On the Tight Security of the Double Ratchet
Daniel Collins, Doreen Riepel, Si An Oliver Tran
摘要
The Signal Protocol is a two-party secure messaging protocol used in applications such as Signal, WhatsApp, Google Messages and Facebook Messenger and is used by billions daily. It consists of two core components, one of which is the Double Ratchet protocol that has been the subject of a line of work that aims to understand and formalise exactly what security it provides. Existing models capture strong guarantees including resilience to state exposure in both forward security (protecting past secrets) and post-compromise security (restoring security), adaptive state corruptions, message injections and out-of-order message delivery. Due to this complexity, prior work has failed to provide security guarantees that do not degrade in the number of interactions, even in the single-session setting. Given the ubiquity of the Double Ratchet in practice, we explore tight security bounds for the Double Ratchet in the multi-session setting. To this end, we revisit the modelling of Alwen, Coretti and Dodis (EUROCRYPT 2019) who decompose the protocol into modular, abstract components, notably continuous key agreement (CKA) and forward-secure AEAD (FS-AEAD). To enable a tight security proof, we propose a CKA security model that provides one-way security under key checking attacks. We show that multisession security of the Double Ratchet can be tightly reduced to the multi-session security of CKA and FS-AEAD, capturing the same strong security guarantees as Alwen et al. Our result improves upon the bounds of Alwen et al. in the random oracle model. Even so, we are unable to provide a completely tight proof for the Double Ratchet based on standard Diffie-Hellman assumptions, and we conjecture it is not possible. We thus go a step further and analyse CKA based on key encapsulation mechanisms (KEMs). In contrast to previous works, our new analysis allows for tight constructions based on the DDH and post-quantum assumptions. CCS Concepts • Security and privacy → Cryptography.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Automated Formal Analysis of Signal's Double Ratchet: Attacks, Fixes and Security ProofsVincent Cheval, Charlie Jacomme, Jessica RichardsS&P 2026 · 被引用 3 次
- Crypto Wars in Secure Messaging: Covert Channels in Signal Despite Leaked KeysRosario Giustolisi, Gabriele Lenzini, Chuanwei Lin, Mohammadamin Rakeei 等USENIX Security 2026 · 被引用 1 次
它引用的顶会 Paper16
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 被引用 91 次
- The Multi-user Security of GCM, Revisited: Tight Bounds for Nonce RandomizationViet Tung Hoang, Stefano Tessaro, Aishwarya ThiruvengadamCCS 2018 · 被引用 39 次
- Tightly-Secure Authenticated Key Exchange, RevisitedTibor Jager, Eike Kiltz, Doreen Riepel, Sven SchägeEUROCRYPT 2021 · 被引用 39 次
- A More Complete Analysis of the Signal Double Ratchet AlgorithmAlexander Bienstock, Jaiden Fairoze, Sanjam Garg, Pratyay Mukherjee 等CRYPTO 2022 · 被引用 31 次
- Authenticated Key Exchange and Signatures with Tight Security in the Standard ModelShuai Han, Tibor Jager, Eike Kiltz, Shengli Liu 等CRYPTO 2021 · 被引用 30 次
相关 Paper
- Formal Analysis of Session-Handling in Secure Messaging: Lifting Security from Sessions to ConversationsCas Cremers, Charlie Jacomme, Aurora NaskaUSENIX Security 2023
- Clone Detection in Secure Messaging: Improving Post-Compromise Security in PracticeCas Cremers, Jaiden Fairoze, Benjamin Kiesl, Aurora NaskaCCS 2020 · 被引用 17 次
- Integrating Causality in Messaging ChannelsShan Chen, Marc FischlinEUROCRYPT 2024 · 被引用 5 次
- Universally Composable End-to-End Secure MessagingRan Canetti, Palak Jain, Marika Swanberg, Mayank VariaCRYPTO 2022 · 被引用 30 次
- On Ends-to-Ends Encryption: Asynchronous Group Messaging with Strong Security GuaranteesKatriel Cohn-Gordon, Cas Cremers, Luke Garratt, Jon Millican 等CCS 2018 · 被引用 140 次
