Triple Ratchet: A Bandwidth Efficient Hybrid-Secure Signal Protocol
Yevgeniy Dodis, Daniel Jost, Shuichi Katsumata, Thomas Prest, Rolfe Schmidt
Abstract
Secure Messaging apps have seen growing adoption, and are used by billions of people daily. However, due to imminent threat of a "Harvest Now, Decrypt Later" attack, secure messaging providers must react know in order to make their protocols : at least as secure as before, but now also post-quantum (PQ) secure. Since many of these apps are internally based on the famous Signal's Double-Ratchet (DR) protocol, making Signal hybrid-secure is of great importance.
In fact, Signal and Apple already put in production various Signal-based variants with certain levels of hybrid security: PQXDH (only on the initial handshake), and PQ3 (on the entire protocol), by adding a to the DR protocol. Unfortunately, due to the large communication overheads of the scheme used by PQ3, real-world PQ3 performs this PQ-ratchet approximately every 50 messages. As we observe, the effectiveness of this amortization, while reasonable in the best-case communication scenario, quickly deteriorates in other still realistic scenarios; causing (rather than in ) re-transmissions of the same public keys and ciphertexts (of combined size 2272 bytes!).
In this work we design a new Signal-based, hybrid-secure secure messaging protocol, which significantly reduces the communication complexity of PQ3. We call our protocol "the " (TR) protocol. First, TR uses to make the communication inside the PQ-ratchet provably balanced. This results in much better communication guarantees of TR, as compared to PQ3. Second, we design a novel "variant" of , called , with significantly smaller combined length of ciphertext and public key (which is the relevant efficiency measure for "PQ-secure ratchets"). For 192 bits of security, improves this key efficiency measure by over 37%: from 2272 to 1416 bytes. In doing so, we identify a critical security flaw in prior suggestions to optimize communication complexity of lattice-based PQ-ratchets, and fix this flaw with a novel proof relying on the recently introduced hint MLWE assumption.
During the development of this work we have been in discussion with the Signal team, and they are actively evaluating bringing a variant of it into production in a future iteration of the Signal protocol.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a7456b42-bab2-4bda-a286-ca9ced8dc6ccCited by top-tier papers6
- Crypto Wars in Secure Messaging: Covert Channels in Signal Despite Leaked KeysRosario Giustolisi, Gabriele Lenzini, Chuanwei Lin, Mohammadamin Rakeei et al.USENIX Security 2026 · 1 citation
- Anamorphic Messaging: Analyzing the Double Ratchet, Triple Ratchet, PQ3, and MLSHien Chu, Alessandro Corsi, Paul RöslerUSENIX Security 2026
- Revisiting PQ Wireguard: A Comprehensive Security Analysis with a New Design Using Reinforced KEMsKeitaro Hashimoto, Shuichi Katsumata, Guilhem Niot, Thom WiggersS&P 2026
- Generic Anonymity Wrapper for Messaging ProtocolsLea Thiemt, Paul Rösler, Alexander Bienstock, Rolfe Schmidt et al.CCS 2025
- How to Compare Bandwidth Constrained Two-Party Secure Messaging Protocols: A Quest for A More Efficient and Secure Post-Quantum ProtocolBenedikt Auerbach, Yevgeniy Dodis, Daniel Jost, Shuichi Katsumata et al.USENIX Security 2025
Builds on12
- Toward Practical Lattice-Based Proof of Knowledge from Hint-MLWEDuhyeong Kim, Dongwon Lee, Jinyeong Seo, Yongsoo SongCRYPTO 2023 · 47 citations
- A More Complete Analysis of the Signal Double Ratchet AlgorithmAlexander Bienstock, Jaiden Fairoze, Sanjam Garg, Pratyay Mukherjee et al.CRYPTO 2022 · 31 citations
- Universally Composable End-to-End Secure MessagingRan Canetti, Palak Jain, Marika Swanberg, Mayank VariaCRYPTO 2022 · 30 citations
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- Formal verification of the PQXDH Post-Quantum key agreement protocol for end-to-end secure messagingKarthikeyan Bhargavan, Charlie Jacomme, Franziskus Kiefer, Rolfe SchmidtUSENIX Security 2024 · 27 citations
Related papers
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica RichardsS&P 2026 · 3 citations
- On the Tight Security of the Double RatchetDaniel Collins, Doreen Riepel, Si An Oliver TranCCS 2024 · 3 citations
- Formal Analysis of Session-Handling in Secure Messaging: Lifting Security from Sessions to ConversationsCas Cremers, Charlie Jacomme, Aurora NaskaUSENIX Security 2023
- A Formal Analysis of Apple's iMessage PQ3 ProtocolFelix Linker, Ralf Sasse, David A. BasinUSENIX Security 2025
- Clone Detection in Secure Messaging: Improving Post-Compromise Security in PracticeCas Cremers, Jaiden Fairoze, Benjamin Kiesl, Aurora NaskaCCS 2020 · 17 citations
