arrow
Return

Efficient Multi-Designated Receiver Authenticated Broadcast Encryption for Group Messaging

delete2026-02-11
delete0
PRE
AI
Z
Z. Z. Zhang
C
Chunxiang Xu
C
Chuhan Ma
DOI:10.1109/TON.2026.3663579delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Communication protocol is a fundamental component of modern networking. With proliferation of networking and communication, users have become more concerned about privacy. This leads to development of end-to-end encrypted messaging systems which provides confidential communication. Besides confidentiality, there is an increasing demand for additional security properties such as unforgeability, anonymity, off-the-record (OTR), and consistency. However, efficiently achieving these properties simultaneously, especially on resource-constrained mobile devices, remains a significant challenge. In this paper, we propose MERIT, a novel multi-designated receiver authenticated broadcast encryption scheme that satisfies all the above security guarantees in a highly efficient manner. MERIT ensures the following key properties: 1) unforgeability prevents unauthorized parties from generating valid messages; 2) privacy safeguards the messages and identities of the sender and receivers from non-designated parties; 3) OTR ensures that receivers cannot later prove the origin of the messages even with their secret keys; and 4) consistency ensures that all designated receivers obtain identical decrypted messages and identities. The core building block of MERIT is a practical multi-designated verifier signature (PMDVS), which might be of independent interest. We employed a novel batched cut-and-choose technology to prove that the ciphertext is well-formed. This results in an order-of-magnitude efficiency improvement in our scheme compared to its counterparts that rely on general-purpose zero-knowledge proofs. We then show how MERIT leverages PMDVS to provide unforgeability, privacy, OTR, and consistency in the scenario of group messaging. We provide security analysis to demonstrate that MERIT satisfies these security guarantees. We also conduct a thorough performance implementation, and the experimental results demonstrate that MERIT is highly efficient for deployment on mobile devices.
Keywords:
Group messaging
broadcast encryption
privacy preservation
off-the-record
mobile devices

Journal

I
IEEE Transactions on Networking
IF:
0
Papers:
543
Citations:
0

Organization

U
university of electronic science and technology of china
Scholars:
1.3W
Papers: 4.7K
Citations: 4