Security of GSM System

Introduction

Every day millions of people use cellular phones over radio links. With the increasing features, the mobile phone is gradually becoming a handheld computer. In the early 1980's, when most of the mobile telephone system was analog, the inefficiency in managing the growing demands in a cost-effective manner led to the opening of the door for digital technology (Huynh & Nguyen, 2003). According to Margrave (n.d), "With the older analog-based cellular telephone systems such as the Advanced Mobile Phone System (AMPS) and the Total Access Communication System (TACS)", cellular fraud is extensive. It's very simple for a radio hobbyist to tune in and hear cellular telephone conversations since without encryption, the voice and user data of the subscriber is sent to the network (Peng, 2000). Margrave (n.d) states that apart from this, cellular fraud can be committed by using complex equipment to receive the Electronic Serial Number so as to clone another mobile phone and place calls with that. To counteract the aforementioned cellular fraud and to make mobile phone traffic secure to a certain extent, GSM (Global System for Mobile communication or Group Special Mobile) is one of the many solutions now out there. According to GSM-tutorials, formed in 1982, GSM is a worldwide accepted standard for digital cellular communication. GSM operates in the 900MHz, 1800MHz, or 1900Mhz frequency bands by "digitizing and compressing data and then sending it down a channel with two other streams of user data, each in its own time slot." GSM provides a secure and confidential method of communication.

Security provided by GSM

The limitation of security in cellular communication is a result of the fact that all cellular communication is sent over the air, which then gives rise to threats from eavesdroppers with suitable receivers. Keeping this in account, security controls were integrated into GSM to make the system as secure as public switched telephone networks. The security functions are:

1. Anonymity: It implies that it is not simple and easy to track the user of the system. According to Srinivas (2001), when a new GSM subscriber switches on his/her phone for the first time, its International Mobile Subscriber Identity (IMSI), i.e. real identity is used and a Temporary Mobile Subscriber Identity (TMSI) is issued to the subscriber, which from that time forward is always used. Use of this TMSI, prevents the recognition of a GSM user by the potential eavesdropper.

2. Authentication: It checks the identity of the holder of the smart card and then decides whether the mobile station is allowed on a particular network. The authentication by the network is done by a response and challenge method. A random 128-bit number (RAND) is generated by the network and sent to the mobile. The mobile uses this RAND as an input and through A3 algorithm using a secret key Ki (128 bits) assigned to that mobile, encrypts the RAND and sends the signed response (SRES-32 bits) back. Network performs the same SRES process and compares its value with the response it has received from the mobile so as to check whether the mobile really has the secret key (Margrave, n.d). Authentication becomes successful when the two values of SRES matches which enables the subscriber to join the network. Since every time a new random number is generated, eavesdroppers don't get any relevant information by listening to the channel. (Srinivas, 2001)

3. User Data and Signalling Protection: Srinivas (2001) states that to protect both user data and signalling, GSM uses a cipher key. After the authentication of the user, the A8 ciphering key generating algorithm (stored in the SIM card) is used. Taking the RAND and Ki as inputs, it results in the ciphering key Kc which is sent through. To encipher or decipher the data, this Kc (54 bits) is used with the A5 ciphering algorithm. This algorithm is contained within the hardware of the mobile phone so as to encrypt and decrypt the data while roaming. Algorithms used to make mobile traffic secure

Authentication Algorithm A3: One way function, A3 is an operator-dependent stream cipher. To compute the output SRES by using A3 is easy but it is very difficult to discover the input (RAND and Ki) from the output. To cover the issue of international roaming, it was mandatory that each operator may choose to use A3 independently. The basis of GSM's security is to keep Ki secret (Srinivas, 2001)

Ciphering Algorithm A5: In recent times, many series of A5 exists but the most common ones are A5/0(unencrypted), A5/1 and A5/2. Because of the export regulations of encryption technologies there is the existence of a series of A5 algorithms (Brookson, 1994).

A8 (Ciphering Key Generating Algorithm): Like A3, it is also operator-dependent. Most providers combine A3 and A8 algorithms into a single hash function known as COMP128. The COMP128 creates KC and SRES, in a single instance (Huynh & Nguyen, 2003).

GSM security flaws

  • Security by obscurity. According to (Li, Chen & Ma) some people asserts that since the GSM algorithms are not publicized so it is not a secure system. "Most security analysts believe any system that is not subject to the scrutiny of the world's best minds can't be as secure." For instance, A5 was never made public, only its description is divulged as part of the GSM specification.
  • Another limitation of GSM is that although all communication between the Mobile station and the Base transceiver station are encrypted, in the fixed network all the communication and signalling is not protected as it is transmitted in plain text most of the time (Li, Chen & Ma).
  • One more problem is that it is hard to upgrade the cryptographic mechanisms timely.
  • Flaws are present within the GSM algorithms. According to Quirke (2004) " A5/2 is a deliberately weakened version of A5/1, since A5/2 can be cracked on the order of about 216".

Security breaches

Time to time, people have tried to decode GSM algorithms. For instance, according to Issac press release (1998) in April 1998, the SDA (Smartcard Developer Association) along with two U.C Berkeley researchers alleged that they have cracked the COMP128 algorithm, which is stored on the SIM. They claimed that within several hours they were able to deduce the Ki by sending immense numbers of challenges to the authorization module. They also said that out of 64 bits, Kc uses only 54 bits with zeros padding out the other 10, which makes the cipher key purposefully weaker. They felt government interference might be the reason behind this, as this would allow them to monitor conversations. However, they were unable to confirm their assertion since it is illegal to use equipment to carry out such an attack in the US. In reply to this assertion, the GSM alliance stated that since the GSM network allows only one call from any phone number at any one time it is of no relevant use even if a SIM could be cloned. GSM has the ability to detect and shut down duplicate SIM codes found on multiple phones (Business press release, 1998).

According to Srinivas (2001), one of the other claims was made by the ISAAC security research group. They asserted that a fake base station could be built for around $10,000, which would allow a "man-in-the-middle" attack. As a result of this, the real base station can get deluged which would compel a mobile station to connect to the fake station. Consequently, the base station could eavesdrop on the conversation by informing the phone to use A5/0, which is without encryption.

One of the other possible scenarios is of insider attack. In the GSM system, communication is encrypted only between the Mobile station and the Base Transceiver station but within the provider's network, all signals are transmitted in plain text, which could give a chance for a hacker to step inside (Li, Chen & Ma).

Measures taken to tackle these flaws

According to Quirke (2004), since the emergence of these, attacks, GSM have been revising its standard to add newer technologies to patch up the possible security holes, e.g. GSM1800, HSCSD, GPRS and EDGE. In the last year, two significant patches have been implemented. Firstly, patches for COMP 128-2 and COMP128-3 hash function have been developed to address the security hole with COMP 128 function. COMP128-3 fixes the issue where the remaining 10 bits of the Session Key (Kc) were replaced by zeroes. Secondly, it has been decided that a new A5/3 algorithm, which is created as part of the 3rd Generation Partnership Project (3GPP) will replace the old and weak A5/2. But this replacement would result in releasing new versions of the software and hardware in order to implement this new algorithm and it requires the co-operation of the hardware and software manufacturers.

GSM is coming out of their "security by obscurity" ideology, which is actually a flaw by making their 3GPP algorithms available to security researchers and scientists (Srinivas, 2001).

Conclusion

To provide security for mobile phone traffic is one the goals described in GSM 02.09 specification, GSM has failed in achieving it in past (Quirke, 2004). Until a certain point GSM did provide strong subscriber authentication and over-the-air transmission encryption but different parts of an operator's network became vulnerable to attacks (Li, Chen, Ma). The reason behind this was the secrecy of designing algorithms and use of weakened algorithms like A5/2 and COMP 128. One of other vulnerability is that of inside attack. In order to achieve its stated goals, GSM is revising its standards and it is bringing in new technologies so as to counteract these security holes. While no human-made technology is perfect, GSM is the most secure, globally accepted, wireless, public standard to date and it can be made more secure by taking appropriate security measures in certain areas.

Bibliography

Business Wire Press release (1998). GSM Alliance Clarifies False & Misleading Reports of Digital Phone Cloning. Retrieved October 26th, 2004 Web site: http://jya.com/gsm042098.txt

Brookson (1994). Gsmdoc Retrieved October 24th, 2004 from gsm Web site: http://www.brookson.com/gsm/gsmdoc.pdf

Chengyuan Peng (2000). GSM and GPRS security. Retrieved October 24th, 2004 from Telecommunications Software and Multimedia Laboratory Helsinki University of Technology Web site: http://www.tml.hut.fi/Opinnot/Tik-110.501/2000/papers/peng.pdf Epoker Retrieved October 27th, 2004 from Department of Mathematics Boise State University, Mathematics 124,Fall 2004 Web site:http://math.boisestate.edu/~marion/teaching/m124f04/epoker.htm Huynh & Nguyen (2003). Overview of GSM and GSM security. Retrieved October 25th, 2004 from Oregon State university, project Web site: http://islab.oregonstate.edu/koc/ece478/project/2003RP/huynh_nguyen_gsm.doc

Li, Chen & Ma (n.d). Security in gsm. Retrieved October 24th, 2004 from gsm-security Web site: http://www.gsm-security.net/papers/securityingsm.pdf

Quirke (2004). Security in the GSM system. Retrieved October 25th, 2004 from Security Website:http://www.ausmobile.com/downloads/technical/Security in the GSM system 01052004.pdf

Margrave (n.d). GSM system and Encryption. Retrieved October 25th, 2004 from gsm-secur Web site: http://www.hackcanada.com/blackcrawl/cell/gsm/gsm-secur/gsm-secur.html

Press release (1998). Smartcard Developer Association Clones Digital GSM 1998). Retrieved October 26th, 2004 from is sac Web site: http://www.isaac.cs.berkeley.edu/isaac/gsm.html

Srinivas (2001). The GSM Standard (An overview of its security) Retrieved October 25th, 2004 from papers Web site:http://www.sans.org/rr/papers/index.php?id=317

Stallings (2003). Cryptography and Network Security: Principles and practices. USA: Prentice Hall.

By Priyanka Agarwal http://M6.net The author is a novice who is trying to create her niche on network of networks.


AddThis Social Bookmark Button

In The News:


TMC Net

Skype makes mobile push
Reuters - 8 hours ago
With an aim to move beyond the desktop computer and the cell phone, Durchslag also said he had begun working with television manufacturers on having Skype ...
Skype Lite for Android and Java phones coming soon TechSpot
Skype thrives amid tough economy CNET News
Free calls from Skype could come soon to iPhones The Associated Press
TG Daily - TechWhackall 142 news articles

T-Mobile slide show
CNET News, CA - 7 hours ago
Sprint may have the Palm Pre, but T-Mobile wasn't a wallflower at CES. The carrier announced five new cell phones that span the range of usability. ...

Canada.com

Motorola's new cell phone lineup includes green effort
Chicago Tribune, United States - Jan 5, 2009
Motorola Inc. will introduce three mobile phones this week at the Consumer Electronics Show in Las Vegas, including the first in a developing line of ...
Motorola unveils mobile phone made from recycled water bottles AFP
Motorola Creates World’s First 100% Recyclable Carbon Neutral Phone eFluxMedia
Motorola Introduces Cellphone Made From Recycled Water Bottles AHN
About - News & Issues - TG Dailyall 289 news articles

SlashPhone

Google Cell Phone Raises HTC Revenues 22%
InformationWeek, NY - Jan 7, 2009
... as the overall cell phone market contracts. HTC said it expects to bring out about 10 new smartphones, most of which will be powered by Windows Mobile. ...
Google picks HTC for first Android phone IT Examiner
all 40 news articles

Chippewa Herald

Broadcasts to mobile devices to start in 22 cities
The Associated Press - 10 hours ago
LG Electronics Inc. of Korea, a major partner in developing the broadcast technology, showed off two prototype cell phones and a portable DVD player. ...
Free Mobile TV Coming To Cell Phones in 2009 RedOrbit
TV stations will broadcast to mobile devices Boston Globe
More on Mobile TV… Television Broadcast
MediaPost Publicationsall 156 news articles

guardian.co.uk

Microsoft: Expect Fewer Phones With Windows
New York Times, United States - 9 hours ago
... the number of devices built with the Windows Mobile operating system. At present, there are around 140 such devices, from a range of cell phone makers, ...
Steve Ballmer's State of Microsoft Keynote at CES 2009 PC World
Microsoft CEO Envisions Converged World Wireless Week
'Our digital lives will only get richer' Globe and Mail
Seattle Post Intelligencer - Scientific Americanall 1,081 news articles

Reuters

Microsoft strikes deals for Live Search
CNET News, CA - Jan 7, 2009
Today mobile search is still in its early days. Only about 9 percent of cell phone subscribers search the Net from their cell phones, according to ComScore ...
Verizon to hire Microsoft to offer Web services for cell phone ... TheNewsTribune.com
Verizon says in mobile search deal with Microsoft Reuters
Verizon: Microsoft beats Google CNN
AHN - TECH.BLORGE.comall 267 news articles

Attorney General Urges Parents To Protect Young Cell Phone Users
FortBendNow, TX - 7 hours ago
... 13 to 19 have mobile devices. As a result, a steadily increasing percentage of children are using cell phones to communicate and access the Internet. ...
AG: Cell phones can endanger children Celina Record
all 6 news articles

iSync update adds more cell phone support
Macworld, CA - 14 hours ago
... synchronization between a number of recently released mobile phones and Mac OS X. iSync lets users synchronize contacts and dates between a cell phone ...

Multi-App Cell Phone Owners Just Want To Make Calls
InformationWeek, NY - Jan 7, 2009
Ross Rubin, who oversaw the NPD "Mobile Phone Usage Report," indicated the study shows there can be opportunity for carriers to promote the sometimes-hidden ...
Almost Half Use Cell Phones Just For Talking MediaPost Publications
Mobile Phone Users Want to Use Their Mobile Phones to Make Calls ... Wireless and Mobile News
all 31 news articles
mobile cell phone - Google News
Your Ad Here

Games at Buy.com

Holiday Home Store at Buy.com

Free Cell Phones All Around - Cashing in on Consumerism

There's no greater way to win the hearts of consumers than to give them something for nothing. In our society of advanced communications devices and state-of-the-art technology,... Read More

Cell Phone Etiquette

CELL PHONE ETIQUETTE Okay, I'll admit I... Read More

Buying A Cell Phone ? Making Smart Choices

Whether you're buying your first cell phone, upgrading to a newer one or contemplating a new cell phone plan, it's a good idea to thoroughly research your... Read More

How Successful Is 3G REALLY In The UK?

How successful is 3G REALLY in the UK? I'm getting mixed messages about 3G take-up in the UK. On one hand, 3 announce that they have added... Read More

Cell phone Etiquette. The Do?s and Don?ts

With more and more people buying cell phones, it becomes more significant to know how to use your cell phone without looking obnoxious. Cell phones play an... Read More

What is SMS?

What is SMS?SMS, also known as short messaging service, is the rage in Europe and parts of Asia. Gradually SMS is gaining momentum in the US as... Read More

Take Care of Your Cell Phone Battery. Your Life May Depend on It

You probably don't even think about it but do you know that your cell phone battery is the most important part of your wireless phone. Without the... Read More

Location Sensitivity - Cell Phone GPS

This is basically a system to locate the handheld when making a call to 911. In the mid to late 1990's, many people got cell phones just... Read More

Cheap Long Distance or is It Really? The Search Continues...

Each month, there are countless Americans who are faced with phone bills that they simply cannot afford. In many cases, they are paying fees that they were... Read More

Cellular Phone

Technology advances in cellular phone field.Cellular phone shoppers can find many excellent cellular phones in the USA at the current moment. Cellular phone companies produce phones that... Read More

Analog vs. Digital Cellular Phones

Cellular phones are an amazing modern convenience, but it can be confusing for consumers to distinguish between the various options available. There are two main types of... Read More

Instant Messaging through Mobile Phones

Instant Messengers are very popular on PCs, with the advancement of mobile technology it has become possible to connect to MSN, Yahoo!, ICQ and other instant messenger... Read More

Lets Talk

In the eyes of a teenage girl cellular phones are the best invention since boys. My daughter has had a cell phone for awhile now but it... Read More

Cell Phone Dos and Donts For Teens!

There are certain things people just shouldn't do with cell phones! Like talking in the grocery store line while trying to pay for your groceries, talking in... Read More

Do Cellular Phones Pose Health Risks?

You hear it in the media on a slow news day. Do cellular phones pose health risks? The available scientific reports do not show that any health... Read More

Phone Fraud

Please be aware of this, as I have had these calls from the switch board ? if you receive one hang up IMMEDITELY!Phone Fraud ? Warning from... Read More

Camera Cell Phones - Say It With Pictures!

Camera cell phones are sweeping the nation! In fact, long gone are the days when a telephone is used for the sole purpose of speaking to another... Read More

Review of Bluetooth Wireless Headsets

Bluetooth headsets make up one of the fastest wireless markets here in the US and around the world. Headsets with Bluetooth wireless technology are capable of working... Read More

SMS Daycare & Gaming

Using the Physical World as a Game Board. This is not Kinky Day Care! SMS stands for Short Message Service. If your children... Read More

What SMS Users Are Telling Telcos

The recent rollout of 3G-ready mobile devices has caused a lot of excitement in the Telco industry, especially in the Asia-Pacific region. This article will highlight the... Read More

Call Mexico at Rates as Amazing as the Murals

It's a country that speaks through its numerous murals and is vibrantly creative and colorful in their representation of the ancient Mayan and Teotihuacán history. It's little... Read More

Helping You Choose From Cell or Land Line

Most of us have two phones, our cell and our land line (house phone). Realistically many people are paying two bills when one is sufficient. The cell... Read More

Cell Phone Abuse - Tips to Curb Employee Abuse

Looking for a way to save your enterprise or government organization tens of thousands of dollars a month or more on wireless mobile communication use? First off,... Read More

Cell Phone - Why Should I Upgrade

We hear from friends or just general chat by people wanting to upgrade their cell phones. There are a number of very good reasons to upgrade but... Read More

Cellular Phone Service

Cellular phone service ? pick the one you like.You can select the cellular phone service of your choice from one of the many cellular phone companies like... Read More

Mobile Phone Radiation - The Facts & How You Can Protect Yourself With This Simple Technique!

Firstly, it's vital to point out that this short report is NOT one of my many tips or secrets related to saving an absolute fortune on your... Read More