Overall ------- From tht title it sounds like your focus is on the use of out-of-band channels (which you call "physical contact") in Secure First Connect. But your survey is very incomplete: quoting from the seminar website: "You need not (and should not) limit yourself to this starter material only." Try making an exhaustive survey of first connect mechanisms using different out of band technologies comparing the OOB technologies in terms of their security properties. In parallel, you can describe the actual key agreement protocols in greater detail and analyze them, focussing on what kind of security requirements they impose, when they are used with OOB technologies. As discussed in the first meeting, you should take Jukka Valkonen's thesis as the starting point. Technical --------- Section 2 - "transient association" is not a necessary assumption - "no previous context" and "no trusted third party" are two aspects of the same thing: initialization of security association has to be done by the users themselves. - the constraints you quote from Jan-Erik's paper are valid, but you don't use or refer to these constraints afterwards. Section 4 - the barcodes or the blinks used in the visual channel are not "secret". Section 5 - restricting that each device must run only one pairing protocol instantace at a time is probably a reasonable restriction in practice. You could explain in more detail what kind of security problems you see in allowing parallel runs of pairing protocols. Editorial --------- - Explain acronyms on first use (e.g. PSP= - be consistent in references e.g., ref 4 lists the first name of the first author; ref 6 only lists initials.