{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,16]],"date-time":"2025-09-16T17:38:27Z","timestamp":1758044307237,"version":"3.44.0"},"reference-count":22,"publisher":"Association for Computing Machinery (ACM)","issue":"5","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62472439, 61602514, 62202493, 61802437, and 61902428"],"award-info":[{"award-number":["62472439, 61602514, 62202493, 61802437, and 61902428"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2025,9,30]]},"abstract":"<jats:p>GEA-1 and its successor GEA-2 are stream ciphers that were selected as the General Packet Radio Service (GPRS) standard encryption algorithms, used to protect the communication between phones and base stations from eavesdropping. These stream ciphers, once widely used for GPRS encryption in the late 1990s and early 2000s, are surprisingly still supported in many current mobile phones and in numerous developing regions even today. GEA-2a is a more secure, improved version of GEA-2 designed by Ding et\u00a0al. in 2022. Side channel attack utilizes easily accessible information from cryptographic devices, such as power consumption, electromagnetic radiation, and runtime, to obtain secret information in the cryptographic systems. Side channel attack is a powerful attack method that has been successfully applied in many stream ciphers, such as TRIVIUM and GRAIN-128-AEAD. In this article, we put forward an automated framework that can mount side channel attack on stream ciphers with structures similar to the GPRS standard encryption algorithms GEA-1 and GEA-2. We use satisfiability modulo theory for modeling, while considering the software and hardware implementation of the algorithms, and use Microsoft\u2019s open source solver Z3 to solve the constructed instances. The experimental results indicate that the internal states of GEA-1, GEA-2, and GEA-2a in the keystream generation phase can be recovered practically under the HW\/32 model. For models where the solution time is too long, by guessing a small number of bits, the state bits can be fully recovered within an acceptable time. Our automated framework is effective in both noiseless and noisy trace scenarios.<\/jats:p>","DOI":"10.1145\/3716385","type":"journal-article","created":{"date-parts":[[2025,2,10]],"date-time":"2025-02-10T11:03:32Z","timestamp":1739185412000},"page":"1-16","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Side Channel Attacks on GPRS Standard Encryption Algorithms"],"prefix":"10.1145","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2676-7512","authenticated-orcid":false,"given":"Zheng","family":"Wu","sequence":"first","affiliation":[{"name":"Information Engineering University","place":["Zhengzhou, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1482-1750","authenticated-orcid":false,"given":"Lin","family":"Ding","sequence":"additional","affiliation":[{"name":"Information Engineering University","place":["Zhengzhou, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-4302-7035","authenticated-orcid":false,"given":"Zhengting","family":"Li","sequence":"additional","affiliation":[{"name":"Information Engineering University","place":["Zhengzhou, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-9129-0446","authenticated-orcid":false,"given":"Xinhai","family":"Wang","sequence":"additional","affiliation":[{"name":"Information Engineering University","place":["Zhengzhou, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-1600-3835","authenticated-orcid":false,"given":"Ziyu","family":"Guan","sequence":"additional","affiliation":[{"name":"Information Engineering University","place":["Zhengzhou, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,9,12]]},"reference":[{"key":"e_1_3_2_2_2","first-page":"57","volume-title":"Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques","author":"Amzaleg Dor","year":"2022","unstructured":"Dor Amzaleg and Itai Dinur. 2022. Refined cryptanalysis of the GPRS ciphers GEA-1 and GEA-2. In Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques. 57\u201385."},{"issue":"10","key":"e_1_3_2_3_2","doi-asserted-by":"crossref","first-page":"2527","DOI":"10.1109\/TC.2021.3135191","article-title":"A new approach for side channel analysis on stream ciphers and related constructions","volume":"71","author":"Baksi Anubhab","year":"2021","unstructured":"Anubhab Baksi, Satyam Kumar, and Santanu Sarkar. 2021. A new approach for side channel analysis on stream ciphers and related constructions. IEEE Transactions on Computers 71, 10 (2021), 2527\u20132537.","journal-title":"IEEE Transactions on Computers"},{"key":"e_1_3_2_4_2","first-page":"155","volume-title":"Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques","author":"Beierle Christof","year":"2021","unstructured":"Christof Beierle, Patrick Derbez, Gregor Leander, Ga\u00ebtan Leurent, H\u00e5vard Raddum, Yann Rotella, David Rupprecht, and Lukas Stennes. 2021. Cryptanalysis of the GPRS encryption algorithms GEA-1 and GEA-2. In Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques. 155\u2013183."},{"key":"e_1_3_2_5_2","doi-asserted-by":"crossref","first-page":"513","DOI":"10.1007\/BFb0052259","volume-title":"Advances in Cryptology CRYPTO\u201997","author":"Biham Eli","year":"1997","unstructured":"Eli Biham and Adi Shamir. 1997. Differential fault analysis of secret key cryptosystems. In Advances in Cryptology CRYPTO\u201997. Lecture Notes in Computer Science, Vol. 1294. Springer, 513\u2013525."},{"key":"e_1_3_2_6_2","article-title":"Combined side-channel and fault analysis attack on protected grain family of stream ciphers","author":"Chakraborty Abhishek","year":"2015","unstructured":"Abhishek Chakraborty, Bodhisatwa Mazumdar, and Debdeep Mukhopadhay. 2015. Combined side-channel and fault analysis attack on protected grain family of stream ciphers. Cryptology ePrint Archive.","journal-title":"Cryptology ePrint Archive."},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3197064"},{"key":"e_1_3_2_8_2","first-page":"16","volume-title":"Cryptographic Hardware and Embedded Systems\u2014CHES 2004","year":"2004","unstructured":"Eric Brier, Christophe Clavier, and Francis Olivier. 2004. Correlation power analysis with a leakage model. In Cryptographic Hardware and Embedded Systems\u2014CHES 2004. Lecture Notes in Computer Science, Vol. 3156. Springer, 16\u201329."},{"key":"e_1_3_2_9_2","doi-asserted-by":"crossref","first-page":"257","DOI":"10.1007\/11967668_17","volume-title":"Topics in Cryptology\u2014CT-RSA 2007","author":"Fischer Wieland","year":"2006","unstructured":"Wieland Fischer, Berndt M Gammel, Oliver Kniffler, and Joachim Velten. 2006. Differential power analysis of stream ciphers. In Topics in Cryptology\u2014CT-RSA 2007. Lecture Notes in Computer Science, Vol. 4377. Springer, 257\u2013270."},{"key":"e_1_3_2_10_2","unstructured":"Benedikt Gierlichs Lejla Batina Christophe Clavier Thomas Eisenbarth Aline Gouget Helena Handschuh Timo Kasper Kerstin Lemke-Rust Stefan Mangard Amir Moradi et\u00a0al. 2008. Susceptibility of eSTREAM candidates towards side channel analysis. In Proceedings of the Workshop on the State of the Art of Stream Ciphers."},{"key":"e_1_3_2_11_2","doi-asserted-by":"crossref","first-page":"198","DOI":"10.1007\/3-540-36400-5_16","volume-title":"Cryptographic Hardware and Embedded Systems\u2014CHES 2002","author":"Goli\u0107 Jovan D","year":"2003","unstructured":"Jovan D Goli\u0107 and Christophe Tymen. 2003. Multiplicative masking and power analysis of AES. In Cryptographic Hardware and Embedded Systems\u2014CHES 2002. Lecture Notes in Computer Science, Vol. 2523. Springer, 198\u2013212."},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2766234"},{"key":"e_1_3_2_13_2","doi-asserted-by":"crossref","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","volume-title":"Advances in Cryptology\u2014CRYPTO 1999","author":"Kocher Paul","year":"1999","unstructured":"Paul Kocher, Joshua Jaffe, and Benjamin Jun. 1999. Differential power analysis. In Advances in Cryptology\u2014CRYPTO 1999. Lecture Notes in Computer Science, Vol. 1666. Springer, 388\u2013397."},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.5555\/646761.706156"},{"key":"e_1_3_2_15_2","volume-title":"Power Analysis Attacks: Revealing the Secrets of Smart Cards","author":"Mangard Stefan","year":"2008","unstructured":"Stefan Mangard, Elisabeth Oswald, and Thomas Popp. 2008. Power Analysis Attacks: Revealing the Secrets of Smart Cards. Vol. 31. Springer Science & Business Media."},{"issue":"2","key":"e_1_3_2_16_2","first-page":"1","article-title":"Power side-channel attack analysis: A review of 20 years of study for the layman","volume":"4","year":"2020","unstructured":"Mark Randolph and William Diehl. 2020. Power side-channel attack analysis: A review of 20 years of study for the layman. Cryptography 4, 2 (2020), 1\u201333.","journal-title":"Cryptography"},{"key":"e_1_3_2_17_2","first-page":"238","volume-title":"Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems","author":"Messerges Thomas S.","year":"2000","unstructured":"Thomas S. Messerges. 2000. Using second-order power analysis to attack DPA resistant software. In Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems. 238\u2013251."},{"key":"e_1_3_2_18_2","doi-asserted-by":"crossref","unstructured":"Eric Peeters. 2013. Side-channel Cryptanalysis: A brief survey. In Advanced DPA Theory and Practice. Springer 11\u201319.","DOI":"10.1007\/978-1-4614-6783-0_2"},{"key":"e_1_3_2_19_2","first-page":"172","volume-title":"Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems","author":"Popp Thomas","year":"2005","unstructured":"Thomas Popp and Stefan Mangard. 2005. Masked dual-rail pre-charge logic: DPA-resistance without routing constraints. In Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems. 172\u2013186."},{"key":"e_1_3_2_20_2","article-title":"DAPA: Differential analysis aided power attack on (non-)linear feedback shift registers (extended version)","author":"Sim Siang Meng","year":"2020","unstructured":"Siang Meng Sim, Dirmanto Jap, and Shivam Bhasin. 2020. DAPA: Differential analysis aided power attack on (non-)linear feedback shift registers (extended version). Cryptology ePrint Archive.","journal-title":"Cryptology ePrint Archive."},{"key":"e_1_3_2_21_2","unstructured":"Daehyun Strobel Ing Christof Paar and M. Kasper. 2004. Side channel analysis attacks on stream ciphers. Master\u2019s Thesis. Ruhr-Universitat Bochum."},{"key":"e_1_3_2_22_2","first-page":"186","volume-title":"Information Security Practice and Experience","author":"Wu Zheng","year":"2024","unstructured":"Zheng Wu, Lin Ding, Zhengting Li, and Xinhai Wang. 2024. Breaking GEA-like stream ciphers with lower time cost. In Information Security Practice and Experience. Lecture Notes in Computer Science, Vol. 15053. Springer, 186\u2013204."},{"issue":"1","key":"e_1_3_2_23_2","doi-asserted-by":"crossref","first-page":"6674019","DOI":"10.1049\/2024\/6674019","article-title":"New practical attacks on GEA-1 based on a new-found weakness","volume":"2024","author":"Wu Zheng","year":"2024","unstructured":"Zheng Wu, Lin Ding, Zhengting Li, Xinhai Wang, and Ziyu Guan. 2024. New practical attacks on GEA-1 based on a new-found weakness. IET Information Security 2024, 1 (2024), 6674019.","journal-title":"IET Information Security"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3716385","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,12]],"date-time":"2025-09-12T11:44:10Z","timestamp":1757677450000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3716385"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,12]]},"references-count":22,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,9,30]]}},"alternative-id":["10.1145\/3716385"],"URL":"https:\/\/doi.org\/10.1145\/3716385","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2025,9,12]]},"assertion":[{"value":"2024-02-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-01-22","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}