Paper 2019/1489
Keep the Dirt: Tainted TreeKEM, Adaptively and Actively Secure Continuous Group Key Agreement
Joël Alwen, Margarita Capretto, Miguel Cueto, Chethan Kamath, Karen Klein, Ilia Markov, Guillermo Pascual-Perez, Krzysztof Pietrzak, Michael Walter, and Michelle Yeo
Abstract
While messaging systems with strong security guarantees are widely used in practice, designing a protocol that scales efficiently to large groups and enjoys similar security guarantees remains largely open. The two existing proposals to date are ART (Cohn-Gordon et al., CCS18) and TreeKEM (IETF, The Messaging Layer Security Protocol, draft). TreeKEM is the currently considered candidate by the IETF MLS working group, but dynamic group operations (i.e. adding and removing users) can cause efficiency issues. In this paper we formalize and analyze a variant of TreeKEM which we term Tainted TreeKEM (TTKEM for short). The basic idea underlying TTKEM was suggested by Millican (MLS mailing list, February 2018). This version is more efficient than TreeKEM for some natural distributions of group operations, we quantify this through simulations.
Our second contribution is two security proofs for TTKEM which establish post compromise and forward secrecy even against adaptive attackers. If
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Major revision. IEEE Symposium on Security and Privacy 2021
- Keywords
- Messaging Layer SecurityGroup Key-Agreement ProtocolsTreeKEMAdaptive Security
- Contact author(s)
-
guillermo pascualperez @ ist ac at
michael walter @ ist ac at
krzpie @ gmail com
jalwen @ wickr com
karen klein @ ist ac at - History
- 2020-10-20: last of 2 revisions
- 2019-12-30: received
- See all versions
- Short URL
- https://ia.cr/2019/1489
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2019/1489, author = {Joël Alwen and Margarita Capretto and Miguel Cueto and Chethan Kamath and Karen Klein and Ilia Markov and Guillermo Pascual-Perez and Krzysztof Pietrzak and Michael Walter and Michelle Yeo}, title = {Keep the Dirt: Tainted {TreeKEM}, Adaptively and Actively Secure Continuous Group Key Agreement}, howpublished = {Cryptology {ePrint} Archive, Paper 2019/1489}, year = {2019}, url = {https://eprint.iacr.org/2019/1489} }