Hacker News new | past | comments | ask | show | jobs | submit login

RFC6979 attempts to guarantee that the nonce is unbiased (under the assumption that HMAC's output is indistinguishable from random). It's definitely attempting to give a stronger property than simply preventing a repeated nonce.

See step (h) in Section 3.2. The nonce is selected by rejection sampling. Thus, under the above assumption about HMAC, the result is indistinguishable from uniformly random in the [1, q-1] range.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: