CoCoA: Concurrent Continuous Group Key Agreement
Joël Alwen, Benedikt Auerbach, Miguel Cueto Noval, Karen Klein, Guillermo Pascual-Perez, Krzysztof Pietrzak, Michael Walter
摘要
Messaging platforms like Signal are widely deployed and provide strong security in an asynchronous setting. It is a challenging problem to construct a protocol with similar security guarantees that can efficiently scale to large groups. A major bottleneck are the frequent key rotations users need to perform to achieve post compromise forward security.
In current proposals -- most notably in TreeKEM (which is part of the IETF's Messaging Layer Security (MLS) protocol draft) -- for users in a group of size to rotate their keys, they must each craft a message of size to be broadcast to the group using an (untrusted) delivery server.
In larger groups, having users sequentially rotate their keys requires too much bandwidth (or takes too long), so variants allowing any users to simultaneously rotate their keys in just communication rounds have been suggested (e.g. "Propose and Commit" by MLS). Unfortunately, -round concurrent updates are either damaging or expensive (or both); i.e. they either result in future operations being more costly (e.g. via "blanking'' or "tainting'') or are costly themselves requiring communication for each user [Bienstock et al., TCC'20].
In this paper we propose CoCoA; a scheme that allows for concurrent updates that are neither damaging nor costly. That is, they add no cost to future operations yet they only require communication per user. To circumvent the [Bienstock et al.] lower bound, CoCoA increases the number of rounds needed to complete all updates from up to (at most) ; though typically fewer rounds are needed.
The key insight of the protocol is the following: in the (non-concurrent version of) TreeKEM, a delivery server which gets concurrent update requests will approve one and reject the remaining . In contrast, our server attempts to apply all of them. If more than one user requests to rotate the same key during a round, the server arbitrarily picks a winner. Surprisingly, we prove that regardless of how the server chooses the winners, all previously compromised users will recover after at most such update rounds.
To keep the communication complexity low, CoCoA is a server-aided CGKA. That is, the delivery server no longer blindly forwards packets, but instead actively computes individualized packets tailored to each user. As the server is untrusted, this change requires us to develop new mechanisms ensuring robustness of the protocol.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper5
- On the Insider Security of MLSJoël Alwen, Daniel Jost, Marta MularczykCRYPTO 2022 · 被引用 28 次
- How to Hide MetaData in MLS-Like Secure Group Messaging: Simple, Modular, and Post-QuantumKeitaro Hashimoto, Shuichi Katsumata, Thomas PrestCCS 2022 · 被引用 12 次
- Quarantined-TreeKEM: A Continuous Group Key Agreement for MLS, Secure in Presence of Inactive UsersCéline Chevalier, Guirec Lebrun, Ange Martinelli, Abdul Rahman TalebCCS 2024 · 被引用 1 次
- Cryptographic Administration for Secure Group MessagingDavid Balbás, Daniel Collins, Serge VaudenayUSENIX Security 2023
- Exploring How to Authenticate Application Messages in MLS: More Efficient, Post-Quantum, and Anonymous BlocklistableKeitaro Hashimoto, Shuichi Katsumata, Guillermo Pascual-PerezUSENIX Security 2025
相关 Paper
- Continuous Group-Key Agreement: Concurrent Updates Without PruningBenedikt Auerbach, Miguel Cueto Noval, Boran Erol, Krzysztof PietrzakCRYPTO 2025 · 被引用 2 次
- Security Analysis and Improvements for the IETF MLS Standard for Group MessagingJoël Alwen, Sandro Coretti, Yevgeniy Dodis, Yiannis TselekounisCRYPTO 2020 · 被引用 91 次
- Keep the Dirt: Tainted TreeKEM, Adaptively and Actively Secure Continuous Group Key AgreementKaren Klein, Guillermo Pascual-Perez, Michael Walter, Chethan Kamath 等S&P 2021 · 被引用 46 次
- A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEsKeitaro Hashimoto, Shuichi Katsumata, Eamonn W. Postlethwaite, Thomas Prest 等CCS 2021 · 被引用 1 次
- Fair-Weather No More: Guaranteed Efficiency in Secure Group MessagingJames Bartusek, Nir Bitansky, Yevgeniy Dodis, Rachit Garg 等CRYPTO 2026
