Unit content
Key exchange and forward secrecy
A key-exchange protocol lets two parties establish shared secret key material over a channel that an adversary may observe.
The resulting shared secret can be transformed into symmetric session keys used to protect later communication.
Key exchange alone does not necessarily authenticate the peer. If an active adversary can intercept and replace messages, two unauthenticated exchanges can be created instead of one end-to-end exchange: a man-in-the-middle attack.
Protocols therefore combine key agreement with verification of the peer's identity or long-term key.
Forward secrecy means compromise of a long-term authentication key does not reveal past session keys that were established using fresh ephemeral secrets and later erased.
This limits the damage of a future key compromise: recorded historical traffic cannot simply be decrypted from the stolen long-term key alone.
Key establishment and peer authentication are distinct protocol tasks, even when a practical handshake performs both together.