Part 4 · 1 chapters · ~8 min
Key Exchange
Diffie-Hellman and elliptic curve Diffie-Hellman (X25519), key derivation with HKDF, why exchange needs authentication, man-in-the-middle attacks, forward secrecy, and hybrid post-quantum key exchange.
8
Agreeing on a secret in public
code
import { generateKeyPairSync, diffieHellman, hkdfSync } from 'node:crypto';
const ada = generateKeyPairSync('x25519'), bank = generateKeyPairSync('x25519');
const s1 = diffieHellman({ privateKey: ada.privateKey, publicKey: bank.publicKey });
const s2 = diffieHellman({ privateKey: bank.privateKey, publicKey: ada.publicKey });
s1.equals(s2); // true
const key = Buffer.from(hkdfSync('sha256', s1, 'salt', 'session v1', 32)); // derive an AES-256 keyDIFFIE-HELLMAN KEY EXCHANGE
two parties agree on a shared secret over a public channel
swipe the figure sideways, or tap expand for full screen
1/5
ephemeral secrets
Each side picks a random private value and computes a public value from it (X25519: a point on Curve25519).
random private values, public pointsX25519 is the common choice