How to derive Z from R and S?

2 replies 369 views
wolf_2020Member
Posts: 9 · Reputation: 229
#1Jun 13, 2018, 04:10 AM
How do you get Z from R and S? Got some examples here: R = 0xcabc3692f1f7ba75a8572dc5d270b35bcc00650534f6e5ecd6338e55355454d5 S = 0xf65bfc44435a91814c142a3b8ee288a9183e6a3f012b84545d1fe334ccfac25e Looking for the target Z value for 0x9b076ad2fe6b2ce63acf4edf7fc82d5152d3c8bffb36b944da7a1cce038f544a Another set: R = 0xcabc3692f1f7ba75a8572dc5d270b35bcc00650534f6e5ecd6338e55355454d5 S = 0x9cae782a191f3e742d9d4ff8f726d097a3a256af9fbc1faf16e7ec4d9fcf6feb Need Z for 0x85e43d48a83d8713a0fe253bf6b1fc70b8ee780e54749dc500f2880b056c4383 And one more: R = 0x79be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798 S = 0xb0fc6f098d906534447438 What do you guys think?
4 Reply Quote Share
ben2019Newbie
Posts: 21 · Reputation: 37
#2Jun 14, 2018, 04:49 AM
Not sure if you can calculate Z like that. If you only have one pair of R and S, that’s a no-go. If you got two pairs, and k is the same for both, you still can't find Z. You only have R, S1, and S2. It’s not enough... To figure out d, you need z and k, but right now you’re missing a bunch of stuff. Four unknowns but only two equations? Sounds like a dead end to me.
4 Reply Quote Share
mr_byteSenior Member
Posts: 10 · Reputation: 1059
#3Jun 14, 2018, 07:24 AM
k = (inv(s) * (z + r * pvk)) % N s = (inv(k) * (z + r * pvk)) % N pvk = (inv(r) * ((k*s) z)) % N r * pvk = ((k*s) z) % N So yeah, R, S, Z, private key, and k can all be odd or even. But like, how do we get past that limit? Anyone got a better approach?
0 Reply Quote Share

Related topics