Hey all,
Looking at some k values here, they seem kinda predictable and deterministic.
R1 = 0x5660647957179a737ee9f43d69ea7923ed179680acaea311986ba7bde67dd321
R2 = 0x566064795718a8c41789a5e3947f17cb2932dca737037bce9b49c7a75f606ce1
The Relative Distance Ratio (Distance / n) is about 0.000000000000003751.
Understanding Nonce Behavior in secp256k1 ECDSA
2 replies 384 views
rocket_2019Member
Posts: 3 · Reputation: 204
#2Aug 14, 2018, 10:24 PM
Predictable? How do you figure?
The math distance between R1 and R2 doesn’t really show the actual distance between their nonces. Here’s an example:
R1 = 0xa03aba6c1d66b0adff5f523b05ae59226b75a3c89c5755728d4278b4d02dec0
R2 = 0xd95ae6aa449d8243d4fc55ffa443c3f9982d235d4237fe0c187dba73b075b71d
Sure, they look far apart mathematically. But if I tell you their Relative Distance Ratio is basically 0, that changes the perspective.
r = x(k*G) mod n. The closeness of r1 and r2 doesn’t mean anything for k1 and k2.
The x mapping and mod reduction mess up any simple distance connection. You can find tiny r gaps from nonces that aren't even related.
Agreed, we need to measure distance in scalar space, not just by looking at r or x(R). Without k or any leaked bits, it’s hard to pinpoint. The real dangers are from nonce reuse, biased RNG, or partial leaks that can lead to lattice attacks.
Related topics
- Understanding the Differences Between Traditional and Simplified Chinese Mnemonics 6
- Understanding Fees with Taproot Script Usage 3
- Exploring n-values and b-values in secp256k1 19
- New Bitcoin Improvement Proposal with $100 Reward 9
- Clipboard Vulnerabilities in Cryptocurrency Transactions 8
- Can You Prune Bitcoin Core Data by Date Range? 4