A Drop-in KEM Replacement for Client Signatures in Post-Quantum SSH

📅 2026-08-25
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出了一种基于KEM的SSH用户认证方法,用会话绑定的挑战-响应证明替代客户端公钥签名,以解决后量子加密中签名带来的高延迟和计算开销问题。
📝 Abstract
The transition to post-quantum cryptography is reshaping the Secure Shell (SSH) protocol for remote administration. Post-quantum key exchange has been deployed in OpenSSH and is being standardized, while SSH authentication largely remains a signature-replacement effort. This path preserves the familiar public-key credential model, but inherits the size and computation overhead of post-quantum signatures, which can increase latency, traffic, and server-side load. KEM-based authentication offers a natural alternative to this signature-centric path, and SSH makes this especially attractive at the user-authentication layer, which is method-extensible, separated from transport-layer key exchange and host-key authentication, and already protected by the established channel. We present a drop-in KEM-based user-authentication method for SSH that replaces client public-key signatures with a session-bound challenge-response proof. The method fits into SSH's existing user-authentication framework, preserving the public-key credential model and enabling incremental deployment alongside existing methods. We provide a reduction-based security argument in the post-quantum ACCE framework, implement the design in OpenSSH using liboqs, and evaluate it under representative RTTs, TCP initial-window settings, and post-quantum migration configurations. Our results show that KEM-based authentication is competitive with compact signature-based authentication under representative network settings, while reducing median handshake latency by up to about 10% against large-signature hybrid baselines. The advantages are clearer when post-quantum signatures stress transmission or computation: median latency under small TCP initial windows falls by up to 7.3% versus ML-DSA and 17.9% versus SLH-DSA, while server-side online cryptographic cost is 59.1% lower than that for ML-DSA in the same NIST category.
Problem

Research questions and friction points this paper is trying to address.

Post-Quantum SSH
Client Signatures
KEM-based Authentication
Latency
Server-side Load
Innovation

Methods, ideas, or system contributions that make the work stand out.

KEM-based authentication
post-quantum cryptography
SSH protocol
handshake latency
cryptography cost
💼 Related Jobs
No related jobs found.
Hongbo Liu
Hongbo Liu
University of Electronic Science and Technology of China
Wireless and Physical Layer SecurityWireless Sensing and Mobile ComputingData Security
Y
Yufan Su
School of Control and Computer Engineering, North China Electric Power University, Beijing, China
J
Jiangxia Ge
China Telecom Quantum Information Technology Group Co., Ltd., Hefei, China
Q
Qionglu Zhang
State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS, Beijing, China
Zhaoxuan Li
Zhaoxuan Li
Institute of Information Engineering
X
Xianhui Lu
State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, CAS, Beijing, China
Li Song
Li Song
Professor of Electronic Engineering, Shanghai Jiao Tong University
Video CodingImage ProcessingComputer Vision
W
Wenhua Gao
Beijing Certificate Authority Co., Ltd. (BJCA), Beijing, China
Li Zhou
Li Zhou
Institute of Software, Chinese Academy of Sciences
Quantum computingFormal Verification