Ad-Hoc-Domain Signatures for Personal eID Documents K.Kluczniak, L.Hanzlik, M.Kutylowski Politechnika Wroclawska We consider the domain signature concept --a powerful tool to realize ``privacy-by-design'' during authentication with personal identity cards. We expand the ideas proposed by German Federal Office for Information Security (BSI). We provide a solid formal model for unlinkability alluding the problems of previous definitions. We present a concrete scheme satisfying all required security and privacy properties, in particular solving the seclusiveness problem of the protocol included in the BSI Technical Guideline. Another novelty is enabling ad hoc creation of domains - without no need of domain registration and creating certificates. This improves flexibility and should significantly reduce implementation costs. TO BE PRESENTED AT: ARTICCRYPT 2016