1、 ETSI TS 1Digital cellular telecommSpecification of the Galgorithms for GeneGEA5 and G(3GPP TS 55.2TECHNICAL SPECIFICATION155 251 V13.0.0 (2017mmunications system (Phase e GEA5 encryption and GIA5 ineral Packet Radio Service (GGIA5 algorithm specification .251 version 13.0.0 Release 13GLOBAL SYSTEMO
2、BILE COMMUN17-02) e 2+) (GSM); 5 integrity (GPRS); n 13) TEM FOR ICATIONSRETSI ETSI TS 155 251 V13.0.0 (2017-02)13GPP TS 55.251 version 13.0.0 Release 13Reference DTS/TSGS-0355251vd00 Keywords GSM,SECURITY ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fa
3、x: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org/standards-search The present document may be made available in electronic ver
4、sions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is
5、 the print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is ava
6、ilable at https:/portal.etsi.org/TB/ETSIDeliverableStatus.aspx If you find errors in the present document, please send your comment to one of the following services: https:/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by
7、 any means, electronic or mechanical, including photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all med
8、ia. European Telecommunications Standards Institute 2017. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organization
9、al Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TS 155 251 V13.0.0 (2017-02)23GPP TS 55.251 version 13.0.0 Release 13Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. T
10、he information pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available f
11、rom the ETSI Secretariat. Latest updates are available on the ETSI Web server (https:/ipr.etsi.org/). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314
12、 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the present document. Foreword The present document may refer to technical specifications or reports using their 3GPP identities, UMTS identities or GSM identities. These should be interpreted as being referen
13、ces to the corresponding ETSI deliverables. The cross reference between GSM, UMTS, 3GPP and ETSI identities can be found under http:/webapp.etsi.org/key/queryform.asp. Modal verbs terminology In the present document “shall“, “shall not“, “should“, “should not“, “may“, “need not“, “will“, “will not“,
14、 “can“ and “cannot“ are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. ETSI ETSI TS 155 251 V13.0.0 (2017-02)33GPP TS 55.251 versi
15、on 13.0.0 Release 13Contents Intellectual Property Rights 2g3Foreword . 2g3Modal verbs terminology 2g3Foreword . 5g3Introduction 5g31 Scope 6g32 References 6g33 Definitions, symbols and abbreviations . 6g33.1 Definitions 6g33.2 Symbols 6g33.3 Abbreviations . 7g34 Introductory information 7g34.1 Intr
16、oduction 7g34.2 Notation 7g34.2.1 Radix . 7g34.2.2 Conventions 7g34.2.3 Bit/byte ordering . 7g34.3 List of variables 8g35 Confidentiality algorithm GEA5 9g35.1 Introduction 9g35.2 Inputs and outputs 9g35.3 Components and architecture . 9g35.4 Initialisation 9g35.5 Keystream generation . 9g35.6 Outpu
17、t octets 9g36 Integrity algorithm GIA5 10g36.1 Introduction . 10g36.2 Inputs and outputs 10g36.3 Components and architecture . 10g36.3.1 SNOW 3G . 10g36.3.2 MULx . 10g36.3.3 MULxPOW. 10g36.3.4 MUL . 10g36.4 Initialization . 11g36.5 Calculation . 11g3Annex A (informative): Mathematical background of
18、some operations of the GIA5 Algorithm . 12g3A.1 The function EVAL_S 12g3A.2 The function MUL(V, P, c) 12g3Annex B (informative): Implementation options for some operations of the GIA5 algorithm . 13g3B.1 Overview 13g3B.2. Procedure Pre_Mul_P. 13g3B.3 Function Mul_P 13g3Annex C (informative): Figures
19、 of the GEA5 and GIA5 algorithms . 14g3Annex D (informative): Simulation program listing . 15g3ETSI ETSI TS 155 251 V13.0.0 (2017-02)43GPP TS 55.251 version 13.0.0 Release 13D.1 GEA5 15g3D.2 GIA5 . 15g3Annex E (informative): Change history . 16g3History 17g3ETSI ETSI TS 155 251 V13.0.0 (2017-02)53GP
20、P TS 55.251 version 13.0.0 Release 13Foreword This Technical Specification (TS) has been produced by ETSI 3rd Generation Partnership Project (3GPP). The contents of the present document are subject to continuing work within the TSG and may change following formal TSG approval. Should the TSG modify
21、the contents of the present document, it will be re-released by the TSG with an identifying change of release date and an increase in version number as follows: Version x.y.z where: x the first digit: 1 presented to TSG for information; 2 presented to TSG for approval; 3 or greater indicates TSG app
22、roved document under change control. y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, updates, etc. z the third digit is incremented when editorial only changes have been incorporated in the document. Introduction This specification has been p
23、repared by the 3GPP Task Force, and gives a detailed specification of the 3GPP confidentiality algorithm GEA5 and the 3GPP integrity algorithm GIA5. This document is the first of three, which between them form the entire specification of the 3GPP confidentiality algorithm GEA5 and the 3GPP integrity
24、 algorithm GIA5: - 3GPP TS 55.251: “Specification of the GEA5 and GIA5 encryption algorithms for GPRS; GEA5 and GIA4 algorithm specification“. - 3GPP TS 55.252: “Specification of the GEA5 and GIA5 encryption algorithms for GPRS; Implementers test data“. - 3GPP TS 55.253: “Specification of the GEA5 a
25、nd GIA5 encryption algorithms for GPRS; Design conformance test data“. ETSI ETSI TS 155 251 V13.0.0 (2017-02)63GPP TS 55.251 version 13.0.0 Release 131 Scope The present document defines the technical details of the 3GPP confidential algorithm GEA5 and the 3GPP integrity algorithm GIA5. 2 References
26、 The following documents contain provisions which, through reference in this text, constitute provisions of the present document. - References are either specific (identified by date of publication, edition number, version number, etc.) or non-specific. - For a specific reference, subsequent revisio
27、ns do not apply. - For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same Release as the present document. 1 3GPP TR 21.905: “Voc
28、abulary for 3GPP Specifications“. 2 3GPP TS 33.216: “Specification of the 3GPP Confidentiality and Integrity Algorithms UEA2 Document 2: SNOW 3G specification“. 3 Definitions, symbols and abbreviations 3.1 Definitions For the purposes of the present document, the terms and definitions given in 3GPP
29、TR 21.905 1 and the following apply. A term defined in the present document takes precedence over the definition of the same term, if any, in 3GPP TR 21.905 1. (none) 3.2 Symbols For the purposes of the present document, the following symbols apply: = The assignment operator. The bitwise exclusive-O
30、R operation. | The concatenation of the two operands. KASUMIxkThe output of the KASUMI algorithm applied to input value x using the key k. Xi The ithbit of the variable X. (X = X0 | X1 | X2 | ). YiThe ithblock of the variable Y. (Y = Y0| Y1 | Y2| . ). ceiling(x) The smallest integer greater than or
31、equal to the real number x. also the input to the GIA5 function which specifies the number of octets of message to be MAC“d (1-65536). MAC the 32-bit message authentication code (MAC) produced by the integrity function GIA5. MESSAGE the input bitstream of LENGTH bits that is to be processed by the G
32、IA5 function. OUTPUT the output octets from the GEA5 function. S1, S2, a sequence of 64-bit words derived from MESSAGE and LENGTH which is used within GIA5 to construct the MAC z1, z2, the 32-bit words forming the keystream sequence of SNOW 3G. The word produced first is z1, the next word z2and so o
33、n. ETSI ETSI TS 155 251 V13.0.0 (2017-02)93GPP TS 55.251 version 13.0.0 Release 135 Confidentiality algorithm GEA5 5.1 Introduction The confidentiality algorithm GEA5 is a stream cipher that encrypts/decrypts blocks of data between 1 and 65536 octets in length. 5.2 Inputs and outputs The inputs to t
34、he algorithm are given in Table 5.2.1, the output in Table 5.2.2: Table 5.2.1: GEA5 inputs Parameter Size (bits) Comment INPUT 32 Frame dependent input INPUT0INPUT31 DIRECTION 1 Direction of transmission DIRECTION0 FRAMETYPE 8 Input value signifying the type of frame to be protected KC128 128 Confid
35、entiality key KC1280.KC128127M The number of octets of output required in the range 1 to 65536 inclusive Table 5.2.2: GEA5 output Parameter Size (bits) Comment OUTPUT 8M Keystream octets OUTPUT0.OUTPUTM-1 5.3 Components and architecture This clause only available under licence. See http:/www.etsi.or
36、g/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. 5.4 Initialisation This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. 5.5 Keystream generation This clause only available under lice
37、nce. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. 5.6 Output octets This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. ETSI ETSI TS 155 251 V13.0.0 (2017-02
38、)103GPP TS 55.251 version 13.0.0 Release 136 Integrity algorithm GIA5 6.1 Introduction The integrity algorithm GIA5 computes a Message Authentication Code (MAC) on an input message under an integrity key KI128. The message may be between 1 and 65536 octets long. For ease of implementation the algori
39、thm is based on the same stream cipher (SNOW 3G) 2 as is used by the confidentiality algorithm GEA5. 6.2 Inputs and outputs The inputs to the algorithm are given in table 6.2.1, the output in table 6.2.2: Table 6.2.1: GIA5 inputs Parameter Size (bits) Comment INPUT-I 32 Frame dependent input INPUT-I
40、0INPUT-I31 M The length of MESSAGE in octets (1-65536) MESSAGE 8M Input octet stream MESSAGE0.MESSAGEM-1 DIRECTION 1 Direction of transmission DIRECTION0 FRAMETYPE 8 Input value signifying the type of frame to be protected KI128 128 Integrity key KI1280KI128127 Table 6.2.2: GIA5 output Parameter Siz
41、e (bits) Comment MAC 32 Message authentication code MAC0MAC31 6.3 Components and architecture 6.3.1 SNOW 3G This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. 6.3.2 MULx This clause only available under licence
42、. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. 6.3.3 MULxPOW This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. 6.3.4 MUL This clause only available under l
43、icence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. ETSI ETSI TS 155 251 V13.0.0 (2017-02)113GPP TS 55.251 version 13.0.0 Release 136.4 Initialization This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-alg
44、orithms-and-codes/cellular-algorithm-licences. 6.5 Calculation This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. ETSI ETSI TS 155 251 V13.0.0 (2017-02)123GPP TS 55.251 version 13.0.0 Release 13Annex A (informa
45、tive): Mathematical background of some operations of the GIA5 Algorithm A.1 The function EVAL_S This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. A.2 The function MUL(V, P, c) This clause only available under
46、licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. ETSI ETSI TS 155 251 V13.0.0 (2017-02)133GPP TS 55.251 version 13.0.0 Release 13Annex B (informative): Implementation options for some operations of the GIA5 algorithm B.1 Overview This clause
47、 only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. B.2. Procedure Pre_Mul_P This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. B.3
48、Function Mul_P This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. ETSI ETSI TS 155 251 V13.0.0 (2017-02)143GPP TS 55.251 version 13.0.0 Release 13Annex C (informative): Figures of the GEA5 and GIA5 algorithms T
49、his clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. ETSI ETSI TS 155 251 V13.0.0 (2017-02)153GPP TS 55.251 version 13.0.0 Release 13Annex D (informative): Simulation program listing D.1 GEA5 This clause only available under licence. See http:/www.etsi.org/about/what-we-do/security-algorithms-and-codes/cellular-algorithm-licences. D.2 GIA5 This clause only available under licence. See http:/www.