Case 7A231C · Cryptography · L5 Expert
ECDSA Nonce Bias Key Recovery
Practise as: Explain it · Interview
Interview questionYour ECDSA signer leaks a few bits of each nonce through timing. Why is that enough to recover the private key?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- s = k^-1 (h + r*d) mod n, so any partial knowledge of nonce k gives a linear equation in the private key d.
- Known or biased nonce bits across many signatures form a Hidden Number Problem, solved by lattice reduction (LLL/BKZ).
- Real cases: TPM-Fail (2019, Intel fTPM and STMicro TPM timing) and Minerva (2019, leaks of nonce bit-length).
- Nonces shorter than the group order (e.g. 64- or 128-bit k on a 256-bit curve) are exploitable with no side channel.
- Fix: RFC 6979 deterministic or hedged nonces, full-width unbiased sampling, and constant-time scalar multiplication.
If the interviewer pushes back
- Why are deterministic nonces (RFC 6979, Ed25519) vulnerable to fault attacks, and what do hedged signatures add?
- How would you test a signing device for nonce bias using only signatures it produces?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.