On Sun, Feb 8, 2015 at 10:08 PM, Trevor Perrin <tr...@trevp.net> wrote: > > Setting M == N is easy - Mike Scott proposed it in 2001 [1], and > Kobara/Imai published a proof in 2003 [2]. So that simplifies the > protocol, and seems adequate for the "simultaneous initiate" case > (Pond, Petmail, 802.11S).
Oops, missing references: [1] https://groups.google.com/forum/#!msg/sci.crypt/4Rie3Yd64BI/H0wSm7m6xxAJ [2] http://eprint.iacr.org/2003/038.pdf _______________________________________________ Curves mailing list Curves@moderncrypto.org https://moderncrypto.org/mailman/listinfo/curves