Open bhess opened 3 years ago
IMHO, from practical point of view, a construct like
K = KDF (SS1 || SS2 || ... || SSn)
is hard to beat, both security-wise and simplicity-wise. I don't think we need anything more elaborated, though a few details should be written down, like fixed length of each shared secret.
Follow-up after #16: