Blind Signatures are a cryptographic primitive invented by David Chaum in 1982 that allow a signer to sign a message without being able to see its content, enabling the message author to later unblind the signature and present a valid signature from the signer without the signer being able to link the signing event to the subsequent presentation. The scheme preserves the unlinkability property — the signer cannot correlate a signing request with a later use of that signature — making it foundational for privacy-preserving payment systems and anonymous credential issuance.

Content

  • David Chaum published the blind signature concept in 1982 and commercialised it through DigiCash, which launched eCash trials with several banks in the early 1990s. The system allowed users to withdraw blinded digital tokens from a bank, unblind them, and spend them at merchants; the bank could verify signature validity without identifying the user. Despite technical success, DigiCash filed for bankruptcy in 1998, primarily due to commercial and adoption challenges rather than cryptographic failures — a cautionary tale for privacy technology ventures.
  • Technically, RSA blind signatures work as follows: the requester generates a random blinding factor r, computes the blinded message m’ = m·r^e mod N where (e, N) is the signer’s public key, sends m’ for signing to receive s’ = (m’)^d mod N, and then unblinds to obtain s = s’/r mod N, which equals m^d mod N — a valid RSA signature on m. The scheme’s security reduces to RSA unforgeability. Schnorr blind signatures and BLS blind signatures extend the principle to other algebraic settings, with some requiring interaction and some being non-interactive.
  • The ecosystem of blind signatures expanded significantly with the introduction of Privacy Pass (IETF RFC 9576), a protocol used by Cloudflare and others to allow clients to prove humanity without tracking. Apple’s Private Access Tokens adopt the RSA Blind Signature scheme from RFC 9474 for iCloud Private Relay. The Zcash cryptocurrency uses a related technique in its Sapling and Orchard shielded transaction protocols, though implemented via zk-SNARKs rather than classical blind signatures.
  • As of 2024–2025, blind signatures see active deployment in privacy-preserving credential systems under the W3C Verifiable Credentials umbrella, particularly in selective-disclosure schemes. The IETF Oblivious HTTP and Privacy Pass standards incorporate blind signatures to decouple authentication from tracking. Post-quantum variants using lattice assumptions (e.g., based on Module-LWE) are under active research to prepare these privacy tools for the anticipated transition away from RSA and elliptic-curve cryptography.