← Entropy Atlas
Secret & unpredictable
Signature nonces
Some signature schemes use a one-time secret number for each message.
Evaluation card
What “plenty” means here.
- Required property
- A unique, secret, correctly distributed nonce—or a vetted deterministic derivation tied to the key and message.
- If it fails
- A repeated, biased, or partially leaked nonce can reveal the long-term signing key.
- Relevant attacker
- Anyone collecting signatures and exploiting correlations or repeated nonce values.
- The Plenty Line
- Use the signature standard’s deterministic procedure or a vetted CSPRNG at the scheme’s security strength.
- Why more is not automatically better
- Oversized randomness is not a substitute for correct modular sampling and strict non-reuse.
Where it appears
Recognize the pattern.
- 01ECDSA per-message values
- 02DSA nonces
- 03blinded or hedged signature generation
The Plentropy rule
Protect the requirement, then stop.
Use the signature standard’s deterministic procedure or a vetted CSPRNG at the scheme’s security strength.
Once that claim has comfortable evidence and margin, improve the next limiting factor instead of worshipping a larger entropy number.