Paper 2026/1622
Formal Security Analysis of the Olvid Messenger
Abstract
We perform the first formal security analysis of the cryptographic core of Olvid, an end-to-end encrypted messaging app notably used by French government officials, including ministers. Despite its deployment in sensitive contexts and its role in critical communications infrastructure, Olvid's cryptographic security has received little independent analysis. To address this gap, we develop detailed models of Olvid's authenticated key exchange and continuous key agreement protocols. We formally verify that our protocol models achieve security properties such as mutual authentication, session-key secrecy, forward secrecy, and replay protection, under an active Dolev-Yao network adversary model that can compromise parties. While we constructively prove that the protocol design meets core security guarantees, our analysis also reveals that, contrary to its claims, the protocol does not meet strong modern security properties that are met by other state-of-the-art secure-messaging protocols, such as Signal. For example, we show in our formal analysis that Olvid is not secure in modern security models such as eCK. Along the way, we uncover a potential timing leakage, and discuss Olvid's anonymity claims.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Major revision. ACM CCS 2026
- Keywords
- Secure MessagingFormal AnalysisTamarin ProverSecurity ProtocolsTiming Attacks
- Contact author(s)
-
noemi terzo @ mpi-sp org
cremers @ cispa de
mail @ ruben-gonzalez de
peter @ cryptojedi org
yuval yarom @ rub de
zhiyuan zhang @ mpi-sp org - History
- 2026-08-06: approved
- 2026-08-05: received
- See all versions
- Short URL
- https://ia.cr/2026/1622
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1622,
author = {Noemi Terzo and Cas Cremers and Ruben Gonzalez and Peter Schwabe and Yuval Yarom and Zhiyuan Zhang},
title = {Formal Security Analysis of the Olvid Messenger},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1622},
year = {2026},
url = {https://eprint.iacr.org/2026/1622}
}