I'm going to be a little pedantic here: the trick of using a PRF (hashing with a secret) to obtain the DSA nonce was not invented by Dan Bernstein. In the Ed25519 paper it's attributed to George Barwood and John Wigley in 1997. Also published in [2] around the same time.

[1] http://ed25519.cr.yp.to/ed25519-20110926.pdf

[2] http://www.di.ens.fr/~pointche/Documents/Papers/1998_sac.pdf

That's not being pedantic, that's helpfully pointing out a fairly serious attribution error. Thanks! I will fix it.

