SIGN IN SIGN UP

Every classical signer now assembles the signature component s through the constant-time BigIntegers.modMult, modAdd and the new modSubtract rather than BigInteger.multiply and mod, whose cost follows the quotient and which were being handed the signing key, covering ECDSA, SM2, DSA, GOST 3410, ECGOST 3410, DSTU 4145, EC-NR and BIP 340, with the public hash-derived value reduced on the way in wherever it could sit at or past the order, DSAPrivateKeyParameters and GOST3410PrivateKeyParameters now holding x to the [1, q-1] their own parameters imply, and the two GOST signers redrawing a nonce that is zero or at or past the order rather than leaving it to be folded by the reduction that followed.

D
David Hook committed
a2194423202b894946a4f6ebfdfa4bc4cef80b58
Parent: acd2178