Recommended Free Tools
CDH asks an attacker to compute the Diffie–Hellman shared group element; DDH asks whether a candidate element is that shared value or a random one. The distinction matters because a group can make CDH difficult while allowing DDH to be easy. In the standard setting, DDH hardness implies CDH hardness—not the other way around—so a protocol that needs DDH security cannot rely on CDH hardness alone.
What CDH and DDH ask an attacker to do
Let G be a cyclic group of order q, let g be a generator, and choose x and y independently and uniformly from the exponent space (commonly, the integers modulo q). The public elements are gx and gy. The two problems differ in what the attacker must produce:
| Aspect | CDH | DDH |
|---|---|---|
| Full name | Computational Diffie–Hellman | Decisional Diffie–Hellman |
| Challenge | Given g, gx, and gy | Given g, gx, gy, and a candidate T |
| Required result | Compute gxy | Decide whether T equals gxy or is gz for an independent uniformly random exponent z |
| Security statement | Every efficient algorithm succeeds at computing the target only with negligible probability | Every efficient algorithm has only negligible advantage in distinguishing the real target from the random one |
“Efficient” means feasible within the relevant computational model; “negligible” is an asymptotic security term, not a particular bit-security figure. Boneh and Shoup define the assumptions through adversaries’ success probability or distinguishing advantage in these experiments. The exact group and sampling convention are part of the definition, not incidental details.
Which assumption implies which?
A successful CDH solver can be used to distinguish a DDH challenge: compute gxy from the two public powers and compare it with T. If they match, identify the real case; otherwise, identify the random case, subject to the experiment’s negligible collision probability. Thus, an efficient CDH solver would yield an efficient DDH distinguisher.
#1 Best Overall
The implication for hardness goes in the reverse direction: if DDH is hard in a specified group and experiment, CDH must also be hard there, because a CDH solver would break DDH. But CDH hardness alone does not guarantee DDH hardness. A distinguisher may learn whether a candidate is the shared value without being able to compute that value. This is why DDH is called the stronger assumption: relying on it requires ruling out a broader attacker capability.
This distinction is especially relevant to semantic-security proofs. Abdalla, Bellare, and Rogaway explain that CDH hardness can leave open the possibility that an attacker learns meaningful partial information about the shared value; DDH provides the indistinguishability guarantee needed in appropriate settings, such as certain proofs for ElGamal encryption.
Why DDH depends on the group
Neither assumption describes “Diffie–Hellman” independently of its mathematics. The answer depends on the chosen group family, how parameters are generated, and what powers or other structure are available to the adversary. In some groups with useful pairing structure, DDH can be easy even when CDH is still believed hard. Consequently, a claim that a group is CDH-hard does not establish that it is DDH-hard.
When assessing a protocol or a security proof, identify the precise group and check the assumption that the proof actually needs. RFC 8236, the 2017 J-PAKE specification, cites DDH in its selected group as part of its security rationale; that is a group-specific claim, not a blanket guarantee for every Diffie–Hellman implementation.
How the distinction applies to key agreement
In Diffie–Hellman key agreement, one party raises the other party’s public group element to its private exponent. With public values gx and gy, both parties obtain gxy. RFC 2631 describes this shared-secret exchange and the conversion of the shared secret into symmetric keying material.
- CDH models a computation threat: can an eavesdropper recover the shared group element from the public powers?
- DDH models an indistinguishability threat: does the public transcript let an attacker tell the actual shared element from an independent random group element?
The relevant protocol proof determines which guarantee is required. Neither assumption by itself establishes that a complete implementation is secure: authentication, parameter selection, subgroup validation, and implementation behavior are separate concerns.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is there a universal CDH or DDH security number?
No single cost estimate applies to generic CDH or DDH across all groups. The cited definitions give negligible-probability or negligible-advantage conditions, not a universal work factor. Concrete estimates depend on the group, parameter size, known algorithms, and the adversary model. Avoid comparing the assumptions using one universal “bit security” number unless the group and estimation method are specified.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

