Add the rest of university notes

This commit is contained in:
John Gatward committed 2026-10-04 14:02:35 +01:00
1 parent c1b84c7f7d
commit d0f27f276b
366 files changed
+9844 -110

No files matched your search

@@ -0,0 +1,135 @@
# Diffie-Hellman
- Two parties can jointly agree a *shared secret* over an *insecure channel*
- Mathematically, what we are doing is both calculating the same value, mod a prime $p$
- Remember $p$ is $\times 10^{600}$
- The parties separately compute the same key, rather than share it
### $\mathbb{Z}_n^*$
> The set $\mathbb{Z}_n^*$ consists of the integers $\{1,2,...,n-1\}$ for which $gcd(i,n)=1$
>
> This set forms an *abelian* group under multiplication modulo $n$. The identity element is 1
- In the majority of cases, we use a prime number as the modulus:
- $\mathbb{Z}_p^* = \{1,2,...,p-1\}$
**Group Cardinality** - The number of elements in that group
$$
|\mathbb{Z}_m^*| = p-1 \\
|\mathbb{Z}_m^*| = \Phi(n) \\
$$
- The security of ciphers often depend on the cardinality of the group
#### Cyclic Groups
- Lets consider group $\mathbb{Z}_{11}^*$
- Consider calculating powers of 3 in this group
$$
3^i \space (mod \space 11) \\
a^1=3\\
a^2=3\cdot 3 = 9 \\
a^3 = 27 \equiv 5 \\
a^4=a\cdot a^3=3\cdot 5 \equiv 4 \\
a^5=a\cdot a^4=3\cdot 4 \equiv 1
$$
- This pattern of $\{3,9,5,4,1\}$ repeats indefinitely
##### Order of an Element
> The order $ord(a)$ of an element $a$ of a group $(G, \circ)$ is the smallest positive integer $k$ such that:
>
> $a^k = \underbrace {a\circ a\circ ...\circ a}_{k\space times} =1$
>
> Where 1 is the neutral element of $G$
##### Another Cyclic Group
- What about $2^i$ in $\mathbb{Z}_{11}^*$
$$
2^i \space mod \space 11 \\
a^1 = 2 \\
a^2=4 \\
a^3=8 \\
a^4=5 \\
a^5=10 \\
a^6=9 \\
a^7=7 \\
a^8=3 \\
a^9=6 \\
a^{10}=1 \\
a^{11}=2 \\
a^{12}=4 \\
$$
- We have generated every value in this group before cycling back round
- A group that contains an element $g$ of maximum order is called a cyclic group
- Any element of maximum order is called a primitive root, or a generator
- $2$ is a generator of $\mathbb{Z}_{11}^* \quad ord(2)=10$
- 3 is not a generator $\mathbb{Z}_{11}^* \quad ord(3)=5$
##### Cyclic Subgroups
- For all primes, $(\mathbb{Z}_{11}^*, \cdot)$ is an *abelian finite cyclic group*
- Let $g \in G$ where $G$ is a cyclic group:
1. $g^{|G|}=1$
2. $ord(g)$ divides $|G|$
- These are called **cyclic subgroups**
- Orders of $\mathbb{Z}_{11}^*$
- ![1647359471.png](img/1647359471.png)
- Note the neutral element generates an order of $1$
## Diffie-Hellman
1. Alice and Bob agree on a large prime $p$, and a generator $g$ that is a primitive root of $p$
2. Alice and Bob choose private numbers $a$ and $b$ at random in $\mathbb{Z}_p^*$
- Where $a\in \{1,2,...,p-1\}$
- and $b\in \{1,2,...,p-1\}$
3. Alice calculates $A=g^a\space mod \space p$ and sends $A$ publicly to Bob
4. Bob calculates $B=g^b\space mod \space p$ and sends $B$ pubicly to Alice
5. Alice computes $k_{ab}=B^a\space mod \space p$
6. Bob computes $k_{ab}=A^b\space mod \space p$
$$
B^a\space mod \space p = (g^b)^a = g^{ab}\space mod \space p \\
A^b\space mod \space p = (g^a)^b = g^{ab}\space mod \space p
$$
#### The Discrete Logarithm Problem
- Why is Diffie-Hellman so hard to break
- Consider $\mathbb{Z}^*_{10000079},\space g=3$
- Alice calculates $A=3^a\space mod \space 10000079 = 4675535$
- What is $a$?
- This is the discrete logarithm problem
**Brute Force** requires $O(|G|)$
**Shank’s Baby-Step Giant-Step** requires $O(\sqrt{|G|})$ and $\sim \sqrt{|G|}$ space
- Using 128 bits, this is $2^{64}$, which would need a cluster
**Pollard’s Rho** requires $O(\sqrt{|G|})$
**Pohlig-Hellman** is based on the prime factorisation of $|G|$
- The discrete log problem is solved mod each prime factor and the results combined using the Chinese remainder theorem
**Index calculus** directly attacks $\mathbb{Z}_p^*$ and is the reason Elliptic Curves is so much more efficient
##### Choosing Primes
- To avoid any unexpected small subgroup attacks, commonly used DH primes are **safe primes**
- A safe prime is a prime $p$ where $\frac{(p-1)}{2}$ is also a prime
- Consider the order of $\mathbb{Z}_p^*$ for a safe prime
- This will have two subgroups of order $p-1$ and $2$
- By choosing a generator of the **subgroup of large prime order**, we avoid attacks on small factors of the group order
- Basically this ensures the prime factorisation has one massive prime in it