Decoding Encryption with Permission...

How secure is DES for radio traffic? - NOT text documents.


  • Total voters
    97
Status
Not open for further replies.

netsmith

Member
Joined
Jun 22, 2006
Messages
23
Reaction score
0
Curiosity Question

Does anyone know?

1. What is the error correcting code used by the transmission?
2. What is the DES mode that is used?

Seems like for a decode you would need that information...

Cheers,

Casey
 
Last edited:

rescue161

KE4FHH
Database Admin
Joined
Jun 5, 2002
Messages
3,738
Reaction score
706
Location
Hubert, NC
DES is the mode that was used. No crazy XL or other extras. As far as error correction, I have no idea. Maybe someone else can answer that.
 

netsmith

Member
Joined
Jun 22, 2006
Messages
23
Reaction score
0
DES Mode, Error Correction

What I meant was, do the radios use ECB, CBC, CFB etc...

These are modes of operation for the DES algorithm.

http://www.itl.nist.gov/fipspubs/fip81.htm

The above article describes the various modes of operation.

I am not sure if anyone knows, unless someone has had more specific training on the radios, but you would need to know this if you were planning on decrypting a message.

Also, Did you already provide the specific model of radio that you are using, perhaps that would help. (It is yet ANOTHER variable you'd have to overcome if you were eavsdropping on encrypted radio traffic. ;-) Lots of layers in this little project, too many...

Cheers,

Casey
 

SCPD

QRT
Joined
Feb 24, 2001
Messages
0
Reaction score
116
Location
Virginia
Radi0 said:
What I meant was, do the radios use ECB, CBC, CFB etc...
Good question. CBC wouldn't work given the unreliable nature of data over radio. If you lost a whole block - every block that followed would also be lost because decrypting depends upon correct data for the current block and all previous blocks.

ECB would definitely work. CFB and OFB might work ... though less reliable than ECB from the standpoint of trying to recover from a lost block of data. They also introduce an extra variable ... the IV or initialization vector. Yuck.
lots of layers in this little project, too many...
I agree.

-rick
 

rescue161

KE4FHH
Database Admin
Joined
Jun 5, 2002
Messages
3,738
Reaction score
706
Location
Hubert, NC
Radio was a Systems Saber model 1, UHF 438-470 MHz.

CFB sounds familiar, but don't count on that. I really have no idea.
 

netsmith

Member
Joined
Jun 22, 2006
Messages
23
Reaction score
0
Decryption Take-2 Another Bust.

Error Correction Modes supported RS, BCH or Golay. Found on the web. Can that be confirmed?

Not sure if that is something that is configurable on the radio or not.

So, my decrypt attempt 2...
Some MAJOR assumptions were made here.

Assumptions Follow below:
-rfmobile's file is an accurate representation of the bit stream transmitted. Transmission played 2x
-Only a voice message was transmitted no extra data
-Reed-Solomon Encoding/Transmission for Error Correction
-No Interleave
-Big-Endian Transmission (tried both formats still got garbage)
-DES-ECB mode with given key
-CVSD Codec
-All My software is working correctly ;-)

Put it all together and I get... Garbage...

For fun, I have a .wav file I produced from my second decode attempt... I am able to get what seems like a 10 second transmission... At first shot, sounds like a quick sentence, then 2 longer phrases... I have a long way to go. Too big to post on the forum, if you want it, send me a pm. Thought people might like to see some of the challenges of trying to pull the layers out of the signal.

Anyway, I had some spare time this week, and, I'll probably keep hacking a way at it just for fun.

Well, rescue161, your secrets are safe for now ... I have a new BC396 arriving soon and that will probably have me distracted ;-)

Thanks for a fun opportunity to apply some knowledge.

Cheers,

Casey
"There is nothing concealed that will not be disclosed, or hidden that will not be made known." Luke 12:2
 
Last edited:

rescue161

KE4FHH
Database Admin
Joined
Jun 5, 2002
Messages
3,738
Reaction score
706
Location
Hubert, NC
Radi0 said:
I am able to get what seems like a 10 second transmission... At first shot, sounds like a quick sentence, then 2 longer phrases...

THAT is VERY close!!!

There are 3 sentences! The first is very short and the second and the third are longer (the third being the longest)!!!
 

netsmith

Member
Joined
Jun 22, 2006
Messages
23
Reaction score
0
Just a Guess

Here's what I have for timing on the sentences:

1, about 1.4 seconds,

2, about 2.7 seconds
I believe this is the sentence you posted:
"They can be modified into other puzzles that can be even more challenging."

3, about 6.1 seconds

Total, close to 11 seconds of transmission.



Cheers,

Casey
 

rescue161

KE4FHH
Database Admin
Joined
Jun 5, 2002
Messages
3,738
Reaction score
706
Location
Hubert, NC
Radi0 said:
Here's what I have for timing on the sentences:

1, about 1.4 seconds,

2, about 2.7 seconds
I believe this is the sentence you posted:
"They can be modified into other puzzles that can be even more challenging."

3, about 6.1 seconds

Total, close to 11 seconds of transmission.



Cheers,

Casey

OUT-FREAKIN-STANDING!!! YES!!! That is the second sentence! Is it clear or almost unintelligible?
 

netsmith

Member
Joined
Jun 22, 2006
Messages
23
Reaction score
0
Still unclear, but getting better!!!

Patterns are starting to emerge. I've been experiementing with error correction/decyrption
I think I have isolated the voice traffic.

I'm probably NOT going to get to a clear message fully, I just don't have time... I've spent too much time already. ;-)

It goes to show you that even if you CAN decrypt a message, by the time you do, its lost it value.

But it was definitely worth a try!!!

Cheers,

Casey
 
N

N_Jay

Guest
Radi0 said:
Still unclear, but getting better!!!

Patterns are starting to emerge. I've been experiementing with error correction/decyrption
I think I have isolated the voice traffic.

I'm probably NOT going to get to a clear message fully, I just don't have time... I've spent too much time already. ;-)

It goes to show you that even if you CAN decrypt a message, by the time you do, its lost it value.

But it was definitely worth a try!!!

Cheers,

Casey

Given the key.

I bet if you change the key a few bits you will see how hard it is to detect when you even have the correct key.
 

netsmith

Member
Joined
Jun 22, 2006
Messages
23
Reaction score
0
Absoluely N_Jay.

All this and we HAVE the key... And a Phrase... And the model and mode the radio was in etc... In the real world you'd have to guess all that...

If he changes the key by 1 bit, then I'd be toast. If you are off 1 bit in the stream you are decoding, your're toast.

I am in agreement that DES decryption, is VERY, VERY difficult.

I doubt anyone will ever be able to post a clear decode of the original message...

If you could eliminate all the variables, except for the key... Then, you'd still have an unbelievable amount of keys to try...

I'd like to see some of those who think DES is so easy to crack, crack this message given all the information we have...

Cheers,

Casey
 

Xitium

Member
Joined
Apr 10, 2006
Messages
80
Reaction score
0
Location
Hillsboro OR
N_Jay said:
The point is (AGAIN) . . . . . .
TEXT:
You could try a key and run the file, if you get lots of invalid ASCII characters, try the next key. all automatically at computer like speed.
This will probably sort out all but a few false positives.
Fast process, computer intensive.

AUDIO:
Try a key and run the file, search the audio for some very basic pass/fail test.
THEN listen to LOTS of false positive audio samples until you hear a voice.
SLOWWWWW Process, human intensive.

GET IT!!!!!!!:roll:

You could use some ASR program it wouldn't be that hard, it would not be as fast as scanning text but it would allow you to remove some of the human effort
 
N

N_Jay

Guest
Xitium said:
You could use some ASR program it wouldn't be that hard, it would not be as fast as scanning text but it would allow you to remove some of the human effort

I doubt it, as ASR usually is very ineffective on high compression vocoded speech, even properly decoded.
 

MattSR

Member
Joined
Jul 26, 2002
Messages
407
Reaction score
11
Location
Sydney, Australia
Hmmm I could have sworn I posted this already and it went missing, but here goes...

I have an old analog saber lying around, I reckon with a DES-XL module loaded with the key that Rescue161 has provided could be used to play back the recording. From what I understand the secure module accepts the baseband audio from the radios discriminator directly - if this is the case then playing the MP3 recording straight into the discriminator input of the radios module should, in theory, work assuming the voltage levels and rates are correct and within spec.

What do people think of this? I know its not "cracking" the encrypted file as Rescue intended it, but it could provide a platform for brute forcing?

Thoughts? Comments?

Cheers,
Matt
VK2TVK
 

MattSR

Member
Joined
Jul 26, 2002
Messages
407
Reaction score
11
Location
Sydney, Australia
Some more info - as rescue161 has said, it was plain DES. According to the securenet documentation I have, plain DES (with no -XL) is CFB mode, with no frames or anything.

The non-XL securenet did have big range problems due to error propagation (ie one error would screw the wole preocess back due to the feedback methods employed)
 

RayAir

Member
Joined
Dec 31, 2005
Messages
1,974
Reaction score
188
rescue161 said:
Dude, you are WAY off. That was a text file that they decoded.

Please don't post things like, "In recent years, the cryptography community repeatedly demonstrated DES's limitations. One such demonstration was a January, 1999, assault involving a combination of 100,000 networked PCs and a $250,000 computer built by the Electronic Frontier Foundation (EEF). It decrypted a DES-encoded message in 22 hours." because that was a TEXT FILE!!! NOT AUDIO!

Do me a favor an post MY audio in the encrypted file to prove the masses wrong.

Even if it is after the 1 week period, there will still be a "prize" so to speak.

Consider this, some federal agencies including the Secret Service have never relied on DES for security. Instead they use fascinator or similar which is probably a 3DES key or higher. This here should prove that DES can be relied on for communications that are sensitive/non-classified or lower. I would take this to mean that DES protects against all but the highly technically capable adversary. And DES absolutely cannot be trusted to protect against any signals intelligence agency.
 

MattSR

Member
Joined
Jul 26, 2002
Messages
407
Reaction score
11
Location
Sydney, Australia
Unitrunker said:
3. I threw together some code to slice the waveform into a 12000 bit per second stream. Bit phase is inferred from +'ve and -'ve transitions through zero with some damping for noise. Bit level was determined by mid-sampling (sampling the waveform at the time believed to be the middle of a bit).

I already had code to do this ... (for Motorola and EDACS trunking) ... so it only took minutes to throw this together.

-rick

When you say "time believed to be the middle of a bit" is this the difference between two 'zero-crossings' divided by 2?

Its possible that the MP3 codec has distorted the waveform to the point that clock recovery is not possible.
 

RayAir

Member
Joined
Dec 31, 2005
Messages
1,974
Reaction score
188
Someone should post an analog scrambled message on here and try to crack that. Not voice inversion, but maybe some rolling code? I figure analog scrambling is more susceptible to cracking than digital encryption. Anyone interested? I can make a scrambled test message......
I can even come up with a prize.
 
Status
Not open for further replies.
Top