Why does a same transaction signed separately have different witness values?



I signed a bitcoin testnet transaction using nbitcoin library and got an output:


then I signed the same transaction with bitcoin-core and it returned an output :


On comparing the outputs, the txwitness stack value differs.

bitcoin-core witness data

"txinwitness": [

nBitcoin witness data

 "txinwitness": [

But still, I'm able to send the transaction signed by nBitcoin.

So my questions are:

1) what are the values in witness stack?

2) why the same transaction have different txwitness value?

Akshay Dev

Posted 2019-12-18T07:42:17.553

Reputation: 65



Bitcoin signatures have two components: s and R. To sign a Bitcoin transaction with private key k, the signing algorithm generates an ephemeral private key r. The R component of the signature is the x-coordinate of that ephemeral public key. The s component of the signature is calculated in the following way: s = r-1 (Hash(m) + k * R) mod p; where Hash(m) is the hash of the transaction data m.

Since, s changes with r, as shown in the equation above, the signature component will be completely different when you compare two transactions signed if their ephemeral key generation algorithm differs.

Most softwares uses RFC 6979 to deterministically but securely generate the ephemeral key used to sign transactions. So for two identical transactions, the ephemeral key should be the same and that is the reason you are seeing the same signatures on different Bitcoin Core software. However, RFC 6979 algorithm also allows the usage of other additional optional data while generating the ephemeral key. This additional optional data might be different for different softwares and as a result you are seeing different (s,R) signature from Bitcoin-Core and nBitcoin.

Ugam Kamat

Posted 2019-12-18T07:42:17.553

Reputation: 6 378

What is P in this equation s = r-1 (Hash(m) + k * R) mod p ? – Akshay Dev – 2019-12-18T11:10:51.823

If S changes with R, why bitcoin core, even on different machines produce the same signature? – Akshay Dev – 2019-12-18T11:12:47.777

1@AkshayDev I have updated my answer to make it more clear. The mod p (modulo prime number p) indicates that the Bitcoin curve (secp256k1) is over a finite field of prime order p. – Ugam Kamat – 2019-12-18T12:54:09.280