Lune

EUROCRYPT2026顶会

ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420

Cas Cremers, Esra Günsay, Vera Wesselkamp, Mang Zhao

2026年份
1被引次数
1顶会引用

摘要

The Messaging Layer Security protocol MLS is standardized in IETF’s RFCRFC\text {RFC} 94209420\text {9420} and allows a group of parties to securely establish and evolve group keys even if the servers are malicious. The core design of MLS is based on the TreeKEM protocol, which was significantly modified and extended during the standard’s development. Over the last years, several partial security analyses have appeared of incomplete drafts of the standard. One of the major additions to MLS RFCRFC\text {RFC} 94209420\text {9420} (the final version of the standard) are the external operations, i.e., external commits and proposals. These additional operations have not been considered in any previous security analysis, while they can have a significant impact on the standard’s security.In this work, we prove the consistency, confidentiality and authentication of MLS in RFCRFC\text {RFC} 94209420\text {9420}. To this end, we formalize ETKETK\textsf{ETK} : External-Operations TreeKEM, which models RFCRFC\text {RFC} 94209420\text {9420} and includes the external commits and proposals. We propose a corresponding ideal functionality FECGKAFECGKA\mathcal {F_\textrm{ECGKA}} and prove that ETKETK\textsf{ETK} realizes it. Our work is the first cryptographic analysis that considers both the final changes to the standard, and the first approach overall to cover external proposals and external commits. Compared to previous works that considered MLS drafts, our ETKETK\textsf{ETK} protocol is by far the closest to the final MLS RFCRFC\text {RFC} 94209420\text {9420} standard.Our analysis implies that the core of MLS in RFCRFC\text {RFC} 94209420\text {9420} is an ETKETK\textsf{ETK} protocol that realizes FECGKAFECGKA\mathcal {F_\textrm{ECGKA}}. Notably, we show that when external proposals and commits are allowed, MLS achieves a weaker form of security than was suggested by previous analyses, because the external operations can be exploited to violate Post-Compromise Security guarantees.We show that the security of the protocol can be further strengthened by leveraging the standard’s optional PSK mechanism, allowing another form of healing, and give a corresponding construction ETKPSKETKPSK\textsf{ETK} ^\textrm{PSK} and ideal functionality FECGKAPSKFECGKAPSK\mathcal {F} _{\textrm{ECGKA}^\textrm{PSK}}.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖