Paper 2026/1165
On the State-Compromise Security of End-to-End Real-Time Group Communication
Abstract
Real-time group communication protocols, such as Zoom and Microsoft Teams, aim to provide end-to-end security for audio and video conferences even in the presence of a malicious server. Despite their widespread deployment, particularly since the COVID-19 pandemic, their intended security guarantees lack comprehensive formalization. Prior work largely focuses on Zoom, and analyzes its security in models that rely on restrictive assumptions, such as the existence of a trusted server at certain points in time or a long-lived leader that never leaves the group. Moreover, existing analyses assume that group-specific session states of group members are secure and incorruptible, leaving the impact of potential full state compromise on group security unexplored. In this work, we propose a set of essential security guarantees for real time group communication with state-compromise resilience against fully malicious servers and provide the first construction that provably satisfies all of these guarantees. To formally prove that our design achieves its goal, we formalize a novel continuous group key distribution protocol and introduce an associated security model that captures all the intended guarantees. We propose a generic construction that is provably secure in this model and suggest both classical and post-quantum secure instantiations. Besides these main design goals, we introduce a novel multi-recipient authenticated key encapsulation mechanism, which serves as a building block for our generic construction. We define two core security notions for maKEM, propose both concrete and generic constructions, and prove their security in the random oracle model and the standard model, respectively.
Note: Version 1.1: June 15, 2026: - Added changelog. - Fixed typos and improved editorial quality. - Added intuition for Lemma 1.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- A major revision of an IACR publication in CRYPTO 2026
- Keywords
- Real-time CommunicationGroup CommunicationKey DistributionMulti-Recipient Authenticated KEMmaKEM
- Contact author(s)
-
mang zhao @ hotmail com
qianwang @ whu edu cn - History
- 2026-06-15: revised
- 2026-06-04: received
- See all versions
- Short URL
- https://ia.cr/2026/1165
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1165,
author = {Mang Zhao and Qian Wang},
title = {On the State-Compromise Security of End-to-End Real-Time Group Communication},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1165},
year = {2026},
url = {https://eprint.iacr.org/2026/1165}
}