Diffie-Hellman Key Exchange Calculator
Calculate Diffie-Hellman key exchange parameters, shared secret, and security analysis.
About this calculator
Diffie-Hellman lets two parties agree on a shared secret over a channel an eavesdropper can watch, without ever transmitting the secret itself. Alice and Bob each pick a private key (a and b) that never leaves their own side, and publicly exchange only A = g^a mod p and B = g^b mod p. Alice then computes B^a mod p, Bob computes A^b mod p, and because (g^b)^a = (g^a)^b = g^(ab), both land on the identical shared secret without either ever having sent a or b in the clear.
An eavesdropper who intercepts p, g, A, and B still cannot efficiently recover a or b — that would require solving the discrete logarithm problem, and the best known general-purpose algorithms for it run in roughly the square root of the modulus p, which is astronomically slow once p is a realistic cryptographic size. This calculator's default modulus is small enough for a browser to brute-force in microseconds, which is exactly the point: it is a textbook-scale demonstration of the arithmetic, not a security parameter. Real-world Diffie-Hellman uses primes of at least 2048 bits — a number with over 600 decimal digits — precisely because the discrete-log difficulty has to outpace realistic computing power for decades, not the lifetime of a JavaScript function call.
Inputs
Results
Alice's Public Key
8
Bob's Public Key
19
Shared Secret
2
Security Level
4.5 bits
How to Use This Calculator
- Enter the prime modulus (p) and generator (g) values.
- Set each party private key value.
- Review the public keys and shared secret computed by the DH protocol.
- Verify the shared secret matches on both sides to confirm the protocol works correctly.
- Use group sizes of at least 2048 bits in production -- 768 and 1024-bit groups are deprecated.
How the result changes with Generator (g)
| Generator (g) | Alice's Public Key | Bob's Public Key | Shared Secret |
|---|---|---|---|
| 2.5 | 8.4 | 13 | 6.7 |
| 3.75 | 9.4 | 3.2 | 8.5 |
| 7.5 | 18.9 | 12.6 | 5.8 |
| 13 | 6 | 18 | 8 |
What each input means
- Prime Modulus (p)
- Large prime number
- Generator (g)
- Primitive root modulo p
- Alice's Private Key (a)
- Alice's secret private key
- Bob's Private Key (b)
- Bob's secret private key
How this is calculated
Formula
Shared Secret = (g^a)^b mod p = (g^b)^a mod pWorked example, using the default values
- Identify Input Parameters4 parametersPrime Modulus (p) = 23, Generator (g) = 5, Alice's Private Key (a) = 6, Bob's Private Key (b) = 15 = 4 input(s) provided
- Calculate Alice's Public KeyAlice's Public Key8 = 8
- Calculate Bob's Public KeyBob's Public Key19 = 19
- Calculate Shared SecretShared Secret2 = 2
- Calculate Discrete Log ComplexityDiscrete Log Complexity4.8 = 4.8
Engine last updated . Checked against 3 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
How can Alice and Bob get the same secret without sending it?
They each combine their own private key with the other party's public key using modular exponentiation, and the algebra works out so both computations land on the same value: (g^b)^a mod p equals (g^a)^b mod p because exponents multiply regardless of order. Only the public keys A and B ever cross the channel; the private keys a and b never do.
Why is a small prime modulus like this calculator's default insecure?
Security depends on the discrete logarithm problem being computationally infeasible to solve, and its difficulty scales with the size of the prime modulus. A small modulus like the one this calculator defaults to can be brute-forced in microseconds by any computer, which is why real Diffie-Hellman implementations require primes of at least 2048 bits to stay ahead of realistic attacker computing power.
What does the security level in bits actually mean here?
It approximates the discrete logarithm problem's difficulty as log base 2 of the prime modulus, giving a rough sense of how many steps a brute-force search over the exponent space would take. It is a simplified textbook approximation, not the same rigorous bit-security estimate cryptographic standards bodies publish for real-world key sizes.
Does Diffie-Hellman by itself protect against a man-in-the-middle attack?
No. Plain Diffie-Hellman authenticates nothing — an attacker who can intercept and relay traffic can run the protocol separately with each party and end up holding two shared secrets, one with Alice and one with Bob, without either noticing. Real deployments add authentication, typically via digital signatures or certificates, on top of the key exchange to close this gap.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
RSA Key Strength Calculator
Calculate RSA key strength, equivalent symmetric key length, brute force time, and security margins.
Cryptography & SecurityElliptic Curve Cryptography Calculator
Calculate ECC key strength, equivalent RSA key length, security level, and cryptographic parameters.
Cryptography & SecurityEncryption Key Space Calculator
Calculate encryption key space size, brute force time, and security level for cryptographic algorithms.
More in Technology & Computing.