USENIX Security2024Top-tier venue
K-Waay: Fast and Deniable Post-Quantum X3DH without Ring Signatures
Daniel Collins, Loïs Huguenin-Dumittan, Ngoc Khanh Nguyen, Nicolas Rolin, Serge Vaudenay
Abstract
The Signal protocol and its X3DH key exchange core are regularly used by billions of people in applications like WhatsApp but are unfortunately not quantum-secure. Thus, designing an efficient and post-quantum secure X3DH alternative is paramount. Notably, X3DH supports asynchronicity, as parties can immediately derive keys after uploading them to a central server, and deniability, allowing parties to plausibly deny having completed key exchange. To satisfy these constraints, existing post-quantum X3DH proposals use ring signatures (or equivalently a form of designated-verifier signatures) to provide authentication without compromising deniability as regular signatures would. Existing ring signature schemes, however, have some drawbacks. Notably, they are not generally proven secure in the quantum random oracle model (QROM) and so the quantum security of parameters that are proposed is unclear and likely weaker than claimed. In addition, they are generally slower than standard primitives like KEMs. In this work, we propose an efficient, deniable and postquantum X3DH-like protocol that we call K-Waay, that does not rely on ring signatures. At its core, K-Waay uses a split-KEM, a primitive introduced by Brendel et al. [SAC 2020], to provide Diffie-Hellman-like implicit authentication and secrecy guarantees. Along the way, we revisit the formalism of Brendel et al. and identify that additional security properties are required to prove a split-KEM-based protocol secure. We instantiate split-KEM by building a protocol based on the Frodo key exchange protocol relying on the plain LWE assumption: our proofs might be of independent interest as we show it satisfies our novel unforgeability and deniability security notions. Finally, we complement our theoretical results by thoroughly benchmarking both K-Waay and existing X3DH protocols. Our results show even when using plain LWE and a conservative choice of parameters that K-Waay is significantly faster than previous work. * The full version of this paper can be found on ePrint [25] .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7e36cdb6-cff0-4ac8-9c1d-0a3414f5ebb4Cited by top-tier papers4
- Triple Ratchet: A Bandwidth Efficient Hybrid-Secure Signal ProtocolYevgeniy Dodis, Daniel Jost, Shuichi Katsumata, Thomas Prest et al.EUROCRYPT 2025 · 10 citations
- Shadowfax: Hybrid Security and Deniability for AKEMsPhillip Gajland, Vincent Hwang, Jonas JanneckUSENIX Security 2026
- Comprehensive Deniability Analysis of Signal Handshake Protocols: X3DH, PQXDH to Fully Post-Quantum with Deniable Ring SignaturesShuichi Katsumata, Guilhem Niot, Ida Tucker, Thom WiggersUSENIX Security 2025
- Bundled Authenticated Key Exchange: A Concrete Treatment of Signal's Handshake Protocol and Post-Quantum SecurityKeitaro Hashimoto, Shuichi Katsumata, Thom WiggersUSENIX Security 2025
Builds on13
- Frodo: Take off the Ring! Practical, Quantum-Secure Key Exchange from LWEJoppe W. Bos, Craig Costello, Léo Ducas, Ilya Mironov et al.CCS 2016 · 431 citations
- An Efficient Key Recovery Attack on SIDHWouter Castryck, Thomas DecruEUROCRYPT 2023 · 284 citations
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 162 citations
- LWE with Side Information: Attacks and Concrete Security EstimationDana Dachman-Soled, Léo Ducas, Huijing Gong, Mélissa RossiCRYPTO 2020 · 162 citations
- DualRing: Generic Construction of Ring Signatures with Efficient InstantiationsTsz Hon Yuen, Muhammed F. Esgin, Joseph K. Liu, Man Ho Au et al.CRYPTO 2021 · 83 citations
Related papers
- Formal verification of the PQXDH Post-Quantum key agreement protocol for end-to-end secure messagingKarthikeyan Bhargavan, Charlie Jacomme, Franziskus Kiefer, Rolfe SchmidtUSENIX Security 2024 · 27 citations
- On Deniable Authentication Against Malicious VerifiersRune Fiedler, Roman LangrehrCRYPTO 2025 · 2 citations
- Post-quantum WireGuardAndreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber et al.S&P 2021 · 73 citations
- Post-quantum Internet Key Exchange via Authenticated Forward-Secure KEMYunlei Zhao, Biming Zhou, Zhixiang Zhao, Yifan Dong et al.CRYPTO 2026
- Post-Quantum Threshold Ring Signature Applications from VOLE-in-the-HeadJames Hsin-yu Chiang, Ivan Damgård, William R. Duro, Sunniva Engan et al.CCS 2025
