3 ms·
It's not a good defense, because a double fault injection attack could bypass the signature verification as well. The only software defense that actually works
by bascule 9y ago
It's not a good defense, because a double fault injection attack could bypass the signature verification as well.
The only software defense that actually works reliably is preventing duplicate r-values from being generated in the first place. This can be accomplished by augmenting the fully deterministic r with some additional randomness, producing a synthetic r which is still guaranteed to be unique-per-message even if we have an RNG failure. See:
https://moderncrypto.org/mail-archive/curves/2017/000925.html https://moderncrypto.org/mail-archive/curves/2017/000925.htm...
Note this is quite different from the k-value in ECDSA, which is not synthesized from the message contents at all.