The freshness requirement without the safety requirement is trivial in RSA -- let Scott choose the public exponent.
No, probably not sufficient for anyone's real needs. At the other extreme, you could go all the way to a Frankel-style shared key generation protocol, and let Scott give Alice his half afterward. Has anyone publicly implemented shared key & signature generation or Frankel, Gemmell, MacKenzie and Yung, 1997, "Proactive RSA"? --------------------------------------------------------------------- The Cryptography Mailing List Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]
