Analyzing Group Chat Encryption in MLS, Session, Signal, and Matrix
Joseph Jaeger, Akshaya Kumar
Abstract
We analyze the composition of symmetric encryption and digital signatures in secure group messaging protocols where group members share a symmetric encryption key. In particular, we analyze the chat encryption algorithms underlying MLS, Session, Signal, and Matrix using the formalism of symmetric signcryption introduced by Jaeger, Kumar, and Stepanovs (Eurocrypt 2024). We identify theoretical attacks against each of the constructions we analyze that result from the insufficient binding between the symmetric encryption scheme and the digital signature scheme. In the case of MLS and Session, these translate into practically exploitable replay and reordering attacks by a group-insider. For Signal this leads to a forgery attack by a group-outsider with access to a user’s signing key, an attack previously discovered by Balbás, Collins, and Gajland (Asiacrypt 2023). In Matrix there are mitigations in the broader ecosystem that prevent exploitation. We provide formal security theorems that each of the four constructions are secure up to these attacks. Additionally, in Session we identified two attacks outside the symmetric signcryption model. The first allows a group-outsider with access to an exposed signing key to forge arbitrary messages and the second allows outsiders to replay ciphertexts.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d1e29956-bb10-4f66-8480-a8b00a0f6878Cited by top-tier papers3
- End-to-End Encrypted Git ServicesYa-Nan Li, Yaqing Song, Qiang Tang, Moti YungCCS 2025 · 1 citation
- Generic Anonymity Wrapper for Messaging ProtocolsLea Thiemt, Paul Rösler, Alexander Bienstock, Rolfe Schmidt et al.CCS 2025
- Message Injection Attacks Against SignalKien Tuong Truong, Noemi Terzo, Kenneth G. PatersonUSENIX Security 2026
Related papers
- Symmetric Signcryption and E2EE Group Messaging in KeybaseJoseph Jaeger, Akshaya Kumar, Igors StepanovsEUROCRYPT 2024 · 2 citations
- On the Tight Security of the Double RatchetDaniel Collins, Doreen Riepel, Si An Oliver TranCCS 2024 · 3 citations
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica RichardsS&P 2026 · 3 citations
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 28 citations
- The Complexities of Healing in Secure Group Messaging: Why Cross-Group Effects MatterCas Cremers, Britta Hale, Konrad KohbrokUSENIX Security 2021 · 24 citations
