The Diffie-Hellman key exchange is a cryptographic protocol that allows two parties to agree on a shared secret key over a public channel — without ever transmitting the key itself. Published by Whitfield Diffie and Martin Hellman in 1976, it solved the fundamental key distribution problem and is still used inside TLS/HTTPS connections today.

What problem does Diffie-Hellman solve?

Symmetric encryption is fast and secure, but it requires both parties to share the same secret key. If Alice wants to send an encrypted message to Bob, they must already share a key — but how do they agree on a key if every message they send can be intercepted?

Sending the key directly over an insecure channel would expose it to any eavesdropper (Eve). Diffie-Hellman solves this by allowing Alice and Bob to each contribute part of the key calculation, using public information and private secrets, so that only they end up knowing the final shared value — even though Eve can see all the public exchanges.

The paint-mixing analogy

The classic explanation uses mixing paints:

  1. Public colour: Alice and Bob agree publicly on a starting colour — say, yellow. Eve can see this.
  2. Private secrets: Alice secretly mixes in orange paint; Bob secretly mixes in blue paint. Each keeps their secret colour private.
  3. Exchange: Alice sends Bob her yellow-orange mixture; Bob sends Alice his yellow-blue mixture. Eve can intercept both mixtures.
  4. Final combination: Alice adds her orange secret to Bob's yellow-blue mixture → yellow-orange-blue. Bob adds his blue secret to Alice's yellow-orange mixture → yellow-orange-blue. Both reach the same combined colour.
  5. Eve's problem: Eve has yellow (public), Alice's yellow-orange mixture, and Bob's yellow-blue mixture, but she cannot isolate the secret colours — mixing paint is easy in one direction and impossible to reverse.

In real Diffie-Hellman, the "mixing" operation is modular exponentiation, which is computationally easy to compute but practically impossible to reverse (the discrete logarithm problem).

How does Diffie-Hellman work mathematically?

The protocol uses two publicly known numbers: a large prime p and a generator g (typically a small number like 2 or 5). Both p and g are shared openly.

Step Alice Bob
1. Choose private secret Chooses secret a (kept private) Chooses secret b (kept private)
2. Compute public value A = g^a mod p (sent to Bob) B = g^b mod p (sent to Alice)
3. Compute shared secret K = B^a mod p K = A^b mod p

Both arrive at K = g^(ab) mod p — the same value — because:

  • Alice computes: B^a = (g^b)^a = g^(ba) mod p
  • Bob computes: A^b = (g^a)^b = g^(ab) mod p

And g^(ba) = g^(ab) in modular arithmetic.

Small worked example (using tiny numbers for illustration — real DH uses numbers with hundreds of digits):

Let p = 23, g = 5. Alice chooses a = 6, Bob chooses b = 15.

Alice Bob
Public value A = 5⁶ mod 23 = 15625 mod 23 = 8 B = 5¹⁵ mod 23 = 30517578125 mod 23 = 19
Shared secret K = 19⁶ mod 23 = 2 K = 8¹⁵ mod 23 = 2

Both arrive at K = 2. Eve sees p = 23, g = 5, A = 8, and B = 19 — but to find a from g^a mod p, she must solve the discrete logarithm problem, which is computationally infeasible for the large numbers used in practice.

Where is Diffie-Hellman used today?

Diffie-Hellman is a core building block of TLS (the protocol behind HTTPS). During the TLS handshake:

  1. The server and client agree on DH parameters.
  2. They exchange public DH values.
  3. Both independently compute the shared secret.
  4. That shared secret generates the symmetric session keys (AES) used to encrypt all subsequent data.

Modern TLS typically uses Ephemeral Diffie-Hellman (DHE) or Elliptic Curve Diffie-Hellman (ECDHE) — variants that generate a fresh key pair for every connection. This property is called Perfect Forward Secrecy (PFS): even if an attacker records encrypted traffic now and later obtains the server's long-term private key, the session keys cannot be reconstructed, because they were derived from ephemeral secrets that were never stored.

What are Diffie-Hellman's limitations?

Limitation Explanation
Not authentication DH establishes a shared key but does not verify who you are talking to — a man-in-the-middle attacker could impersonate both parties
Requires digital certificates In HTTPS, DH is combined with digital certificates and a CA to prove the server's identity, preventing MITM attacks
Discrete log must remain hard Security depends on the difficulty of the discrete logarithm problem — quantum computers could break this in the future

Diffie-Hellman is therefore always used in combination with authentication mechanisms, not as a standalone security solution.

Frequently asked questions

Is Diffie-Hellman a type of encryption?

No. Diffie-Hellman is a key exchange (or key agreement) protocol — it establishes a shared secret key, but does not encrypt any data itself. The shared secret is used as the key for a separate symmetric encryption algorithm (typically AES). DH solves the key distribution problem; AES then uses that shared key to encrypt the actual communication.

Why can't Eve calculate the shared secret if she sees all the public values?

Eve can see p, g, A (= g^a mod p), and B (= g^b mod p). To find Alice's secret a, she must solve: given g, A, and p, find a such that g^a ≡ A (mod p). This is the discrete logarithm problem, which has no known efficient classical algorithm for large numbers. For numbers of the size used in practice (2,048 bits or more), brute-force would take longer than the age of the universe.

What is the difference between Diffie-Hellman and RSA in key exchange?

In RSA key exchange (the older method), the client generates the session key and encrypts it with the server's RSA public key; only the server's private key can decrypt it. In Diffie-Hellman key exchange, neither party sends the key — both compute it independently. DH (especially ephemeral DH) provides Perfect Forward Secrecy because the ephemeral key pairs are discarded after the session; RSA key exchange does not provide PFS.

Do I need to perform Diffie-Hellman calculations in GCSE exams?

At GCSE, you are expected to understand the concept — that two parties can agree on a shared secret over a public channel without an eavesdropper learning it — and be able to describe the paint-mixing analogy. Performing modular exponentiation calculations may appear in the highest-tier questions of some specifications; being able to follow a worked example (as above) with small numbers is a useful preparation.


Explore cryptography and network security with Professor Turing's GCSE support at aitutors.me.