None
EN
Keyhive 02 · Group Key Agreement with BeeKEM
[]
Ink & Switch
When we update our leaf DH public key, we must then update the secrets for all the nodes on our path, eventually updating the root secret for the entire group. Later on, when the sibling wants to decrypt that parent secret, it can do Diffie Hellman the other way, using the encrypter node’s DH public key with the sibling node’s secret to derive the same shared DH secret that was used to encrypt the parent. During a future update (key rotation), if you find a conflict key node on the path you’re updating, you can remove all conflict keys at that node and replace them with a single new public key and encrypted secret (as with normal parent encryption).