CS 161, Lesson 27, in 54 slides. It states the key-exchange problem and gives the paint intuition, in sections 10 and 10.1, then covers one-way functions and the discrete-log problem in section 10.2 and the Diffie-Hellman protocol with a worked toy example in section 10.3. It goes on to elliptic-curve Diffie-Hellman and the equivalences in bit strength, in sections 10.4 and 10.5, and ends with the man-in-the-middle attack that forces authentication, in section 10.6. It is anchored to textbook sections 10.1 to 10.6.
Subject: Computer Security · 85 slides · applied lesson
Open the interactive version of this deck · Homework for this lesson
Title
CS 161 · Lesson 27 of 45
the key-exchange problem · one-way functions · Diffie-Hellman · ECDH · and the man-in-the-middle that forces authentication
Objectives
Warm-up
Discussion prompt
Before we open L27 · Diffie-Hellman Key Exchange, ECDH & MITM: without looking back, what was the main idea of L26 · HMAC-DRBG & Stream Ciphers, and what could you do by the end of it that you could not do before?
Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.
Answer:
CS 161, Lesson 26, in 51 slides. It covers HMAC-DRBG, a secure pseudorandom generator built from HMAC, along with its Seed and Generate algorithms, its absorption of low-entropy input, and its rollback resistance, in section 9.4, then the Dual_EC_DRBG backdoor as enrichment. It closes with stream ciphers in section 9.5: the keystream used as a one-time pad, the formal Enc and Dec scheme, the roughly 2^64-bit limit on AES-CTR, and ChaCha20's counter-driven random access. It is anchored to textbook sections 9.4 to 9.5.
Concept
Symmetric crypto (L19–L24) gave us strong ciphers — but every one of them assumed Alice and Bob already shared a key. This lesson asks how they get one in the first place.
Matching
Match the pairs
From Three questions this lesson answers — match each one to what it actually does. The descriptions have been shuffled.
Why: What is the problem?, What makes it possible?, What still breaks it? are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.
Section
Part 1 · §10–10.1 the problem and the paint
Concept
Every symmetric scheme so far — the one-time pad, AES, the MAC — needs Alice and Bob to already share a secret key. But two strangers on the open Internet have never met. How do they agree on one?
The hard part: the channel is insecure. An eavesdropper, Eve, sees every byte they exchange. Anything Alice sends to set up the key, Eve sees too.
Counterexample
Discussion prompt
Every symmetric scheme so far — the one-time pad, AES, the MAC — needs Alice and Bob to already share a secret key. But two strangers on the open Internet have never met. How do they agree on one?
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Answer:
The hard part: the channel is insecure. An eavesdropper, Eve, sees every byte they exchange. Anything Alice sends to set up the key, Eve sees too.
Concept
Key exchange — A protocol letting two parties agree on a shared secret key over a public channel, such that an eavesdropper who sees the whole conversation still cannot compute the key.
The goal is usually an ephemeral key: a fresh secret used for one session, then thrown away. Diffie and Hellman solved this in the 1970s — the founding idea of public-key cryptography.
Analogy
Discussion prompt
Explain §10 What we actually want: an ephemeral key by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
The goal is usually an ephemeral key: a fresh secret used for one session, then thrown away. Diffie and Hellman solved this in the 1970s — the founding idea of public-key cryptography.
Intuition
Picture Alice and Bob mixing paint. They publicly agree on a common color — say green — that Eve also sees. Each then picks a secret color: Alice keeps amber, Bob keeps blue.
Each mixes their secret into the common green and sends the mixture across: Alice ships green-amber, Bob ships green-blue. Eve sees both mixtures travel by.
Now each adds their OWN secret to the mixture they received. Alice adds amber to green-blue; Bob adds blue to green-amber. Both end up at the SAME bucket: green-amber-blue.
Explain it
Discussion prompt
Explain §10.1 The paint analogy: mixing in public to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Picture Alice and Bob mixing paint. They publicly agree on a common color — say green — that Eve also sees. Each then picks a secret color: Alice keeps amber, Bob keeps blue.
Intuition
Eve saw green-amber and green-blue go by. To match Alice and Bob she needs green-amber-blue — but mixing the two public mixtures gives her green-amber-green-blue: too much green, the wrong shade.
She would have to 'un-mix' a public mixture to pull out a single secret color — and separating mixed paint is infeasible. That one-way difficulty is the whole trick.
Ask yourself: what does Eve lack that Alice and Bob each have? (One private secret color. Without it she can never reach exactly green-amber-blue.)
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'Eve has green-amber and green-blue — she just mixes them to get the shared color green-amber-blue.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Mixing green-amber with green-blue gives green-amber-GREEN-blue — an extra dose of the common color.
A student: what does Eve actually need, and why can't she get it?
Why: Mixing green-amber with green-blue gives green-amber-GREEN-blue — an extra dose of the common color. The result is the wrong shade, not the shared secret.
Trap
A student: 'Eve has green-amber and green-blue — she just mixes them to get the shared color green-amber-blue.'
Combine the two intercepted public mixtures
Why: Wrong. Mixing green-amber with green-blue gives green-amber-GREEN-blue — an extra dose of the common color. The result is the wrong shade, not the shared secret.
A student: what does Eve actually need, and why can't she get it?
Recognize she needs ONE party's private secret color added once, not both public mixtures combined
Why: §10.1: Alice and Bob each add a single private color to a received mixture. Eve has neither private color and can't un-mix a public one — so she can't land on green-amber-blue.
Section
Part 2 · §10.2 the math behind the paint
Concept
The paint's 'easy one way, infeasible the other' has a precise mathematical version: a one-way function. It is the engine under Diffie-Hellman.
One-way function f — A function where, given x, computing f(x) is easy, but given f(x), finding any x that maps to it is computationally infeasible. The 'cow → hamburger' analogy: grinding is easy, un-grinding is not.
Concept
The classic one-way function uses arithmetic modulo a large prime p, with a fixed base g (a generator). The function is modular exponentiation:
\[ f(x) = g^{x} \bmod p \]
Forward — given x, compute g^x mod p — is fast (repeated squaring). Backward — recover x from g^x mod p — is believed hard.
Intuition
Forward is cheap because of repeated squaring: even for a 2048-bit exponent you square and multiply a few thousand times, never computing the gigantic power directly — you reduce mod p at every step.
Backward has no such shortcut. Because the values wrap around mod p, the output g^x looks scrambled and unordered — there is no 'bigger output ⇒ bigger x' to binary-search on, the way an ordinary logarithm gives you.
Ask yourself: in ordinary real-number math, how do you recover x from g^x? (Take a logarithm.) Why doesn't that work mod p? (The mod scrambles the order, so the smooth logarithm has nothing to grab.)
Concept
Discrete logarithm problem (DLP) — Given a prime p, a generator g, and the value y = g^x mod p, find x. No efficient (polynomial-time) algorithm is known on a classical computer; DH's security rests on this being hard.
So inverting f(x) = g^x mod p IS the discrete-log problem. 'Easy to mix, hard to un-mix' becomes 'easy to exponentiate, hard to take the discrete log.'
Definition probe
Sort into buckets
Every line below is part of the definition of One-way function f or of Discrete logarithm problem (DLP) — one or the other, never both. Put each where it belongs.
Ranking
Put in order
Put the moves of §10.2 Compute the forward direction by repeated squaring into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Forward evaluation is what every party does in DH; we show it costs only a handful of multiplications, never a huge number.
Worked example
Goal: compute g^x mod p for g = 5, x = 6, p = 23, the cheap direction
Why: Forward evaluation is what every party does in DH; we show it costs only a handful of multiplications, never a huge number.
Build the small powers by squaring, reducing mod 23 each time
Why: Repeated squaring: 5^1, then square to 5^2, square again to 5^4 — each step stays a small residue mod 23.
| power | value mod 23 |
|---|---|
| 5^1 | 5 |
| 5^2 | 2 |
| 5^4 = (5^2)^2 | 4 |
Combine the pieces: 6 = 4 + 2, so 5^6 = 5^4 · 5^2
Why: Write the exponent in binary (6 = 110), multiply the squared pieces it selects — that is the whole repeated-squaring trick.
\[ 5^{6} \bmod 23 = (5^{4} \cdot 5^{2}) \bmod 23 = (4 \cdot 2) \bmod 23 = 8 \]
Verify: 5^6 = 15625, and 15625 mod 23 = 8
Why: §10.2: 15625 = 679·23 + 8, so the residue is 8 — the squaring shortcut gives the same answer with far less work, while the REVERSE (find x from 8) has no shortcut.
Comparison
Comparison matrix
From §10.2 Compute the forward direction by repeated squaring: refill the value mod 23 column from what you know. The rest of the table is as it appeared.
| power | value mod 23 |
|---|---|
| 5^1 | 5 |
| 5^2 | 2 |
| 5^4 = (5^2)^2 | 4 |
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'g^x mod p is just exponentiation — to get x back, take log base g, like log_5 of the result.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: An ordinary log works on real numbers where bigger input means bigger output.
A student: why is inverting g^x mod p actually hard?
Why: An ordinary log works on real numbers where bigger input means bigger output. The 'mod p' wrap destroys that ordering — the discrete log has NO known efficient algorithm.
Trap
A student: 'g^x mod p is just exponentiation — to get x back, take log base g, like log_5 of the result.'
\[ x \stackrel{?}{=} \log_{g}\!\big(g^{x} \bmod p\big) \]
Apply an ordinary real-valued logarithm to the modular result
Why: Wrong. An ordinary log works on real numbers where bigger input means bigger output. The 'mod p' wrap destroys that ordering — the discrete log has NO known efficient algorithm.
A student: why is inverting g^x mod p actually hard?
Recognize this is the discrete-logarithm problem, believed infeasible
Why: §10.2: recovering x from g^x mod p is the DLP. Best known classical attacks are sub-exponential but still infeasible for 2048-bit p — there is no efficient logarithm to take.
Notation
Annotate
From Trap: 'just take a logarithm to recover x' — read this one piece at a time. What is each part doing?
On: \( x \stackrel{?}{=} \log_{g}\!\big(g^{x} \bmod p\big) \)
Section
Part 3 · §10.3 the core exchange
Concept
Diffie-Hellman starts with two public numbers, fixed in advance and often standardized. Eve knows them too — they are not secret.
\[ p:\ \text{a large prime (e.g. 2048 bits)} \]
\[ g:\ \text{a generator with } 1 < g < p-1 \]
Concept
Alice and Bob each pick a private secret — their 'secret paint color' — uniformly from {1, …, p−2}, and send the one-way image of it.
\[ \text{Alice: secret } a, \quad \text{sends } A = g^{a} \bmod p \]
\[ \text{Bob: secret } b, \quad \text{sends } B = g^{b} \bmod p \]
Concept
Each raises the value they RECEIVED to their OWN secret exponent. Alice computes B^a; Bob computes A^b.
\[ \text{Alice: } S = B^{a} = (g^{b})^{a} = g^{ba} \bmod p \]
\[ \text{Bob: } S = A^{b} = (g^{a})^{b} = g^{ab} \bmod p \]
\[ g^{ba} = g^{ab} \bmod p \ \Rightarrow\ \text{same } S \]
Sorting
Sort into buckets
These are the pieces of L27 · Diffie-Hellman Key Exchange, ECDH & MITM, out of order. Put each one back under the part of the lesson it belongs to.
Intuition
The common color is g; Alice's amber is a, Bob's blue is b. 'Mixing my secret into the common color' is exponentiating: g^a, g^b. The mixtures on the wire are A and B.
'Adding my own secret to your mixture' is exponentiating again: Alice does (g^b)^a, Bob does (g^a)^b. Because exponents multiply and multiplication commutes, both reach g^{ab} — the shared green-amber-blue.
Ask yourself: which paint step matches multiplying the exponents? (Adding your secret color the second time — and ab = ba is exactly why both buckets match.)
Concept
In practice you don't use the raw S = g^{ab} mod p as the key directly — it has mathematical structure. You hash it to produce a clean symmetric key.
\[ K = H(S) = H\big(g^{ab} \bmod p\big) \]
That K then seeds the symmetric schemes from earlier in the unit (AES, HMAC) for the actual session.
Step zero
Discussion prompt
§10.3 A full toy exchange: p = 23, g = 5 — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Fix the public parameters p = 23 and g = 5 (tiny, for hand…
Answer:
Worked example
Fix the public parameters p = 23 and g = 5 (tiny, for hand computation)
Why: Real DH uses a 2048-bit prime; here we use a small prime so every step is checkable by hand. Eve also knows p and g.
Alice picks secret a = 6 and sends A = 5^6 mod 23
Why: From the repeated-squaring slide, 5^6 mod 23 = 8, so Alice sends A = 8.
\[ A = 5^{6} \bmod 23 = 8 \]
Bob picks secret b = 15 and sends B = 5^15 mod 23
Why: Computing 5^15 mod 23 by repeated squaring gives 19, so Bob sends B = 19.
\[ B = 5^{15} \bmod 23 = 19 \]
Translation
\( B = 5^{15} \bmod 23 = 19 \)
Draw it
Translate both ways. First write the expression above as a sentence with no symbols in it at all. Then cover it, and write your sentence back as notation. If the two versions disagree, the disagreement is the thing to fix.
Ranking
Put in order
Put the moves of §10.3 Both parties compute S — and it matches into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. She raises Bob's public value 19 to her own secret 6; this equals g^{ba}.
Worked example
Alice computes S = B^a = 19^6 mod 23
Why: She raises Bob's public value 19 to her own secret 6; this equals g^{ba}.
Bob computes S = A^b = 8^15 mod 23
Why: He raises Alice's public value 8 to his own secret 15; this equals g^{ab}.
| who | computes | value mod 23 |
|---|---|---|
| Alice | B^a = 19^6 | 2 |
| Bob | A^b = 8^15 | 2 |
| both | g^{ab} = g^{ba} | 2 — identical |
\[ S = 19^{6} \bmod 23 = 2 = 8^{15} \bmod 23 \]
Verify: both sides independently reach S = 2 without ever sending it
Why: §10.3: Alice and Bob now share S = 2 over a public channel. Eve saw 23, 5, 8, and 19 — but not a, b, or S. The shared secret never crossed the wire.
Trade off
Comparison matrix
From §10.3 Both parties compute S — and it matches: every row here is a choice with a cost. Fill the computes column, then say which row you would actually pick and what you give up for it.
| who | computes | value mod 23 |
|---|---|---|
| Alice | B^a = 19^6 | 2 |
| Bob | A^b = 8^15 | 2 |
| both | g^{ab} = g^{ba} | 2 — identical |
Concept
Eve has g, p, A = g^a, and B = g^b. To get S = g^{ab} she'd need a or b — i.e. she'd have to take a discrete log of A or B. That's the assumption believed hard.
Computational Diffie-Hellman (CDH) assumption — Given g, p, g^a, and g^b, it is infeasible to compute g^{ab} mod p. DH's eavesdropper-security rests on CDH (which would follow if discrete log were easy).
Concept
The best known classical attack on discrete log (the general number field sieve) runs in roughly sub-exponential time in the bit length n:
\[ \approx \exp\!\Big( c \cdot n^{1/3} \cdot (\log n)^{2/3} \Big) \]
For n = 2048 bits this is astronomically large — infeasible for any real attacker. That is why DH primes are chosen at 2048 bits or more.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'Eve has A = g^a and B = g^b; she just multiplies (or adds) them to get S.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Multiplying gives g^{a+b}, not g^{ab}; adding gives nonsense.
A student: what would Eve actually need to compute S?
Why: Multiplying gives g^{a+b}, not g^{ab}; adding gives nonsense. To reach g^{ab} from g^a and g^b you need a discrete log — exactly the hard problem.
Trap
A student: 'Eve has A = g^a and B = g^b; she just multiplies (or adds) them to get S.'
\[ A \cdot B = g^{a} \cdot g^{b} = g^{a+b} \ne g^{ab} = S \]
Multiply or add the two public values to reconstruct the secret
Why: Wrong. Multiplying gives g^{a+b}, not g^{ab}; adding gives nonsense. To reach g^{ab} from g^a and g^b you need a discrete log — exactly the hard problem.
A student: what would Eve actually need to compute S?
Recognize she needs a discrete log: recover a from A (or b from B), then exponentiate
Why: §10.3: only a holder of a private exponent can reach g^{ab}. From the public g^a and g^b, computing g^{ab} is the CDH problem — believed infeasible.
Notation
Annotate
From Trap: 'Eve combines A and B to get S' — read this one piece at a time. What is each part doing?
On: \( A \cdot B = g^{a} \cdot g^{b} = g^{a+b} \ne g^{ab} = S \)
Section
Part 4 · §10.4–10.5 smaller keys, same security
Concept
Elliptic-Curve Diffie-Hellman (ECDH) is structurally identical to DH — only the underlying group changes. Instead of integers mod p, the secrets act on points of an elliptic curve, where the hard problem is the elliptic-curve discrete log.
Scalar multiplication a·G — The elliptic-curve analogue of g^a: the public point G added to itself a times. Easy forward; recovering a from a·G (the EC discrete-log problem) is believed hard.
Concept
Public parameter: a base point G on the curve. The exponentiations become scalar multiplications; the shared secret is the same multiply-commutes trick.
\[ \text{Alice: } A = a \cdot G, \qquad \text{Bob: } B = b \cdot G \]
\[ S = a \cdot B = a \cdot b \cdot G = b \cdot A \]
Same protocol, same MITM caveat (Part 5). The payoff is smaller keys for the same security.
Intuition
Against finite-field DH, attackers have the number field sieve — a sub-exponential algorithm. On a well-chosen elliptic curve, no such sub-exponential attack is known; the best attacks are essentially square-root of the group size.
Slower attacks mean you need fewer bits to reach the same wall. A 256-bit curve resists attack as well as a 2048-bit DH prime — so EC keys are shorter, faster, and cheaper to transmit.
Ask yourself: does a smaller ECDH key mean weaker security? (No — it means a harder underlying problem, so fewer bits buy the same strength.)
Concept
§10.5 lines up the key sizes that take roughly equal work to break. Match your symmetric strength to your public-key strength — a weak link anywhere sets the security.
| Symmetric (AES) | Finite-field DH/RSA | Elliptic curve | Hash |
|---|---|---|---|
| 128-bit | 2048-bit | 256-bit | SHA-256 |
| 256-bit | 3072-bit | 384-bit | SHA-384 |
So a balanced 128-bit suite pairs AES-128 with SHA-256 and EITHER a 256-bit curve OR a 2048-bit DH/RSA modulus.
Comparison
Comparison matrix
From §10.5 Equivalent security levels, in bits: refill the Hash column from what you know. The rest of the table is as it appeared.
| Symmetric (AES) | Finite-field DH/RSA | Elliptic curve | Hash |
|---|---|---|---|
| 128-bit | 2048-bit | 256-bit | SHA-256 |
| 256-bit | 3072-bit | 384-bit | SHA-384 |
Step zero
Discussion prompt
§10.5 Pick a matched cipher suite — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Target a 128-bit security level for a TLS-style session
Answer:
Worked example
Target a 128-bit security level for a TLS-style session
Why: 128 bits is the common modern baseline; every primitive in the suite must reach at least that strength or it becomes the weak link.
Choose the symmetric cipher and hash at 128-bit strength
Why: AES-128 for confidentiality and SHA-256 for hashing both sit at the 128-bit row of the equivalence table.
Choose the key-exchange group at matching strength: 256-bit curve OR 2048-bit DH
Why: Both a 256-bit elliptic curve and a 2048-bit finite-field DH prime are 128-bit-equivalent — either pairs correctly with AES-128 + SHA-256.
Contrast with the NSA top-secret suite
Why: For top-secret traffic the NSA specifies AES-256, 384-bit curves, SHA-384, and 3072-bit DH/RSA — the 256-bit row, every primitive bumped up together.
Verify the suite is balanced: every primitive ≥ 128-bit, none weaker
Why: §10.5: AES-128, SHA-256, and a 256-bit curve all sit at 128-bit strength — no single primitive drags the suite down. That balance IS the design rule.
Blank canvas
Draw it
Draw what §10.5 Pick a matched cipher suite just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'A 256-bit ECDH key is way shorter than a 2048-bit DH key, so ECDH must be much weaker.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Bit length only compares within the SAME problem.
A student: how do you compare strength across DH and ECDH?
Why: Bit length only compares within the SAME problem. The EC discrete-log problem has no sub-exponential attack, so 256 EC bits ≈ 2048 DH bits in real attack work.
Trap
A student: 'A 256-bit ECDH key is way shorter than a 2048-bit DH key, so ECDH must be much weaker.'
Equate key length directly with strength across different problems
Why: Wrong. Bit length only compares within the SAME problem. The EC discrete-log problem has no sub-exponential attack, so 256 EC bits ≈ 2048 DH bits in real attack work.
A student: how do you compare strength across DH and ECDH?
Compare by equivalent security level, not raw key length
Why: §10.5: a 256-bit curve ≈ a 2048-bit DH prime ≈ a 128-bit symmetric key. Smaller EC keys give EQUAL security, with faster math and shorter messages.
Section
Part 5 · §10.6 why DH needs authentication
Concept
Everything so far defended against Eve, a passive eavesdropper who only watches. Against Eve, DH is secure: she sees g^a, g^b and is stuck on CDH.
Active attacker (Mallory) — An attacker who can intercept, modify, drop, and inject messages on the channel — not just read them. DH provides NO defense against an active man-in-the-middle.
Intuition
Mallory sits between Alice and Bob and impersonates each to the other. To Bob she pretends to be Alice; to Alice she pretends to be Bob. Neither sees who they're really talking to.
She runs TWO separate Diffie-Hellman exchanges — one with Alice, one with Bob — using her own secret m on both sides. The result: two keys she controls, and neither victim notices.
Ask yourself: what stops Alice from checking that g^b really came from Bob? (Nothing — the DH messages carry no proof of who sent them.)
Concept
When Alice sends g^a, Mallory intercepts it and forwards her own g^m to Bob. When Bob sends g^b, Mallory intercepts it and forwards g^m to Alice.
\[ \text{Alice} \xrightarrow{\,g^{a}\,} \boxed{\text{Mallory}} \xrightarrow{\,g^{m}\,} \text{Bob} \]
\[ \text{Alice} \xleftarrow{\,g^{m}\,} \boxed{\text{Mallory}} \xleftarrow{\,g^{b}\,} \text{Bob} \]
Concept
Alice thinks she shares a key with Bob; she actually shares one with Mallory. Same for Bob. The two keys differ:
\[ K_{A} = g^{ma} \ \text{(Alice} \leftrightarrow \text{Mallory)} \]
\[ K_{B} = g^{mb} \ \text{(Bob} \leftrightarrow \text{Mallory)} \]
Mallory knows m and saw g^a, so she computes K_A = (g^a)^m. She saw g^b, so she computes K_B = (g^b)^m. She holds both.
Explain it
Discussion prompt
Explain §10.6 Two different keys — both known to Mallory to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Alice thinks she shares a key with Bob; she actually shares one with Mallory. Same for Bob. The two keys differ:
Ranking
Put in order
Put the moves of §10.6 Trace the two keys with toy numbers into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Alice sends A = g^a = 8 and Bob sends B = g^b = 19, as before; Mallory injects g^m = 5^7 mod 23 = 17 toward each side.
Worked example
Reuse p = 23, g = 5, a = 6, b = 15; Mallory's secret m = 7
Why: Alice sends A = g^a = 8 and Bob sends B = g^b = 19, as before; Mallory injects g^m = 5^7 mod 23 = 17 toward each side.
\[ g^{m} = 5^{7} \bmod 23 = 17 \]
Compute the Alice↔Mallory key: K_A = A^m = 8^7 mod 23
Why: Alice computes (g^m)^a = 17^6; Mallory computes (g^a)^m = 8^7 — both equal g^{am}.
Compute the Bob↔Mallory key: K_B = B^m = 19^7 mod 23
Why: Bob computes (g^m)^b = 17^15; Mallory computes (g^b)^m = 19^7 — both equal g^{bm}.
| link | key g^{m·secret} | Alice/Bob computes | Mallory computes | value |
|---|---|---|---|---|
| Alice ↔ Mallory | g^{am} | 17^6 mod 23 | 8^7 mod 23 | 12 |
| Bob ↔ Mallory | g^{bm} | 17^15 mod 23 | 19^7 mod 23 | 15 |
Verify: K_A = 12 ≠ 15 = K_B, and Mallory knows BOTH
Why: §10.6: the two halves use different keys (12 and 15), each computable by Mallory from m plus a public value. Alice and Bob never share a key with each other.
Comparison
Comparison matrix
From §10.6 Trace the two keys with toy numbers: refill the value column from what you know. The rest of the table is as it appeared.
| link | key g^{m·secret} | Alice/Bob computes | Mallory computes | value |
|---|---|---|---|---|
| Alice ↔ Mallory | g^{am} | 17^6 mod 23 | 8^7 mod 23 | 12 |
| Bob ↔ Mallory | g^{bm} | 17^15 mod 23 | 19^7 mod 23 | 15 |
Concept
Now traffic flows: Alice encrypts under K_A and sends. Mallory decrypts with K_A, reads (and can alter) the message, re-encrypts under K_B, and forwards to Bob. The reverse direction works the same way.
To Alice and Bob everything looks normal — the messages arrive, decrypt cleanly, and read sensibly. Mallory is a transparent relay who sees and can change every byte.
Analogy
Discussion prompt
Explain §10.6 Mallory relays — and tampers — invisibly by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
To Alice and Bob everything looks normal — the messages arrive, decrypt cleanly, and read sensibly. Mallory is a transparent relay who sees and can change every byte.
Concept
Why does this work? The DH messages g^a and g^b carry no proof of who sent them and no protection against modification. Alice has no way to tell Bob's g^b from Mallory's g^m.
Root cause of DH MITM — Plain Diffie-Hellman provides no integrity or authenticity for the exchanged public values. An active attacker can substitute her own values undetected.
Matching
Match the pairs
Match each term to the definition this lesson gave it — not the one you would guess from the word.
Why: These are the working definitions of Key exchange, Computational Diffie-Hellman (CDH) assumption, Scalar multiplication a·G, Active attacker (Mallory), Root cause of DH MITM as L27 · Diffie-Hellman Key Exchange, ECDH & MITM uses them. Pairing them correctly is the test of whether you could state each one with the slide switched off.
Concept
Stop the substitution by authenticating the DH messages, so each side can verify the value really came from the right party and was not altered.
Counterexample
Discussion prompt
Stop the substitution by authenticating the DH messages, so each side can verify the value really came from the right party and was not altered.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Concept
Use a fresh DH secret per session — ephemeral DH (DHE / ECDHE) — and you gain forward secrecy: session keys aren't recoverable even if a long-term key later leaks.
Forward secrecy — A property where compromise of a long-term key does NOT expose past session keys, because each session used an independent ephemeral DH secret that was discarded afterward.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'Diffie-Hellman defeats the eavesdropper, so it's secure against any attacker — no need for anything else.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: DH stops PASSIVE Eve, but an ACTIVE Mallory substitutes her own g^m on both sides and relays everything.
A student: what does DH need to be secure against a man-in-the-middle?
Why: DH stops PASSIVE Eve, but an ACTIVE Mallory substitutes her own g^m on both sides and relays everything. DH alone has no integrity, so it cannot detect this.
Trap
A student: 'Diffie-Hellman defeats the eavesdropper, so it's secure against any attacker — no need for anything else.'
Assume eavesdropper-security implies security against an active attacker
Why: Wrong. DH stops PASSIVE Eve, but an ACTIVE Mallory substitutes her own g^m on both sides and relays everything. DH alone has no integrity, so it cannot detect this.
A student: what does DH need to be secure against a man-in-the-middle?
Authenticate the DH values — e.g. sign them or bind them to a trusted identity
Why: §10.6: plain DH only resists eavesdropping. Adding authenticity/integrity (digital signatures or a pre-shared key) is what blocks the MITM substitution.
Two truths and a lie
Sort into buckets
Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.
Constraint
Discussion prompt
Run The Diffie-Hellman playbook with this step confiscated:
Eavesdropper-secure: Eve has g, p, g^a, g^b but computing g^{ab} is CDH — infeasible for 2048-bit p; multiplying A·B gives g^{a+b}, not S.
Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.
Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.
Answer:
Pattern
Edge cases
Discussion prompt
The Diffie-Hellman playbook works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".
Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.
Answer:
Elimination
Eliminate the wrong options
Against which attacker does plain (unauthenticated) Diffie-Hellman FAIL, and why?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: B
Why: §10.6: plain DH carries no integrity or authenticity on the exchanged values. An active man-in-the-middle (Mallory) intercepts g^a and g^b and forwards her own g^m to each side, establishing K_A = g^{am} with Alice and K_B = g^{mb} with Bob — both known to her. She then relays and tampers invisibly. DH does defeat a passive eavesdropper (computing g^{ab} from g^a, g^b is the infeasible CDH problem), so the gap is specifically the ACTIVE attacker. The fix is to authenticate the exchange with digital signatures or a pre-shared key.
Check
Alice and Bob run plain, unauthenticated Diffie-Hellman over the Internet. Mallory controls the network: she can read, drop, modify, and inject any message. Think it through on paper before choosing.
Check your understanding
Against which attacker does plain (unauthenticated) Diffie-Hellman FAIL, and why?
Answer: B
Why: §10.6: plain DH carries no integrity or authenticity on the exchanged values. An active man-in-the-middle (Mallory) intercepts g^a and g^b and forwards her own g^m to each side, establishing K_A = g^{am} with Alice and K_B = g^{mb} with Bob — both known to her. She then relays and tampers invisibly. DH does defeat a passive eavesdropper (computing g^{ab} from g^a, g^b is the infeasible CDH problem), so the gap is specifically the ACTIVE attacker. The fix is to authenticate the exchange with digital signatures or a pre-shared key.
Concept
Concept
Concept
Connect it up
Draw it
One page, no notation unless you need it: draw how these connect — The Key-Exchange Problem · One-Way Functions & Discrete Log · The Diffie-Hellman Protocol · Elliptic-Curve DH & Bit Strength · The Man-in-the-Middle Attack. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.
Recap
You can now explain the key-exchange problem and the paint intuition, define a one-way function and the discrete-log problem, run Diffie-Hellman to a shared secret on a concrete example, read the DH/ECDH/symmetric bit-strength equivalences, and trace the man-in-the-middle attack that forces DH to be authenticated.
| Idea | § | The one-line version |
|---|---|---|
| Key exchange | 10.1 | Agree on a key over a channel Eve watches; paint mixes one way |
| One-way function | 10.2 | f(x)=g^x mod p easy forward, discrete log hard backward |
| DH protocol | 10.3 | A=g^a, B=g^b ⇒ S=g^{ab}=g^{ba}, then K=H(S) |
| Eavesdropper-secure | 10.3 | CDH: g^{ab} from g^a,g^b is infeasible; A·B=g^{a+b}≠S |
| ECDH & bit strength | 10.4–10.5 | 256-bit curve ≈ 2048-bit DH ≈ 128-bit AES — equal security |
| Man-in-the-middle | 10.6 | Active Mallory injects g^m: K_A=g^{am}, K_B=g^{bm}, both hers |
| The fix | 10.6 | Authenticate the exchange (signatures / PSK); ephemeral DH ⇒ forward secrecy |
Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.