RFC 9420: Messaging Layer Security
Summary
RFC 9420 defines MLS for efficient end-to-end encryption in dynamic groups. Group encryption is more than pairwise encryption between many participants. Removed members must lose future access cryptographically.
Ideas
- A ratchet tree distributes key changes in a scalable way.
- Membership changes create new epochs.
- Authentication and confidentiality are modelled separately.
Remarks
- RFC 9420 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Use reviewed MLS libraries instead of your own group ratchets.
- Protect identity binding and device synchronisation as well as message keys.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.