惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI
大猫的无限游戏
大猫的无限游戏
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
爱范儿
爱范儿
The Cloudflare Blog
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
博客园_首页
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
V
V2EX
V
Visual Studio Blog
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队

Cryptology ePrint Archive

Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies PipeSC: A Resource-efficient and Pipelined Hardware Accelerator for Sumcheck Protocol Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning High-Throughput Side-Channel-Protected Stream Cipher Hardware for 6G Systems Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX Zeal: PIR for Non-Cooperative Databases VEIL: Lightweight Zero-Knowledge for Hash-Based Multilinear Proof Systems Witness-Indistinguishable Arguments of Knowledge and One-Way Functions The many faces of Schnorr: a touch-up Open Problems in List Decoding and Correlated Agreement Compressed Key Exchange Protocol from Orientations of Large Discriminant Using AVX-512 SPLASH: SPeculative Leakage-Adaptive Secure Hardware An Efficient Identity-Based Blind Signature Scheme from SM9 Efficient Batch Threshold Encryption Using Partial Fraction Techniques A note on the Unsuitability of LIGA for Linkable Ring Signatures: The perils of non-commutativity Verification Facade: Masquerading Insecure Cryptographic Implementations as Verified Code Cryptographic Implications of Worst-Case Hardness of Time-Bounded Kolmogorov Complexity Efficient Merkle-Tree Consistent Accumulator FLOSS: Fast Linear Online Secret-Shared Shuffling Which Privacy Blanket is Optimal in the Shuffle Model?
ETK: External-Operations TreeKEM and the Security of MLS ...
2025-02-14 · via Cryptology ePrint Archive

Paper 2025/229

ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420

Esra Günsay, CISPA Helmholtz Center for Information Security

Vera Wesselkamp, Hasso Plattner Institute

Mang Zhao, Wuhan University

Abstract

The Messaging Layer Security protocol MLS is standardized in IETF's RFC 9420 and allows a group of parties to securely establish and evolve group keys even if the servers are malicious. The core design of MLS is based on the TreeKEM protocol, which was significantly modified and extended during the standard's development. Over the last years, several partial security analyses have appeared of incomplete drafts of the standard. One of the major additions to MLS RFC 9420 (the final version of the standard) are the external operations, i.e., external commits and proposals. These additional operations have not been considered in any previous security analysis, while they can have a significant impact on the standard's security. In this work, we prove the consistency, confidentiality and authentication of MLS in RFC 9420. To this end, we formalize $\mathsf{ETK}$: External-Operations TreeKEM, which models RFC 9420 and includes the external commits and proposals. We propose a corresponding ideal functionality $\mathcal{F}_{\mathrm{ECGKA}}$ and prove that $\mathsf{ETK}$ realizes it. Our work is the first cryptographic analysis that considers both the final changes to the standard, and the first approach overall to cover external proposals and external commits. Compared to previous works that considered MLS drafts, our $\mathsf{ETK}$ protocol is by far the closest to the final MLS RFC 9420 standard. Our analysis implies that the core of MLS in RFC 9420 is an $\mathsf{ETK}$ protocol that realizes $\mathcal{F}_{\mathrm{ECGKA}}$. Notably, we show that when external proposals and commits are allowed, MLS achieves a weaker form of security than was suggested by previous analyses, because the external operations can be exploited to violate Post-Compromise Security guarantees. We show that the security of the protocol can be further strengthened by leveraging the standard's optional PSK mechanism, allowing another form of healing, and give a corresponding construction $\mathsf{ETK}^{\mathrm{PSK}}$ and ideal functionality $\mathcal{F}_{\mathrm{ECGKA}^{\mathrm{PSK}}}$.

Note: Version 2.0, April 11, 2026: - Added Changelog. - Extended security results in Section 5.2. - Substantial additions including simpli ed versions of ETK, ETKPSK, and helper functions. - Updated the parent-hash computation from the Draft 12 formulation to the version adopted in MLS since Draft 13. - Updated technical details and improved consistency regarding the corruption of isk and ssk in Figures 13 and 15.

BibTeX

@misc{cryptoeprint:2025/229,
      author = {Cas Cremers and Esra Günsay and Vera Wesselkamp and Mang Zhao},
      title = {{ETK}: External-Operations {TreeKEM} and the Security of {MLS} in {RFC} 9420},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/229},
      year = {2025},
      url = {https://eprint.iacr.org/2025/229}
}