Bitcoin Forum

Bitcoin => Development & Technical Discussion => Topic started by: SlaitX on March 21, 2024, 04:47:48 AM



Title: ECDSA 1/k
Post by: SlaitX on March 21, 2024, 04:47:48 AM
The task:

We have 2 signatures
d - private key
k - nonce
r - public key
s - Signature
z - Hash

d1=(k1*s1-z1)/r1
k1=(d1*r1+z1)/s1
r1=(k1*s1-z1)/d1
s1=(d1*r1+z1)/k1
z1=k1*s1-d1*r1

Any ideas if we have a signature another signature

d2=1/k-1
k2=1/k1
r2=(k2*s2-z2)/d2
s2=(d2*r2+z2)/k2
z2=k2*s2-d2*r2

We have 1/k and k, how can we calculate the value of k?


Title: Re: ECDSA 1/k
Post by: SlaitX on April 15, 2024, 07:44:37 AM
Added new information
d1=(k1*s1-z1)/r1
k1=(d1*r1+z1)/s1
r1=(k1*s1-z1)/d1
s1=(d1*r1+z1)/k1
z1=k1*s1-d1*r1

Any ideas if we have a signature another signature

d2=k1^(n-2)-1
k2=k1^(n-2)
r2=(k2*s2-z2)/d2
s2=(d2*r2+z2)/k2
z2=k2*s2-d2*r2


Title: Re: ECDSA 1/k
Post by: cassondracoffee on April 15, 2024, 11:16:07 AM

Added new information
d1=(k1*s1-z1)/r1
k1=(d1*r1+z1)/s1
r1=(k1*s1-z1)/d1
s1=(d1*r1+z1)/k1
z1=k1*s1-d1*r1

Any ideas if we have a signature another signature

d2=k1^(n-2)-1
k2=k1^(n-2)
r2=(k2*s2-z2)/d2
s2=(d2*r2+z2)/k2
z2=k2*s2-d2*r2



Added new information
d1=(k1*s1-z1)/r1
k1=(d1*r1+z1)/s1
r1=(k1*s1-z1)/d1
s1=(d1*r1+z1)/k1
z1=k1*s1-d1*r1

Any ideas if we have a signature another signature

d2=k1^(n-2)-1
k2=k1^(n-2)
r2=(k2*s2-z2)/d2
s2=(d2*r2+z2)/k2
z2=k2*s2-d2*r2


Where is the rsz value?? Give your RSZ value

r=0x
s=0x
z=0x


Title: Re: ECDSA 1/k
Post by: stilichovandal on April 18, 2024, 02:12:02 PM
Added new information
d1=(k1*s1-z1)/r1
k1=(d1*r1+z1)/s1
r1=(k1*s1-z1)/d1
s1=(d1*r1+z1)/k1
z1=k1*s1-d1*r1

Any ideas if we have a signature another signature

d2=k1^(n-2)-1
k2=k1^(n-2)
r2=(k2*s2-z2)/d2
s2=(d2*r2+z2)/k2
z2=k2*s2-d2*r2


I don't understand the question here.

Are you saying  k1 ie x coordinate and k2 x coordinate are inverse to each other ? or the actual nonce is inverse?