3 ms·
>That proof can in theory be tied to a particular message. It's a good point that a signature is needed, so code is not simpler. But it can't be tied cryptogr
by Buge 6y ago
>That proof can in theory be tied to a particular message.
It's a good point that a signature is needed, so code is not simpler.
But it can't be tied cryptographically to a particular message. The DH generates a shared key, and the signature proves that a DH exchange happened. But the signature proves nothing about the message, the signature isn't over the message. The receiver has access to the shared key and thus can forge messages.
- loup-vaillant 6y ago> > That proof can in theory be tied to a particular message. > It's a good point that a signature is needed, so code is not simpler. A common misconception. One that I would forgive, if I didn't already linked to a counter-example in this very thread: https://noiseprotocol.org https://noiseprotocol.org Noise protocols don't use signatures. Their existence proves beyond the shadow of a doubt that mutual authentication can be achieved without signatures. Here's an example: Before the protocol ------------------- sa : Alice's private key SA : Alice's public key (known to Bob) sb : Bob's private key SB : Bob's public key (know to Alice) Protocol -------- Alice: ea = random EA = public_key(ea) send -> EA, SA Bob: eb = random EB = public_key(eb) send -> EB, SB Alice: verifies that SB is indeed Bob's key ee = DH(ea, EB) es = DH(ea, SB) se = DH(sa, EB) key = HASH(ee, es, se) Bob: verifies that SA is indeed Alice's key ee = DH(eb, EA) es = DH(sb, EA) se = DH(eb, SA) key = HASH(ee, es, se) At this point, Alice and Bob have a mutually authenticated, secret, shared session key. We only needed key exchange (and hashing) to achieve that. Now if you need a public key infrastructure, that's another matter. Stuff like certificate does require signatures. But that's a separate matter from the protocol itself, which can verify the trustworthiness of a key buy a simple lookup. For instance, an IoT device can hold a copy of its Company's public key. Or, Alice and Bob could have met in a crypto party.