arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.24447cs.CR

一种用于后量子SSH中客户端签名的即插即用KEM替换方案

A Drop-in KEM Replacement for Client Signatures in Post-Quantum SSH

Hongbo Liu, Yufan Su, Jiangxia Ge, Qionglu Zhang, Zhaoxuan Li, Xianhui Lu, Li Song, Wenhua Gao, Li Zhou

首次发表
浏览论文内容

中文总结 AI 辅助

该研究提出一种即插即用的基于KEM的SSH用户身份验证方法,替换客户端公钥签名,经实验验证可降低延迟与服务器端开销,适配后量子密码迁移需求。

中文摘要 AI 辅助

向后量子密码学的转变正在重塑用于远程管理的安全 Shell(SSH)协议。后量子密钥交换已在 OpenSSH 中部署并正在标准化,而 SSH 身份验证在很大程度上仍处于签名替换阶段。该路径保留了熟悉的公钥凭证模型,但继承了后量子签名的大小和计算开销,这会增加延迟、流量和服务器端负载。基于 KEM 的身份验证为这种以签名为中心的路径提供了自然的替代方案,而 SSH 在用户身份验证层尤其具有吸引力,该层具有方法可扩展性,与传输层密钥交换和主机密钥身份验证分离,且已受既定通道保护。我们提出了一种用于 SSH 的基于 KEM 的即插即用用户身份验证方法,该方法用与会话绑定的挑战-响应证明替换客户端公钥签名。该方法适配 SSH 现有的用户身份验证框架,保留公钥凭证模型,并支持与现有方法的增量部署。我们在后量子 ACCE 框架中提供了基于归约的安全论证,使用 liboqs 在 OpenSSH 中实现了该设计,并在代表性 RTT、TCP 初始窗口设置和后量子迁移配置下对其进行了评估。我们的结果表明,在代表性网络设置下,基于 KEM 的身份验证与紧凑的基于签名的身份验证具有竞争力,同时相较于大签名混合基线,可将中位数握手延迟降低多达约 10%。当后量子签名对传输或计算造成压力时,优势更为明显:相较于 ML-DSA,在小 TCP 初始窗口下的中位数延迟降低多达 7.3%,相较于 SLH-DSA 降低多达 17.9%,而服务器端在线密码学成本比同一 NIST 类别中 ML-DSA 的成本低 59.1%。

英文摘要

The transition to post-quantum cryptography is reshaping the Secure Shell (SSH) protocol for remote administration. Post-quantum key exchange has been deployed in OpenSSH and is being standardized, while SSH authentication largely remains a signature-replacement effort. This path preserves the familiar public-key credential model, but inherits the size and computation overhead of post-quantum signatures, which can increase latency, traffic, and server-side load. KEM-based authentication offers a natural alternative to this signature-centric path, and SSH makes this especially attractive at the user-authentication layer, which is method-extensible, separated from transport-layer key exchange and host-key authentication, and already protected by the established channel. We present a drop-in KEM-based user-authentication method for SSH that replaces client public-key signatures with a session-bound challenge-response proof. The method fits into SSH's existing user-authentication framework, preserving the public-key credential model and enabling incremental deployment alongside existing methods. We provide a reduction-based security argument in the post-quantum ACCE framework, implement the design in OpenSSH using liboqs, and evaluate it under representative RTTs, TCP initial-window settings, and post-quantum migration configurations. Our results show that KEM-based authentication is competitive with compact signature-based authentication under representative network settings, while reducing median handshake latency by up to about 10% against large-signature hybrid baselines. The advantages are clearer when post-quantum signatures stress transmission or computation: median latency under small TCP initial windows falls by up to 7.3% versus ML-DSA and 17.9% versus SLH-DSA, while server-side online cryptographic cost is 59.1% lower than that for ML-DSA in the same NIST category.

补充信息

↑