Re: A Method of Session Key Generation

New Message Reply About this list Date view Thread view Subject view Author view

bram (bram@gawth.com)
Thu, 28 Jan 1999 15:54:57 -0800 (PST)


A certain person who obviously hasn't been paying attention asked about
session key generation.

The answer is use a CSPRNG. This has been discussed here a *lot* already.

There's a more subtle problem of what to do when your counterparty doesn't
trust you to have a good source of entropy. That problem can be fixed by
having certificates from third parties saying 'I gave some random bits to
party x at time y using his public key'. The exact details of what sets of
such certificates are acceptable to begin a session are, of course, an
implementation problem, but a very non-trivial one.

-Bram


New Message Reply About this list Date view Thread view Subject view Author view

 
All trademarks and copyrights are the property of their respective owners.

Other Directory Sites: SeekWonder | Directory Owners Forum

The following archive was created by hippie-mail 7.98617-22 on Sat Apr 10 1999 - 01:18:06