USENIX Security2022Top-tier venue
Practical Privacy-Preserving Authentication for SSH
Lawrence Roy, Stanislav Lyakhov, Yeongjin Jang, Mike Rosulek
Abstract
Public-key authentication in SSH reveals more information about the participants' keys than is necessary. (1) The server can learn a client's entire set of public keys, even keys generated for other servers. (2) The server learns exactly which key the client uses to authenticate, and can further prove this fact to a third party. (3) A client can learn whether the server recognizes public keys belonging to other users. Each of these problems lead to tangible privacy violations for SSH users. In this work we introduce a new public-key authentication method for SSH that reveals essentially the minimum possible amount of information. With our new method, the server learns only whether the client knows the private key for some authorized public key. If multiple keys are authorized, the server does not learn which one the client used. The client cannot learn whether the server recognizes public keys belonging to other users. Unlike traditional SSH authentication, our method is fully deniable. Our new method also makes it harder for a malicious server to intercept first-use SSH connections on a large scale. Our method supports existing SSH keypairs of all standard flavors -RSA, ECDSA, EdDSA. It does not require users to generate new key material. As in traditional SSH authentication, clients and servers can use a mixture of different key flavors in a single authentication session. We integrated our new authentication method into OpenSSH, and found it to be practical and scalable. For a typical client and server with at most 10 ECDSA/EdDSA keys each, our protocol requires 9 kB of communication and 12.4 ms of latency. Even for a client with 20 keys and server with 100 keys, our protocol requires only 12 kB of communication and 26.7 ms of latency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext acb64829-a960-422d-a1e2-2f89d10a33a7Cited by top-tier papers2
- NetCap: Data-Plane Capability-Based Defense Against Token Theft in Network AccessOsama Bajaber, Bo Ji, Peng GaoNDSS 2026 · 2 citations
- Hop: A Modern Transport and Remote Access ProtocolPaul Flammarion, George Hosono, Wilson Nguyen, Laura Bauman et al.USENIX Security 2026
Builds on2
Related papers
- On the Security of SSH Client SignaturesFabian Bäumer, Marcus Brinkmann, Maximilian Radoy, Jörg Schwenk et al.CCS 2025
- Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number ManipulationFabian Bäumer, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2024 · 15 citations
- Post-Quantum Cryptographic Analysis of SSHBenjamin Bencina, Benjamin Dowling, Varun Maram, Keita XagawaS&P 2025
- "Make Sure DSA Signing Exponentiations Really are Constant-Time"Cesar Pereida García, Billy Bob Brumley, Yuval YaromCCS 2016 · 93 citations
- Deniable Authentication When Signing Keys LeakSuvradip Chakraborty, Dennis Hofheinz, Ueli Maurer, Guilherme RitoEUROCRYPT 2023 · 10 citations
