Files
notes/docs/lectures/cryptography/11_diffie-hellman.md
T

136 lines
4.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Diffie-Hellman
- Two parties can jointly agree a *shared secret* over an *insecure channel*
- Mathematically, what we are doing is both calculating the same value, mod a prime $p$
- Remember $p$ is $\times 10^{600}$
- The parties separately compute the same key, rather than share it
### $\mathbb{Z}_n^*$
> The set $\mathbb{Z}_n^*$ consists of the integers $\{1,2,...,n-1\}$ for which $gcd(i,n)=1$
>
> This set forms an *abelian* group under multiplication modulo $n$. The identity element is 1
- In the majority of cases, we use a prime number as the modulus:
- $\mathbb{Z}_p^* = \{1,2,...,p-1\}$
**Group Cardinality** - The number of elements in that group
$$
|\mathbb{Z}_m^*| = p-1 \\
|\mathbb{Z}_m^*| = \Phi(n) \\
$$
- The security of ciphers often depend on the cardinality of the group
#### Cyclic Groups
- Lets consider group $\mathbb{Z}_{11}^*$
- Consider calculating powers of 3 in this group
$$
3^i \space (mod \space 11) \\
a^1=3\\
a^2=3\cdot 3 = 9 \\
a^3 = 27 \equiv 5 \\
a^4=a\cdot a^3=3\cdot 5 \equiv 4 \\
a^5=a\cdot a^4=3\cdot 4 \equiv 1
$$
- This pattern of $\{3,9,5,4,1\}$ repeats indefinitely
##### Order of an Element
> The order $ord(a)$ of an element $a$ of a group $(G, \circ)$ is the smallest positive integer $k$ such that:
>
> $a^k = \underbrace {a\circ a\circ ...\circ a}_{k\space times} =1$
>
> Where 1 is the neutral element of $G$
##### Another Cyclic Group
- What about $2^i$ in $\mathbb{Z}_{11}^*$
$$
2^i \space mod \space 11 \\
a^1 = 2 \\
a^2=4 \\
a^3=8 \\
a^4=5 \\
a^5=10 \\
a^6=9 \\
a^7=7 \\
a^8=3 \\
a^9=6 \\
a^{10}=1 \\
a^{11}=2 \\
a^{12}=4 \\
$$
- We have generated every value in this group before cycling back round
- A group that contains an element $g$ of maximum order is called a cyclic group
- Any element of maximum order is called a primitive root, or a generator
- $2$ is a generator of $\mathbb{Z}_{11}^* \quad ord(2)=10$
- 3 is not a generator $\mathbb{Z}_{11}^* \quad ord(3)=5$
##### Cyclic Subgroups
- For all primes, $(\mathbb{Z}_{11}^*, \cdot)$ is an *abelian finite cyclic group*
- Let $g \in G$ where $G$ is a cyclic group:
1. $g^{|G|}=1$
2. $ord(g)$ divides $|G|$
- These are called **cyclic subgroups**
- Orders of $\mathbb{Z}_{11}^*$
- ![1647359471.png](img/1647359471.png)
- Note the neutral element generates an order of $1$
## Diffie-Hellman
1. Alice and Bob agree on a large prime $p$, and a generator $g$ that is a primitive root of $p$
2. Alice and Bob choose private numbers $a$ and $b$ at random in $\mathbb{Z}_p^*$
- Where $a\in \{1,2,...,p-1\}$
- and $b\in \{1,2,...,p-1\}$
3. Alice calculates $A=g^a\space mod \space p$ and sends $A$ publicly to Bob
4. Bob calculates $B=g^b\space mod \space p$ and sends $B$ pubicly to Alice
5. Alice computes $k_{ab}=B^a\space mod \space p$
6. Bob computes $k_{ab}=A^b\space mod \space p$
$$
B^a\space mod \space p = (g^b)^a = g^{ab}\space mod \space p \\
A^b\space mod \space p = (g^a)^b = g^{ab}\space mod \space p
$$
#### The Discrete Logarithm Problem
- Why is Diffie-Hellman so hard to break
- Consider $\mathbb{Z}^*_{10000079},\space g=3$
- Alice calculates $A=3^a\space mod \space 10000079 = 4675535$
- What is $a$?
- This is the discrete logarithm problem
**Brute Force** requires $O(|G|)$
**Shank’s Baby-Step Giant-Step** requires $O(\sqrt{|G|})$ and $\sim \sqrt{|G|}$ space
- Using 128 bits, this is $2^{64}$, which would need a cluster
**Pollard’s Rho** requires $O(\sqrt{|G|})$
**Pohlig-Hellman** is based on the prime factorisation of $|G|$
- The discrete log problem is solved mod each prime factor and the results combined using the Chinese remainder theorem
**Index calculus** directly attacks $\mathbb{Z}_p^*$ and is the reason Elliptic Curves is so much more efficient
##### Choosing Primes
- To avoid any unexpected small subgroup attacks, commonly used DH primes are **safe primes**
- A safe prime is a prime $p$ where $\frac{(p-1)}{2}$ is also a prime
- Consider the order of $\mathbb{Z}_p^*$ for a safe prime
- This will have two subgroups of order $p-1$ and $2$
- By choosing a generator of the **subgroup of large prime order**, we avoid attacks on small factors of the group order
- Basically this ensures the prime factorisation has one massive prime in it