Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2
Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent, Håvard Raddum, Yann Rotella, David Rupprecht, Lukas Stennes
Abstract
This paper presents the first publicly available cryptanalytic attacks on the GEA-1 and GEA-2 algorithms. Instead of providing full 64-bit security, we show that the initial state of GEA-1 can be recovered from as little as 65 bits of known keystream (with at least 24 bits coming from one frame) in time GEA-1 evaluations and using 44.5 GiB of memory.
The attack on GEA-1 is based on an exceptional interaction of the deployed LFSRs and the key initialization, which is highly unlikely to occur by chance. This unusual pattern indicates that the weakness is intentionally hidden to limit the security level to 40 bit by design.
In contrast, for GEA-2 we did not discover the same intentional weakness. However, using a combination of algebraic techniques and list merging algorithms we are still able to break GEA-2 in time GEA-2 evaluations. The main practical hurdle is the required knowledge of 1600 bytes of keystream.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c6a74f4b-4ef2-4477-8397-b5401ac74769Cited by top-tier papers3
- Constructing and Deconstructing Intentional Weaknesses in Symmetric CiphersChristof Beierle, Tim Beyne, Patrick Felke, Gregor LeanderCRYPTO 2022 · 7 citations
- Preventing SIM Box Fraud Using Device Model FingerprintingBeomseok Oh, Junho Ahn, Sangwook Bae, Mincheol Son et al.NDSS 2023
- Reversing, Breaking, and Fixing the French Legislative Election E-Voting ProtocolAlexandre Debant, Lucca HirschiUSENIX Security 2023
Related papers
- Refined Cryptanalysis of the GPRS Ciphers GEA-1 and GEA-2Dor Amzaleg, Itai DinurEUROCRYPT 2022 · 10 citations
- A Correlation Attack on Full SNOW-V and SNOW-ViZhen Shi, Chenhui Jin, Jiyan Zhang, Ting Cui et al.EUROCRYPT 2022 · 22 citations
- Better Concrete Security for Half-Gates Garbling (in the Multi-instance Setting)Chun Guo, Jonathan Katz, Xiao Wang, Chenkai Weng et al.CRYPTO 2020 · 32 citations
- A Greater GIFT: Strengthening GIFT Against Statistical CryptanalysisLing Sun, Bart Preneel, Wei Wang, Meiqin WangEUROCRYPT 2022 · 6 citations
- Improving Key-Recovery in Linear Attacks: Application to 28-Round PRESENTAntonio Flórez-Gutiérrez, María Naya-PlasenciaEUROCRYPT 2020 · 39 citations
