SEEMless: Secure End-to-End Encrypted Messaging with less</> Trust
Melissa Chase, Apoorvaa Deshpande, Esha Ghosh, Harjasleen Malvai
Abstract
End-to-end encrypted messaging (E2E) is only secure if participants have a way to retrieve the correct public key for the desired recipient. However, to make these systems usable, users must be able to replace their keys (e.g. when they lose or reset their devices, or reinstall their app), and we cannot assume any cryptographic means of authenticating the new keys. In the current E2E systems, the service provider manages the directory of public keys of its registered users; this allows a compromised or coerced service provider to introduce their own keys and execute a man in the middle attack. Building on the approach of CONIKS (Melara et al, USENIX Security '15), we formalize the notion of a Privacy-Preserving Verifiable Key Directory (VKD): a system which allows users to monitor the keys that the service is distributing on their behalf. We then propose a new VKD scheme which we call SEEMless, which improves on prior work in terms of privacy and scalability. In particular, our new approach allows key changes to take effect almost immediately; we show experimentally that our scheme easily supports delays less than a minute, in contrast to previous work which proposes a delay of one hour.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 2c046ccb-2ef2-46cc-a8e7-b897fd7ba59dCited by top-tier papers22
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang et al.S&P 2021 · 51 citations
- OPTIKS: An Optimized Key Transparency SystemJulia Len, Melissa Chase, Esha Ghosh, Kim Laine et al.USENIX Security 2024 · 18 citations
- FastVer: Making Data Integrity a CommodityArvind Arasu, Badrish Chandramouli, Johannes Gehrke, Esha Ghosh et al.SIGMOD 2021 · 15 citations
- Notus: Dynamic Proofs of Liabilities from Zero-knowledge RSA AccumulatorsJiajun Xin, Arman Haghighi, Xiangan Tian, Dimitrios PapadopoulosUSENIX Security 2024 · 11 citations
- Hekaton: Horizontally-Scalable zkSNARKs Via Proof AggregationMichael Rosenberg, Tushar Mopuri, Hossein Hafezi, Ian Miers et al.CCS 2024 · 7 citations
Related papers
- ELEKTRA: Efficient Lightweight multi-dEvice Key TRAnsparencyJulia Len, Melissa Chase, Esha Ghosh, Daniel Jost et al.CCS 2023 · 4 citations
- Compact Key Storage - A Modern Approach to Key Backup and DelegationYevgeniy Dodis, Daniel Jost, Antonio MarcedoneCRYPTO 2024 · 2 citations
- Parakeet: Practical Key Transparency for End-to-End Encrypted MessagingHarjasleen Malvai, Lefteris Kokoris-Kogias, Alberto Sonnino, Esha Ghosh et al.NDSS 2023
- Secret Key Recovery in a Global-Scale End-to-End Encryption SystemGraeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman et al.OSDI 2024 · 19 citations
- Automatic Detection of Fake Key Attacks in Secure MessagingTarun Kumar Yadav, Devashish Gosain, Amir Herzberg, Daniel Zappala et al.CCS 2022 · 6 citations
