๐Ÿ”‘ Diffie-Hellman Key Exchange Demo

This is an educational demo. Small numbers are not suitable for real security.

Aliceโ€™s public key (A = g^a mod p)8
Bobโ€™s public key (B = g^b mod p)19
Shared secret (Aliceโ€™s side: B^a mod p)2
Shared secret (Bobโ€™s side: A^b mod p)2
โœ“ Both sides computed the same shared secret

Enter a prime p, a generator g, and both partiesโ€™ private keys (a, b) to see how the Diffie-Hellman key exchange algorithm computes public keys and a shared secret. Confirm for yourself that both sides independently arrive at the same shared secret via different calculation paths.

How to use

  1. Enter the prime p and generator g.
  2. Enter Aliceโ€™s and Bobโ€™s private keys (a, b).
  3. The public keys (A, B) and the matching shared secret computed by each side are shown automatically.

How the calculation works

Diffie-Hellman (DH) key exchange, published by Diffie and Hellman in 1976, lets two people agree on a shared secret over a channel that is being eavesdropped. This tool demonstrates it with small numbers. 1. Both agree publicly on a prime p and a generator g. 2. Alice picks a secret a and sends A = g^a mod p. 3. Bob picks a secret b and sends B = g^b mod p. 4. Alice computes B^a mod p; Bob computes A^b mod p. Both results equal g^(ab) mod p, so they share the same value. An eavesdropper who knows p, g, A and B still cannot compute it, because recovering a or b (the discrete logarithm problem) is extremely hard.

Worked example

p = 23, g = 5, Alice's secret a = 6, Bob's secret b = 15 Alice's public value: A = 5โถ mod 23 = 8 Bob's public value: B = 5ยนโต mod 23 = 19 Alice computes: 19โถ mod 23 = 2 Bob computes: 8ยนโต mod 23 = 2 Shared secret: 2 (they match)

Things to be aware of

  • With numbers this small, the secrets are easy to find by brute force. Real systems use primes of 2048 bits or more, or elliptic-curve ECDH.
  • Diffie-Hellman alone does not prove who you are talking to (man-in-the-middle attacks). TLS combines it with certificate-based authentication.
  • This demo does not check that p is prime. Enter a prime for p to see it work properly.

FAQ

What is Diffie-Hellman key exchange?

An algorithm that lets two parties with no prior shared secret establish a common secret key over an insecure channel. It underlies many encrypted protocols, including TLS.

Why do both sides get the same shared secret?

Because of the laws of exponents: (g^a)^b mod p and (g^b)^a mod p are always mathematically equal.

Can I use these small numbers for real security?

No โ€” this is an educational demo to illustrate the mechanism. Real-world use requires very large primes (2048 bits or more).