Open indomitableSwan opened 1 year ago
Instead of using a global oprf_seed in OPAQUE, the server should first pick a per-user seed, user_seed, and then derive the per-user OPAQUE oprf seed from user_seed plus a domain separator.
oprf_seed
user_seed
Instead of using a global
oprf_seed
in OPAQUE, the server should first pick a per-user seed,user_seed
, and then derive the per-user OPAQUE oprf seed fromuser_seed
plus a domain separator.