Diffie-Hellman Key Exchange Explained: Worked Examples, Security and Exam Traps
Learn what Diffie-Hellman shares, calculate two exchanges by hand, trace an unauthenticated attack, and avoid the most common conceptual and arithmetic errors.
KnowledgeGate Team
Exam prep & CS education

The formula g^(ab) mod p looks simple, but errors usually happen one step earlier, when public values, private exponents and modular powers get mixed up. Diffie-Hellman agrees on key material over a public channel; it does not encrypt a message or prove who is at the other end. Small groups with p = 23 and p = 11 make each modular power reproducible by hand. A man-in-the-middle can still form separate shared secrets with Alice and Bob because correct key-agreement arithmetic does not authenticate either peer.
Related reading: cryptography and network security MCQs.
1. Diffie-Hellman key exchange: what it does and what stays secret
Alice and Bob publish values, then independently derive the same secret. In a proper group, a passive observer cannot feasibly recover it or their exponents.
Item | Alice | Bob | Public or secret |
|---|---|---|---|
Parameters |
|
| Public |
Private exponent |
|
| Secret |
Published value |
|
| Public |
Derived value |
|
| Secret key material |
a and b never cross the channel. Diffie-Hellman produces key material, a key-derivation function makes symmetric keys, and authentication binds identities. K is not ciphertext, a signature or identity proof.
2. Diffie-Hellman mathematics: why both sides obtain the same value
Textbook questions use non-zero residues modulo prime p, with g of the required order. Our p = 23, g = 5 permits hand calculation but provides no security.
Alice calculates:
B^a mod p = (g^b)^a mod p = g^(ba) mod p
Bob calculates:
A^b mod p = (g^a)^b mod p = g^(ab) mod p
Since ab = ba, both reach the same element without sending a, b or g^(ab). Recovering a from p, g, A is the discrete-logarithm problem. Computing the shared value from g^a, g^b without an exponent is the computational Diffie-Hellman problem. Security needs validated parameters and unpredictable exponents.
3. Diffie-Hellman worked example with p = 23
Let p = 23, g = 5, a = 6, and b = 15.
Alice uses repeated squaring:
5^2 mod 23 = 25 mod 23 = 25^4 mod 23 = 2^2 = 4A = 5^6 mod 23 = 5^4 x 5^2 mod 23 = 4 x 2 = 8
Alice sends only A = 8.
Bob splits 15 = 8 + 4 + 2 + 1. Since 5^2 mod 23 = 2, 5^4 mod 23 = 4, and 5^8 mod 23 = 16:
B = 5^15 mod 23 = 16 x 4 x 2 x 5 mod 23 = 640 mod 23 = 19
Bob sends only B = 19.
Alice gets 19^2 mod 23 = 16, then 19^4 mod 23 = 16^2 mod 23 = 3. Therefore 19^6 mod 23 = 3 x 16 mod 23 = 48 mod 23 = 2.
Bob gets 8^2 mod 23 = 18, 8^4 mod 23 = 18^2 mod 23 = 2, and 8^8 mod 23 = 4. Therefore 8^15 mod 23 = 4 x 2 x 18 x 8 mod 23 = 1152 mod 23 = 2.
Both obtain K = 2, a toy group element, not a production key.

4. Diffie-Hellman exam calculation with one private exponent
Given p = 11, g = 2, A = 9, b = 3, find Bob's public value and the shared key.
Bob publishes B = 2^3 mod 11 = 8, then uses Alice's public value:
K = A^b mod p = 9^3 mod 11 = 729 mod 11 = 3
Cross-check: 2^6 mod 11 = 64 mod 11 = 9, so a = 6. Then 8^2 mod 11 = 9, 8^4 mod 11 = 4, and 8^6 mod 11 = 4 x 9 mod 11 = 36 mod 11 = 3.
Given | Find | Correct expression |
|---|---|---|
| Alice's public value |
|
| Bob's public value and key |
|
| Common value | Verify |
Use the other party's public value with your private exponent. Split the exponent into powers of two, reduce each product, then cross-check.
5. Diffie-Hellman man-in-the-middle attack
Return to p = 23, g = 5, Alice's a = 6, A = 8, and Bob's b = 15, B = 19. Mallory sends Alice M_A = 5^7 mod 23 = 17 using m_A = 7, and Bob M_B = 5^3 mod 23 = 10 using m_B = 3.
Alice derives 17^6 mod 23 = 12; Mallory matches it with 8^7 mod 23 = 12. Bob derives 10^15 mod 23 = 5; Mallory matches it with 19^3 mod 23 = 5.
Alice shares 12 with Mallory; Bob shares 5 with Mallory. The arithmetic works, but secrecy is not authentication. Mallory can translate traffic between sessions.
Authenticate the ephemeral public values and transcript through a correctly verified signature or authenticated handshake. A larger prime authenticates nobody.

6. Diffie-Hellman security and protocol layers
Real use needs approved groups, random exponents, public-value validation, side-channel resistance and key derivation. With p = 23, enumerating 5^1 through 5^6 mod 23 gives 5, 2, 10, 4, 20, 8, revealing a = 6 from A = 8.
Static DH reuses a long-term private value. Ephemeral DH creates and later erases fresh session exponents. In a correctly authenticated protocol, this can provide forward secrecy: later compromise of the authentication key does not itself reveal erased session secrets.
Diffie-Hellman is a handshake component, not TCP, UDP, DNS or HTTP. TCP vs UDP: Transport Layer Explained covers transport semantics; Application Layer Protocols: DNS and HTTP Guide gives application-layer context.
7. Diffie-Hellman exam traps and checking routine
Questions may classify values, compute A, B, K, prove equality, name the hard problems, trace the attack, or compare key agreement, encryption, signatures, static DH and ephemeral DH.
Trap | Wrong move | Correction using the worked values |
|---|---|---|
Send a private value | Send | Send |
Use your own public value | Alice calculates | Alice uses |
Delay the modulus | Expand the full power | Reduce each square and product |
Expect equal public values | Require |
|
Call the result ciphertext | Treat | It is toy shared key material |
Assume identity is proven | Say DH authenticates Bob | Mallory creates separate keys |
Trust a tiny group | Call | Enumeration recovers |
Confuse freshness with identity | Say ephemeral DH authenticates a peer | Authentication is still separate |
Check in five steps: list public and private inputs; write the formula; expand the exponent in binary; reduce every value; verify through the other party. The GATE Test Series offers optional timed practice, while GATE CS Exam Preparation is the category route.
8. Diffie-Hellman key exchange: the short version
Publish p, g; keep a, b private. Exchange A = g^a mod p, B = g^b mod p. Calculate B^a mod p, A^b mod p; both equal g^(ab) mod p. Authenticate and derive usable keys.
Do two no-calculator checks. For p = 23, g = 5, a = 6, b = 15, get A = 8, B = 19, K = 2. For p = 11, g = 2, A = 9, b = 3, get B = 8, K = 3.
GATE Guidance by Sanchit Sir is an optional structured route through core CS. Otherwise, revise the exchanges, attack diagram and trap table until every value is reproducible.
Keep learning

Computer Networks Hardware Basics: Devices, Domains and Worked Examples
Learn what hubs, switches, routers, gateways and access points actually do, then count network domains and trace frames through a two-LAN topology.

Data Link Layer Framing Explained: Byte Stuffing, Bit Stuffing and a Cross-Concept Numerical
Frame one four-byte payload in two ways, decode it, and then reuse the verified frame sizes in link-load and Stop-and-Wait calculations.

Byte Stuffing in Computer Networks: Worked Framing Example and Exam Traps
Learn a precise byte-stuffing convention, trace a payload containing both FLAG and ESC, reverse it safely, and calculate frame overhead and transmission time.

Go-Back-N Protocol Explained: Sliding Windows, Worked Numericals and Exam Traps
Trace Go-Back-N through a lost frame, calculate its legal window and link utilisation, and avoid the ACK and wrap-around traps that spoil numericals.