Noon RSA Blind Signature Architecture
Hash & Blind
Multiplies hash with secret factor r
m' = (m · re) mod n Blind Signature
Signs without seeing payload m
s' = (m')d mod n Unblind
Removes blinding factor r
s = (s' · r-1) mod n Anonymous Proof
Verifies without user linkage
m ≡ se mod n ✓ The signing authority signs the blinded hash m' without seeing the submission payload m. The submitter unblinds s' and submits anonymously.
Most web applications promising "anonymous feedback" or "confidential voting" rely on policy assurances while continuing to record IP addresses, session cookies, and browser fingerprints. Noon eliminates the need for organizational trust by using RSA Blind Signature Cryptography, mathematically breaking the connection between a participant's identity and their response.
The Cryptographic Mathematics of Blind Signatures
First designed by cryptographer David Chaum in 1983, blind signatures enable an authority to sign a digital document without observing its contents. The resulting signature is verifiable by anyone using the signer's public key, yet cannot be correlated with the original signing transaction.
The Five-Step RSA Process
- Setup: The server maintains an RSA key pair $(n, e, d)$ and publishes the public modulus $n$ and exponent $e$.
- Blinding: The client computes the digest of their answers $m = \text{SHA256}(\text{Submission} \parallel \text{Nonce})$. Choosing a random blinding factor $r$ where $\gcd(r, n) = 1$, the client blinds the digest:
m' = (m · re) mod n
- Signing: The server verifies that the user is authorized to submit, signs the blinded value $m'$, and decrements the user's signature balance:
s' = (m')d mod n ≡ (md · r) mod n
- Unblinding: The client receives $s'$ and removes the random factor $r$ by multiplying with its modular inverse:
s = (s' · r-1) mod n ≡ md mod n
- Anonymous Verification: The client submits the submission data, nonce, and signature $s$ across an unauthenticated connection. The server verifies that:
m ≡ se mod n
Authentication Without Deanonymization
Preventing spam without identifying submitters requires a decoupled, two-stage architecture:
- Step 1 (Authenticated Token Exchange): The participant proves eligibility using standard authentication (e.g., OTP or verified account). The server validates permission and signs the blinded payload, recording only that this specific account used its submission right.
- Step 2 (Unauthenticated Payload Submission): The client unblinds the signature and dispatches the answers with signature $s$ through an isolated network request stripped of session cookies, authentication tokens, or identifying headers.
Network-Level Anonymity and Future Hardening
While blind signatures make cryptographic payload linkage impossible, network-level side channels must also be addressed in high-stakes environments:
- Routing via Tor / Proxies: Separating the network path of the signing request from the submission request to prevent IP correlation.
- Temporal Decoupling: Adding randomized delays between receiving the signature and submitting the response to defeat timing analysis.
- Client Sandboxing: Standardizing user-agent strings and headers to prevent browser fingerprinting.
Check out the open-source implementation of Noon on GitHub at github.com/lupyd/noon.
- ✓ Standard anonymous forms rely on corporate policy; Noon replaces policy with mathematical blind signature guarantees.
- ✓ David Chaum's RSA blind signature scheme allows a server to sign and authorize a submission hash without seeing its content.
- ✓ Unblinding allows the submitter to prove validity to the server over an unauthenticated connection.
- ✓ Two-phase token exchange prevents double-submissions while completely severing the link between identity and response.
- ✓ Future resilience includes Tor-based multi-path routing, client-side timing jitter, and zero-knowledge proofs.