DDH ⇒ KE
Statement
Migrated verbatim from decisional-diffie-hellman § Decisional Diffie-Hellman:
The Decisional Diffie-Hellman (DDH) assumption is a central assumption in cryptography, and one of the first used to construct key exchange DH76. It is implied by the CDH assumption. In other words, an adversary which can solve the CDH problem can also solve DDH in the same group.
Migrated verbatim from key-exchange § Other results:
Notes
class: unstated: no citing page says which notion of reduction is meant.
Recording a class the wiki does not state would add a claim.
This relation is stated on 2 pages; the statements above are all of them.
Recorded during migration and not fixed — these are claims about the source text, not changes to it:
- DH76 predates the DDH assumption; the attribution is historical rather than a security reduction proved in that paper.
- No security notion is stated for the resulting key exchange (passive security under DDH).
- Anachronistic attribution: DH76 predates the formalization of DDH; the DDH-based security proof is much later. Report only.
- Conclusion should arguably be NIKE, not general KE.