4 ms·
GSM is the first (civilian) cellular system to have any encryption at all. The fact that all the primitives are broken comes from the fact that all of them are
by dfox 2y ago
GSM is the first (civilian) cellular system to have any encryption at all. The fact that all the primitives are broken comes from the fact that all of them are custom and optimized for hardware implementation on for the time very resource constrained device, also the design predates the open cryptology research community and thus there were not many existing primitives that could just be used unchanged (one can imagine specifying something derived from DES as A3 and A8, but that is moot as the Comp128 in the spec is only an recommendation and these can be freely chosen by the network, I believe most current SIMs use somewhat convoluted algorithm based on AES and SHA256 as that is what is used for EPS-AKA procedure in LTE). As for the authentication being unilateral, nobody probably expected that to be a problem. And the weird way how the A5 stream cipher is used to encrypt the radio frames (which do not have cryptographic authentication, except the fact that what gets encrypted are FEC symbols, not the raw data) shows that the designers were somewhat familiar with military encryption systems, which often have similar availability-vs-authenticity tradeoff.
And well, given the track record of AES, we can probably consider AES secure for foreseeable future. And for many other modern symmetric algorithms (Salsa/ChaCha, Keccak…) one can produce quite believable arguments that they are as secure as AES.