Blinding for Unanticipated Signatures

Previously known blind signature systems require an amount of computation at least proportional to the number of signature types, and also that the number of such types be fixed in advance. These requirements are not practical in some applications. Here, a new blind signature technique is introduced that allows an unlimited number of signature types with only a (modest) constant amount of computation.