Skip to main content
Calcimator

Diffie-Hellman Key Exchange Calculator

Calculate Diffie-Hellman key exchange parameters, shared secret, and security analysis.

About this calculator

Diffie-Hellman lets two parties agree on a shared secret over a channel an eavesdropper can watch, without ever transmitting the secret itself. Alice and Bob each pick a private key (a and b) that never leaves their own side, and publicly exchange only A = g^a mod p and B = g^b mod p. Alice then computes B^a mod p, Bob computes A^b mod p, and because (g^b)^a = (g^a)^b = g^(ab), both land on the identical shared secret without either ever having sent a or b in the clear.

An eavesdropper who intercepts p, g, A, and B still cannot efficiently recover a or b — that would require solving the discrete logarithm problem, and the best known general-purpose algorithms for it run in roughly the square root of the modulus p, which is astronomically slow once p is a realistic cryptographic size. This calculator's default modulus is small enough for a browser to brute-force in microseconds, which is exactly the point: it is a textbook-scale demonstration of the arithmetic, not a security parameter. Real-world Diffie-Hellman uses primes of at least 2048 bits — a number with over 600 decimal digits — precisely because the discrete-log difficulty has to outpace realistic computing power for decades, not the lifetime of a JavaScript function call.

Inputs

Results

Alice's Public Key

8

Bob's Public Key

19

Shared Secret

2

Security Level

4.5 bits

Discrete Log Complexity4.8
How to Use This Calculator
  1. Enter the prime modulus (p) and generator (g) values.
  2. Set each party private key value.
  3. Review the public keys and shared secret computed by the DH protocol.
  4. Verify the shared secret matches on both sides to confirm the protocol works correctly.
  5. Use group sizes of at least 2048 bits in production -- 768 and 1024-bit groups are deprecated.

How the result changes with Generator (g)

Generator (g)Alice's Public KeyBob's Public KeyShared Secret
2.58.4136.7
3.759.43.28.5
7.518.912.65.8
136188

What each input means

Prime Modulus (p)
Large prime number
Generator (g)
Primitive root modulo p
Alice's Private Key (a)
Alice's secret private key
Bob's Private Key (b)
Bob's secret private key

How this is calculated

Formula

Shared Secret = (g^a)^b mod p = (g^b)^a mod p

Worked example, using the default values

  1. Identify Input Parameters
    4 parameters
    Prime Modulus (p) = 23, Generator (g) = 5, Alice's Private Key (a) = 6, Bob's Private Key (b) = 15 = 4 input(s) provided
  2. Calculate Alice's Public Key
    Alice's Public Key
    8 = 8
  3. Calculate Bob's Public Key
    Bob's Public Key
    19 = 19
  4. Calculate Shared Secret
    Shared Secret
    2 = 2
  5. Calculate Discrete Log Complexity
    Discrete Log Complexity
    4.8 = 4.8

Engine last updated . Checked against 3 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.

Frequently Asked Questions

How can Alice and Bob get the same secret without sending it?

They each combine their own private key with the other party's public key using modular exponentiation, and the algebra works out so both computations land on the same value: (g^b)^a mod p equals (g^a)^b mod p because exponents multiply regardless of order. Only the public keys A and B ever cross the channel; the private keys a and b never do.

Why is a small prime modulus like this calculator's default insecure?

Security depends on the discrete logarithm problem being computationally infeasible to solve, and its difficulty scales with the size of the prime modulus. A small modulus like the one this calculator defaults to can be brute-forced in microseconds by any computer, which is why real Diffie-Hellman implementations require primes of at least 2048 bits to stay ahead of realistic attacker computing power.

What does the security level in bits actually mean here?

It approximates the discrete logarithm problem's difficulty as log base 2 of the prime modulus, giving a rough sense of how many steps a brute-force search over the exponent space would take. It is a simplified textbook approximation, not the same rigorous bit-security estimate cryptographic standards bodies publish for real-world key sizes.

Does Diffie-Hellman by itself protect against a man-in-the-middle attack?

No. Plain Diffie-Hellman authenticates nothing — an attacker who can intercept and relay traffic can run the protocol separately with each party and end up holding two shared secrets, one with Alice and one with Bob, without either noticing. Real deployments add authentication, typically via digital signatures or certificates, on top of the key exchange to close this gap.

The questions that sit next to this one — chosen by subject, including calculators filed under a different category.

More in Technology & Computing.