In Chaum’s RSA construction, the requester blinds an encoded message with a random factor, obtains a signature on the hidden value and removes the blinding. Correctness, blindness and unforgeability are distinct properties; the signature alone prevents neither token copying nor double spending.
Ordinary signatures show the signer the message. A blind protocol separates authorization from content, allowing a claim or value to be certified without knowing the final token. [David Chaum — Blind Signatures for Untraceable Payments] [RFC 9474 — RSA Blind Signatures]
With RSA public key (n,e), the requester encodes message m, chooses random invertible r and sends m′ = m·r^e mod n. Blinding hides the message from the signer. [David Chaum — Blind Signatures for Untraceable Payments] [RFC 9474 — RSA Blind Signatures]
The signer uses private exponent d and returns s′ = (m′)^d mod n after checking authorization. It sees the blinded value and the authorization event, not the final message. [David Chaum — Blind Signatures for Untraceable Payments] [RFC 9474 — RSA Blind Signatures]
The requester computes s = s′·r⁻¹ mod n. Algebra removes the blinding, leaving the same RSA signature as direct signing of encoded m would produce. [David Chaum — Blind Signatures for Untraceable Payments] [RFC 9474 — RSA Blind Signatures]
Anyone with the public key verifies that s^e corresponds to the encoded message. The final message-signature pair need not carry an identifier of the interactive issuance. [RFC 9474 — RSA Blind Signatures] [CFRG — RSA Blind Signatures security analysis]
Blindness means the signer cannot reliably link a later token to a particular signing session. Safe encoding and fresh unpredictable factors are essential; textbook RSA is not a production protocol. [RFC 9474 — RSA Blind Signatures] [CFRG — RSA Blind Signatures security analysis]
Unforgeability prevents creating more valid signatures than the number of authorized signing interactions. One-more unforgeability also considers an attacker running multiple sessions concurrently. [RFC 9474 — RSA Blind Signatures] [CFRG — RSA Blind Signatures security analysis]
In Chaumian cash, the mint debits funds or checks entitlement at withdrawal and blindly signs coin secrets. Later it verifies its liability without automatically knowing the account from which the coin originated. [David Chaum — Blind Signatures for Untraceable Payments] [GNU Taler — Blind signatures]
A blind signature does not prevent token copying, hide merchant information or network metadata, or guarantee issuer solvency or the safety of a compromised wallet. A spent-token registry or another protocol handles double spending. [RFC 9474 — RSA Blind Signatures] [GNU Taler — Blind signatures]
Cashu and Fedimint use blind-signed claims against a mint or federation in the Bitcoin and Lightning Network ecosystem. Their specific cryptographic constructions differ from the RSA illustration above. Transaction privacy comes with issuer custody and availability risks. [Cashu protocol specifications] [Fedimint documentation]
For the clearest picture, read this entry together with David Chaum, Chaumian eCash, DigiCash, Cashu, Fedimint, Bitcoin Privacy. The reverse links also lead from DigiCash, Chaumian eCash, Cashu, David Chaum.