Security Difference between DSA and Schnorr's Signature

Zhengjun Cao, Olivier Markowitch · 2009

We investigate the security difference between DSA and Schnorr's signature. The security of DSA can be reduced to the problem: to find m isin Omega, rho, thetas isin Zq* such that H(m) = P ((gpy)thetasmod p) mod q, where Omega denotes the text space and the message to is not restrained. Unlike DSA evaluates the hash function only at the message to, Schnorr's signature adopts a self-feedback mode by evaluating the hash function at (m, r, s). Thus its security becomes more robust.

Read the paper · More papers on PaperTik