Things Have History
Diffie, Hellman, and the key two strangers can share

cryptography

Diffie, Hellman, and the key two strangers can share

Listen · 4:23

Picture two people who have never met, speaking on a telephone line that a third person is recording. They need to agree, before the call ends, on a secret the third person cannot know — no courier, no codebook, no prior arrangement. For most of recorded cryptographic history, every expert who thought seriously about this problem came back with the same answer: it cannot be done. A secret shared over an open channel is a contradiction in terms.

Whitfield Diffie did not believe that. In 1973, he left his position at Stanford’s Artificial Intelligence Laboratory to find out why. His father, a history professor, had once carried home the entire crypto shelf of the City College Library in New York for a ten-year-old Diffie to read, and that habit of thought had followed him. He was now spending his savings on what he later described as “digging up rare manuscripts in libraries, driving around, visiting friends at universities.” His girlfriend Mary Fischer came along. In the summer of 1974, a stop at IBM’s Thomas J. Watson Research Center in Yorktown Heights, New York, produced an unexpected lead: a cryptographer named Alan Konheim, unable to discuss his own classified work, suggested Diffie go meet Martin Hellman, an electrical engineering professor at Stanford who was, independently, bothered by the same problem.

Their planned half-hour meeting lasted most of the day.

Hellman hired Diffie as a part-time research programmer in spring 1975. Together, and drawing on earlier work by Ralph Merkle — a Berkeley undergraduate whose 1974 proposal for asymmetric key exchange had been dismissed by his professor as unworkable before it eventually reached Hellman — they developed what became the Diffie–Hellman key exchange. The mathematics rests on an asymmetry in the discrete logarithm problem: computing g^a from a is straightforward; recovering a from g^a alone, for large enough numbers, is computationally infeasible. Two parties exchange public values over an open channel, each applies their private exponent, and both arrive at the same shared secret — one that was never transmitted. Their paper, “New Directions in Cryptography,” appeared in the IEEE Transactions on Information Theory in November 1976 and opened with what turned out to be an accurate sentence: “We stand today on the brink of a revolution in cryptography.”

The paper credited Merkle; Hellman later argued it should properly be called the Diffie–Hellman–Merkle key exchange to reflect his essential contribution. That name has not reached the textbooks. Merkle’s share of the invention appears in every careful history and in the 2015 ACM Turing Award citation that Diffie and Hellman received — but not in the name most engineers type into their terminal.

The last detail surfaced in 1997. GCHQ, Britain’s signals intelligence agency, declassified a set of internal papers showing that James Ellis, Clifford Cocks, and Malcolm Williamson had developed essentially the same concept between 1969 and 1973 — years before the Stanford paper. The work had been classified immediately and filed away while Diffie drove across America looking for an answer nobody was supposed to have found yet. Ellis died two months before GCHQ released the documents. He never got to tell anyone.

Every HTTPS connection your browser opens negotiates its session key using the principle Diffie mapped out on that road trip: two strangers, on a wire anyone can tap, arriving at a secret nobody else can reconstruct. The courier is still out there — he just doesn’t carry anything anymore.

Sources

Spot a mistake?

Wrong date, broken citation, a fact that doesn't hold? Tell us. It lands in an inbox a human reads and the post can be pulled or corrected.