The Problem of Secure Key Exchange

How do two people agree on a shared secret key?

PUBLISHED
DURATION 2 min read
MODIFIED
TAGS
#cryptography
Table of Contents

For two people to communicate with each other securely, a common strategy is to ensure both parties have a shared piece of information, called a secret key.

Shared because both parties need to have it. Secret because it should be known only to the two parties involved, not to the public.

With this secret key, one party encrypts their message using that key, and sends the encrypted message in public to the intended recipient.

As long as the recipient also has that key, they can use it to decrypt the message. This is called Symmetric Key Cryptography.

Symmetric because the same key is used to encrypt and decrypt the message.

In this approach, it is important that nobody else has access to this secret key, since that would mean they could read the messages too.

But how do the two parties agree on a secret key?

One party can pick a key, and try to send it to the other party. But if that key is sent over a public channel, then an eavesdropper can intercept the key, and make a copy of the secret for themselves.

This introduces the problem of Secure Key Exchange.

Diffie-Hellman Key Exchange is one strategy to solve this problem. It is a protocol that allows two parties to agree on a secret key by communicating publicly, without revealing that secret key to anyone who might be listening.

[!What exactly is this secret key?] In cryptography, it’s just a really big number.

Diffie-Hellman Key Exchange is slightly misnamed, because we don’t actually exchange the key on the public channel, instead we exchange some public variables and combine them with some private variables to create a shared key together.

References

Diffie-Hellman Key Exchange: How to Share a Secret Secret Key Exchange (Diffie-Hellman) - Computerphile