[noise] XEdDSA and Noise

Jason A. Donenfeld Jason at zx2c4.com
Tue Oct 25 14:05:26 PDT 2016


On Oct 26, 2016 5:50 AM, "Trevor Perrin" <trevp at trevp.net> wrote:
> I don't have an immediate use case for this

dhss could be replaced with sig in some patterns. I think an advantage of
this might be avoiding KCI to the responder prior to the initiator's first
transport message providing confirmation (per KEA+C).

One usage of this that comes to mind is taking care of the TODO in
add_new_keypair: https://git.zx2c4.com/WireGuard/tree/src/noise.c#n113

OTOH, I really really like the simplicity of signature-less noise.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20161026/180c720c/attachment.html>


More information about the Noise mailing list