ffgg
- Protocol where A is the initiator and B is the responder, and
N1 and N2 are uniquely originating:
- A->B: A
- B->A: B, N1, N2
- A->B: A, {N1, N2, M}pub(B)
%{N1, X, Y}pub(B)
- B->A: B, N1, X, {X, Y,
N1}pub(B)
- Point of view: responder with M uniquely originating, privk(B)
non-originating, and a listener for M