The Signal Protocol
The Signal Protocol is a non-federated cryptographic protocol that provides End-to-End Encryption for voice calls, video calls, and instant messaging conversations. Developed by Moxie Marlinspike and Trevor Perrin at Open Whisper Systems in 2013, the protocol is designed to prevent third parties and even the service providers themselves from accessing plaintext message content.
The architecture of the Signal Protocol relies on several advanced cryptographic primitives. Most notably, it uses the Double Ratchet Algorithm, which combines a Diffie-Hellman ratchet and a Key Derivation Function (KDF) ratchet to ensure that keys are constantly refreshed. This mechanism provides Forward Secrecy, ensuring that if a long-term key is compromised, past communications remain secure, and Post-Compromise-Security, which allows the protocol to recover security after a session key has been leaked.
For session initialization, the protocol employs the X3DH (Extended Triple Diffie-Hellman) handshake, which allows for the establishment of a shared secret even when one party is offline. The protocol has been widely praised by the Cybersecurity community and has been integrated into several high-profile applications, including WhatsApp, Facebook Messenger, and Google Messages. Detailed formal audits of the protocol, such as those found on IACR Cryptology ePrint Archive, confirm its robust security properties. Further technical specifications are maintained by the Signal Foundation.