The Signal protocol is the most widely deployed end-to-end-encrypted messaging protocol. Its initial handshake protocol \(\textsf{X3DH}\) allows parties to asynchronously derive a shared session key without the need to be online simultaneously, while providing implicit authentication, forward secrecy, and a form of offline deniability. The \(\textsf{X3DH}\) protocol has been extensively studied in the cryptographic literature and is acclaimed for its strong “maximum-exposure” security guarantees, hedging against compromises of users’ long-term keys and medium-term keys but also the ephemeral randomness used in the handshake. This maximum-exposure security is achieved by deriving keys from the concatenation of 3–4 Diffie–Hellman (DH) secrets, each combining two long-term, medium-term, or ephemeral DH shares. Remarkably, \(\textsf{X3DH}\) ’s approach of concatenating plain DH combinations is sub-optimal, both in terms of maximum-exposure security and performance. Indeed, Krawczyk’s well-known HMQV protocol (Crypto ’05) is a high-performance, DH-based key exchange that provides strong security against long-term and ephemeral key compromise. One might hence wonder: why not base Signal’s initial handshake on HMQV? In this work, we study this question and show that a carefully adapted variant of HMQV, which we call \(\textsf{XHMQV}\) , indeed enables stronger security and efficiency while matching the constraints of Signal’s initial handshake. Most notably, HMQV does not work as a drop-in replacement for \(\textsf{X3DH}\) , as the latter’s asynchronicity requires the protocol to handle cases where one party runs out of ephemeral keys (pre-uploaded to the Signal server). Our \(\textsf{XHMQV}\) design hence augments HMQV with medium-term keys analogous to those used in \(\textsf{X3DH}\) . We prove that \(\textsf{XHMQV}\) provides security in all 3–4 compromise scenarios where \(\textsf{X3DH}\) does and additionally in 1–2 further scenarios, strengthening the handshake’s maximum-exposure guarantees while using more efficient group operations. We further confirm that our \(\textsf{XHMQV}\) design achieves deniability guarantees comparable to \(\textsf{X3DH}\) . Our security model is the first to capture Signal’s long-term key reuse between DH key exchange and signatures, which may be of independent interest.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

\(\textsf{XHMQV}\) : Better Efficiency and Stronger Security for Signal’s Initial Handshake based on HMQV

  • Rune Fiedler,
  • Felix Günther,
  • Jiaxin Pan,
  • Runzhi Zeng

摘要

The Signal protocol is the most widely deployed end-to-end-encrypted messaging protocol. Its initial handshake protocol \(\textsf{X3DH}\) allows parties to asynchronously derive a shared session key without the need to be online simultaneously, while providing implicit authentication, forward secrecy, and a form of offline deniability. The \(\textsf{X3DH}\) protocol has been extensively studied in the cryptographic literature and is acclaimed for its strong “maximum-exposure” security guarantees, hedging against compromises of users’ long-term keys and medium-term keys but also the ephemeral randomness used in the handshake. This maximum-exposure security is achieved by deriving keys from the concatenation of 3–4 Diffie–Hellman (DH) secrets, each combining two long-term, medium-term, or ephemeral DH shares. Remarkably, \(\textsf{X3DH}\) ’s approach of concatenating plain DH combinations is sub-optimal, both in terms of maximum-exposure security and performance. Indeed, Krawczyk’s well-known HMQV protocol (Crypto ’05) is a high-performance, DH-based key exchange that provides strong security against long-term and ephemeral key compromise. One might hence wonder: why not base Signal’s initial handshake on HMQV? In this work, we study this question and show that a carefully adapted variant of HMQV, which we call \(\textsf{XHMQV}\) , indeed enables stronger security and efficiency while matching the constraints of Signal’s initial handshake. Most notably, HMQV does not work as a drop-in replacement for \(\textsf{X3DH}\) , as the latter’s asynchronicity requires the protocol to handle cases where one party runs out of ephemeral keys (pre-uploaded to the Signal server). Our \(\textsf{XHMQV}\) design hence augments HMQV with medium-term keys analogous to those used in \(\textsf{X3DH}\) . We prove that \(\textsf{XHMQV}\) provides security in all 3–4 compromise scenarios where \(\textsf{X3DH}\) does and additionally in 1–2 further scenarios, strengthening the handshake’s maximum-exposure guarantees while using more efficient group operations. We further confirm that our \(\textsf{XHMQV}\) design achieves deniability guarantees comparable to \(\textsf{X3DH}\) . Our security model is the first to capture Signal’s long-term key reuse between DH key exchange and signatures, which may be of independent interest.