{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T04:25:11Z","timestamp":1778127911315,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,11,3]],"date-time":"2014-11-03T00:00:00Z","timestamp":1414972800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000923","name":"Australian Research Council","doi-asserted-by":"publisher","award":["DP130104304"],"award-info":[{"award-number":["DP130104304"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001655","name":"German Academic Exchange Service","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001655","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["ICT-2007-216646"],"award-info":[{"award-number":["ICT-2007-216646"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,11,3]]},"DOI":"10.1145\/2660267.2660286","type":"proceedings-article","created":{"date-parts":[[2014,11,11]],"date-time":"2014-11-11T13:40:05Z","timestamp":1415713205000},"page":"369-381","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Multi-Ciphersuite Security of the Secure Shell (SSH) Protocol"],"prefix":"10.1145","author":[{"given":"Florian","family":"Bergsma","sequence":"first","affiliation":[{"name":"Ruhr-Universit\u00e4t Bochum, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Benjamin","family":"Dowling","sequence":"additional","affiliation":[{"name":"Queensland University of Technology, Brisbane, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Florian","family":"Kohlar","sequence":"additional","affiliation":[{"name":"Ruhr-Universit\u00e4t Bochum, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"J\u00f6rg","family":"Schwenk","sequence":"additional","affiliation":[{"name":"Ruhr-Universit\u00e4t Bochum, Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Douglas","family":"Stebila","sequence":"additional","affiliation":[{"name":"Queensland University of Technology, Brisbane, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,11,3]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.5"},{"key":"e_1_3_2_1_2_1","first-page":"566","volume-title":"Proc. 21st National Information Systems Security Conference","author":"Alves-Foss J.","year":"1998"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"R. J.\n       \n      Anderson\n     and \n      \n      \n      R. M.\n       \n      Needham\n      \n  \n  . \n  Robustness principles for public key protocols. In D. Coppersmith editor CRYPTO'95 volume \n  963\n   of \n  LNCS pages \n  236\n  --\n  247\n  . \n  Springer Aug. \n  1995\n  .   R. J. Anderson and R. M. Needham. Robustness principles for public key protocols. In D. Coppersmith editor CRYPTO'95 volume 963 of LNCS pages 236--247. Springer Aug. 1995.","DOI":"10.1007\/3-540-44750-4_19"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ic.2007.07.002"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCP.2007.4352155"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/996943.996945"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"M.\n       \n      Bellare\n     and \n      \n      \n      P.\n       \n      Rogaway\n      \n  \n  . \n  Entity authentication and key distribution. In D. R. Stinson editor CRYPTO'93 volume \n  773\n   of \n  LNCS pages \n  232\n  --\n  249\n  . \n  Springer Aug. \n  1993\n  .   M. Bellare and P. Rogaway. Entity authentication and key distribution. In D. R. Stinson editor CRYPTO'93 volume 773 of LNCS pages 232--249. Springer Aug. 1993.","DOI":"10.1007\/3-540-48329-2_21"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.37"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","unstructured":"K.\n       \n      Bhargavan C.\n       \n      Fournet M.\n       \n      Kohlweiss A.\n       \n      Pironti P.-Y.\n       \n      Strub and \n      \n      \n      S.\n       \n      Zanella-Beguelin\n      \n  \n  . \n  Proving the TLS handshake secure (as it is). In J. A. Garay and R. Gennaro editors CRYPTO\n   \n  2014 volume \n  8617\n   of \n  LNCS pages \n  235\n  --\n  255\n  . \n  Springer 2014.  K. Bhargavan C. Fournet M. Kohlweiss A. Pironti P.-Y. Strub and S. Zanella-Beguelin. Proving the TLS handshake secure (as it is). In J. A. Garay and R. Gennaro editors CRYPTO 2014 volume 8617 of LNCS pages 235--255. Springer 2014.","DOI":"10.1007\/978-3-662-44381-1_14"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-013-0192-y"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/874063.875553"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"R.\n       \n      Canetti\n     and \n      \n      \n      H.\n       \n      Krawczyk\n      \n  \n  . \n  Analysis of key-exchange protocols and their use for building secure channels. In B. Pfitzmann editor EUROCRYPT\n   \n  2001 volume \n  2045\n   of \n  LNCS pages \n  453\n  --\n  474\n  . \n  Springer May 2001.   R. Canetti and H. Krawczyk. Analysis of key-exchange protocols and their use for building secure channels. In B. Pfitzmann editor EUROCRYPT 2001 volume 2045 of LNCS pages 453--474. Springer May 2001.","DOI":"10.1007\/3-540-44987-6_28"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"R.\n       \n      Canetti C.\n       \n      Meadows and \n      \n      \n      P.\n       \n      Syverson\n      \n  \n  . \n  Environmental requirements for authentication protocols. In M. Okada B. C. Pierce A. Scedrov H. Tokuda and A. Yonezawa editors Proc. Mext-NSF-JSPS Internaional Symposium on Software Security (ISSS) -- Theories and Systems Part 9 volume \n  2609\n   of \n  LNCS pages \n  339\n  --\n  355\n  . \n  Springer 2002\n  .   R. Canetti C. Meadows and P. Syverson. Environmental requirements for authentication protocols. In M. Okada B. C. Pierce A. Scedrov H. Tokuda and A. Yonezawa editors Proc. Mext-NSF-JSPS Internaional Symposium on Software Security (ISSS) -- Theories and Systems Part 9 volume 2609 of LNCS pages 339--355. Springer 2002.","DOI":"10.1007\/3-540-36532-X_21"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2006.63"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1571-0661(03)50011-1"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516694"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/794200.795141"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"B. Harris. RSA Key Exchange for the Secure Shell (SSH) Transport Layer Protocol. RFC 4432 (Proposed Standard) Mar. 2006.  B. Harris. RSA Key Exchange for the Secure Shell (SSH) Transport Layer Protocol. RFC 4432 (Proposed Standard) Mar. 2006.","DOI":"10.17487\/rfc4432"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"T.\n       \n      Jager F.\n       \n      Kohlar S.\n     Sch\\\"age and \n      \n      \n      J.\n       \n      Schwenk\n      \n  \n  . \n  On the security of TLS-DHE in the standard model. In R. Safavi-Naini and R. Canetti editors CRYPTO\n   \n  2012 volume \n  7417\n   of \n  LNCS pages \n  273\n  --\n  293\n  . \n  Springer Aug. 2012.  T. Jager F. Kohlar S. Sch\\\"age and J. Schwenk. On the security of TLS-DHE in the standard model. In R. Safavi-Naini and R. Canetti editors CRYPTO 2012 volume 7417 of LNCS pages 273--293. Springer Aug. 2012.","DOI":"10.1007\/978-3-642-32009-5_17"},{"key":"e_1_3_2_1_21_1","volume-title":"Proc. Internet Society Network and Distributed System Security Symposium (NDSS) 2013","author":"Jager T.","year":"2013"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"J.\n       \n      Jonsson\n     and \n      \n      \n      B. S.\n       \n      Kaliski\n        \n      Jr\n      \n  \n  . \n  On the security of RSA encryption in TLS. In M. Yung editor CRYPTO\n   \n  2002 volume \n  2442\n   of \n  LNCS pages \n  127\n  --\n  142\n  . \n  Springer Aug. 2002.   J. Jonsson and B. S. Kaliski Jr. On the security of RSA encryption in TLS. In M. Yung editor CRYPTO 2002 volume 2442 of LNCS pages 127--142. Springer Aug. 2002.","DOI":"10.1007\/3-540-45708-9_9"},{"key":"e_1_3_2_1_23_1","series-title":"LNCS","first-page":"91","volume-title":"5th International Workshop on Security Protocols","author":"Kelsey J.","year":"1997"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"H.\n       \n      Krawczyk\n    . \n      \n      \n      Cryptographic\n     extraction and key derivation\n      \n  \n  : \n  The HKDF scheme. In T. Rabin editor CRYPTO\n   \n  2010 volume \n  6223\n   of \n  LNCS pages \n  631\n  --\n  648\n  . \n  Springer Aug. 2010.   H. Krawczyk. Cryptographic extraction and key derivation: The HKDF scheme. In T. Rabin editor CRYPTO 2010 volume 6223 of LNCS pages 631--648. Springer Aug. 2010.","DOI":"10.1007\/978-3-642-14623-7_34"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"H.\n       \n      Krawczyk K. G.\n       \n      Paterson and \n      \n      \n      H.\n       \n      Wee\n      \n  \n  . \n  On the security of the TLS protocol: A systematic analysis. In R. Canetti and J. A. Garay editors CRYPTO\n   \n  2013 Part I volume \n  8042\n   of \n  LNCS pages \n  429\n  --\n  448\n  . \n  Springer Aug. 2013.  H. Krawczyk K. G. Paterson and H. Wee. On the security of the TLS protocol: A systematic analysis. In R. Canetti and J. A. Garay editors CRYPTO 2013 Part I volume 8042 of LNCS pages 429--448. Springer Aug. 2013.","DOI":"10.1007\/978-3-642-40041-4_24"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"B. A.\n       \n      LaMacchia K.\n       \n      Lauter and \n      \n      \n      A.\n       \n      Mityagin\n      \n  \n  . \n  Stronger security of authenticated key exchange\n  . In W. Susilo J. K. Liu and Y. Mu editors ProvSec \n  2007 volume \n  4784\n   of \n  LNCS pages \n  1\n  --\n  16\n  . \n  Springer Nov. 2007.   B. A. LaMacchia K. Lauter and A. Mityagin. Stronger security of authenticated key exchange. In W. Susilo J. K. Liu and Y. Mu editors ProvSec 2007 volume 4784 of LNCS pages 1--16. Springer Nov. 2007.","DOI":"10.1007\/978-3-540-75670-5_1"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382206"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89255-7_5"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13190-5_18"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/11958239_14"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"D. Stebila and J. Green. Elliptic Curve Algorithm Integration in the Secure Shell Transport Layer. RFC 5656 (Proposed Standard) Dec. 2009.  D. Stebila and J. Green. Elliptic Curve Algorithm Integration in the Secure Shell Transport Layer. RFC 5656 (Proposed Standard) Dec. 2009.","DOI":"10.17487\/rfc5656"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/794199.795113"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0020-0190(99)00023-X"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.5555\/1267167.1267171"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"crossref","unstructured":"T. Ylonen and C. Lonvick. The Secure Shell (SSH) Authentication Protocol. RFC 4252 (Proposed Standard) Jan. 2006.  T. Ylonen and C. Lonvick. The Secure Shell (SSH) Authentication Protocol. RFC 4252 (Proposed Standard) Jan. 2006.","DOI":"10.17487\/rfc4252"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"T. Ylonen and C. Lonvick. The Secure Shell (SSH) Connection Protocol. RFC 4254 (Proposed Standard) Jan. 2006.  T. Ylonen and C. Lonvick. The Secure Shell (SSH) Connection Protocol. RFC 4254 (Proposed Standard) Jan. 2006.","DOI":"10.17487\/rfc4254"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"T. Ylonen and C. Lonvick. The Secure Shell (SSH) Protocol Architecture. RFC 4251 (Proposed Standard) Jan. 2006.  T. Ylonen and C. Lonvick. The Secure Shell (SSH) Protocol Architecture. RFC 4251 (Proposed Standard) Jan. 2006.","DOI":"10.17487\/rfc4251"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"crossref","unstructured":"T. Ylonen and C. Lonvick. The Secure Shell (SSH) Transport Layer Protocol. RFC 4253 (Proposed Standard) Jan. 2006. Updated by RFC 6668.  T. Ylonen and C. Lonvick. The Secure Shell (SSH) Transport Layer Protocol. RFC 4253 (Proposed Standard) Jan. 2006. Updated by RFC 6668.","DOI":"10.17487\/rfc4253"}],"event":{"name":"CCS'14: 2014 ACM SIGSAC Conference on Computer and Communications Security","location":"Scottsdale Arizona USA","acronym":"CCS'14","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2660267.2660286","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2660267.2660286","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:56:10Z","timestamp":1750229770000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2660267.2660286"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,11,3]]},"references-count":37,"alternative-id":["10.1145\/2660267.2660286","10.1145\/2660267"],"URL":"https:\/\/doi.org\/10.1145\/2660267.2660286","relation":{},"subject":[],"published":{"date-parts":[[2014,11,3]]},"assertion":[{"value":"2014-11-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}