A flaw in a theorem about Schnorr signatures.

Daniel R. L. Brown · 2015

An alleged theorem of Neven, Smart and Warinschi (NSW) about the security of Schnorr signatures seems to have a flaw described in this report. Schnorr signatures require representation of an element in a dis-crete logarithm group as a hashable bit string. This report describes a defective bit string representation of elliptic curve points. Schnorr signatures are insecure when used with this defective representation. Nevertheless, the defective representation meets all the conditions of the NSW theorem. Of course, a natural representation of an elliptic curve group ele-ment would not suffer from this major defect. So, the NSW theorem can probably be fixed. 1

Read the paper · More papers on PaperTik