Skip to main navigation Skip to search Skip to main content

基于信任链技术的SSH 传输层协议改进

Translated title of the contribution: Improvement of SSH Transport Layer Protocol Based on Chain of Trust
  • Xingguo Wang
  • , Yunxiao Sun
  • , Bailing Wang*
  • *Corresponding author for this work
  • School of Computer Science and Technology, Harbin Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

Host keys are identification of SSH servers. Users are required to check host key fingerprints to authenticate SSH servers. However, users often ignore the process of checking fingerprints when using SSH, making man-in-the-middle attacks based on host key replacement possible. In this regard,an improvement scheme of the SSH transport layer protocol is proposed based on the chain of trust. In the scheme,a chain of trust is established by signing the new host key with the old host key. The improved SSH protocol can solve the trust problem of new host keys without the need for users to check fingerprints, so as to achieve identity authentication of servers, which greatly reduces the risk of man-in-the-middle attacks. Finally, using Pro Verify to analyze the improved protocol, verification results show that the improved protocol satisfies confidentiality and authentication,and can resist man-in-the-middle attacks.

Translated title of the contributionImprovement of SSH Transport Layer Protocol Based on Chain of Trust
Original languageChinese (Traditional)
Pages (from-to)353-361
Number of pages9
JournalComputer Science
Volume52
Issue number2
DOIs
StatePublished - 15 Feb 2025

Fingerprint

Dive into the research topics of 'Improvement of SSH Transport Layer Protocol Based on Chain of Trust'. Together they form a unique fingerprint.

Cite this