4 ms·
One thing I would point out is that when calculating r, the equation r=k*G mod N is somewhat misleading. G is not a number, but rather an (X,Y) point on an elli
by scottmsul 5y ago
One thing I would point out is that when calculating r, the equation r=k*G mod N is somewhat misleading. G is not a number, but rather an (X,Y) point on an elliptic curve. There is a way to "add" two points on an elliptic curve but it is a group operation which is very unlike normal addition. "Multiplication" still exists between a scalar and a point but refers to a number of point self-additions.
So really R=k*G generates a new point R, where k is the nonce and G is a point that is part of the ECDSA standard. Then r is taken as the x-coordinate of R.
It is easy to derive k in b=k*a mod N if you know a and b, but nearly impossible to derive k in B=k*A if B is k self additions of A on an elliptic curve.