Four Attacks and a Proof for Telegram
Martin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Igors Stepanovs
摘要
We study the use of symmetric cryptography in the MTProto 2.0 protocol, Telegram's equivalent of the TLS record protocol. We give positive and negative results. On the one hand, we formally and in detail model a slight variant of Telegram's "record protocol" and prove that it achieves security in a suitable bidirectional secure channel model, albeit under unstudied assumptions; this model itself advances the state-of-the-art for secure channels. On the other hand, we first motivate our modelling deviation from MTProto as deployed by giving two attacks -one of practical, one of theoretical interest -against MTProto without our modifications. We then also give a third attack exploiting timing side channels, of varying strength, in three official Telegram clients. On its own this attack is thwarted by the secrecy of salt and id fields that are established by Telegram's key exchange protocol. We chain the third attack with a fourth one against the implementation of the key exchange protocol on Telegram's servers. This fourth attack breaks the authentication properties of Telegram's key exchange, allowing a MitM attack. More mundanely, it also recovers the id field, reducing the cost of the plaintext recovery attack to guessing the 64-bit salt field. In totality, our results provide the first comprehensive study of MTProto's use of symmetric cryptography, as well as highlight weaknesses in its key exchange.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Caveat Implementor! Key Recovery Attacks on MEGAMartin R. Albrecht, Miro Haller, Lenka Mareková, Kenneth G. PatersonEUROCRYPT 2023 · 被引用 8 次
- MFKDF: Multiple Factors Knocked Down FlatMatteo Scarlata, Matilda Backendal, Miro HallerUSENIX Security 2024 · 被引用 3 次
- On the Virtues of Information Security in the UK Climate MovementMikaela Brough, Rikke Bjerg Jensen, Martin R. AlbrechtUSENIX Security 2025
- Hash Gone Bad: Automated discovery of protocol attacks that exploit hash function weaknessesVincent Cheval, Cas Cremers, Alexander Dax, Lucca Hirschi 等USENIX Security 2023
- Three Lessons From Threema: Analysis of a Secure MessengerKenneth G. Paterson, Matteo Scarlata, Kien Tuong TruongUSENIX Security 2023
它引用的顶会 Paper3
- Collective Information Security in Large-Scale Urban Protests: the Case of Hong KongMartin R. Albrecht, Jorge Blasco, Rikke Bjerg Jensen, Lenka MarekováUSENIX Security 2021 · 被引用 39 次
- Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)Robert Merget, Marcus Brinkmann, Nimrod Aviram, Juraj Somorovsky 等USENIX Security 2021 · 被引用 36 次
- On Bounded Distance Decoding with Predicate: Breaking the "Lattice Barrier" for the Hidden Number ProblemMartin R. Albrecht, Nadia HeningerEUROCRYPT 2021 · 被引用 31 次
相关 Paper
- Analysis of the Telegram Key ExchangeMartin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Eyal Ronen 等EUROCRYPT 2025 · 被引用 4 次
- Analyzing Group Chat Encryption in MLS, Session, Signal, and MatrixJoseph Jaeger, Akshaya KumarEUROCRYPT 2025 · 被引用 2 次
- TreeSync: Authenticated Group Management for Messaging Layer SecurityThéophile Wallez, Jonathan Protzenko, Benjamin Beurdouche, Karthikeyan BhargavanUSENIX Security 2023
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 被引用 128 次
- Clone Detection in Secure Messaging: Improving Post-Compromise Security in PracticeCas Cremers, Jaiden Fairoze, Benjamin Kiesl, Aurora NaskaCCS 2020 · 被引用 17 次
