# Diffie-Hellman - Two parties can jointly agree a *shared secret* over an *insecure channel* - Mathematically, what we are doing is both calculating the same value, mod a prime $p$ - Remember $p$ is $\times 10^{600}$ - The parties separately compute the same key, rather than share it ### $\mathbb{Z}_n^*$ > The set $\mathbb{Z}_n^*$ consists of the integers $\{1,2,...,n-1\}$ for which $gcd(i,n)=1$ > > This set forms an *abelian* group under multiplication modulo $n$. The identity element is 1 - In the majority of cases, we use a prime number as the modulus: - $\mathbb{Z}_p^* = \{1,2,...,p-1\}$ **Group Cardinality** - The number of elements in that group $$ |\mathbb{Z}_m^*| = p-1 \\ |\mathbb{Z}_m^*| = \Phi(n) \\ $$ - The security of ciphers often depend on the cardinality of the group #### Cyclic Groups - Lets consider group $\mathbb{Z}_{11}^*$ - Consider calculating powers of 3 in this group $$ 3^i \space (mod \space 11) \\ a^1=3\\ a^2=3\cdot 3 = 9 \\ a^3 = 27 \equiv 5 \\ a^4=a\cdot a^3=3\cdot 5 \equiv 4 \\ a^5=a\cdot a^4=3\cdot 4 \equiv 1 $$ - This pattern of $\{3,9,5,4,1\}$ repeats indefinitely ##### Order of an Element > The order $ord(a)$ of an element $a$ of a group $(G, \circ)$ is the smallest positive integer $k$ such that: > > $a^k = \underbrace {a\circ a\circ ...\circ a}_{k\space times} =1$ > > Where 1 is the neutral element of $G$ ##### Another Cyclic Group - What about $2^i$ in $\mathbb{Z}_{11}^*$ $$ 2^i \space mod \space 11 \\ a^1 = 2 \\ a^2=4 \\ a^3=8 \\ a^4=5 \\ a^5=10 \\ a^6=9 \\ a^7=7 \\ a^8=3 \\ a^9=6 \\ a^{10}=1 \\ a^{11}=2 \\ a^{12}=4 \\ $$ - We have generated every value in this group before cycling back round - A group that contains an element $g$ of maximum order is called a cyclic group - Any element of maximum order is called a primitive root, or a generator - $2$ is a generator of $\mathbb{Z}_{11}^* \quad ord(2)=10$ - 3 is not a generator $\mathbb{Z}_{11}^* \quad ord(3)=5$ ##### Cyclic Subgroups - For all primes, $(\mathbb{Z}_{11}^*, \cdot)$ is an *abelian finite cyclic group* - Let $g \in G$ where $G$ is a cyclic group: 1. $g^{|G|}=1$ 2. $ord(g)$ divides $|G|$ - These are called **cyclic subgroups** - Orders of $\mathbb{Z}_{11}^*$ - ![1647359471.png](img/1647359471.png) - Note the neutral element generates an order of $1$ ## Diffie-Hellman 1. Alice and Bob agree on a large prime $p$, and a generator $g$ that is a primitive root of $p$ 2. Alice and Bob choose private numbers $a$ and $b$ at random in $\mathbb{Z}_p^*$ - Where $a\in \{1,2,...,p-1\}$ - and $b\in \{1,2,...,p-1\}$ 3. Alice calculates $A=g^a\space mod \space p$ and sends $A$ publicly to Bob 4. Bob calculates $B=g^b\space mod \space p$ and sends $B$ pubicly to Alice 5. Alice computes $k_{ab}=B^a\space mod \space p$ 6. Bob computes $k_{ab}=A^b\space mod \space p$ $$ B^a\space mod \space p = (g^b)^a = g^{ab}\space mod \space p \\ A^b\space mod \space p = (g^a)^b = g^{ab}\space mod \space p $$ #### The Discrete Logarithm Problem - Why is Diffie-Hellman so hard to break - Consider $\mathbb{Z}^*_{10000079},\space g=3$ - Alice calculates $A=3^a\space mod \space 10000079 = 4675535$ - What is $a$? - This is the discrete logarithm problem **Brute Force** requires $O(|G|)$ **Shank’s Baby-Step Giant-Step** requires $O(\sqrt{|G|})$ and $\sim \sqrt{|G|}$ space - Using 128 bits, this is $2^{64}$, which would need a cluster **Pollard’s Rho** requires $O(\sqrt{|G|})$ **Pohlig-Hellman** is based on the prime factorisation of $|G|$ - The discrete log problem is solved mod each prime factor and the results combined using the Chinese remainder theorem **Index calculus** directly attacks $\mathbb{Z}_p^*$ and is the reason Elliptic Curves is so much more efficient ##### Choosing Primes - To avoid any unexpected small subgroup attacks, commonly used DH primes are **safe primes** - A safe prime is a prime $p$ where $\frac{(p-1)}{2}$ is also a prime - Consider the order of $\mathbb{Z}_p^*$ for a safe prime - This will have two subgroups of order $p-1$ and $2$ - By choosing a generator of the **subgroup of large prime order**, we avoid attacks on small factors of the group order - Basically this ensures the prime factorisation has one massive prime in it