Sorry, I wasn't aware that unlinkability was a requirement...
> -----Original Message----- > From: Martin Thomson [mailto:[email protected]] > Sent: Tuesday, March 28, 2017 11:51 AM > To: Scott Fluhrer (sfluhrer) > Cc: <[email protected]> > Subject: Re: [TLS] The alternative idea I had for token buckets. > > On 28 March 2017 at 10:48, Scott Fluhrer (sfluhrer) <[email protected]> > wrote: > > The server recovers E_K(R) because the client sent it (along with i and the > protected message). It recovers R because it also knows K. > > So E_K(R) is sent directly? That would link packets. _______________________________________________ TLS mailing list [email protected] https://www.ietf.org/mailman/listinfo/tls
