* How to exchange the topic key is described as out of scope, but totally critical since you also propose renewing the topic key as a way of attaining forward secrecy.
* You totally hand-waved away the exchange of participant keys.
* I'm pretty sure you've exposed some cryptographic weaknesses in the core protocol but I'm not going to spend the time to keep analyzing.
So in short, your protocol is not very useful. Sorry.
The biggest problems in IoT space are key agreement and machine trust among a hugely heterogeneous population. Solutions will come in the form of standards adoption, hegemony, government regulation, and probably a combination of all three. Multicast security is somewhat of a solved problem (e.g. wifi.)
Communications security between actual people is an entirely different and more easily solved problem.
There's no weakness there that's not fixable. Replay protection can be easily added in the layer above, and rolling the topic key can also be done. The nonce problem can go away with using the wider Salsa variant.
> How to exchange the topic key is described as out of scope, but totally critical since you also propose renewing the topic key as a way of attaining forward secrecy.
Where did you see that? I go into a lot of detail here: https://stringphone.readthedocs.org/en/latest/protocol.html#...
> You totally hand-waved away the exchange of participant keys.
See the previous point.
> I'm pretty sure you've exposed some cryptographic weaknesses in the core protocol but I'm not going to spend the time to keep analyzing.
Hmm.
> Solutions will come in the form of standards adoption, hegemony, government regulation, and probably a combination of all three.
"Don't bother working on it" doesn't sound like very useful advice...
What's the stop a MITM between a client and any other client from intercepting the conversation? In your protocol, nothing, except that if the MITM isn't there at the start, they can't join in right away. This is not a very useful assurance. So please, keep working on it, but I think your challenges are pretty serious. If the problems are fixable, then go ahead and fix them. I'd be happy to take another look - after that.
Would love to hear thoughts on it. Email address in my profile.