With the widespread adoption of end-to-end encryption (E2EE) in messaging services, it has become the standard for protecting personal chats. However, sensitive data isn’t limited to personal communication channels: Collaborative online documents such as Google Docs, Apple Notes, and Microsoft 365 also contain data—whether for personal or business use—that requires confidentiality.
Many collaborative document services do not use E2EE for co-editing. Although the content is transmitted and stored in encrypted form, it must be decrypted on the providers’ servers to enable users to edit it together. This means that the respective service providers can access personal documents at any time. Researchers from Bochum have now developed a method that allows the E2EE principle to be applied to collaborative documents using a messaging service such as Signal.
Award at the USENIX Security Symposium 2026
In their paper End-to-End Encrypted Collaborative Documents, CASA researchers and members of the Max Planck Institute for Security and Privacy (MPI-SP), Carmela Troncoso and Zayd Maradni, together with Christian Knabenhans from EPFL, apply the principle of E2EE to collaborative documents. In doing so, they consider common functional requirements of users and design a model that uses the Signal messenger as an encrypted, asynchronous broadcast channel for synchronizing edits. Their work was honored with the Internet Defense Prize and an Honorable Mention at the prestigious USENIX Security Symposium 2026.
Security Meets Usability
At its core, a collaborative document is based on a reconciliation mechanism that ensures all users have access to a consistent version of the document at all times. Existing solutions implement this mechanism either on the server side or on the client side. While security-focused approaches such as CryptPad encrypt communication between users, they do not offer fully transparent security guarantees.
To make their method as user-friendly as possible, the researchers first examined what requirements users have for collaborative documents. A practical system must enable unrestricted collaboration: Multiple people should be able to edit and share documents simultaneously or at different times. In addition, users expect role-based access control that allows different permissions—such as reading, commenting, or editing—to be assigned.
A New Approach to Secure Collaboration
In their approach, the researchers combine a mechanism for synchronizing edits with an end-to-end encrypted (E2EE) broadcast channel. This results in an end-to-end encrypted collaborative document (E2EE-CD).
In practical implementation, they use the cryptographic protocol of the Signal messenger (Signal Protocol). This protocol already fulfils key requirements such as E2EE and is used by millions of people worldwide every day. The researchers are expanding the existing features of Signal chat to meet the requirements for collaborative documents: When a person creates a new document, a Signal group is created. Other collaborators gain access by joining this group. All changes are then shared via the Signal group, converted into a transferable format, and applied to a local copy of the document.
In a series of experiments, the researchers tested various scenarios and evaluated the trade-off between usability and security. The system responded with a delay of about 120 milliseconds and proved to be scalable.
The results show that an E2EE broadcast channel is sufficient for implementing secure collaborative document systems and lay the foundation for collaborative document systems that meet high security requirements while also being suitable for practical use.
Original Publication
End-to-End Encrypted Collaborative Documents
Christian Knabenhans, EPFL; Zayd Maradni, MPI-SP Max Plank Institute for Security and Privacy; Carmela Troncoso, MPI-SP Max Plank Institute for Security and Privacy, EPFL
2026, USENIX Security Symposium, Baltimore, USA
Press Contact
Carmela Troncoso, carmela.troncoso(at)mpi-sp.org
General note: In case of using gender-assigning attributes we include all those who consider themselves in this gender regardless of their own biological sex.