Analysis of a man-in-the-middle attack on the Diffie-Hellman key exchange protocol
Aaron C. Geary
Abstract
Aaron C. Geary
Abstract
The ability to distribute cryptographic keys securely has been a challenge for centuries. The Diffie-Hellman key exchange protocol was the first practical solution to the key exchange dilemma. The Diffie-Hellman protocol allows two parties to exchange a secret key over unsecured communication channels without meeting in advance. The secret key can then be used in a symmetric encryption application, and the two parties can communicate securely. However, if the key exchange takes place in certain mathematical environments, the exchange becomes vulnerable to a specific man-in-the-middle attack, first observed by Vanstone [1]. We explore this man-in-the-middle attack, analyze countermeasures against the attack, and extend the attack to the multi-party setting.
OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The ability to distribute cryptographic keys securely has been a challenge for centuries. The Diffie-Hellman key exchange protocol was the first practical solution to the key exchange dilemma. The Diffie-Hellman protocol allows two parties to exchange a secret key over unsecured communication channels without meeting in advance. The secret key can then be used in a symmetric encryption application, and the two parties can communicate securely. However, if the key exchange takes place in certain mathematical environments, the exchange becomes vulnerable to a specific man-in-the-middle attack, first observed by Vanstone [1]. We explore this man-in-the-middle attack, analyze countermeasures against the attack, and extend the attack to the multi-party setting.
Key concepts: Key exchange, Diffie–Hellman key exchange, Computer security, Man-in-the-middle attack, Computer science, Key (lock), Protocol (science), Authenticated Key Exchange