On Sun, Feb 8, 2015 at 10:08 PM, Trevor Perrin <tr...@trevp.net> wrote:
>
> Setting M == N is easy - Mike Scott proposed it in 2001 [1], and
> Kobara/Imai published a proof in 2003 [2].  So that simplifies the
> protocol, and seems adequate for the "simultaneous initiate" case
> (Pond, Petmail, 802.11S).

Oops, missing references:

[1] https://groups.google.com/forum/#!msg/sci.crypt/4Rie3Yd64BI/H0wSm7m6xxAJ
[2] http://eprint.iacr.org/2003/038.pdf
_______________________________________________
Curves mailing list
Curves@moderncrypto.org
https://moderncrypto.org/mailman/listinfo/curves

Reply via email to