Research Disclosures

TETRA security disclosures

Updated August 2025

Introduction

In August 2023, the security consultancy Midnight Blue B.V. published papers describing a set of findings relating to TETRA security.  Further research was presented in December 2024, and additional material including research into end-to-end encryption was published in August 2025.  TCCA has prepared this document to describe the impact of these findings and mitigations.

Summary

A summary of the findings and mitigations is as follows:

  • The air interface encryption algorithms TEA1, TEA4 and TEA7 have reduced effective key lengths, which was done to simplify export in some cases from countries that are signatories to the Wassenaar Arrangement (note: the same export issues apply to many technologies). A change to an alternative air interface encryption algorithm or use of end-to-end encryption are mitigations.
  • An anomaly was found in the TEA3 algorithm, but separate independent research has not found any weakness due to this. No weaknesses or anomalies have been found with the TEA2, TEA5 or TEA6 algorithms.
  • It was noted that where TEA1 is used together with another algorithm, the key used for group communications on both can be attacked. Note that the standard recommends against this configuration.  The attack does not affect individual communications, and Group Cipher Keys or end-to-end encryption can provide protection.
  • A weakness was discovered in the identity encryption mechanism used with the original air interface encryption algorithms TEA1, TEA2, TEA3 and TEA4 (known as TEA set A). This can be mitigated by use of a different identity encryption process with the newer algorithms TEA5, TEA6 and TEA7 (TEA set B).
  • In laboratory conditions, a method was found to inject fake messages into a TETRA system; this has been mitigated by an update to the TETRA standard and software updates from suppliers.
  • It was found possible to inject a fake speech transmission into an end-to-end encrypted system with some specific preconditions, although it is not possible to decrypt any encrypted speech. This is mitigated by the use of air interface encryption together with end-to-end encryption (the usual case) or by the optional anti-replay mechanism already specified in the recommendations.
  • An end-to-end encrypted SDS message can be recorded and replayed, although the content cannot be decrypted. This can be mitigated by the use of air interface encryption together with end-to-end encryption (the usual case), or where replay protection is added by the application sending the SDS message (as already stated in the recommendations).
  • There is an end-to-end encryption algorithm available with an effective key length reduction to 56 bits, although most end-to-end encryption algorithms have key lengths of 128 or 256 bits. The choice of algorithm is determined by user organisations and their national security agencies.

Background

Researchers working for security consultancy Midnight Blue B.V. were funded by the NLnet Foundation, which financially supports organisations and people that contribute to an open information society, to conduct research into TETRA security.  The researchers reviewed the open TETRA standards published by ETSI, and reverse engineered publicly-available equipment to recover algorithms that were only available under confidentiality agreements at the time.

Following a responsible disclosure process, early research findings were disclosed in strict confidence to ETSI in January 2022 to enable mitigations to be made in TETRA security standards before the research was published.  ETSI TCCE was already working on an additional set of algorithms for a next release of the TETRA standard to maintain TETRA security into the 2040s, and so additional mitigations were added into the ongoing standardisation work.  Revised TETRA security standards were published in October 2022, and TETRA manufacturers and suppliers already have software upgrades available that address some of the findings.  ETSI plans to release a further update to the standard in 2025, as the standard is continually enhanced.

The research findings were made public by Midnight Blue B.V. in August 2023 at Black Hat USA, and subsequent security conferences.

In December 2024, further research was presented at the Chaos Communications Congress in Hamburg. This presentation provided a first review of the security revisions in the updated TETRA standard and the new TAA2 and TEA5, TEA6 and TEA7 algorithms.  Additional material, including research into the end-to-end encryption mechanisms in TETRA, was published at the Black Hat USA conference in August 2025.

Findings on the TEA1 encryption algorithm

The researchers’ findings all apply to air interface encrypted systems.  Clear systems are not affected.  There are no findings that affect authentication.

The main finding, raising most concerns in the user community, is about the TEA1 encryption algorithm which internally reduces the effective length of the encryption key, thus requiring less effort than expected to recover the reduced key and decrypt communications.

No issues were found with the TEA2 algorithm, and it is considered to be safe for continued use. The researchers noted an anomaly in a table in the TEA3 algorithm.  However, independent reviewers do not believe that this leads to any weakness in TEA3 in the way that it is used in TETRA, and TEA3 is also considered to be secure (https://doi.org/10.46586/tosc.v2025.i1.276-308).

TEA1 was conceived in the mid 1990s to be easily exportable. The key reduction was therefore needed to comply with the Wassenaar Arrangement signed by many countries – 42 at present – limiting the exports of military and ‘dual use’ (military and civilian applications) technologies, which includes cryptography.  Note that the same export restrictions apply to many technologies, not just to TETRA.  In the TEA1 algorithm design, the key length was reduced to an equivalent of 32 bits to permit worldwide export according to the Arrangement. The actual value of the equivalent key length had not been public before the Midnight Blue publication, but the status of TEA1 as an export-friendly variant was public.

TETRA algorithms were until recently available only to suppliers under a strict non-disclosure agreement, and so the design of the TEA1 algorithm had to be kept secret by manufacturers and remained as such until the research findings were published.  Although many encryption systems today are fully published to allow open scrutiny and research, when TETRA was designed it was far more normal to keep algorithms secret – especially for security systems that protect government communications.  Part of the security of TEA1 was provided by the secrecy of the algorithm.

Mitigation

End-to-end encryption can be used to protect speech and/or data and is not affected by any attack on TEA1.  An alternative algorithm, either TEA2 or TEA3 from the original set, or TEA5, TEA6 or TEA7 from the additional algorithm set introduced in 2022, can be used in place of TEA1 to protect speech, data and signalling.  TEA2 and TEA3 use 80 bit keys without any reduction in the key length, but deployment of these algorithms is more restricted than TEA1.  The new algorithms TEA5 and TEA6 use 192 bit keys without any reduction but are also restricted in where they can be deployed.  The new algorithm TEA7 has an effective key length reduction to 56 bits and will be available in many countries as per the Wassenaar Arrangement.

Additional finding related to TEA1

An additional finding indicates that where TEA1 is used in conjunction with another algorithm on the same system (e.g. TEA3), the Common Cipher Key used for group communications can be attacked and recovered for both algorithms.  The standard warns against using two algorithms on the same system, and is expected that this scenario is only likely during algorithm transition.  Individual communications are not affected, and group communications can be further protected by the use of end-to-end encryption or the Group Cipher Key.

Other findings

The research also found a weakness of the identity encryption that could allow an attacker to discover the numerical identities (SSIs) of the users (not the personal identities of the users themselves). Direct Mode Operation (DMO) uses a different mechanism and is not vulnerable to this attack.

The additional encryption algorithms, TEA5, TEA6 and TEA7 have been designed together with a different authentication and key management algorithm set TAA2 which uses a different identity encryption process which is not vulnerable to the attack.  Migration to TAA2 would completely solve the issue. TAA2 is implemented when migrating to TEA5, TEA6 or TEA7.

Finally, the research also contained two secondary findings, which can be solved by a software upgrade of mobile stations. Despite the low probability of either attack being carried out in a real system environment, changes have been made in the TETRA standard to mitigate these findings and these are no longer considered to be an issue.

Further research findings

The subsequent research presented in December 2024 confirmed that, in the opinions of the researchers, the revisions to the identity encryption process and the methods of initialising the new air encryption algorithms in the latest revisions of the TETRA standards do indeed strengthen the security of TETRA.  They also have not found any weaknesses in TEA5 and TEA6.  They, and other academic cryptographers (https://doi.org/10.46586/tosc.v2025.i1.276-308), have looked further into the anomaly found in TEA3, and have not identified any attacks against the algorithm.  A potential attack was proposed against TEA7, but it is uncertain whether there is any practical attack which requires less effort than would be required to attack an equivalent algorithm with 56 bit key length.

The researchers again mentioned that message integrity protection is not provided by a cryptographic mechanism, however it would be difficult to mount a practical attack against TETRA’s mechanisms.

End-to-end encryption

The findings presented in August 2025 showed that, given very particular pre-conditions, it was possible to capture the start of an end-to-end encrypted speech transmission and use it to generate encrypted fake speech messages.  It is important to note that it is not possible to decrypt any speech with this attack, and end-to-end encrypted transmissions remain confidential; it was only possible to inject new messages.  The attack cannot succeed if the optional anti-replay mechanisms for end-to-end encryption are used, and will also not work if air interface encryption is employed together with end-to-end encryption (the normal case) as air interface encryption also provides replay protection.

The researchers also found that it was possible to replay end-to-end encrypted SDS messages: again, it was not possible to recover the content of those messages, only to replay a previous message.  The attack can be mitigated if the message content includes replay protection, as highlighted in existing recommendations from TCCA, or if air interface encryption is used, which provides replay protection.

They also found that one available encryption algorithm had an effective key length of 56 bits: TETRA end-to-end encryption supports many algorithms including restricted national algorithms, and the choice of algorithm is up to the end user or national security agency concerned (subject to export control restrictions).

Recommended actions

Any TETRA system operator or user should work with their national cybersecurity agencies and with their suppliers to assess whether the findings provide a material risk to their system operation. This will depend on their specific threats and threat actors, the consequences of the threats being acted upon, and additional mitigations already designed into their system. For example, end-to-end data protection mechanisms intrinsic to the data applications in use.

The findings related to air interface encryption that are not related to algorithms only require a software update to completely mitigate, and suppliers have updates available. Transition to a new algorithm is complex, and system operators should consult their suppliers to investigate implications and timescales.  System operators and user organisations should review the findings related to end-to-end encryption, and decide whether there are risks that require further mitigations in their systems or operations.

TCCA Working Groups have already input significantly on addressing these issues, and further information is available to TCCA members here (log in required).

In July 2024, ETSI published the primitives of all TETRA Air Interface cryptographic algorithms* as part of the TETRA documentation set, but maintain the requirement for Confidentiality and Restricted Usage Undertakings (CRUUs) and confidential handling of the full set of documentation needed to confidently implement such algorithms (see ETSI TS 101 052-1/-2 and ETSI TS 101 053-1 to -7).

*In this case, the primitives of the algorithms relate to the algorithm specification and not any example  code or test data.

ETSI has a Coordinated Vulnerability Disclosure process (https://www.etsi.org/standards/coordinated-vulnerability-disclosure) which allows security researchers to responsibly divulge potential vulnerabilities in any ETSI standard or algorithm, including those applying to TETRA, in confidence to allow ETSI to investigate mitigations prior to publication of research.  TCCA and ETSI TCCE encourage all finders of potential vulnerabilities to follow this process to allow a responsible disclosure of potential vulnerabilities.

For more information on the security issues in this paper, please contact david.chater-lea@tcca.info

On behalf of its members, TCCA supports all standard mobile critical communications technologies and complementary applications. Our members are drawn from end users, operators and industry across the globe. We believe in and promote the principle of open and competitive markets worldwide through the use of open standards and harmonised spectrum.

For more information on TCCA, please contact admin@tcca.info

If you want to help shape the future of critical communications – Join us!

© TCCA. Website design: Peacock Carter