L27 · Diffie-Hellman Key Exchange, ECDH & MITM

CS 161, Lesson 27, in 54 slides. It states the key-exchange problem and gives the paint intuition, in sections 10 and 10.1, then covers one-way functions and the discrete-log problem in section 10.2 and the Diffie-Hellman protocol with a worked toy example in section 10.3. It goes on to elliptic-curve Diffie-Hellman and the equivalences in bit strength, in sections 10.4 and 10.5, and ends with the man-in-the-middle attack that forces authentication, in section 10.6. It is anchored to textbook sections 10.1 to 10.6.

Subject: Computer Security · 85 slides · applied lesson

Open the interactive version of this deck · Homework for this lesson

What this lesson covers

The lesson, slide by slide

1. Agreeing on a Secret In Public

Title

CS 161 · Lesson 27 of 45

the key-exchange problem · one-way functions · Diffie-Hellman · ECDH · and the man-in-the-middle that forces authentication

2. By the end of this lesson you can…

Objectives

  1. Explain the key-exchange problem symmetric crypto assumed away, and the paint intuition for solving it over an insecure channel.
  2. Define a one-way function and the discrete-logarithm problem that makes modular exponentiation hard to invert.
  3. Run the Diffie-Hellman protocol end to end and compute the shared secret on a concrete toy example.
  4. Compare ECDH with finite-field DH and read a bit-strength equivalence table (2048-bit DH ≈ 256-bit curve ≈ 128-bit symmetric).
  5. Trace the man-in-the-middle attack and explain why DH needs authentication (signatures, pre-shared keys) to be secure.

3. What survived from L26 · HMAC-DRBG & Stream Ciphers?

Warm-up

Discussion prompt

Before we open L27 · Diffie-Hellman Key Exchange, ECDH & MITM: without looking back, what was the main idea of L26 · HMAC-DRBG & Stream Ciphers, and what could you do by the end of it that you could not do before?

Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.

Answer:

CS 161, Lesson 26, in 51 slides. It covers HMAC-DRBG, a secure pseudorandom generator built from HMAC, along with its Seed and Generate algorithms, its absorption of low-entropy input, and its rollback resistance, in section 9.4, then the Dual_EC_DRBG backdoor as enrichment. It closes with stream ciphers in section 9.5: the keystream used as a one-time pad, the formal Enc and Dec scheme, the roughly 2^64-bit limit on AES-CTR, and ChaCha20's counter-driven random access. It is anchored to textbook sections 9.4 to 9.5.

4. Three questions this lesson answers

Concept

Symmetric crypto (L19–L24) gave us strong ciphers — but every one of them assumed Alice and Bob already shared a key. This lesson asks how they get one in the first place.

What is the problem?
§10.1 agree on a key over a channel Eve watches
What makes it possible?
§10.2–10.3 one-way functions and Diffie-Hellman
What still breaks it?
§10.6 an active man-in-the-middle, unless we authenticate

5. Which is which: Three questions this lesson answers

Matching

Match the pairs

From Three questions this lesson answers — match each one to what it actually does. The descriptions have been shuffled.

  • c1. What is the problem?
  • c2. What makes it possible?
  • c3. What still breaks it?
  • b1. §10.1 agree on a key over a channel Eve watches
  • b2. §10.2–10.3 one-way functions and Diffie-Hellman
  • b3. §10.6 an active man-in-the-middle, unless we authenticate

Why: What is the problem?, What makes it possible?, What still breaks it? are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.

6. The Key-Exchange Problem

Section

Part 1 · §10–10.1 the problem and the paint

7. §10 The gap symmetric crypto left open

Concept

Every symmetric scheme so far — the one-time pad, AES, the MAC — needs Alice and Bob to already share a secret key. But two strangers on the open Internet have never met. How do they agree on one?

The hard part: the channel is insecure. An eavesdropper, Eve, sees every byte they exchange. Anything Alice sends to set up the key, Eve sees too.

8. Break it if you can: §10 The gap symmetric crypto left open

Counterexample

Discussion prompt

Every symmetric scheme so far — the one-time pad, AES, the MAC — needs Alice and Bob to already share a secret key. But two strangers on the open Internet have never met. How do they agree on one?

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

Answer:

The hard part: the channel is insecure. An eavesdropper, Eve, sees every byte they exchange. Anything Alice sends to set up the key, Eve sees too.

9. §10 What we actually want: an ephemeral key

Concept

Key exchange — A protocol letting two parties agree on a shared secret key over a public channel, such that an eavesdropper who sees the whole conversation still cannot compute the key.

The goal is usually an ephemeral key: a fresh secret used for one session, then thrown away. Diffie and Hellman solved this in the 1970s — the founding idea of public-key cryptography.

10. By analogy: §10 What we actually want: an ephemeral key

Analogy

Discussion prompt

Explain §10 What we actually want: an ephemeral key by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

The goal is usually an ephemeral key: a fresh secret used for one session, then thrown away. Diffie and Hellman solved this in the 1970s — the founding idea of public-key cryptography.

11. §10.1 The paint analogy: mixing in public

Intuition

Picture Alice and Bob mixing paint. They publicly agree on a common color — say green — that Eve also sees. Each then picks a secret color: Alice keeps amber, Bob keeps blue.

Each mixes their secret into the common green and sends the mixture across: Alice ships green-amber, Bob ships green-blue. Eve sees both mixtures travel by.

Now each adds their OWN secret to the mixture they received. Alice adds amber to green-blue; Bob adds blue to green-amber. Both end up at the SAME bucket: green-amber-blue.

12. Teach it back: §10.1 The paint analogy: mixing in public

Explain it

Discussion prompt

Explain §10.1 The paint analogy: mixing in public to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Picture Alice and Bob mixing paint. They publicly agree on a common color — say green — that Eve also sees. Each then picks a secret color: Alice keeps amber, Bob keeps blue.

13. §10.1 Why Eve can't reproduce the shared color

Intuition

Eve saw green-amber and green-blue go by. To match Alice and Bob she needs green-amber-blue — but mixing the two public mixtures gives her green-amber-green-blue: too much green, the wrong shade.

She would have to 'un-mix' a public mixture to pull out a single secret color — and separating mixed paint is infeasible. That one-way difficulty is the whole trick.

Ask yourself: what does Eve lack that Alice and Bob each have? (One private secret color. Without it she can never reach exactly green-amber-blue.)

14. Something is wrong here: 'Eve can just mix the two public mixtures'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'Eve has green-amber and green-blue — she just mixes them to get the shared color green-amber-blue.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Mixing green-amber with green-blue gives green-amber-GREEN-blue — an extra dose of the common color.

A student: what does Eve actually need, and why can't she get it?

Why: Mixing green-amber with green-blue gives green-amber-GREEN-blue — an extra dose of the common color. The result is the wrong shade, not the shared secret.

15. Trap: 'Eve can just mix the two public mixtures'

Trap

The trap

A student: 'Eve has green-amber and green-blue — she just mixes them to get the shared color green-amber-blue.'

Combine the two intercepted public mixtures

Why: Wrong. Mixing green-amber with green-blue gives green-amber-GREEN-blue — an extra dose of the common color. The result is the wrong shade, not the shared secret.

The fix

A student: what does Eve actually need, and why can't she get it?

Recognize she needs ONE party's private secret color added once, not both public mixtures combined

Why: §10.1: Alice and Bob each add a single private color to a received mixture. Eve has neither private color and can't un-mix a public one — so she can't land on green-amber-blue.

16. One-Way Functions & Discrete Log

Section

Part 2 · §10.2 the math behind the paint

17. §10.2 Easy to mix, hard to un-mix

Concept

The paint's 'easy one way, infeasible the other' has a precise mathematical version: a one-way function. It is the engine under Diffie-Hellman.

One-way function f — A function where, given x, computing f(x) is easy, but given f(x), finding any x that maps to it is computationally infeasible. The 'cow → hamburger' analogy: grinding is easy, un-grinding is not.

18. §10.2 The standard one-way function: modular exponentiation

Concept

The classic one-way function uses arithmetic modulo a large prime p, with a fixed base g (a generator). The function is modular exponentiation:

\[ f(x) = g^{x} \bmod p \]

Forward — given x, compute g^x mod p — is fast (repeated squaring). Backward — recover x from g^x mod p — is believed hard.

19. §10.2 Why forward is cheap but backward is not

Intuition

Forward is cheap because of repeated squaring: even for a 2048-bit exponent you square and multiply a few thousand times, never computing the gigantic power directly — you reduce mod p at every step.

Backward has no such shortcut. Because the values wrap around mod p, the output g^x looks scrambled and unordered — there is no 'bigger output ⇒ bigger x' to binary-search on, the way an ordinary logarithm gives you.

Ask yourself: in ordinary real-number math, how do you recover x from g^x? (Take a logarithm.) Why doesn't that work mod p? (The mod scrambles the order, so the smooth logarithm has nothing to grab.)

20. §10.2 The discrete logarithm problem

Concept

Discrete logarithm problem (DLP) — Given a prime p, a generator g, and the value y = g^x mod p, find x. No efficient (polynomial-time) algorithm is known on a classical computer; DH's security rests on this being hard.

So inverting f(x) = g^x mod p IS the discrete-log problem. 'Easy to mix, hard to un-mix' becomes 'easy to exponentiate, hard to take the discrete log.'

21. Take the definitions apart: One-way function f vs Discrete logarithm…

Definition probe

Sort into buckets

Every line below is part of the definition of One-way function f or of Discrete logarithm problem (DLP) — one or the other, never both. Put each where it belongs.

One-way function f
A function where, given x, computing f(x) is easy, but given f(x), finding any x that maps to it is computationally infeasible.; The 'cow → hamburger' analogy; grinding is easy, un-grinding is not.
Discrete logarithm problem (DLP)
Given a prime p, a generator g, and the value y = g^x mod p, find x.; No efficient (polynomial-time) algorithm is known on a classical computer; DH's security rests on this being hard.
b1
A function where, given x, computing f(x) is easy, but given f(x), finding any x that maps to it is computationally infeasible. The 'cow → hamburger' analogy: grinding is easy, un-grinding is not.
b2
Given a prime p, a generator g, and the value y = g^x mod p, find x. No efficient (polynomial-time) algorithm is known on a classical computer; DH's security rests on this being hard.

22. What has to happen first: §10.2 Compute the forward direction by repeated…

Ranking

Put in order

Put the moves of §10.2 Compute the forward direction by repeated squaring into the order they have to happen.

  1. Goal: compute g^x mod p for g = 5, x = 6, p = 23, the cheap direction
  2. Build the small powers by squaring, reducing mod 23 each time
  3. Combine the pieces: 6 = 4 + 2, so 5^6 = 5^4 · 5^2
  4. Verify: 5^6 = 15625, and 15625 mod 23 = 8

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Forward evaluation is what every party does in DH; we show it costs only a handful of multiplications, never a huge number.

23. §10.2 Compute the forward direction by repeated squaring

Worked example

Goal: compute g^x mod p for g = 5, x = 6, p = 23, the cheap direction

Why: Forward evaluation is what every party does in DH; we show it costs only a handful of multiplications, never a huge number.

Build the small powers by squaring, reducing mod 23 each time

Why: Repeated squaring: 5^1, then square to 5^2, square again to 5^4 — each step stays a small residue mod 23.

powervalue mod 23
5^15
5^22
5^4 = (5^2)^24

Combine the pieces: 6 = 4 + 2, so 5^6 = 5^4 · 5^2

Why: Write the exponent in binary (6 = 110), multiply the squared pieces it selects — that is the whole repeated-squaring trick.

\[ 5^{6} \bmod 23 = (5^{4} \cdot 5^{2}) \bmod 23 = (4 \cdot 2) \bmod 23 = 8 \]

Verify: 5^6 = 15625, and 15625 mod 23 = 8

Why: §10.2: 15625 = 679·23 + 8, so the residue is 8 — the squaring shortcut gives the same answer with far less work, while the REVERSE (find x from 8) has no shortcut.

24. Fill in: value mod 23 for §10.2 Compute the forward direction by…

Comparison

Comparison matrix

From §10.2 Compute the forward direction by repeated squaring: refill the value mod 23 column from what you know. The rest of the table is as it appeared.

powervalue mod 23
5^15
5^22
5^4 = (5^2)^24

25. Something is wrong here: 'just take a logarithm to recover x'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'g^x mod p is just exponentiation — to get x back, take log base g, like log_5 of the result.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: An ordinary log works on real numbers where bigger input means bigger output.

A student: why is inverting g^x mod p actually hard?

Why: An ordinary log works on real numbers where bigger input means bigger output. The 'mod p' wrap destroys that ordering — the discrete log has NO known efficient algorithm.

26. Trap: 'just take a logarithm to recover x'

Trap

The trap

A student: 'g^x mod p is just exponentiation — to get x back, take log base g, like log_5 of the result.'

\[ x \stackrel{?}{=} \log_{g}\!\big(g^{x} \bmod p\big) \]

Apply an ordinary real-valued logarithm to the modular result

Why: Wrong. An ordinary log works on real numbers where bigger input means bigger output. The 'mod p' wrap destroys that ordering — the discrete log has NO known efficient algorithm.

The fix

A student: why is inverting g^x mod p actually hard?

Recognize this is the discrete-logarithm problem, believed infeasible

Why: §10.2: recovering x from g^x mod p is the DLP. Best known classical attacks are sub-exponential but still infeasible for 2048-bit p — there is no efficient logarithm to take.

27. Decode the notation: Trap: 'just take a logarithm to recover x'

Notation

Annotate

From Trap: 'just take a logarithm to recover x' — read this one piece at a time. What is each part doing?

On: \( x \stackrel{?}{=} \log_{g}\!\big(g^{x} \bmod p\big) \)

  • Wrong. An ordinary log works on real numbers where bigger input means bigger output. The 'mod p' wrap destroys that ordering — the discrete log has NO known efficient algorithm.
  • §10.2: recovering x from g^x mod p is the DLP. Best known classical attacks are sub-exponential but still infeasible for 2048-bit p — there is no efficient logarithm to take.

28. The Diffie-Hellman Protocol

Section

Part 3 · §10.3 the core exchange

29. §10.3 Public parameters everyone agrees on

Concept

Diffie-Hellman starts with two public numbers, fixed in advance and often standardized. Eve knows them too — they are not secret.

\[ p:\ \text{a large prime (e.g. 2048 bits)} \]

\[ g:\ \text{a generator with } 1 < g < p-1 \]

30. §10.3 Each side picks a secret and sends a public value

Concept

Alice and Bob each pick a private secret — their 'secret paint color' — uniformly from {1, …, p−2}, and send the one-way image of it.

\[ \text{Alice: secret } a, \quad \text{sends } A = g^{a} \bmod p \]

\[ \text{Bob: secret } b, \quad \text{sends } B = g^{b} \bmod p \]

31. §10.3 Both sides land on the same secret

Concept

Each raises the value they RECEIVED to their OWN secret exponent. Alice computes B^a; Bob computes A^b.

\[ \text{Alice: } S = B^{a} = (g^{b})^{a} = g^{ba} \bmod p \]

\[ \text{Bob: } S = A^{b} = (g^{a})^{b} = g^{ab} \bmod p \]

\[ g^{ba} = g^{ab} \bmod p \ \Rightarrow\ \text{same } S \]

32. Where does each piece belong: L27 · Diffie-Hellman Key Exchange, ECDH &…

Sorting

Sort into buckets

These are the pieces of L27 · Diffie-Hellman Key Exchange, ECDH & MITM, out of order. Put each one back under the part of the lesson it belongs to.

The Key-Exchange Problem
§10 The gap symmetric crypto left open; §10 What we actually want: an ephemeral key; §10.1 The paint analogy: mixing in public
One-Way Functions & Discrete Log
§10.2 Easy to mix, hard to un-mix; §10.2 The standard one-way function: modular exponentiation; §10.2 Why forward is cheap but backward is not
The Diffie-Hellman Protocol
§10.3 Public parameters everyone agrees on; §10.3 Each side picks a secret and sends a public value; §10.3 Both sides land on the same secret
s1
The Key-Exchange Problem is where L27 · Diffie-Hellman Key Exchange, ECDH & MITM puts §10 The gap symmetric crypto left open, §10 What we actually want: an ephemeral key, §10.1 The paint analogy: mixing in public. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.
s2
One-Way Functions & Discrete Log is where L27 · Diffie-Hellman Key Exchange, ECDH & MITM puts §10.2 Easy to mix, hard to un-mix, §10.2 The standard one-way function: modular exponentiation, §10.2 Why forward is cheap but backward is not. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.
s3
The Diffie-Hellman Protocol is where L27 · Diffie-Hellman Key Exchange, ECDH & MITM puts §10.3 Public parameters everyone agrees on, §10.3 Each side picks a secret and sends a public value, §10.3 Both sides land on the same secret. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.

33. §10.3 The paint, now in exponents

Intuition

The common color is g; Alice's amber is a, Bob's blue is b. 'Mixing my secret into the common color' is exponentiating: g^a, g^b. The mixtures on the wire are A and B.

'Adding my own secret to your mixture' is exponentiating again: Alice does (g^b)^a, Bob does (g^a)^b. Because exponents multiply and multiplication commutes, both reach g^{ab} — the shared green-amber-blue.

Ask yourself: which paint step matches multiplying the exponents? (Adding your secret color the second time — and ab = ba is exactly why both buckets match.)

34. §10.3 Hash the shared secret into a key

Concept

In practice you don't use the raw S = g^{ab} mod p as the key directly — it has mathematical structure. You hash it to produce a clean symmetric key.

\[ K = H(S) = H\big(g^{ab} \bmod p\big) \]

That K then seeds the symmetric schemes from earlier in the unit (AES, HMAC) for the actual session.

35. Plan first: §10.3 A full toy exchange: p = 23, g = 5

Step zero

Discussion prompt

§10.3 A full toy exchange: p = 23, g = 5 — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Fix the public parameters p = 23 and g = 5 (tiny, for hand…

Answer:

  1. Fix the public parameters p = 23 and g = 5 (tiny, for hand computation)
  2. Alice picks secret a = 6 and sends A = 5^6 mod 23
  3. Bob picks secret b = 15 and sends B = 5^15 mod 23

36. §10.3 A full toy exchange: p = 23, g = 5

Worked example

Fix the public parameters p = 23 and g = 5 (tiny, for hand computation)

Why: Real DH uses a 2048-bit prime; here we use a small prime so every step is checkable by hand. Eve also knows p and g.

Alice picks secret a = 6 and sends A = 5^6 mod 23

Why: From the repeated-squaring slide, 5^6 mod 23 = 8, so Alice sends A = 8.

\[ A = 5^{6} \bmod 23 = 8 \]

Bob picks secret b = 15 and sends B = 5^15 mod 23

Why: Computing 5^15 mod 23 by repeated squaring gives 19, so Bob sends B = 19.

\[ B = 5^{15} \bmod 23 = 19 \]

37. Say it in words: §10.3 A full toy exchange: p = 23, g = 5

Translation

\( B = 5^{15} \bmod 23 = 19 \)

Draw it

Translate both ways. First write the expression above as a sentence with no symbols in it at all. Then cover it, and write your sentence back as notation. If the two versions disagree, the disagreement is the thing to fix.

38. What has to happen first: §10.3 Both parties compute S — and it matches

Ranking

Put in order

Put the moves of §10.3 Both parties compute S — and it matches into the order they have to happen.

  1. Alice computes S = B^a = 19^6 mod 23
  2. Bob computes S = A^b = 8^15 mod 23
  3. Verify: both sides independently reach S = 2 without ever sending it

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. She raises Bob's public value 19 to her own secret 6; this equals g^{ba}.

39. §10.3 Both parties compute S — and it matches

Worked example

Alice computes S = B^a = 19^6 mod 23

Why: She raises Bob's public value 19 to her own secret 6; this equals g^{ba}.

Bob computes S = A^b = 8^15 mod 23

Why: He raises Alice's public value 8 to his own secret 15; this equals g^{ab}.

whocomputesvalue mod 23
AliceB^a = 19^62
BobA^b = 8^152
bothg^{ab} = g^{ba}2 — identical

\[ S = 19^{6} \bmod 23 = 2 = 8^{15} \bmod 23 \]

Verify: both sides independently reach S = 2 without ever sending it

Why: §10.3: Alice and Bob now share S = 2 over a public channel. Eve saw 23, 5, 8, and 19 — but not a, b, or S. The shared secret never crossed the wire.

40. What each one costs: §10.3 Both parties compute S — and it matches

Trade off

Comparison matrix

From §10.3 Both parties compute S — and it matches: every row here is a choice with a cost. Fill the computes column, then say which row you would actually pick and what you give up for it.

whocomputesvalue mod 23
AliceB^a = 19^62
BobA^b = 8^152
bothg^{ab} = g^{ba}2 — identical

41. §10.3 What Eve sees, and why she's stuck

Concept

Eve has g, p, A = g^a, and B = g^b. To get S = g^{ab} she'd need a or b — i.e. she'd have to take a discrete log of A or B. That's the assumption believed hard.

Computational Diffie-Hellman (CDH) assumption — Given g, p, g^a, and g^b, it is infeasible to compute g^{ab} mod p. DH's eavesdropper-security rests on CDH (which would follow if discrete log were easy).

42. §10.3 How hard is 'hard'? The numbers

Concept

The best known classical attack on discrete log (the general number field sieve) runs in roughly sub-exponential time in the bit length n:

\[ \approx \exp\!\Big( c \cdot n^{1/3} \cdot (\log n)^{2/3} \Big) \]

For n = 2048 bits this is astronomically large — infeasible for any real attacker. That is why DH primes are chosen at 2048 bits or more.

43. Something is wrong here: 'Eve combines A and B to get S'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'Eve has A = g^a and B = g^b; she just multiplies (or adds) them to get S.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Multiplying gives g^{a+b}, not g^{ab}; adding gives nonsense.

A student: what would Eve actually need to compute S?

Why: Multiplying gives g^{a+b}, not g^{ab}; adding gives nonsense. To reach g^{ab} from g^a and g^b you need a discrete log — exactly the hard problem.

44. Trap: 'Eve combines A and B to get S'

Trap

The trap

A student: 'Eve has A = g^a and B = g^b; she just multiplies (or adds) them to get S.'

\[ A \cdot B = g^{a} \cdot g^{b} = g^{a+b} \ne g^{ab} = S \]

Multiply or add the two public values to reconstruct the secret

Why: Wrong. Multiplying gives g^{a+b}, not g^{ab}; adding gives nonsense. To reach g^{ab} from g^a and g^b you need a discrete log — exactly the hard problem.

The fix

A student: what would Eve actually need to compute S?

Recognize she needs a discrete log: recover a from A (or b from B), then exponentiate

Why: §10.3: only a holder of a private exponent can reach g^{ab}. From the public g^a and g^b, computing g^{ab} is the CDH problem — believed infeasible.

45. Decode the notation: Trap: 'Eve combines A and B to get S'

Notation

Annotate

From Trap: 'Eve combines A and B to get S' — read this one piece at a time. What is each part doing?

On: \( A \cdot B = g^{a} \cdot g^{b} = g^{a+b} \ne g^{ab} = S \)

  • Wrong. Multiplying gives g^{a+b}, not g^{ab}; adding gives nonsense. To reach g^{ab} from g^a and g^b you need a discrete log — exactly the hard problem.
  • §10.3: only a holder of a private exponent can reach g^{ab}. From the public g^a and g^b, computing g^{ab} is the CDH problem — believed infeasible.

46. Elliptic-Curve DH & Bit Strength

Section

Part 4 · §10.4–10.5 smaller keys, same security

47. §10.4 The same idea on an elliptic curve

Concept

Elliptic-Curve Diffie-Hellman (ECDH) is structurally identical to DH — only the underlying group changes. Instead of integers mod p, the secrets act on points of an elliptic curve, where the hard problem is the elliptic-curve discrete log.

Scalar multiplication a·G — The elliptic-curve analogue of g^a: the public point G added to itself a times. Easy forward; recovering a from a·G (the EC discrete-log problem) is believed hard.

48. §10.4 ECDH, step for step

Concept

Public parameter: a base point G on the curve. The exponentiations become scalar multiplications; the shared secret is the same multiply-commutes trick.

\[ \text{Alice: } A = a \cdot G, \qquad \text{Bob: } B = b \cdot G \]

\[ S = a \cdot B = a \cdot b \cdot G = b \cdot A \]

Same protocol, same MITM caveat (Part 5). The payoff is smaller keys for the same security.

49. §10.4 Why a curve buys smaller keys

Intuition

Against finite-field DH, attackers have the number field sieve — a sub-exponential algorithm. On a well-chosen elliptic curve, no such sub-exponential attack is known; the best attacks are essentially square-root of the group size.

Slower attacks mean you need fewer bits to reach the same wall. A 256-bit curve resists attack as well as a 2048-bit DH prime — so EC keys are shorter, faster, and cheaper to transmit.

Ask yourself: does a smaller ECDH key mean weaker security? (No — it means a harder underlying problem, so fewer bits buy the same strength.)

50. §10.5 Equivalent security levels, in bits

Concept

§10.5 lines up the key sizes that take roughly equal work to break. Match your symmetric strength to your public-key strength — a weak link anywhere sets the security.

Symmetric (AES)Finite-field DH/RSAElliptic curveHash
128-bit2048-bit256-bitSHA-256
256-bit3072-bit384-bitSHA-384

So a balanced 128-bit suite pairs AES-128 with SHA-256 and EITHER a 256-bit curve OR a 2048-bit DH/RSA modulus.

51. Fill in: Hash for §10.5 Equivalent security levels, in bits

Comparison

Comparison matrix

From §10.5 Equivalent security levels, in bits: refill the Hash column from what you know. The rest of the table is as it appeared.

Symmetric (AES)Finite-field DH/RSAElliptic curveHash
128-bit2048-bit256-bitSHA-256
256-bit3072-bit384-bitSHA-384

52. Plan first: §10.5 Pick a matched cipher suite

Step zero

Discussion prompt

§10.5 Pick a matched cipher suite — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Target a 128-bit security level for a TLS-style session

Answer:

  1. Target a 128-bit security level for a TLS-style session
  2. Choose the symmetric cipher and hash at 128-bit strength
  3. Choose the key-exchange group at matching strength: 256-bit curve OR 2048-bit DH
  4. Contrast with the NSA top-secret suite
  5. Verify the suite is balanced: every primitive ≥ 128-bit, none weaker

53. §10.5 Pick a matched cipher suite

Worked example

Target a 128-bit security level for a TLS-style session

Why: 128 bits is the common modern baseline; every primitive in the suite must reach at least that strength or it becomes the weak link.

Choose the symmetric cipher and hash at 128-bit strength

Why: AES-128 for confidentiality and SHA-256 for hashing both sit at the 128-bit row of the equivalence table.

Choose the key-exchange group at matching strength: 256-bit curve OR 2048-bit DH

Why: Both a 256-bit elliptic curve and a 2048-bit finite-field DH prime are 128-bit-equivalent — either pairs correctly with AES-128 + SHA-256.

Contrast with the NSA top-secret suite

Why: For top-secret traffic the NSA specifies AES-256, 384-bit curves, SHA-384, and 3072-bit DH/RSA — the 256-bit row, every primitive bumped up together.

Verify the suite is balanced: every primitive ≥ 128-bit, none weaker

Why: §10.5: AES-128, SHA-256, and a 256-bit curve all sit at 128-bit strength — no single primitive drags the suite down. That balance IS the design rule.

54. Draw the shape of it: §10.5 Pick a matched cipher suite

Blank canvas

Draw it

Draw what §10.5 Pick a matched cipher suite just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.

55. Something is wrong here: 'ECDH is weaker because the keys are smaller'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'A 256-bit ECDH key is way shorter than a 2048-bit DH key, so ECDH must be much weaker.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Bit length only compares within the SAME problem.

A student: how do you compare strength across DH and ECDH?

Why: Bit length only compares within the SAME problem. The EC discrete-log problem has no sub-exponential attack, so 256 EC bits ≈ 2048 DH bits in real attack work.

56. Trap: 'ECDH is weaker because the keys are smaller'

Trap

The trap

A student: 'A 256-bit ECDH key is way shorter than a 2048-bit DH key, so ECDH must be much weaker.'

Equate key length directly with strength across different problems

Why: Wrong. Bit length only compares within the SAME problem. The EC discrete-log problem has no sub-exponential attack, so 256 EC bits ≈ 2048 DH bits in real attack work.

The fix

A student: how do you compare strength across DH and ECDH?

Compare by equivalent security level, not raw key length

Why: §10.5: a 256-bit curve ≈ a 2048-bit DH prime ≈ a 128-bit symmetric key. Smaller EC keys give EQUAL security, with faster math and shorter messages.

57. The Man-in-the-Middle Attack

Section

Part 5 · §10.6 why DH needs authentication

58. §10.6 Passive vs active attackers

Concept

Everything so far defended against Eve, a passive eavesdropper who only watches. Against Eve, DH is secure: she sees g^a, g^b and is stuck on CDH.

Active attacker (Mallory) — An attacker who can intercept, modify, drop, and inject messages on the channel — not just read them. DH provides NO defense against an active man-in-the-middle.

59. §10.6 Mallory pretends to be each side

Intuition

Mallory sits between Alice and Bob and impersonates each to the other. To Bob she pretends to be Alice; to Alice she pretends to be Bob. Neither sees who they're really talking to.

She runs TWO separate Diffie-Hellman exchanges — one with Alice, one with Bob — using her own secret m on both sides. The result: two keys she controls, and neither victim notices.

Ask yourself: what stops Alice from checking that g^b really came from Bob? (Nothing — the DH messages carry no proof of who sent them.)

60. §10.6 The intercept-and-substitute move

Concept

When Alice sends g^a, Mallory intercepts it and forwards her own g^m to Bob. When Bob sends g^b, Mallory intercepts it and forwards g^m to Alice.

\[ \text{Alice} \xrightarrow{\,g^{a}\,} \boxed{\text{Mallory}} \xrightarrow{\,g^{m}\,} \text{Bob} \]

\[ \text{Alice} \xleftarrow{\,g^{m}\,} \boxed{\text{Mallory}} \xleftarrow{\,g^{b}\,} \text{Bob} \]

61. §10.6 Two different keys — both known to Mallory

Concept

Alice thinks she shares a key with Bob; she actually shares one with Mallory. Same for Bob. The two keys differ:

\[ K_{A} = g^{ma} \ \text{(Alice} \leftrightarrow \text{Mallory)} \]

\[ K_{B} = g^{mb} \ \text{(Bob} \leftrightarrow \text{Mallory)} \]

Mallory knows m and saw g^a, so she computes K_A = (g^a)^m. She saw g^b, so she computes K_B = (g^b)^m. She holds both.

62. Teach it back: §10.6 Two different keys — both known to Mallory

Explain it

Discussion prompt

Explain §10.6 Two different keys — both known to Mallory to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Alice thinks she shares a key with Bob; she actually shares one with Mallory. Same for Bob. The two keys differ:

63. What has to happen first: §10.6 Trace the two keys with toy numbers

Ranking

Put in order

Put the moves of §10.6 Trace the two keys with toy numbers into the order they have to happen.

  1. Reuse p = 23, g = 5, a = 6, b = 15; Mallory's secret m = 7
  2. Compute the Alice↔Mallory key: K_A = A^m = 8^7 mod 23
  3. Compute the Bob↔Mallory key: K_B = B^m = 19^7 mod 23
  4. Verify: K_A = 12 ≠ 15 = K_B, and Mallory knows BOTH

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Alice sends A = g^a = 8 and Bob sends B = g^b = 19, as before; Mallory injects g^m = 5^7 mod 23 = 17 toward each side.

64. §10.6 Trace the two keys with toy numbers

Worked example

Reuse p = 23, g = 5, a = 6, b = 15; Mallory's secret m = 7

Why: Alice sends A = g^a = 8 and Bob sends B = g^b = 19, as before; Mallory injects g^m = 5^7 mod 23 = 17 toward each side.

\[ g^{m} = 5^{7} \bmod 23 = 17 \]

Compute the Alice↔Mallory key: K_A = A^m = 8^7 mod 23

Why: Alice computes (g^m)^a = 17^6; Mallory computes (g^a)^m = 8^7 — both equal g^{am}.

Compute the Bob↔Mallory key: K_B = B^m = 19^7 mod 23

Why: Bob computes (g^m)^b = 17^15; Mallory computes (g^b)^m = 19^7 — both equal g^{bm}.

linkkey g^{m·secret}Alice/Bob computesMallory computesvalue
Alice ↔ Malloryg^{am}17^6 mod 238^7 mod 2312
Bob ↔ Malloryg^{bm}17^15 mod 2319^7 mod 2315

Verify: K_A = 12 ≠ 15 = K_B, and Mallory knows BOTH

Why: §10.6: the two halves use different keys (12 and 15), each computable by Mallory from m plus a public value. Alice and Bob never share a key with each other.

65. Fill in: value for §10.6 Trace the two keys with toy numbers

Comparison

Comparison matrix

From §10.6 Trace the two keys with toy numbers: refill the value column from what you know. The rest of the table is as it appeared.

linkkey g^{m·secret}Alice/Bob computesMallory computesvalue
Alice ↔ Malloryg^{am}17^6 mod 238^7 mod 2312
Bob ↔ Malloryg^{bm}17^15 mod 2319^7 mod 2315

66. §10.6 Mallory relays — and tampers — invisibly

Concept

Now traffic flows: Alice encrypts under K_A and sends. Mallory decrypts with K_A, reads (and can alter) the message, re-encrypts under K_B, and forwards to Bob. The reverse direction works the same way.

To Alice and Bob everything looks normal — the messages arrive, decrypt cleanly, and read sensibly. Mallory is a transparent relay who sees and can change every byte.

67. By analogy: §10.6 Mallory relays — and tampers — invisibly

Analogy

Discussion prompt

Explain §10.6 Mallory relays — and tampers — invisibly by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

To Alice and Bob everything looks normal — the messages arrive, decrypt cleanly, and read sensibly. Mallory is a transparent relay who sees and can change every byte.

68. §10.6 The root cause: no integrity, no authenticity

Concept

Why does this work? The DH messages g^a and g^b carry no proof of who sent them and no protection against modification. Alice has no way to tell Bob's g^b from Mallory's g^m.

Root cause of DH MITM — Plain Diffie-Hellman provides no integrity or authenticity for the exchanged public values. An active attacker can substitute her own values undetected.

69. Term to definition: L27 · Diffie-Hellman Key Exchange, ECDH & MITM

Matching

Match the pairs

Match each term to the definition this lesson gave it — not the one you would guess from the word.

  • t1. Key exchange
  • t2. Computational Diffie-Hellman (CDH) assumption
  • t3. Scalar multiplication a·G
  • t4. Active attacker (Mallory)
  • t5. Root cause of DH MITM
  • d1. A protocol letting two parties agree on a shared secret key over a public channel, such that an eavesdropper who sees the whole conversation still cannot compute the key.
  • d2. Given g, p, g^a, and g^b, it is infeasible to compute g^{ab} mod p. DH's eavesdropper-security rests on CDH (which would follow if discrete log were easy).
  • d3. The elliptic-curve analogue of g^a: the public point G added to itself a times. Easy forward; recovering a from a·G (the EC discrete-log problem) is believed hard.
  • d4. An attacker who can intercept, modify, drop, and inject messages on the channel — not just read them. DH provides NO defense against an active man-in-the-middle.
  • d5. Plain Diffie-Hellman provides no integrity or authenticity for the exchanged public values. An active attacker can substitute her own values undetected.

Why: These are the working definitions of Key exchange, Computational Diffie-Hellman (CDH) assumption, Scalar multiplication a·G, Active attacker (Mallory), Root cause of DH MITM as L27 · Diffie-Hellman Key Exchange, ECDH & MITM uses them. Pairing them correctly is the test of whether you could state each one with the slide switched off.

70. §10.6 The fix: authenticate the exchange

Concept

Stop the substitution by authenticating the DH messages, so each side can verify the value really came from the right party and was not altered.

71. Break it if you can: §10.6 The fix: authenticate the exchange

Counterexample

Discussion prompt

Stop the substitution by authenticating the DH messages, so each side can verify the value really came from the right party and was not altered.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

72. §10.6 Ephemeral DH and forward secrecy

Concept

Use a fresh DH secret per session — ephemeral DH (DHE / ECDHE) — and you gain forward secrecy: session keys aren't recoverable even if a long-term key later leaks.

Forward secrecy — A property where compromise of a long-term key does NOT expose past session keys, because each session used an independent ephemeral DH secret that was discarded afterward.

73. Something is wrong here: 'DH alone is secure against any attacker'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student: 'Diffie-Hellman defeats the eavesdropper, so it's secure against any attacker — no need for anything else.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: DH stops PASSIVE Eve, but an ACTIVE Mallory substitutes her own g^m on both sides and relays everything.

A student: what does DH need to be secure against a man-in-the-middle?

Why: DH stops PASSIVE Eve, but an ACTIVE Mallory substitutes her own g^m on both sides and relays everything. DH alone has no integrity, so it cannot detect this.

74. Trap: 'DH alone is secure against any attacker'

Trap

The trap

A student: 'Diffie-Hellman defeats the eavesdropper, so it's secure against any attacker — no need for anything else.'

Assume eavesdropper-security implies security against an active attacker

Why: Wrong. DH stops PASSIVE Eve, but an ACTIVE Mallory substitutes her own g^m on both sides and relays everything. DH alone has no integrity, so it cannot detect this.

The fix

A student: what does DH need to be secure against a man-in-the-middle?

Authenticate the DH values — e.g. sign them or bind them to a trusted identity

Why: §10.6: plain DH only resists eavesdropping. Adding authenticity/integrity (digital signatures or a pre-shared key) is what blocks the MITM substitution.

75. Which of these survive contact with L27 · Diffie-Hellman Key Exchange, ECDH &…?

Two truths and a lie

Sort into buckets

Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.

Holds up
Symmetric crypto (L19–L24) gave us strong ciphers — but every one of them assumed Alice and Bob already shared a key. This lesson asks how they get one in the first place.; The hard part: the channel is insecure. An eavesdropper, Eve, sees every byte they exchange. Anything Alice sends to set up the key, Eve sees too.; Each mixes their secret into the common green and sends the mixture across: Alice ships green-amber, Bob ships green-blue. Eve sees both mixtures travel by.
Breaks
A student: 'Eve has green-amber and green-blue — she just mixes them to get the shared color green-amber-blue.'; A student: 'g^x mod p is just exponentiation — to get x back, take log base g, like log_5 of the result.'
sound
These are stated as this lesson states them — each one survives the edge cases L27 · Diffie-Hellman Key Exchange, ECDH & MITM puts it through.
flawed
Each of these is lifted from a trap in this deck: reasonable-sounding, and wrong in a way that only shows up once you rely on it.

76. Without one step: The Diffie-Hellman playbook

Constraint

Discussion prompt

Run The Diffie-Hellman playbook with this step confiscated:

Eavesdropper-secure: Eve has g, p, g^a, g^b but computing g^{ab} is CDH — infeasible for 2048-bit p; multiplying A·B gives g^{a+b}, not S.

Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.

Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.

Answer:

  1. Public parameters: a large prime p and a generator g, fixed and known to everyone (Eve included).
  2. One-way core: f(x) = g^x mod p is easy forward, hard to invert — inverting it is the discrete-log problem.
  3. Exchange: Alice sends A = g^a, Bob sends B = g^b; each raises the received value to its own secret to get S = g^{ab} = g^{ba}, then K = H(S).
  4. Eavesdropper-secure: Eve has g, p, g^a, g^b but computing g^{ab} is CDH — infeasible for 2048-bit p; multiplying A·B gives g^{a+b}, not S.
  5. ECDH: same protocol on a curve (A = a·G, S = a·b·G); 256-bit curve ≈ 2048-bit DH ≈ 128-bit AES — smaller keys, equal security.
  6. MITM caveat: an active Mallory substitutes g^m and shares g^{am} with Alice, g^{bm} with Bob. Fix: authenticate the exchange (signatures, pre-shared key)…

77. The Diffie-Hellman playbook

Pattern

  1. Public parameters: a large prime p and a generator g, fixed and known to everyone (Eve included).
  2. One-way core: f(x) = g^x mod p is easy forward, hard to invert — inverting it is the discrete-log problem.
  3. Exchange: Alice sends A = g^a, Bob sends B = g^b; each raises the received value to its own secret to get S = g^{ab} = g^{ba}, then K = H(S).
  4. Eavesdropper-secure: Eve has g, p, g^a, g^b but computing g^{ab} is CDH — infeasible for 2048-bit p; multiplying A·B gives g^{a+b}, not S.
  5. ECDH: same protocol on a curve (A = a·G, S = a·b·G); 256-bit curve ≈ 2048-bit DH ≈ 128-bit AES — smaller keys, equal security.
  6. MITM caveat: an active Mallory substitutes g^m and shares g^{am} with Alice, g^{bm} with Bob. Fix: authenticate the exchange (signatures, pre-shared key); use ephemeral DH for forward secrecy.

78. Where does it stop working: The Diffie-Hellman playbook

Edge cases

Discussion prompt

The Diffie-Hellman playbook works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".

Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.

Answer:

  1. Public parameters: a large prime p and a generator g, fixed and known to everyone (Eve included).
  2. One-way core: f(x) = g^x mod p is easy forward, hard to invert — inverting it is the discrete-log problem.
  3. Exchange: Alice sends A = g^a, Bob sends B = g^b; each raises the received value to its own secret to get S = g^{ab} = g^{ba}, then K = H(S).
  4. Eavesdropper-secure: Eve has g, p, g^a, g^b but computing g^{ab} is CDH — infeasible for 2048-bit p; multiplying A·B gives g^{a+b}, not S.
  5. ECDH: same protocol on a curve (A = a·G, S = a·b·G); 256-bit curve ≈ 2048-bit DH ≈ 128-bit AES — smaller keys, equal security.
  6. MITM caveat: an active Mallory substitutes g^m and shares g^{am} with Alice, g^{bm} with Bob. Fix: authenticate the exchange (signatures, pre-shared key)…

79. Rule out three: Checkpoint — what does DH alone NOT protect…

Elimination

Eliminate the wrong options

Against which attacker does plain (unauthenticated) Diffie-Hellman FAIL, and why?

3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.

  • A. A passive eavesdropper, because she can multiply A·B to recover S = g^{ab}.
  • B. An active man-in-the-middle, because the DH values have no authenticity, so Mallory substitutes g^m and shares one key with each side.
  • C. No attacker — plain DH is secure against both passive and active attackers.
  • D. A passive eavesdropper, because she can take the discrete log of A in feasible time.

Survives elimination: B

Why: §10.6: plain DH carries no integrity or authenticity on the exchanged values. An active man-in-the-middle (Mallory) intercepts g^a and g^b and forwards her own g^m to each side, establishing K_A = g^{am} with Alice and K_B = g^{mb} with Bob — both known to her. She then relays and tampers invisibly. DH does defeat a passive eavesdropper (computing g^{ab} from g^a, g^b is the infeasible CDH problem), so the gap is specifically the ACTIVE attacker. The fix is to authenticate the exchange with digital signatures or a pre-shared key.

80. Checkpoint — what does DH alone NOT protect against?

Check

Alice and Bob run plain, unauthenticated Diffie-Hellman over the Internet. Mallory controls the network: she can read, drop, modify, and inject any message. Think it through on paper before choosing.

Check your understanding

Against which attacker does plain (unauthenticated) Diffie-Hellman FAIL, and why?

  • A. A passive eavesdropper, because she can multiply A·B to recover S = g^{ab}.
  • B. An active man-in-the-middle, because the DH values have no authenticity, so Mallory substitutes g^m and shares one key with each side. (correct)
  • C. No attacker — plain DH is secure against both passive and active attackers.
  • D. A passive eavesdropper, because she can take the discrete log of A in feasible time.

Answer: B

Why: §10.6: plain DH carries no integrity or authenticity on the exchanged values. An active man-in-the-middle (Mallory) intercepts g^a and g^b and forwards her own g^m to each side, establishing K_A = g^{am} with Alice and K_B = g^{mb} with Bob — both known to her. She then relays and tampers invisibly. DH does defeat a passive eavesdropper (computing g^{ab} from g^a, g^b is the infeasible CDH problem), so the gap is specifically the ACTIVE attacker. The fix is to authenticate the exchange with digital signatures or a pre-shared key.

Why A tempts people
A passive eavesdropper cannot recover S: A·B = g^a·g^b = g^{a+b}, NOT g^{ab} = S. Reaching g^{ab} from the public values is the Computational Diffie-Hellman problem, believed infeasible. DH is secure against passive Eve.
Why C tempts people
Plain DH is NOT secure against an active attacker. Because the DH values carry no authenticity, Mallory substitutes her own g^m on each side and ends up sharing a separate key with Alice and with Bob — relaying and tampering undetected.
Why D tempts people
Taking the discrete log of A = g^a to recover a is exactly the hard problem DH relies on; for a 2048-bit prime no feasible algorithm is known. A passive eavesdropper cannot do this, so DH does protect against her.

81. Misconceptions to retire

Concept

82. Synthesis — DH closes the loop the symmetric unit opened

Concept

83. Primary sources & where to read more

Concept

84. Connect it up: L27 · Diffie-Hellman Key Exchange, ECDH & MITM

Connect it up

Draw it

One page, no notation unless you need it: draw how these connect — The Key-Exchange Problem · One-Way Functions & Discrete Log · The Diffie-Hellman Protocol · Elliptic-Curve DH & Bit Strength · The Man-in-the-Middle Attack. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.

85. Recap — Lesson 27

Recap

You can now explain the key-exchange problem and the paint intuition, define a one-way function and the discrete-log problem, run Diffie-Hellman to a shared secret on a concrete example, read the DH/ECDH/symmetric bit-strength equivalences, and trace the man-in-the-middle attack that forces DH to be authenticated.

Idea§The one-line version
Key exchange10.1Agree on a key over a channel Eve watches; paint mixes one way
One-way function10.2f(x)=g^x mod p easy forward, discrete log hard backward
DH protocol10.3A=g^a, B=g^b ⇒ S=g^{ab}=g^{ba}, then K=H(S)
Eavesdropper-secure10.3CDH: g^{ab} from g^a,g^b is infeasible; A·B=g^{a+b}≠S
ECDH & bit strength10.4–10.5256-bit curve ≈ 2048-bit DH ≈ 128-bit AES — equal security
Man-in-the-middle10.6Active Mallory injects g^m: K_A=g^{am}, K_B=g^{bm}, both hers
The fix10.6Authenticate the exchange (signatures / PSK); ephemeral DH ⇒ forward secrecy

Sources

  1. CS 161 Computer Security Textbook §10.1–10.6 — Wagner, Weaver, Kao, Shakir, Law & Ngai, UC Berkeley — the key-exchange problem and the paint analogy (§10.1), one-way functions and the discrete-logarithm problem (§10.2), the Diffie-Hellman protocol (§10.3), elliptic-curve Diffie-Hellman (§10.4), difficulty/bit-strength equivalences (§10.5), and the man-in-the-middle attack (§10.6)
  2. New Directions in Cryptography — W. Diffie & M. E. Hellman, IEEE Transactions on Information Theory 22(6), pp. 644–654 (1976) — introduces public key-exchange over an insecure channel
  3. Elliptic curve cryptosystems / Use of elliptic curves in cryptography — N. Koblitz, Mathematics of Computation 48(177), pp. 203–209 (1987); V. S. Miller, CRYPTO '85, LNCS 218, pp. 417–426 (1986) — independently propose elliptic curves for public-key cryptography
  4. NIST SP 800-56A Rev. 3 — Recommendation for Pair-Wise Key-Establishment Using Discrete Logarithm Cryptography — E. Barker, L. Chen, A. Roginsky, A. Vassilev & R. Davis, NIST, 2018 — standardizes finite-field and elliptic-curve Diffie-Hellman key establishment

Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108