COMP128-1 SIM Cryptanalysis & Cloning (Wagner & Goldberg Discovery)
David Wagner and Ian Goldberg (UC Berkeley ISAAC Group) completely cracked the GSM COMP128-1 algorithm, allowing extraction of SIM master keys (Ki) and physical cloning of SIM cards.
01Video Presentation & Conference Keynote
02Deep-Dive Technical Analysis
COMP128-1 served as the combined A3 (authentication) and A8 (encryption key generation) algorithm inside GSM SIM cards. Wagner and Goldberg discovered a differential cryptanalysis flaw in the hash compression function that leaked bytes of the 128-bit master secret key (Ki). By issuing approximately 150,000 challenge queries over the smartcard interface (taking under an hour), the secret key could be completely recovered.
03Vulnerability & Exploit Flow
Differential cryptanalysis of the COMP128-1 compression function via chosen challenge APDUs.
04Recommended Defense & Mitigation Protocol
Deploy COMP128-2, COMP128-3, or Milenage algorithms with hardware tamper-resistant USIM modules.
05Security Impact & Geopolitical Consequence
Proved that SIM smartcards were vulnerable to physical cloning attacks, prompting the GSM Association to develop COMP128-2 and COMP128-3 algorithms with larger effective keys and differential power analysis countermeasures.
06Authoritative Standards & External References
07Related Topic Cluster Records
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.