[noise] Noise_XR

Trevor Perrin trevp at trevp.net
Wed May 11 21:34:44 PDT 2016


I added this pattern because I thought it was a nice demonstration of
flexibility that we could do the equivalent of SIGMA-I and SIGMA-R:

https://www.iacr.org/archive/crypto2003/27290399/27290399.ps

On further thought, XR and SIGMA-R aren't that useful.  They're almost
the same as if the initiator just asked the responder to initiate an
XX handshake.

There's a slight difference, in that the first response message can be
encrypted (to an unknown party, with no authentication).  But that
doesn't seem useful enough to be making this one of the initial main
patterns.

So my current thought is to simplify and remove it, and return to just
12 basic interactive patterns.

Trevor


More information about the Noise mailing list