Signal recently deployed a new handshake protocol named \(\textsf{PQXDH} \) to protect against “harvest now, decrypt later” attacks of a future quantum computer. To this end, \(\textsf{PQXDH} \) adds a post-quantum KEM to the Diffie–Hellman combinations of the prior \(\textsf{X3DH} \) handshake. In this work, we give a reductionist security analysis of Signal’s \(\textsf{PQXDH} \) handshake in a game-based security model that captures the targeted “maximum-exposure” security against both classical and quantum adversaries, allowing fine-grained compromise of user’s long-term, semi-static, and ephemeral key material. We augment prior such models to capture not only the added KEM component but also the signing of public keys, which prior analyses did not capture but which adds an additional flavor of post-quantum security in \(\textsf{PQXDH} \) . We then establish fully parameterized, concrete security bounds for the classical and post-quantum session key security of \(\textsf{PQXDH} \) , and discuss how design choices in \(\textsf{PQXDH} \) make a KEM binding property necessary and how a lack of domain separation reduces the achievable security. Our discussion of KEM binding and domain separation complements the concurrent tool-based analysis of \(\textsf{PQXDH} \) by Bhargavan, Jacomme, Kiefer, and Schmidt (USENIX Security 2024), which pointed out a potential re-encapsulation attack if the KEM shared secret does not bind the public key. In contrast to the tool-based analysis, we analyze all protocol modes of \(\textsf{PQXDH} \) and its “maximum-exposure” security. We further show that both \(\textsf{Kyber} \) (used in \(\textsf{PQXDH} \) ) and the NIST standard \(\textsf{ML} \text {-}\textsf{KEM} \) (expected to replace \(\textsf{Kyber} \) ) satisfy a novel binding notion we introduce and rely on for our \(\textsf{PQXDH} \) analysis, which may be of independent interest.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security Analysis of Signal’s \(\textsf{PQXDH} \) Handshake

  • Rune Fiedler,
  • Felix Günther

摘要

Signal recently deployed a new handshake protocol named \(\textsf{PQXDH} \) to protect against “harvest now, decrypt later” attacks of a future quantum computer. To this end, \(\textsf{PQXDH} \) adds a post-quantum KEM to the Diffie–Hellman combinations of the prior \(\textsf{X3DH} \) handshake. In this work, we give a reductionist security analysis of Signal’s \(\textsf{PQXDH} \) handshake in a game-based security model that captures the targeted “maximum-exposure” security against both classical and quantum adversaries, allowing fine-grained compromise of user’s long-term, semi-static, and ephemeral key material. We augment prior such models to capture not only the added KEM component but also the signing of public keys, which prior analyses did not capture but which adds an additional flavor of post-quantum security in \(\textsf{PQXDH} \) . We then establish fully parameterized, concrete security bounds for the classical and post-quantum session key security of \(\textsf{PQXDH} \) , and discuss how design choices in \(\textsf{PQXDH} \) make a KEM binding property necessary and how a lack of domain separation reduces the achievable security. Our discussion of KEM binding and domain separation complements the concurrent tool-based analysis of \(\textsf{PQXDH} \) by Bhargavan, Jacomme, Kiefer, and Schmidt (USENIX Security 2024), which pointed out a potential re-encapsulation attack if the KEM shared secret does not bind the public key. In contrast to the tool-based analysis, we analyze all protocol modes of \(\textsf{PQXDH} \) and its “maximum-exposure” security. We further show that both \(\textsf{Kyber} \) (used in \(\textsf{PQXDH} \) ) and the NIST standard \(\textsf{ML} \text {-}\textsf{KEM} \) (expected to replace \(\textsf{Kyber} \) ) satisfy a novel binding notion we introduce and rely on for our \(\textsf{PQXDH} \) analysis, which may be of independent interest.