USENIX Security2026Top-tier venue
Oblivious Signaling
Mirza Kamrul Bashar Shuhan, Foteini Baldimtsi, Giuseppe Ateniese
Abstract
An anonymous messaging service has to solve a basic routing problem: a server must deliver an encrypted message to its recipient without learning who the recipient is. Broadcasting all ciphertexts hides the destination but forces every recipient to constantly scan for new messages. Oblivious Message Retrieval (OMR; CRYPTO '22) tackles this by using fully homomorphic encryption (FHE) to let an untrusted server perform message retrieval on a recipient's behalf without learning which messages are pertinent. We introduce Oblivious Signaling , which shifts this cost from retrieval to sending . The server maintains a fixed-size encrypted inbox for each recipient. When a sender submits a message, the server applies the same homomorphic update to every inbox: the intended inbox absorbs the message, and the rest remain unchanged at the plaintext level. The update is uniform, can be parallelized across inboxes, and ties the delivery cost strictly to the size of the anonymity set rather than global traffic. Recipients retrieve by fetching and decrypting their inbox, so checking for new messages is independent of the global traffic. We formalize receiver privacy against an untrusted server, even when it colludes with other users, give a concrete construction based on fully homomorphic encryption, and analyze the resulting ``digital postage'' trade-off: delivery is expensive, but checking is cheap. Our prototype identifies practical regimes in which this cost-model shift is preferable to scan-based retrieval, even with highly optimized OMR implementations. This cost model is well-suited to settings where recipients check frequently, and messages arrive sporadically, and it naturally discourages high-volume spam.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3f6cb54b-86d2-445d-9678-d44ce0ac5cc2Builds on14
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 231 citations
- The Loopix Anonymity SystemAnia M. Piotrowska, Jamie Hayes, Tariq Elahi, Sebastian Meiser et al.USENIX Security 2017 · 214 citations
- Express: Lowering the Cost of Metadata-hiding Communication with Cryptographic PrivacySaba Eskandarian, Henry Corrigan-Gibbs, Matei Zaharia, Dan BonehUSENIX Security 2021 · 98 citations
- Sabre: Sender-Anonymous Messaging with Fast AuditsAdithya Vadapalli, Kyle Storrier, Ryan HenryS&P 2022 · 32 citations
- Oblivious Message RetrievalZeyu Liu, Eran TromerCRYPTO 2022 · 28 citations
Related papers
- Group Oblivious Message RetrievalZeyu Liu, Eran Tromer, Yunhao WangS&P 2024 · 24 citations
- InstantOMR: Oblivious Message Retrieval with Low Latency and Optimal ParallelizabilityHaofei Liang, Zeyu Liu, Eran Tromer, Xiang Xie et al.USENIX Security 2026
- SophOMR: Improved Oblivious Message Retrieval from SIMD-Aware Homomorphic CompressionKeewoo Lee, Yongdong YeoUSENIX Security 2026
- StOMR: Stateful Oblivious Message RetrievalCharles Gouert, Keewoo Lee, Dimitris Mouris, Yiannis Tselekounis et al.CCS 2026
- PerfOMR: Oblivious Message Retrieval with Reduced Communication and ComputationZeyu Liu, Eran Tromer, Yunhao WangUSENIX Security 2024 · 16 citations
