Digital Enhanced Cordless Telephony, DECT, is a world-wide standard for cordless telephony that is frequently integrated into Unified Communications systems both in commercial and residential environments. DECT supports encryption to protect the confidentiality of the communications whilst allowing the interoperability between products from different models and manufacturers. In this paper we explore, from both a theoretical and a practical standpoint, the security of the DECT cryptographic pairing process, which plays a vital role in the security chain of Unified Communications systems involving DECT technology. Furthermore, we demonstrate a practical security attack against the DECT pairing process that is able to retrieve the cryptographic keys and decrypt in real-time any subsequent encrypted voice communication. We also present a proposal for a more secure alternative cryptographic pairing process that is not vulnerable to this type of passive attack.
COISEL Iwen;
SANCHEZ MARTIN Jose Ignacio;
2015-04-14
Institute of Electrical and Electronics Engineers (IEEE)
JRC90564
978-1-4799-6364-5,
http://ieeexplore.ieee.org/xpl/articleDetails.jsp?arnumber=6975562,
https://publications.jrc.ec.europa.eu/repository/handle/JRC90564,
10.1109/JISIC.2014.26,
| Name | Country | City | Type |
|---|
This document is only visible at the Commission level.
You are not authorized to publish or distribute it outside the European Commission.
This is a public document. You can share this publication.
Datasets
| ID | Title | Public URL |
|---|
Dataset collections
| ID | Acronym | Title | Public URL |
|---|
Scripts / source codes
| Description | Public URL |
|---|
Additional supporting files
| File name | Description | File type |
|---|