The issuer signs a vector of messages. The holder proves knowledge of a signature on a subset. Unlinkability is a goal of the proof, not of the issuer's log.

Where the claim stops

The paper's scheme is not every library that says BBS.

One action, walked through

  1. The issuer signs the attributes.
  2. The holder generates a proof that reveals the attributes they chose.
  3. The verifier checks the proof against the issuer's public key.
  4. Which messages are revealed?

The argument, unpacked

Why it is still on the desk

A selective-disclosure pitch should say which signature, which fields are hidden, and whether two presentations can be tied together.

After the text

W3C and DIF profiles later pointed at BBS. The 2016 paper is the signature, not the product.

What has to be true

  • The paper's scheme is not every library that says BBS.
  • Revocation and issuer correlation are extra.
  • It does not put the attributes on a chain.

What happened after the paper

W3C and DIF profiles later pointed at BBS. The 2016 paper is the signature, not the product.

What to check before you use the idea

  • Which messages are revealed?
  • Can two presentations be linked?
  • Where is revocation checked?

Terms

Selective disclosure
Showing some signed fields and withholding the rest.
Unlinkable presentation
A proof that does not identify the holder across uses.

The problem the paper names

A signed credential that must be shown in full teaches the verifier every field, and links every presentation to the same signature.

What the design proposes

  • The issuer signs a vector of messages.
  • The holder proves knowledge of a signature on a subset.
  • Unlinkability is a goal of the proof, not of the issuer's log.

How the mechanism is specified

  • The issuer signs the attributes.
  • The holder generates a proof that reveals the attributes they chose.
  • The verifier checks the proof against the issuer's public key.

What this page does not treat as proven

  • The paper's scheme is not every library that says BBS.
  • Revocation and issuer correlation are extra.
  • It does not put the attributes on a chain.

Why a venture studio still reads it

A selective-disclosure pitch should say which signature, which fields are hidden, and whether two presentations can be tied together.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.