crypto
← Back to practices Practice 07

Toy ECDH

Follow scalar multiplication bit by bit and agree on a secret point with ECDH. Compare RTL and LTR algorithms with integers up to 2048 bits.

Public parameters

y² = x³ + ax + b mod p

P for kP; G for ECDH (x1, y1, z1)

Normalized points (x1, y1, 1); infinity (0, 1, 0). ECDH requires at least 7-bit p and finite points. Prime validation uses 32 Miller–Rabin rounds.

Scalar multiplication

Compare every iteration: RTL reads bits from least significant to most significant; LTR reads them in reverse.

Each row shows Q and P after the iteration. RTL shows the doubled working P; LTR keeps P fixed.

Local ECDH simulation

A = rG · B = sG
K_A = rB · K_B = sA

Alice uses RTL and Bob uses LTR. Example secrets are public and intended for reproducible testing.

Exchange between two computers

Agree on p, a, b and G. Each person generates a secret on their own computer and shares only A or B. Enter the received public key here and compute your K.

B · received public key (x2, y2, z2)

Educational implementation: rand() generates toy secrets. No authentication, KDF, subgroup-order verification or constant-time execution. K is a point, not an encryption-ready key.