4.2 KiB
Diffie-Hellman
- Two parties can jointly agree a shared secret over an insecure channel
- Mathematically, what we are doing is both calculating the same value, mod a prime
p- Remember
pis\times 10^{600}
- Remember
- The parties separately compute the same key, rather than share it
\mathbb{Z}_n^*
The set
\mathbb{Z}_n^*consists of the integers\{1,2,...,n-1\}for whichgcd(i,n)=1This set forms an abelian group under multiplication modulo
n. The identity element is 1
- In the majority of cases, we use a prime number as the modulus:
\mathbb{Z}_p^* = \{1,2,...,p-1\}
Group Cardinality - The number of elements in that group
|\mathbb{Z}_m^*| = p-1 \\
|\mathbb{Z}_m^*| = \Phi(n) \\
- The security of ciphers often depends on the cardinality of the group
Cyclic Groups
- Let's consider group
\mathbb{Z}_{11}^* - Consider calculating powers of 3 in this group
3^i \space (mod \space 11) \\
a^1=3\\
a^2=3\cdot 3 = 9 \\
a^3 = 27 \equiv 5 \\
a^4=a\cdot a^3=3\cdot 5 \equiv 4 \\
a^5=a\cdot a^4=3\cdot 4 \equiv 1
- This pattern of
\{3,9,5,4,1\}repeats indefinitely
Order of an Element
The order
ord(a)of an elementaof a group(G, \circ)is the smallest positive integerksuch that:
a^k = \underbrace {a\circ a\circ ...\circ a}_{k\space times} =1Where 1 is the neutral element of
G
Another Cyclic Group
- What about
2^iin\mathbb{Z}_{11}^*
2^i \space mod \space 11 \\
a^1 = 2 \\
a^2=4 \\
a^3=8 \\
a^4=5 \\
a^5=10 \\
a^6=9 \\
a^7=7 \\
a^8=3 \\
a^9=6 \\
a^{10}=1 \\
a^{11}=2 \\
a^{12}=4 \\
-
We have generated every value in this group before cycling back round
-
A group that contains an element
gof maximum order is called a cyclic group -
Any element of maximum order is called a primitive root, or a generator
2is a generator of\mathbb{Z}_{11}^* \quad ord(2)=10- 3 is not a generator
\mathbb{Z}_{11}^* \quad ord(3)=5
Cyclic Subgroups
-
For all primes,
(\mathbb{Z}_{11}^*, \cdot)is an abelian finite cyclic group- Let
g \in GwhereGis a cyclic group:g^{|G|}=1ord(g)divides|G|
- These are called cyclic subgroups
- Let
-
Orders of
\mathbb{Z}_{11}^*
Diffie-Hellman
- Alice and Bob agree on a large prime
p, and a generatorgthat is a primitive root ofp - Alice and Bob choose private numbers
aandbat random in\mathbb{Z}_p^*- Where
a\in \{1,2,...,p-1\} - and
b\in \{1,2,...,p-1\}
- Where
- Alice calculates
A=g^a\space mod \space pand sendsApublicly to Bob - Bob calculates
B=g^b\space mod \space pand sendsBpublicly to Alice - Alice computes
k_{ab}=B^a\space mod \space p - Bob computes
k_{ab}=A^b\space mod \space p
B^a\space mod \space p = (g^b)^a = g^{ab}\space mod \space p \\
A^b\space mod \space p = (g^a)^b = g^{ab}\space mod \space p
The Discrete Logarithm Problem
- Why is Diffie-Hellman so hard to break
- Consider
\mathbb{Z}^*_{10000079},\space g=3- Alice calculates
A=3^a\space mod \space 10000079 = 4675535 - What is
a?
- Alice calculates
- This is the discrete logarithm problem
Brute Force requires O(|G|)
Shanks’ Baby-Step Giant-Step requires O(\sqrt{|G|}) and \sim \sqrt{|G|} space
- Using 128 bits, this is
2^{64}, which would need a cluster
Pollard’s Rho requires O(\sqrt{|G|})
Pohlig-Hellman is based on the prime factorisation of |G|
- The discrete log problem is solved mod each prime factor and the results combined using the Chinese remainder theorem
Index calculus directly attacks \mathbb{Z}_p^* and is the reason elliptic curves are so much more efficient
Choosing Primes
- To avoid any unexpected small subgroup attacks, commonly used DH primes are safe primes
- A safe prime is a prime
pwhere\frac{(p-1)}{2}is also a prime - Consider the order of
\mathbb{Z}_p^*for a safe prime- This will have two subgroups of order
p-1and2 - By choosing a generator of the subgroup of large prime order, we avoid attacks on small factors of the group order
- Basically this ensures the prime factorisation has one massive prime in it
- This will have two subgroups of order
