Crypto Lab

Course module

Key exchange & secure channels

Fits the key-exchange or TLS unit of an undergraduate computer networking, network security, or introductory cryptography course. The extension exhibit suits an upper-level security or formal-methods course that introduces symbolic protocol analysis.

Audience
Undergraduate computer science, networking, and security students, and motivated newcomers, who can follow modular arithmetic and want to see how two parties agree on a key over an open network and what stops an attacker from sitting in the middle.
Class time
About 64 minutes of class time for the core sequence, plus about 19 minutes of extension. Predict is pre-class reading and Explain is a spoken debrief.
Last checked
2026-09-22

Ready to teach

Class time
About 64 minutes for the core sequence, plus about 19 minutes of extension. Predict is pre-class reading and Explain is a spoken debrief.
Checked in
Chromium 153, Firefox 155 and WebKit 26.6, at desktop width and phone width.
Known issues
Protocol Checker (WebKit 26.6). What the checks found. Last re-derived against the live page 2026-09-22.

Prerequisites

Learning outcomes

  1. Students will be able to contrast a passive eavesdropper with an active man-in-the-middle against Diffie–Hellman, and identify which threat larger parameters address and which one requires authentication.
  2. Students will be able to trace a TLS 1.3 handshake message by message, stating for each step which keys are derived and which transcript a signature or Finished MAC covers.
  3. Students will be able to predict which TLS 1.3 verification check fails under a given fault or attacker strategy, and justify the prediction from what that check binds.
  4. Students will be able to demonstrate a supported_groups downgrade against an unbound negotiation and explain how transcript binding through the Finished MAC makes the same strip abort.
  5. Students will be able to evaluate server and client policies (PQC preferred versus required, fail-open versus fail-closed retry) for whether they let an on-path attacker force a downgrade.

Sequence

Protocol Checker: Its class sequence is a demonstration of symbolic protocol analysis rather than one of this module's outcomes: the Diffie-Hellman arc that served outcome 1 moved into Fix / Extend when the worksheet was cut to its budget.

Each exhibit opens in its own site. Roles: Intro builds the idea, Break it has students cause the failure, Fix shows the construction that holds, and Extension is optional depth.

ExhibitRoleTimeWorksheet
DH MITMIntro19 minWorksheet for DH MITM
Run a Diffie–Hellman exchange on the parameter presets, press Break it to recover Alice's secret exponent by baby-step giant-step, run Mallory's man-in-the-middle to leave Alice and Bob with two different keys, then run the ECDSA-signed exchange honest and tampered to watch it fail closed.
Cite this exhibit: Clark, P. A. (2026). DH MITM [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-diffie-hellman-mitm/
TLS HandshakeFix24 minWorksheet for TLS Handshake
Step through the eight handshake steps reading the transcript-hash chip, check that both sides compute the same X25519 secret, inject each fault in Break this handshake and each attacker move in the MITM panel to see which verifier checks fail, then press New session and compare which values change.
Cite this exhibit: Clark, P. A. TLS Handshake [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-tls-handshake/
Downgrade WireBreak it21 minWorksheet for Downgrade Wire
Play the downgrade, then strip X25519MLKEM768 and run it unbound and under TLS 1.3 (or Compare both), expand Show the Finished MAC to follow the byte diff, and flip the server policy, sentinel checks, and retry policy to see which settings let the downgrade through.
Cite this exhibit: Clark, P. A. Downgrade Wire [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-downgrade-wire/
Protocol CheckerExtension19 minWorksheet for Protocol Checker
Run the search on Needham-Schroeder Public Key, step the attack trace and attacker-knowledge panel to watch the attacker derive Nb, tick Lowe's fix and re-run, then switch to Diffie-Hellman and toggle signatures.
Cite this exhibit: Clark, P. A. Protocol Checker [Interactive teaching demonstration]. Crypto Lab. Retrieved [date accessed], from https://systemslibrarian.github.io/crypto-lab-protocol-checker/

Hand-out: every worksheet in this module, in sequence order

What students hand in

Two-run handshake trace. One honest run and one attacked run of the same protocol, set side by side from the student's own Record tables, naming the field that differs, the check that did or did not notice, and the run of messages that check is computed over. It has to say which of the two threats the difference speaks to — an eavesdropper, or a party in the middle.

It is drawn from what the worksheets already produce, so it adds no new task. Values differ from run to run, so there is no key to mark against: what a marker is reading is whether each claim is tied to something the student recorded, and whether the reasoning from it holds.

Discussion questions

  1. Mallory solves no discrete logarithm in the Diffie–Hellman lab. What does she exploit instead, and why does switching to the 2048-bit group leave her attack untouched?
  2. Under the TLS lab's 'Break the ECDHE agreement' fault, the certificate chain and CertificateVerify still verify. What does that tell you about the difference between knowing who your peer is and sharing keys with it?
  3. The TLS MITM panel's 'Relay unchanged' move passes the client's checks. Should that count as a successful attack? What does the attacker end up holding?
  4. Downgrade Wire can show 'Handshake COMPLETED' beside 'DOWNGRADE — ALARM'. Why does the lab keep the cryptographic result and the security verdict as separate indicators, and what goes wrong if they are merged?
  5. Transcript binding makes the strip fail closed. How can a client's retry policy hand the attacker the downgrade anyway, and what does 'PQC required' cost in exchange for stopping the silent downgrade?

Instructor notes

These notes are public, and they are conceptual on purpose: they describe what students should notice and why, never the specific values a run produces.

Expected observations

Common misconceptions

Conceptual answers

Checks

Browser support. Every exhibit in this module, and every step of its worksheet, was run in Chromium, Firefox and WebKit at a desktop width and at a phone width (1280 by 720 and 390 by 720), checked 2026-09-22. One exhibit needs a word of warning:

Privacy. Opening these exhibits sends nothing to anyone but the site they are served from: no exhibit sets a cookie, and none stores anything beyond the setting that pins its dark theme. The exception:

Detailed check results — engine versions, every step run, transfer sizes, and the source line behind each run-specific verdict. The worksheet drift check reads this module’s anchors manifest.

For your syllabus

Crypto Lab exhibits are teaching demonstrations, not production libraries. Do not use exhibit code to protect real data. https://crypto-lab.systemslibrarian.dev/teach/key-exchange/

How to cite this module’s exhibits

Each exhibit's citation is in the Sequence table above, in that exhibit's own row. Exhibits change as they are improved, so the retrieval date is what says which version you used; it is filled in from your device's clock when the page loads.

BibTeX
@misc{clark_diffie_hellman_mitm,
  author       = {Clark, Paul A.},
  title        = {DH MITM},
  year         = {2026},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-diffie-hellman-mitm/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_tls_handshake,
  author       = {Clark, Paul A.},
  title        = {TLS Handshake},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-tls-handshake/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_downgrade_wire,
  author       = {Clark, Paul A.},
  title        = {Downgrade Wire},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-downgrade-wire/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

@misc{clark_protocol_checker,
  author       = {Clark, Paul A.},
  title        = {Protocol Checker},
  howpublished = {\url{https://systemslibrarian.github.io/crypto-lab-protocol-checker/}},
  note         = {Crypto Lab. Accessed [date accessed]}
}

To cite the whole collection, see How to cite.