|
[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]
Re: Silicon.fr reporting GSM crypto broken |  |
- To: [EMAIL PROTECTED]
- Subject: Re: Silicon.fr reporting GSM crypto broken
- From: [EMAIL PROTECTED] (David Wagner)
- Date: Thu, 4 Sep 2003 18:28:34 +0000 (UTC)
- Distribution: isaac
- Newsgroups: isaac.lists.ukcrypto
- Organization: University of California, Berkeley
- References: <[EMAIL PROTECTED]>
- Reply-to: [EMAIL PROTECTED]
- Sender: [EMAIL PROTECTED]
 |
| |
Owen Blacker wrote:
>Though I think their paragraph "The security loophole arises because of
>a fundamental mistake made by GSM developers in creating a system which
>corrected for interference of the line prior to encrypting a
>conversation, he explained." might be down to poor translation
>somewhere (from Hebrew, maybe?) as my translation feels like it makes
>more sense to me.
GSM compresses before encrypting. This means that some of the input to
the encryption is known. This in turn makes ciphertext-only attacks
on GSM possible. Then they exploited a number of protocol attacks to
show how to use attacks on A5/2 (the weak cipher) to recover A5/1 keys,
even without cryptanalyzing A5/1 itself. An impressive piece of work.
If you missed the talk at CRYPTO, you really missed out!
| |