[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Some comments on JFK



Radia Perlman - Boston Center for Networking writes:
 > EKR said:
 > >>	(1) In message 1 the initiator sends g^i. This is replayed in message
 > >>	3. I see why the initiator needs to tell the responder the group he
 > >>	wants to use but why does it need to communicate g^i? If you simply
 > >>	want the initiator to commit to g^i, why not use a hash? This would
 > >>	save some bandwidth, which is always nice :)
 > 
 > If g^i is in message
 > 1 it gives Bob the option of getting going on his Diffie-Hellman
 > calculation if he was willing to
 > not be stateless and computeless.

   Right, and this goes well with my "average
   case" mantra which is that you're normally not
   going to be under attack, so it would be nice
   eliminate its overhead when you're not hurting.
   TCP-SYN cookies work the same way.

		Mike


References: