Paper 2026/1622

Formal Security Analysis of the Olvid Messenger

Noemi Terzo, Max Planck Institute for Security and Privacy (MPI-SP)
Cas Cremers, CISPA Helmholtz Center for Information Security
Ruben Gonzalez, Neodyme AG
Peter Schwabe, Max Planck Institute for Security and Privacy (MPI-SP), Radboud University Nijmegen
Yuval Yarom, Ruhr University Bochum
Zhiyuan Zhang, Max Planck Institute for Security and Privacy (MPI-SP)
Abstract

We perform the first formal security analysis of the cryptographic core of Olvid, an end-to-end encrypted messaging app notably used by French government officials, including ministers. Despite its deployment in sensitive contexts and its role in critical communications infrastructure, Olvid's cryptographic security has received little independent analysis. To address this gap, we develop detailed models of Olvid's authenticated key exchange and continuous key agreement protocols. We formally verify that our protocol models achieve security properties such as mutual authentication, session-key secrecy, forward secrecy, and replay protection, under an active Dolev-Yao network adversary model that can compromise parties. While we constructively prove that the protocol design meets core security guarantees, our analysis also reveals that, contrary to its claims, the protocol does not meet strong modern security properties that are met by other state-of-the-art secure-messaging protocols, such as Signal. For example, we show in our formal analysis that Olvid is not secure in modern security models such as eCK. Along the way, we uncover a potential timing leakage, and discuss Olvid's anonymity claims.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Major revision. ACM CCS 2026
Keywords
Secure MessagingFormal AnalysisTamarin ProverSecurity ProtocolsTiming Attacks
Contact author(s)
noemi terzo @ mpi-sp org
cremers @ cispa de
mail @ ruben-gonzalez de
peter @ cryptojedi org
yuval yarom @ rub de
zhiyuan zhang @ mpi-sp org
History
2026-08-06: approved
2026-08-05: received
See all versions
Short URL
https://ia.cr/2026/1622
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1622,
      author = {Noemi Terzo and Cas Cremers and Ruben Gonzalez and Peter Schwabe and Yuval Yarom and Zhiyuan Zhang},
      title = {Formal Security Analysis of the Olvid Messenger},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1622},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1622}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.