Paper 2023/1199

RSA Blind Signatures with Public Metadata

Ghous Amjad, Google (United States)
Kevin Yeo, Google (United States)
Moti Yung, Google (United States)
Abstract

Anonymous tokens are, essentially, digital signature schemes that enable issuers to provide users with signatures without learning the user inputs or the final signatures. These primitives allow applications to propagate trust while simultaneously protecting the user identity. They have become a core component for improving the privacy of several real-world applications including ad measurements, authorization protocols, spam detection, and VPNs. In certain applications, it is natural to associate signatures with specific public metadata, ensuring that trust is only propagated with respect to only a certain set of users and scenarios. To solve this, we study the notion of anonymous tokens with public metadata. We present a variant of RSA blind signatures with public metadata where issuers may only generate signatures that verify for a certain choice of public metadata a modification of a scheme by Abe and Fujisaki [9]. Our protocol exclusively uses standard cryptography with widely available implementations. We prove security from the one-more RSA assumptions with multiple exponents that we introduce. Furthermore, we provide evidence that the concrete security bounds should be nearly identical to standard RSA blind signatures. We show that our protocol incurs minimal overhead over standard RSA blind signatures and report anonymous telemetry for a real-world deployment to showcase its scalability. Moreover, the protocol in this paper has been proposed as a technical specification in an IRTF internet draft [12].

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. 25th Privacy Enhancing Technologies Symposium (PETS 2025)
Keywords
blind signaturesanonymous tokenspublic metadatapartially blind
Contact author(s)
gamjad @ google com
kwlyeo @ google com
moti @ google com
History
2025-01-16: revised
2023-08-08: received
See all versions
Short URL
https://ia.cr/2023/1199
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2023/1199,
      author = {Ghous Amjad and Kevin Yeo and Moti Yung},
      title = {{RSA} Blind Signatures with Public Metadata},
      howpublished = {Cryptology {ePrint} Archive, Paper 2023/1199},
      year = {2023},
      url = {https://eprint.iacr.org/2023/1199}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.