A5/1 is in the Air: Passive Detection of 2G (GSM) Ciphering Algorithms

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Koch, Matthias, Nettersheim, Christian, Horstmann, Thorsten, Rademacher, Michael
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910957699072000
author Koch, Matthias
Nettersheim, Christian
Horstmann, Thorsten
Rademacher, Michael
author_facet Koch, Matthias
Nettersheim, Christian
Horstmann, Thorsten
Rademacher, Michael
contents This paper investigates the ongoing use of the A5/1 ciphering algorithm within 2G GSM networks. Despite its known vulnerabilities and the gradual phasing out of GSM technology by some operators, GSM security remains relevant due to potential downgrade attacks from 4G/5G networks and its use in IoT applications. We present a comprehensive overview of a historical weakness associated with the A5 family of cryptographic algorithms. Building on this, our main contribution is the design of a measurement approach using low-cost, off-the-shelf hardware to passively monitor Cipher Mode Command messages transmitted by base transceiver stations (BTS). We collected over 500,000 samples at 10 different locations, focusing on the three largest mobile network operators in Germany. Our findings reveal significant variations in algorithm usage among these providers. One operator favors A5/3, while another surprisingly retains a high reliance on the compromised A5/1. The third provider shows a marked preference for A5/3 and A5/4, indicating a shift towards more secure ciphering algorithms in GSM networks.
format Preprint
id arxiv_https___arxiv_org_abs_2505_14509
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A5/1 is in the Air: Passive Detection of 2G (GSM) Ciphering Algorithms
Koch, Matthias
Nettersheim, Christian
Horstmann, Thorsten
Rademacher, Michael
Networking and Internet Architecture
This paper investigates the ongoing use of the A5/1 ciphering algorithm within 2G GSM networks. Despite its known vulnerabilities and the gradual phasing out of GSM technology by some operators, GSM security remains relevant due to potential downgrade attacks from 4G/5G networks and its use in IoT applications. We present a comprehensive overview of a historical weakness associated with the A5 family of cryptographic algorithms. Building on this, our main contribution is the design of a measurement approach using low-cost, off-the-shelf hardware to passively monitor Cipher Mode Command messages transmitted by base transceiver stations (BTS). We collected over 500,000 samples at 10 different locations, focusing on the three largest mobile network operators in Germany. Our findings reveal significant variations in algorithm usage among these providers. One operator favors A5/3, while another surprisingly retains a high reliance on the compromised A5/1. The third provider shows a marked preference for A5/3 and A5/4, indicating a shift towards more secure ciphering algorithms in GSM networks.
title A5/1 is in the Air: Passive Detection of 2G (GSM) Ciphering Algorithms
topic Networking and Internet Architecture
url https://arxiv.org/abs/2505.14509