On 28 March 2017 at 10:48, Scott Fluhrer (sfluhrer) <sfluh...@cisco.com> wrote: > The server recovers E_K(R) because the client sent it (along with i and the > protected message). It recovers R because it also knows K.
So E_K(R) is sent directly? That would link packets. _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls