Elliptic Curve Diffie-Hellman (ECDH) is a key-agreement protocol in which two parties each combine their own private elliptic-curve key with the other party’s public key to derive an identical shared secret, without transmitting that secret over the network. It provides the same forward-secrecy properties as classical Diffie-Hellman key exchange but with much smaller key sizes for equivalent security, because it relies on the elliptic curve discrete logarithm problem. It is the key-exchange mechanism used in TLS 1.3 and other modern TLS-based encryption to establish ephemeral session keys.

Provenance