Nonce Generation for Discrete Logarithm‐Based Signatures

Akira Takahashi, Mehdi Tibouchi · 2025

Discrete logarithm-based signature schemes, such as Schnorr signatures and elliptic curve digital signature algorithm (ECDSA), are commonly used in today's real-world systems along with RSA. The signature generation algorithms in these schemes crucially rely on some ephemeral randomness, sometimes referred to as the nonce . Nonce reuse has been a common vulnerability in practical implementations of discrete logarithm-based schemes: some high-profile attack examples include the extraction of leading technology company's ECDSA secret key for signing gaming software. One of the most common settings in which this attack applies is the case of non-constant time scalar multiplication on elliptic curves, where timing information reveals (albeit imperfectly) the bit length of the nonce . Independently of the lattice attack, a completely different approach to the hidden number problem was proposed by Bleichenbacher in 2000.

Read the paper · More papers on PaperTik