Lecture 29: The Diffie-Hellman Key Exchange: Creating a Shared Secret in Public

Clean infographic explaining the Diffie-Hellman key exchange using the paint mixing analogy. Use three columns for Alice, Public Channel, and Bob. Show Alice starting with public yellow paint and her secret red paint. She mixes them into orange and sends it to the public channel. Show Bob starting with public yellow paint and his secret blue paint. He mixes them into green and sends it to the public channel. In the final step, show Alice mixing her secret red with the received green, and Bob mixing his secret blue with the received orange, both arriving at the same final secret brown color. A shadowy Eve figure in the public channel is shown looking confused with only yellow, orange, and green paint. For a blog post on cryptography.

Sequentia Explores: The Mathematics of Crypto

Part III: Historical Ciphers & the Dawn of Cryptanalysis

Lecture 29: The Diffie-Hellman Key Exchange: Creating a Shared Secret in Public

In Lecture 22, we were left with a seemingly impossible paradox: the Key Exchange Problem. How can Alice and Bob, communicating over a public channel monitored by Eve, agree on a secret key to use for their symmetric encryption?

Today, we explore the revolutionary 1976 proposal by Whitfield Diffie and Martin Hellman that solved this problem for the first time. The Diffie-Hellman Key Exchange is a mathematical marvel that allows two parties to create a shared secret out of thin air, right in front of everyone. It doesn’t involve sending the secret itself, but rather the components that allow both parties to independently calculate the same secret.

To understand this, let’s start with a classic analogy.

The Paint Mixing Analogy

Imagine Alice and Bob want to agree on a secret color of paint, but they are in a public room where Eve can see everything they do.

  1. Public Agreement: Alice and Bob first agree on a common, public color of paint. Let’s say it’s Yellow. Everyone, including Eve, knows they are starting with Yellow.
  2. Private Secrets:
    • Alice secretly chooses her own private color, say Red. She keeps this secret.
    • Bob secretly chooses his own private color, say Blue. He keeps this secret.
  3. Mixing and Exchanging:
    • Alice mixes her secret Red with the public Yellow, creating a new color: Orange. She publicly sends a bucket of this Orange paint to Bob. Eve sees the Orange paint.
    • Bob mixes his secret Blue with the public Yellow, creating a new color: Green. He publicly sends a bucket of this Green paint to Alice. Eve sees the Green paint.
  4. Creating the Shared Secret:
    • Alice takes the Green paint she received from Bob and mixes it with her own secret color, Red. Green + Red = (Yellow + Blue) + Red.
    • Bob takes the Orange paint he received from Alice and mixes it with his own secret color, Blue. Orange + Blue = (Yellow + Red) + Blue.

Because the order of mixing doesn’t matter, both Alice and Bob will arrive at the exact same final color: a brownish Yellow-Blue-Red mixture.

What does Eve have? She has the public Yellow paint, the Orange mixture, and the Green mixture. But because separating mixed paint colors is chemically “hard,” she cannot easily figure out Alice’s secret Red or Bob’s secret Blue. Therefore, she cannot create the final secret color herself.

The Mathematics of Diffie-Hellman

The Diffie-Hellman algorithm is the mathematical equivalent of this paint mixing process. It replaces colors with numbers and paint mixing with modular exponentiation. The “hard problem” of separating paint is replaced by the Discrete Logarithm Problem (DLP).

Here’s how it works:

  1. Public Agreement: Alice and Bob publicly agree on two numbers:
    • A large prime number p (the modulus).
    • A base number g (the generator, related to p).
    • Both p and g are public. Eve knows them.
  2. Private Secrets:
    • Alice secretly chooses a large random integer a. This is her private key.
    • Bob secretly chooses a large random integer b. This is his private key.
  3. Mixing and Exchanging (Modular Exponentiation):
    • Alice calculates her public key, A, by performing a modular exponentiation:
      A = g^a mod p
      She sends the result A to Bob over the public channel. Eve sees A.
    • Bob calculates his public key, B, with his own secret:
      B = g^b mod p
      He sends the result B to Alice over the public channel. Eve sees B.
  4. Creating the Shared Secret:
    • Alice takes the public number she received from Bob (B) and raises it to the power of her own private secret a:
      Shared Secret = B^a mod p
      Shared Secret = (g^b mod p)^a mod p
    • Bob takes the public number he received from Alice (A) and raises it to the power of his own private secret b:
      Shared Secret = A^b mod p
      Shared Secret = (g^a mod p)^b mod p

The “Aha!” Moment: Why It’s the Same Secret

Thanks to the rules of exponents, (g^b)^a is the same as (g^a)^b, which both equal g^(a×b). The modulo operations at each step don’t change this fundamental equality.

Both Alice and Bob have independently calculated the same final number: g^(a×b) mod p.

This number is their new shared secret key. They can now use this key to encrypt their subsequent communication with a fast and efficient symmetric cipher like AES.

Why is it Secure from Eve?

What does Eve have?

  • The public numbers p and g.
  • Alice’s public result A = g^a mod p.
  • Bob’s public result B = g^b mod p.

To find the shared secret, Eve would need to know either Alice’s private a or Bob’s private b. To find a, she would have to solve g^a ≡ A (mod p). This is the Discrete Logarithm Problem. As we’ve discussed, for large prime numbers p, this is computationally infeasible.

Eve is stuck with the “mixed paint” (A and B) and the “public base color” (g and p), but she cannot un-mix them to find the secret ingredients (a and b).

The Diffie-Hellman key exchange was a monumental breakthrough. It was the first published practical method for creating a shared secret from public information, directly solving the key exchange problem. It forms the basis of many secure protocols on the internet, often used to establish a temporary, secure “session key” at the beginning of a secure communication session (like in TLS/HTTPS).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top