Side Channel Attacks on GPRS Standard Encryption Algorithms

Zheng Wu, Lin Ding, Zhengting Li, Xinhai Wang, Ziyu Guan · ACM Transactions on Embedded Computing Systems · 2025

GEA-1 and its successor GEA-2 are stream ciphers that were selected as the General Packet Radio Service (GPRS) standard encryption algorithms, used to protect the communication between phones and base stations from eavesdropping. These stream ciphers, once widely used for GPRS encryption in the late 1990s and early 2000s, are surprisingly still supported in many current mobile phones and in numerous developing regions even today. GEA-2a is a more secure, improved version of GEA-2 designed by Ding et al. in 2022. Side channel attack utilizes easily accessible information from cryptographic devices, such as power consumption, electromagnetic radiation, and runtime, to obtain secret information in the cryptographic systems. Side channel attack is a powerful attack method that has been successfully applied in many stream ciphers, such as TRIVIUM and GRAIN-128-AEAD. In this article, we put forward an automated framework that can mount side channel attack on stream ciphers with structures similar to the GPRS standard encryption algorithms GEA-1 and GEA-2. We use satisfiability modulo theory for modeling, while considering the software and hardware implementation of the algorithms, and use Microsoft’s open source solver Z3 to solve the constructed instances. The experimental results indicate that the internal states of GEA-1, GEA-2, and GEA-2a in the keystream generation phase can be recovered practically under the HW/32 model. For models where the solution time is too long, by guessing a small number of bits, the state bits can be fully recovered within an acceptable time. Our automated framework is effective in both noiseless and noisy trace scenarios.

Read the paper · More papers on PaperTik