How to Hide MetaData in MLS-Like Secure Group Messaging: Simple, Modular, and Post-Quantum
Keitaro Hashimoto, Shuichi Katsumata, Thomas Prest
摘要
Secure group messaging (SGM) protocols allow large groups of users to communicate in a secure and asynchronous manner. In recent years, continuous group key agreements (CGKAs) have provided a powerful abstraction to reason on the security properties we expect from SGM protocols. While robust techniques have been developed to protect the contents of conversations in this context, it is in general more challenging to protect metadata (e.g. the identity and social relationships of group members), since their knowledge is often needed by the server in order to ensure the proper function of the SGM protocol. In this work, we provide a simple and generic wrapper protocol that upgrades non-metadata-hiding CGKAs into metadata-hiding CGKAs. Our key insight is to leverage the existence of a unique continuously evolving group secret key shared among the group members. We use this key to perform a group membership authentication protocol that convinces the server in an anonymous manner that a user is a legitimate group member. Our technique only uses a standard signature scheme, and thus, the wrapper protocol can be instantiated from a wide range of assumptions, including postquantum ones. It is also very efficient, as it increases the bandwidth cost of the underlying CGKA operations by at most a factor of two. To formally prove the security of our protocol, we use the universal composability (UC) framework and model a new ideal functionality F mh CGKA capturing the correctness and security guarantee of metadata-hiding CGKA. To capture the above intuition of a "wrapper" protocol, we also define a restricted ideal functionality F ctxt CGKA , which roughly captures a non-metadata-hiding CGKA. We then show that our wrapper protocol UC-realizes F mh CGKA in the F ctxt CGKAhybrid model, which in particular formalizes the intuition that any non-metadata-hiding CGKA can be modularly bootstrapped into metadata-hiding CGKA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Triple Ratchet: A Bandwidth Efficient Hybrid-Secure Signal ProtocolYevgeniy Dodis, Daniel Jost, Shuichi Katsumata, Thomas Prest 等EUROCRYPT 2025 · 被引用 10 次
- Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group ChatsKai-Hsiang Chou, Yi-Min Lin, Yi-An Wang, Jonathan Weiping Li 等USENIX Security 2025
- Generic Anonymity Wrapper for Messaging ProtocolsLea Thiemt, Paul Rösler, Alexander Bienstock, Rolfe Schmidt 等CCS 2025
- Comprehensive Deniability Analysis of Signal Handshake Protocols: X3DH, PQXDH to Fully Post-Quantum with Deniable Ring SignaturesShuichi Katsumata, Guilhem Niot, Ida Tucker, Thom WiggersUSENIX Security 2025
- Exploring How to Authenticate Application Messages in MLS: More Efficient, Post-Quantum, and Anonymous BlocklistableKeitaro Hashimoto, Shuichi Katsumata, Guillermo Pascual-PerezUSENIX Security 2025
它引用的顶会 Paper10
- On Ends-to-Ends Encryption: Asynchronous Group Messaging with Strong Security GuaranteesKatriel Cohn-Gordon, Cas Cremers, Luke Garratt, Jon Millican 等CCS 2018 · 被引用 140 次
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 被引用 91 次
- Keep the Dirt: Tainted TreeKEM, Adaptively and Actively Secure Continuous Group Key AgreementKaren Klein, Guillermo Pascual-Perez, Michael Walter, Chethan Kamath 等S&P 2021 · 被引用 46 次
- Key Agreement for Decentralized Secure Group Messaging with Strong Security GuaranteesMatthew Weidner, Martin Kleppmann, Daniel Hugenroth, Alastair R. BeresfordCCS 2021 · 被引用 28 次
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 被引用 28 次
相关 Paper
- A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEsKeitaro Hashimoto, Shuichi Katsumata, Eamonn W. Postlethwaite, Thomas Prest 等CCS 2021 · 被引用 1 次
- GURKE: Group Unidirectional Ratcheted Key ExchangeDaniel Collins, Paul RöslerCRYPTO 2025 · 被引用 1 次
- Fair-Weather No More: Guaranteed Efficiency in Secure Group MessagingJames Bartusek, Nir Bitansky, Yevgeniy Dodis, Rachit Garg 等CRYPTO 2026
- Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersCéline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman TalebCCS 2024 · 被引用 1 次
- Cryptographic Administration for Secure Group MessagingDavid Balbás, Daniel Collins, Serge VaudenayUSENIX Security 2023
