Understanding 1-Bit Signatures in Lattice Attacks

5 replies 35 views
Posts: 2 · Reputation: 21
#1Feb 2, 2022, 07:37 PM
I was trying to generate 1-bit signatures using this repo I found. But I keep hitting a wall with "private key not found". I want to figure out how 1-bit signatures r, s, z can help with that. Anyone got these signatures to share here? I’m really keen to prove that 1-bit is enough to crack d.
3 Reply Quote Share
falcon2019Full Member
Posts: 90 · Reputation: 425
#2Feb 2, 2022, 11:12 PM
You might need a ton of those signatures. More than your RAM can handle, tbh.
0 Reply Quote Share
sigma2016Newbie
Posts: 64 · Reputation: 22
#3Feb 3, 2022, 05:09 AM
Honestly, 1-bit signatures don't really add up, even for tiny elliptic curves like p=79, n=67. They call it 7-bit security, but it’s closer to 6-bit in practice. If you have r and s as single bits, they can only be 0 or 1. So you end up with four combinations. What’s the end goal here?
4 Reply Quote Share
falcon2019Full Member
Posts: 90 · Reputation: 425
#4Feb 3, 2022, 08:45 AM
I thought the OP was talking about biased nonces to solve lattice problems. But s as a forced 1-bit… yeah, that doesn’t work since r is tied to kG.x mod n.
1 Reply Quote Share
markl4serMember
Posts: 2 · Reputation: 41
#5Feb 3, 2022, 01:12 PM
You can’t apply a Lattice attack with just 1-bit nonces. It just doesn’t work. The error vector is too noisy when you deal in larger dimensions. You’d be better off with a Fourier attack.
4 Reply Quote Share
GrimFarmFull Member
Posts: 49 · Reputation: 792
#6Feb 3, 2022, 06:05 PM
I think the confusion lies in how you’re defining a "1-bit r, s, z signature." Those values need to be full-sized. For lattice attacks, knowing the nonce k is more key than any cute labeling. One full nonce is enough for one signature; a few almost known can work too. But trying to claim you need 1-bit signatures? Nah.
0 Reply Quote Share

Related topics