[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Some comments on JFK
Radia Perlman - Boston Center for Networking writes:
> EKR said:
> >> (1) In message 1 the initiator sends g^i. This is replayed in message
> >> 3. I see why the initiator needs to tell the responder the group he
> >> wants to use but why does it need to communicate g^i? If you simply
> >> want the initiator to commit to g^i, why not use a hash? This would
> >> save some bandwidth, which is always nice :)
>
> If g^i is in message
> 1 it gives Bob the option of getting going on his Diffie-Hellman
> calculation if he was willing to
> not be stateless and computeless.
Right, and this goes well with my "average
case" mantra which is that you're normally not
going to be under attack, so it would be nice
eliminate its overhead when you're not hurting.
TCP-SYN cookies work the same way.
Mike
References: