Is it secure to disclose the personal key that generates the R nonce in schnorr sigs?

on

|

views

and

comments


No, it’s not secure. If the random nonce ok is revealed, the counterparty can calculate your personal key.

A Schnorr signature consists of two scalars (r,s). The place r is the x coordinate of a degree R generated from a random nonce ok. If I perceive you proper, you’re asking whether or not it’s secure to disclose this ok.

A Schnorr signature is generated within the following method:

  • m: message
  • x: personal key
  • P: public key; P = x×G
  • ok: random nonce
  • R: random level; R = ok×G
  • r = R.x (x coordinate of random level R)
  • s = ok + hash(P,R,m)•x

If either side of the final equation are multiplied with the generator level G:

s = ok + hash(P,R,m)•x
s×G = (ok + hash(P,R,m)•x)×G
s×G = ok×G + hash(P,R,m)•x×G
s×G = R + hash(P,R,m)•P

So, any third social gathering can examine whether or not the signature is legitimate by plugging (r,s), the message m from the context of the transaction, and the general public key P from both the prior output or the witness construction into:

s×G = R + hash(P,R,m)•P

If the equation holds, the signature proves that the signer knew the personal key x equivalent to the general public key P.

No, it isn’t secure to share ok, as a result of given ok the counterparty can resolve for the personal key on this equation solely composed of scalars:

x = (s - ok) / hash(P,R,m)

Share this
Tags

Must-read

‘The automobile all of the sudden accelerated with our child in it’: the terrifying fact about why Tesla’s automobiles maintain crashing | Tesla

It was a Monday afternoon in June 2023 when Rita Meier, 45, joined us for a video name. Meier advised us in regards...

Tesla car deliveries drop sharply as Musk backlash impacts demand | Tesla

Tesla posted one other massive drop in quarterly deliveries on Wednesday, placing it on track for its second straight annual gross sales decline...

‘Lidar is lame’: why Elon Musk’s imaginative and prescient for a self-driving Tesla taxi faltered | Tesla

After years of promising traders that thousands and thousands of Tesla robotaxis would quickly fill the streets, Elon Musk debuted his driverless automobile...

Recent articles

More like this

LEAVE A REPLY

Please enter your comment!
Please enter your name here