All cops are broadcasting: TETRA under scrutiny
Carlo Meijer, Wouter Bokslag, Jos Wetzels
摘要
This paper presents the first public in-depth security analysis of TETRA (Terrestrial Trunked Radio): a European standard for trunked radio globally used by government agencies, police, prisons, emergency services and military operators. Additionally, it is widely deployed in industrial environments such as factory campuses, harbor container terminals and airports, as well as critical infrastructure such as SCADA telecontrol of oil rigs, pipelines, transportation and electric and water utilities. Authentication and encryption within TETRA are handled by secret, proprietary cryptographic primitives. This secrecy thwarts public security assessments and independent academic scrutiny of the protection that TETRA claims to provide. The widespread adoption of TETRA, combined with the often sensitive nature of the communications, raises legitimate questions regarding its cryptographic resilience. In this light, we have set out to achieve two main goals. First, we demonstrate the feasibility of obtaining the underlying secret cryptographic primitives through reverse engineering. Second, we provide an initial assessment of the robustness of said primitives in the context of the protocols in which they are used. We present five serious security vulnerabilities pertaining to TETRA, two of which are deemed critical. Furthermore, we present descriptions and implementations of the primitives, enabling further academic scrutiny. Our findings have been validated in practice using a common-offthe-shelf radio on a TETRA network lab setup. More than a year ago, we started to communicate our preliminary findings through a coordinated disclosure process with several key stakeholders. During this process we have actively supported these stakeholders in the identification, development and deployment of possible mitigations. 1 Not to be confused with Tiny Encryption Algorithm [35] 1 straints have been imposed, both technically and regulatory. However, with millions of TETRA devices being deployed around the world, the primitives are bound to fall into the hands of adversarial parties, through either reverse engineering efforts or leaked/stolen documents. Acquisition of TETRA cryptographic primitives We distinguish three methods of acquiring the TETRA cryptographic primitives. First, the official route through ETSI, involving extensive eligibility criteria and non-disclosure agreements. Second, theft of the official specification or source code from any ETSI-approved party. Third, reverse engineering of a firmware or hardware implementation. The ETSI standards body is the official institution governing access to descriptions of TETRA cryptographic primitives. They can be obtained under a 'Non disclosure and restricted usage license', restricting copying of the specification and requiring implementation of countermeasures against reverse engineering in end products. Approval is given to 'bona fide' manufacturers of TETRA radio equipment, and a record is kept in a register [9, 10] . For TEA2, additional requirements apply, such as geographic restrictions and a license requirement for parties involved in installing, repairing and/or destroying TEA2 capable equipment [11] . Clearly, the restrictions imposed by ETSI prevent academic discussion. It is worth noting that the scientific community is likely considerably more impacted by the restrictions than a malicious actor with clandestine goals and fewer inclinations towards legal compliance. While the possibility of theft (through hacking, coercion or otherwise) is self-evident, estimating the feasibility of reverse engineering is less straightforward. Such an endeavor is nontrivial, due to the aforementioned ETSI-mandated countermeasures against reverse engineering. We successfully recovered the TAA1 suite of primitives and the TEA1, TEA2 and TEA3 stream ciphers from a Motorola MTM5400 (a common off-the-shelf radio) and its associated firmware images, using software exploitation techniques. With our research, we demonstrate the feasibility of the reverse engineering approach, while complying with the legal framework and remaining at liberty to share our findings with the public. Uncovered issues Having obtained the primitives through reverse engineering, we find ourselves in the unique position to study the security of TETRA in a more in-depth fashion than any previously published work in the scientific literature. We found several serious issues, pertaining to air interface encryption, identity encryption and the authentication. Ranging from trivial key recovery through brute-force and meet-in-the-middle attacks to keystream recovery by an active adversary, our work proves the long-standing reputation of TETRA as a highly secure system to be unjustified. Surprisingly, one of the most severe issues (Section 5.1) could have been identified without access to the cryptographic primitives. We speculate the closed nature of TETRA security has dissuaded the usual public research from taking
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
相关 Paper
- Practically-exploitable Cryptographic Vulnerabilities in MatrixMartin R. Albrecht, Sofía Celi, Benjamin Dowling, Daniel JonesS&P 2023
- How Not to Protect Your IP - An Industry-Wide Break of IEEE 1735 ImplementationsJulian Speith, Florian Schweins, Maik Ender, Marc Fyrbiak 等S&P 2022 · 被引用 10 次
- Three Lessons From Threema: Analysis of a Secure MessengerKenneth G. Paterson, Matteo Scarlata, Kien Tuong TruongUSENIX Security 2023
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 被引用 231 次
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
