.. DO NOT EDIT. .. THIS FILE WAS AUTOMATICALLY GENERATED BY SPHINX-GALLERY. .. TO MAKE CHANGES, EDIT THE SOURCE PYTHON FILE: .. "api/gallery/crypto/public_keys/plot_02_diffie_hellman.py" .. LINE NUMBERS ARE GIVEN BELOW. .. only:: html .. note:: :class: sphx-glr-download-link-note :ref:`Go to the end ` to download the full example code or to run this example in your browser via JupyterLite. .. rst-class:: sphx-glr-example-title .. _sphx_glr_api_gallery_crypto_public_keys_plot_02_diffie_hellman.py: Diffie-Hellman: agreeing on a secret over a public channel (1976) ================================================================= Diffie and Hellman showed that two people can reach the same secret by exchanging only public values: each raises the other's public element to their own private exponent, and both arrive at g**(a*b). An eavesdropper sees g**a and g**b but would need a discrete logarithm to continue. What to look for ---------------- Both parties compute the same shared element without ever sending it. Then a man in the middle substitutes his own public value: the arithmetic still works, but Alice now shares a secret with Mallory. Agreement on a secret is not authentication of the other person. The history behind this experiment: :doc:`/history/crypto_breakthroughs`. See :doc:`/exercises/crypto` for a worked solution to the exercise. .. GENERATED FROM PYTHON SOURCE LINES 23-26 Agree on a shared group element ------------------------------- Neither party sends the shared value. Both reach g**(a*b) modulo p. .. GENERATED FROM PYTHON SOURCE LINES 26-38 .. code-block:: Python import matplotlib.pyplot as plt import blockchainkit as bk group = bk.crypto.DHGroup() # p = 23, q = 11, g = 2: tiny, so every value is visible. alice_secret, bob_secret = 3, 7 alice_public = group.public(alice_secret) bob_public = group.public(bob_secret) shared = group.shared(bob_public, alice_secret) assert shared == group.shared(alice_public, bob_secret) print(f"Public values: {alice_public}, {bob_public}; shared element: {shared}") .. rst-class:: sphx-glr-script-out .. code-block:: none Public values: 8, 13; shared element: 12 .. GENERATED FROM PYTHON SOURCE LINES 39-43 Authentication is a separate problem ------------------------------------ Mallory substitutes her own public value. Alice now shares a secret with Mallory, not Bob. Real protocols authenticate the exchange and use a KDF. .. GENERATED FROM PYTHON SOURCE LINES 43-49 .. code-block:: Python mallory_secret = 4 alice_mallory = group.shared(group.public(mallory_secret), alice_secret) assert alice_mallory == group.shared(alice_public, mallory_secret) assert alice_mallory != shared print("After key substitution, Alice's shared element is", alice_mallory) .. rst-class:: sphx-glr-script-out .. code-block:: none After key substitution, Alice's shared element is 2 .. GENERATED FROM PYTHON SOURCE LINES 50-52 The same exchange in a group too large to search by hand -------------------------------------------------------- .. GENERATED FROM PYTHON SOURCE LINES 52-56 .. code-block:: Python big = bk.crypto.TEACHING_GROUP a, b = 0x1234_5678_9ABC, 0x0FED_CBA9_8765 assert big.shared(big.public(b), a) == big.shared(big.public(a), b) .. GENERATED FROM PYTHON SOURCE LINES 57-59 Exponentiation scrambles the subgroup ------------------------------------- .. GENERATED FROM PYTHON SOURCE LINES 59-67 .. code-block:: Python fig, ax = plt.subplots(figsize=(7, 3.8)) exponents = list(range(1, group.q)) ax.scatter(exponents, [group.public(x) for x in exponents], color="#2563eb") ax.set( xlabel="private exponent x", ylabel="public element g**x mod p", title="DH in a tiny subgroup" ) fig.tight_layout() .. image-sg:: /api/gallery/crypto/public_keys/images/sphx_glr_plot_02_diffie_hellman_001.png :alt: DH in a tiny subgroup :srcset: /api/gallery/crypto/public_keys/images/sphx_glr_plot_02_diffie_hellman_001.png :class: sphx-glr-single-img .. GENERATED FROM PYTHON SOURCE LINES 68-72 Exercise -------- Exhaustively recover Alice's exponent from her public value. Why does this experiment say nothing about the cost for a carefully chosen large group? .. rst-class:: sphx-glr-timing **Total running time of the script:** (0 minutes 0.135 seconds) .. _sphx_glr_download_api_gallery_crypto_public_keys_plot_02_diffie_hellman.py: .. only:: html .. container:: sphx-glr-footer sphx-glr-footer-example .. container:: lite-badge .. image:: images/jupyterlite_badge_logo.svg :target: ../../../../lite/lab/index.html?path=api/gallery/crypto/public_keys/plot_02_diffie_hellman.ipynb :alt: Launch JupyterLite :width: 150 px .. container:: sphx-glr-download sphx-glr-download-jupyter :download:`Download Jupyter notebook: plot_02_diffie_hellman.ipynb ` .. container:: sphx-glr-download sphx-glr-download-python :download:`Download Python source code: plot_02_diffie_hellman.py ` .. container:: sphx-glr-download sphx-glr-download-zip :download:`Download zipped: plot_02_diffie_hellman.zip ` .. only:: html .. rst-class:: sphx-glr-signature `Gallery generated by Sphinx-Gallery `_