4 ms·
Am I missing something? I thought the nonce had to just be non repeating, didn't have to be a secret.
by ayende 3y ago
Am I missing something? I thought the nonce had to just be non repeating, didn't have to be a secret.
- dfox 3y agoSchnorr-like (including DSA and ECDSA) signature schemes use a parameter "k" that has to be uniformly random, secret and non repeating for the security of the system, calling that a "nonce" is slightly weird. Edit: the intuitive reasoning for why it has to be secret and uniformly random is that half of the resulting signature is essentially an linear function of private key, k and the other half of the signature. So if attacker knows k he can trivially recover the whole private key. (EC)DSA uses slightly different representation of the signature, but it is only about shuffling stuff around (presumably to sidestep Schnorr's patent on the scheme) and the same attack still works.