Passive SSH key compromise via lattices
Name
3576915.3616629.pdf
Size
1.08 MB
Format
Adobe PDF
Checksum (MD5)
26df9ed40582260b67dbce9327819130
Author(s) • • •
Ryan, Keegan
He, Kaiwen
Sullivan, George
Heninger, Nadia
Date Issued
November 15, 2023
Publisher
ACM|Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
Citation
Ryan, Keegan, He, Kaiwen, Sullivan, George and Heninger, Nadia. 2023. "Passive SSH key compromise via lattices."
Version
Final published version
Abstract
We demonstrate that a passive network attacker can opportunistically obtain private RSA host keys from an SSH server that experiences a naturally arising fault during signature computation. In prior work, this was not believed to be possible for the SSH protocol because the signature included information like the shared Diffie-Hellman secret that would not be available to a passive network observer. We show that for the signature parameters commonly in use for SSH, there is an efficient lattice attack to recover the private key in case of a signature fault. We provide a security analysis of the SSH, IKEv1, and IKEv2 protocols in this scenario, and use our attack to discover hundreds of compromised keys in the wild from several independently vulnerable implementations.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Creative Commons Attribution
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1145/3576915.3616629