Nonce Reuse
Nonce Reuse: Repeated use of a one-time value, disclosing plaintexts or private keys depending on the scheme. A nonceNonceA value intended for use only once in a cryptographic context. is unique by definition — repetition is not a quality issue but a complete break.
How it works and where it fits
In signature schemes such as DSA and ECDSA, every signature consumes a secret random value k. Two signatures using the same k are recognisable by an identical signature component r. The two equations allow k to be eliminated and the private key to be computed in closed form — no brute force, pure algebra. In authenticated encryption such as AES-GCM, a repeated nonce causes keystream reuseKeystream ReuseReusing the same keystream, making the encrypted messages recoverable. and additionally enables forging authentication tags.
Practical security relevance
In practice, repeats arise from weak entropy at boot, cloned virtual machines, hard-coded test values, or fallback processes such as emergency signing stations. Effective measures are deterministic nonce derivation per RFC 6979, vetted entropy sources, and monitoring published signatures for repeated r values. Because signatures are often public, the scheme conveniently ships its own evidence.
Related concepts
- NonceNonceA value intended for use only once in a cryptographic context.: A value intended for use only once in a cryptographic context.
- Keystream ReuseKeystream ReuseReusing the same keystream, making the encrypted messages recoverable.: Reusing the same keystream, making the encrypted messages recoverable.
- Digital SignatureDigital SignatureCryptographic proof of the authenticity and integrity of digital data.: Cryptographic proof of the authenticity and integrity of digital data.
- Elliptic Curve CryptographyElliptic Curve CryptographyCryptography based on elliptic curves using comparatively short keys.: Cryptography based on elliptic curves using comparatively short keys.