Asymmetric & Key Exchange
A track of P52 · Cryptography Foundations.
Agreeing a secret in the open with Diffie–Hellman, its man-in-the-middle gap, and public-key encryption and signatures with toy RSA.
Symmetric encryption needs both sides to already hold the same key. So how did your browser and a server it had never contacted before agree on one, over a network where every packet is visible, in the fraction of a second before this page loaded? Stated plainly it sounds impossible: two strangers shouting across a crowded room, agreeing a secret number that everyone in the room can hear them constructing, and yet nobody else ends up knowing it. That is Diffie-Hellman, and you will build a working toy of it here.
The trick is arithmetic that is easy forwards and hard backwards. Each side picks a private number, publishes a value derived from it, and combines their own private number with the other's published value. Both arrive at the same shared secret; an eavesdropper who saw both published values cannot get there without solving a problem believed to be infeasible at real key sizes. You will implement it with small numbers you can check by hand, confirm both sides compute the same secret, and see exactly which quantities are safe to publish and which must never leave the process.
Then comes the flaw that shapes the rest of the discipline. Diffie-Hellman gives you a secret shared with somebody, and says nothing about who. An attacker positioned in the middle can run the exchange twice — once with each side — and sit transparently between two parties who both believe the channel is private. Nothing in the mathematics detects this. The missing ingredient is authentication, which the track introduces through public-key cryptography: a key pair where one key encrypts and the other decrypts, and signatures where a private key produces something anyone can verify with the public key but nobody else could have produced. You will build toy RSA to see both directions work, which sets up P53 exactly: a certificate is a signature over the statement "this public key belongs to this name".