Security Under Message-Derived Keys: Signcryption in iMessage
Mihir Bellare, Igors Stepanovs
Abstract
At the core of Apple's iMessage is a signcryption scheme that involves symmetric encryption of a message under a key that is derived from the message itself. This motivates us to formalize a primitive we call Encryption under Message-Derived Keys (EMDK). We prove security of the EMDK scheme underlying iMessage. We use this to prove security of the signcryption scheme itself, with respect to definitions of signcryption we give that enhance prior ones to cover issues peculiar to messaging protocols. Our provable-security results are quantitative, and we discuss the practical implications for iMessage.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Analysing the HPKE StandardJoël Alwen, Bruno Blanchet, Eduard Hauck, Eike Kiltz et al.EUROCRYPT 2021 · 29 citations
- Shadowfax: Hybrid Security and Deniability for AKEMsPhillip Gajland, Vincent Hwang, Jonas JanneckUSENIX Security 2026
- A Real-World Law-Enforcement Hack: The Case of EncrochatMartin R. Albrecht, Sunoo Park, Michael A. Specter, Douglas StebilaCRYPTO 2026
Builds on2
Related papers
- Symmetric Signcryption and E2EE Group Messaging in KeybaseJoseph Jaeger, Akshaya Kumar, Igors StepanovsEUROCRYPT 2024 · 2 citations
- A Formal Analysis of Apple's iMessage PQ3 ProtocolFelix Linker, Ralf Sasse, David A. BasinUSENIX Security 2025
- Analyzing Group Chat Encryption in MLS, Session, Signal, and MatrixJoseph Jaeger, Akshaya KumarEUROCRYPT 2025 · 2 citations
- Formal Security Analysis of the Olvid MessengerNoemi Terzo), Cas Cremers, Ruben Gonzalez, Peter Schwabe) et al.CCS 2026
- Device-Oriented Group Messaging: A Formal Cryptographic Analysis of Matrix' CoreMartin R. Albrecht, Benjamin Dowling, Daniel JonesS&P 2024 · 10 citations
