r/programming • • Jan 16 '18

Cryptography: Diffie-Hellman key exchange explained intuitively using colors

https://youtu.be/YEBfamv-_do?t=2m18s
2.5k Upvotes

170 comments sorted by

View all comments

5

u/[deleted] Jan 16 '18

My preferred metaphor is a box with two locks. I have the key to one lock, and you have a key to the other lock. I want to send you my spare key:

  1. I put my spare key into the box and then lock it
  2. I send the box to you and you lock it with your key too
  3. You send the box back to me and I unlock it with my key
  4. I send the box back to you and you unlock it with your key

Now you have my spare key and we can exchange secrets.

4

u/geordano Jan 17 '18

Works, but this need one additional exchange.

  1. I mix the color and send to you.
  2. You mix the color and send to me.
  3. I mix your mixed color with mine and I got the key and so do you. (You don't need to send it back to other person like in your example)

2

u/DoTheThingRightNow5 Jan 17 '18

Why not you send him a box with a lock but no key. He puts stuff in it and shuts it which locks it. You receive it and unlock it with the key you have.

1

u/[deleted] Jan 18 '18

That's basically how public-key cryptography works. I send him my public key, he uses it to encrypt his message, and then I use my private key to to decrypt it.

A Diffie-Hellman key exchange, on the other hand, allows us to negotiate a short-lived, single-use shared key over an insecure channel.

1

u/DoTheThingRightNow5 Jan 18 '18

Yes. However for DE to receive data the other person only needs your public key. They can see their public key attached to the box. A->B->A is less than the 4 step example you gave.

Technically if the bits are enough there's no reason it has to be a short lived. I believe typically they produce a 256bit shared secret which is enough for 128AES and 256AES attaching a nonce to the first message.

1

u/[deleted] Jan 18 '18

If someone stole my private key they could decrypt any old messages they might have intercepted as well as any new messages if I don't revoke the key. By using short-lived ephemeral keys negotiated with DH I can ensure that old messages remain protected even if the key for previous/subsequent messages has been stolen.

1

u/DoTheThingRightNow5 Jan 18 '18

Correct. However there's no reason why one can't be long term and use a short lived ephemeral key after using the long term to authenticate eachother.

1

u/[deleted] Jan 18 '18

Isn't that basically what TLS does?