Paper 2025/2267
How to Compare Bandwidth Constrained Two-Party Secure Messaging Protocols: A Quest for A More Efficient and Secure Post-Quantum Protocol
Abstract
Transitioning existing classical two-party secure messaging protocols to post-quantum protocols has been an active movement in practice in recent years: Apple’s PQ3 protocol and the recent Triple Ratchet protocol being investigated by the Signal team with academics (Dodis et al. Eurocrypt’25). However, due to the large communication overhead of post-quantum primitives, numerous design choices non-existent in the classical setting are being explored, rendering comparison of secure messaging protocols difficult, if not impossible. In this work, we thus propose a new pragmatic metric to measure how secure a messaging protocol is given a particular communication pattern, enabling a concrete methodology to compare secure messaging protocols. We uncover that there can be no “optimal” protocol, as different protocols are often incomparable with the respect to worst-case (adversarial) messaging behaviors, especially when faced with real-world bandwidth constraints. We develop a comprehensive framework to experimentally compare various messaging protocols under given bandwidth limits and messaging behaviors. Finally, we apply our framework to compare several new and old messaging protocols. Independently, we also uncover untapped optimizations which we call opportunistic sending, leading to better post-quantum messaging protocols. To capture these optimizations, we further propose sparse continuous key agreement as a fundamental building block for secure messaging protocols, which could be of independent interest.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Major revision. USENIX Security 25
- Keywords
- secure messagingpost-quantum securitycontinuous key agreement
- Contact author(s)
-
benedikt auerbach @ pqshield com
dodis @ cs nyu edu
daniel @ blanqet net
shuichi katsumata @ pqshield com
rolfe @ signal org - History
- 2025-12-18: approved
- 2025-12-17: received
- See all versions
- Short URL
- https://ia.cr/2025/2267
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2267,
author = {Benedikt Auerbach and Yevgeniy Dodis and Daniel Jost and Shuichi Katsumata and Rolfe Schmidt},
title = {How to Compare Bandwidth Constrained Two-Party Secure Messaging Protocols: A Quest for A More Efficient and Secure Post-Quantum Protocol},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2267},
year = {2025},
url = {https://eprint.iacr.org/2025/2267}
}