136 lines
4.2 KiB
Markdown
136 lines
4.2 KiB
Markdown
# Diffie-Hellman
|
||
|
||
- Two parties can jointly agree a *shared secret* over an *insecure channel*
|
||
- Mathematically, what we are doing is both calculating the same value, mod a prime $p$
|
||
- Remember $p$ is $\times 10^{600}$
|
||
- The parties separately compute the same key, rather than share it
|
||
|
||
### $\mathbb{Z}_n^*$
|
||
|
||
> The set $\mathbb{Z}_n^*$ consists of the integers $\{1,2,...,n-1\}$ for which $gcd(i,n)=1$
|
||
>
|
||
> This set forms an *abelian* group under multiplication modulo $n$. The identity element is 1
|
||
|
||
- In the majority of cases, we use a prime number as the modulus:
|
||
- $\mathbb{Z}_p^* = \{1,2,...,p-1\}$
|
||
|
||
**Group Cardinality** - The number of elements in that group
|
||
|
||
$$
|
||
|\mathbb{Z}_m^*| = p-1 \\
|
||
|\mathbb{Z}_m^*| = \Phi(n) \\
|
||
$$
|
||
|
||
- The security of ciphers often depend on the cardinality of the group
|
||
|
||
#### Cyclic Groups
|
||
|
||
- Lets consider group $\mathbb{Z}_{11}^*$
|
||
- Consider calculating powers of 3 in this group
|
||
|
||
$$
|
||
3^i \space (mod \space 11) \\
|
||
a^1=3\\
|
||
a^2=3\cdot 3 = 9 \\
|
||
a^3 = 27 \equiv 5 \\
|
||
a^4=a\cdot a^3=3\cdot 5 \equiv 4 \\
|
||
a^5=a\cdot a^4=3\cdot 4 \equiv 1
|
||
$$
|
||
|
||
- This pattern of $\{3,9,5,4,1\}$ repeats indefinitely
|
||
|
||
##### Order of an Element
|
||
|
||
> The order $ord(a)$ of an element $a$ of a group $(G, \circ)$ is the smallest positive integer $k$ such that:
|
||
>
|
||
> $a^k = \underbrace {a\circ a\circ ...\circ a}_{k\space times} =1$
|
||
>
|
||
> Where 1 is the neutral element of $G$
|
||
|
||
##### Another Cyclic Group
|
||
|
||
- What about $2^i$ in $\mathbb{Z}_{11}^*$
|
||
|
||
$$
|
||
2^i \space mod \space 11 \\
|
||
a^1 = 2 \\
|
||
a^2=4 \\
|
||
a^3=8 \\
|
||
a^4=5 \\
|
||
a^5=10 \\
|
||
a^6=9 \\
|
||
a^7=7 \\
|
||
a^8=3 \\
|
||
a^9=6 \\
|
||
a^{10}=1 \\
|
||
a^{11}=2 \\
|
||
a^{12}=4 \\
|
||
$$
|
||
|
||
- We have generated every value in this group before cycling back round
|
||
|
||
- A group that contains an element $g$ of maximum order is called a cyclic group
|
||
- Any element of maximum order is called a primitive root, or a generator
|
||
- $2$ is a generator of $\mathbb{Z}_{11}^* \quad ord(2)=10$
|
||
- 3 is not a generator $\mathbb{Z}_{11}^* \quad ord(3)=5$
|
||
|
||
##### Cyclic Subgroups
|
||
|
||
- For all primes, $(\mathbb{Z}_{11}^*, \cdot)$ is an *abelian finite cyclic group*
|
||
- Let $g \in G$ where $G$ is a cyclic group:
|
||
1. $g^{|G|}=1$
|
||
2. $ord(g)$ divides $|G|$
|
||
- These are called **cyclic subgroups**
|
||
- Orders of $\mathbb{Z}_{11}^*$
|
||
- 
|
||
- Note the neutral element generates an order of $1$
|
||
|
||
## Diffie-Hellman
|
||
|
||
1. Alice and Bob agree on a large prime $p$, and a generator $g$ that is a primitive root of $p$
|
||
2. Alice and Bob choose private numbers $a$ and $b$ at random in $\mathbb{Z}_p^*$
|
||
- Where $a\in \{1,2,...,p-1\}$
|
||
- and $b\in \{1,2,...,p-1\}$
|
||
3. Alice calculates $A=g^a\space mod \space p$ and sends $A$ publicly to Bob
|
||
4. Bob calculates $B=g^b\space mod \space p$ and sends $B$ pubicly to Alice
|
||
5. Alice computes $k_{ab}=B^a\space mod \space p$
|
||
6. Bob computes $k_{ab}=A^b\space mod \space p$
|
||
|
||
$$
|
||
B^a\space mod \space p = (g^b)^a = g^{ab}\space mod \space p \\
|
||
A^b\space mod \space p = (g^a)^b = g^{ab}\space mod \space p
|
||
$$
|
||
|
||
#### The Discrete Logarithm Problem
|
||
|
||
- Why is Diffie-Hellman so hard to break
|
||
- Consider $\mathbb{Z}^*_{10000079},\space g=3$
|
||
- Alice calculates $A=3^a\space mod \space 10000079 = 4675535$
|
||
- What is $a$?
|
||
- This is the discrete logarithm problem
|
||
|
||
**Brute Force** requires $O(|G|)$
|
||
|
||
**Shank’s Baby-Step Giant-Step** requires $O(\sqrt{|G|})$ and $\sim \sqrt{|G|}$ space
|
||
|
||
- Using 128 bits, this is $2^{64}$, which would need a cluster
|
||
|
||
**Pollard’s Rho** requires $O(\sqrt{|G|})$
|
||
|
||
**Pohlig-Hellman** is based on the prime factorisation of $|G|$
|
||
|
||
- The discrete log problem is solved mod each prime factor and the results combined using the Chinese remainder theorem
|
||
|
||
**Index calculus** directly attacks $\mathbb{Z}_p^*$ and is the reason Elliptic Curves is so much more efficient
|
||
|
||
##### Choosing Primes
|
||
|
||
- To avoid any unexpected small subgroup attacks, commonly used DH primes are **safe primes**
|
||
- A safe prime is a prime $p$ where $\frac{(p-1)}{2}$ is also a prime
|
||
- Consider the order of $\mathbb{Z}_p^*$ for a safe prime
|
||
- This will have two subgroups of order $p-1$ and $2$
|
||
- By choosing a generator of the **subgroup of large prime order**, we avoid attacks on small factors of the group order
|
||
- Basically this ensures the prime factorisation has one massive prime in it
|
||
|
||
|