The Diffie-Hellman key exchange algorithm lets two parties establish a shared secret key over a communication channel that anyone else can openly observe, without having exchanged any secret information beforehand, so the shared key can then be used to encrypt their actual messages under an ordinary symmetric cipher. Each party generates its own private number and uses it to compute a public value through modular exponentiation; the two parties exchange their public values openly, and each combines the other party's public value with its own private number to arrive at the identical shared secret, a computation that an eavesdropper who has seen only the exchanged public values cannot feasibly reproduce because doing so requires solving the discrete logarithm problem. Whitfield Diffie and Martin Hellman published the method in 1976, describing it as one of the earliest practical public-key techniques in cryptography; it later came to light that researchers at Britain's GCHQ had developed the same underlying idea in 1969 but kept it classified. Diffie-Hellman and its later elliptic-curve variant remain the basis for establishing forward-secret session keys in widely used protocols such as TLS.
Reader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.