

A, B :  principal 
Na, Nb :  fresh number 
Sa :  private key 
Pa = exp(g,Sa) :  public key 
1.  A  >  B  :  a 
2.  B  >  A  :  Nb 
3.  A  >  B  :  r 
a × exp(Pa,Nb)  
=  exp(g,Na) × exp(exp(g,Sa),Nb)  
=  exp(g,Na) × exp(g,Sa × Nb)  
=  exp(g,Na + Sa × Nb)  
=  exp(g, r) 

