What is the Exact Security of the Signal Protocol?
What is the Exact Security of the Signal Protocol?
复制标题
信号协议的确切安全性是什么?
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Srinivasan Raghuraman
中科院分区:
文献类型:
--
作者:
Alexander Bienstock;Jaiden Fairoze;Sanjam Garg;Pratyay Mukherjee;Srinivasan Raghuraman
In this work we develop comprehensive definitions in the Universal Composability framework to study the Signal Double Ratchet (Signal for short) protocol. Our definitions enable a more fine-grained and rigorous analysis of the exact security of Signal by explicitly capturing many new security guarantees, in addition to the ones that were already identified in the state-of-art work by Alwen, Coretti and Dodis [Eurocrypt 2019]. Moreover, our definitions provide the ability to more easily build on top of Signal, using the UC Composition Theorem. The Signal protocol, as it is described in the whitepaper, securely realizes our ideal functionality FSignal. However, as we interpret from the high-level description in the whitepaper, the guarantees of FSignal seem slightly weaker than those one would expect Signal to satisfy. Therefore we provide a stronger, more natural definition, formalized through the ideal functionality FSignal+ . Based on our definitions we are able to make many important insights as follows: • We observe several shortcomings of Alwen et al.’s game-based security notions. To demonstrate them, we construct four different modified versions of the Signal protocol, all of which are insecure according to our weaker FSignal definition, but remain secure according to their definitions. Among them, one variant was suggested for use by Alwen et al.; another one was suggested for use by the Signal whitepaper itself. • We identify the exact assumptions required for the full security of Signal. In particular, our security proofs use the gap-Diffie-Hellman assumption and the random oracle model, as opposed to the DDH assumption and standard model used in Alwen et al. • We demonstrate the shortcomings of Signal with respect to our stronger functionality FSignal+ by showing a non-trivial (albeit minor) weakness with respect to that definition. • Finally, we complement the above weakness by providing a minimalistic modification to Signal (that we call the Triple Ratchet) and show that the resulting protocol securely realizes the stronger functionality FSignal+ . Remarkably, the modification incurs no additional communication cost and virtually no additional computational cost.