Security Difference between DSA and Schnorr's Signature
Zhengjun Cao, Olivier Markowitch · 2009
We investigate the security difference between DSA and Schnorr's signature. The security of DSA can be reduced to the problem: to find m isin Omega, rho, thetas isin Zq* such that H(m) = P ((gpy)thetasmod p) mod q, where Omega denotes the text space and the message to is not restrained. Unlike DSA evaluates the hash function only at the message to, Schnorr's signature adopts a self-feedback mode by evaluating the hash function at (m, r, s). Thus its security becomes more robust.