BBS+ Signatures is the collective term for the class of pairing-based multi-message signature schemes derived from the BBS construction, encompassing both the base signature algorithm and the proof-of-knowledge protocols that enable selective disclosure and unlinkable presentation of signed credential attributes. As a scheme family, BBS+ Signatures represent the cryptographic foundation for privacy-preserving digital credential ecosystems.

Content

  • The BBS+ scheme family traces its roots to the 2004 Boneh-Boyen-Shacham paper and gained momentum when applied to anonymous credential systems in the 2010s. Early adoption came from the Hyperledger Indy/AnonCreds ecosystem, which used a closely related scheme called CL (Camenisch-Lysyanskaya) signatures — themselves predecessors of BBS+. The shift to BBS+ accelerated after 2019 when DIF members recognised that BBS+ offered better performance on modern pairing-friendly curves whilst preserving the unlinkability properties required for SSI.
  • The scheme family encompasses several cryptographic objects: the signing key pair (issuer private/public key), the signature over a committed message vector, the proof-of-knowledge (PoK) protocol for generating derived presentations, and the verifier algorithm that checks the PoK without learning the signature. Multiple parameter specifications exist — BBS (IETF draft-irtf-cfrg-bbs-signatures) uses BLS12-381; research variants explore BN254 for gas-efficient on-chain verification. The proof size is constant regardless of how many messages are signed or disclosed.
  • In deployment, BBS+ Signatures are implemented in libraries including the Mattrglobal bbs-signatures TypeScript library, the Hyperledger AnonCreds Rust library, and the W3C vc-di-bbs JavaScript library. These are integrated into SSI wallets (Trinsic, Esatus, Lissi) and government identity programmes including the EU EUDI Wallet pilot. The BBS cryptosuite for W3C Verifiable Credentials has reached Candidate Recommendation status.
  • By 2024–2025, BBS+ Signatures are positioned as the preferred cryptographic method for large-scale digital identity deployments requiring both interoperability and user privacy. The EUDI Wallet’s selective disclosure requirements have driven substantial implementation work across EU member states. Open research questions include post-quantum security — pairing-based schemes are vulnerable to Shor’s algorithm — and hardware security module (HSM) support for issuer signing operations, which most HSM vendors do not yet natively support for BLS12-381 curve operations.