2026-08-15
For 3,000 years, cryptography had one unbreakable rule: to share a secret message, you first had to share a secret key. Caesar's generals carried scytales. WWII U-boats carried Enigma codebooks. Every scheme required physical, prearranged trust. In a world where any two computers might suddenly need to communicate securely — without ever meeting — this was a dead end.
The insight. Whitfield Diffie, a nomadic researcher who once drove across the country hunting cryptography papers, teamed with Stanford professor Martin Hellman and a Berkeley undergraduate named Ralph Merkle. Together they proposed something that sounded impossible: a trapdoor function — easy to compute forward, effectively impossible to reverse — could let two strangers exchange numbers in the clear and derive an identical secret that no eavesdropper could recover.
The math. Alice picks a private number a; Bob picks b. Given public values g and prime p, Alice sends g^a mod p; Bob sends g^b mod p. Each raises the other's value to their private exponent — both compute g^(ab) mod p. An observer sees g^a and g^b but must solve the discrete logarithm problem to recover the shared key. Believed infeasible. Still believed infeasible.
The patent.
The paper preceded the patent: "New Directions in Cryptography" (IEEE Transactions on Information Theory, November 1976) — arguably the most consequential cryptography paper ever published.
The NSA tried to bury it. In 1977, an NSA-affiliated engineer named J.A. Meyer warned that publishing cryptography research might violate export controls administered like arms dealing. Hellman consulted Stanford's lawyers, published anyway, and established the precedent that academic cryptography is protected speech. Two decades later, declassified GCHQ files revealed that James Ellis, Clifford Cocks, and Malcolm Williamson had discovered essentially the same math in 1969–1974 — and locked it in a safe until 1997.
Modern impact. Every browser padlock you see was negotiated by Diffie-Hellman or its elliptic-curve descendant ECDH. TLS 1.3 mandates it. Signal's Double Ratchet, WireGuard tunnels, SSH sessions, WhatsApp end-to-end encryption, Bitcoin's ECDSA, Apple's iMessage — all descend from patent 4,200,770. Roughly a billion new session keys are exchanged every second on Earth using this idea.
Merkle's forgotten role. Ralph Merkle proposed a public-key scheme ("Merkle puzzles") in a 1974 Berkeley class project. His professor called it unfocused and told him to drop the topic. Merkle persisted, joined the patent, and later invented Merkle trees — the hash-tree structure that now anchors Git commits, IPFS content addressing, and every blockchain in existence. One rejected undergrad paper, two data structures, and the entire cryptographic web.
Why it's surprising. The patent expired in 1997, quietly and without fanfare. RSA (US 4,405,829) got more press because it also handled signatures. But Diffie-Hellman was the ur-patent — the first proof that asymmetric cryptography was possible at all. Diffie and Hellman won the 2015 Turing Award for it. Merkle, again, was overlooked.
