Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessage
Christina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers, Michael Rushanan
摘要
Apple's iMessage is one of the most widely-deployed end-to-end encrypted messaging protocols. Despite its broad deployment, the encryption protocols used by iMessage have never been subjected to rigorous cryptanalysis. In this paper, we conduct a thorough analysis of iMessage to determine the security of the protocol against a variety of attacks. Our analysis shows that iMessage has significant vulnerabilities that can be exploited by a sophisticated attacker. In particular, we outline a novel chosen ciphertext attack on Huffman compressed data, which allows retrospective decryption of some iMessage payloads in less than 2 18 queries. The practical implication of these attacks is that any party who gains access to iMessage ciphertexts may potentially decrypt them remotely and after the fact. We additionally describe mitigations that will prevent these attacks on the protocol, without breaking backwards compatibility. Apple has deployed our mitigations in the latest iOS and OS X releases.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Obstacles to the Adoption of Secure Communication ToolsRuba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova 等S&P 2017 · 被引用 170 次
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon 等CCS 2019 · 被引用 159 次
- Partitioning Oracle AttacksJulia Len, Paul Grubbs, Thomas RistenpartUSENIX Security 2021 · 被引用 57 次
- Practical Decryption exFiltration: Breaking PDF EncryptionJens Müller, Fabian Ising, Vladislav Mladenov, Christian Mainka 等CCS 2019 · 被引用 18 次
- Security Under Message-Derived Keys: Signcryption in iMessageMihir Bellare, Igors StepanovsEUROCRYPT 2020 · 被引用 15 次
相关 Paper
- Three Lessons From Threema: Analysis of a Secure MessengerKenneth G. Paterson, Matteo Scarlata, Kien Tuong TruongUSENIX Security 2023
- Blue Bubbles, Red Flags: Investigating Privacy Leakage in Apple iMessageViktor E. Garske, Swantje Lange, Gabriel K. Gegenhuber), David Schmidt 等CCS 2026
- Injection Attacks Against End-to-End Encrypted ApplicationsAndrés Fábrega, Carolina Ortega Pérez, Armin Namavari, Ben Nassi 等S&P 2024 · 被引用 9 次
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica RichardsS&P 2026 · 被引用 3 次
- Starshields for iOS: Navigating the Security Cosmos in Satellite CommunicationJiska Classen, Alexander Heinrich, Fabian Portner, Felix Rohrbach 等NDSS 2025
