Signal protocol X3DH

E831072

Signal protocol X3DH is a key agreement protocol used in secure messaging systems to establish forward-secure, asynchronous end-to-end encrypted sessions between users.

All labels observed (2)

How this entity was disambiguated

Statements (51)

Predicate Object
instanceOf asynchronous key exchange protocol
cryptographic protocol
key agreement protocol
abbreviation X3DH
basedOn Diffie–Hellman key exchange
category end-to-end encryption technology
componentOf Signal Protocol
linked to: Signal protocol
designedBy Moxie Marlinspike
Trevor Perrin
extends triple Diffie–Hellman (3DH)
firstPublicationYear 2016
followsModel triple Diffie–Hellman pattern
fullName Extended Triple Diffie-Hellman
hasPhase initial handshake phase
prekey publication phase
session key derivation phase
providesProperty asynchronous operation
authentication
deniability
forward secrecy
identity binding
publishedBy Open Whisper Systems
roleInProtocolSuite initial key agreement for the Signal Double Ratchet
securityGoal confidentiality of session keys
mutual authentication
post-compromise security for future sessions
resistance to key compromise impersonation
resistance to replay attacks
specifiedIn X3DH: Extended Triple Diffie-Hellman Key Agreement protocol specification
supports asynchronous message setup
clients that are offline during key establishment
threatModel active network attacker
passive eavesdropper
usedBy Facebook Messenger Secret Conversations
Google RCS end-to-end encryption (based on Signal protocol)
Signal messenger
Signal secure messaging protocol
WhatsApp end-to-end encryption
linked to: Signal protocol

Wire messenger (Signal-based variants historically)
usedFor asynchronous key agreement
establishing end-to-end encrypted sessions
forward-secure key establishment
secure messaging
usesCurve Curve25519 (in Signal’s implementation)
usesKeyType ephemeral key
identity key
one-time prekey
signed prekey
usesPrimitive digital signatures
elliptic-curve Diffie–Hellman
public-key cryptography

How these facts were elicited

Referenced by (2)

Full triples — surface form annotated when it differs from this entity's canonical label.

Curve25519-based schemes supportsProtocol Signal protocol X3DH
Signal protocol X3DH specifiedIn X3DH: Extended Triple Diffie-Hellman Key Agreement protocol specification
linked to: Signal protocol X3DH