Cryptography Intermediate

Diffie-Hellman Key Exchange

Alice and Bob agree on a secret while every message they exchange is public. Nothing is encrypted and no key is ever sent — the security is that recovering a private exponent means solving a discrete logarithm.

Both sides computed live
Eve's complete view
Discrete log brute force
Live
Public Parameters
Alice — private
A = ga mod p8
Bob — private
B = gb mod p19
Only a and b stay secret. p, g, A and B are all sent in the clear — Eve sees every one of them.
The Exchange
AliceA = 8Bob
AliceB = 19Bob
Alice computes Ba mod p
2
Bob computes Ab mod p
2
Eve — everything she can see
p23
g5
A8
B19
Shared secretnot directly computable

To get the secret Eve must find a from A = ga mod p — the discrete logarithm problem. Easy for p = 23; believed infeasible for a 2048-bit prime.

Step-by-Step Exchange
Break It: Solve the Discrete Logarithm

Eve knows g, A and p. Recovering a means answering “g to what power gives A?” Brute force below tries every exponent — instant for a small prime, and the reason real deployments use primes of 2048 bits or more.

One warning this tool cannot show you: Diffie-Hellman gives no authentication. Eve sitting in the middle can run one exchange with Alice and another with Bob, and read everything while both believe they are secure. That is why real protocols sign the exchange — the key agreement and the identity check are separate problems.

A Shared Secret Over a Public Channel
(g^a)^b = g^(ab) = (g^b)^a mod p

Alice and Bob agree publicly on a prime p and a generator g. Alice picks a secret a and sends ga; Bob picks a secret b and sends gb. Each raises what they received to their own secret.

Both land on gab mod p, because exponents multiply the same way in either order. Neither ever transmitted their exponent, and no key travelled across the wire at all.

Eve sees p, g, ga and gb. To finish she needs gab, and the only known route is to recover a or b — the discrete logarithm problem.

This was the 1976 paper that started public-key cryptography. Before it, every cipher needed a key delivered in advance by some other trusted means.
What It Does and Does Not Give You

Diffie-Hellman solves exactly one problem, and it is important to be precise about which:

  • It agrees a key. That is all. It does not encrypt anything — the shared secret is then fed through a key derivation function and used with AES or similar.
  • It does not authenticate. An active attacker in the middle runs two separate exchanges and relays between them. Both sides think they are secure and Eve reads everything. Signatures or certificates are what close this.
  • The raw secret must not be used directly. gab is a group element with structure, not a uniform bit string. Real protocols hash it first.
  • Small subgroups matter. If g generates only a small subgroup the secret has few possible values. Safe primes and validated parameters exist for this reason.
  • Ephemeral keys give forward secrecy. Fresh a and b per session mean a key compromised later cannot decrypt traffic recorded earlier — which is why TLS uses ephemeral Diffie-Hellman.
Modern TLS runs this over an elliptic curve instead of integers mod p: same idea, same algebra, far smaller numbers for the same security.
Put It Into Practice

The tool shows the mechanism — the slides show why it is built that way.

The idea that made the internet possible

Agreeing a secret in public sounds impossible until you see it work. One-on-one tutoring builds it from the group theory up, then shows how TLS uses it today.

Book a Free Consultation →