Paper 2026/1806

Practical Differential Fault Attacks on the GPRS Standard Ciphers

Zhengting Li, Information Engineering University, Zhengzhou 450001, China
Lin Ding, Information Engineering University, Zhengzhou 450001, China
An Wang, Beijing Institute of Technology, Beijing 100081, China
Haotong Xu, Beijing Institute of Technology, Beijing 100081, China
Zheng Liu, Beijing Institute of Technology, Beijing 100081, China
Zheng Wu, Information Engineering University, Zhengzhou 450001, China
Xinhai Wang, Information Engineering University, Zhengzhou 450001, China
Jiang Wan, Information Engineering University, Zhengzhou 450001, China
Abstract

GEA-1 and GEA-2 are two standard stream ciphers used in GPRS (General Packet Radio Service) to protect against eavesdropping GPRS between the base station and the phone. Now, a range of current phones still support them. In this paper, a differential fault attack on the GEA-like stream ciphers under the random fault model is proposed for the first time. In this attack, an efficient dedicated algorithm for identifying the exact fault location is proposed. By using this dedicated algorithm, the attacker can succeed in determining the exact fault location. As applications, practical differential fault attacks on the GPRS standard ciphers (i.e., GEA-1 and GEA-2) are presented, which recover the 64-bit secret keys of GEA-1 and GEA-2 with time complexities of ${2^{{\rm{33}}{\rm{.807}}}}$ and ${2^{{\rm{33}}{\rm{.858}}}}$, respectively. We validate the cryptanalytic results by simulating the whole attacks on the platform ChipWhisperer Lite. The experimental results show that both GEA-1 and GEA-2 can be broken within sixteen minutes on a common laptop. Finally, the possible countermeasures are presented to protect the processed data of massive GPRS devices.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. IEEE Transactions on Dependable and Secure Computing
DOI
10.1109/TDSC.2026.3671957
Keywords
Differential fault attackCountermeasureStandard cipherGEA-1GEA-2General Packet Radio Service
Contact author(s)
dinglin_cipher @ 163 com
History
2026-08-28: approved
2026-08-26: received
See all versions
Short URL
https://ia.cr/2026/1806
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1806,
      author = {Zhengting Li and Lin Ding and An Wang and Haotong Xu and Zheng Liu and Zheng Wu and Xinhai Wang and Jiang Wan},
      title = {Practical Differential Fault Attacks on the {GPRS} Standard Ciphers},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1806},
      year = {2026},
      doi = {10.1109/TDSC.2026.3671957},
      url = {https://eprint.iacr.org/2026/1806}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.