Paper 2026/1980

Better Security Proofs for X3DH and XHMQV

Jiawei Bao, University of Kassel
Jiaxin Pan, University of Kassel
Runzhi Zeng, University of Kassel
Abstract

The Signal protocol is used by billions of users daily and recognized as the gold standard for end-to-end encrypted messaging. Its initial handshake protocol X3DH uses XEdDSA to sign its semi-static key and allows parties to derive a session key asynchronously. The protocol is implemented over Curve25519, relying on the assumed 128-bit hardness for solving Discrete Logarithms (DL). Previous non-tight reductions incur a large loss in the number of sessions, and the resulting concrete security guarantees fall far below the intended 128-bit security level. This motivates the development of tight security bounds for these protocols. In this paper, we improve the security analysis of X3DH and its recent enhancement XHMQV (Fiedler et al., CRYPTO'25) by providing tight security reductions under multi-user Diffie–Hellman (DH) assumptions (Kiltz et al., CT-RSA'23) in the Random Oracle Model. Unlike prior work, our proofs are in the more realistic multi-Test setting. The variant of X3DH that we analyze hashes additional context into the session key. Although this modification is minor, it yields tight security bounds and provides a stronger justification for the use of Curve25519. In light of our results, the Signal developers plan to adopt the same modification.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in ASIACRYPT 2026
Keywords
Secure messaginginitial handshake protocolssignaturetight security
Contact author(s)
jiawei bao @ uni-kassel de
jiaxin pan @ uni-kassel de
Runzhi Zeng @ uni-kassel de
History
2026-09-13: approved
2026-09-11: received
See all versions
Short URL
https://ia.cr/2026/1980
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1980,
      author = {Jiawei Bao and Jiaxin Pan and Runzhi Zeng},
      title = {Better Security Proofs for {X3DH} and {XHMQV}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1980},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1980}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.