Deniable Authentication When Signing Keys Leak
Suvradip Chakraborty, Dennis Hofheinz, Ueli Maurer, Guilherme Rito
Abstract
Deniable Authentication is a highly desirable property for secure messaging protocols: it allows a sender Alice to authentically transmit messages to a designated receiver Bob in such a way that only Bob gets convinced that Alice indeed sent these messages. In particular, it guarantees that even if Bob tries to convince a (non-designated) party Judy that Alice sent some message, and even if Bob gives Judy his own secret key, Judy will not be convinced: as far as Judy knows, Bob could be making it all up! In this paper we study Deniable Authentication in the setting where Judy can additionally obtain Alice's secret key. Informally, we want that knowledge of Alice's secret key does not help Judy in learning whether Alice sent any messages, even if Bob does not have Alice's secret key and even if Bob cooperates with Judy by giving her his own secret key. This stronger flavor of Deniable Authentication was not considered before and is particularly relevant for Off-The-Record Group Messaging as it gives users stronger deniability guarantees. Our main contribution is a scalable "MDRS-PKE" (Multi-Designated Receiver Signed Public Key Encryption) scheme-a technical formalization of Deniable Authentication that is particularly useful for secure messaging for its confidentiality guarantees-that provides this stronger deniability guarantee. At its core lie new MDVS (Multi-Designated Verifier Signature) and PKEBC (Public Key Encryption for Broadcast) scheme constructions: our MDVS is not only secure with respect to the new deniability notions, but it is also the first to be tightly secure under standard assumptions; our PKEBC-which is also of independent interest-is the first with ciphertext sizes and encryption and decryption times that grow only linearly in the number of receivers. This is a significant improvement upon the construction given by Maurer et al. (EUROCRYPT '22), where ciphertext sizes and encryption and decryption times are quadratic in the number of receivers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2eff941a-1303-4faa-b7fa-3adbfdf0f4aaBuilds on1
Related papers
- On Deniable Authentication Against Malicious VerifiersRune Fiedler, Roman LangrehrCRYPTO 2025 · 2 citations
- Secure Messaging with Strong Compromise Resilience, Temporal Privacy, and Immediate DecryptionCas Cremers, Mang ZhaoS&P 2024 · 3 citations
- Fully Deniable Interactive EncryptionRan Canetti, Sunoo Park, Oxana PoburinnayaCRYPTO 2020 · 35 citations
- Epochal Signatures for Deniable Group ChatsAndreas Hülsing, Florian WeberS&P 2021 · 11 citations
- Anamorphic Encryption, RevisitedFabio Banfi, Konstantin Gegier, Martin Hirt, Ueli Maurer et al.EUROCRYPT 2024 · 21 citations
