Device-Oriented Group Messaging: A Formal Cryptographic Analysis of Matrix' Core
Martin R. Albrecht, Benjamin Dowling, Daniel Jones
Abstract
Focusing on its cryptographic core, we provide the first formal description of the Matrix secure group messaging protocol. Observing that no existing secure messaging model in the literature captures the relationships (and shared state) between users, their devices and the groups they are a part of, we introduce the Device-Oriented Group Messaging model to capture these key characteristics of the Matrix protocol. Utilising our new formalism, we determine that Matrix achieves the basic security notions of confidentiality and authentication, provided it introduces authenticated group membership. On the other hand, while the state sharing functionality in Matrix conflicts with advanced security notions in the literature – forward and post-compromise security – it enables features such as history sharing and account recovery, provoking broader questions about how such security notions should be conceptualised.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4a901396-7b37-40ef-9bcf-44677de3ee34Cited by top-tier papers3
- SAGA: A Security Architecture for Governing AI Agentic SystemsGeorgios Syros, Anshuman Suri, Jacob Ginesin, Cristina Nita-Rotaru et al.NDSS 2026 · 63 citations
- Cryptographic Analysis of Delta ChatYuanming Song, Lenka Mareková, Kenneth G. PatersonUSENIX Security 2024
- Message Injection Attacks Against SignalKien Tuong Truong, Noemi Terzo, Kenneth G. PatersonUSENIX Security 2026
Related papers
- Formal Analysis of Multi-device Group Messaging in WhatsAppMartin R. Albrecht, Benjamin Dowling, Daniel JonesEUROCRYPT 2025 · 3 citations
- TreeSync: Authenticated Group Management for Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Benjamin Beurdouche, Karthikeyan BhargavanUSENIX Security 2023
- Practically-exploitable Cryptographic Vulnerabilities in MatrixMartin R. Albrecht, Sofía Celi, Benjamin Dowling, Daniel JonesS&P 2023
- Formal Security Analysis of the Olvid MessengerNoemi Terzo), Cas Cremers, Ruben Gonzalez, Peter Schwabe) et al.CCS 2026
- Analyzing Group Chat Encryption in MLS, Session, Signal, and MatrixJoseph Jaeger, Akshaya KumarEUROCRYPT 2025 · 2 citations
