Paper 2021/1686

Hecate: Abuse Reporting in Secure Messengers with Sealed Sender

Rawane Issa, Nicolas Alhaddad, and Mayank Varia


End-to-end encryption provides strong privacy protections to billions of people, but it also complicates efforts to moderate content that can seriously harm people. To address this concern, Tyagi et al. [CRYPTO 2019] introduced the concept of asymmetric message franking (AMF), which allows people to report abusive content to a moderator, while otherwise retaining end-to-end privacy by default and even compatibility with anonymous communication systems like Signal’s sealed sender. In this work, we provide a new construction for asymmetric message franking called Hecate that is faster, more secure, and introduces additional functionality compared to Tyagi et al. First, our construction uses fewer invocations of standardized crypto primitives and operates in the plain model. Second, on top of AMF’s accountability and deniability requirements, we also add forward and backward secrecy. Third, we combine AMF with source tracing, another approach to content moderation that has previously been considered only in the setting of non-anonymous networks. Source tracing allows for messages to be forwarded, and a report only identifies the original source who created a message. To provide anonymity for senders and forwarders, we introduce a model of "AMF with preprocessing" whereby every client authenticates with the moderator out-of-band to receive a token that they later consume when sending a message anonymously.

Available format(s)
Publication info
Published elsewhere. MAJOR revision.USENIX Security 2022
end-to-end encrypted messaginganonymitytracingabuse reportingmessage franking
Contact author(s)
ra1issa @ bu edu
2022-05-11: last of 4 revisions
2021-12-30: received
See all versions
Short URL
Creative Commons Attribution


      author = {Rawane Issa and Nicolas Alhaddad and Mayank Varia},
      title = {Hecate: Abuse Reporting in Secure Messengers with Sealed Sender},
      howpublished = {Cryptology ePrint Archive, Paper 2021/1686},
      year = {2021},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.