Menu

Database

Weaknesses in the A5/1 Cipher

WVE ID: WVE-2008-0007

Type: Vulnerability

Status: Candidate

Classification:
Cryptographic
Information Disclosure

Description:
The A5/1 cipher is vulnerable to an offline key-state attack that allows an attacker to decrypt encrypted information without key knowledge. A5/1 is leveraged by cellular GSM networks to protect voice conversations and SMS messages.

Discussion:
A5/1 is a stream cipher used in GSM networks for confidentiality of voice conversations and SMS messages. Multiple weaknesses weaken the security of the cipher such that an attacker can mount a precomputed key-state lookup attack against information collected during connection setup-up between a base station and a GSM handset. Using known plain-text and cipher-text pairs, the 64-bit cipher is effectively reduced to 1/64 of the keyspace, or approximately 288 quadrillion key states.

Leveraging an array of FPGA's, it is possible to precompute all 288 quadrillion key states, resulting in 2 TB of data. Using this data, an attacker can determine the per-session key derived for voice and SMS messages and successfully decrypt the data. One effort is underway to generate this data, with the intent on making the use of this data open to the public.

Credits
Author: Steve : THC
Author: David Hulton : Pico Computing

References
URL: http://dewy.fem.tu-ilmenau.de/CCC/CCCamp07/video/m4v/cccamp07-en-2015-The_A5_Cracking_Project.m4v
URL: http://wiki.thc.org/cracking_a5
URL: http://www.blackhat.com/html/featured_media/bh08-002-Stream-1.mov

Released: 2007-05-25

Submitter
Joshua Wright (jwright@arubanetworks.com) : Aruba Networks

Submitted: Wed Apr 09 18:07:20 -0700 2008

Candidate Date: Wed Apr 09 19:15:03 -0700 2008


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...