Re: [openscreenprotocol] [Auth] Symmetric vs Asymmetric (#110)

We investigated using PSK with TLS 1.3 and decided it wasn't suitable for this application.  The current authentication proposal (in Section 8) is a mutual authentication handshake that generates a shared secred for symmetric encryption based on an ephemeral passcode that the human user must convey from one agent to the other.  I believe that is similar to your "Symmetric" scenario above.

@pthatcherg is working on the details of the authentication protocol and may be able to offer more detailed thoughts.


-- 
GitHub Notification of comment by mfoltzgoogle
Please view or discuss this issue at https://github.com/webscreens/openscreenprotocol/issues/110#issuecomment-488852108 using your GitHub account

Received on Thursday, 2 May 2019 22:17:25 UTC