[ RECORD YEAR ]1998

COMP128-1 SIM Cryptanalysis & Cloning (Wagner & Goldberg Discovery)

David Wagner and Ian Goldberg (UC Berkeley ISAAC Group) completely cracked the GSM COMP128-1 algorithm, allowing extraction of SIM master keys (Ki) and physical cloning of SIM cards.

THREAT SEVERITY
8.8 / 10
Target TechnologyGSM COMP128-1 Algorithm, SmartCard ISO 7816, Ki Extraction
OSI Network LayerLayer 7 / SIM Smartcard Application Layer
Threat Actor / AttributionDavid Wagner & Ian Goldberg (UC Berkeley ISAAC Group)
Protocol StandardGSM 03.20 Security Specifications

01Video Presentation & Conference Keynote

02Deep-Dive Technical Analysis

COMP128-1 served as the combined A3 (authentication) and A8 (encryption key generation) algorithm inside GSM SIM cards. Wagner and Goldberg discovered a differential cryptanalysis flaw in the hash compression function that leaked bytes of the 128-bit master secret key (Ki). By issuing approximately 150,000 challenge queries over the smartcard interface (taking under an hour), the secret key could be completely recovered.

03Vulnerability & Exploit Flow

Exploit Vector

Differential cryptanalysis of the COMP128-1 compression function via chosen challenge APDUs.

04Recommended Defense & Mitigation Protocol

Operator Hardening Strategy

Deploy COMP128-2, COMP128-3, or Milenage algorithms with hardware tamper-resistant USIM modules.

05Security Impact & Geopolitical Consequence

Proved that SIM smartcards were vulnerable to physical cloning attacks, prompting the GSM Association to develop COMP128-2 and COMP128-3 algorithms with larger effective keys and differential power analysis countermeasures.

06Authoritative Standards & External References

07Related Topic Cluster Records

TelcoSec Global Ecosystem · Academy & Enterprise Audits

Master 5G Core, SS7 Defense & Subsea Cable Auditing

Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.

Hands-on SS7, Diameter & 5G SBA Firewall Defense
5G SA Zero Trust Security Architecture & ProLabs
Enterprise Carrier Auditing & Rogue Base Station Interception
Explore SaaS Academy Labs?Enterprise Consultancy (telco-sec.com)?
SaaS Academy free tier · Enterprise audits for operators