- • A shared generator g and prime p, agreed publicly
- • No pre-existing secret channel required
- • Input: public g, p + each party's private secret
- • Output: identical shared secret K on both sides
- • K typically feeds directly into AES-GCM
- • ECDHE — the TLS 1.3 handshake key exchange
- • SSH session key negotiation
- • Signal / WhatsApp end-to-end encryption setup