Paper 2026/1434
BeeKEM: Decentralized, Secure and Efficient Group Key Agreement
Abstract
Group key agreement protocols are essential for modern secure messaging. Most existing group key agreement protocols assume a centralized model with a semi-trusted service that mediates the communication. This is efficient, but problematic for some important applications, since a central service can be a choke point for surveillance and censorship. There is a nascent literature on decentralized group key agreement that avoids such reliance, but existing proposals either do not scale, with update costs linear or quadratic in the group size, or lack proofs of security. Centralized protocols can offer much lower (logarithmic) cost. We present BeeKEM, the first decentralized group key agreement protocol with logarithmic update cost in the common case (degrading to linear in the worst case) and proofs of security. We provide an open-source implementation and demonstrate that it is competitive with OpenMLS. BeeKEM opens the door for a range of communication and collaboration applications offering not only end-to-end encryption, but also metadata privacy and censorship resistance.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- CGKAkey agreementcontinuous group key agreementDCGKAsecure messaginggroup messagingdecentralization
- Contact author(s)
-
derek yen @ nyu edu
andresfg @ cs cornell edu - History
- 2026-07-16: approved
- 2026-07-13: received
- See all versions
- Short URL
- https://ia.cr/2026/1434
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1434,
author = {Derek Yen and Andrés Fábrega and Liangrun Da and Martin Kleppmann and John Mumm and Sunoo Park and Brooklyn Zelenka},
title = {{BeeKEM}: Decentralized, Secure and Efficient Group Key Agreement},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1434},
year = {2026},
url = {https://eprint.iacr.org/2026/1434}
}