Signal Protocol Double Ratchet Key Exchange State Visualizer
Explore end-to-end encryption cryptography interactively. Step through Diffie-Hellman (DH) ratchets, KDF symmetric-key chains, out-of-order message key derivations, and forward secrecy state transitions powering Signal and WhatsApp.Documentation & FAQs ↓
Signal Protocol Double Ratchet Cryptographic Key Visualizer
Diffie-Hellman turnaround ratchet, symmetric KDF chains, Forward Secrecy & Break-in Recovery (PCS).
Simulate Message Exchange
Past messages stay encrypted forever even if future keys leak.
Next DH turnaround self-heals privacy after an attacker compromise.
Message Ratchet Stream (0 Messages)
Click red button to simulate key leakNo messages exchanged yet.
Click "Send: Alice → Bob" to initiate the Double Ratchet state machine.
Step-by-Step Instructions
4 Steps to CompletionStart a new session between simulated users Alice and Bob with pre-shared master secrets (X3DH initial setup).
Click 'Send Message' from Alice to Bob to advance the sending KDF ratchet and derive a unique ephemeral message encryption key.
Trigger a reply from Bob to observe the Diffie-Hellman ratchet advance, generating a fresh shared root key and new chain keys.
Simulate dropped or out-of-order packets to inspect how skipped message keys are stored and expired in secure client memory.
Practical Use Cases & Real-World Scenarios
Interactive Dual-Ratchet State Machine
Step through Alice and Bob's asynchronous communication, tracking root keys, sending/receiving chain keys, and ephemeral ECDH curve25519 public keys.
Forward Secrecy & Break-in Recovery
Simulates key compromise scenarios, demonstrating how ratchet advances protect historical messages (Forward Secrecy) and restore privacy on subsequent turns (Break-in Recovery).
Out-of-Order Message Handling
Demonstrates skipped message key buffers, explaining how E2EE clients decrypt delayed or out-of-sequence cellular SMS/data packets without stalling the ratchet.
KDF Hash Function Chain Modeling
Visualizes HMAC-SHA256 Key Derivation Functions (KDF), illustrating how single-use ephemeral message keys are irreversibly derived from chain keys.
Frequently Asked Questions
What makes the Double Ratchet algorithm superior to standard PGP encryption?↓
What are the two ratchets in the 'Double Ratchet'?↓
How does the protocol recover if an attacker steals an active session key?↓
Why doesn't the Double Ratchet break when network packets arrive out of order?↓
What is the relationship between X3DH and the Double Ratchet?↓
15 Most Secure Messaging apps for Android and iPhone in 2026
Dive deeper into the foundational technical concepts behind this tool on our editorial blog. Includes comprehensive hardware benchmarks, case studies, and best practices.
Found this tool helpful? Share it with colleagues & friends:
100% free, private in-browser utility with zero server uploads.
