Untraceable payments
The ordinary digital signature (e.g. (EC)DSA, Schnorr, etc…) verification process involves the public key of the signer. It is a necessary condition, because the signature actually proves that the author possesses the corresponding secret key. But it is not always a sufficient condition.