Paper 2025/204

On the Composable Security of MDVS and MDRS-PKE Constructions

Chen-Da Liu-Zhang, Lucerne University of Applied Sciences and Arts, Web3 Foundation
Christopher Portmann, Concordium
Guilherme Rito, Ruhr University Bochum
Abstract

Off-The-Record (OTR) messaging applications are designed to provide so-called Deniable Authentication guarantees. These allow a sender Alice to designate a receiver Bob and sign him a message m that only he can validate. While Bob is guaranteed Alice signed m, he cannot convince non-designated Judy that Alice signed m, even if he gives Judy his secret keys. This is because, as Judy knows, Bob could have forged that signature. In recent work, Liu-Zhang, Portmann and Rito construct the first fully Off-The-Record group messaging application (ePrint 2024/1593). Central to their construction are new idealized communication channels that provide rather strong Deniable Authentication guarantees. While these channels are introduced to capture the guarantees provided by Multi-Designated Verifier Signatures (MDVS) and Multi-Designated Receiver Signed Public Key Encryption (MDRS-PKE) schemes, no scheme is proven to construct them. More, the only composable treatment of MDVS schemes does not guarantee deniability for messages that are read by honest parties (Maurer, Portmann and Rito, ASIACRYPT ’21). In contrast, however, the channels assumed for the construction of the OTR messenger provide this guarantee, meaning their OTR messenger has no known provably secure instantiations. We close this gap by providing a new (generic) composable treatment of MDVS and MDRS-PKE schemes. Interestingly, our treatment allowed us to identify a new property, Forgery Invalidity, without which we do not know how to prove the deniability of neither MDVS nor MDRS-PKE schemes when honest receivers read. We show that any MDVS and MDRS-PKE scheme providing this guarantee (plus other known ones) constructs the idealized channel semantics that are assumed by Liu-Zhang, Portmann and Rito’s OTR messenger construction. Then, we prove that Chakraborty et al.’s MDVS (EUROCRYPT ’23) has this property, and that Maurer et al.’s MDRS-PKE (EUROCRYPT ’22) preserves it from the underlying MDVS. Together, our results imply that Liu-Zhang, Portmann and Rito’s OTR messenger can be securely instantiated from Chakraborty et al.’s MDVS, or from Maurer et al.’s MDRS-PKE.

Metadata
Available format(s)
PDF
Publication info
Preprint.
Contact author(s)
chendaliu @ gmail com
chportma @ gmail com
guilherme teixeira rito @ gmail com
History
2026-02-16: last of 3 revisions
2025-02-11: received
See all versions
Short URL
https://ia.cr/2025/204
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/204,
      author = {Chen-Da Liu-Zhang and Christopher Portmann and Guilherme Rito},
      title = {On the Composable Security of {MDVS} and {MDRS}-{PKE} Constructions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/204},
      year = {2025},
      url = {https://eprint.iacr.org/2025/204}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.