Key exchange
A key exchange (or key agreement) protocol allows two parties communicating over a public, authenticated channel to establish a shared secret key that is computationally indistinguishable from uniformly random to any eavesdropper. Unlike PKE, key exchange does not require a pre-established public key infrastructure.
Syntax
A two-party key exchange protocol is a pair of interactive algorithms run between parties and over a shared transcript. Following execution, both parties output a key . In the non-interactive setting:
- where and each party publishes , then computes .
Properties
Correctness
Both parties output the same key with probability 1 (over their randomness).
Security (indistinguishability from random)
A key exchange protocol is secure if for all efficient adversaries that observe the full transcript, the session key is computationally indistinguishable from a uniformly random key .
Variations
Non-interactive key exchange (NIKE)
A NIKE allows any two parties to derive the same shared key from each other’s public keys alone, with no interaction at all. Diffie-Hellman over a cyclic group is the canonical example: given public keys and .
Authenticated key exchange (AKE)
An AKE additionally guarantees that the parties authenticate each other’s identities during the protocol, preventing man-in-the-middle attacks.
Multi-party key exchange
Generalizes two-party KE to parties. Requires additional rounds or structure (e.g., Burmester-Desmedt, pairing-based constructions).
Other results
- DDH ⇒ KE
- KE ⇒ PKE
- No reduction from OWP to KE
- No reduction from ROM to KE
- LWE ⇒ PKE
- PKE ⇒ KE
- No reduction from ROM to KE
Participates in
Builds on Key exchange
Produces Key exchange
Barriers