BBS+ Signature is a pairing-based digital signature scheme that signs a vector of messages simultaneously and supports the generation of zero-knowledge proofs that reveal only a chosen subset of those messages — a property known as selective disclosure — without revealing the full signed message set or enabling linkage of multiple presentations to the same credential. It is a cornerstone primitive for privacy-preserving verifiable credentials.

Content

  • The BBS signature scheme was originally proposed by Dan Boneh, Xavier Boyen, and Hovav Shacham in 2004 (the “BBS” acronym). The ”+” extension — adding support for multiple messages and zero-knowledge proof of knowledge of the signature — was developed through subsequent academic work and formalised by Jan Camenisch, Manu Sporny, and collaborators. The Decentralized Identity Foundation (DIF) and W3C Credentials Community Group began drafting an interoperable specification in 2019, leading to the BBS Signature draft specification that is now under IETF standardisation.
  • Technically, BBS+ operates over a pairing-friendly elliptic curve (most commonly BLS12-381, which provides 128-bit security). Signing generates a single group element that is a function of all signed messages and the issuer’s private key. Proof generation — a zero-knowledge proof of knowledge of the signature — uses a modified Fiat-Shamir transform to commit to the full set of signed messages, then selectively open commitments only for the attributes the holder chooses to disclose. The resulting proof is unlinkable across presentations because new randomness is introduced at each proof generation step.
  • The primary application domain is self-sovereign identity (SSI): credentials issued by governments, universities, or employers can be selectively presented to verifiers with only the required attributes revealed. For example, a driving licence credential might disclose the “over 18” flag for age verification without revealing name, address, or exact date of birth. This is a major advance over simple credential presentation where the full document is shared.
  • By 2024–2025, BBS+ Signature has been incorporated into the W3C Verifiable Credentials Data Model via the BBS cryptosuite specification, the EU EUDI Wallet architecture (as an optional cryptographic suite), and commercial SSI platforms including Hyperledger AnonCreds v2. IETF draft RFC specification work continues, with interoperability testing events identifying edge cases in multi-message proof generation. Post-quantum variants of BBS+ are under active research, given that pairing-based schemes are vulnerable to future quantum attacks.