Passive SSH Key Compromise via Lattices
Keegan Ryan, Kaiwen He, George Arnold Sullivan, Nadia Heninger
Abstract
We demonstrate that a passive network attacker can opportunistically obtain private RSA host keys from an SSH server that experiences a naturally arising fault during signature computation. In prior work, this was not believed to be possible for the SSH protocol because the signature included information like the shared Diffie-Hellman secret that would not be available to a passive network observer. We show that for the signature parameters commonly in use for SSH, there is an efficient lattice attack to recover the private key in case of a signature fault. We provide a security analysis of the SSH, IKEv1, and IKEv2 protocols in this scenario, and use our attack to discover hundreds of compromised keys in the wild from several independently vulnerable implementations. CCS CONCEPTS • Security and privacy → Cryptanalysis and other attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a8970837-d311-4f5d-846c-17c2f1f682a6Cited by top-tier papers4
- Censys: A Map of Internet Hosts and ServicesZakir Durumeric, Hudson Clark, Jeff Cody, Elliot Cubit et al.SIGCOMM 2025 · 6 citations
- Unfiltered: Measuring Cloud-based Email Filtering BypassesSumanth Rao, Enze Liu, Grant Ho, Geoffrey M. Voelker et al.WWW 2024 · 1 citation
- Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed ChannelsFabian Bäumer, Marcus BrinkmannCCS 2026
- On the Security of SSH Client SignaturesFabian Bäumer, Marcus Brinkmann, Maximilian Radoy, Jörg Schwenk et al.CCS 2025
Builds on8
- Return Of Bleichenbacher's Oracle Threat (ROBOT)Hanno Böck, Juraj Somorovsky, Craig YoungUSENIX Security 2018 · 69 citations
- Measuring small subgroup attacks against Diffie-HellmanLuke Valenta, David Adrian, Antonio Sanso, Shaanan Cohney et al.NDSS 2017 · 34 citations
- Fast Practical Lattice Reduction Through Iterated CompressionKeegan Ryan, Nadia HeningerCRYPTO 2023 · 28 citations
- Scalable Scanning and Automatic Classification of TLS Padding Oracle VulnerabilitiesRobert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young et al.USENIX Security 2019 · 27 citations
- On the Security of the PKCS#1 v1.5 Signature SchemeTibor Jager, Saqib A. Kakvi, Alexander MayCCS 2018 · 19 citations
Related papers
- Open to a fault: On the passive compromise of TLS keys via transient errorsGeorge Arnold Sullivan, Jackson Sippe, Nadia Heninger, Eric WustrowUSENIX Security 2022
- Jolt: Recovering TLS Signing Keys via Rowhammer FaultsKoksal Mus, Yarkin Doröz, M. Caner Tol, Kristi Rahman et al.S&P 2023
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 93 citations
- Catch-22: Uncovering Compromised Hosts using SSH Public KeysCristian Munteanu, Georgios Smaragdakis, Anja Feldmann, Tobias FiebigUSENIX Security 2025
- Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number ManipulationFabian Bäumer, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2024 · 15 citations
