Paper 2025/2267

How to Compare Bandwidth Constrained Two-Party Secure Messaging Protocols: A Quest for A More Efficient and Secure Post-Quantum Protocol

Benedikt Auerbach, PQShield
Yevgeniy Dodis, New York University
Daniel Jost, Blanqet
Shuichi Katsumata, PQShield, National Institute of Advanced Industrial Science and Technology
Rolfe Schmidt, Signal Messenger
Abstract

Transitioning existing classical two-party secure messaging protocols to post-quantum protocols has been an active movement in practice in recent years: Apple’s PQ3 protocol and the recent Triple Ratchet protocol being investigated by the Signal team with academics (Dodis et al. Eurocrypt’25). However, due to the large communication overhead of post-quantum primitives, numerous design choices non-existent in the classical setting are being explored, rendering comparison of secure messaging protocols difficult, if not impossible. In this work, we thus propose a new pragmatic metric to measure how secure a messaging protocol is given a particular communication pattern, enabling a concrete methodology to compare secure messaging protocols. We uncover that there can be no “optimal” protocol, as different protocols are often incomparable with the respect to worst-case (adversarial) messaging behaviors, especially when faced with real-world bandwidth constraints. We develop a comprehensive framework to experimentally compare various messaging protocols under given bandwidth limits and messaging behaviors. Finally, we apply our framework to compare several new and old messaging protocols. Independently, we also uncover untapped optimizations which we call opportunistic sending, leading to better post-quantum messaging protocols. To capture these optimizations, we further propose sparse continuous key agreement as a fundamental building block for secure messaging protocols, which could be of independent interest.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Major revision. USENIX Security 25
Keywords
secure messagingpost-quantum securitycontinuous key agreement
Contact author(s)
benedikt auerbach @ pqshield com
dodis @ cs nyu edu
daniel @ blanqet net
shuichi katsumata @ pqshield com
rolfe @ signal org
History
2025-12-18: approved
2025-12-17: received
See all versions
Short URL
https://ia.cr/2025/2267
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2267,
      author = {Benedikt Auerbach and Yevgeniy Dodis and Daniel Jost and Shuichi Katsumata and Rolfe Schmidt},
      title = {How to Compare Bandwidth Constrained Two-Party Secure Messaging Protocols: A Quest for A More Efficient and Secure Post-Quantum Protocol},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2267},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2267}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.