How to Hide MetaData in MLS-Like Secure Group Messaging
Keitaro Hashimoto, Shuichi Katsumata, Thomas Prest · Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security · 2022
Secure group messaging (SGM) protocols allow large groups of users to communicate in a secure and asynchronous manner. In recent years, continuous group key agreements (CGKAs) have provided a powerful abstraction to reason on the security properties we expect from SGM protocols. While robust techniques have been developed to protect the contents of conversations in this context, it is in general more challenging to protect metadata (e.g. the identity and social relationships of group members), since their knowledge is often needed by the server in order to ensure the proper function of the SGM protocol.