ETSI to publish TETRA cryptography algorithms

By

Ending 'security by obscurity'.

The secret cryptographic algorithms that underpin TETRA are to be published, in response to a collection of vulnerabilities discovered earlier this year.

ETSI to publish TETRA cryptography algorithms

The European Telecommunications Standards Institute (ETSI) made the decision this week, saying “we are open to academic research for independent reviews.”

The primitives of all TETRA Air Interface cryptographic algorithms will be made available in the public domain, ETSI said.

In late July, Dutch researchers discovered protocol vulnerabilities that would open TETRA-based radiocommunications systems (often in applications like public safety) to a variety of attacks.

The researchers, from company Midnight Blue, said TETRA messages would be subject to “real-time decryption, harvest-now-decrypt-later attacks, message injection, user deanonymisation, or session key pinning”.

ETSI noted that secrecy of cryptographic algorithms “was common practice in the early 1990s when the original TETRA algorithms were designed."

“Effective scrutiny of public-domain algorithms allows for any flaws to be uncovered and mitigated before widespread deployment occurs,” ETSI’s announcement states.

The publications will include TETRA’s original air interface cryptographic algorithms (TEA 1, 2, 3 and 4), along with TEA 5 to 7 which were introduced in 2022 to quantum-proof messages.

The TAA1 and TAA2 authentication and key management specifications will also be put into the public domain, ETSI said.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Eagers Automotive finds unauthorised access to parts of IT systems

Eagers Automotive finds unauthorised access to parts of IT systems

Hackers hit Victoria's court recording database

Hackers hit Victoria's court recording database

St Vincent's Health Australia warns cyber attack forensics could "take some time"

St Vincent's Health Australia warns cyber attack forensics could "take some time"

Yakult Australia confirms cyber incident

Yakult Australia confirms cyber incident

Log In

  |  Forgot your password?