On reusing ephemeral keys in Diffie-Hellman key agreement protocols

Alfred Menezes, Berkant Ustaoğlu · International Journal of Applied Cryptography · 2010

A party may choose to reuse ephemeral public keys in a Diffie-Hellman key agreement protocol in order to reduce its computational workload or to mitigate against denial-of-service attacks. In this note, we show that small-subgroup attacks can be successfully launched on some Diffie-Hellman protocols that reuse ephemeral keys if domain parameters are not appropriately selected or if public keys are not appropriately validated.

Read the paper · More papers on PaperTik