1 of 22

Signal Protocol

The Modern, Open-Source, Encryption Protocol behind WhatsApp

Authors:

Y. B.

Anon

(2016)

2 of 22

What’s with WhatsApp?

  • Signal Protocol used in:
    • WhatsApp (February 2016, 1 Billion Users)
    • Facebook Secret Conversations
    • Google Allo
  • End-to-End Encryption (April 2016)
    • Powered by Signal Protocol
      • Moxie Marlinspike

3 of 22

Agenda

  • Terminology
  • Other Protocols
    • How Signal Optimizes the Protocols
  • Inner Workings of Signal Protocol
  • Implementation
    • Session initialization
    • Messages
  • Services, misc

4 of 22

Terminology

  • Ratchet
  • Forward and Future Secrecy

5 of 22

Previous Protocols

  • Pretty Good Privacy (PGP)
  • Off-the-Record (OTR)
  • SCIMP Ratcheting

6 of 22

Pretty Good Privacy (PGP)

  • Public-Key Scheme (asymmetric)
  • Common use e-mails (or files)
  • Digital signatures provide a strong proof of authorship.

Highlights:

  1. Asynchronous
  2. Long-term keys and non-reputability
  3. Lacks Forward Secrecy

7 of 22

Off-the-Record (OTR)

  • “Off-the-Record”, mimics casual conversation.

  • Reputability, instead of non-reputability
  • Short-term keys (forward secrecy, lower degree of permanance)

8 of 22

Off-the-Record (OTR) Ratcheting

  • Each roundtrip uses a new key
  • Can’t forward key until Bob acknowledges
  • Lacks forward secrecy (intermittently)

9 of 22

SCIMP (Silent Circle Instant Messaging)

  • Allows for “Forward Secrecy”
  • Lacks “Future Secrecy”

10 of 22

Key Derivation Function

  • A KDF generates keys using cryptographic primitives as input
    • Signal implements this by calculating the HMAC of Elliptic Curve Key Pairs
  • Handshake RootKey (RK)
    • Initial authentication, similar to a certificate
    • 3-DH handshake provides � authenticity and deniability
    • Inputs: ID keys 'A','B' , ephemeral keys 'a','b'
  • Conversation RootKey
    • Refreshed at each DH-exchange
    • Initially derived from RootKey
    • Subsequently derived from itself, DH-pair

11 of 22

12 of 22

Cryptographic Ratchet

  • Algorithm continuously generates new keys
  • Key Generation referred to as "advancing ratchet"
  • Double Ratchet (generic overview):
    • Combination of two ratchets, outer and inner
    • advancement of outer ratchet�spawns new inner ratchet,�deprecates previous inner ratchet
    • Essentially:� one outer click generates two keys
    • Application:�seed symmetric cipher with asymmetric key

13 of 22

Signal Protocol Double-Ratchet

  • Algorithm combines two ratcheting protocols� to enable secure offline communications
  • Uses ECDH Key Exchange and HMAC-SHA256
  • Generates one Message Key (MK) per message:
    • ECDH key pairs form a root key RK
      • HMAC of RK forms chain key CK
      • HMAC of CK forms MK
      • If recipient offline, i.e. unable to exchange new keys:
        • New RK',CK' derived from HMAC of current RK,CK
      • ElseIf recipient exchanges new keys:
        • CK is reset

14 of 22

Signal Protocol Double Ratchet

  • Security:
    • Message Key
      • Deriving MK from CK is secure - MK cannot be used to predict MK'
    • Root Key
      • Three DH shared secrets input to HKDF
        • Essentially a symmetric key: both parties derive same key
      • Provides second-party authentication ("A knows this message is from B")
      • Provides third-party deniability� ("Grace does not know whether Alice or Bob sent message")
    • Caveat:
      • User ID transmitted to Server� -> have to trust server not to reveal participants of conversation to PRISM
      • Message content is encrypted, no need to worry

15 of 22

Signal Protocol - Registration

  • Both Clients submit public keys to server at install time
  • Key Server: pre-shared keys enable asynchronous authentication

16 of 22

Signal Protocol - Session Initiation

  • A requests� B public keys from S
  • S sends B public keys � deletes one � pre-shared key
  • A computes initial � RootKey, ChainKey� from master secret

17 of 22

Signal Protocol - Session Reception

  • S sends B public keys of A and ID of B's expired pre-shared key
  • B computes same master_secret as A, then deletes the expired pre-shared key
  • A computes initial RootKey, ChainKey from master secret

18 of 22

Signal Protocol - Message Exchange

19 of 22

20 of 22

Cryptographic Primitives

  • Curve25519
    • (Diffie-Helman)
    • y2 = x3 + 486662x2 + x defined over the prime number 2255 − 19 (hence 25519).
  • HMAC-SHA256
    • (hashing algorithm for key derivations)
  • AES-256
    • (message encryption)
  • HKDF
    • Used to transform key material

21 of 22

Services

  • Forward Secrecy
  • Future Secrecy
  • Message Ordering
  • Replay Protection
  • Authentication
  • Deniability

22 of 22

Conclusion

  • Modern secure communication

Should we trust closed source implementation?

What about local storage?