1、 ETSI TS 1Universal Mobile TelSpecification ointeDocument 3(3GPP TS 35.2TECHNICAL SPECIFICATION135 203 V13.0.0 (2016elecommunications System (LTE; 3G Security; of the 3GPP confidentiality anntegrity algorithms; t 3: Implementors test data .203 version 13.0.0 Release 1316-01) (UMTS); and 13) ETSI ETS
2、I TS 135 203 V13.0.0 (2016-01)13GPP TS 35.203 version 13.0.0 Release 13Reference RTS/TSGS-0335203vd00 Keywords LTE,SECURITY,UMTS ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but no
3、n lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any electronic and/or print versions of
4、 the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (PDF) version kept on a specific n
5、etwork drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in th
6、e present document, please send your comment to one of the following services: https:/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm except as au
7、thorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2016. All rights reserved. DECTTM,
8、PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Assoc
9、iation. ETSI ETSI TS 135 203 V13.0.0 (2016-01)23GPP TS 35.203 version 13.0.0 Release 13Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ET
10、SI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server (https:/i
11、pr.etsi.org/). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential
12、 to the present document. Foreword This Technical Specification (TS) has been produced by ETSI 3rd Generation Partnership Project (3GPP). The present document may refer to technical specifications or reports using their 3GPP identities, UMTS identities or GSM identities. These should be interpreted
13、as being references to the corresponding ETSI deliverables. The cross reference between GSM, UMTS, 3GPP and ETSI identities can be found under http:/webapp.etsi.org/key/queryform.asp. Modal verbs terminology In the present document “shall“, “shall not“, “should“, “should not“, “may“, “need not“, “wi
14、ll“, “will not“, “can“ and “cannot“ are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. ETSI ETSI TS 135 203 V13.0.0 (2016-01)33GPP
15、 TS 35.203 version 13.0.0 Release 13Contents Intellectual Property Rights 2g3Foreword . 2g3Modal verbs terminology 2g3Foreword . 4g3Introduction 4g30 Scope 5g31 Outline of the implementors test data 5g31.1 References 5g32 Introductory information 6g32.1 Introduction 6g32.2 Radix 6g32.3 Bit/Byte orde
16、ring 6g32.4 Presentation of input/output data 6g33 KASUMI 6g33.1 Overview 6g33.2 Format 6g33.3 Test Set 1 7g33.4 Test Set 2 9g33.5 Test Set 3 10g33.6 Test Set 4 12g34 Confidentiality algorithm f8 . 12g34.1 Overview 12g34.2 Format 12g34.3 Test Set 1 13g34.4 Test Set 2 13g34.5 Test Set 3 14g34.6 Test
17、Set 4 14g34.7 Test Set 5 15g35 Integrity algorithm f9 15g35.1 Overview 15g35.2 Format 15g35.3 Test Set 1 16g35.4 Test Set 2 16g35.5 Test Set 3 16g35.6 Test Set 4 17g35.7 Test Set 5 17g3Annex A (informative): Change history . 18g3History 19g3ETSI ETSI TS 135 203 V13.0.0 (2016-01)43GPP TS 35.203 versi
18、on 13.0.0 Release 13Foreword This Technical Specification has been produced by the 3rdGeneration Partnership Project (3GPP). The 3GPP Confidentiality and Integrity Algorithms f8 2 presented to TSG for approval; 3 or greater indicates TSG approved document under change control. y the second digit is
19、incremented for all changes of substance, i.e. technical enhancements, corrections, updates, etc. z the third digit is incremented when editorial only changes have been incorporated in the document. Introduction This specification has been prepared by the 3GPP Task Force, and gives detailed test dat
20、a for implementors of the algorithm set. It provides visibility of the internal state of the algorithm to aid in the realisation of the algorithms. This document is the third of four, which between them form the entire specification of the 3GPP Confidentiality and Integrity Algorithms: - 3GPP TS 35.
21、201: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 1: f8 and f9 Specification“. - 3GPP TS 35.202: “3rd Generation Partnership Project; Technical Specification G
22、roup Services and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 2: KASUMI Specification“. - 3GPP TS 35.203: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Specification of the 3G
23、PP Confidentiality and Integrity Algorithms; Document 3: Implementors Test Data“. - 3GPP TS 35.204: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 4: Design Conf
24、ormance Test Data“. This document is purely informative. The normative part of the specification of the f8 (confidentiality) and the f9 (integrity) algorithms is in the main body of Document 1. The normative part of the specification of KASUMI is found in document 2. ETSI ETSI TS 135 203 V13.0.0 (20
25、16-01)53GPP TS 35.203 version 13.0.0 Release 130 Scope This specification gives detailed test data for implementors of the algorithm set. It provides visibility of the internal state of the algorithm to aid in the realisation of the algorithms. 1 Outline of the implementors test data Section 2 intro
26、duces the algorithms and describes the notation used in the subsequent sections. Section 3 provides test data for KASUMI. Section 4 provides test data for the Confidentiality Algorithm F8. Section 5 provides test data for the Integrity Algorithm F9. 1.1 References The following documents contain pro
27、visions which, through reference in this text, constitute provisions of the present document. References are either specific (identified by date of publication, edition number, version number, etc.) or non-specific. For a specific reference, subsequent revisions do not apply. For a non-specific refe
28、rence, the latest version applies. In the case of a reference to a 3GPP document (including a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same Release as the present document. 1 3GPP TS 33.102 version 3.2.0: “3rd Generation Partnership Proj
29、ect; Technical Specification Group Services and System Aspects; 3G Security; Security Architecture“. 2 3GPP TS 33.105 version 3.1.0: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Cryptographic Algorithm Requirements“. 3 3GPP TS 35.201: “
30、3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 1: f8 and f9 Specification“. 4 3GPP TS 35.202: “3rd Generation Partnership Project; Technical Specification Group S
31、ervices and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 2: KASUMI Specification“. 5 3GPP TS 35.203: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Specification of the 3GPP Con
32、fidentiality and Integrity Algorithms; Document 3: Implementors Test Data“. 6 3GPP TS 35.204: “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3G Security; Specification of the 3GPP Confidentiality and Integrity Algorithms; Document 4: Design Conformanc
33、e Test Data“. 7 ISO/IEC 9797-1:1999: “Information technology Security techniques Message Authentication Codes (MACs)“. ETSI ETSI TS 135 203 V13.0.0 (2016-01)63GPP TS 35.203 version 13.0.0 Release 132 Introductory information 2.1 Introduction Within the security architecture of the 3GPP system there
34、are two standardised algorithms; a confidentiality algorithm f8, and an integrity algorithm f9. These algorithms are specified in a companion document 3. Each of these algorithms is based on the KASUMI algorithm that is specified in 4. To assist implementors with their realisation of the algorithm s
35、et this document provides test data for these algorithms along with extensive detail of the internal states of the algorithms as they process the given input data. Final testing of the algorithms should be performed using the test data sets given in the “Design Conformance“ companion document 6. 2.2
36、 Radix Unless stated otherwise, all test data values presented in this document are in hexadecimal. 2.3 Bit/Byte ordering All data variables in this specification are presented with the most significant bit (or byte) on the left hand side and the least significant bit (or byte) on the right hand sid
37、e. Where a variable is broken down into a number of sub-strings, the left most (most significant) sub-string is numbered 1, the next most significant is numbered 2 and so on through to the least significant. For example the 128-kit key K is subdivided into eight 16-bit substrings K1.K8 so if we have
38、 a key K = 0123456789ABCDEFFEDCBA9876543210 we have: K1 = 0123, K2 = 5678, K3 = 9ABC, K8 = 3210. 2.4 Presentation of input/output data The basic data processed by the f8 and f9 algorithms are bit streams. In general in this document the data is presented in hexadecimal format as bytes, thus the last
39、 byte shown as part of an input or output data stream may include between 0 and 7 bits that are ignored once the LENGTH parameter is taken into account. (The least significant bits of the byte are ignored). 3 KASUMI 3.1 Overview The test data sets presented here are for the KASUMI block cipher algor
40、ithm. 3.2 Format Each test set starts by showing the input and output data values. This is followed by a table showing the internal sub-keys that are derived from the 128-bit key. For each round the inputs and outputs are shown for the FL, FO and FI functions in the form: ETSI ETSI TS 135 203 V13.0.
41、0 (2016-01)73GPP TS 35.203 version 13.0.0 Release 13Round i FLi( input, KL1i, KL2i )-output FOi( input )-output FIi1( input, KIi1 ) - output FIi2( input, KIi2 ) - output FIi3( input, KIi3 ) - output In addition, for the first two rounds, the internal states of the 7-bit and 9-bit data paths within t
42、he FI function are shown in the form: seven 17- 0C- 47- 72- 6C- 21 nine 19E-05C-04B-1BB-1BF-1CD where the first value shown is the value derived from the 16-bit input, and the subsequent values are the changes that occur as the data passes through the function down the respective 7-bit or 9-bit data
43、 paths. i.e. The values shown following the input value are: result of S-box lookup, XOR with other half, XOR with key, S-box lookup, XOR with other half. 3.3 Test Set 1 Key: 2B D6 45 9F 82 C5 B3 00 95 2C 49 10 48 81 FF 48 input: EA 02 47 14 AD 5C 4D 84 output: DF 1F 9B 25 1C 0B F4 5F Key schedule:
44、1 2 3 4 5 6 7 8 KLi1 57AC 8B3E 058B 6601 2A59 9220 9102 FE91 KLi2 0B6E 7EEF 6BF0 F388 3ED5 CD58 2AF5 00F8 KOi1 B3E8 58B0 6016 A592 2209 1029 E91F 7AC5 KOi2 1049 8148 48FF D62B 9F45 C582 00B3 2C95 KOi3 2910 1FE9 C57A E8B3 B058 1660 92A5 0922 KIi1 6BF0 F388 3ED5 CD58 2AF5 00F8 0B6E 7EEF KIi2 7EEF 6BF0
45、 F388 3ED5 CD58 2AF5 00F8 0B6E KIi3 CD58 2AF5 00F8 0B6E 7EEF 6BF0 F388 3ED5 Input: EA024714 AD5C4D84 Round 1 FL1(EA024714,57AC,0B6E)-7CFFC314 FO1(7CFFC314)-58871737 FI11(CF17,6BF0)-43CD seven 17- 0C- 47- 72- 6C- 21 nine 19E-05C-04B-1BB-1BF-1CD FI12(D35D,7EEF)-D85E seven 5D- 61- 3E- 01- 32- 6C nine 1
46、A6-082-0DF-030-05F-05E FI13(A9C9,CD58)-4FB0 seven 49- 63- 52- 34- 17- 27 nine 153-1F8-1B1-0E9-184-1B0 Round 2 FO2(F5DB5AB3)-03E715B9 FI21(AD6B,F388)-E2FC seven 6B- 31- 4F- 36- 0D- 71 nine 15A-015-07E-1F6-0CA-0FC FI22(DBFB,6BF0)-BBA8 seven 7B- 29- 75- 40- 75- 5D nine 1B7-127-15C-0AC-1E8-1A8 FI23(A7A6
47、,2AF5)-165E seven 26- 3A- 73- 66- 55- 0B nine 14F-06F-049-0BC-038-05E FL2(03E715B9,8B3E,7EEF)-FC1913F5 Round 3 FL3(161B54E1,058B,6BF0)-E9F55CF7 ETSI ETSI TS 135 203 V13.0.0 (2016-01)83GPP TS 35.203 version 13.0.0 Release 13FO3(E9F55CF7)-F9C9DB3F FI31(89E3,3ED5)-4C63 seven 63- 2D- 54- 4B- 45- 26 nine
48、 113-19A-1F9-12C-028-063 FI32(1408,F388)-E95D seven 08- 26- 02- 7B- 29- 74 nine 028-02C-024-1AC-126-15D FI33(D5EE,00F8)-22F6 seven 6E- 73- 5B- 5B- 67- 11 nine 1AB-046-028-0D0-0AD-0F6 Round 4 FO4(0C12818C)-F9C83A1A FI41(A980,CD58)-4D43 seven 00- 36- 4E- 28- 65- 26 nine 153-1F8-1F8-0A0-16B-143 FI42(57
49、A7,3ED5)-3507 seven 27- 30- 72- 6D- 1D- 1A nine 0AF-0E5-0C2-017-16A-107 FI43(247C,0B6E)-C3D2 seven 7C- 58- 54- 51- 33- 61 nine 048-0F0-08C-1E2-183-1D2 FL4(F9C83A1A,6601,F388)-0EFDFA1A Round 5 FL5(18E6AEFB,2A59,3ED5)-6519BE7B FO5(6519BE7B)-D1FAD9E0 FI51(4710,2AF5)-781A seven 10- 37- 1D- 08- 26- 3C nine 08E-1BA-1AA-15F-012-01A FI52(213E,CD58)-179B seven 3E- 69- 5C- 3A- 10- 0B nine 042-18B-1B5-0ED-1A1-19B FI53(7639,7EEF)-081A seven 39- 01- 73- 4C- 1E- 04 nine 0EC-1CB-1F2-11D-056-01A Round 6 FO6(DDE8586C)-DD0B619B FI61(CDC1,00F8)-8FF4 seven