The Insecurity of the Digital Signature Algorithm with Partially Known Nonces
Igor E. Shparlinski · Birkhäuser Basel eBooks · 2003
Here we present the polynomial-time algorithm of [417] which recovers theprivate keyof the signer if a small portion of bits of the so-callednoncein the Digital Signature Algorithm modulo a primepis known forsignatures.