Understanding Nonce Behavior in secp256k1 ECDSA

2 replies 384 views
chain1337Hero Member
Posts: 58 · Reputation: 3203
#1Aug 14, 2018, 07:07 PM
Hey all, Looking at some k values here, they seem kinda predictable and deterministic. R1 = 0x5660647957179a737ee9f43d69ea7923ed179680acaea311986ba7bde67dd321 R2 = 0x566064795718a8c41789a5e3947f17cb2932dca737037bce9b49c7a75f606ce1 The Relative Distance Ratio (Distance / n) is about 0.000000000000003751.
2 Reply Quote Share
Posts: 3 · Reputation: 204
#2Aug 14, 2018, 10:24 PM
Predictable? How do you figure? The math distance between R1 and R2 doesn’t really show the actual distance between their nonces. Here’s an example: R1 = 0xa03aba6c1d66b0adff5f523b05ae59226b75a3c89c5755728d4278b4d02dec0 R2 = 0xd95ae6aa449d8243d4fc55ffa443c3f9982d235d4237fe0c187dba73b075b71d Sure, they look far apart mathematically. But if I tell you their Relative Distance Ratio is basically 0, that changes the perspective.
1 Reply Quote Share
GrimFarmFull Member
Posts: 13 · Reputation: 792
#3Aug 16, 2018, 05:20 PM
r = x(k*G) mod n. The closeness of r1 and r2 doesn’t mean anything for k1 and k2. The x mapping and mod reduction mess up any simple distance connection. You can find tiny r gaps from nonces that aren't even related. Agreed, we need to measure distance in scalar space, not just by looking at r or x(R). Without k or any leaked bits, it’s hard to pinpoint. The real dangers are from nonce reuse, biased RNG, or partial leaks that can lead to lattice attacks.
2 Reply Quote Share

Related topics