On Fri, May 06, 2011 at 10:50:05AM -0400, Nick Mathewson wrote:
Crypto people who have been following threads about the circuit-establishment handshake will be interested in the new paper, "Anonymity and one-way authentication in key-exchange protocols", by Goldberg, Stebila, and Ostaoglu. Here's the version they updated today:
http://www.cacr.math.uwaterloo.ca/techreports/2011/cacr2011-11.pdf
If we're moving to an improved handshake, this might be a good candidate to consider. The protocol itself is on page 14.
FYI: it's now been accepted to the Designs, Codes, and Cryptography jounral:
http://www.springerlink.com/content/nl86n0u547873001/
(The above cacr link has also been updated to the latest version.)
- Ian