USENIX Security2021Top-tier venue
The Complexities of Healing in Secure Group Messaging: Why Cross-Group Effects Matter
Cas Cremers, Britta Hale, Konrad Kohbrok
Abstract
Modern secure messaging protocols can offer strong security guarantees such as Post-Compromise Security (PCS) [18] , which enables participants to heal after compromise. The core PCS mechanism in protocols like Signal [34] is designed for pairwise communication, making it inefficient for large groups, while recently proposed designs for secure group messaging, ART [19], IETF's MLS /TreeKEM [11] , use group keys derived from tree structures to efficiently provide PCS to large groups. Until now, research on PCS designs only considered healing behaviour within a single group. In this work we provide the first analysis of the healing behaviour when a user participates in multiple groups. Surprisingly, our analysis reveals that the currently proposed protocols based on group keys, such as ART and TreeKEM/MLS Draft-11, provide significantly weaker PCS guarantees than group protocols based on pairwise PCS channels. In fact, we show that if new users can be created dynamically, ART, TreeKEM, and MLS Draft-11 never fully heal authentication. We map the design space of healing mechanisms, analyzing security and overhead of possible solutions. This leads us to a promising solution based on (i) global updates that affect all current and future groups, and (ii) post-compromise secure signatures. Our solution allows group messaging protocols such ART and MLS to achieve substantially stronger PCS guarantees. We provide a security definition for postcompromise secure signatures and an instantiation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- On the Tight Security of the Double RatchetDaniel Collins, Doreen Riepel, Si An Oliver TranCCS 2024 · 3 citations
- TreeKEM: A Modular Machine-Checked Symbolic Security Analysis of Group Key Agreement in Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Karthikeyan BhargavanS&P 2025
- Cryptographic Administration for Secure Group MessagingDavid Balbás, Daniel Collins, Serge VaudenayUSENIX Security 2023
- TreeSync: Authenticated Group Management for Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Benjamin Beurdouche, Karthikeyan BhargavanUSENIX Security 2023
Builds on3
- On Ends-to-Ends Encryption: Asynchronous Group Messaging with Strong Security GuaranteesKatriel Cohn-Gordon, Cas Cremers, Luke Garratt, Jon Millican et al.CCS 2018 · 140 citations
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 91 citations
- Keep the Dirt: Tainted TreeKEM, Adaptively and Actively Secure Continuous Group Key AgreementKaren Klein, Guillermo Pascual-Perez, Michael Walter, Chethan Kamath et al.S&P 2021 · 46 citations
Related papers
- Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersCéline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman TalebCCS 2024 · 1 citation
- Security Analysis of the MLS Key DerivationChris Brzuska, Eric Cornelissen, Konrad KohbrokS&P 2022 · 26 citations
- 3PaaS: Privacy-Preserving Post-Compromise Security as a ServiceCas Cremers, Abhinav Nakarmi, Aleksi Peltonen, Eyal RonenCCS 2026
- ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420Cas Cremers, Esra Günsay, Vera Wesselkamp, Mang ZhaoEUROCRYPT 2026 · 1 citation
- A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEsKeitaro Hashimoto, Shuichi Katsumata, Eamonn W. Postlethwaite, Thomas Prest et al.CCS 2021 · 1 citation
