Diffie–Hellman key exchange is a method that lets two parties agree on a shared secret key over an insecure channel without ever sending the key itself.
How Diffie–Hellman works
The protocol was published by Whitfield Diffie and Martin Hellman in 1976 and is the first practical example of public-key cryptography. Both sides agree on public parameters, each picks a secret number and sends the other a value derived from it. Combining their own secret with the value received, both arrive at the same result, while an eavesdropper who sees only the exchanged values would have to solve the discrete logarithm problem to obtain it. The shared secret is then used to derive symmetric session keys.
Modern systems mostly use the elliptic-curve variant (ECDH), especially X25519 (RFC 7748). When fresh keys are generated for every session (DHE or ECDHE), a later theft of a server’s long-term key does not expose past traffic – a property called forward secrecy.
Why Diffie–Hellman matters
Ephemeral Diffie–Hellman is mandatory in TLS 1.3 and is used in SSH, IPsec VPNs, WireGuard and the Signal protocol. Its known weaknesses are well understood:
- No authentication by itself – an attacker in a man-in-the-middle position can run separate exchanges with each side, so the exchanged values must be signed or tied to certificates.
- Weak groups – the 2015 Logjam attack was a downgrade attack that forced TLS servers to use 512-bit “export-grade” groups, which could be broken quickly.
- Quantum threat – Shor’s algorithm would break classic and elliptic-curve Diffie–Hellman, so browsers and messengers now combine X25519 with post-quantum ML-KEM in hybrid key exchanges.
Best practices
- Use ECDHE with X25519 or NIST P-256, or finite-field groups of at least 2048 bits.
- Disable export ciphers and static (non-ephemeral) key exchange.
- Always authenticate the exchange with certificates or pinned keys.
- Enable hybrid post-quantum key exchange where supported.