Evolution of Cellular Systems 13
The 128 bit number (RAND) challenge is first transmitted from the network to
the subscriber through the air interface, where it is processed at the SIM card. A3
authentication algorithm and Ki are responsible for sending the RAND to the SIM card
in the phone. The SIM card processes RAND and the secret 128‐bit key Ki, through the
A3 algorithm, to produce a 32‐bit signed response (SRES). The output of the A3 algorithm, that is, the SRES is transmitted back to the network from the subscriber again
through the air interface. In the network, the AuC compares its value of SRES with the
value of SRES that was received from the subscriber. If the two values match, authentication is considered to be successful, and the subscriber becomes eligible to join the network. The AuC does not store the copy of SRES, but takes the help of home location
register (HLR) or visitor location register (VLR) whenever required.
1.4.5.4 A8 Algorithm
GSM uses ciphering to protect both user data and signaling at an air interface. Once the
authentication has been successfully carried out, the RAND coming from the network
together with the Ki coming from the SIM, are sent through an A8 ciphering key generating
algorithm to create a ciphering key (Kc). This Kc created by the A8 algorithm is used with
the A5 ciphering algorithm to cipher or decipher the data. The A5 algorithm is implemented in the hardware of the mobile phone as it encrypts and decrypts data in the air.
Whenever the A3 algorithm is run to generate the SRES, the A8 algorithm also runs. Other
than the A8 generating the ciphering key Kc, the network also generates the Kc, and shares
it with the base stations handling the connection.
SIM
MS
Network
4-Run GSM algorithm
(RAND)
4-Authentication Response (SRES)
3-Authentication Request (RAND)
2-Identity in initial message
(TMSI or IMSI)
1-Establishment of channel
5-Response (SRES, Kc)
Figure 1.5 Working principle of A3 algorithm.
Kc (64 bit)
RAND Challenge (128 bit)
Ki(128 bit)
A8
Figure 1.6 The A8 algorithm.
The 128 bit number (RAND) challenge is first transmitted from the network to
the subscriber through the air interface, where it is processed at the SIM card. A3
authentication algorithm and Ki are responsible for sending the RAND to the SIM card
in the phone. The SIM card processes RAND and the secret 128‐bit key Ki, through the
A3 algorithm, to produce a 32‐bit signed response (SRES). The output of the A3 algorithm, that is, the SRES is transmitted back to the network from the subscriber again
through the air interface. In the network, the AuC compares its value of SRES with the
value of SRES that was received from the subscriber. If the two values match, authentication is considered to be successful, and the subscriber becomes eligible to join the network. The AuC does not store the copy of SRES, but takes the help of home location
register (HLR) or visitor location register (VLR) whenever required.
1.4.5.4 A8 Algorithm
GSM uses ciphering to protect both user data and signaling at an air interface. Once the
authentication has been successfully carried out, the RAND coming from the network
together with the Ki coming from the SIM, are sent through an A8 ciphering key generating
algorithm to create a ciphering key (Kc). This Kc created by the A8 algorithm is used with
the A5 ciphering algorithm to cipher or decipher the data. The A5 algorithm is implemented in the hardware of the mobile phone as it encrypts and decrypts data in the air.
Whenever the A3 algorithm is run to generate the SRES, the A8 algorithm also runs. Other
than the A8 generating the ciphering key Kc, the network also generates the Kc, and shares
it with the base stations handling the connection.
SIM
MS
Network
4-Run GSM algorithm
(RAND)
4-Authentication Response (SRES)
3-Authentication Request (RAND)
2-Identity in initial message
(TMSI or IMSI)
1-Establishment of channel
5-Response (SRES, Kc)
Figure 1.5 Working principle of A3 algorithm.
Kc (64 bit)
RAND Challenge (128 bit)
Ki(128 bit)
A8
Figure 1.6 The A8 algorithm.
