ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420
Cas Cremers, Esra Günsay, Vera Wesselkamp, Mang Zhao
Abstract
The Messaging Layer Security protocol MLS is standardized in IETF’s RFC 9420 and allows a group of parties to securely establish and evolve group keys even if the servers are malicious. The core design of MLS is based on the TreeKEM protocol, which was significantly modified and extended during the standard’s development. Over the last years, several partial security analyses have appeared of incomplete drafts of the standard. One of the major additions to MLS RFC 9420 (the final version of the standard) are the external operations, i.e., external commits and proposals. These additional operations have not been considered in any previous security analysis, while they can have a significant impact on the standard’s security.In this work, we prove the consistency, confidentiality and authentication of MLS in RFC 9420. To this end, we formalize ETK : External-Operations TreeKEM, which models RFC 9420 and includes the external commits and proposals. We propose a corresponding ideal functionality FECGKA and prove that ETK realizes it. Our work is the first cryptographic analysis that considers both the final changes to the standard, and the first approach overall to cover external proposals and external commits. Compared to previous works that considered MLS drafts, our ETK protocol is by far the closest to the final MLS RFC 9420 standard.Our analysis implies that the core of MLS in RFC 9420 is an ETK protocol that realizes FECGKA. Notably, we show that when external proposals and commits are allowed, MLS achieves a weaker form of security than was suggested by previous analyses, because the external operations can be exploited to violate Post-Compromise Security guarantees.We show that the security of the protocol can be further strengthened by leveraging the standard’s optional PSK mechanism, allowing another form of healing, and give a corresponding construction ETKPSK and ideal functionality FECGKAPSK.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- TreeSync: Authenticated Group Management for Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Benjamin Beurdouche, Karthikeyan BhargavanUSENIX Security 2023
- TreeKEM: A Modular Machine-Checked Symbolic Security Analysis of Group Key Agreement in Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Karthikeyan BhargavanS&P 2025
- Modular Design of Secure Group Messaging Protocols and the Security of MLSJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCCS 2021 · 1 citation
- Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersCéline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman TalebCCS 2024 · 1 citation
