{"id":{"repo_id":"cuny","oai_identifier":"oai:academicworks.cuny.edu:cc_etds_theses-1872"},"canonical_url":"https://search.dev.ndltd.org/etd/cuny/oai:academicworks.cuny.edu:cc_etds_theses-1872","repository":{"repo_id":"cuny","name":"City University of New York - City College","base_url":"https://academicworks.cuny.edu/do/oai/"},"display":{"title":"Sniffing, Decoding and Decryption of GSM Signals Using low cost hardware and Open-source software","abstract":"<p>We have participated in the creation of almost two terabytes of tables aimed at cracking A5/1, the most common ciphering algorithm used in GSM. Given 114-bit of known plaintext, we are able to recover the session key with a hit rate of 19%. The tables are expected to be unique as they provide the best coverage yet known to the authors and research workers and they are the first step in a real-world passive attack against GSM. An initial investigation and analysis into the air interface of GSM were performed, from both a theoretical and practical point of view. These examinations would be essential in order to utilize the downloaded tables in a practical attack. Additionally, a rogue GSM network was built and deployed without enabling ciphering and frequency hopping. This active attack was purely based on opensource software and hardware, implying that real GSM networks could be spoofed with resources available to the general public</p>","abstract_html":"&lt;p&gt;We have participated in the creation of almost two terabytes of tables aimed at cracking A5/1, the most common ciphering algorithm used in GSM. Given 114-bit of known plaintext, we are able to recover the session key with a hit rate of 19%. The tables are expected to be unique as they provide the best coverage yet known to the authors and research workers and they are the first step in a real-world passive attack against GSM. An initial investigation and analysis into the air interface of GSM were performed, from both a theoretical and practical point of view. These examinations would be essential in order to utilize the downloaded tables in a practical attack. Additionally, a rogue GSM network was built and deployed without enabling ciphering and frequency hopping. This active attack was purely based on opensource software and hardware, implying that real GSM networks could be spoofed with resources available to the general public&lt;/p&gt;","abstract_has_math":false,"creators":["Choudhry, Muhammad Talha"],"institution":null,"degree_name":"Master of Engineering (M.E.)","degree_level":"Thesis","degree_discipline":"Engineering","degree_department":null,"school":null,"contributors":["Mohamed A. Ali"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2019,"date_issued":"2019-01-01T08:00:00Z","date_published":"2019-01-01T08:00:00Z","updated_at":"2026-07-24T01:57:28Z","subjects":["2G Second-generation","A3 Authentication Algorithm","A5 Encryption Algorithm","A8 Key Generation Algorithm","AGCH Access Grant Channel","AMR Adaptive Multi-Rate","Other Electrical and Computer Engineering","Signal Processing"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://academicworks.cuny.edu/cc_etds_theses/870","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Mohamed A. Ali"]},{"key":"dc:creator","label":"Author","values":["Choudhry, Muhammad Talha"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2019-12-17T08:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Engineering (M.E.)"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["2G Second-generation","A3 Authentication Algorithm","A5 Encryption Algorithm","A8 Key Generation Algorithm","AGCH Access Grant Channel","AMR Adaptive Multi-Rate","Other Electrical and Computer Engineering","Signal Processing"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://academicworks.cuny.edu/cc_etds_theses/870"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>We have participated in the creation of almost two terabytes of tables aimed at cracking A5/1, the most common ciphering algorithm used in GSM. Given 114-bit of known plaintext, we are able to recover the session key with a hit rate of 19%. The tables are expected to be unique as they provide the best coverage yet known to the authors and research workers and they are the first step in a real-world passive attack against GSM. An initial investigation and analysis into the air interface of GSM were performed, from both a theoretical and practical point of view. These examinations would be essential in order to utilize the downloaded tables in a practical attack. Additionally, a rogue GSM network was built and deployed without enabling ciphering and frequency hopping. This active attack was purely based on opensource software and hardware, implying that real GSM networks could be spoofed with resources available to the general public</p>"]},{"key":"dc:title","label":"Title","values":["Sniffing, Decoding and Decryption of GSM Signals Using low cost hardware and Open-source software"]}]}],"canonical_facts":{"dc:contributor":["Mohamed A. Ali"],"dc:creator":["Choudhry, Muhammad Talha"],"dc:date.available":["2019-12-17T08:00:00Z"],"dc:description.abstract":["<p>We have participated in the creation of almost two terabytes of tables aimed at cracking A5/1, the most common ciphering algorithm used in GSM. Given 114-bit of known plaintext, we are able to recover the session key with a hit rate of 19%. The tables are expected to be unique as they provide the best coverage yet known to the authors and research workers and they are the first step in a real-world passive attack against GSM. An initial investigation and analysis into the air interface of GSM were performed, from both a theoretical and practical point of view. These examinations would be essential in order to utilize the downloaded tables in a practical attack. Additionally, a rogue GSM network was built and deployed without enabling ciphering and frequency hopping. This active attack was purely based on opensource software and hardware, implying that real GSM networks could be spoofed with resources available to the general public</p>"],"dc:identifier":["https://academicworks.cuny.edu/cc_etds_theses/870"],"dc:subject":["2G Second-generation","A3 Authentication Algorithm","A5 Encryption Algorithm","A8 Key Generation Algorithm","AGCH Access Grant Channel","AMR Adaptive Multi-Rate","Other Electrical and Computer Engineering","Signal Processing"],"dc:title":["Sniffing, Decoding and Decryption of GSM Signals Using low cost hardware and Open-source software"],"thesis:degree_discipline":["Engineering"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["Master of Engineering (M.E.)"]},"updated_at":"2026-07-24T01:57:28Z"}