Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/2810103.2813707acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
Open access

Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice

Published: 12 October 2015 Publication History


We investigate the security of Diffie-Hellman key exchange as used in popular Internet protocols and find it to be less secure than widely believed. First, we present Logjam, a novel flaw in TLS that lets a man-in-the-middle downgrade connections to "export-grade" Diffie-Hellman. To carry out this attack, we implement the number field sieve discrete log algorithm. After a week-long precomputation for a specified 512-bit group, we can compute arbitrary discrete logs in that group in about a minute. We find that 82% of vulnerable servers use a single 512-bit group, allowing us to compromise connections to 7% of Alexa Top Million HTTPS sites. In response, major browsers are being changed to reject short groups. We go on to consider Diffie-Hellman with 768- and 1024-bit groups. We estimate that even in the 1024-bit case, the computations are plausible given nation-state resources. A small number of fixed or standardized groups are used by millions of servers; performing precomputation for a single 1024-bit group would allow passive eavesdropping on 18% of popular HTTPS sites, and a second group would allow decryption of traffic to 66% of IPsec VPNs and 26% of SSH servers. A close reading of published NSA leaks shows that the agency's attacks on VPNs are consistent with having achieved such a break. We conclude that moving to stronger key exchange methods should be a priority for the Internet community.


S. Bai, C. Bouvier, A. Filbois, P. Gaudry, L. Imbert, A. Kruppa, F. Morain, E. Thomé, and P. Zimmermann.upshape cado-nfs, an implementation of the number field sieve algorithm, 2014. Release 2.1.1.
R. Barbulescu. Algorithmes de logarithmes discrets dans les corps finis. PhD thesis, Université de Lorraine, France, 2013.
R. Barbulescu, P. Gaudry, A. Joux, and E. Thomé. A heuristic quasi-polynomial algorithm for discrete logarithm in finite fields of small characteristic. In Eurocrypt, 2014.
E. Barker, W. Barker, W. Burr, W. Polk, and M. Smid. NIST Special Publication 800--57: Recommendation for Key Management, 2007.
D. J. Bernstein. How to find smooth parts of integers, 2004. http://cr.yp.to/factorization/smoothparts-20040510.pdf.
D. J. Bernstein and T. Lange. Batch NFS. In Selected Areas in Cryptography, 2014.
B. Beurdouche, K. Bhargavan, A. Delignat-Lavaud, C. Fournet, M. Kohlweiss, A. Pironti, P.-Y. Strub, and J. K. Zinzindohoue. A messy state of the union: Taming the composite state machines of TLS. In IEEE Symposium on Security and Privacy, 2015.
C. Bouvier, P. Gaudry, L. Imbert, H. Jeljeli, and E. Thomé. New record for discrete logarithm in a prime finite field of 180 decimal digits, 2014. http://caramel.loria.fr/p180.txt.
R. Canetti and H. Krawczyk. Security analysis of IKE's signature-based key-exchange protocol. In Crypto, 2002.
A. Commeine and I. Semaev. An algorithm to solve the discrete logarithm problem with the number field sieve. In PKC, 2006.
D. Coppersmith. Solving linear equations over GF(2) via block Wiedemann algorithm. Math. Comp., 62(205), 1994.
R. Crandall and C. B. Pomerance. Prime Numbers: A Computational Perspective. Springer, 2001.
B. den Boer. Diffie-Hellman is as strong as discrete log for certain primes. In Crypto, 1988.
W. Diffie and M. E. Hellman. New directions in cryptography. IEEE Trans. Inform. Theory, 22(6):644--654, 1976.
Z. Durumeric, E. Wustrow, and J. A. Halderman. ZMap: Fast Internet-wide scanning and its security applications. In Usenix Security, 2013.
M. Friedl, N. Provos, and W. Simpson. Diffie-Hellman group exchange for the secure shell (SSH) transport layer protocol. RFC 4419, Mar. 2006.
W. Geiselmann, H. Kopfer, R. Steinwandt, and E. Tromer. Improved routing-based linear algebra for the number field sieve. In Information Technology: Coding and Computing, 2005.
W. Geiselmann and R. Steinwandt. Non-wafer-scale sieving hardware for the NFS: Another attempt to cope with 1024-bit. In Eurocrypt, 2007.
D. Gillmor. Negotiated finite field Diffie-Hellman ephemeral parameters for TLS. IETF Internet Draft, May 2015.
D. M. Gordon. Designing and detecting trapdoors for discrete log cryptosystems. In Crypto, 1992.
D. M. Gordon. Discrete logarithms in GF(p) using the number field sieve. SIAM J. Discrete Math., 6(1), 1993.
D. Harkins and D. Carrel. The Internet key exchange (IKE). RFC 2409, Nov. 1998.
T. Jager, K. G. Paterson, and J. Somorovsky. One bad apple: Backwards compatibility attacks on state-of-the-art cryptography. In NDSS, 2013.
A. Joux and R. Lercier. Improvements to the general number field sieve for discrete logarithms in prime fields. A comparison with the Gaussian integer method. Math. Comp., 72(242):953--967, 2003.
C. Kaufman, P. Hoffman, Y. Nir, P. Eronen, and T. Kivinen. Internet key exchange protocol version 2 (IKEv2). RFC 7296, Oct. 2014.
S. Kent. IP authentication header. RFC 4302, Dec. 2005.
S. Kent. IP encapsulating security payload (ESP). RFC 4303, Dec. 2005.
T. Kleinjung. Cofactorisation strategies for the number field sieve and an estimate for the sieving step for factoring 1024 bit integers, 2006. http://www.hyperelliptic.org/tanja/SHARCS/talks06/thorsten.pdf.
T. Kleinjung, K. Aoki, J. Franke, A. K. Lenstra, E. Thomé, J. W. Bos, P. Gaudry, A. Kruppa, P. L. Montgomery, D. A. Osvik, H. te Riele, A. Timofeev, and P. Zimmermann. Factorization of a 768-bit RSA modulus. In Crypto, 2010.
A. Langley, N. Modadugu, and B. Moeller. Transport layer security (TLS) false start. IETF Internet Draft, 2010.
A. K. Lenstra and H. W. Lenstra, Jr., editors. The Development of the Number Field Sieve. Springer, 1993.
M. Lipacis. Semiconductors: Moore stress = structural industry shift. Technical report, Jefferies, 2012.
U. M. Maurer. Towards the equivalence of breaking the Diffie-Hellman protocol and computing discrete logarithms. In Crypto, 1994.
U. M. Maurer and S. Wolf. Diffie-Hellman oracles. In Crypto, 1996.
N. Mavrogiannopoulos, F. Vercauteren, V. Velichkov, and B. Preneel. A cross-protocol attack on the TLS protocol. In ACM CCS, pages 62--72, 2012.
C. Meadows. Analysis of the Internet key exchange protocol using the NRL protocol analyzer. In IEEE Symposium on Security and Privacy, 1999.
Microsoft Security Bulletin MS15-055. Vulnerability in Schannel could allow information disclosure, May 2015. https://technet.microsoft.com/en-us/library/security/ms15-055.aspx.
NIST. FIPS PUB 186--4: Digital signature standard, 2013.
Oak Ridge National Laboratory. Introducing Titan, 2012. https://www.olcf.ornl.gov/titan.
H. Orman. The Oakley key determination protocol. RFC 2412, Nov. 1998.
S. C. Pohlig and M. E. Hellman. An improved algorithm for computing logarithms over $\mathrmGF(p)$ and its cryptographic significance (corresp.). Trans. Inform. Theory, 24(1), 1978.
J. M. Pollard. A Monte Carlo method for factorization. BIT Numerical Mathematics, 15(3):331--334, 1975.
O. Schirokauer. Virtual logarithms. J. Algorithms, 57(2):140--147, 2005.
I. A. Semaev. Special prime numbers and discrete logs in finite prime fields. Math. Comp., 71(237):363--377, 2002.
D. Shanks. Class number, a theory of factorization, and genera. In Proc. Sympos. Pure Math., volume 20. 1971.
Spiegel Staff. Prying eyes: Inside the NSA's war on Internet security. Der Spiegel, Dec 2014. http://www.spiegel.de/international/germany/inside-the-nsa-s-war-on-internet-security-a-1010361.html.
W. Stein et al. Sage Mathematics Software (Version 6.5). The Sage Development Team, 2015. http://www.sagemath.org.
stud: The scalable TLS unwrapping daemon, 2012. https://github.com/bumptech/stud/blob/19a7f19686bcdbd689c6fbea31f68a276e62d886/stud.c#L593.
E. Thomé. Subquadratic computation of vector generating polynomials and improvement of the block Wiedemann algorithm. J. Symbolic Comput., 33(5):757--775, 2002.
P. C. Van Oorschot and M. J. Wiener. Parallel collision search with application to hash functions and discrete logarithms. In ACM CCS, 1994.
P. C. Van Oorschot and M. J. Wiener. On Diffie-Hellman key agreement with short exponents. In Eurocrypt, 1996.
D. Wagner and B. Schneier. Analysis of the SSL 3.0 protocol. In 2nd Usenix Workshop on Electronic Commerce, 1996.
J. Wagnon. SSL profiles part 5: SSL options, 2013. https://devcentral.f5.com/articles/ssl-profiles-part-5-ssl-options.
P. Zimmermann et al. GMP-ECM, 2012. https://gforge.inria.fr/projects/ecm.
APEX active/passive exfiltration. Media leak, Aug. 2009. http://www.spiegel.de/media/media-35671.pdf.
Fielded capability: End-to-end VPN SPIN 9 design review. Media leak. http://www.spiegel.de/media/media-35529.pdf.
FY 2013 congressional budget justification. Media leak. http://cryptome.org/2013/08/spy-budget-fy13.pdf.
GALLANTWAVE@scale. Media leak. http://www.spiegel.de/media/media-35514.pdf.
Innov8 experiment profile. Media leak. http://www.spiegel.de/media/media-35509.pdf.
Intro to the VPN exploitation process. Media leak, Sept. 2010. http://www.spiegel.de/media/media-35515.pdf.
LONGHAUL -- WikiInfo. Media leak. http://www.spiegel.de/media/media-35533.pdf.
POISONNUT -- WikiInfo. Media leak. http://www.spiegel.de/media/media-35519.pdf.
SIGINT strategy. Media leak. http://www.nytimes.com/interactive/2013/11/23/us/politics/23nsa-sigint-strategy-document.html.
SPIN 15 VPN story. Media leak. http://www.spiegel.de/media/media-35522.pdf.
TURMOIL/APEX/APEX high level description document. Media leak. http://www.spiegel.de/media/media-35513.pdf.
TURMOIL IPsec VPN sessionization. Media leak, Aug. 2009. http://www.spiegel.de/media/media-35528.pdf.
TURMOIL VPN processing. Media leak, Oct. 2009. http://www.spiegel.de/media/media-35526.pdf.
VALIANTSURF (VS): Capability levels. Media leak. http://www.spiegel.de/media/media-35517.pdf.
VALIANTSURF -- WikiInfo. Media leak. http://www.spiegel.de/media/media-35527.pdf.
VPN SigDev basics. Media leak. http://www.spiegel.de/media/media-35520.pdf.
What your mother never told you about SIGDEV analysis. Media leak. http://www.spiegel.de/media/media-35551.pdf.

Cited By

View all
  • (2024)Threat-TLS: A Tool for Threat Identification in Weak, Malicious, or Suspicious TLS ConnectionsProceedings of the 19th International Conference on Availability, Reliability and Security10.1145/3664476.3670945(1-9)Online publication date: 30-Jul-2024
  • (2024)IPREDS: Efficient Prediction System for Internet-wide Port and Service ScanningProceedings of the ACM on Networking10.1145/36494702:CoNEXT1(1-24)Online publication date: 28-Mar-2024
  • (2024)Post Quantum Communication Over the Internet InfrastructureProceedings of the 25th International Conference on Distributed Computing and Networking10.1145/3631461.3632514(1-3)Online publication date: 4-Jan-2024
  • Show More Cited By



Information & Contributors


Published In

cover image ACM Conferences
CCS '15: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
October 2015
1750 pages
Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.



Association for Computing Machinery

New York, NY, United States

Publication History

Published: 12 October 2015

Check for updates


  • Best Paper

Author Tags

  1. Diffie-Hellman
  2. internet measurement
  3. logjam
  4. number field sieve
  5. vulnerabilities


  • Research-article

Funding Sources

  • NSF
  • ONR
  • ERC
  • ANR



Acceptance Rates

CCS '15 Paper Acceptance Rate 128 of 660 submissions, 19%;
Overall Acceptance Rate 1,261 of 6,999 submissions, 18%

Upcoming Conference

CCS '24
ACM SIGSAC Conference on Computer and Communications Security
October 14 - 18, 2024
Salt Lake City , UT , USA


Other Metrics

Bibliometrics & Citations


Article Metrics

  • Downloads (Last 12 months)949
  • Downloads (Last 6 weeks)95
Reflects downloads up to 13 Sep 2024

Other Metrics


Cited By

View all
  • (2024)Threat-TLS: A Tool for Threat Identification in Weak, Malicious, or Suspicious TLS ConnectionsProceedings of the 19th International Conference on Availability, Reliability and Security10.1145/3664476.3670945(1-9)Online publication date: 30-Jul-2024
  • (2024)IPREDS: Efficient Prediction System for Internet-wide Port and Service ScanningProceedings of the ACM on Networking10.1145/36494702:CoNEXT1(1-24)Online publication date: 28-Mar-2024
  • (2024)Post Quantum Communication Over the Internet InfrastructureProceedings of the 25th International Conference on Distributed Computing and Networking10.1145/3631461.3632514(1-3)Online publication date: 4-Jan-2024
  • (2024)Investigating TLS Version Downgrade in Enterprise SoftwareProceedings of the Fourteenth ACM Conference on Data and Application Security and Privacy10.1145/3626232.3653263(31-42)Online publication date: 19-Jun-2024
  • (2024)Anti-Quantum Certificateless Group Authentication for Massive Accessing IoT DevicesIEEE Internet of Things Journal10.1109/JIOT.2024.335380711:9(16561-16577)Online publication date: 1-May-2024
  • (2024)CRS: A Privacy-Preserving Two-Layered Distributed Machine Learning Framework for IoVIEEE Internet of Things Journal10.1109/JIOT.2023.328779911:1(1080-1095)Online publication date: 1-Jan-2024
  • (2024)ProInspector: Uncovering Logical Bugs in Protocol Implementations2024 IEEE 9th European Symposium on Security and Privacy (EuroS&P)10.1109/EuroSP60621.2024.00040(617-632)Online publication date: 8-Jul-2024
  • (2024)D(HE)at: A Practical Denial-of-Service Attack on the Finite Field Diffie–Hellman Key ExchangeIEEE Access10.1109/ACCESS.2023.334742212(957-980)Online publication date: 2024
  • (2024)ITor-SDN: Intelligent Tor Networks-Based SDN for Data Forwarding ManagementIEEE Access10.1109/ACCESS.2023.334735012(4792-4800)Online publication date: 2024
  • (2024)Cryptanalysis of Algebraic Verifiable Delay FunctionsAdvances in Cryptology – CRYPTO 202410.1007/978-3-031-68382-4_14(457-490)Online publication date: 18-Aug-2024
  • Show More Cited By

View Options

View options


View or Download as a PDF file.



View online with eReader.


Get Access

Login options







Share this Publication link

Share on social media