Cellular communications in the GSM network use a form of ciphering (encryption) known as A5. There are three variants of A5 in use:
A5/1 has been known to be a weak cipher for more than ten years, and in 2009 a brute force attack was demonstrated that can break the cipher in seconds or minutes. Since then, 3GPP has updated the GSM specifications with methods to strengthen the system against the attack, and by advocating the use of A5/3 instead of A5/1. However, in most networks (as of Dec 2013), none of these additions have been implemented, and communications in the networks remain vulnerable.
In 2010, a proof-of-concept method utilizing the brute force attack was published. This method uses a collection of tools to do the attack off-line:
However, with much of the process being manual, the method is cumbersome to use in practice.
In 2013 it was revealed that NSA has the capability to eavesdrop on GSM networks on a large scale. It would be reasonable to assume that intelligence agencies in other countries also have this capability. Further, obtaining raw data is very easy, since all that is required is to be in range of the same base station as the victim, which may be several km away. Thus, it is likely that GSM eavesdropping is done also by other organizations, e.g. for corporate espionage.
The purpose of Airean is to show that practical eavesdropping of GSM traffic is possible with a regular desktop PC and commodity hardware. However, intercepting other peoples' communications is still unethical, and may also be illegal in your country. It is released with the sole hope that it will lead to an accelerated adoption of A5/3 for GSM networks.
Using Airean requires hardware to receive GSM signals. The only currently supported device is the Universal Software Radio Peripheral (USRP) from Ettus Research. It has been tested with the USRP1 and the DBSRX2 daughterboard, although it should also work with other Ettus devices.
Support is planned for the HackRF, and will be implemented when the devices start shipping.
In order to break the A5/1 cipher, Airean interfaces with Skraken. Skraken is an implementation of the above mentioned brute-force attack and is based on Kraken. It requires access to 1.7 TB of pre-computed table data. Airean can also be used stand-alone to listen to the broadcast channels of a base station, or to receive communications for which the session key is known.
Obtain the source through git:
$ git clone git://git.code.sf.net/p/airean/code airean
See the file README for library requirements and compile instructions.
See [Usage] for usage of the program.
Airean contains highly optimized digital signal processing code to be able to do GSM baseband processing for several channels simultaneously. A description of the implementation is in the attached file airean_technical.pdf.
Airean was developed by Anton Blad.