2024/05/20 by David Soler, Carlos Dafonte, Soler, David +8 · 1 voice · 1 citation
Computer Science · Social Sciences · #Access Control and Trust #Advanced Authentication Protocols Security #Cryptography and Data Security #Security in Wireless Sensor Networks #User Authentication and Security Systems
paper · doi:10.1016/j.comnet.2026.112302
openalex publication_date 2026/04/01 · crossref created 2026/04/21 · openalex created_date 2026/04/22 · openalex updated_date 2026/04/22 · crossref issued 2026/06/01 · crossref published 2026/06/01 · crossref published-print 2026/06/01 · crossref deposited 2026/07/04 · crossref indexed 2026/07/04
Messaging Layer security (MLS) and its underlying Continuous Group Key Agreement (CGKA) protocol allows a group of users to share a cryptographic secret in a dynamic manner, such that the secret is modified in member insertions and deletions. Although this flexibility makes MLS ideal for implementations in distributed environments, a number of issues need to be overcome. Particularly, the use of digital certificates for authentication in a group goes against the group members' privacy. In this work we provide an alternative method of authentication in which the solicitors, instead of revealing their identity, only need to prove possession of certain attributes, dynamically defined by the group, to become a member. Instead of digital certificates, we employ Attribute-Based Credentials accompanied with Selective Disclosure in order to reveal the minimum required amount of information and to prevent attackers from linking the activity of a user through multiple groups. We formally define a CGKA variant named Attribute-Authenticated Continuous Group Key Agreement (AA-CGKA) and provide security proofs for its properties of Requirement Integrity, Unforgeability and Unlinkability. We also provide guidelines for an integration of our construction in MLS.