On reusing ephemeral keys in Diffie-Hellman key agreement protocols
Alfred Menezes, Berkant Ustaoğlu · International Journal of Applied Cryptography · 2010
A party may choose to reuse ephemeral public keys in a Diffie-Hellman key agreement protocol in order to reduce its computational workload or to mitigate against denial-of-service attacks. In this note, we show that small-subgroup attacks can be successfully launched on some Diffie-Hellman protocols that reuse ephemeral keys if domain parameters are not appropriately selected or if public keys are not appropriately validated.