New Security Proofs for the 3GPP Confidentiality and Integrity Algorithms [chapter]

Tetsu Iwata, Tadayoshi Kohno
<span title="">2004</span> <i title="Springer Berlin Heidelberg"> <a target="_blank" rel="noopener" href="" style="color: black;">Lecture Notes in Computer Science</a> </i> &nbsp;
This paper analyses the 3GPP confidentiality and integrity schemes adopted by Universal Mobile Telecommunication System, an emerging standard for third generation wireless communications. The schemes, known as f 8 and f 9, are based on the block cipher KASUMI. Although previous works claim security proofs for f 8 and f 9 , where f 9 is a generalized versions of f 9, it was recently shown that these proofs are incorrect. Moreover, Iwata and Kurosawa (2003) showed that it is impossible to prove f
more &raquo; ... 8 and f 9 secure under the standard PRP assumption on the underlying block cipher. We address this issue here, showing that it is possible to prove f 8 and f 9 secure if we make the assumption that the underlying block cipher is a secure PRP-RKA against a certain class of related-key attacks; here f 8 is a generalized version of f 8. Our results clarify the assumptions necessary in order for f 8 and f 9 to be secure and, since no related-key attacks are known against the full eight rounds of KASUMI, lead us to believe that the confidentiality and integrity mechanisms used in real 3GPP applications are secure.
<span class="external-identifiers"> <a target="_blank" rel="external noopener noreferrer" href="">doi:10.1007/978-3-540-25937-4_27</a> <a target="_blank" rel="external noopener" href="">fatcat:irhogdu47fgglkhbu5yox3o6ya</a> </span>
