[Cryptography] "Incremental" DH Key exchange ??

Henry Baker hbaker1 at pipeline.com
Wed Aug 22 10:03:37 EDT 2018


Suppose that there's essentially no latency and
that messages are extremely cheap (relative to
everything else), so we're no longer trying to
minimize round-trips during a key exchange.

I'm wondering if there's a DH-type of key exchange
which "incrementalizes" the key exchange to develop
a shared secret a few bits at a time.

My analogy/intuition here is a Newton-type iteration
that doubles the number of shared secret bits on
every iteration.

I've heard of "amplification", but don't really
understand it.  Is that a possible direction to
look?



More information about the cryptography mailing list