An Efficient and Generic Construction for Signal’s Handshake (X3DH): Post-quantum, State Leakage Secure, and Deniable

An Efficient and Generic Construction for Signal’s Handshake (X3DH): Post-quantum, State Leakage Secure, and Deniable
复制标题

DOI:
10.1007/s00145-022-09427-1
复制
发表时间:
2022-05
影响因子:
3
通讯作者:
Keitaro Hashimoto;Shuichi Katsumata;Kris Kwiatkowski;Thomas Prest
Keitaro Hashimoto;Shuichi Katsumata;Kris Kwiatkowski;Thomas Prest
中科院分区:
计算机科学4区
文献类型:
--
作者:
Keitaro Hashimoto;Shuichi Katsumata;Kris Kwiatkowski;Thomas Prest

文献摘要

相似文献

Signal协议是一种安全的即时消息协议,它是WhatsApp、Skype、Facebook Messenger等众多应用程序的安全基础。信令协议由两个子协议组成,即X3DH协议和双棘轮协议,后者最近得到了很大的关注。例如,Alwen、Coretti和Dodis(Eurocrypt‘19)提供了一个具体的安全模型,以及一个基于简单构建块的通用结构,这些构建块可以从多种假设中实例化,包括后量子假设。相比之下,据我们所知,关注X3DH协议的工作似乎有限。在这项工作中,我们将X3DH协议描述为一种特定类型的认证密钥交换(AKE)协议,我们称之为符合Signal的AKE协议,并在已有的关于AKE协议的工作的基础上形式化地定义了它的安全模型。然后,我们基于密钥封装机制(KEM)和签名方案等标准密码原语,首次有效地构造了符合信号的AKE协议。具体地说,这导致了基于公认的假设的第一个后量子安全的X3DH协议的替换。与X3DH协议类似,我们的符合信号的AKE协议提供了一种很强(或更强)的安全性,其中交换的密钥保持安全,即使长期秘密和会话特定秘密的所有非平凡组合都被泄露。此外,我们的协议具有较弱的可否认性,我们进一步展示了如何使用环签名和/或非交互零知识证明系统来逐步加强它。最后,我们提供了我们(弱可否认的)协议的一个成熟的、通用的C实现。我们用NIST后量子标准化过程的几个第三轮候选者(决赛和候补者)来实例化它,并比较所产生的带宽和计算性能。我们的实现是公开可用的。
The Signal protocol is a secure instant messaging protocol that underlies the security of numerous applications such as WhatsApp, Skype, Facebook Messenger among many others. The Signal protocol consists of two sub-protocols known as the X3DH protocol and the double ratchet protocol, where the latter has recently gained much attention. For instance, Alwen, Coretti, and Dodis (Eurocrypt’19) provided a concrete security model along with a generic construction based on simple building blocks that are instantiable from versatile assumptions, including post-quantum ones. In contrast, as far as we are aware, works focusing on the X3DH protocol seem limited. In this work, we cast the X3DH protocol as a specific type of authenticated key exchange (AKE) protocol, which we call aSignal-conforming AKEprotocol, and formally define its security model based on the vast prior works on AKE protocols. We then provide the first efficient generic construction of a Signal-conforming AKE protocol based on standard cryptographic primitives such as key encapsulation mechanisms (KEM) and signature schemes. Specifically, this results in the first post-quantum secure replacement of the X3DH protocol based on well-established assumptions. Similar to the X3DH protocol, our Signal-conforming AKE protocol offers a strong (or stronger) flavor of security, where the exchanged key remains secure even when all the non-trivial combinations of the long-term secrets and session-specific secrets are compromised. Moreover, our protocol has a weak flavor of deniability and we further show how to progressively strengthen it using ring signatures and/or non-interactive zero-knowledge proof systems. Finally, we provide a full-fledged, generic C implementation of our (weakly deniable) protocol. We instantiate it with several Round 3 candidates (finalists and alternates) to the NIST post-quantum standardization process and compare the resulting bandwidth and computation performances. Our implementation is publicly available.