惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News and Events Feed by Topic
Stack Overflow Blog
Stack Overflow Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
量子位
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog RSS Feed
F
Full Disclosure
aimingoo的专栏
aimingoo的专栏
云风的 BLOG
云风的 BLOG
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
A
About on SuperTechFans
G
Google Developers Blog
U
Unit 42
腾讯CDC
雷峰网
雷峰网
爱范儿
爱范儿
H
Help Net Security
Engineering at Meta
Engineering at Meta
Vercel News
Vercel News
Cloudbric
Cloudbric
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
S
Secure Thoughts
有赞技术团队
有赞技术团队
Jina AI
Jina AI
L
LINUX DO - 最新话题
Martin Fowler
Martin Fowler
C
Cybersecurity and Infrastructure Security Agency CISA
V
Visual Studio Blog
TaoSecurity Blog
TaoSecurity Blog
F
Fortinet All Blogs
S
Security @ Cisco Blogs
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
IT之家
IT之家
T
The Blog of Author Tim Ferriss
K
Kaspersky official blog
N
News | PayPal Newsroom
美团技术团队
月光博客
月光博客
PCI Perspectives
PCI Perspectives
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Google Online Security Blog
Google Online Security Blog
L
LINUX DO - 热门话题
Help Net Security
Help Net Security
Recent Announcements
Recent Announcements
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
Latest news
Latest news
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Cryptology ePrint Archive

Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies PipeSC: A Resource-efficient and Pipelined Hardware Accelerator for Sumcheck Protocol Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning High-Throughput Side-Channel-Protected Stream Cipher Hardware for 6G Systems Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX Zeal: PIR for Non-Cooperative Databases VEIL: Lightweight Zero-Knowledge for Hash-Based Multilinear Proof Systems Witness-Indistinguishable Arguments of Knowledge and One-Way Functions The many faces of Schnorr: a touch-up Open Problems in List Decoding and Correlated Agreement Compressed Key Exchange Protocol from Orientations of Large Discriminant Using AVX-512 SPLASH: SPeculative Leakage-Adaptive Secure Hardware An Efficient Identity-Based Blind Signature Scheme from SM9 Efficient Batch Threshold Encryption Using Partial Fraction Techniques A note on the Unsuitability of LIGA for Linkable Ring Signatures: The perils of non-commutativity Verification Facade: Masquerading Insecure Cryptographic Implementations as Verified Code Cryptographic Implications of Worst-Case Hardness of Time-Bounded Kolmogorov Complexity Efficient Merkle-Tree Consistent Accumulator FLOSS: Fast Linear Online Secret-Shared Shuffling Which Privacy Blanket is Optimal in the Shuffle Model? Applications of Bruhat-Chevalley-Renner Decomposition to Metric-Aware Code-Based Cryptography Expanders Meet Reed-Muller: Easy Instances of Noisy k-XOR Verifiable Divide-and-Conquer Pseudorandomness of UFLM: A Characterization via Its Linear Layer QED-Lite: Lightweight Detection of Quantum-Vulnerable ELF Binaries via Cryptographic Library Version Fingerprinting Reformulating the SNOVA Signature Scheme Game Theory Does Not Always Help: The Case of Statistical Multi-Party Coin Tossing Improved Codes and Decoders for HQC Delegate: Coalition Proof Incentivized Outsourced Computation with Smart Contracts Fast and Efficient Perfectly Secure Network-Agnostic Secure Computation Tighter Bounds for the Oblivious Bit-Fixing Inner Product Extractor on Biased Seeds Random Robust Secret Sharing with Perfect Privacy and its Applications Counting and recovering the quadratic relations of a vectorial function A Search-to-Decision Reduction for Continuous LWE Robot: Robust Threshold BBS+ in Two Rounds Perils of Parallelism: Transaction Fee Mechanisms under Execution Uncertainty Synthesis of RTL-based Characterization Programs for Fault Injection SSLE-DAG: A High-Throughput Proof-of-Stake Consensus Protocol Combining an Adaptive DAG with a Single Secret Leader Election On Optimal Information-Theoretic Security in Symmetric Encryption under Low-Entropy Keys Efficient and Parallel Implementation of Isogeny-based Deterministic Group Actions Fast and Compact Lattice-Based Registration-Based Encryption Graph-based Asynchrony with Quasilinear Complexity for Any Linear Verifiable Secret Sharing Scheme MTSF --- Market-Theoretic Security Framework: A Unified Paradigm For The Art Of Proving and Disproving Security Ticket to Hide: Private, Practical Proofs of Provenance for TLS Linear Code Equivalence via Plücker Coordinates Survey of isogeny-based signature schemes resistant to Castryck–Decru attack On the Need for (Quantum) Memory with Short Outputs Simulating Noisy Leakage with Bounded Leakage: Simpler, Better, Faster Relaxed Modular PCS from Arbitrary PCS and Applications to SNARKs for Integers Tripling on Hessian curves via isogeny decomposition Reducing the Number of Qubits in Quantum Discrete Logarithms on Elliptic Curves At-Compromise Security: The Case for Alert Blindness A Practical Neighborhood Search Attack on Oracle MLWE Designated-Verifier Dynamic zk-SNARKs with Applications to Dynamic Proofs of Index Abelian surfaces in Hesse form and explicit isogeny formulas Efficiently Provable Approximations for Non-Polynomial Functions Laminate: Succinct SIMD-Friendly Verifiable FHE Accelerating FrodoKEM in Hardware TSS-PV: Traceable Secret Sharing with Public Verifiability PIRANHAS: PrIvacy-Preserving Remote Attestation in Non-Hierarchical Asynchronous Swarms Small-field hash-based SNARGs are less sound than conjectured Hash-Based Blind Signatures: First Steps Partial Fraction Techniques for Cryptography VIA: Communication-Efficient Single-Server Private Information Retrieval Enabling Index-free Adjacency in Oblivious Graph Processing with Delayed Duplications Accurate BGV Parameters Selection: Accounting for Secret and Public Key Dependencies in Average-Case Analysis Multi-Party Functional Encryption (MPFE): A tool in the distributed and decentralized world Compact, Efficient and CCA-Secure Updatable Encryption from Isogenies Faster Homomorphic Integer Computer Tempo: An ML-KEM to PAKE Compiler Resilient to Timing Attacks OhLaLa: Combined Security against Region Fault Attacks in Constant Protection Order Threshold Signatures Reloaded: ML-DSA and Enhanced Raccoon with Identifiable Aborts The Pipes Model for Latency and Throughput Analysis Tighter Quantum Security for Fiat-Shamir-with-Aborts and Hash-and-Sign-with-Retry Signatures InstaRand: Instantly Available and Instantly Verifiable On-chain Randomness Simple and Efficient Lattice Threshold Signatures with Identifiable Aborts BERMUDA: A BPSec-Compatible Key Management Scheme for DTNs Making Uncertified DAG BFT Provably Live with Linear Payload and Quadratic Metadata Communication A proof of P≠NP (New symmetric encryption algorithm against any linear attacks and differential attacks) A Combinatorial Attack on Ternary Sparse Learning with Errors (sLWE) A Divide-and-Conquer Strategy for Hard-Label Extraction of Deep Neural Networks via Side-Channel Attacks On the practicality of quantum sieving algorithms for the shortest vector problem Dynamic zk-SNARKs (with applications to sparse zk-SNARKs and IVC) ProxCode: Efficient Proximity Searchable Encryption from Error Correcting Codes Two-Round Threshold Signature from Algebraic One-More Learning with Errors The Last Challenge Attack on Fiat-Shamir in KZG-based SNARKs A New Perspective on Key Switching for BGV-like Schemes Improved Circuit Synthesis with Multi-Value Bootstrapping for FHEW-like Schemes DiStefano: Decentralized Infrastructure for Sharing Trusted Encrypted Facts and Nothing More Finding and Evaluating Parameters for BGV
ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420
2025-02-14 · via Cryptology ePrint Archive

Paper 2025/229

ETK: External-Operations TreeKEM and the Security of MLS in RFC 9420

Esra Günsay, CISPA Helmholtz Center for Information Security

Vera Wesselkamp, Hasso Plattner Institute

Mang Zhao, Wuhan University

Abstract

The Messaging Layer Security protocol MLS is standardized in IETF's RFC 9420 and allows a group of parties to securely establish and evolve group keys even if the servers are malicious. The core design of MLS is based on the TreeKEM protocol, which was significantly modified and extended during the standard's development. Over the last years, several partial security analyses have appeared of incomplete drafts of the standard. One of the major additions to MLS RFC 9420 (the final version of the standard) are the external operations, i.e., external commits and proposals. These additional operations have not been considered in any previous security analysis, while they can have a significant impact on the standard's security. In this work, we prove the consistency, confidentiality and authentication of MLS in RFC 9420. To this end, we formalize $\mathsf{ETK}$: External-Operations TreeKEM, which models RFC 9420 and includes the external commits and proposals. We propose a corresponding ideal functionality $\mathcal{F}_{\mathrm{ECGKA}}$ and prove that $\mathsf{ETK}$ realizes it. Our work is the first cryptographic analysis that considers both the final changes to the standard, and the first approach overall to cover external proposals and external commits. Compared to previous works that considered MLS drafts, our $\mathsf{ETK}$ protocol is by far the closest to the final MLS RFC 9420 standard. Our analysis implies that the core of MLS in RFC 9420 is an $\mathsf{ETK}$ protocol that realizes $\mathcal{F}_{\mathrm{ECGKA}}$. Notably, we show that when external proposals and commits are allowed, MLS achieves a weaker form of security than was suggested by previous analyses, because the external operations can be exploited to violate Post-Compromise Security guarantees. We show that the security of the protocol can be further strengthened by leveraging the standard's optional PSK mechanism, allowing another form of healing, and give a corresponding construction $\mathsf{ETK}^{\mathrm{PSK}}$ and ideal functionality $\mathcal{F}_{\mathrm{ECGKA}^{\mathrm{PSK}}}$.

Note: Version 2.0, April 11, 2026: - Added Changelog. - Extended security results in Section 5.2. - Substantial additions including simpli ed versions of ETK, ETKPSK, and helper functions. - Updated the parent-hash computation from the Draft 12 formulation to the version adopted in MLS since Draft 13. - Updated technical details and improved consistency regarding the corruption of isk and ssk in Figures 13 and 15.

BibTeX

@misc{cryptoeprint:2025/229,
      author = {Cas Cremers and Esra Günsay and Vera Wesselkamp and Mang Zhao},
      title = {{ETK}: External-Operations {TreeKEM} and the Security of {MLS} in {RFC} 9420},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/229},
      year = {2025},
      url = {https://eprint.iacr.org/2025/229}
}