Formally Modeling the Terrapin Attack on SSH

📅 2026-09-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
本文针对SSH通道完整性受到Terrapin攻击的问题,提出了一个基于部分选择状态的正式模型,并通过分析八种主要AEAD模式的安全性,明确了各模式在不同攻击类型下的安全性界限。
📝 Abstract
The Terrapin attack against SSH channel integrity (USENIX Security 2024) used a novel attack vector: attacks on the channel state. Surprisingly, not all AEAD modes of SSH were equally affected by this attack, and it remained an open question if "unaffected" meant "secure". Existing formal models for secure channels are based on stateful encryption. However, these models do not define what the channel state is and how it is used as input to the different AEAD modes. In this paper, we propose a formal model for channel integrity under partially chosen state. Applied to the Terrapin attack, the chosen state is the SSH sequence number. It uses an abstract stateful encryption interface, for which we provide pseudocode descriptions for the eight most prominent AEAD modes used in SSH. By varying the SND oracle, we can model ciphertext-only (CO; the Terrapin attack), known-plaintext (KPA), and chosen-plaintext (CPA) attacks. This allows us to establish concrete bounds on the security of the AEAD modes. We find that all three Encrypt-then-MAC (EtM) modes and ChaCha20-Poly1305 in SSH are insecure in the CO model. AES-GCM is the only cipher secure in all three model variants. Going beyond Terrapin, we show that Encrypt-and-MAC (EaM) with a CBC cipher is secure, even in the KPA model. In particular, we describe a novel BEAST-like chosen-plaintext attack on the channel integrity of EaM-CBC, which separates the KPA and CPA models for this scheme.
Problem

Research questions and friction points this paper is trying to address.

Channel Integrity
AEAD Modes
Stateful Encryption
Terrapin Attack
SSH
Innovation

Methods, ideas, or system contributions that make the work stand out.

formal model
partially chosen state
AEAD modes
Encrypt-then-MAC
Encrypt-and-MAC
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.