[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Some comments on JFK



EKR said:
>>	(1) In message 1 the initiator sends g^i. This is replayed in message
>>	3. I see why the initiator needs to tell the responder the group he
>>	wants to use but why does it need to communicate g^i? If you simply
>>	want the initiator to commit to g^i, why not use a hash? This would
>>	save some bandwidth, which is always nice :)

If g^i is in message
1 it gives Bob the option of getting going on his Diffie-Hellman
calculation if he was willing to
not be stateless and computeless.

Radia



Follow-Ups: