SSH communication method and device based on quantum key and medium
By integrating quantum key distribution technology into the SSH protocol, using a key exchange algorithm based on quantum keys, the security risks of traditional SSH protocols in the face of quantum computer attacks are solved, and remote login and data transmission are achieved with higher security.
Patent Information
- Application Number
- CN202510594323.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-05-09
AI Technical Summary
When traditional SSH protocol faces security risks when attacking quantum computers, traditional encryption algorithms are easily quickly cracked by quantum computers, resulting in security threats.
Integrating quantum key distribution (QKD) technology into the handshake process of the SSH protocol, by extending SSH protocol messages, negotiating the use of a quantum key-based key exchange algorithm to generate the final session key combined with the traditional SSH key exchange algorithm.
It provides a higher security remote login and data transmission solution, which can withstand quantum computer attacks and ensure the security of communication data in the face of future quantum computer attacks.
Smart Images

Figure CN120128339A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more specifically, to an SSH communication method, device, and medium based on quantum keys. Background Art
[0002] With the rapid development of information technology, network security issues have increasingly become the focus of attention in all sectors of society. Among many security protocols, the SSH (Secure Shell) protocol is widely adopted due to its security in providing remote login and data transmission.
[0003] Traditional SSH protocols mainly rely on asymmetric encryption algorithms (such as RSA, DSA, etc.) to ensure the security and integrity of data transmission. However, with the development of quantum computing technology, traditional encryption algorithms face unprecedented challenges. Quantum computers have powerful computing capabilities beyond classical computers. In particular, for traditional encryption algorithms based on factorization and discrete logarithm problems, they can theoretically be quickly cracked, thus posing a serious threat to the security of existing SSH protocols.
[0004] In the face of the above security risks, it is particularly important to explore a new SSH communication method that can resist quantum computer attacks. For this reason, the present invention proposes an SSH communication solution based on quantum key distribution (QKD, Quantum Key Distribution) technology. Summary of the Invention
[0005] In view of this, the present invention provides an SSH communication method, device, and medium based on quantum keys, aiming to solve the security risks of traditional SSH protocols in the face of quantum computer attacks. By applying quantum key distribution technology to the SSH protocol, a remote login and data transmission solution with higher security is provided.
[0006] To achieve the above object, the present invention adopts the following technical solutions:
[0007] An SSH communication method based on quantum keys, comprising:
[0008] The client sends a client SSH protocol version message to the server, and after receiving it, the server sends a server SSH protocol version message to the client;
[0009] After receiving the server SSH protocol version message, the client sends a key exchange initialization message to the server, and after receiving it, the server sends a key exchange initialization message to the client;
[0010] After initialization is completed, the client sends a quantum key exchange request to the server. After receiving the quantum key exchange request, the server sends a quantum key exchange response to the client, and calculates the server SSH traditional protocol key negotiation session key and the server QK quantum key;
[0011] After receiving the quantum key exchange response, the client calculates the new session key and sends a quantum key exchange end message to the server;
[0012] After receiving the quantum key exchange end message, the server calculates the new session key through the server SSH traditional protocol key negotiation session key and the server QK quantum key.
[0013] Preferably, the client SSH protocol version message includes the SSH protocol, quantum SSH, and client custom information;
[0014] The server SSH protocol version message includes the SSH protocol, quantum SSH, and server custom information.
[0015] Preferably, the key exchange initialization message includes the key exchange algorithm, host key algorithm, client-to-server encryption algorithm, server-to-client encryption algorithm, client-to-server MAC algorithm, and server-to-client MAC algorithm.
[0016] Preferably, before the client sends a quantum key exchange request to the server, it also includes:
[0017] The client obtains quantum key extension information from the QKD device. The quantum key extension information includes the client QK quantum key and the client quantum key extension.
[0018] Preferably, the quantum key exchange request includes the client's SSH traditional protocol key and the client quantum key extension.
[0019] Preferably, when the server calculates the server SSH traditional protocol key negotiation session key and the server QK quantum key, it specifically includes:
[0020] Calculate the server SSH traditional protocol key negotiation session key based on the client's SSH traditional protocol key;
[0021] Obtain the server QK quantum key through the client quantum key extension on the same QKD device.
[0022] Preferably, the quantum key exchange response includes the server SSH traditional protocol key exchange parameters and the server quantum key extension.
[0023] Preferably, when the client calculates the new session key after receiving the quantum key exchange response, it includes:
[0024] Compare the server-side quantum key expansion with the client-side quantum key expansion. If they are the same, the verification passes;
[0025] Calculate the client SSH traditional protocol key negotiation session key based on the server SSH traditional protocol key exchange parameters;
[0026] Calculate the new session key based on the client SSH traditional protocol key negotiation session key and the client QK quantum key.
[0027] A computer device, comprising: a memory and a processor. A computer program that can run on the processor is stored in the memory. When the processor executes the computer program, a SSH communication method based on quantum keys is implemented.
[0028] A computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, a SSH communication method based on quantum keys is implemented.
[0029] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses a SSH communication method, device and medium based on quantum keys, integrating the quantum key distribution (QKD) technology into the handshake process of the SSH protocol, negotiating to use a key exchange algorithm based on quantum keys by extending the SSH protocol message. The communication parties use the QKD device to generate and share quantum keys, and combine them with the keys generated by the traditional SSH key exchange algorithm to generate the final session key for subsequent encrypted communication. It solves the security risks of the traditional SSH protocol in the face of quantum computer attacks, and provides a remote login and data transmission solution with higher security. It is applicable to remote login and data transmission scenarios with high security requirements, such as network communications in government agencies, financial institutions and military fields. By using the SSH communication method based on quantum keys, these institutions can ensure the security of their communication data in the face of future quantum computer attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0031] Figure 1 It is a flowchart of a SSH communication method based on quantum keys provided by the present invention.
[0032] Figure 2 It is an interaction flowchart provided by the present invention. Detailed implementation manners
[0033] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0034] An SSH communication method based on quantum keys is disclosed in the embodiments of the present invention. As Figure 1 and Figure 2 shown, both the client and the server are connected to a common QKD device for obtaining QK quantum keys. The method includes:
[0035] 1) The client sends a client SSH protocol version message to the server. After receiving it, the server confirms it as the quantum version according to the client SSH protocol version message and then sends a server SSH protocol version message to the client. The client SSH protocol version message includes the SSH protocol, quantum SSH, and client-customized information. The server SSH protocol version message includes the SSH protocol, quantum SSH, and server-customized information.
[0036] 2) After the client receives the server SSH protocol version message and confirms it as the quantum version, it sends a key exchange initialization message to the server. The message includes a key exchange algorithm, a host key algorithm, a client-to-server encryption algorithm, a server-to-client encryption algorithm, a client-to-server MAC algorithm, and a server-to-client MAC algorithm;
[0037] Among them, a quantum key negotiation algorithm extension is added to the key exchange algorithm, as shown in the following examples:
[0038] qkd-diffie-hellman-group1-sha1 (Diffie-Hellman key exchange algorithm group1, quantum key extension)
[0039] qkd-diffie-hellman-group14-sha1 (Diffie-Hellman key exchange algorithm group14, quantum key extension)
[0040] qkd-diffie-hellman-group-exchange-sha1 (Diffie-Hellman key exchange algorithm exchange, quantum key extension)
[0041] qkd-diffie-hellman-group-exchange-sha256 (Diffie-Hellman key exchange algorithm exchange, quantum key expansion)
[0042]
[0043] qkd-sm2-sm3 (National Cryptography SM2 key exchange algorithm, quantum key expansion)
[0044] After receiving it, the server sends a key exchange initialization message to the client, and the key exchange initialization is the same as the content sent by the client.
[0045] For the convenience of understanding the technical solution, in the following content, the quantum key expansion is called the client quantum key expansion on the client side and the server quantum key expansion on the server side.
[0046] 3) The client obtains quantum key expansion information from the QKD device. The quantum key expansion information includes the client QK quantum key and the client quantum key expansion. The client QK quantum key is locally saved, and the client sends a quantum key exchange request to the server. The quantum key exchange request contains the client's SSH traditional protocol key and the client quantum key expansion.
[0047] After the server receives the quantum key exchange request sent by the client, it performs the following operations:
[0048] A) Send a quantum key exchange response. The message content includes the server SSH traditional protocol key exchange parameters and the server quantum key expansion. The server quantum key expansion is the same as that of the client and is used for the client to confirm;
[0049] B) Calculate the server SSH traditional protocol key negotiation session key based on the client's SSH traditional protocol key;
[0050] C) Use the client quantum key expansion sent by the client to obtain the server QK quantum key on the same QKD device.
[0051] 4) After the client receives the server quantum key exchange response, it sends a quantum key exchange end message and calculates a new session key.
[0052] Among them, the quantum key exchange end message is an optional message. In some traditional algorithms (such as sm2-sm3), if this message is included, the quantum expansion is increased. The content of the quantum key exchange end message includes the client quantum key expansion.
[0053] The client calculates the new session key after receiving the quantum key exchange response, including:
[0054] Compare the server-side quantum key expansion with the client-side quantum key expansion. If they are the same, the verification passes;
[0055] Calculate the client SSH traditional protocol key negotiation session key based on the server SSH traditional protocol key exchange parameters;
[0056] Calculate the new session key based on the client SSH traditional protocol key negotiation session key and the client QK quantum key.
[0057] 5) After the server receives the quantum key exchange end message, perform the same key operation:
[0058] Calculate the new session key based on the server SSH traditional protocol key negotiation session key and the server QK quantum key.
[0059] For subsequent communications, the client and the server use the same session key for encrypted communication based on the algorithm in the key exchange initialization message.
[0060] In the entire negotiation process of the present invention, QK quantum key negotiation is added. The QK quantum key participates in the traditional SSH handshake interaction, and the traditional SSH handshake interaction participates in the final session key calculation in the final communication session key calculation stage, solving the security hidden danger problem of the traditional SSH protocol in the face of quantum computer attacks.
[0061] This embodiment provides a computer device, including: a memory and a processor. A computer program that can run on the processor is stored in the memory. When the processor executes the computer program, a SSH communication method based on quantum keys is implemented.
[0062] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, a SSH communication method based on quantum keys is implemented.
[0063] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes: various media such as mobile storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0064] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0065] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A SSH communication method based on quantum key, characterized in that: include: The client sends a client SSH protocol version message to the server, and the server sends a server SSH protocol version message to the client after receiving it. After receiving the SSH protocol version message from the server, the client sends a key exchange initialization message to the server. After receiving the message, the server sends a key exchange initialization message to the client. After the initialization is completed, the client sends a quantum key exchange request to the server. After receiving the quantum key exchange request, the server sends a quantum key exchange response to the client and calculates the server's SSH traditional protocol key negotiation session key and the server's QK quantum key; After receiving the quantum key exchange response, the client calculates the new session key and sends a quantum key exchange end message to the server; After receiving the quantum key exchange completion message, the server negotiates the session key through the server's SSH traditional protocol key and calculates the new session key with the server's QK quantum key.
2. The SSH communication method based on quantum key according to claim 1, characterized in that: The client SSH protocol version message includes SSH protocol, quantum SSH, and client customized information; The server-side SSH protocol version message includes SSH protocol, quantum SSH, and server-side custom information.
3. The SSH communication method based on quantum key according to claim 1, characterized in that: The key exchange initialization message includes the key exchange algorithm, host key algorithm, client-to-server encryption algorithm, server-to-client encryption algorithm, client-to-server MAC algorithm, and server-to-client MAC algorithm.
4. The SSH communication method based on quantum key according to claim 1, characterized in that: Before the client sends a quantum key exchange request to the server, it also includes: The client obtains quantum key extension information from the QKD device, and the quantum key extension information includes the client QK quantum key and the client quantum key extension.
5. The SSH communication method based on quantum key according to claim 4, characterized in that: The quantum key exchange request includes the client's SSH traditional protocol key and the client quantum key extension.
6. The SSH communication method based on quantum key according to claim 5, characterized in that: The server calculates the server SSH traditional protocol key negotiation session key and the server QK quantum key, including: Calculate the server-side SSH traditional protocol key negotiation session key based on the client's SSH traditional protocol key; The server-side QK quantum key is obtained on the same QKD device through client-side quantum key expansion.
7. The SSH communication method based on quantum key according to claim 5, characterized in that: The quantum key exchange response includes the server-side SSH traditional protocol key exchange parameters and the server-side quantum key extension.
8. The SSH communication method based on quantum key according to claim 7, characterized in that: After receiving the quantum key exchange response, the client calculates the new session key including: Compare the server quantum key extension with the client quantum key extension, if they are the same, the verification is successful; Calculate the client SSH traditional protocol key negotiation session key based on the server SSH traditional protocol key exchange parameters; The new session key is calculated based on the client's SSH traditional protocol key negotiation session key and the client's QK quantum key.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor executes the computer program, the method according to any one of claims 1 to 8 is implemented.
10. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, which, when executed by a processor, implements the method described in any one of claims 1 to 8.
Citation Information
Patent Citations
Method and system for achieving SSH protocol based on post-quantum key exchange
CN108111301A
Anti-quantum security enhancement method of secure shell protocol
CN118659881A
National cryptographic SSH protocol supporting anti-quantum algorithm and cryptographic device
CN118984225A
Key generation method and device, computer program product and electronic equipment
CN119276497A
Authentication method and system based on Ksession shared session key MAC
CN119583064A