Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
Menu
Open sidebar
matrix-org
Olm
Commits
930c4677
Commit
930c4677
authored
Nov 08, 2019
by
Richard van der Hoff
Browse files
Update signing.md to use operatorname
parent
04690658
Changes
1
Hide whitespace changes
Inline
Side-by-side
docs/signing.md
View file @
930c4677
...
...
@@ -49,9 +49,9 @@ compromised keys, and sends a pre-key message using a shared secret $`S`$,
where:
```
math
S = ECDH\left(I_A,E_E\right)\;\parallel\;
ECDH\left(E_A,I_B\right)\;\parallel\;
ECDH\left(E_A,E_E\right)
S =
\operatorname{
ECDH
}
\left(I_A,E_E\right)\;\parallel\;
\operatorname{
ECDH
}
\left(E_A,I_B\right)\;\parallel\;
\operatorname{
ECDH
}
\left(E_A,E_E\right)
```
Eve cannot decrypt the message because she does not have the private parts of
...
...
@@ -67,9 +67,9 @@ On the other hand, signing the one-time keys leads to a reduction in
deniability. Recall that the shared secret is calculated as follows:
```
math
S = ECDH\left(I_A,E_B\right)\;\parallel\;
ECDH\left(E_A,I_B\right)\;\parallel\;
ECDH\left(E_A,E_B\right)
S =
\operatorname{
ECDH
}
\left(I_A,E_B\right)\;\parallel\;
\operatorname{
ECDH
}
\left(E_A,I_B\right)\;\parallel\;
\operatorname{
ECDH
}
\left(E_A,E_B\right)
```
If keys are unsigned, a forger can make up values of $
`E_A`
$ and
...
...
@@ -82,7 +82,7 @@ a conversation between the two of them, rather than constructed by a forger.
If $
`E_B`
$ is signed, it is no longer possible to construct arbitrary
transcripts. Given a transcript and Alice and Bob's identity keys, we can now
show that at least one of Alice or Bob was involved in the conversation,
because the ability to calculate $
`ECDH\left(I_A,
\,
E_B\right)`
$ requires
because the ability to calculate $
`
\operatorname{
ECDH
}
\left(I_A,E_B\right)`
$ requires
knowledge of the private parts of either $
`I_A`
$ (proving Alice's
involvement) or $
`E_B`
$ (proving Bob's involvement, via the
signature). Note that it remains impossible to show that
*both*
Alice and Bob
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment