Post-Quantum Cryptographic Analysis of SSH
Benjamin Bencina, Benjamin Dowling, Varun Maram, Keita Xagawa
摘要
The Secure Shell (SSH) protocol is one of the first security protocols on the Internet to upgrade itself to resist attacks against future quantum computers, with the default adoption of the “quantum (otherwise, classically)” secure hybrid key exchange in OpenSSH from April 2022. However, there is a lack of a comprehensive security analysis of this quantum-resistant version of SSH in the literature: related works either focus on the hybrid key exchange in isolation and do not consider security of the overall protocol, or analyze the protocol in security models which are not appropriate for SSH, especially in the “post-quantum” setting. In this paper, we remedy the state of affairs by providing a thorough post-quantum cryptographic analysis of SSH. We follow a “top-down” approach wherein we first prove security of SSH in a more appropriate model, namely, our post-quantum extension of the so-called authenticated and confidential channel establishment (ACCE) protocol security model; our extension which captures “harvest now, decrypt later” attacks could be of independent interest. Then we establish the cryptographic properties of SSH's underlying primitives, as concretely instantiated in practice, based on our protocol-level ACCE security analysis: for example, we prove relevant cryptographic properties of “Streamlined NTRU Prime”, a key encapsulation mechanism (KEM) which is used in recent versions of OpenSSH and TinySSH, in the quantum random oracle model, and address open problems related to its analysis in the literature. Notably, our ACCE security analysis of post-quantum SSH relies on the weaker notion of IND-CPA security of the ephemeral KEMs used in the hybrid key exchange. This is in contrast to prior works which rely on the stronger assumption of IND-CCA secure ephemeral KEMs. Hence we conclude the paper with a discussion on potentially replacing IND-CCA secure KEMs in current post-quantum implementations of SSH with simpler and faster IND-CPA secure counterparts, and also provide the corresponding benchmarks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Hop: A Modern Transport and Remote Access ProtocolPaul Flammarion, George Hosono, Wilson Nguyen, Laura Bauman 等USENIX Security 2026
- Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed ChannelsFabian Bäumer, Marcus BrinkmannCCS 2026
它引用的顶会 Paper3
- Measure-Rewind-Measure: Tighter Quantum Random Oracle Model Proofs for One-Way to Hiding and CCA SecurityVeronika Kuchta, Amin Sakzad, Damien Stehlé, Ron Steinfeld 等EUROCRYPT 2020 · 被引用 60 次
- Anonymity of NIST PQC Round 3 KEMsKeita XagawaEUROCRYPT 2022 · 被引用 21 次
- On IND-qCCA Security in the ROM and Its Applications - CPA Security Is Sufficient for TLS 1.3Loïs Huguenin-Dumittan, Serge VaudenayEUROCRYPT 2022 · 被引用 18 次
相关 Paper
- Post-quantum WireGuardAndreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber 等S&P 2021 · 被引用 73 次
- Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number ManipulationFabian Bäumer, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2024 · 被引用 15 次
- Keeping Up with the KEMs: Stronger Security Notions for KEMs and Automated Analysis of KEM-based ProtocolsCas Cremers, Alexander Dax, Niklas MedingerCCS 2024 · 被引用 11 次
- A Tale of Two Worlds, a Formal Story of WireGuard HybridizationPascal Lafourcade, Dhekra Mahmoud, Sylvain Ruhault, Abdul Rahman TalebUSENIX Security 2025
- Post-quantum TLS 1.3 Handshake from CPA-Secure KEMs with Tighter ReductionsJinrong Chen, Biming Zhou, Rongmao Chen, Haodong Jiang 等EUROCRYPT 2026
