Paper 2025/1872

Interoperable Symmetric Message Franking

Carolina Ortega Pérez, Cornell University
Thomas Ristenpart, Cornell Tech
Julia Len, University of North Carolina at Chapel Hill
Abstract

The recent Digital Markets Act (DMA), a regulation passed by the European Union in 2022, requires messaging applications with large user bases to support interoperable end-to-end encrypted (E2EE) communication. This raises numerous questions about how to adapt cryptographic protocols to this setting in a way that preserves security and privacy. This question is not only limited to the main messaging protocols, but also extends to protocols for abuse mitigation such as the symmetric message franking protocol first proposed by Facebook. The latter uses symmetric cryptography to enable reporting abusive E2EE messages in a way that allows the platform to cryptographically verify the report's veracity. In this paper, we initiate a formal treatment of interoperable symmetric message franking (IMF). We focus on a server-to-server messaging flow, where messages are routed sequentially through the sender's and recipient's service providers, but allow the recipient to dynamically choose who to send a report to. We formalize the security definitions for IMF including adapting the sender and recipient binding definitions into various reportability and unforgeability definitions that take into account one of the service providers misbehaving. We also prove relations among these new definitions. Finally, we detail an IMF construction that satisfies the security definitions, and include a discussion of users' identity privacy goals and deployment considerations.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published elsewhere. ACM CCS 2025
Contact author(s)
carolina @ cs cornell edu
History
2025-10-11: approved
2025-10-08: received
See all versions
Short URL
https://ia.cr/2025/1872
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1872,
      author = {Carolina Ortega Pérez and Thomas Ristenpart and Julia Len},
      title = {Interoperable Symmetric Message Franking},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1872},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1872}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.