{"id":248,"date":"2018-07-16T12:01:34","date_gmt":"2018-07-16T12:01:34","guid":{"rendered":"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=248"},"modified":"2019-05-15T09:43:45","modified_gmt":"2019-05-15T09:43:45","slug":"gsm-security","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/chapter\/gsm-security\/","title":{"rendered":"GSM Security"},"content":{"raw":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/EzUtfSqw8G0\" target=\"_blank\" rel=\"noopener\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\n<div>\r\n\r\n&nbsp;\r\n\r\n<strong>Introduction<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">The wireless-radio medium is open to all .Being a wireless network, GSM is also sensitive to unauthorized use of resources. GSM offers precise security measures some of which maintains privacy and confidentiality of users\u2019 identity and data while others ensure that only registered users access the network. This module provides detail discussion of GSM\u2019s Security mechanisms and their implementation. The topics covered in this module are:<\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Goals of Security features of GSM<\/span><\/li>\r\n \t<li style=\"text-align: justify;\">Introduction to principles of security namely access control, anonymity authentication and encryption<\/li>\r\n \t<li style=\"text-align: justify;\">Understanding of Security algorithms and mechanisms provided by GSM<\/li>\r\n<\/ul>\r\n<strong>Goals of Security features<\/strong>\r\n\r\n&nbsp;\r\n\r\nThe security features should be provided two sided i.e. from the Operator Side as well as User Side\r\n\r\n&nbsp;\r\n<p class=\"no-indent\"><strong>Operator Side: <\/strong>From operator\u2019s point of view it should be ensured that operators<\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Bill the right person<\/span><\/li>\r\n \t<li style=\"text-align: justify;\">There should be mechanisms to avoid fraud<\/li>\r\n \t<li style=\"text-align: justify;\">Services should be protected from<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify;\"><strong>Subscriber side: <\/strong>The security measures need to be more promising and precise on subscribers side. They should aim at<\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Maintaining privacy and anonymity of user which means that identification and location of the subscriber should be concealed<\/span><\/li>\r\n \t<li style=\"text-align: justify;\">Confidentiality of communication over air should be maintained by providing proper<\/li>\r\n \t<li style=\"text-align: justify;\">encryption methods<\/li>\r\n \t<li style=\"text-align: justify;\">There should be strong access control mechanisms for devices and SIM card<\/li>\r\n \t<li style=\"text-align: justify;\">Only authenticated users should be able to access the network<\/li>\r\n<\/ul>\r\n<\/div>\r\n<strong>Rules of GSM Security<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">The Security features should adhere to the following rules:<\/p>\r\n\r\n<ol>\r\n \t<li style=\"text-align: justify;\">Should not add much load to voice calls or data communication<\/li>\r\n \t<li style=\"text-align: justify;\">Should not increase the error rate<\/li>\r\n \t<li style=\"text-align: justify;\">Should not increase the complexity of system<\/li>\r\n \t<li style=\"text-align: justify;\">Should not demand for more bandwidth<\/li>\r\n \t<li style=\"text-align: justify;\">Should be useful and cost efficient<\/li>\r\n<\/ol>\r\n<strong>Principles of GSM Security<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">GSM provides security under following mechanisms: &amp; PU<\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify;\"><strong>Access Control <\/strong>to SIM card: This is done by use of Personal Identification Number (PIN) to get access to the SIM card<\/li>\r\n \t<li style=\"text-align: justify;\"><strong>Anonymity: <\/strong>Hiding the identity and location of user. This is done by using a TMSI number<\/li>\r\n \t<li style=\"text-align: justify;\"><strong>Authentication:\u00a0<\/strong>of subscriber so as to ensure only registered and authorized users have access to network<\/li>\r\n \t<li style=\"text-align: justify;\"><strong>Encryption <\/strong>of Data and signal to protect them against interception<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify;\">Now we see how security measures described in above outlines are implemented by GSM network<\/p>\r\n&nbsp;\r\n<p class=\"hanging-indent\"><strong>Access control<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">SIM <strong>Subscriber identity module <\/strong>stores confidential information which can be personal as well as network specific. It stores the following information:<\/p>\r\n\r\n<ul>\r\n \t<li>\r\n<p style=\"text-align: justify;\"><strong style=\"font-size: 1em;\">International Mobile Subscriber Identity (IMSI) number:<\/strong><span style=\"font-size: 1em;\">A globally unique identifier allocated to each GSM subscriber. It is permanently stored both in the HLR of the user and in the SIM of the user terminal. Any GSM subscriber can be uniquely identified by its IMSI number. This International Mobile Subscriber Identity (IMSI) number is composed of <\/span>the Mobile<span style=\"font-size: 1em;\">\u00a0Country Code (MCC, three digits), the Mobile Network Code (MNC, two digits) and the Mobile Subscriber Identification Number (MSIN, ten digits).<\/span><\/p>\r\n<\/li>\r\n \t<li style=\"text-align: justify;\"><strong style=\"text-align: initial; font-size: 1em;\">S<\/strong><strong style=\"text-align: initial; font-size: 1em;\">ubscriber Authentication key (K<\/strong><strong style=\"text-align: initial; font-size: 1em;\">i <\/strong><strong style=\"text-align: initial; font-size: 1em;\">)<\/strong><strong style=\"text-align: initial; font-size: 1em;\">: <\/strong><span style=\"text-align: initial; font-size: 1em;\">128 bit shared \u00a0key used for authentication of the\u00a0<\/span>subscriber by the network<\/li>\r\n \t<li style=\"text-align: justify;\"><strong style=\"text-align: initial; font-size: 1em;\">A3 and A8 Security algorithms: <\/strong><span style=\"text-align: initial; font-size: 1em;\">Algorithms used for authentication and generation of cipher key.\u00a0<\/span><\/li>\r\n<\/ul>\r\n<div style=\"text-align: center;\"><strong style=\"text-align: initial; font-size: 1em;\"><em>T<\/em><\/strong><strong style=\"text-align: initial; font-size: 1em;\"><em>herefore it is necessary to protect the SIM card<\/em><\/strong><\/div>\r\n<strong>Access Control Mechanisms<\/strong>\r\n<ul>\r\n \t<li style=\"text-align: justify;\"><strong>P<\/strong><strong>I<\/strong><strong>N (Personal Identification Number): <\/strong>GSM provides provision of protection of SIM card by using a PIN. The user needs to know the PIN to unlock the SIM card. The SIM card automatically \u201cLock Out\u201d after 3 unsuccessful attempts by feeding wrong PIN.<\/li>\r\n \t<li style=\"text-align: justify;\"><strong>PU<\/strong><strong>K (Personal Unlocking \u00a0Key): \u00a0<\/strong>A \u00a0PIN \u00a0unblocking \u00a0key \u00a0should \u00a0be \u00a0entered \u00a0which \u00a0is provided by the user to unlock the SIM which is locked after giving the wrong PIN. If the PUK entered incorrectly a number of times, (normally 10) the access to inform is refused permanently and SIM becomes useless.<\/li>\r\n<\/ul>\r\n<p class=\"hanging-indent\"><strong>Anonymity providing Mechanism<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">To prevent eavesdropping, the identity of the user should be hidden. The identity of user is hidden by use of TSMI (Temporary Mobile Subscriber Identity) in place of IMSI of the user .When a MS makes initial contact with the GSM network, an un encrypted subscriber identifier (IMSI) has to be transmitted.The IMSI is sent only once, then a temporary mobile subscriber identity (TMSI) is assigned (encrypted) and used in the entire range of the MSC. When the MS moves into the range of another MSC a new TMSI is assigned. The IMSI is not sent over the radio interface so as to prevent the user from being traced. A TMSI is used instead of IMSI. It is valid in the area of associated MSC i.e. will be valid only till the user is in the area of MSC for communication .Outside location area, it is used along with LAI (Location Area Identification). The TMSI identifies the user along with the location area. The TMSI is updated every time user moves to a new geographical area. It can contain 4 * 8 bits (4 octets). But all 32 bits as one cannot be allocated. TMSI is stored in SIM and all 1\u2019s in SIM indicates no TMSI. The VLR must be capable of correlating an allocated TMSI with IMSI of MS to which it is allocated. At the time of paging, to localize the mobile phone the TMSI is broadcasted.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Authentication and Encryption GSM ensures authentication of subscriber before it can use any services of the network. At the same time privacy of user data and signal should also be maintained by proper encryption mechanisms. Three security algorithms are documented in GSM specifications for this purpose. They are called A3, A5 and A8. A3 is authentication algorithm, A8 is ciphering key generating algorithm and A5 is a stream cipher for encryption of user data transmitted between mobile and base station. The GSM specifications for security were designed by GSM consortium in secrecy. The consortium used <strong>\u201cSecurity by obscurity\u201d <\/strong>which says algorithm would be difficult to crack if they are not publicly available. Therefore algorithms were made available only to hardware and software manufactures and GSM network operators. A3 and A8 are stored on SIM card and at AUC. A5 is stored on device. A3 and A8 are not that strong therefore the network providers can use their own algorithms or users can use their own algorithms but the encryption algorithmA5 is implemented on device and should be identical for all providers. A3 and A8 are symmetric algorithms using the same key embedded on SIM card.<\/p>\r\n&nbsp;\r\n\r\n<img class=\"aligncenter size-full wp-image-249\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic1.png\" alt=\"\" width=\"210\" height=\"303\" \/>\r\n<p style=\"text-align: center;\"><strong>Figure 2: A8 algorithm<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Both are one way functions which means output can be found if inputs are known but it is impossible to find inputs if output is known. A3 and A8 use <strong>COMP128 <\/strong>which is a keyed hash function.Both are one way functions which means output can be found if inputs are known but it is impossible to find inputs if output is known. A3 and A8 use <strong>COMP128 <\/strong>which is a keyed hash function.It takes 128 bit key and 128 bit RAND number as input and produces 128 bit output. The first 32 bits of 128 bit form SRES i.e. Signed response and next 54 bits forms the cipher key which is used for authentication and encryption.<\/p>\r\n&nbsp;\r\n\r\n<img class=\"aligncenter size-full wp-image-250\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic2.png\" alt=\"\" width=\"210\" height=\"134\" \/>\r\n<p style=\"text-align: center;\"><strong>Figure 3: COMP \u00a0128 algorithm<\/strong><\/p>\r\n&nbsp;\r\n<p class=\"hanging-indent\"><strong>Authentication mechanism<\/strong><\/p>\r\n&nbsp;\r\n\r\nAuthentication is performed using following entities and a technique called <strong>\u201cChallenge Response\u201d<\/strong>\r\n<ul>\r\n \t<li>A3 Algorithm for Authentication<\/li>\r\n \t<li>128 bit key Kistored at SIM card and AUC<\/li>\r\n \t<li>RAND number auto generated by AUC known as Challenge<\/li>\r\n<\/ul>\r\n<strong>Following steps are followed for authentication<\/strong>\r\n<ol>\r\n \t<li style=\"text-align: justify;\">Mobile station sends IMSI to network<\/li>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Network accepts IMSI and find corresponding <\/span><strong style=\"font-size: 1em;\">K<\/strong><strong style=\"font-size: 1em;\">i \u00a0<\/strong><span style=\"font-size: 1em;\">which is 128 bit secret key stored on the SIM card as well as available with the authentication center<\/span><\/li>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">The AUC generates 128 bit random number <\/span><strong style=\"font-size: 1em;\">RAND <\/strong><span style=\"font-size: 1em;\">and sends to the mobile station. This is called \u201cchallenge\u201d<\/span><\/li>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">SIM card accepts this challenge and uses the random number and key Ki as input to A3 algorithm. SIM has a microcontrollerto execute the algorithm A3. It produces 32 bit output called signature response <\/span><strong style=\"font-size: 1em;\">SRES <\/strong><span style=\"font-size: 1em;\">using Ki and RAND as input<\/span><\/li>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Network also calculates output using same inputs i.e. Ki,RAND and algorithm A3.<\/span><\/li>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">MS sends SRES to network<\/span><\/li>\r\n \t<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Network matches both SRES, if matched subscriber is authenticated.<\/span><\/li>\r\n<\/ol>\r\n<p style=\"text-align: justify;\">The above mentioned steps are described in the activity diagram and block diagram shown in Fig. 4&amp;5<\/p>\r\n&nbsp;\r\n\r\n<img class=\"aligncenter wp-image-251 size-full\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic3-e1534140423459.png\" alt=\"\" width=\"403\" height=\"243\" \/>\r\n<p style=\"text-align: center;\"><strong>Figure 4: Authentication via Challenge Response<\/strong><\/p>\r\n<img class=\"aligncenter size-full wp-image-252\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic4.png\" alt=\"\" width=\"480\" height=\"360\" \/>\r\n<p style=\"text-align: center;\"><strong>Figure 5: Authentication mechanism<\/strong><\/p>\r\n&nbsp;\r\n<p class=\"hanging-indent\"><strong> Encryption<\/strong><\/p>\r\n&nbsp;\r\n\r\nThe data and signals are encrypted only between mobile station and base station.\r\n\r\n&nbsp;\r\n\r\n<img class=\"aligncenter size-full wp-image-253\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic5.png\" alt=\"\" width=\"289\" height=\"112\" \/>\r\n<p style=\"text-align: center;\"><em>There is no end-to-end encryption<\/em><\/p>\r\n\r\n<div>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Therefore mechanisms for encryption need to be performed both at base station and mobile station. The algorithms A5 and A8 are used for encryption.Any encryption algorithm needs a cipher key. This cipher key is not statically available. It is dynamically generated using A8 algorithm. It takes 128 bit key Ki and 128 bit RAND to generate 54 bit cipher key. Then 10 zero bits are appended to the key to make it 64 bit. This is done to reduce the key space from 64 bits to 54 bits.<\/p>\r\n\r\n<\/div>\r\n<p class=\"hanging-indent\"><strong>A5 algorithm<\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">A5 is the encryption algorithm. It is a stream cipher. It works on bit-by-bit basis. A5 is stored on hardware as it has to encrypt and decrypt data during transmission and reception of information, which must be fast enough. A5 takes 64-bit cipher key and 22 bit function key as input and 114 bit plain text to generate 114-bit cipher text (Fig.7). The encryption decryption processes are performed both at Base station and Mobile station.<\/p>\r\n&nbsp;\r\n<p class=\"hanging-indent\"><strong><em>A5 is not implemented as block cipher<\/em><\/strong><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">The reason being that bit error rate on the wireless links is high. If there is an error of single bit in the cipher text it affects an entire clear text frame. In contrast to it, by using a Stream cipher, a single bit error in the cipher text affects only one\u00a0 single clear text\u00a0 bit. Therefore stream cipher is used for encryption in GSM. There are many implementation of algorithm. Most common one being A5\/0 A5\/1 A5\/2 A5\/3 A5\/1 is the strongest one. A5\/0 is literally no encryption.<img class=\"aligncenter wp-image-254 \" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic6-e1534140456539.png\" alt=\"\" width=\"734\" height=\"450\" \/><\/p>\r\n<p style=\"text-align: center;\"><strong>Figure 7: A5 algorithm<\/strong><\/p>\r\n\r\n<div>\r\n\r\n<strong>S<\/strong><strong>t<\/strong><strong>ep<\/strong><strong>s followed during encryption<\/strong>\r\n<ul>\r\n \t<li style=\"text-align: justify;\">Network initiates a ciphering mode request command<\/li>\r\n \t<li style=\"text-align: justify;\">Mobile station receives this command<\/li>\r\n \t<li style=\"text-align: justify;\">Network sends RAND number generated to generate the cipher key<\/li>\r\n \t<li style=\"text-align: justify;\">Mobile station uses RAND, Ki and RAND the network also generates Kc and distributes to BS<\/li>\r\n \t<li style=\"text-align: justify;\"><span style=\"text-align: initial; font-size: 1em;\">As long as user is authenticated Kc remains same. If authentication is done again, another cipher key would be generated. During handovers if the mobile station has moved to a different base station but there is no need to authenticate it again, then the same key can be used by the new base station. The key would be forwarded to the new base station<\/span><\/li>\r\n \t<li style=\"text-align: justify;\">Once the cipher key is generated, it can be used to encrypt the data and signal using A5 algorithm.<\/li>\r\n<\/ul>\r\n<img class=\"aligncenter size-full wp-image-255\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic7.png\" alt=\"\" width=\"466\" height=\"296\" \/>\r\n<p class=\"hanging-indent\"><strong>GSM security issues<\/strong><\/p>\r\n\r\n<ul>\r\n \t<li>Security is not implemented in fixed part<\/li>\r\n \t<li>Encryption only between base station and mobile Length of Kc (cipher key) is 64 bits which is not sufficient enough<\/li>\r\n \t<li>Authentication is from mobile station to network and vice versa is not possible<\/li>\r\n \t<li><span style=\"font-size: 1em;\">No measures to maintain Integrity is provided<\/span><\/li>\r\n \t<li><span style=\"font-size: 1em;\">Ciphering algorithms are not available for public<\/span><\/li>\r\n<\/ul>\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on GSM Security<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/EzUtfSqw8G0\" target=\"_blank\" rel=\"noopener\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<strong>Suggested Reading:<\/strong>\r\n<ol>\r\n \t<li>\"Mobile Communications\u201d, 2nd edition, by Jochen Schiller<\/li>\r\n \t<li>Asoke K Talukder, Hasan Ahmed, Roopa R Yavagal, \u201cMobile Computing: Technology, Applications and Service Creation\u201d, 2nd ed, Tata McGraw Hill, 2010<\/li>\r\n \t<li>Rajkamal, \u201cMobile Computing\u201d 2nd ed, Oxford Press<\/li>\r\n \t<li>http:\/\/www.tml.tkk.fi\/Opinnot\/Tik-110.501\/1999\/papers\/gsminterception\/netsec.html<\/li>\r\n<\/ol>\r\n<\/div>","rendered":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/EzUtfSqw8G0\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<div>\n<p>&nbsp;<\/p>\n<p><strong>Introduction<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">The wireless-radio medium is open to all .Being a wireless network, GSM is also sensitive to unauthorized use of resources. GSM offers precise security measures some of which maintains privacy and confidentiality of users\u2019 identity and data while others ensure that only registered users access the network. This module provides detail discussion of GSM\u2019s Security mechanisms and their implementation. The topics covered in this module are:<\/p>\n<ul>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Goals of Security features of GSM<\/span><\/li>\n<li style=\"text-align: justify;\">Introduction to principles of security namely access control, anonymity authentication and encryption<\/li>\n<li style=\"text-align: justify;\">Understanding of Security algorithms and mechanisms provided by GSM<\/li>\n<\/ul>\n<p><strong>Goals of Security features<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>The security features should be provided two sided i.e. from the Operator Side as well as User Side<\/p>\n<p>&nbsp;<\/p>\n<p class=\"no-indent\"><strong>Operator Side: <\/strong>From operator\u2019s point of view it should be ensured that operators<\/p>\n<ul>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Bill the right person<\/span><\/li>\n<li style=\"text-align: justify;\">There should be mechanisms to avoid fraud<\/li>\n<li style=\"text-align: justify;\">Services should be protected from<\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><strong>Subscriber side: <\/strong>The security measures need to be more promising and precise on subscribers side. They should aim at<\/p>\n<ul>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Maintaining privacy and anonymity of user which means that identification and location of the subscriber should be concealed<\/span><\/li>\n<li style=\"text-align: justify;\">Confidentiality of communication over air should be maintained by providing proper<\/li>\n<li style=\"text-align: justify;\">encryption methods<\/li>\n<li style=\"text-align: justify;\">There should be strong access control mechanisms for devices and SIM card<\/li>\n<li style=\"text-align: justify;\">Only authenticated users should be able to access the network<\/li>\n<\/ul>\n<\/div>\n<p><strong>Rules of GSM Security<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">The Security features should adhere to the following rules:<\/p>\n<ol>\n<li style=\"text-align: justify;\">Should not add much load to voice calls or data communication<\/li>\n<li style=\"text-align: justify;\">Should not increase the error rate<\/li>\n<li style=\"text-align: justify;\">Should not increase the complexity of system<\/li>\n<li style=\"text-align: justify;\">Should not demand for more bandwidth<\/li>\n<li style=\"text-align: justify;\">Should be useful and cost efficient<\/li>\n<\/ol>\n<p><strong>Principles of GSM Security<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">GSM provides security under following mechanisms: &amp; PU<\/p>\n<ul>\n<li style=\"text-align: justify;\"><strong>Access Control <\/strong>to SIM card: This is done by use of Personal Identification Number (PIN) to get access to the SIM card<\/li>\n<li style=\"text-align: justify;\"><strong>Anonymity: <\/strong>Hiding the identity and location of user. This is done by using a TMSI number<\/li>\n<li style=\"text-align: justify;\"><strong>Authentication:\u00a0<\/strong>of subscriber so as to ensure only registered and authorized users have access to network<\/li>\n<li style=\"text-align: justify;\"><strong>Encryption <\/strong>of Data and signal to protect them against interception<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">Now we see how security measures described in above outlines are implemented by GSM network<\/p>\n<p>&nbsp;<\/p>\n<p class=\"hanging-indent\"><strong>Access control<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">SIM <strong>Subscriber identity module <\/strong>stores confidential information which can be personal as well as network specific. It stores the following information:<\/p>\n<ul>\n<li>\n<p style=\"text-align: justify;\"><strong style=\"font-size: 1em;\">International Mobile Subscriber Identity (IMSI) number:<\/strong><span style=\"font-size: 1em;\">A globally unique identifier allocated to each GSM subscriber. It is permanently stored both in the HLR of the user and in the SIM of the user terminal. Any GSM subscriber can be uniquely identified by its IMSI number. This International Mobile Subscriber Identity (IMSI) number is composed of <\/span>the Mobile<span style=\"font-size: 1em;\">\u00a0Country Code (MCC, three digits), the Mobile Network Code (MNC, two digits) and the Mobile Subscriber Identification Number (MSIN, ten digits).<\/span><\/p>\n<\/li>\n<li style=\"text-align: justify;\"><strong style=\"text-align: initial; font-size: 1em;\">S<\/strong><strong style=\"text-align: initial; font-size: 1em;\">ubscriber Authentication key (K<\/strong><strong style=\"text-align: initial; font-size: 1em;\">i <\/strong><strong style=\"text-align: initial; font-size: 1em;\">)<\/strong><strong style=\"text-align: initial; font-size: 1em;\">: <\/strong><span style=\"text-align: initial; font-size: 1em;\">128 bit shared \u00a0key used for authentication of the\u00a0<\/span>subscriber by the network<\/li>\n<li style=\"text-align: justify;\"><strong style=\"text-align: initial; font-size: 1em;\">A3 and A8 Security algorithms: <\/strong><span style=\"text-align: initial; font-size: 1em;\">Algorithms used for authentication and generation of cipher key.\u00a0<\/span><\/li>\n<\/ul>\n<div style=\"text-align: center;\"><strong style=\"text-align: initial; font-size: 1em;\"><em>T<\/em><\/strong><strong style=\"text-align: initial; font-size: 1em;\"><em>herefore it is necessary to protect the SIM card<\/em><\/strong><\/div>\n<p><strong>Access Control Mechanisms<\/strong><\/p>\n<ul>\n<li style=\"text-align: justify;\"><strong>P<\/strong><strong>I<\/strong><strong>N (Personal Identification Number): <\/strong>GSM provides provision of protection of SIM card by using a PIN. The user needs to know the PIN to unlock the SIM card. The SIM card automatically \u201cLock Out\u201d after 3 unsuccessful attempts by feeding wrong PIN.<\/li>\n<li style=\"text-align: justify;\"><strong>PU<\/strong><strong>K (Personal Unlocking \u00a0Key): \u00a0<\/strong>A \u00a0PIN \u00a0unblocking \u00a0key \u00a0should \u00a0be \u00a0entered \u00a0which \u00a0is provided by the user to unlock the SIM which is locked after giving the wrong PIN. If the PUK entered incorrectly a number of times, (normally 10) the access to inform is refused permanently and SIM becomes useless.<\/li>\n<\/ul>\n<p class=\"hanging-indent\"><strong>Anonymity providing Mechanism<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">To prevent eavesdropping, the identity of the user should be hidden. The identity of user is hidden by use of TSMI (Temporary Mobile Subscriber Identity) in place of IMSI of the user .When a MS makes initial contact with the GSM network, an un encrypted subscriber identifier (IMSI) has to be transmitted.The IMSI is sent only once, then a temporary mobile subscriber identity (TMSI) is assigned (encrypted) and used in the entire range of the MSC. When the MS moves into the range of another MSC a new TMSI is assigned. The IMSI is not sent over the radio interface so as to prevent the user from being traced. A TMSI is used instead of IMSI. It is valid in the area of associated MSC i.e. will be valid only till the user is in the area of MSC for communication .Outside location area, it is used along with LAI (Location Area Identification). The TMSI identifies the user along with the location area. The TMSI is updated every time user moves to a new geographical area. It can contain 4 * 8 bits (4 octets). But all 32 bits as one cannot be allocated. TMSI is stored in SIM and all 1\u2019s in SIM indicates no TMSI. The VLR must be capable of correlating an allocated TMSI with IMSI of MS to which it is allocated. At the time of paging, to localize the mobile phone the TMSI is broadcasted.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Authentication and Encryption GSM ensures authentication of subscriber before it can use any services of the network. At the same time privacy of user data and signal should also be maintained by proper encryption mechanisms. Three security algorithms are documented in GSM specifications for this purpose. They are called A3, A5 and A8. A3 is authentication algorithm, A8 is ciphering key generating algorithm and A5 is a stream cipher for encryption of user data transmitted between mobile and base station. The GSM specifications for security were designed by GSM consortium in secrecy. The consortium used <strong>\u201cSecurity by obscurity\u201d <\/strong>which says algorithm would be difficult to crack if they are not publicly available. Therefore algorithms were made available only to hardware and software manufactures and GSM network operators. A3 and A8 are stored on SIM card and at AUC. A5 is stored on device. A3 and A8 are not that strong therefore the network providers can use their own algorithms or users can use their own algorithms but the encryption algorithmA5 is implemented on device and should be identical for all providers. A3 and A8 are symmetric algorithms using the same key embedded on SIM card.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-249\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic1.png\" alt=\"\" width=\"210\" height=\"303\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic1.png 210w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic1-208x300.png 208w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic1-65x94.png 65w\" sizes=\"auto, (max-width: 210px) 100vw, 210px\" \/><\/p>\n<p style=\"text-align: center;\"><strong>Figure 2: A8 algorithm<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Both are one way functions which means output can be found if inputs are known but it is impossible to find inputs if output is known. A3 and A8 use <strong>COMP128 <\/strong>which is a keyed hash function.Both are one way functions which means output can be found if inputs are known but it is impossible to find inputs if output is known. A3 and A8 use <strong>COMP128 <\/strong>which is a keyed hash function.It takes 128 bit key and 128 bit RAND number as input and produces 128 bit output. The first 32 bits of 128 bit form SRES i.e. Signed response and next 54 bits forms the cipher key which is used for authentication and encryption.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-250\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic2.png\" alt=\"\" width=\"210\" height=\"134\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic2.png 210w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic2-65x41.png 65w\" sizes=\"auto, (max-width: 210px) 100vw, 210px\" \/><\/p>\n<p style=\"text-align: center;\"><strong>Figure 3: COMP \u00a0128 algorithm<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p class=\"hanging-indent\"><strong>Authentication mechanism<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Authentication is performed using following entities and a technique called <strong>\u201cChallenge Response\u201d<\/strong><\/p>\n<ul>\n<li>A3 Algorithm for Authentication<\/li>\n<li>128 bit key Kistored at SIM card and AUC<\/li>\n<li>RAND number auto generated by AUC known as Challenge<\/li>\n<\/ul>\n<p><strong>Following steps are followed for authentication<\/strong><\/p>\n<ol>\n<li style=\"text-align: justify;\">Mobile station sends IMSI to network<\/li>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Network accepts IMSI and find corresponding <\/span><strong style=\"font-size: 1em;\">K<\/strong><strong style=\"font-size: 1em;\">i \u00a0<\/strong><span style=\"font-size: 1em;\">which is 128 bit secret key stored on the SIM card as well as available with the authentication center<\/span><\/li>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">The AUC generates 128 bit random number <\/span><strong style=\"font-size: 1em;\">RAND <\/strong><span style=\"font-size: 1em;\">and sends to the mobile station. This is called \u201cchallenge\u201d<\/span><\/li>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">SIM card accepts this challenge and uses the random number and key Ki as input to A3 algorithm. SIM has a microcontrollerto execute the algorithm A3. It produces 32 bit output called signature response <\/span><strong style=\"font-size: 1em;\">SRES <\/strong><span style=\"font-size: 1em;\">using Ki and RAND as input<\/span><\/li>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Network also calculates output using same inputs i.e. Ki,RAND and algorithm A3.<\/span><\/li>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">MS sends SRES to network<\/span><\/li>\n<li style=\"text-align: justify;\"><span style=\"font-size: 1em;\">Network matches both SRES, if matched subscriber is authenticated.<\/span><\/li>\n<\/ol>\n<p style=\"text-align: justify;\">The above mentioned steps are described in the activity diagram and block diagram shown in Fig. 4&amp;5<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-251 size-full\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic3-e1534140423459.png\" alt=\"\" width=\"403\" height=\"243\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic3-e1534140423459.png 403w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic3-e1534140423459-300x181.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic3-e1534140423459-65x39.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic3-e1534140423459-225x136.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic3-e1534140423459-350x211.png 350w\" sizes=\"auto, (max-width: 403px) 100vw, 403px\" \/><\/p>\n<p style=\"text-align: center;\"><strong>Figure 4: Authentication via Challenge Response<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-252\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic4.png\" alt=\"\" width=\"480\" height=\"360\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic4.png 480w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic4-300x225.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic4-65x49.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic4-225x169.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic4-350x263.png 350w\" sizes=\"auto, (max-width: 480px) 100vw, 480px\" \/><\/p>\n<p style=\"text-align: center;\"><strong>Figure 5: Authentication mechanism<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p class=\"hanging-indent\"><strong> Encryption<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>The data and signals are encrypted only between mobile station and base station.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-253\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic5.png\" alt=\"\" width=\"289\" height=\"112\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic5.png 289w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic5-65x25.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic5-225x87.png 225w\" sizes=\"auto, (max-width: 289px) 100vw, 289px\" \/><\/p>\n<p style=\"text-align: center;\"><em>There is no end-to-end encryption<\/em><\/p>\n<div>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Therefore mechanisms for encryption need to be performed both at base station and mobile station. The algorithms A5 and A8 are used for encryption.Any encryption algorithm needs a cipher key. This cipher key is not statically available. It is dynamically generated using A8 algorithm. It takes 128 bit key Ki and 128 bit RAND to generate 54 bit cipher key. Then 10 zero bits are appended to the key to make it 64 bit. This is done to reduce the key space from 64 bits to 54 bits.<\/p>\n<\/div>\n<p class=\"hanging-indent\"><strong>A5 algorithm<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">A5 is the encryption algorithm. It is a stream cipher. It works on bit-by-bit basis. A5 is stored on hardware as it has to encrypt and decrypt data during transmission and reception of information, which must be fast enough. A5 takes 64-bit cipher key and 22 bit function key as input and 114 bit plain text to generate 114-bit cipher text (Fig.7). The encryption decryption processes are performed both at Base station and Mobile station.<\/p>\n<p>&nbsp;<\/p>\n<p class=\"hanging-indent\"><strong><em>A5 is not implemented as block cipher<\/em><\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">The reason being that bit error rate on the wireless links is high. If there is an error of single bit in the cipher text it affects an entire clear text frame. In contrast to it, by using a Stream cipher, a single bit error in the cipher text affects only one\u00a0 single clear text\u00a0 bit. Therefore stream cipher is used for encryption in GSM. There are many implementation of algorithm. Most common one being A5\/0 A5\/1 A5\/2 A5\/3 A5\/1 is the strongest one. A5\/0 is literally no encryption.<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-254\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic6-e1534140456539.png\" alt=\"\" width=\"734\" height=\"450\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic6-e1534140456539.png 445w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic6-e1534140456539-300x184.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic6-e1534140456539-65x40.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic6-e1534140456539-225x138.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic6-e1534140456539-350x215.png 350w\" sizes=\"auto, (max-width: 734px) 100vw, 734px\" \/><\/p>\n<p style=\"text-align: center;\"><strong>Figure 7: A5 algorithm<\/strong><\/p>\n<div>\n<p><strong>S<\/strong><strong>t<\/strong><strong>ep<\/strong><strong>s followed during encryption<\/strong><\/p>\n<ul>\n<li style=\"text-align: justify;\">Network initiates a ciphering mode request command<\/li>\n<li style=\"text-align: justify;\">Mobile station receives this command<\/li>\n<li style=\"text-align: justify;\">Network sends RAND number generated to generate the cipher key<\/li>\n<li style=\"text-align: justify;\">Mobile station uses RAND, Ki and RAND the network also generates Kc and distributes to BS<\/li>\n<li style=\"text-align: justify;\"><span style=\"text-align: initial; font-size: 1em;\">As long as user is authenticated Kc remains same. If authentication is done again, another cipher key would be generated. During handovers if the mobile station has moved to a different base station but there is no need to authenticate it again, then the same key can be used by the new base station. The key would be forwarded to the new base station<\/span><\/li>\n<li style=\"text-align: justify;\">Once the cipher key is generated, it can be used to encrypt the data and signal using A5 algorithm.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-255\" src=\"http:\/\/itp12.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic7.png\" alt=\"\" width=\"466\" height=\"296\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic7.png 466w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic7-300x191.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic7-65x41.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic7-225x143.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-content\/uploads\/sites\/27\/2018\/07\/M22Pic7-350x222.png 350w\" sizes=\"auto, (max-width: 466px) 100vw, 466px\" \/><\/p>\n<p class=\"hanging-indent\"><strong>GSM security issues<\/strong><\/p>\n<ul>\n<li>Security is not implemented in fixed part<\/li>\n<li>Encryption only between base station and mobile Length of Kc (cipher key) is 64 bits which is not sufficient enough<\/li>\n<li>Authentication is from mobile station to network and vice versa is not possible<\/li>\n<li><span style=\"font-size: 1em;\">No measures to maintain Integrity is provided<\/span><\/li>\n<li><span style=\"font-size: 1em;\">Ciphering algorithms are not available for public<\/span><\/li>\n<\/ul>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on GSM Security<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/EzUtfSqw8G0\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Suggested Reading:<\/strong><\/p>\n<ol>\n<li>&#8220;Mobile Communications\u201d, 2nd edition, by Jochen Schiller<\/li>\n<li>Asoke K Talukder, Hasan Ahmed, Roopa R Yavagal, \u201cMobile Computing: Technology, Applications and Service Creation\u201d, 2nd ed, Tata McGraw Hill, 2010<\/li>\n<li>Rajkamal, \u201cMobile Computing\u201d 2nd ed, Oxford Press<\/li>\n<li>http:\/\/www.tml.tkk.fi\/Opinnot\/Tik-110.501\/1999\/papers\/gsminterception\/netsec.html<\/li>\n<\/ol>\n<\/div>\n","protected":false},"author":4,"menu_order":19,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":["miss-suchit-purohit"],"pb_section_license":""},"chapter-type":[],"contributor":[59],"license":[],"class_list":["post-248","chapter","type-chapter","status-publish","hentry","contributor-miss-suchit-purohit"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/pressbooks\/v2\/chapters\/248","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/wp\/v2\/users\/4"}],"version-history":[{"count":10,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/pressbooks\/v2\/chapters\/248\/revisions"}],"predecessor-version":[{"id":645,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/pressbooks\/v2\/chapters\/248\/revisions\/645"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/pressbooks\/v2\/chapters\/248\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/wp\/v2\/media?parent=248"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/pressbooks\/v2\/chapter-type?post=248"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/wp\/v2\/contributor?post=248"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp12\/wp-json\/wp\/v2\/license?post=248"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}