EDHOC compresses authenticated key exchange into three concise CBOR messages. Its efficiency still depends on exact transcript bytes, credential profiles and state transitions.


EDHOC compresses authenticated key exchange into three concise CBOR messages. Its efficiency still depends on exact transcript bytes, credential profiles and state transitions.

Key transparency gives public-key distribution a consistent, auditable history. Its proofs expose silent substitution only when clients, monitors or witnesses compare committed views.

Remote attestation authenticates evidence about a target environment. Endorsements, reference values and appraisal policy are what turn that evidence into a decision.

Oblivious HTTP partitions network identity and request contents between a relay and a gateway. Padding, discovery, metadata and collusion still determine the privacy of the complete system.

OPAQUE lets a client and server establish a mutually authenticated key without disclosing the password to the server. Registration, recovery and server-key custody still define the system’s real boundary.

Privacy Pass separates token issuance from token redemption. The token can prove prior authorization without carrying a stable client identity.

VDAFs let several aggregators verify and combine hidden client measurements. The result protects individual values only when non-collusion, batching and query policy hold.

FROST turns distributed authority into one ordinary Schnorr signature. The difficult security work remains in share generation, nonce state, participant coordination and recovery.

A zero-knowledge proof can verify correctly while authorizing the wrong statement. Fiat-Shamir security begins with the exact public instance, transcript order and domain separation absorbed by the hash.

BBS signatures support selective disclosure and randomized derived proofs. Unlinkability still depends on disclosed values, proof context, revocation and the surrounding protocol.