The Absolute in secure mobile communications |
Why is the Tripleton® Enigma an ultra secure mobile phone?This page will give you the essential points highlighting why the Tripleton Enigma is one of the most secure mobile phones on the market. We truly believe it is "the absolute solution for secure GSM communications." We will demonstrate how safe & secure the Tripleton Enigma is by illustrating the possible ways an interceptor / attacker could try to eavesdrop on a secure call between two Tripleton Enigma devices.The Technology in a Nutshell The Tripleton Enigma uses the method of Public Key Infrastructure (PKI) to securely transfer voice data across the GSM network. It incorporates cutting edge deployment of digital certificates, authentication, CA trust centres and Smart Cards to establish secure calls between Tripleton Enigma users. The Tripleton Enigma uses a Hybrid Cryptosystem using two proven strong cryptographic algorithms, the asymmetric RSA 1024 bits and the symmetric AES 256 bit algorithm. If an attacker/interceptor tries to eavesdrop on a Tripleton device engaged in a secure crypto-call, there are several logical steps he or she would need take to order to comprehensively listen in on the call. The first is to gain access to the GSM air interface.
Gain access to the GSM air interface
This is by no means a trivial task but there are known inherent weaknesses within GSM networks which allow
interceptors/attackers, with right equipment and expertise to gain access to the GSM air interface. Once an attacker has
gained access to this interface they would be able to eavesdrop and record call data for targeted conversations. So how can the
Tripleton Enigma device help and why is it so ultra secure?
After gaining access to the GSM air interface, the interceptor/attacker would need to accomplish a series a tasks in order to have comprehensive access to an encrypted call between two Tripleton devices. These tasks are...
*Within the Tripleton Enigma a CODEC chip samples the users voice on the microphone and generates a continuous stream of digitised speech data. This speech data is forwarded to another process for further encoding, compression and broken up into speech blocks in preparation for rate transfer over the V110 GSM data channel. Finally and most importantly these speech blocks are encrypted using AES 256 bit encryption and sent over the air interface via the V110 GSM data channel. Points (A), (B) and (D) are all possible with the right equipment, technical knowledge and access. HOWEVER to achieve point (C) the attacker MUST decrypt the AES-256bit encrypted speech. For this to be accomplished the attacker/interceptor needs to be successful with ANY of the listed attacks below. (1) Deduce the 256 bit AES Session Key used to encrypt the speech
A 256 bit key length represents approx 1077 possible key combinations and so it would take in all practical terms for eternity to deduce the right key. To give some practical idea of the type of effort needed to deduce the AES session key let's examine the kind of computing effort required to deduce an AES 128bit session key. Let’s first consider how big a number 128 bits really is. This represents 2 to the 128th power, or 3.4 x 10 to the 38th power (i.e., 38zeros): 3,400,000,000,000,000,000,000,000,000,000,000,000,000.
Conclusion: The Tripleton Enigma is resistant to attack by method (1) so next attack level could be by method (2) below. (2) Find a weakness in the AES algorithm.
AES algorithm is a public algorithm that has been formally tested and certified by all major governments. It has been found to be cryptographically secure. No weakness exists. Conclusion: The Tripleton Enigma is resistant to attack by method (2) so next attack level could be by method (3) (3) Find a weakness in RSA 1024 bit Encryption to extract Session Key that is sent over the air
during the beginning of the call.
Before a crypto call is established and before encrypted speech data is exchanged between Tripleton devices, the AES session key is generated and transmitted from calling side to called side during the "key exchange" phase. The Session key is transmitted in encrypted format using the cryptographic algorithm RSA with a key length 1024 bit. So to extract the session key the attacker would need to break RSA-1024 bit encryption. RSA algorithm is a public algorithm that has been formally tested and certified by all major governments to be cryptographically secure. No weakness currently exists for key length 1024 bits. Conclusion: The Tripleton Enigma is resistant to attack by method (3) so next attack level could be by method (4) (4) Extract the Secret RSA Key from the Crypto Card.
During the "key exchange" phase the Session Key is generated inside the Crypto Card and then encrypted with the RSA secret key stored inside the crypto card. This secret or private key never leaves the secure environment of the crypto card. The crypto card is a purpose built Smart Card which has a multitude of hardware and software security mechanisms to prevent unauthorised access to data secured in it. The crypto card has been formally tested, certified and approved to be secure to E4+ mechanical strength (high) by ITSEC. So it is not possible for the secret key to be read from the card. Conclusion: The Tripleton Enigma is resistant to attack by method (4) so next attack level could be by method (5) (5) Get a copy of the RSA Key Pair from Telesec Trust Centre during Crypto Card production.
The Telesec Trust Centre operates under strict German ( and EU ) signature law which dictates that the Trust Centre programming environment must...
Conclusion: The Tripleton Enigma is resistant to attack by method (5) so next attack level could be by method (6) (6) Use Stolen Enigma as part of an Middle Man attack.
During every secure call the identify and authenticity of each Tripleton device is mutually checked. This is possible by digitally signing all RSA keys by a trusted third party. This ensures that secure calls can only take place between two Enigma units which contain crypto cards issued by either the Telesec Trust Centre or by Customer's own Trust Centre. With the additional feature CUG ("Closed User Groups") this restriction is reduced further ensuring that secure calls can only take place between designated Tripleton devices within a closed user group. Additionally lost Enigma units can be eliminated from a closed user group very easily and quickly. Thus Tripleton Enigma eliminates the threat of a middle man attack. Conclusion: Tripleton Enigma is resistant to Attack by method (6) so next attack level could be by method (7) (7) Try to Compromise the Enigma by loading Trojan software into it so that encryption is
weakened or disabled.
The GSM and Security module operating system has restricted functionality and security functions to prevent unauthorised download of third party applications. Attack by point g) is not feasible. FURTHER READING
February 2001
Introduction to Public Key Technology and the PKI Infrastructure
May 2003
The RSA Key Size
NEWS OF INTEREST
05-th October 2008
There’s no hiding place as spy HQ plans to see all
04-th January 2009
Psst! It’s so easy to spy on the wife
19-th October 2008
You can’t escape: it’s spy web, plan B
02-nd February 2006
Greek government's phones tapped
| ||||