Ratcheted Encryption and Key Exchange: The Security of Messaging

Mihir Bellare, Asha Camper Singh, Joseph Jaeger, Maya Nyayapati, and Igors Stepanovs


We aim to understand, formalize and provably achieve the goals underlying the core key-ratcheting technique of Borisov, Goldberg and Brewer, extensions of which are now used in secure messaging systems. We give syntax and security definitions for ratcheted encryption and key-exchange. We give a proven-secure protocol for ratcheted key exchange. We then show how to generically obtain ratcheted encryption from ratcheted key-exchange and standard encryption.

Note: Fixed the upper bounds provided for the security of ODHE in ROM assumption in Appendix A.

CRYPTO 2017
symmetric encryptionforward securitybackward securityauthenticated key exchangeDiffie-HellmanOff-the-Record Messaging protocolSignal protocol
istepano @ eng ucsd edu
