Home/Labs/TLS & ECDHE Key Exchange
All 280 Labs
INTERACTIVE LAB🔑

TLS Handshake & Encryption Lab (Interactive)

Compute the real Diffie-Hellman shared secret with BigInt modular exponentiation and compare TLS 1.2 vs 1.3. Step through ClientHello to Finished with live g^a mod p math, forward-secrecy reasoning, and 2-RTT versus 1-RTT versus 0-RTT latency.

TLS Handshake & ECDHE Key Exchange Lab

Compute the real Diffie-Hellman shared secret (g^ab mod p) with BigInt modular exponentiation, then compare 1.2 vs 1.3 handshake latency.

Live ECDHE math (modPow, BigInt)
g = 3, p = 257
Client: A = g^a mod p = 132
Server: B = g^b mod p = 173
Client computes S = B^a mod p = 100
Server computes S = A^b mod p = 100
Secrets match — S never travels on the wire
TCP handshake
40 ms
1 RTT
TLS 1.3 handshake
40 ms
1 RTT
Time to first byte
80 ms
50% faster than 1.2

ClientHello

SENT

Client sends supported groups + ECDHE key_share A = g^a mod p = 132 in the very first flight. TLS 1.3 removed RC4, 3DES, MD5 and static RSA key exchange — only ECDHE with AES-GCM/ChaCha20 remains.

ServerHello + Certificate + Finished

PENDING

Server replies with key_share B = g^b mod p = 173, its X.509 certificate chain (Root CA → Intermediate → end-entity), and a signed CertVerify. Both sides now derive S = g^(ab) mod p independently — the secret itself never crosses the wire.

Finished + encrypted HTTP request

PENDING

Client verifies the certificate chain against its ~150 trusted roots and sends Finished plus the first AES-256-GCM encrypted request. Secure channel established in 1 RTT.

Forward secrecy: because a and b are ephemeral and discarded, stealing the server certificate key later cannot decrypt recorded past traffic.

How It Works Under the Hood

TLS uses hybrid encryption: slow asymmetric operations only to negotiate keys, then fast symmetric AES-256-GCM or ChaCha20 for the payload. With ECDHE, the client picks a private value a and publishes g^a mod p; the server does the same with b; both independently compute S = g^(ab) mod p, a secret that never crosses the wire. Because a and b are ephemeral and discarded, Perfect Forward Secrecy holds even if the certificate key is stolen later. TLS 1.3 folded the key share into the first flight, halving handshake latency to 1 RTT and enabling 0-RTT resumption — at the price of replay vulnerability on non-idempotent requests.

Core Architectural Principles

  • Shared secret S = B^a mod p = A^b mod p computed on both sides via modular exponentiation.
  • TLS 1.2 costs 2 RTTs and allowed RC4/3DES/static RSA; TLS 1.3 allows only ECDHE AEAD suites in 1 RTT.
  • Trust chain: Root CA → Intermediate CA → end-entity certificate, verified against ~150 browser-trusted roots.
Interview Round Script

Explain handshake cost architecturally: TLS 1.3 is 1 RTT (0-RTT for returning clients), so edge CDNs that terminate TLS near users cut hundreds of milliseconds globally. Mention OCSP stapling as the latency-free revocation check and mTLS for service-to-service identity — the follow-ups interviewers always probe after a security answer.

Key Trade-Offs

1-RTT and 0-RTT speed versus 0-RTT replay risk on side-effecting requests, mitigated by server-side anti-replay caches.

Related Curriculum Chapter

TLS/SSL Handshake & Encryption Basics

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs