Identification Schemes, Schnorr Signatures, and DSA
1. Scope of the lecture
The previous lecture introduced digital signatures and, in particular, an RSA-based hash-and-sign construction. This lecture develops two other signature schemes used in practice: Schnorr signatures and the Digital Signature Algorithm (DSA). Before defining them, it introduces interactive identification schemes and shows how the Fiat–Shamir transform converts an appropriate three-move identification protocol into a non-interactive signature scheme.
The lecturer emphasized that the course had only scratched the surface of digital signatures. A later, informal lecture was planned to discuss more advanced topics such as BLS signatures, threshold signatures, blind signatures, and other variants. That later material was not intended for the final exam. According to the announcement in this lecture, the examinable material included everything covered up to this point, this lecture, and the following two lectures on zero knowledge; material after that cutoff would be optional and non-examinable. The lecture also began with a reminder that the course-evaluation link and the relevant uploaded file were still available for a limited time.
One motivation for alternatives to the earlier RSA construction was efficiency. Traditional RSA parameters use two primes of roughly \(1000\) bits each and therefore a modulus of roughly \(2000\) bits. Arithmetic on integers of that size was relatively expensive, especially on constrained hardware. Schnorr signatures were designed to provide a much more compact and efficient alternative. DSA has a closely related but historically more complicated origin, discussed near the end of the lecture.
2. The identification problem
2.1. Motivation: proving possession of a credential
The motivating application is access control. A user wants to log in to an account and must convince a server that the user possesses the proper credential. Passwords are one possible mechanism, but simple password-based mechanisms can suffer from replay attacks. For example, if a protocol repeatedly sends the same password-derived authenticator, then an observer may record that value and later replay it.
There is also a conceptual limitation to ordinary password authentication. The user sends a secret, normally through an encrypted connection, and the server checks it against account data. The server therefore receives or otherwise possesses enough information to perform the same authentication check. Public-key cryptography suggests a cleaner goal: associate a public key with the account and let the user prove possession of the corresponding secret key without revealing that secret key.
Thus, an identification scheme has two principal parties:
- The prover is normally the user. It knows the secret key \(sk\).
- The verifier is normally the server. It knows the public key \(pk\) bound to the user’s account.
The prover’s goal is to convince the verifier that it knows a secret key \(sk\) corresponding to \(pk\).
The key pair is produced by a generation algorithm
\[ (pk,sk) \leftarrow \mathsf{Gen}(1^\lambda). \]
The public key may then be registered with a particular account. When a user claims that account, the server retrieves the registered public key and starts the identification protocol.
The lecturer referred interested students to the old and relatively accessible paper entitled How to Prove Yourself, which studies ways to formalize and construct authentication and identification mechanisms.
2.2. Three-move identification schemes and Sigma protocols
The lecture focuses on a three-move identification scheme. In the terminology used in the lecture, this is also called a Sigma protocol. The three exchanged values form a shape resembling the Greek letter \(\Sigma\) when drawn in the usual protocol diagram.
Let \((\mathsf{Gen},P_1,P_2,V)\) be such a scheme. The protocol is
\begin{equation*} \begin{array}{rclcl} \text{Prover}(sk) &&&& \text{Verifier}(pk)\\[2mm] (I,st) \leftarrow P_1(sk) &\quad& \xrightarrow{\;I\;} &&\\[1mm] && \xleftarrow{\;r\;} &\quad& r \xleftarrow{\$} \Omega_{pk}\\[1mm] s \leftarrow P_2(sk,st,r) && \xrightarrow{\;s\;} && \text{accept iff } V(pk,r,s)=I. \end{array} \end{equation*}The three messages have the following roles.
- The prover computes a commitment \(I\) and retains private state \(st\). The word “commitment” is used informally here: the lecture had not yet introduced cryptographic commitment schemes, and \(I\) is not being claimed to satisfy a separate commitment definition.
- The verifier independently samples a random challenge \(r\in\Omega_{pk}\).
- The prover uses \(sk\), \(st\), and \(r\) to compute a response \(s\). Producing an acceptable response to a fresh challenge should be hard without the secret key.
Because the protocol is interactive, it is more natural to describe it by a message-flow diagram than as three completely independent algorithms. If desired, the verifier can also be split into a first algorithm that samples the challenge and a second algorithm that checks the response. The essential verification input consists of \(pk\), the original commitment \(I\), the challenge \(r\), and the response \(s\).
2.3. Correctness and public transcripts
Correctness requires that an honest prover is always accepted:
\[ \Pr\!\left[V(pk,r,s)=I \;\middle|\; (pk,sk)\leftarrow\mathsf{Gen}(1^\lambda), \text{ honest protocol run}\right]=1. \]
A public transcript is the complete sequence of values exchanged over the network:
\[ (I,r,s). \]
It does not include the secret key or the prover’s private state. An eavesdropper can observe this tuple. The lecture defines a randomized wrapper
\[ \mathsf{trans}(pk,sk) \]
that internally runs an honest prover and verifier and returns the resulting public transcript. This wrapper is introduced mainly to make the security experiment concise.
In response to a question, the lecturer stressed that the roles are named by their cryptographic functions, not by the application: the user proves knowledge and is therefore the prover, while the server checks the proof and is therefore the verifier. Another question compared this notion with a TLS transcript. The lecturer’s answer was explicitly tentative; the important course definition is simply that the identification transcript contains the publicly exchanged values \((I,r,s)\), not any secret internal state.
At this stage no digital signature is used. A signature can nevertheless give an identification protocol immediately: the server sends a fresh random challenge and the user signs it. This is a two-message challenge–response protocol. Passkeys were given as a practical example: a server sends a challenge, the user’s device signs it, and the signature is returned to the server. The purpose of the present development is to study identification more generally before returning from identification schemes to signatures.
3. Security of identification schemes
3.1. Passive observation followed by impersonation
The lecture defines security against an adversary that first passively observes honest protocol runs and then attempts one active impersonation. An intuitive example is an ISP that sees messages exchanged between a user and a service but does not modify them. After observing a polynomial number of valid executions, the ISP tries to authenticate to the service as that user.
The experiment \(\mathsf{Ident}_{\mathcal A}(\lambda)\) is:
The challenger generates
\[ (pk,sk)\leftarrow\mathsf{Gen}(1^\lambda) \]
and gives \(pk\) to the adversary \(\mathcal A\).
The adversary may request honest transcripts. Each query is answered with
\[ (I_j,r_j,s_j)\leftarrow\mathsf{trans}(pk,sk). \]
- To begin its impersonation attempt, \(\mathcal A\) sends a commitment \(I\) to the challenger.
The challenger samples a fresh challenge
\[ r\xleftarrow{\$}\Omega_{pk} \]
and sends it to \(\mathcal A\).
The adversary returns \(s\). The experiment outputs \(1\) exactly when
\[ V(pk,r,s)=I. \]
An identification scheme is secure if, for every PPT adversary \(\mathcal A\), there exists a negligible function \(\nu\) such that
\[ \Pr[\mathsf{Ident}_{\mathcal A}(\lambda)=1] \leq \nu(\lambda). \]
The learning phase is passive: the adversary receives complete honest transcripts rather than choosing messages inside those runs. Its final phase is active because it must interact with the verifier and answer a fresh challenge. The lecturer noted that this is not the most expressive identification-security definition possible, but it is sufficient for the construction and proof in this lecture.
4. Recap: the discrete-logarithm problem
Let \(\mathbb G\) be a cryptographic cyclic group of prime order \(p\), and let \(g\) be a generator. Although the group-generation algorithm is omitted from the notation, one should remember that cryptographic security uses an infinite family of groups indexed by the security parameter.
For
\[ x\xleftarrow{\$}\mathbb Z_p, \]
computing \(g^x\) is easy, while extracting \(x\) from \(g^x\) is conjectured to be hard. The discrete-logarithm assumption states that, for every PPT algorithm \(\mathcal A\),
\[ \Pr\!\left[\mathcal A(g^x)=x\right] \leq \operatorname{negl}(\lambda). \]
The generator \(g\) and the group description are public system parameters. They may be treated as globally fixed or explicitly included in the public key. This answers a question raised during the proof about how the reduction and the adversary know which generator is being used.
5. Schnorr’s identification scheme
5.1. Construction
Schnorr identification uses the same discrete-logarithm key structure already seen in Diffie–Hellman and ElGamal:
\[ x\xleftarrow{\$}\mathbb Z_p, \qquad y=g^x, \qquad sk=x, \qquad pk=y. \]
The interactive protocol is
\begin{equation*} \begin{array}{rclcl} \text{Prover}(x) &&&& \text{Verifier}(y)\\[2mm] k\xleftarrow{\$}\mathbb Z_p, \quad I=g^k && \xrightarrow{\;I\;} &&\\[1mm] && \xleftarrow{\;r\;} && r\xleftarrow{\$}\mathbb Z_p\\[1mm] s=(rx+k)\bmod p && \xrightarrow{\;s\;} && \text{accept iff }g^s y^{-r}=I. \end{array} \end{equation*}Here \(k\) is fresh prover randomness, \(I=g^k\) is the commitment, \(r\) is the verifier’s fresh challenge, and \(s\) is the response.
5.2. Correctness
For an honest prover,
\begin{equation*} \begin{aligned} g^s y^{-r} &=g^{rx+k}(g^x)^{-r}\\ &=g^{rx+k-rx}\\ &=g^k\\ &=I. \end{aligned} \end{equation*}All exponent arithmetic is modulo the group order \(p\). Thus an honest execution is accepted with probability \(1\).
5.3. Security theorem
The lecture states the following result.
Assume the discrete-logarithm assumption holds in \(\mathbb G\). Then Schnorr’s identification scheme is secure in the identification experiment defined above.
This is attractive because it relies on the basic discrete-logarithm assumption, rather than a stronger decisional assumption such as DDH. The proof uses two central techniques: transcript simulation and rewinding.
5.4. Simulating transcripts without the secret key
A reduction that receives a discrete-logarithm challenge \(y=g^\alpha\) does not know \(\alpha\). It therefore cannot answer transcript queries by honestly running the prover, since the original algorithm
\[ \mathsf{trans}(pk,sk) \]
requires the secret key. The first step is to replace it with an alternative simulator \(\mathsf{trans}'(pk)\) that needs only the public key.
The simulator works backwards:
\begin{equation*} \begin{array}{l} r\xleftarrow{\$}\mathbb Z_p,\\ s\xleftarrow{\$}\mathbb Z_p,\\ I\leftarrow g^s y^{-r},\\ \text{return }(I,r,s). \end{array} \end{equation*}The output is always accepted because \(I\) is defined to satisfy the verification equation. It also has the same distribution as an honest transcript. In an honest run,
\[ s=rx+k \pmod p. \]
For fixed \(r\) and \(x\), uniform \(k\) makes \(s\) uniform, and
\[ I=g^k=g^{s-rx}=g^s(g^x)^{-r}=g^s y^{-r}. \]
Consequently, the adversary cannot distinguish simulated transcript-oracle answers from honest ones.
This does not let an attacker impersonate the prover in a live run. The simulator chooses \(r\) and \(s\) first and defines \(I\) afterwards. In a real interaction, the attacker must send \(I\) before learning the verifier’s random challenge \(r\). Once \(I\) has been sent, the attacker cannot go backwards and change it to fit the newly received challenge. This ordering is precisely why the first message is called a commitment in the protocol.
5.5. Rewinding and extraction of the discrete logarithm
Suppose an impersonator \(\mathcal A\) succeeds with non-negligible probability. The reduction receives a discrete-logarithm instance
\[ (g,y=g^\alpha) \]
and must recover \(\alpha\). It sets the identification public key to \(y\), answers all transcript requests using \(\mathsf{trans}'(y)\), and waits for \(\mathcal A\) to send its final commitment \(I\).
At this point the reduction saves the entire state of the adversary. This is the rewinding step: one may imagine running the adversary inside a virtual machine, taking a snapshot immediately after \(I\) has been sent, and later returning to that identical snapshot.
From the saved state, the reduction performs two continuations:
\[ (I,r_0,s_0) \qquad\text{and}\qquad (I,r_1,s_1), \]
where \(r_0\neq r_1\), and both transcripts are accepting. The commitment \(I\) is identical because both continuations start from the same saved state, but the challenges are different.
Acceptance gives
\[ g^{s_0}y^{-r_0}=I=g^{s_1}y^{-r_1}. \]
Rearranging,
\[ y^{r_1-r_0}=g^{s_1-s_0}. \]
Because \(p\) is prime and \(r_1-r_0\neq0\pmod p\), the difference has a multiplicative inverse in \(\mathbb Z_p\). Raising both sides to \((r_1-r_0)^{-1}\) yields
\[ y =g^{(s_1-s_0)(r_1-r_0)^{-1}}. \]
Since \(y=g^\alpha\), the reduction extracts
\[ \boxed{ \alpha=(s_1-s_0)(r_1-r_0)^{-1}\bmod p }. \]
Thus, two accepting responses to different challenges for the same commitment reveal the secret exponent. If the adversary’s success probability is non-negligible rather than \(1\), the reduction tests whether a response verifies and repeats or rewinds until it obtains two accepting continuations. Non-negligible success means that only polynomially many attempts are required in the proof sketch. For example, if the success probability were \(1/q\) for a polynomial \(q\), a polynomial number of repetitions would suffice in expectation. The challenges can be sampled subject to \(r_0\neq r_1\).
This establishes the contradiction: a successful efficient impersonator would give an efficient algorithm for discrete logarithms.
6. From identification to signatures
6.1. The direction from signatures to identification
A signature scheme immediately yields identification by challenge–response. The verifier sends a fresh random challenge \(r\), and the prover returns a signature on \(r\). Anyone with the verification key can check the response, while only the holder of the signing key should be able to generate it.
The converse direction is less immediate. If an identification protocol can be made non-interactive, then a prover could produce evidence of knowing the secret key without first contacting a particular verifier. If a message is bound into that evidence, the result behaves like a signature.
6.2. Why allowing the prover to choose the challenge is insecure
A tempting way to remove the verifier’s message is to let the prover choose the challenge \(r\). For Schnorr identification this is insecure. A cheating prover can choose arbitrary \(r,s\in\mathbb Z_p\) and set
\[ I=g^s y^{-r}. \]
The tuple \((I,r,s)\) then passes verification even though the prover need not know the secret exponent. This is exactly the transcript simulator from the security proof. It is safe for simulating already completed public transcripts, but unsafe as an authentication strategy when the prover controls the challenge.
6.3. The Fiat–Shamir idea
Fiat and Shamir proposed deriving the challenge deterministically from the commitment:
\[ r=H(I). \]
To obtain a signature on a message \(m\), the message is included as well:
\[ r=H(I,m). \]
If \(H\) is modeled as a random oracle, its output on each fresh input \((I,m)\) is unpredictable. The signer must first determine \(I\) before it can learn the associated challenge \(r\), recreating the crucial order of the interactive protocol without requiring a verifier to send a message. Binding \(m\) into the challenge also makes the resulting proof refer to that particular message.
7. The generic Fiat–Shamir transform
Let \((\mathsf{Gen},P_1,P_2,V)\) be a three-move, public-coin identification scheme whose verifier samples a uniform challenge from \(\Omega_{pk}\). Let
\[ H:\{0,1\}^*\longrightarrow\Omega_{pk} \]
be a hash function. The Fiat–Shamir signature scheme \((\mathsf{Gen}',\mathsf{Sign}',\mathsf{Verify}')\) is defined as follows.
7.1. Key generation
Run the identification scheme’s key generator:
\[ (pk,sk)\leftarrow\mathsf{Gen}(1^\lambda). \]
Use \(vk=pk\) as the signature verification key and retain the same \(sk\) as the signing key.
7.2. Signing
To sign \(m\):
\begin{equation*} \begin{aligned} (I,st)&\leftarrow P_1(sk),\\ r&\leftarrow H(I,m),\\ s&\leftarrow P_2(sk,st,r),\\ \sigma&\leftarrow(I,r,s). \end{aligned} \end{equation*}The signature is therefore a complete transcript, except that the challenge is computed locally from \(I\) and \(m\) rather than sampled and sent by an interactive verifier.
7.3. Verification
Given \(vk=pk\), \(m\), and \(\sigma=(I,r,s)\), output \(1\) exactly when both
\[ V(pk,r,s)=I \]
and
\[ r=H(I,m) \]
hold. The second check is essential. Without it, an attacker could simply run the backwards transcript simulator and choose \(r,s\) before constructing \(I\).
The transform requires the verifier’s challenge in the original protocol to be fresh public randomness. If challenge generation depends on a verifier secret or has some additional hidden structure, it cannot simply be replaced by the public hash value above.
The lecture states, without proving, the following theorem:
If the identification scheme is secure and \(H\) is modeled as a random oracle, then its Fiat–Shamir transform is an EUF-CMA-secure signature scheme.
Thus the proof is in the random-oracle model. In practice, a concrete cryptographic hash function is used and is assumed to provide the required unpredictability for fresh inputs.
8. The Schnorr signature scheme
Applying the Fiat–Shamir transform to Schnorr identification gives the Schnorr signature scheme.
Let \(\mathbb G\) have prime order \(p\) and generator \(g\), and let
\[ H:\{0,1\}^*\longrightarrow\mathbb Z_p. \]
8.1. Key generation
\[ x\xleftarrow{\$}\mathbb Z_p, \qquad y=g^x, \qquad sk=x, \qquad vk=y. \]
8.2. Signing
To sign \(m\), choose fresh randomness \(k\) and compute
\begin{equation*} \begin{aligned} k&\xleftarrow{\$}\mathbb Z_p,\\ I&=g^k,\\ r&=H(I,m),\\ s&=(rx+k)\bmod p. \end{aligned} \end{equation*}The generic transform would output \((I,r,s)\), but the optimized Schnorr signature omits \(I\):
\[ \sigma=(r,s). \]
8.3. Verification and reconstruction of the commitment
Given \(y,m,\sigma=(r,s)\), compute
\[ I'=g^s y^{-r} \]
and accept exactly when
\[ r=H(I',m). \]
For an honestly generated signature,
\[ I'=g^{rx+k}(g^x)^{-r}=g^k=I, \]
so the hash check succeeds.
The omission of \(I\) is a scheme-specific optimization. In a black-box use of Fiat–Shamir, the verifier generally needs the complete transcript \((I,r,s)\). Schnorr verification, however, can reconstruct the only candidate commitment compatible with \(y,r,s\), and the hash equation then checks that this candidate is the commitment from which \(r\) was derived.
This mattered greatly for signature size. In a traditional finite-field instantiation, a group element could occupy roughly \(2048\) bits, while the two scalars \(r\) and \(s\) together occupy roughly \(500\) bits. Including \(I\) would make the result at least as large as the old RSA signatures the scheme was meant to improve upon. Omitting it gives a signature roughly four times smaller in the lecture’s historical comparison.
For a standard elliptic-curve realization, the slides quoted the following representative figures:
- signing key: \(256\) bits (\(32\) bytes);
- verification key: \(256\) bits (\(32\) bytes);
- signature: \(512\) bits (\(64\) bytes);
- signing cost: one group exponentiation/scalar multiplication;
- verification cost: two group exponentiations/scalar multiplications.
The group, its order, and its generator are normally fixed public parameters. The slides cited Ed25519 as an example of a fast elliptic-curve setting related to this Schnorr-style design. The lecture characterized Schnorr signatures as especially short and efficient when instantiated with standard elliptic-curve groups.
9. Historical and practical remarks about Schnorr signatures
Claus-Peter Schnorr designed the scheme with constrained devices such as smart cards in mind; the lecturer also noted Schnorr’s connection with Saarland University. The construction was efficient because signing requires only the single exponentiation \(g^k\), while verification requires two exponentiations.
However, Schnorr patented the construction. The patent discouraged broad standardization and deployment even though the scheme had an attractive security proof and performance profile. The United States standardization process developed DSA as a sufficiently different construction that avoided the Schnorr patent. The patent later expired, around 2010, allowing wider use of Schnorr-style signatures.
The lecturer mentioned several consequences in practice. Cryptocurrency systems have moved or are moving from ECDSA toward Schnorr signatures. Modern elliptic-curve variants such as EdDSA/Ed25519 are fast and designed with useful side-channel protections, and such algorithms are available in protocols and tools such as TLS and SSH. At the same time, long-lived certified hardware often implements only older algorithms such as ECDSA. The European Digital Identity Wallet was given as an example where legacy certified chips and limited algorithm support complicate deployment.
The broader engineering lesson was about cryptographic agility and intellectual property. A strong algorithm may fail to achieve adoption if legal restrictions push standards and hardware toward an alternative. Once old hardware has been manufactured and security-certified, replacing its cryptographic algorithms is difficult. The lecturer suggested that publishing a construction and building expertise around it may lead to wider and longer-lasting impact than restricting it through a patent.
The lecture also contrasted the clean security story of Schnorr with DSA. The Schnorr scheme presented here follows from a secure identification scheme and Fiat–Shamir in the random-oracle model, ultimately connecting security to the discrete-logarithm assumption. For DSA, the lecture did not present an analogous clean reduction from discrete logarithms and described its theoretical security justification as less satisfactory, even though DSA and ECDSA have been used extensively in practice.
10. The Digital Signature Algorithm (DSA)
10.1. Group notation
The lecture uses a group \(\mathbb G\) of prime order \(p\) with generator \(g\). For a concrete finite-field instantiation, \(\mathbb G\) can be a subgroup of the multiplicative group modulo another prime \(q\):
\begin{equation*} \mathbb G\subseteq\mathbb Z_q^*, \qquad |\mathbb G|=p. \end{equation*}The two primes serve different purposes:
- \(q\) is the modulus used to represent and multiply group elements;
- \(p\) is the order of the subgroup and therefore the modulus for exponents.
For example, one may use related primes satisfying \(q=2p+1\). The lecture’s notation places \(p\) in the role of the subgroup order and \(q\) in the role of the finite-field modulus; some external descriptions of DSA use different letter conventions.
When the lecture writes \(g^k\), exponentiation is performed in \(\mathbb G\), so the resulting group element is represented by an integer modulo \(q\). DSA then maps that representative into \(\mathbb Z_p\) by applying another reduction modulo \(p\). It is useful to make this map explicit:
\[ \rho(z)=z\bmod p. \]
The hash function used for messages is written as
\[ H:\{0,1\}^*\longrightarrow\mathbb Z_p. \]
10.2. Key generation
As in Schnorr,
\[ x\xleftarrow{\$}\mathbb Z_p, \qquad y=g^x, \qquad sk=x, \qquad vk=y. \]
10.3. Signing
To sign \(m\), choose a fresh invertible nonce \(k\in\mathbb Z_p^*\). First compute a group element and then map it to the scalar space:
\[ r=\rho(g^k)=(g^k\text{ in }\mathbb G)\bmod p. \]
Then compute
\[ s=k^{-1}\bigl(H(m)+xr\bigr)\bmod p. \]
If \(r=0\) or \(s=0\), restart with fresh \(k\). The signature is
\[ \sigma=(r,s). \]
The two stages in the computation of \(r\) are important. First \(g^k\) is computed as a group element, using multiplication modulo \(q\). Only afterwards is its integer representative reduced modulo the subgroup order \(p\). In the lecturer’s terminology, this moves a value from the group-element space into the exponent space.
10.4. Verification
Given \(y,m,(r,s)\), first reject if \(r=0\) or \(s=0\). Otherwise compute in \(\mathbb Z_p\)
\[ w=s^{-1}, \qquad u_1=H(m)w, \qquad u_2=rw. \]
Then compute the group element
\[ g^{u_1}y^{u_2}\in\mathbb G \]
and map it to \(\mathbb Z_p\):
\[ v=\rho\!\left(g^{H(m)s^{-1}}y^{rs^{-1}}\right). \]
Accept if and only if
\[ v=r. \]
10.5. Correctness
Using \(y=g^x\), the group element computed by the verifier is
\begin{equation*} \begin{aligned} g^{H(m)s^{-1}}y^{rs^{-1}} &=g^{H(m)s^{-1}}(g^x)^{rs^{-1}}\\ &=g^{(H(m)+xr)s^{-1}}. \end{aligned} \end{equation*}Signing defined
\[ s=k^{-1}(H(m)+xr)\pmod p, \]
so
\[ s^{-1}=k(H(m)+xr)^{-1}\pmod p. \]
Consequently,
\[ (H(m)+xr)s^{-1}=k\pmod p \]
and therefore
\[ g^{H(m)s^{-1}}y^{rs^{-1}}=g^k. \]
Applying the same map \(\rho\) used during signing gives
\[ v=\rho(g^k)=r. \]
Thus every honestly generated nonzero signature verifies.
10.6. Comparison with Schnorr
The two schemes use the same public key \(y=g^x\) and both output two scalars, but their signing equations differ substantially.
Schnorr computes
\[ r=H(g^k,m), \qquad s=k+xr\pmod p. \]
DSA computes
\[ r=\rho(g^k), \qquad s=k^{-1}(H(m)+xr)\pmod p. \]
In Schnorr, the commitment and message are hashed together to create the challenge. In DSA, only the message is hashed in the displayed signing equation, the commitment is mapped to \(r\) by reduction modulo \(p\), and the entire sum is multiplied by \(k^{-1}\). The lecturer described this more contrived structure as the change that allowed DSA to avoid the Schnorr patent.
ECDSA is the elliptic-curve version of DSA. The high-level equations are analogous, but an elliptic-curve group element is a point rather than an integer modulo \(q\). Therefore the operation that extracts the scalar \(r\) from \(kG\) is defined through a coordinate of the point rather than by directly reducing an integer group element as above. The lecture did not develop the elliptic-curve details.
11. Final perspective
The toy password example at the start is not meant to describe every detail of modern authentication. Real access-control systems are much more elaborate. Nevertheless, the central cryptographic idea remains important: a user should be able to prove possession of a private key corresponding to a registered public key.
The lecturer was not aware of a major modern deployment using the original three-message Schnorr identification protocol directly. A signature-based challenge–response mechanism needs only the server’s challenge and the user’s signature response, so it is often more convenient; passkeys are the motivating example. The three-move scheme remains valuable conceptually and modularly:
\begin{equation*} \boxed{ \begin{array}{c} \text{Schnorr identification}\\ +\\ \text{Fiat--Shamir transform in the random-oracle model} \end{array} \Longrightarrow \text{Schnorr signatures.} } \end{equation*}The lecture’s main conclusions are:
- Naive reusable password authenticators are vulnerable to replay.
- Identification schemes formalize interactive proof of secret-key possession.
- Schnorr identification is secure under the discrete-logarithm assumption; transcript simulation and rewinding explain the reduction.
- Signatures immediately give identification via challenge–response.
- A public-coin three-move identification scheme can be made non-interactive through Fiat–Shamir, with security proved in the random-oracle model.
- Applying Fiat–Shamir to Schnorr identification produces a short and efficient EUF-CMA-secure signature scheme.
- Patent restrictions historically impeded Schnorr adoption and motivated the standardization of the structurally more complicated DSA scheme.
- ECDSA carries the DSA design into elliptic-curve groups, while modern systems increasingly make use of Schnorr-style alternatives.