arXiv · 2207.08891
Wink: Deniable Secure Messaging
Abstract
End-to-end encrypted (E2EE) messaging is an essential first step in providing message confidentiality. Unfortunately, all security guarantees of end-to-end encryption are lost when keys or plaintext are disclosed, either due to device compromise or (sometimes lawful) coercion by powerful adversaries. This work introduces Wink, the first plausibly-deniable messaging system protecting message confidentiality from partial device compromise and compelled key disclosure. Wink can surreptitiously inject hidden messages in standard random coins (e.g., salts, IVs) used by existing E2EE protocols. It does so as part of legitimate secure cryptographic functionality deployed inside the widely-available trusted execution environment (TEE) TrustZone. This results in hidden communication using virtually unchanged existing E2EE messaging apps, as well as strong plausible deniability. Wink has been demonstrated with multiple existing E2EE applications (including Telegram and Signal) with minimal (external) instrumentation, negligible overheads, and crucially, without changing on-wire message formats.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Anrin Chakraborti, Darius Suciu, Radu Sion. 2023-06-10. Wink: Deniable Secure Messaging. https://arxiv.org/abs/2207.08891
Cite the original work for its findings. Save a collection to share your selection of sources.