Paper 2026/1980
Better Security Proofs for X3DH and XHMQV
Abstract
The Signal protocol is used by billions of users daily and recognized as the gold standard for end-to-end encrypted messaging. Its initial handshake protocol X3DH uses XEdDSA to sign its semi-static key and allows parties to derive a session key asynchronously. The protocol is implemented over Curve25519, relying on the assumed 128-bit hardness for solving Discrete Logarithms (DL). Previous non-tight reductions incur a large loss in the number of sessions, and the resulting concrete security guarantees fall far below the intended 128-bit security level. This motivates the development of tight security bounds for these protocols. In this paper, we improve the security analysis of X3DH and its recent enhancement XHMQV (Fiedler et al., CRYPTO'25) by providing tight security reductions under multi-user Diffie–Hellman (DH) assumptions (Kiltz et al., CT-RSA'23) in the Random Oracle Model. Unlike prior work, our proofs are in the more realistic multi-Test setting. The variant of X3DH that we analyze hashes additional context into the session key. Although this modification is minor, it yields tight security bounds and provides a stronger justification for the use of Curve25519. In light of our results, the Signal developers plan to adopt the same modification.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2026
- Keywords
- Secure messaginginitial handshake protocolssignaturetight security
- Contact author(s)
-
jiawei bao @ uni-kassel de
jiaxin pan @ uni-kassel de
Runzhi Zeng @ uni-kassel de - History
- 2026-09-13: approved
- 2026-09-11: received
- See all versions
- Short URL
- https://ia.cr/2026/1980
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1980,
author = {Jiawei Bao and Jiaxin Pan and Runzhi Zeng},
title = {Better Security Proofs for {X3DH} and {XHMQV}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1980},
year = {2026},
url = {https://eprint.iacr.org/2026/1980}
}