USENIX Security2023Top-tier venue
Formal Analysis of Session-Handling in Secure Messaging: Lifting Security from Sessions to Conversations
Cas Cremers, Charlie Jacomme, Aurora Naska
Abstract
The building blocks for secure messaging apps, such as Signal's X3DH and Double Ratchet (DR) protocols, have received a lot of attention from the research community. They have notably been proved to meet strong security properties even in the case of compromise such as Forward Secrecy (FS) and Post-Compromise Security (PCS). However, there is a lack of formal study of these properties at the application level. Whereas the research works have studied such properties in the context of a single ratcheting chain, a conversation between two persons in a messaging application can in fact be the result of merging multiple ratcheting chains. In this work, we initiate the formal analysis of secure messaging taking the session-handling layer into account, and apply our approach to Sesame, Signal's session management. We first experimentally show practical scenarios in which PCS can be violated in Signal by a clone attacker, despite its use of the Double Ratchet. We identify how this is enabled by Signal's session-handling layer. We then design a formal model of the session-handling layer of Signal that is tractable for automated verification with the Tamarin prover, and use this model to rediscover the PCS violation and propose two provably secure mechanisms to offer stronger guarantees.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 97682f1e-5797-42a1-9ba0-9653d7b024b7Cited by top-tier papers17
- Formal verification of the PQXDH Post-Quantum key agreement protocol for end-to-end secure messagingKarthikeyan Bhargavan, Charlie Jacomme, Franziskus Kiefer, Rolfe SchmidtUSENIX Security 2024 · 27 citations
- Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and PrivacyGabriel K. Gegenhuber, Philipp É. Frenzel, Maximilian Günther, Johanna Ullrich et al.NDSS 2026 · 5 citations
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica RichardsS&P 2026 · 3 citations
- On the Tight Security of the Double RatchetDaniel Collins, Doreen Riepel, Si An Oliver TranCCS 2024 · 3 citations
- Automated Side-Channel Analysis of Cryptographic Protocol ImplementationsFaezeh Nasrabadi, Robert Künnemann, Hamed NematiCCS 2026 · 2 citations
Builds on4
- A More Complete Analysis of the Signal Double Ratchet AlgorithmAlexander Bienstock, Jaiden Fairoze, Sanjam Garg, Pratyay Mukherjee et al.CRYPTO 2022 · 31 citations
- Universally Composable End-to-End Secure MessagingRan Canetti, Palak Jain, Marika Swanberg, Mayank VariaCRYPTO 2022 · 30 citations
- Clone Detection in Secure Messaging: Improving Post-Compromise Security in PracticeCas Cremers, Jaiden Fairoze, Benjamin Kiesl, Aurora NaskaCCS 2020 · 17 citations
- How fast do you heal? A taxonomy for post-compromise security in secure-channel establishmentOlivier Blazy, Ioana Boureanu, Pascal Lafourcade, Cristina Onete et al.USENIX Security 2023
Related papers
- Impossibility Results for Post-Compromise Security in Real-World Communication SystemsCas Cremers, Niklas Medinger, Aurora NaskaS&P 2025
- A Formal Analysis of Apple's iMessage PQ3 ProtocolFelix Linker, Ralf Sasse, David A. BasinUSENIX Security 2025
- On Ends-to-Ends Encryption: Asynchronous Group Messaging with Strong Security GuaranteesKatriel Cohn-Gordon, Cas Cremers, Luke Garratt, Jon Millican et al.CCS 2018 · 140 citations
- 3PaaS: Privacy-Preserving Post-Compromise Security as a ServiceCas Cremers, Abhinav Nakarmi, Aleksi Peltonen, Eyal RonenCCS 2026
- Integrating Causality in Messaging ChannelsShan Chen, Marc FischlinEUROCRYPT 2024 · 5 citations
