USENIX Security2023Top-tier venue
TreeSync: Authenticated Group Management for Messaging Layer Security
Théophile Wallez, Jonathan Protzenko, Benjamin Beurdouche, Karthikeyan Bhargavan
Abstract
Messaging Layer Security (MLS), currently undergoing standardization at the IETF, is an asynchronous group messaging protocol that aims to be efficient for large dynamic groups, while providing strong guarantees like forward secrecy (FS) and post-compromise security (PCS). While prior work on MLS has extensively studied its group key establishment component (called TreeKEM), many flaws in early designs of MLS have stemmed from its group integrity and authentication mechanisms that are not as well-understood. In this work, we identify and formalize TreeSync: a sub-protocol of MLS that specifies the shared group state, defines group management operations, and ensures consistency, integrity, and authentication for the group state across all members. We present a precise, executable, machine-checked formal specification of TreeSync, and show how it can be composed with other components to implement the full MLS protocol. Our specification is written in F * and serves as a reference implementation of MLS; it passes the RFC test vectors and is interoperable with other MLS implementations. Using the DY * symbolic protocol analysis framework, we formalize and prove the integrity and authentication guarantees of TreeSync, under minimal security assumptions on the rest of MLS. Our analysis identifies a new attack and we propose several changes that have been incorporated in the latest MLS draft. Ours is the first testable, machine-checked, formal specification for MLS, and should be of interest to both developers and researchers interested in this upcoming standard.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 51007397-ab6d-4a12-8928-f85c91c4e48dCited by top-tier papers6
- Private Hierarchical Governance for Encrypted MessagingArmin Namavari, Barry Wang, Sanketh Menda, Ben Nassi et al.S&P 2024 · 1 citation
- Formal Security and Functional Verification of Cryptographic Protocol Implementations in RustKarthikeyan Bhargavan, Lasse Letager Hansen, Franziskus Kiefer, Jonas Schneider-Bensch et al.CCS 2025 · 1 citation
- TreeKEM: A Modular Machine-Checked Symbolic Security Analysis of Group Key Agreement in Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Karthikeyan BhargavanS&P 2025
- Anamorphic Messaging: Analyzing the Double Ratchet, Triple Ratchet, PQ3, and MLSHien Chu, Alessandro Corsi, Paul RöslerUSENIX Security 2026
- Exploring How to Authenticate Application Messages in MLS: More Efficient, Post-Quantum, and Anonymous BlocklistableKeitaro Hashimoto, Shuichi Katsumata, Guillermo Pascual-PerezUSENIX Security 2025
Builds on15
- HACL*: A Verified Modern Cryptographic LibraryJean Karim Zinzindohoué, Karthikeyan Bhargavan, Jonathan Protzenko, Benjamin BeurdoucheCCS 2017 · 258 citations
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott et al.CCS 2017 · 247 citations
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 233 citations
- SoK: Computer-Aided CryptographyManuel Barbosa, Gilles Barthe, Karthik Bhargavan, Bruno Blanchet et al.S&P 2021 · 169 citations
- On Ends-to-Ends Encryption: Asynchronous Group Messaging with Strong Security GuaranteesKatriel Cohn-Gordon, Cas Cremers, Luke Garratt, Jon Millican et al.CCS 2018 · 140 citations
Related papers
- Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersCéline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman TalebCCS 2024 · 1 citation
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 91 citations
- Security Analysis of the MLS Key DerivationChris Brzuska, Eric Cornelissen, Konrad KohbrokS&P 2022 · 26 citations
- ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420Cas Cremers, Esra Günsay, Vera Wesselkamp, Mang ZhaoEUROCRYPT 2026 · 1 citation
