{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,17]],"date-time":"2026-04-17T16:35:18Z","timestamp":1776443718444,"version":"3.51.2"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T00:00:00Z","timestamp":1700524800000},"content-version":"vor","delay-in-days":6,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2048563,1913210"],"award-info":[{"award-number":["2048563,1913210"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3616629","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"2886-2900","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Passive SSH Key Compromise via Lattices"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5846-2046","authenticated-orcid":false,"given":"Keegan","family":"Ryan","sequence":"first","affiliation":[{"name":"University of California, San Diego, La Jolla, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0613-5208","authenticated-orcid":false,"given":"Kaiwen","family":"He","sequence":"additional","affiliation":[{"name":"University of California, San Diego &amp; Massachusetts Institute of Technology, La Jolla, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0091-8183","authenticated-orcid":false,"given":"George Arnold","family":"Sullivan","sequence":"additional","affiliation":[{"name":"University of California, San Diego, La Jolla, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7904-7295","authenticated-orcid":false,"given":"Nadia","family":"Heninger","sequence":"additional","affiliation":[{"name":"University of California, San Diego, La Jolla, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"N. Asokan Valtteri Niemi and Kaisa Nyberg. 2002. Man-in-the-Middle in Tunnelled Authentication Protocols. Cryptology ePrint Archive Report 2002\/163. https:\/\/eprint.iacr.org\/2002\/163."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36400-5_20"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36362-7_13"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44709-3_12"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-68339-9_34"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-54631-0_11"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"D. Bider. 2018. RFC 8332: Use of RSA Keys with SHA-256 and SHA-512 in the Secure Shell (SSH) Protocol.","DOI":"10.17487\/RFC8332"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948151"},{"key":"e_1_3_2_1_9_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"B\u00f6ck Hanno","year":"2018","unstructured":"Hanno B\u00f6ck, Juraj Somorovsky, and Craig Young. 2018. Return Of Bleichenbachertextquoterights Oracle Threat (ROBOT ). In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, MD, 817--849. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/bock"},{"key":"e_1_3_2_1_10_1","first-page":"203","article-title":"Twenty years of attacks on the RSA cryptosystem","volume":"46","author":"Dan Boneh","year":"1999","unstructured":"Dan Boneh et al. 1999. Twenty years of attacks on the RSA cryptosystem. Notices of the AMS, Vol. 46, 2 (1999), 203--213.","journal-title":"Notices of the AMS"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/s001450010016"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32101-7_1"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23951-9_13"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-68339-9_16"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/s001459900030"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04138-9_31"},{"key":"e_1_3_2_1_17_1","unstructured":"Jean-S\u00e9bastien Coron Antoine Joux Ilya Kizhvatov David Naccache and Pascal Paillier. 2009b. Fault Attacks on RSA Signatures with Partially Unknown Messages. Cryptology ePrint Archive Report 2009\/309. https:\/\/eprint.iacr.org\/2009\/309."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"T. Dierks and E. Rescorla. 2008. RFC 5246: The Transport Layer Security (TLS) Protocol Version 1.2.","DOI":"10.17487\/rfc5246"},{"key":"e_1_3_2_1_19_1","volume-title":"Indiscreet Logs: Diffie-Hellman Backdoors in TLS. In NDSS","author":"Dorey Kristen","year":"2017","unstructured":"Kristen Dorey, Nicholas Chang-Fong, and Aleksander Essex. 2017. Indiscreet Logs: Diffie-Hellman Backdoors in TLS. In NDSS 2017. The Internet Society."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813703"},{"key":"e_1_3_2_1_21_1","volume-title":"USENIX Security","author":"Durumeric Zakir","year":"2013","unstructured":"Zakir Durumeric, Eric Wustrow, and J. Alex Halderman. 2013. ZMap: Fast Internet-wide Scanning and Its Security Applications. In USENIX Security 2013, Samuel T. King (Ed.). USENIX Association, 605--620."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-013-0050-x"},{"key":"e_1_3_2_1_23_1","volume-title":"On the Multiple Fault Attacks on RSA Signatures with LSBs of Messages Unknown","author":"Han Lidong","unstructured":"Lidong Han, Wei Wei, and Mingjie Liu. 2013. On the Multiple Fault Attacks on RSA Signatures with LSBs of Messages Unknown. In Information Security and Cryptology, Miros\u0142aw Kuty\u0142owski and Moti Yung (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 1--9."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Dan Harkins and Dave Carrel. 1998. The Internet Key Exchange (IKE). IETF RFC 2409 (Proposed Standard).","DOI":"10.17487\/rfc2409"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"B. Harris. 2006. RFC 4432: RSA Key Exchange for the Secure Shell (SSH) Transport Layer Protocol.","DOI":"10.17487\/rfc4432"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2987443.2987486"},{"key":"e_1_3_2_1_27_1","volume-title":"USENIX Security","author":"Heninger Nadia","year":"2012","unstructured":"Nadia Heninger, Zakir Durumeric, Eric Wustrow, and J. Alex Halderman. 2012. Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices. In USENIX Security 2012, Tadayoshi Kohno (Ed.). USENIX Association, 205--220."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89255-7_25"},{"key":"e_1_3_2_1_29_1","volume-title":"Approximate Integer Common Divisors","author":"Howgrave-Graham Nick","unstructured":"Nick Howgrave-Graham. 2001. Approximate Integer Common Divisors. In Cryptography and Lattices, Joseph H. Silverman (Ed.). Springer Berlin Heidelberg, Berlin, Heidelberg, 51--66."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243798"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Burt Kaliski. 1998. PKCS# 1: RSA encryption version 1.5.","DOI":"10.17487\/rfc2313"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"C. Kaufman P. Hoffman Y. Nir P. Eronen and T. Kivinen. 2014. RFC 7296: Internet Key Exchange Protocol Version 2 (IKEv2).","DOI":"10.17487\/rfc7296"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-72354-7_18"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-84245-1_26"},{"key":"e_1_3_2_1_35_1","unstructured":"Arjen K Lenstra. 1996. Memo on RSA signature generation in the presence of faults. Technical Report. EPFL. https:\/\/infoscience.epfl.ch\/record\/164524."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01457454"},{"key":"e_1_3_2_1_37_1","volume-title":"Wordlists: Tool Documentation. https:\/\/www.kali.org\/tools\/wordlists\/.","author":"Linux Kali","year":"2022","unstructured":"Kali Linux. 2022. Wordlists: Tool Documentation. https:\/\/www.kali.org\/tools\/wordlists\/."},{"key":"e_1_3_2_1_38_1","unstructured":"Moxie Marlinspike David Hulton and Marsh Ray. 2012. Defeating PPTP VPNs and WPA2 Enterprise with MS-CHAPv2. In DEFCON 20. DEFCON. https:\/\/media.defcon.org\/DEF%20CON%2020\/ DEF%20CON%2020%20video%20and%20slides\/DEF%20CON%2020%20- %20Marlinspike%20Hulton%20and%20Ray%20- %20Defeating%20PPTP%20VPNs%20and%20WPA2%20Enterprise%20with%20MS-CHAPv2%20-%20Video%20and%20Slides.mp4"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"D. Maughan M. Schertler M. Schneider and J. Turner. 1998. RFC 2408: Internet Security Association and Key Management Protocol (ISAKMP).","DOI":"10.17487\/rfc2408"},{"key":"e_1_3_2_1_40_1","volume-title":"The LLL algorithm","author":"May Alexander","unstructured":"Alexander May. 2009. Using LLL-reduction for solving RSA and factorization problems. In The LLL algorithm. Springer, 315--348."},{"key":"e_1_3_2_1_41_1","volume-title":"USENIX Security","author":"Merget Robert","year":"2019","unstructured":"Robert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young, Janis Fliegenschmidt, J\u00f6rg Schwenk, and Yuval Shavitt. 2019. Scalable Scanning and Automatic Classification of TLS Padding Oracle Vulnerabilities. In USENIX Security 2019, Nadia Heninger and Patrick Traynor (Eds.). USENIX Association, 1029--1046."},{"key":"e_1_3_2_1_42_1","unstructured":"Damien Miller. 2022. SSH agent restriction. https:\/\/www.openssh.com\/agent-restrict.html."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"S. Moonesamy. 2015. RFC 7479: Using Ed25519 in SSHFP Resource Records.","DOI":"10.17487\/rfc7479"},{"key":"e_1_3_2_1_44_1","unstructured":"ntop. 2023. PF_RING: High-speed packet capture filtering and analysis. https:\/\/www.ntop.org\/products\/packet-capture\/pf_ring\/."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_46_1","volume-title":"Automation & Test in Europe Conference & Exhibition (DATE","author":"Pellegrini Andrea","year":"2010","unstructured":"Andrea Pellegrini, Valeria Bertacco, and Todd Austin. 2010. Fault-based attack of RSA authentication. In 2010 Design, Automation & Test in Europe Conference & Exhibition (DATE 2010). IEEE, 855--860."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"crossref","unstructured":"E. Rescorla. 2018. RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3.","DOI":"10.17487\/RFC8446"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-38548-3_1"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"crossref","unstructured":"D. Stebila and J. Green. 2009. RFC 5656: Elliptic Curve Algorithm Integration in the Secure Shell Transport Layer.","DOI":"10.17487\/rfc5656"},{"key":"e_1_3_2_1_50_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Sullivan George Arnold","year":"2022","unstructured":"George Arnold Sullivan, Jackson Sippe, Nadia Heninger, and Eric Wustrow. 2022. Open to a fault: On the passive compromise of TLS keys via transient errors. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA, 233--250. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/ presentation\/sullivan"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23171"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00034"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13190-5_2"},{"key":"e_1_3_2_1_54_1","unstructured":"Florian Weimer. 2015. Factoring RSA Keys With TLS Perfect Forward Secrecy. Technical Report. Red Hat. https:\/\/www.redhat.com\/en\/blog\/factoring-rsa-keys-tls-perfect-forward-secrecy."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.13154\/tches.v2020.i3.169--195"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"crossref","unstructured":"T. Ylonen and C. Lonvick. 2006 a. RFC 4252: The Secure Shell (SSH) Authentication Protocol.","DOI":"10.17487\/rfc4252"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"T. Ylonen and C. Lonvick. 2006 b. RFC 4253: The Secure Shell (SSH) Transport Layer Protocol.","DOI":"10.17487\/rfc4253"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616629","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3616629","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3616629","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:50:42Z","timestamp":1755741042000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616629"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":57,"alternative-id":["10.1145\/3576915.3616629","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3616629","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}