On Deniable Authentication Against Malicious Verifiers
Rune Fiedler, Roman Langrehr
Abstract
Deniable authentication allows Alice to authenticate a message to Bob, while retaining deniability towards third parties. In particular, not even Bob can convince a third party that Alice authenticated that message. Clearly, in this setting Bob should not be considered trustworthy. Furthermore, deniable authentication is necessary for deniable key exchange, as explicitly desired by Signal and off-the-record (OTR) messaging.
In this work we focus on (publicly verifiable) designated verifier signatures (DVS), which are a widely used primitive to achieve deniable authentication. We propose a definition of deniability against malicious verifiers for DVS. We give a construction that achieves this notion in the random oracle (RO) model. Moreover, we show that our notion is not achievable in the standard model with a concrete attack; thereby giving a non-contrived example of the RO heuristic failing.
All previous protocols that claim to achieve deniable authentication against malicious verifiers (like Signal's initial handshake protocols X3DH and PQXDH) rely on the Extended Knowledge of Diffie–Hellman (EKDH) assumption. We show that this assumption is broken and that these protocols do not achieve deniability against malicious verifiers.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- Deniable Authentication When Signing Keys LeakSuvradip Chakraborty, Dennis Hofheinz, Ueli Maurer, Guilherme RitoEUROCRYPT 2023 · 10 citations
- Epochal Signatures for Deniable Group ChatsAndreas Hülsing, Florian WeberS&P 2021 · 11 citations
- Fully Deniable Interactive EncryptionRan Canetti, Sunoo Park, Oxana PoburinnayaCRYPTO 2020 · 35 citations
- How to Delete Without a Trace: Certified Deniability in a Quantum WorldAlper Çakan, Vipul Goyal, Justin RaizesCRYPTO 2026
- K-Waay: Fast and Deniable Post-Quantum X3DH without Ring SignaturesDaniel Collins, Loïs Huguenin-Dumittan, Ngoc Khanh Nguyen, Nicolas Rolin et al.USENIX Security 2024 · 12 citations
