Skip to content

Cryptography

GuyPhy edited this page Sep 17, 2023 · 5 revisions

Key cryptographic aspects/encryption/algorithms/protocols used in,

GSM

GSM (Global System for Mobile Communications) is a standard for mobile telecommunications that includes various cryptographic aspects, encryption algorithms, and protocols to secure communication.

1. Authentication and Key Agreement (AKA)

AKA is the primary authentication and key establishment protocol used in GSM networks.
It ensures the authenticity of the subscriber and helps establish a session key for secure communication between the mobile device and the network.

  • AKA works by having the mobile device and the network exchange a series of challenges and responses.
  • The challenges are generated by the network and the responses are generated by the mobile device using a secret key stored on the SIM card.

If the responses are correct, the network can be confident that the mobile device is authentic.

  • The session key generated by AKA is used to encrypt all subsequent communication between the mobile device and the network.
  • This ensures that the communication is secure from eavesdropping or tampering.
  • AKA is a critical security protocol for GSM networks.

It helps to protect subscribers from unauthorized access to their accounts and data, also helps to prevent fraud and other malicious activities.

2. Comp128 Algorithms

COMP128 is a family of proprietary algorithms used for generating the Authentication Response (RAND) during the AKA process. The most common variants are COMP128-1, COMP128-2, and COMP128-3. However, over time, security vulnerabilities were discovered in these algorithms.

  • The COMP128-1 algorithm is considered weak because there is insufficient diffusion of small changes in the input.
    This means that small changes in the input can have a large impact on the output, which makes it easier for attackers to guess the output.

  • Practical attacks have been demonstrated that can recover the subscriber key from the SIM using COMP128-1.
    This means that an attacker could gain unauthorized access to the subscriber's account and data.

  • The COMP128-2 and COMP128-3 algorithms are considered to be more secure than COMP128-1.
    However, they still have some security vulnerabilities.
    For example, it is possible to generate collisions between different inputs, which could be used to launch denial-of-service attacks.

For these reasons, COMP128 is no longer considered to be a secure algorithm for generating the Authentication Response (RAND) during the AKA process. It has been replaced by more secure algorithms, such as Milenage.
Milenage is a family of algorithms that is used to generate the Authentication Response (RAND) during the AKA process.

  • Milenage is based on the Advanced Encryption Standard (AES) algorithm, which is one of the most secure encryption algorithms available.
  • It also uses a number of other security features to protect against attacks.

3. GSM Security Modes

GSM supports different security modes based on the level of security required. These modes include:

  • No Security (no encryption or authentication):
    This mode provides no security at all. There is no encryption or authentication, so anyone can listen in on calls or intercept data.

  • A5/0 (no encryption, but authentication):
    This mode provides authentication but no encryption. This means that the network can be confident that the subscriber is who they say they are, but the communication is not secure from eavesdropping.

  • A5/1 (encryption and authentication, now considered weak):
    This mode provides both encryption and authentication. It is considered to be the most secure mode available in GSM networks. However, there have been some security vulnerabilities discovered in A5/1, so it is not considered to be as secure as newer algorithms.

  • A5/2 (encryption and authentication, weaker than A5/1):
    This mode is similar to A5/1, but it is considered to be weaker. It is not recommended for use in new networks.

  • A5/3 (encryption and authentication, the most secure option):
    This mode is the most secure option available in GSM networks. It is based on the Advanced Encryption Standard (AES) algorithm, which is one of the most secure encryption algorithms available.

4. Key Generation Center (KGC)

The KGC is responsible for generating and distributing cryptographic keys in GSM networks. It generates the session keys used for encryption and decryption during communication.

  • The KGC is a trusted third party that is not part of the GSM network.

  • The KGC distributes the keys to the network elements in the GSM network, such as the Base Stations (BSs) and the Mobile Switching Centers (MSCS).

  • The BSs use the keys to encrypt and decrypt the data that is sent between them and the mobile devices.

  • The MSCSs use the keys to authenticate the mobile devices and to establish secure communication channels with them.

  • The KGC also generates the keys that are used for the AKA authentication process. The AKA authentication process is used to authenticate the mobile devices and to establish a session key for secure communication.

  • The KGC is a critical part of the GSM security architecture. It ensures that the keys used for encryption and decryption are secure and that they cannot be compromised by attackers. This helps to protect the subscribers' data and to prevent fraud and other malicious activities.

KGC maintains a master public/secret key pair (mpk, msk).
The KGC (implicitly) confirms the validity of each user ID and then issues an associated secret key skID using the master secret key msk.

5. Subscriber Identity Module (SIM)

The SIM card stores important cryptographic keys and information, including the International Mobile Subscriber Identity (IMSI) and the secret Ki key.
These keys are used during the authentication process.

6. Base Station Subsystem (BSS)

The BSS includes the Base Transceiver Station (BTS) and the Base Station Controller (BSC).
It handles communication with mobile devices and initiates the authentication and encryption processes.

7. Home Location Register (HLR) and Authentication Center (AuC)

The HLR stores subscriber information and the AuC generates the Authentication Vectors (RAND) used in the AKA process. These vectors are sent to the mobile device and the network to authenticate and establish secure communication.

8. Temporary Mobile Subscriber Identity (TMSI)

The TMSI is a temporary identifier assigned to a mobile device to enhance privacy by reducing the exposure of the IMSI during communication.

3G (UMTS - Universal Mobile Telecommunications System)


1. Authentication and Key Agreement (AKA)

Similar to GSM, 3G UMTS networks also use AKA for authentication and key establishment.
It ensures subscriber authenticity and session key establishment.

  • The AKA process in 3G UMTS networks is similar to the AKA process in GSM networks.
    However, there are some differences.
    • In 3G UMTS networks, the Authentication Center (AuC) is responsible for generating the keys that are used for the AKA authentication process.
    • In 3G UMTS networks, the session key that is generated by AKA is used to encrypt all subsequent communication between the mobile device and the network, including the authentication messages that are exchanged during the AKA process.
      This helps to protect the authentication messages from being intercepted by attackers.
  • The AuC is a trusted third party that is not part of the 3G UMTS network.
    This means that it cannot be compromised by an attacker who has gained access to the network.

2. KASUMI Algorithm

KASUMI is used for encryption in 3G UMTS networks. It provides confidentiality and integrity of user data and signaling messages.

KASUMI Cipher

KASUMI is a block cipher algorithm designed to provide strong encryption and security for UMTS networks.
It operates on blocks of data and employs a secret key to transform the input plaintext into ciphertext.
This ciphertext can then be transmitted securely over the network, ensuring that only authorized parties can decrypt and access the original data.

Confidentiality

In the context of 3G UMTS networks, KASUMI is primarily used to achieve confidentiality.
When a user initiates communication (such as making a call or sending data), the data generated by the user's device is encrypted using KASUMI with session keys derived through the Authentication and Key Agreement (AKA) protocol.

  • Authentication and Key Agreement (AKA):

The AKA protocol ensures mutual authentication between the user's device (UE) and the network's authentication center (AuC). During the AKA process, temporary session keys (CK and IK) are generated. These session keys are unique to the user and the current communication session.

  • Data Encryption:

Once the session keys are established, KASUMI is used to encrypt the user's data before transmission. The plaintext data is divided into blocks, and each block is encrypted using the KASUMI algorithm with the session keys. The resulting ciphertext is transmitted over the network.

  • Integrity:
    In addition to confidentiality, KASUMI also contributes to ensuring the integrity of user data and signaling messages. Integrity protection prevents unauthorized modification or tampering with the transmitted data.

Here's how integrity is achieved:

  • Data Integrity Protection:

Before the data is encrypted, a process called integrity protection is applied. The integrity protection mechanism generates an integrity check value (ICV) for the data. This ICV is then encrypted along with the data using KASUMI and the session keys.

  • Verification of Integrity:

At the receiving end, the ICV is decrypted and verified using KASUMI and the session keys. If the calculated ICV matches the received ICV, it indicates that the data has not been tampered with during transmission.

3. UMTS Security Algorithms

UEA1 (UMTS Encryption Algorithm 128-bit) and UEA2

Used for encryption of user data in UMTS networks.

  • UEA1 and UEA2 are encryption algorithms employed in UMTS networks to provide confidentiality for user data.
  • UEA1 uses a 128-bit key length and UEA2 employs a 128-bit key length as well.
  • These algorithms transform the plaintext user data into ciphertext using the session keys established during the Authentication and Key Agreement (AKA) protocol.
  • The encrypted data is then transmitted over the network, safeguarding the privacy of the communication.

UIA1 (UMTS Integrity Algorithm 128-bit) and UIA2

Used for message integrity protection.

  • UIA1 and UIA2 are integrity algorithms used in UMTS networks to protect the integrity of messages and data.
  • UIA1 uses a 128-bit key length and UIA2 also utilizes a 128-bit key length.
  • These algorithms generate integrity check values (ICVs) for the transmitted messages.
  • The ICVs are computed using the session keys and the message data. This process ensures that the data remains unchanged during transmission.
  • At the receiving end, the ICVs are recalculated using the same algorithm and session keys. If the recalculated ICV matches the received ICV, it indicates that the message has not been tampered with.

4G (LTE - Long-Term Evolution)

1. Authentication and Key Agreement (AKA)

4G LTE networks use an enhanced version of AKA called EPS-AKA (Evolved Packet System-AKA). It includes mutual authentication and key establishment between the user equipment (UE) and the network.

EPS-AKA (Evolved Packet System-AKA)

EPS-AKA is the authentication and key agreement protocol used in 4G LTE networks.
It's an evolved version of the AKA protocol used in earlier mobile generations and is designed to address the security requirements of LTE's advanced features and architecture.

Features of EPS-AKA

  • Mutual Authentication:

EPS-AKA provides mutual authentication between the user equipment (UE) and the network.
Both the UE and the network authenticate each other to establish a secure communication channel.

  • Key Establishment:

EPS-AKA is responsible for generating session keys that are used for encryption and integrity protection of user data and signaling messages. These session keys are unique to each communication session and are derived from the authentication process.

  • Security Algorithms:

EPS-AKA supports the use of strong cryptographic algorithms for encryption, integrity protection, and authentication. These algorithms ensure the confidentiality, integrity, and authenticity of the data transmitted over the LTE network. Protection Against Attacks:

EPS-AKA is designed to mitigate various security threats, including eavesdropping, impersonation attacks, and man-in-the-middle attacks. The mutual authentication process helps prevent unauthorized devices from gaining access to the network.

Authentication and Key Agreement Process in EPS-AKA

  • Authentication Vectors:

The Home Subscriber Server (HSS) generates authentication vectors that include a random challenge and other parameters. The UE and the network both use these vectors in the authentication process.

  • Mutual Authentication:

The UE responds to the network's challenge with a calculated response. The network verifies the response, and if successful, authenticates the UE. Similarly, the network responds with a challenge to the UE, and the UE verifies the response to authenticate the network. Key Generation:

Upon successful authentication, EPS-AKA generates session keys (KeNB and KASME) that are used for encryption and integrity protection. These keys are unique to the UE and the specific communication session.

2. Elliptic Curve Cryptography (ECC)

ECC is used for key exchange and authentication in LTE networks, providing strong security with shorter key lengths compared to traditional RSA.

Elliptic Curve Cryptography (ECC) in LTE Networks

  • Key Exchange:

ECC allows secure key exchange between parties, enabling them to establish a shared secret key over an insecure communication channel.
This shared key can then be used for symmetric encryption and decryption, providing confidentiality for the data exchanged.

  • Authentication:

ECC is also used for authentication purposes in LTE networks.
By using ECC-based digital signatures, devices can prove their authenticity and integrity to the network or other devices.
ECC's shorter key lengths make signature generation and verification faster and more efficient.

Advantages of ECC in LTE Networks

  • Shorter Key Lengths:

One of the most significant advantages of ECC is its ability to provide the same level of security as traditional methods (like RSA) but with much shorter key lengths.
Shorter keys mean less computational overhead, reduced processing time, and lower memory requirements, which are critical for mobile devices with limited resources.

  • Efficiency:

ECC operations, such as encryption, decryption, and digital signatures, are computationally lighter compared to traditional methods.
This efficiency is crucial for mobile networks where devices have limited processing power and battery life.

  • Bandwidth Savings:

The use of shorter key lengths in ECC reduces the size of cryptographic payloads in data packets, resulting in less overhead and improved bandwidth efficiency.

  • Strong Security:

Despite the shorter key lengths, ECC maintains a high level of security due to the mathematical properties of elliptic curves. ECC's resistance to various attacks makes it a reliable choice for securing communications.

  • Future-Proofing:

ECC is considered more resistant to attacks based on quantum computers compared to traditional algorithms like RSA. This makes ECC a good choice for future-proofing the security of LTE networks.

3. LTE Security Algorithms

  • EEA1 (Encryption Algorithm 128-bit) and EEA2: Used for user data encryption.
  • EIA1 (Integrity Algorithm 128-bit) and EIA2: Used for message integrity protection.

4. LTE Security Modes

LTE supports different security modes similar to GSM, allowing different levels of encryption and integrity protection.

5G

  1. Authentication and Key Agreement (AKA): 5G networks use a more advanced version of AKA called 5G-AKA. It offers improved security and privacy features, including support for 5G-specific services.

  2. ECC and Post-Quantum Cryptography (PQC): 5G introduces the use of ECC for key exchange and authentication, along with the consideration of post-quantum cryptographic algorithms to prepare for quantum computing threats.

  3. 5G Security Algorithms:

  • 1NEA1 (New Encryption Algorithm 128-bit) and NEA2: Used for user data encryption.
  • NIA1 (New Integrity Algorithm 128-bit) and NIA2: Used for message integrity protection.
  1. Network Slicing Security: 5G's architecture supports network slicing, which requires strong isolation between slices to prevent unauthorized access and data leakage.

  2. Security for Internet of Things (IoT): 5G incorporates security features specifically designed for IoT devices, including device identity, secure device onboarding, and communication encryption.

  3. Network Function Virtualization (NFV) and Software-Defined Networking (SDN) Security: 5G's virtualized and software-defined infrastructure introduces new security challenges and solutions, including secure deployment and management of network functions.