In this paper, we present a deterministic attack on (EC)DSA signature scheme, providing that several signatures are known such that the corresponding ephemeral keys share a certain amount of bits without knowing their value. By eliminating the shared blocks of bits between the ephemeral keys, we get a lattice of dimension equal to the number of signatures having a vector containing the private key. We compute an upper bound for the distance of this vector from a target vector, and next, using Kannan's enumeration algorithm, we determine it and hence the secret key. The attack can be made highly efficient by appropriately selecting the number of shared bits and the number of signatures.
翻译:本文提出了一种针对(EC)DSA签名方案的确定性攻击,前提是已知若干签名,其对应的临时密钥共享一定数量的比特位,而无需知晓这些比特位的具体值。通过消除临时密钥间共享的比特块,我们得到一个维度等于签名数量的格,该格中包含含有私钥的向量。我们计算了该向量与目标向量距离的上界,随后利用Kannan枚举算法确定该向量,从而获取私钥。通过适当选择共享比特数和签名数量,该攻击可实现高效性。