Server-Aided Continuous Group Key Agreement
Joël Alwen, Dominik Hartmann, Eike Kiltz, Marta Mularczyk
Abstract
Continuous Group Key Agreement (CGKA) -or Group Ratcheting -lies at the heart of a new generation of scalable End-to-End secure (E2E) cryptographic multi-party applications. One of the most important (and first deployed) CGKAs is ITK which underpins the IETF's upcoming Messaging Layer Security E2E secure group messaging standard. To scale beyond the group sizes possible with earlier E2E protocols, a central focus of CGKA protocol design is to minimize bandwidth requirements (i.e. communication complexity). In this work, we advance both the theory and design of CGKA culminating in an extremely bandwidth efficient CGKA. To that end, we first generalize the standard CGKA communication model by introducing server-aided CGKA (saCGKA) which generalizes CGKA and more accurately models how most E2E protocols are deployed in the wild. Next, we introduce the SAIK protocol; a modification of ITK, designed for real-world use, that leverages the new capabilities available to an saCGKA to greatly reduce its communication (and computational) complexity in practical concrete terms. Further, we introduce an intuitive, yet precise, security model for saCGKA. It improves upon existing security models for CGKA in several ways. It more directly captures the intuitive security goals of CGKA. Yet, formally it also relaxes certain requirements allowing us to take advantage of the saCGKA communication model. Finally, it is significantly simpler making it more tractable to work with and easier to build intuition for. As a result, the security proof of SAIK is also simpler and more modular. Finally, we provide empirical data comparing the (at times, quite dramatically improved) complexity profile of SAIK to state-of-the art CGKAs. For example, in a newly created group with 10K members, to change the group state (e.g. add/remove parties) ITK requires each group member download 1.38MB. However, with SAIK, members download no more than 2.7KB.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 22b83184-43a6-4e8b-8d59-c17485886f50Cited by top-tier papers7
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- Triple Ratchet: A Bandwidth Efficient Hybrid-Secure Signal ProtocolYevgeniy Dodis, Daniel Jost, Shuichi Katsumata, Thomas Prest et al.EUROCRYPT 2025 · 10 citations
- Post-Quantum Multi-Recipient Public Key EncryptionJoël Alwen, Dominik Hartmann, Eike Kiltz, Marta Mularczyk et al.CCS 2023 · 6 citations
- mmCipher: Batching Post-Quantum Public Key Encryption Made Bandwidth-OptimalHongxiao Wang, Ron Steinfeld, Markku-Juhani O. Saarinen, Muhammed F. Esgin et al.USENIX Security 2026 · 2 citations
- Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersCéline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman TalebCCS 2024 · 1 citation
Builds on6
- On Ends-to-Ends Encryption: Asynchronous Group Messaging with Strong Security GuaranteesKatriel Cohn-Gordon, Cas Cremers, Luke Garratt, Jon Millican et al.CCS 2018 · 140 citations
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 91 citations
- Analysing the HPKE StandardJoël Alwen, Bruno Blanchet, Eduard Hauck, Eike Kiltz et al.EUROCRYPT 2021 · 29 citations
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- Modular Design of Secure Group Messaging Protocols and the Security of MLSJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCCS 2021 · 1 citation
Related papers
- Cryptographic Administration for Secure Group MessagingDavid Balbás, Daniel Collins, Serge VaudenayUSENIX Security 2023
- Fair-Weather No More: Guaranteed Efficiency in Secure Group MessagingJames Bartusek, Nir Bitansky, Yevgeniy Dodis, Rachit Garg et al.CRYPTO 2026
- GURKE: Group Unidirectional Ratcheted Key ExchangeDaniel Collins, Paul RöslerCRYPTO 2025 · 1 citation
- Fork-Resilient Continuous Group Key AgreementJoël Alwen, Marta Mularczyk, Yiannis TselekounisCRYPTO 2023 · 14 citations
- A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEsKeitaro Hashimoto, Shuichi Katsumata, Eamonn W. Postlethwaite, Thomas Prest et al.CCS 2021 · 1 citation
