Open cardosec

Case B4D530 · Cryptography · L5 Expert

Group E2EE with MLS

Practise as: Deep dive · Interview

Interview questionHow would you design end-to-end encryption for groups of thousands of members, and how does MLS approach it?

  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Pairwise sessions make group re-keying cost O(n); MLS (RFC 9420) uses a TreeKEM ratchet tree, typically O(log n) per commit.
  2. State advances in epochs; each Commit feeds the key schedule a new secret, giving forward secrecy and post-compromise security.
  3. Removing a member blanks their leaf and the commit re-keys the committer path, so the removed member cannot derive the next epoch.
  4. Members are authenticated by credentials bound to signature keys; clients must trust the Authentication Service that vouches.
  5. The Delivery Service orders handshake messages but is untrusted for confidentiality; it can still drop, delay or split views.

If the interviewer pushes back

  • How would you add key transparency so clients can detect an Authentication Service issuing rogue credentials?
  • Why do many removals leave blank nodes that degrade TreeKEM efficiency, and how do full-path commits restore it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.