Case B4D530 · Cryptography · L5 Expert
Group E2EE with MLS
Practise as: Deep dive · Interview
Interview questionHow would you design end-to-end encryption for groups of thousands of members, and how does MLS approach it?
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Pairwise sessions make group re-keying cost O(n); MLS (RFC 9420) uses a TreeKEM ratchet tree, typically O(log n) per commit.
- State advances in epochs; each Commit feeds the key schedule a new secret, giving forward secrecy and post-compromise security.
- Removing a member blanks their leaf and the commit re-keys the committer path, so the removed member cannot derive the next epoch.
- Members are authenticated by credentials bound to signature keys; clients must trust the Authentication Service that vouches.
- The Delivery Service orders handshake messages but is untrusted for confidentiality; it can still drop, delay or split views.
If the interviewer pushes back
- How would you add key transparency so clients can detect an Authentication Service issuing rogue credentials?
- Why do many removals leave blank nodes that degrade TreeKEM efficiency, and how do full-path commits restore it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.