Pages / #cryptography / #security
Diffie-Hellman key exchange
Diffie-Hellman lets two parties agree on a shared secret over a channel anyone can read, by mixing private exponents into public numbers an eavesdropper cannot unmix.
Mix a secret in publicInteractive
- Published
- 1976, Diffie and Hellman
- Hard problem
- Discrete logarithm
- Recommended prime
- 2048 bits or more
- Toy example
- p = 23, g = 5, secret 18
- In TLS 1.3
- (EC)DHE, P-256 and X25519
- Quantum threat
- Shor's algorithm
The worked example: p = 23, g = 5
In words
How the exchange works
6/6
Alice and Bob agree in public on a prime modulus p and a base g. Each picks a secret exponent and sends g raised to it, mod p; each then raises what the other sent to their own secret, and both land on the same number, written in RFC 2631 as ZZ = (yb ^ xa) mod p = (ya ^ xb) mod p 1. Wikipedia's small example uses p = 23 and g = 5 2 and ends with a shared secret of 18 3. The goal is a secret that stays unavailable to eavesdroppers 4, which then keys a fast symmetric cipher 5. Paint is the classic picture: anyone listening knows only the common color and the two mixes 6.
6 of 6 quotes found in their sources
-
RFC 2631: Diffie-Hellman Key Agreement Method (IETF, 1999) rfc-editor.org
ZZ = (yb ^ xa) mod p = (ya ^ xb) mod p
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
Alice and Bob publicly agree to use a modulus p = 23 and base g = 5
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
Alice and Bob now share a secret (the number 18)
Quote found in the source -
RFC 2631: Diffie-Hellman Key Agreement Method (IETF, 1999) rfc-editor.org
agree upon a shared secret in such a way that the secret will be unavailable to eavesdroppers
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
This key can then be used to encrypt subsequent communications using a symmetric-key cipher.
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
If a third party listened to the exchange, they would only know the common color
Quote found in the source
Why Eve is stuck
6/6
Eve sees p, g and both public values. Getting a secret exponent back from them is the discrete logarithm problem 1, which is currently considered difficult when the group is large enough 2; Wikipedia recommends primes of at least 2048 bits 3. A fast discrete log algorithm would break this and many other public key systems 4, and Shor's algorithm on a quantum computer is one 5. The bare exchange also proves nothing about who is on the other end: it is non-authenticated, and serves as the basis for authenticated protocols 6.
6 of 6 quotes found in their sources
-
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
Such a problem is called the discrete logarithm problem.
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
This is currently considered difficult for groups whose order is large enough.
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
it is recommended to use prime numbers of at least 2048 bits in length
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
An efficient algorithm to solve the discrete logarithm problem would make it easy to compute a or b
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
Quantum computers can break public-key cryptographic schemes, such as RSA, finite-field DH and elliptic-curve DH key-exchange protocols, using Shor's algorithm
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
exchange itself is a non-authenticated key-agreement protocol, it provides the basis for a variety of authenticated protocols
Quote found in the source
Where it runs today
6/6
TLS 1.3 lists (EC)DHE, Diffie-Hellman over finite fields or elliptic curves, as a key exchange mode 1; implementations must support P-256 and should support X25519 2. Using fresh keys per session gives forward secrecy: the private keys are discarded once agreement is complete 3. Signal's X3DH runs several elliptic curve Diffie-Hellman exchanges on X25519 or X448 4. The method was published by Whitfield Diffie and Martin Hellman in 1976 5; Hellman counts Ralph Merkle as a co-inventor of public key cryptography 6.
6 of 6 quotes found in their sources
-
RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3 (IETF, 2018) rfc-editor.org
(EC)DHE (Diffie-Hellman over either finite fields or elliptic curves)
Quote found in the source -
RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3 (IETF, 2018) rfc-editor.org
MUST support key exchange with secp256r1 (NIST P-256) and SHOULD support key exchange with X25519
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
the private keys are discarded once key agreement is complete
Quote found in the source -
The X3DH Key Agreement Protocol (Signal) signal.org
The Elliptic Curve Diffie-Hellman function will be either the X25519 or X448 function
Quote found in the source -
Diffie-Hellman key exchange (Wikipedia) en.wikipedia.org
It is named after Whitfield Diffie and Martin Hellman who published it in 1976.
Quote found in the source -
Martin E. Hellman's home page (Stanford) www-ee.stanford.edu
best known for his invention, with Diffie and Merkle, of public key cryptography
Quote found in the source