Differential Fault Attack on KASUMI Cipher Used in GSM Telephony

Zongyue Wang, Xiaoyang Dong, Keting Jia, Jingyuan Zhao · Mathematical Problems in Engineering · 2014

The confidentiality of GSM cellular telephony depends on the security of A5 family of cryptosystems. As an algorithm in this family survived from cryptanalysis, A5/3 is based on the block cipher KASUMI. This paper describes a novel differential fault attack on KAUSMI with a 64‐bit key. Taking advantage of some mathematical observations on the FL, FO functions, and key schedule, only one 16‐bit word fault is required to recover all information of the 64‐bit key. The time complexity is only 232 encryptions. We have practically simulated the attack on a PC which takes only a few minutes to recover all the key bits. The simulation also experimentally verifies the correctness and complexity.

Read the paper · More papers on PaperTik