Key‐Exchange Algorithms
Bruce Schneier · 2015
This chapter discusses a list of public key-exchange algorithms including Diffie-Hellman key-exchange protocol, station-to-station protocol, Shamir's three-pass protocol, communications setup (COMSET), encrypted key exchange (EKE) protocol, fortified key negotiation scheme, and conference key distribution. COMSET is a mutual identification and key exchange protocol developed for the RIPE project. The mathematical principle behind COMSET is Rabin's scheme. The Encrypted Key Exchange (EKE) protocol provides security and authentication on computer networks, using both symmetric and public-key cryptography in a novel way: A shared secret key is used to encrypt a randomly generated public key. EKE can be implemented with a variety of public-key algorithms: RSA, ElGamal, Diffie-Hellman. There are security problems with implementing EKE with a knapsack algorithm (aside from the inherent insecurity of knapsack algorithms): The normal distribution of the ciphertext messages negates the benefits of EKE.