According to documentation on group key agreement the following check seems to be ommited: z1⊕ . . . ⊕zn = 0 whilst mentioned on original Pointcheval's GKE+P protocol.
So I wondered why is ommited? I also asked upon this as well: https://crypto.stackexchange.com/q/66544/59291
According to documentation on group key agreement the following check seems to be ommited: z1⊕ . . . ⊕zn = 0 whilst mentioned on original Pointcheval's GKE+P protocol.
So I wondered why is ommited? I also asked upon this as well: https://crypto.stackexchange.com/q/66544/59291