Shuichi Katsumata, PQShield & AIST; Guilhem Niot, PQShield & Univ Rennes, CNRS, IRISA; Ida Tucker and Thom Wiggers, PQShield
The Signal protocol relies on a handshake protocol, formerly X3DH and now PQXDH, to set up secure conversations. One of its privacy properties, of value to Signal, is deniability, allowing users to deny participation in communications. Prior analyses of deniability for these protocols, including post-quantum variants, use models highly tailored to the individual protocols and generally make ad-hoc adaptations to "standard" AKE definitions, obscuring the concrete deniability guarantees and complicating comparisons across protocols. Building on Hashimoto et al.'s abstraction for Signal handshake protocols (USENIX '25), we address this gap by presenting a unified framework for analyzing their deniability.
We analyze Signal's classically secure X3DH and harvest-now-decrypt-later-secure PQXDH, and show that PQXDH is deniable against harvest-now-judge-later attacks, where a quantum judge retrospectively assesses the participation of classical users. We further analyze post-quantum alternatives like RingXKEM, whose deniability relies on ring signatures (RS). By introducing a novel metric inspired by differential privacy, we provide relaxed, pragmatic guarantees for deniability. We also use this metric to define deniability for RS, a relaxation of anonymity, allowing us to build an efficient RS from NIST-standardized Falcon (and MAYO), which is not anonymous, but is provably deniable.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Shuichi Katsumata and Guilhem Niot and Ida Tucker and Thom Wiggers},
title = {Comprehensive Deniability Analysis of Signal Handshake Protocols: {X3DH}, {PQXDH} to Fully {Post-Quantum} with Deniable Ring Signatures},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
isbn = {978-1-939133-52-6},
address = {Seattle, WA},
pages = {6797--6816},
url = {https://www.usenix.org/conference/usenixsecurity25/presentation/katsumata},
publisher = {USENIX Association},
month = aug
}


