pairing, just as we did in section~\ref{sec:wident-id}. However, to prove
the zero-knowledge property, one needs to make a bilinear analogue of the
knowledge of exponent assumption.
We suspect that a key-exchange protocol like ours can be constructed using
pairing, just as we did in section~\ref{sec:wident-id}. However, to prove
the zero-knowledge property, one needs to make a bilinear analogue of the
knowledge of exponent assumption.
We suspect that a key-exchange protocol like ours can be constructed using