Skip to content

fix(DiffieHellman): use each role's own private exponent - #1041

Open
SamuelSchlesinger wants to merge 2 commits into
samschles/fix-dh-call-arityfrom
samschles/fix-dh-role-exponents
Open

SamuelSchlesinger wants to merge 2 commits into
samschles/fix-dh-call-arityfrom
samschles/fix-dh-role-exponents

Conversation

@SamuelSchlesinger

@SamuelSchlesinger SamuelSchlesinger commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Alice computed her public message with Bob's exponent, and Bob computed his shared secret with Alice's exponent. Use Alice's exponent for her public message and Bob's exponent for his shared secret.

The regression checks assert all four role-specific outputs explicitly: Alice's public message is g ^ a, Bob's is g ^ b, and each shared secret uses the receiving role's own exponent. Checking key agreement alone would miss these mistakes.

Depends on #1040 (the shared-secret call-arity fix); this PR targets that branch.

Implemented with Codex.

The evaluator expressed modulus equality as an implication, so a call
with the wrong modulus accepted every result. Require modulus equality
together with the expected computed value.

Adds a regression check rejecting every result for both functions when
the modulus differs, while retaining the valid role-evaluation checks.
The field elements already have type `ZMod params.p`, so the corrected
relation also avoids the old dependent casts.

Depends on #1041 (the role-exponent fix); this PR targets that branch.

Implemented with Codex.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant