Fork-resilient continuous group key agreement

J Alwen, M Mularczyk, Y Tselekounis - Annual International Cryptology …, 2023 - Springer
Abstract Continuous Group Key Agreement (CGKA) lets an evolving group of clients agree
on a sequence of group keys. An important application of CGKA is scalable end-to-end …

CoCoA: concurrent continuous group key agreement

J Alwen, B Auerbach, MC Noval, K Klein… - … Conference on the …, 2022 - Springer
Messaging platforms like Signal are widely deployed and provide strong security in an
asynchronous setting. It is a challenging problem to construct a protocol with similar security …

On the insider security of MLS

J Alwen, D Jost, M Mularczyk - Annual International Cryptology …, 2022 - Springer
Abstract The Messaging Layer Security (MLS) protocol is an open standard for end-to-end
(E2E) secure group messaging being developed by the IETF, poised for deployment to …

Server-aided continuous group key agreement

J Alwen, D Hartmann, E Kiltz, M Mularczyk - Proceedings of the 2022 …, 2022 - dl.acm.org
Continuous Group Key Agreement (CGKA)--or Group Ratcheting--lies at the heart of a new
generation of scalable End-to-End secure (E2E) cryptographic multi-party applications. One …

Cryptographic administration for secure group messaging

D Balbás, D Collins, S Vaudenay - 32nd USENIX Security Symposium …, 2023 - usenix.org
Many real-world group messaging systems delegate group administration to the application
level, failing to provide formal guarantees related to group membership. Taking a …

On the Tight Security of the Double Ratchet

D Collins, D Riepel, SAO Tran - Proceedings of the 2024 on ACM …, 2024 - dl.acm.org
The Signal Protocol is a two-party secure messaging protocol used in applications such as
Signal, WhatsApp, Google Messages and Facebook Messenger and is used by billions …

DeCAF: decentralizable continuous group key agreement with fast healing

J Alwen, B Auerbach, MC Noval, K Klein… - Cryptology ePrint …, 2022 - eprint.iacr.org
Continuous group key agreement (CGKA) allows a group of users to maintain a
continuously updated shared key in an asynchronous setting where parties only come …

Leveraging smart contracts for secure and asynchronous group key exchange without trusted third party

VY Kemmoe, Y Kwon, R Hussain… - IEEE Transactions on …, 2022 - ieeexplore.ieee.org
Group Key Exchange (GKE) is an important tool to develop secure multi-user applications
such as group text messages, ad-hoc networks, and so on. Most of the currently deployed …

The Cost of Maintaining Keys in Dynamic Groups with Applications to Multicast Encryption and Group Messaging

M Anastos, B Auerbach, MA Baig, MC Noval… - Theory of Cryptography …, 2024 - Springer
In this work we prove lower bounds on the (communication) cost of maintaining a shared key
among a dynamic group of users. Being “dynamic” means one can add and remove users …

Interval key-encapsulation mechanism

A Bienstock, Y Dodis, P Rösler, D Wichs - International Conference on the …, 2025 - Springer
Abstract Forward-Secure Key-Encapsulation Mechanism (FS-KEM; Canetti et al. Eurocrypt
2003) allows Alice to encapsulate a key k to Bob for some time t such that Bob can …