Paper 2025/1437

GURKE: Group Unidirectional Ratcheted Key Exchange

Daniel Collins, Texas A&M University
Paul Rösler, FAU Erlangen-Nürnberg
Abstract

Continuous Group Key Agreement (CGKA) is a primitive with which members of a group can continuously establish shared keys. With every interaction, these members also update their individual, local secrets such that temporary corruptions of these secrets only affect the security of shared keys established shortly before (Forward Security; FS) and after the corruption (Post-Compromise Security; PCS). Due to these interactive updates–possibly enriched by dynamic group membership changes–, CGKA is a very powerful but also very complex primitive. In this work, we limit the power of CGKA to identify and analyze its core components. More concretely, we consider the case that all members of a group are always either senders or receivers. Thus, the interaction is strictly unidirectional from the former to the latter: a group of senders Alice establishes shared keys with a group of receivers Bob. With every shared key, Alice updates her local state to achieve FS and PCS; when receiving an established key, each Bob also updates their local state to achieve FS. This notion naturally lifts the so called Unidirectional Ratcheted Key Exchange concept (Bellare et al., Crypto 2017; Poettering and Rösler, Crypto 2018) to the group setting and, thereby, captures and generalizes Signal's Sender Key Mechanism, which is the core of WhatsApp and Signal's group chat protocols. We modularize this concept of Group Unidirectional RKE (GURKE) by considering either single or multiple senders, single or multiple receivers, and static or dynamic membership on each of both sides of the group. To instantiate these new primitives, we develop a building block called Updatable Broadcast KEM (UB-KEM). Using UB-KEM, our GURKE constructions for static groups only use standard Key Encapsulation Mechanisms (KEMs) and induce only a constant communication overhead. Our GURKE constructions for dynamic groups are based on general Non-Interactive Key Exchange (NIKE) and offer a constant communication overhead as long as the set of members is unchanged; only for adding and removing users, a communication overhead logarithmic in the group size is induced. We discuss the benefits of replacing the Sender Key Mechanism in Signal and WhatsApp with our constructions, and demonstrate their practicality with a performance evaluation of our proof of concept UB-KEM implementation.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in CRYPTO 2025
Keywords
Ratcheted Key ExchangeSecure MessagingContinuous Group Key AgreementBroadcast EncryptionMulticast Encryption
Contact author(s)
danielpatcollins @ gmail com
paul roesler @ fau de
History
2025-08-07: approved
2025-08-07: received
See all versions
Short URL
https://ia.cr/2025/1437
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1437,
      author = {Daniel Collins and Paul Rösler},
      title = {{GURKE}: Group Unidirectional Ratcheted Key Exchange},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1437},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1437}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.