How SSH Really Works

ByteByteGoAbout 3 min readMar 24, 2025Watch original
THE SUMMARYAI-generated

SSH Protocol Explained: Securing Remote Connections

Key Concepts:

  • SSH (Secure Shell): A cryptographic network protocol for secure remote access.
  • SSH2: The standardized version of SSH with improved security.
  • TCP Connection: The foundation for SSH communication, typically on port 22.
  • Algorithm Negotiation: The process of agreeing on cryptographic algorithms for key exchange, encryption, and integrity checking.
  • Elliptic Curve Diffie-Hellman (ECDH): A key exchange method used to generate a shared secret key.
  • Ephemeral Keys: Temporary keys used in ECDH to provide perfect forward secrecy.
  • Perfect Forward Secrecy (PFS): A security feature ensuring past session data remains secure even if keys are compromised in the future.
  • Public Key Authentication: A secure authentication method using public-private key pairs.
  • ~/.ssh/authorized_keys: The file on Unix-like systems where authorized public keys are stored.
  • SSH Local Forwarding: Tunneling other network services through an SSH connection.

1. Initial Connection and Negotiation:

  • The SSH client initiates a TCP connection to the server, usually on port 22.
  • Version Negotiation: The client and server agree on the SSH protocol version (SSH2 is the focus). This ensures compatibility.
  • Algorithm Negotiation: The client and server negotiate cryptographic algorithms for:
    • Key exchange (e.g., Elliptic Curve Diffie-Hellman)
    • Encryption (symmetric encryption for data transfer)
    • Integrity checking (ensuring data hasn't been tampered with)
  • This negotiation allows SSH to adapt to different security requirements and computational capabilities.

2. Key Exchange (Elliptic Curve Diffie-Hellman):

  • The client and server use Elliptic Curve Diffie-Hellman (ECDH) to generate a shared session key.
  • Both sides generate ephemeral key pairs (public and private).
  • They exchange their public keys.
  • Using the exchanged public keys and their own private keys, both sides independently compute the same shared secret.
  • Perfect Forward Secrecy (PFS): The use of ephemeral keys ensures that even if the server's private key is compromised in the future, past session data remains secure because the session key was unique and temporary.

3. Authentication:

  • The client initiates a login request.
  • Public Key Authentication (Preferred Method):
    • The server checks the ~/.ssh/authorized_keys file (on Unix-like systems) for a matching public key.
    • If a match is found, the server encrypts a random number using the client's public key and sends it back to the client.
    • The client decrypts the random number using its private key and sends the decrypted value back to the server.
    • The server verifies the decrypted value, confirming the client's identity.
  • Password-Based Authentication (Less Secure): SSH also supports password authentication, but it's less secure than public key authentication.
  • The challenge-response mechanism proves that:
    • The server has the correct public key for the client.
    • The client possesses the corresponding private key.

4. Secure Communication:

  • Once authentication is complete, the SSH session is fully established.
  • All subsequent communication (commands and responses) is encrypted using the shared session key established during the key exchange.
  • The client sends commands to the server, encrypted with the session key.
  • The server executes the commands and encrypts the results using the same session key before sending them back to the client.
  • The client decrypts the results using the session key.
  • This encrypted back-and-forth continues for the duration of the SSH session.

5. SSH Local Forwarding (Tunneling):

  • SSH supports features like SSH local forwarding, which allows you to tunnel other network services through the SSH connection.
  • This is useful for:
    • Accessing services blocked by firewalls.
    • Adding a layer of security to unencrypted protocols.

6. Conclusion:

SSH provides a secure tunnel for remote access by establishing a TCP connection, negotiating cryptographic algorithms, performing key exchange (preferably using ECDH for PFS), and authenticating the client (ideally using public key authentication). All subsequent communication is encrypted, ensuring confidentiality and integrity. SSH also supports features like local forwarding for added flexibility and security.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.