Fork-Resilient Continuous Group Key Agreement
Joël Alwen, Marta Mularczyk, Yiannis Tselekounis
Abstract
Continuous Group Key Agreement (CGKA) lets a evolving group of clients agree on a sequence of group keys. An important application of CGKA is scalable asynchronous end-to-end (E2E) encrypted group messaging.
A major problem preventing the use of CGKA over unreliable infrastructure are so-called forks. A fork occurs when group members have diverging views of the group's history (and thus its current state); e.g. due to network or server failures. Once communication channels are restored, members resolve a fork by agreeing on the state of the group again. Today's CGKA protocols make fork resolution challenging, as natural resolution strategies seem to conflict with the way the protocols enforce group state agreement and forward secrecy. Meanwhile, secure group messaging protocols which do support fork resolution do not scale nearly as well as CGKA does.
In this work, we pave the way to practical scalable E2E messaging over unreliable infrastructure. To that end, we generalize CGKA to Fork Resilient-CGKA which allows clients to process significantly more types of out-of-order network traffic. This is important for many natural fork resolution procedures as they are based, in part, on replaying missed traffic. Next, we give two FR-CGKA constructions: a practical one based on the CGKA underlying the MLS messaging standard and an optimally secure one (albeit with only theoretical efficiency). To further assist with fork resolution, we introduce a simple new abstraction to describe a client's local protocol state. The abstraction describes all and only the information relevant to natural fork resolution, making it easier for higher-level fork resolution procedures to work with and reason about. We define a black-box extension of an FR-CGKA which maintains such a description of a client's internal state. Finally, as a proof of concept, we give a basic fork resolution protocol.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 996236ba-aac5-42b2-aab9-7c76fb3faa7fCited by top-tier papers3
- Realizing Flexible Broadcast Encryption: How to Broadcast to a Public-Key DirectoryRachit Garg, George Lu, Brent Waters, David J. WuCCS 2023 · 6 citations
- Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersCéline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman TalebCCS 2024 · 1 citation
- Cryptographic Analysis of Delta ChatYuanming Song, Lenka Mareková, Kenneth G. PatersonUSENIX Security 2024
Related papers
- Cryptographic Administration for Secure Group MessagingDavid Balbás, Daniel Collins, Serge VaudenayUSENIX Security 2023
- Fair-Weather No More: Guaranteed Efficiency in Secure Group MessagingJames Bartusek, Nir Bitansky, Yevgeniy Dodis, Rachit Garg et al.CRYPTO 2026
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- Key Agreement for Decentralized Secure Group Messaging with Strong Security GuaranteesMatthew Weidner, Martin Kleppmann, Daniel Hugenroth, Alastair R. BeresfordCCS 2021 · 28 citations
- Server-Aided Continuous Group Key AgreementJoël Alwen, Dominik Hartmann, Eike Kiltz, Marta MularczykCCS 2022 · 19 citations
