3 ms·
To make it a little more fixed-size and built of known primitives, what about just signing a mutated hash of the content a la HMAC?
by spb 11y ago
To make it a little more fixed-size and built of known primitives, what about just signing a mutated hash of the content a la HMAC?
- BoppreH 11y agoLike this? Server: server_nonce Client: random_key + sign(hmac(server_nonce, random_key)) That's a nice alternative. Though generating random data and XOR'ing is as known and as primitive as you can get, and none of it is ever reused, so I have no preferences of one over the other. (if you are thinking "why not just sign the hash of the nonce without bothering with a key?", that's exactly how we sign documents, because they are long. You could sign the hash of the hash to avoid this conflict, but that's a hack)