Secure Collaboration On Shared Documents

Max Planck Society

Researchers develope end-to-end encryption for significantly more secure collaborative documents based on the Signal protocol

Person typing on a laptop with a digital document icon displayed at the center of the screen, connected by lines to multiple user profile icons. The illustration represents electronic document management, digital collaboration, workflow automation, or online document sharing.

To encrypt communication in collaborative documents end-to-end, the researchers are using the Signal protocol.

© AdobeStock_tadamichi

To encrypt communication in collaborative documents end-to-end, the researchers are using the Signal protocol.
© AdobeStock_tadamichi

To the point:

  • Secure collaboration on documents: A new approach enables true end-to-end encrypted (E2EE) collaborative documents, closing a major privacy gap in today’s online document services.
  • Real-time end-to-end encryption: Unlike existing collaboration platforms, which decrypt documents on providers’ servers during co-editing, the method keeps document content end-to-end encrypted while supporting real-time collaboration and role-based access control.
  • Encryption based on the Signal protocol: By extending the Signal Protocol to synchronize document changes, the approach demonstrates that secure, practical, and scalable collaborative editing is possible, with response times of around 120 milliseconds.

Researchers from the Max Planck Institute for Security and Privacy, EPFL and the CASA Cluster of Excellence have developed a new approach that provides end-to-end encryption for collaborative online documents throughout the entire process, thereby combining high security standards with the requirements of modern collaboration.

With the widespread adoption of end-to-end encryption (E2EE) in messaging services, it has become the standard for protecting personal chats. However, sensitive data isn’t limited to personal communication channels: Collaborative online documents such as Google Docs, Apple Notes, and Microsoft 365 also contain data-whether for personal or business use-that requires confidentiality.

Many collaborative document services do not use E2EE for co-editing. Although the content is transmitted and stored in encrypted form, it must be decrypted on the providers’ servers to enable users to edit it together. This means that the respective service providers can access personal documents at any time. Researchers from Bochum have now developed a method that allows the E2EE principle to be applied to collaborative documents using a messaging service such as Signal.

Award at the USENIX Security Symposium 2026

In their paper End-to-End Encrypted Collaborative Documents, researchers from the Max Planck Institute for Security and Privacy (MPI-SP), Carmela Troncoso and Zayd Maradni, together with Christian Knabenhans from EPFL, apply the principle of E2EE to collaborative documents. In doing so, they consider common functional requirements of users and design a model that uses the Signal messenger as an encrypted, asynchronous broadcast channel for synchronizing edits. Their work was honored with the Internet Defense Prize and an Honorable Mention at the prestigious USENIX Security Symposium 2026.

Security Meets Usability

At its core, a collaborative document is based on a reconciliation mechanism that ensures all users have access to a consistent version of the document at all times. Existing solutions implement this mechanism either on the server side or on the client side. While security-focused approaches such as CryptPad encrypt communication between users, they do not offer fully transparent security guarantees.

To make their method as user-friendly as possible, the researchers first examined what requirements users have for collaborative documents. A practical system must enable unrestricted collaboration: Multiple people should be able to edit and share documents simultaneously or at different times. In addition, users expect role-based access control that allows different permissions-such as reading, commenting, or editing-to be assigned.

A New Approach to Secure Collaboration

In their approach, the researchers combine a mechanism for synchronizing edits with an end-to-end encrypted (E2EE) broadcast channel. This results in an end-to-end encrypted collaborative document (E2EE-CD).

In practical implementation, they use the cryptographic protocol of the Signal messenger (Signal Protocol). This protocol already fulfils key requirements such as E2EE and is used by millions of people worldwide every day. The researchers are expanding the existing features of Signal chat to meet the requirements for collaborative documents: When a person creates a new document, a Signal group is created. Other collaborators gain access by joining this group. All changes are then shared via the Signal group, converted into a transferable format, and applied to a local copy of the document.

In a series of experiments, the researchers tested various scenarios and evaluated the trade-off between usability and security. The system responded with a delay of about 120 milliseconds and proved to be scalable.

The results show that an E2EE broadcast channel is sufficient for implementing secure collaborative document systems and lay the foundation for collaborative document systems that meet high security requirements while also being suitable for practical use.

Text: Annika Sengalski

/Public Release. View in full here.