A Real-Time Related Key Attack on the WG-16 Stream Cipher for Securing 4G-LTE Networks.

Lin Ding,Dawu Gu,Lei Wang,Chenhui Jin,Jie Guan
DOI: https://doi.org/10.1016/j.jisa.2021.103015
IF: 4.96
2021-01-01
Journal of Information Security and Applications
Abstract:The WG-16 stream cipher proposed in 2013 is an efficient variant of the well-known WG stream cipher family. WG-16 inherits good randomness properties of the WG stream cipher family and is intended for use in confidentiality and integrity algorithms in mobile communications, such as 4G-LTE networks. This paper finds that there exist related Key-IV pairs for the WG-16 stream cipher that can generate keystreams which are exact shifts of each other throughout the keystream generation. By exploiting this slide property, a real-time related key attack on WG-16 is proposed, which recovers all 128 key bits with time complexity of about 2 35 . 81, requiring 2 35 . 81 chosen IVs and 6 related keys. We verify this attack on a common PC, which shows that our attack can recover all 128 key bits of WG-16 within four days. The experimental results indicate that WG-16 can be broken in real time in the multiple related key setting and is not secure as claimed by the designers. This is the first attack that defeats the practical security of WG-16.
What problem does this paper attempt to address?