USENIX Security2026Top-tier venue
Anamorphic Messaging: Analyzing the Double Ratchet, Triple Ratchet, PQ3, and MLS
Hien Chu, Alessandro Corsi, Paul Rösler
Abstract
Anamorphic cryptography targets the scenario in which a dictator does not forbid the use of cryptography but requires all users to reveal their secret keys to them. Thus, the dictator can decrypt all honestly generated ciphertexts. The approach for bypassing this is to identify spots, such as random nonces, in existing cryptographic protocols in which secret messages can be hidden using an additional secret double key. So far, the literature mostly focused on identifying such spots in simple primitives like public-key encryption or signatures; only recently, an initial work identified limited spots in Signal's Double Ratchet Algorithm.
We are the first to leverage the statefulness of cryptographic communication protocols to employ continuously updated double states and, thereby, achieve Forward Security: Even if the adversary (i) observes all traffic, (ii) knows all users' regular secret key material at any stage of the protocol execution, and (iii) at some point learns the secret double state, the entire protocol execution looks benign although covert messages were previously hidden in the traffic anamorphically. We formalize this notion and also cover robustness and authenticity, which appear to be particularly relevant in the messaging context.
In this new model, we study four of the most relevant messaging protocols and identify hiding spots therein: Signal's Double Ratchet, Signal's Triple Ratchet, Apple's PQ3, and the two-party core of the Messaging Layer Security Standard. We focus on the cryptographic parts of these protocols and, despite their complexity, identify surprisingly few anamorphic hiding spots. We prove that all these protocols offer forward secure, authenticated anamorphic channels and we evaluate their bandwidths: While 16 bits can be embedded in every epoch of the Double Ratchet, Triple Ratchet and PQ3 provide 176 bits, respectively 256 bits, of bandwidth per post-quantum epoch, and MLS provides 688 bits per epoch.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 28a1ab6a-d844-4a0a-8248-dc1677aebd0dBuilds on37
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott et al.CCS 2017 · 247 citations
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 91 citations
- Meteor: Cryptographically Secure Steganography for Realistic DistributionsGabriel Kaptchuk, Tushar M. Jois, Matthew Green, Aviel D. RubinCCS 2021 · 50 citations
- Keep the Dirt: Tainted TreeKEM, Adaptively and Actively Secure Continuous Group Key AgreementKaren Klein, Guillermo Pascual-Perez, Michael Walter, Chethan Kamath et al.S&P 2021 · 46 citations
- Anamorphic Encryption: Private Communication Against a DictatorGiuseppe Persiano, Duong Hieu Phan, Moti YungEUROCRYPT 2022 · 45 citations
Related papers
- Crypto Wars in Secure Messaging: Covert Channels in Signal Despite Leaked KeysRosario Giustolisi, Gabriele Lenzini, Chuanwei Lin, Mohammadamin Rakeei et al.USENIX Security 2026 · 1 citation
- How to Compare Bandwidth Constrained Two-Party Secure Messaging Protocols: A Quest for A More Efficient and Secure Post-Quantum ProtocolBenedikt Auerbach, Yevgeniy Dodis, Daniel Jost, Shuichi Katsumata et al.USENIX Security 2025
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica RichardsS&P 2026 · 3 citations
- A Unified Treatment of Anamorphic EncryptionWonseok Choi, Daniel Collins, Xiangyu Liu, Roy Stracovsky et al.CRYPTO 2026
- On the Tight Security of the Double RatchetDaniel Collins, Doreen Riepel, Si An Oliver TranCCS 2024 · 3 citations
