Lune

EUROCRYPT2026Top-tier venue

ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420

Cas Cremers, Esra Günsay, Vera Wesselkamp, Mang Zhao

2026Year
1Citations
1Top-tier citations

Abstract

The Messaging Layer Security protocol MLS is standardized in IETF’s RFCRFC\text {RFC} 94209420\text {9420} and allows a group of parties to securely establish and evolve group keys even if the servers are malicious. The core design of MLS is based on the TreeKEM protocol, which was significantly modified and extended during the standard’s development. Over the last years, several partial security analyses have appeared of incomplete drafts of the standard. One of the major additions to MLS RFCRFC\text {RFC} 94209420\text {9420} (the final version of the standard) are the external operations, i.e., external commits and proposals. These additional operations have not been considered in any previous security analysis, while they can have a significant impact on the standard’s security.In this work, we prove the consistency, confidentiality and authentication of MLS in RFCRFC\text {RFC} 94209420\text {9420}. To this end, we formalize ETKETK\textsf{ETK} : External-Operations TreeKEM, which models RFCRFC\text {RFC} 94209420\text {9420} and includes the external commits and proposals. We propose a corresponding ideal functionality FECGKAFECGKA\mathcal {F_\textrm{ECGKA}} and prove that ETKETK\textsf{ETK} realizes it. Our work is the first cryptographic analysis that considers both the final changes to the standard, and the first approach overall to cover external proposals and external commits. Compared to previous works that considered MLS drafts, our ETKETK\textsf{ETK} protocol is by far the closest to the final MLS RFCRFC\text {RFC} 94209420\text {9420} standard.Our analysis implies that the core of MLS in RFCRFC\text {RFC} 94209420\text {9420} is an ETKETK\textsf{ETK} protocol that realizes FECGKAFECGKA\mathcal {F_\textrm{ECGKA}}. Notably, we show that when external proposals and commits are allowed, MLS achieves a weaker form of security than was suggested by previous analyses, because the external operations can be exploited to violate Post-Compromise Security guarantees.We show that the security of the protocol can be further strengthened by leveraging the standard’s optional PSK mechanism, allowing another form of healing, and give a corresponding construction ETKPSKETKPSK\textsf{ETK} ^\textrm{PSK} and ideal functionality FECGKAPSKFECGKAPSK\mathcal {F} _{\textrm{ECGKA}^\textrm{PSK}}.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Cited by top-tier papers1

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines