On the Insider Security of MLS
Joël Alwen, Daniel Jost, Marta Mularczyk
Abstract
The Messaging Layer Security (MLS) protocol is an open standard for end-to-end (E2E) secure group messaging being developed by the IETF, poised for deployment to consumers, industry, and government. It is designed to provide E2E privacy and authenticity for messages in long-lived sessions whenever possible, despite the participation (at times) of malicious insiders that can adaptively interact with the PKI at will, actively deviate from the protocol, leak honest parties' states, and fully control the network. The core of the MLS protocol (from which it inherits essentially all of its efficiency and security properties) is a Continuous Group Key Agreement (CGKA) protocol. It provides asynchronous E2E group management by allowing group members to agree on a fresh independent symmetric key after every change to the group's state (e.g. when someone joins/leaves the group).
In this work, we make progress towards a precise understanding of the insider security of MLS (Draft 12). On the theory side, we overcome several subtleties to formulate the first notion of insider security for CGKA (or group messaging). Next, we isolate the core components of MLS to obtain a CGKA protocol we dub Insider Secure TreeKEM (ITK). Finally, we give a rigorous security proof for ITK. In particular, this work also initiates the study of insider secure CGKA and group messaging protocols. Along the way we give three new (very practical) attacks on MLS and corresponding fixes. (Those fixes have now been included into the standard.) We also describe a second attack against MLS-like CGKA protocols proven secure under all previously considered security notions (including those designed specifically to analyze MLS). These attacks highlight the pitfalls in simplifying security notions even in the name of tractability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 345b2299-1749-4929-97af-018c26f6b17bCited by top-tier papers14
- Security Analysis of the MLS Key DerivationChris Brzuska, Eric Cornelissen, Konrad KohbrokS&P 2022 · 26 citations
- Server-Aided Continuous Group Key AgreementJoël Alwen, Dominik Hartmann, Eike Kiltz, Marta MularczykCCS 2022 · 19 citations
- How to Hide MetaData in MLS-Like Secure Group Messaging: Simple, Modular, and Post-QuantumKeitaro Hashimoto, Shuichi Katsumata, Thomas PrestCCS 2022 · 12 citations
- Triple Ratchet: A Bandwidth Efficient Hybrid-Secure Signal ProtocolYevgeniy Dodis, Daniel Jost, Shuichi Katsumata, Thomas Prest et al.EUROCRYPT 2025 · 10 citations
- Private Hierarchical Governance for Encrypted MessagingArmin Namavari, Barry Wang, Sanketh Menda, Ben Nassi et al.S&P 2024 · 1 citation
Builds on10
- On Ends-to-Ends Encryption: Asynchronous Group Messaging with Strong Security GuaranteesKatriel Cohn-Gordon, Cas Cremers, Luke Garratt, Jon Millican et al.CCS 2018 · 140 citations
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 91 citations
- Keep the Dirt: Tainted TreeKEM, Adaptively and Actively Secure Continuous Group Key AgreementKaren Klein, Guillermo Pascual-Perez, Michael Walter, Chethan Kamath et al.S&P 2021 · 46 citations
- Analysing the HPKE StandardJoël Alwen, Bruno Blanchet, Eduard Hauck, Eike Kiltz et al.EUROCRYPT 2021 · 29 citations
- Security Analysis of the MLS Key DerivationChris Brzuska, Eric Cornelissen, Konrad KohbrokS&P 2022 · 26 citations
Related papers
- Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersCéline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman TalebCCS 2024 · 1 citation
- Modular Design of Secure Group Messaging Protocols and the Security of MLSJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCCS 2021 · 1 citation
- ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420Cas Cremers, Esra Günsay, Vera Wesselkamp, Mang ZhaoEUROCRYPT 2026 · 1 citation
- TreeSync: Authenticated Group Management for Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Benjamin Beurdouche, Karthikeyan BhargavanUSENIX Security 2023
- TreeKEM: A Modular Machine-Checked Symbolic Security Analysis of Group Key Agreement in Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Karthikeyan BhargavanS&P 2025
