{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T06:04:32Z","timestamp":1771481072690,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,12]],"date-time":"2021-11-12T00:00:00Z","timestamp":1636675200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"EPSRC","award":["EP\/M020320\/1"],"award-info":[{"award-number":["EP\/M020320\/1"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,12]]},"DOI":"10.1145\/3460120.3484542","type":"proceedings-article","created":{"date-parts":[[2021,11,13]],"date-time":"2021-11-13T12:05:34Z","timestamp":1636805134000},"page":"2024-2045","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":26,"title":["Key Agreement for Decentralized Secure Group Messaging with Strong Security Guarantees"],"prefix":"10.1145","author":[{"given":"Matthew","family":"Weidner","sequence":"first","affiliation":[{"name":"Carnegie Mellon University, Pittsburgh, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Kleppmann","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Hugenroth","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alastair R.","family":"Beresford","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,11,13]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-030--75539--3_16"},{"key":"e_1_3_2_1_2_1","volume-title":"Advances in Cryptology -- EUROCRYPT 2019","author":"Alwen Jo\u00ebl","year":"2018","unstructured":"Jo\u00ebl Alwen, Sandro Coretti, and Yevgeniy Dodis. 2019. The Double Ratchet: Security Notions, Proofs, and Modularization for the Signal Protocol. In Advances in Cryptology -- EUROCRYPT 2019 . Springer, 129--158. Full version: https:\/\/eprint.iacr.org\/2018\/1037."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-56784-2_9"},{"key":"e_1_3_2_1_4_1","volume-title":"Hong Kong protesters use a mesh network to organise. New Scientist (Sept","author":"Aron Jacob","year":"2017","unstructured":"Jacob Aron and Aviva Rutkin. 2017. Hong Kong protesters use a mesh network to organise. New Scientist (Sept. 2017). https:\/\/www.newscientist.com\/article\/dn26285-hong-kong-protesters-use-a-mesh-network-to-organise\/ Archived at https:\/\/perma.cc\/VKH7-KE9K."},{"key":"e_1_3_2_1_5_1","unstructured":"Richard Barnes Benjamin Beurdouche Jon Millican Emad Omara Katriel Cohn-Gordon and Raphael Robert. 2020. The Messaging Layer Security (MLS) Protocol. Internet-Draft draft-ietf-mls-protocol-11. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-mls-protocol-11 Work in Progress."},{"key":"e_1_3_2_1_6_1","volume-title":"Joseph Jaeger, Maya Nyayapati, and Igors Stepanovs.","author":"Bellare Mihir","year":"2017","unstructured":"Mihir Bellare, Asha Camper Singh, Joseph Jaeger, Maya Nyayapati, and Igors Stepanovs. 2017. Ratcheted Encryption and Key Exchange: The Security of Messaging. In Advances in Cryptology -- CRYPTO 2017. Springer, 619--650. Full version: https:\/\/eprint.iacr.org\/2016\/1028."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/11745853_14"},{"key":"e_1_3_2_1_8_1","unstructured":"Karthikeyan Bhargavan Richard Barnes and Eric Rescorla. 2018. TreeKEM: Asynchronous Decentralized Key Management for Large Dynamic Groups. Messaging Layer Security mailing list. https:\/\/mailarchive.ietf.org\/arch\/msg\/mls\/v1CY0jFAOVOHokB4DtNqS__tX1o"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-64378-2_8"},{"key":"e_1_3_2_1_10_1","unstructured":"Simon Bl\u00f6chinger and Richard von Seck. 2021. Survey of Mesh Networking Messengers . Technical Report. TU Munich Seminar IITM. https:\/\/doi.org\/10.2313\/NET-2021-05--1_01"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/0020-0190(91)90055-M"},{"key":"e_1_3_2_1_12_1","unstructured":"Katriel Cohn-Gordon. 2018. Trivial DoS by a malicious client. https:\/\/github.com\/mlswg\/mls-protocol\/issues\/21"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.27"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.19"},{"key":"e_1_3_2_1_15_1","unstructured":"Cas Cremers Britta Hale and Konrad Kohbrok. 2019. Efficient Post-Compromise Security Beyond One Group. Cryptology ePrint Archive Report 2019\/477. https:\/\/eprint.iacr.org\/2019\/477."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.21236\/ADA465464"},{"key":"e_1_3_2_1_17_1","volume-title":"Advances in Information and Computer Security","author":"Bet\u00fcl Durak F.","year":"2018","unstructured":"F. Bet\u00fcl Durak and Serge Vaudenay. 2019. Bidirectional Asynchronous Ratcheted Key Agreement with Linear Complexity. In Advances in Information and Computer Security. Springer, 343--362. Full version: https:\/\/eprint.iacr.org\/2018\/889."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the 11th Australian Computer Science Conference","volume":"10","author":"Fidge C. J.","year":"1988","unstructured":"C. J. Fidge. 1988. Timestamps in message-passing systems that preserve the partial ordering. Proceedings of the 11th Australian Computer Science Conference , Vol. 10, 1 (1988), 56--66."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/564585.564601"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/comst.2007.4317616"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3381991.3395399"},{"key":"e_1_3_2_1_22_1","volume-title":"Optimal Channel Security Against Fine-Grained State Compromise: The Safety of Messaging. In CRYPTO 2018","author":"Jaeger Joseph","year":"2018","unstructured":"Joseph Jaeger and Igors Stepanovs. 2018. Optimal Channel Security Against Fine-Grained State Compromise: The Safety of Messaging. In CRYPTO 2018. Springer, 33--62. Full version: https:\/\/eprint.iacr.org\/2018\/553."},{"key":"e_1_3_2_1_23_1","volume-title":"Efficient Ratcheting: Almost-Optimal Guarantees for Secure Messaging. In EUROCRYPT 2019 . 159--188","author":"Jost Daniel","year":"2019","unstructured":"Daniel Jost, Ueli Maurer, and Marta Mularczyk. 2019. Efficient Ratcheting: Almost-Optimal Guarantees for Secure Messaging. In EUROCRYPT 2019 . 159--188. Full version: https:\/\/eprint.iacr.org\/2018\/954.pdf."},{"key":"e_1_3_2_1_24_1","volume-title":"Byzantine Eventual Consistency and the Fundamental Limits of Peer-to-Peer Databases. CoRR","author":"Kleppmann Martin","year":"2020","unstructured":"Martin Kleppmann and Heidi Howard. 2020. Byzantine Eventual Consistency and the Fundamental Limits of Peer-to-Peer Databases. CoRR , Vol. abs\/2012.00472 (2020). arxiv: 2012.00472 https:\/\/arxiv.org\/abs\/2012.00472"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3--642--14623--7_34"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","unstructured":"Hugo Krawczyk and Pasi Eronen. 2010. HMAC-based Extract-and-Expand Key Derivation Function (HKDF) . RFC 5869. https:\/\/doi.org\/10.17487\/RFC5869","DOI":"10.17487\/RFC5869"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-0--387-09751-0_29"},{"key":"e_1_3_2_1_28_1","unstructured":"Moxie Marlinspike and Trevor Perrin. 2016. The X3DH Key Agreement Protocol . Technical Report Revision 1. https:\/\/www.signal.org\/docs\/specifications\/x3dh\/ Archived at https:\/\/perma.cc\/633M-J2WM."},{"key":"e_1_3_2_1_29_1","unstructured":"Matrix.org Foundation. 2019. End-to-End Encryption implementation guide. https:\/\/matrix.org\/docs\/guides\/end-to-end-encryption-implementation-guide Archived at https:\/\/perma.cc\/75RC-HS9B."},{"key":"e_1_3_2_1_30_1","unstructured":"Friedemann Mattern. 1989. Virtual Time and Global States of Distributed Systems. In Parallel & Distributed Algorithms . North-Holland 215--226."},{"key":"e_1_3_2_1_31_1","unstructured":"Emad Omara Benjamin Beurdouche Eric Rescorla Srinivas Inguva Albert Kwon and Alan Duric. 2020. The Messaging Layer Security (MLS) Architecture. Internet-Draft draft-ietf-mls-architecture-05. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-mls-architecture-05 Work in Progress."},{"key":"e_1_3_2_1_32_1","unstructured":"Trevor Perrin and Moxie Marlinspike. 2016. The Double Ratchet Algorithm . Technical Report Revision 1. https:\/\/signal.org\/docs\/specifications\/doubleratchet\/ Archived at https:\/\/perma.cc\/AJL9-MBSB."},{"key":"e_1_3_2_1_33_1","volume-title":"The Loopix Anonymity System. In USENIX Security Symposium .","author":"Piotrowska Ania M","year":"2017","unstructured":"Ania M Piotrowska, Jamie Hayes, Tariq Elahi, Sebastian Meiser, and George Danezis. 2017. The Loopix Anonymity System. In USENIX Security Symposium ."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3--319--96884--1_1"},{"key":"e_1_3_2_1_35_1","volume-title":"Carlos Baquero, and Marc Shapiro.","author":"Nuno","year":"2018","unstructured":"Nuno M. Preguicc a, Carlos Baquero, and Marc Shapiro. 2018. Conflict-free Replicated Data Types (CRDTs). CoRR , Vol. abs\/1805.06358 (2018). arxiv: 1805.06358 http:\/\/arxiv.org\/abs\/1805.06358"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","unstructured":"Paul R\u00f6sler Christian Mainka and J\u00f6rg Schwenk. 2018. More is Less: On the End-to-End Security of Group Chats in Signal WhatsApp and Threema. In 2018 IEEE EuroS&P. 415--429. https:\/\/doi.org\/10.1109\/EuroSP.2018.00036","DOI":"10.1109\/EuroSP.2018.00036"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3--642--24550--3_29"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1080\/17544750.2015.1058834"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.22"},{"key":"e_1_3_2_1_40_1","unstructured":"Richard van der Hoff. 2019. Megolm group ratchet. https:\/\/gitlab.matrix.org\/matrix-org\/olm\/-\/blob\/efd17631b16d1271a029e0af8f7d8e5ae795cc5d\/docs\/megolm.md"},{"key":"e_1_3_2_1_41_1","volume-title":"Group Messaging for Secure Asynchronous Collaboration . Master's thesis","author":"Weidner Matthew","unstructured":"Matthew Weidner. 2019. Group Messaging for Secure Asynchronous Collaboration . Master's thesis. University of Cambridge, Cambridge, UK. http:\/\/mattweidner.com\/acs-dissertation.pdf Archived at https:\/\/perma.cc\/XA8S-BHFN."},{"key":"e_1_3_2_1_42_1","volume-title":"Beresford","author":"Weidner Matthew","year":"2020","unstructured":"Matthew Weidner, Martin Kleppmann, Daniel Hugenroth, and Alastair R. Beresford. 2020. Key Agreement for Decentralized Secure Group Messaging with Strong Security Guarantees. Cryptology ePrint Archive, Report 2020\/1281. https:\/\/eprint.iacr.org\/2020\/1281."},{"key":"e_1_3_2_1_43_1","unstructured":"WhatsApp. 2017. WhatsApp Encryption Overview. https:\/\/www.whatsapp.com\/security\/WhatsApp-Security-Whitepaper.pdf Archived at https:\/\/perma.cc\/QD7M-GPG5."}],"event":{"name":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event Republic of Korea","acronym":"CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484542","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460120.3484542","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T20:52:12Z","timestamp":1763499132000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484542"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,12]]},"references-count":43,"alternative-id":["10.1145\/3460120.3484542","10.1145\/3460120"],"URL":"https:\/\/doi.org\/10.1145\/3460120.3484542","relation":{},"subject":[],"published":{"date-parts":[[2021,11,12]]},"assertion":[{"value":"2021-11-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}