Paper 2026/1165

On the State-Compromise Security of End-to-End Real-Time Group Communication

Mang Zhao, Wuhan University
Qian Wang, Wuhan University
Abstract

Real-time group communication protocols, such as Zoom and Microsoft Teams, aim to provide end-to-end security for audio and video conferences even in the presence of a malicious server. Despite their widespread deployment, particularly since the COVID-19 pandemic, their intended security guarantees lack comprehensive formalization. Prior work largely focuses on Zoom, and analyzes its security in models that rely on restrictive assumptions, such as the existence of a trusted server at certain points in time or a long-lived leader that never leaves the group. Moreover, existing analyses assume that group-specific session states of group members are secure and incorruptible, leaving the impact of potential full state compromise on group security unexplored. In this work, we propose a set of essential security guarantees for real time group communication with state-compromise resilience against fully malicious servers and provide the first construction that provably satisfies all of these guarantees. To formally prove that our design achieves its goal, we formalize a novel continuous group key distribution protocol and introduce an associated security model that captures all the intended guarantees. We propose a generic construction that is provably secure in this model and suggest both classical and post-quantum secure instantiations. Besides these main design goals, we introduce a novel multi-recipient authenticated key encapsulation mechanism, which serves as a building block for our generic construction. We define two core security notions for maKEM, propose both concrete and generic constructions, and prove their security in the random oracle model and the standard model, respectively.

Note: Version 1.1: June 15, 2026: - Added changelog. - Fixed typos and improved editorial quality. - Added intuition for Lemma 1.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in CRYPTO 2026
Keywords
Real-time CommunicationGroup CommunicationKey DistributionMulti-Recipient Authenticated KEMmaKEM
Contact author(s)
mang zhao @ hotmail com
qianwang @ whu edu cn
History
2026-06-15: revised
2026-06-04: received
See all versions
Short URL
https://ia.cr/2026/1165
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1165,
      author = {Mang Zhao and Qian Wang},
      title = {On the State-Compromise Security of End-to-End Real-Time Group Communication},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1165},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1165}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.