GEA-1 and GEA-2 are two proprietary stream ciphers used in GPRS (General Packet Radio Service) to protect GPRS from eavesdropping. GEA-2a is an improved version of GEA-2 proposed recently. In this paper, new weaknesses of GEA-like stream ciphers (i.e., GEA-1, GEA-2 and GEA-2a) are discovered and analyzed. As the technical contribution, an automatic algorithm is proposed to search for differential paths of full GEA-like stream ciphers. By this automatic algorithm, the differential paths of full GEA-1, GEA-2 and GEA-2a are found, whose probabilities are up to \(2^{-22.90}\) , \(2^{-19.60}\) and \(2^{-18.60}\) respectively. Based on these found differential paths, practical distinguishing attacks and key recovery attacks on GEA-like stream ciphers in the chosen IV setting are presented. All these attacks have been confirmed by experimental results on a common PC. The cryptanalytic results show that the initializations of all GEA-like stream ciphers are far from being optimal and need to be strengthened.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Breaking GEA-Like Stream Ciphers with Lower Time Cost

  • Zheng Wu,
  • Lin Ding,
  • Zhengting Li,
  • Xinhai Wang

摘要

GEA-1 and GEA-2 are two proprietary stream ciphers used in GPRS (General Packet Radio Service) to protect GPRS from eavesdropping. GEA-2a is an improved version of GEA-2 proposed recently. In this paper, new weaknesses of GEA-like stream ciphers (i.e., GEA-1, GEA-2 and GEA-2a) are discovered and analyzed. As the technical contribution, an automatic algorithm is proposed to search for differential paths of full GEA-like stream ciphers. By this automatic algorithm, the differential paths of full GEA-1, GEA-2 and GEA-2a are found, whose probabilities are up to \(2^{-22.90}\) , \(2^{-19.60}\) and \(2^{-18.60}\) respectively. Based on these found differential paths, practical distinguishing attacks and key recovery attacks on GEA-like stream ciphers in the chosen IV setting are presented. All these attacks have been confirmed by experimental results on a common PC. The cryptanalytic results show that the initializations of all GEA-like stream ciphers are far from being optimal and need to be strengthened.