Files
notes/docs/lectures/cryptography/11_diffie-hellman.md
T
2026-10-04 15:24:17 +01:00

4.2 KiB
Raw Blame History

Diffie-Hellman

  • Two parties can jointly agree a shared secret over an insecure channel
  • Mathematically, what we are doing is both calculating the same value, mod a prime p
    • Remember p is \times 10^{600}
  • The parties separately compute the same key, rather than share it

\mathbb{Z}_n^*

The set \mathbb{Z}_n^* consists of the integers \{1,2,...,n-1\} for which gcd(i,n)=1

This set forms an abelian group under multiplication modulo n. The identity element is 1

  • In the majority of cases, we use a prime number as the modulus:
    • \mathbb{Z}_p^* = \{1,2,...,p-1\}

Group Cardinality - The number of elements in that group


|\mathbb{Z}_m^*| = p-1 \\
|\mathbb{Z}_m^*| = \Phi(n) \\
  • The security of ciphers often depends on the cardinality of the group

Cyclic Groups

  • Let's consider group \mathbb{Z}_{11}^*
  • Consider calculating powers of 3 in this group

3^i \space (mod \space 11) \\
a^1=3\\
a^2=3\cdot 3 = 9 \\
a^3 = 27 \equiv 5 \\
a^4=a\cdot a^3=3\cdot 5 \equiv 4 \\
a^5=a\cdot a^4=3\cdot 4 \equiv 1
  • This pattern of \{3,9,5,4,1\} repeats indefinitely
Order of an Element

The order ord(a) of an element a of a group (G, \circ) is the smallest positive integer k such that:

a^k = \underbrace {a\circ a\circ ...\circ a}_{k\space times} =1

Where 1 is the neutral element of G

Another Cyclic Group
  • What about 2^i in \mathbb{Z}_{11}^*

2^i \space mod \space 11 \\
a^1 = 2 \\
a^2=4 \\
a^3=8 \\
a^4=5 \\
a^5=10 \\
a^6=9 \\
a^7=7 \\
a^8=3 \\
a^9=6 \\
a^{10}=1 \\
a^{11}=2 \\
a^{12}=4 \\
  • We have generated every value in this group before cycling back round

  • A group that contains an element g of maximum order is called a cyclic group

  • Any element of maximum order is called a primitive root, or a generator

    • 2 is a generator of \mathbb{Z}_{11}^* \quad ord(2)=10
    • 3 is not a generator \mathbb{Z}_{11}^* \quad ord(3)=5
Cyclic Subgroups
  • For all primes, (\mathbb{Z}_{11}^*, \cdot) is an abelian finite cyclic group

    • Let g \in G where G is a cyclic group:
      1. g^{|G|}=1
      2. ord(g) divides |G|
    • These are called cyclic subgroups
  • Orders of \mathbb{Z}_{11}^*

    • 1647359471.png

    • Note the neutral element generates an order of 1

Diffie-Hellman

  1. Alice and Bob agree on a large prime p, and a generator g that is a primitive root of p
  2. Alice and Bob choose private numbers a and b at random in \mathbb{Z}_p^*
    • Where a\in \{1,2,...,p-1\}
    • and b\in \{1,2,...,p-1\}
  3. Alice calculates A=g^a\space mod \space p and sends A publicly to Bob
  4. Bob calculates B=g^b\space mod \space p and sends B publicly to Alice
  5. Alice computes k_{ab}=B^a\space mod \space p
  6. Bob computes k_{ab}=A^b\space mod \space p

B^a\space mod \space p = (g^b)^a = g^{ab}\space mod \space p \\
A^b\space mod \space p = (g^a)^b = g^{ab}\space mod \space p

The Discrete Logarithm Problem

  • Why is Diffie-Hellman so hard to break
  • Consider \mathbb{Z}^*_{10000079},\space g=3
    • Alice calculates A=3^a\space mod \space 10000079 = 4675535
    • What is a?
  • This is the discrete logarithm problem

Brute Force requires O(|G|)

Shanks’ Baby-Step Giant-Step requires O(\sqrt{|G|}) and \sim \sqrt{|G|} space

  • Using 128 bits, this is 2^{64}, which would need a cluster

Pollard’s Rho requires O(\sqrt{|G|})

Pohlig-Hellman is based on the prime factorisation of |G|

  • The discrete log problem is solved mod each prime factor and the results combined using the Chinese remainder theorem

Index calculus directly attacks \mathbb{Z}_p^* and is the reason elliptic curves are so much more efficient

Choosing Primes
  • To avoid any unexpected small subgroup attacks, commonly used DH primes are safe primes
  • A safe prime is a prime p where \frac{(p-1)}{2} is also a prime
  • Consider the order of \mathbb{Z}_p^* for a safe prime
    • This will have two subgroups of order p-1 and 2
    • By choosing a generator of the subgroup of large prime order, we avoid attacks on small factors of the group order
    • Basically this ensures the prime factorisation has one massive prime in it