Algorithms and codes

Secure communications with ETSI codes and trusted encryption algorithms

Enabling Secure Communications

Codes

ETSI algorithms & codes service assigns and manages codes for various technologies used in the communications industry to convey information about systems and equipment.

  • Cost: EUR 200 per code (VAT excluded, administrative fees included).
  • Requirement: Customers must sign a contract and meet specified approval conditions.

ETSI’s Centre for Testing and Interoperability (CTI) assigns and registers codes for ETSI Technical Committees without requiring a contract or payment.

Algorithms

 A security algorithm encrypts data using a mathematical procedure, encoding it so that a software key is required to decode it back into its original form. Encryption ensures effective and secure user authentication and is crucial for technology security.

ETSI as Custodian:

  • Distributes and licenses algorithms developed by ETSI or other organisations.
  • Manages specifications and confidential information.
  • Cost: EUR 2 000 per algorithm (VAT excluded, administrative fees included).
  • Requirement: Customers must sign a contract and meet specified approval conditions.

Export Licence:

  • Required for countries outside the European Union (EU).

If the export authorisation is not granted by the SBDU, ETSI will not refund the administrative fees incurred.

How to order and pay?

Down ArrowORDER

Both the payment and the completed, signed web form are required to obtain the code(s)/algorithm(s).

  1. First of all, CLICK on the PRODUCT you wish to order from this list:
  1. From the drop down list (if any), SELECT the product you wish to order and the quantity (if relevant).
  2. FILL IN all required details in the web form (company’s name, address, etc.). When moving the cursor over the fields, additional information is provided to help better understand what specific information is needed/requested.
    Please note that foreign and special characters are not allowed
    . Kindly ensure all content adheres to the approved English language.
  3. SIGN the electronic form.
  4. SEND the form.
  5. An email will be automatically sent from Adobe Sign to CONFIRM your email address. If you do not receive this email, please check your junk or spam folder.

When the e-mail address has been confirmed, the ETSI Secretariat will automatically receive your order.

Please contact us ([email protected]) to obtain the proforma invoice.

Further details to place your order are available on PDF and detailed instructions on completing the web form and making the payment are available by watching this video.

For payment instructions only, watch this video, or access our online payment platform.

IMPORTANT

  • Please note that completing the web form is essential to obtain the code or the algorithm, and is separate from the payment process. You will receive the contract only at the final stage, after it has been countersigned by an ETSI legal representative and the payment has been processed.
  • If you require an invoice with your PO number, please send us this information as soon as possible in order to speed up the process. For a faster service, we recommend a payment via ETSI WEBstore (secured platform). Once the payment is received, the “web form” will be digitally countersigned by a duly authorised ETSI representative. You will then receive an e-mail from “Adobe Sign” with the contract (web form) containing the code(s) on the final page and the algorithms send via a secure platform.

Down ArrowPAYMENT

The administrative charge is EUR 200 for each code ordered and EUR 2 000 for each algorithm ordered. Payment can be done with the following methods:

✓ by credit card: accepted through the designated payment service when the request is made online via the ETSI WEBstore;

✓ by wire transfer: to the bank account as designated in ETSI’s invoice within thirty (30) days after issuing of the said invoice by ETSI.

Please contact us ([email protected]) to obtain the proforma invoice.

Further details to place your order are available on PDF and detailed instructions on completing the web form and making the payment are available by watching this video.

For payment instructions only, watch this video, or access our online payment platform.

Codes [non-public - public]

Shield with padlock - icon

Non-public codes

Here are some characteristics and contexts where non-public codes might be used:

  • Encryption: Encrypting and decrypting data to ensure only authorised access.
  • Authentication: Verifying the identity of users or devices.
  • Access Control: Granting or restricting access to resources or systems.
  • Fraud Prevention: Detecting and preventing fraudulent activities in financial transactions and networks.
  • Data Privacy: Ensuring the privacy and integrity of user data in telecommunications and online services.

Non-public codes are crucial for maintaining the security and integrity of sensitive information and systems.

Information related to these codes can be found in the following specifications:

Public codes

The list of public codes already assigned can be consulted here.
Information related to these codes can be found in the following specifications:
DMR (Digital Mobile Radio) MFID: TS 102 361-1.
TETRATM FAC (Final Assembly Code): EN 300 392-2.
TETRATM Location System Coding scheme (Equipment Manufacturer Code): EN 300 392-2.
TETRATM proprietary AT command name family: TS 100 392 5.
TETRATM proprietary element owner: EN 300 392-2.
TETRATM SDS-TL protocol identifier: EN 300 392-2.

For further information, please contact Algorithms & codes service.

Protocol Naming and Numbering Service

ETSI’s Centre for Testing and Interoperability (CTI) assigns and registers ASN.1 object identifiers, protocol numbers, XML and URI namespaces, etc. for all ETSI Technical Bodies (TBs). ETSI CTI also allocates CNI codes for the broadcast industry.

Many protocols require the allocation of globally unique names or numbers in order to interoperate successfully. Ranges of names or numbers are often allocated to standards bodies in order to distribute the task of allocation, while still maintaining global uniqueness. 

In addition, ETSI CTI can manage, on behalf of an ETSI TB, a request for a protocol name or number allocation from another issuing authority. For example, allocations of Network Management Parameters or allocations for Diameter, XCAP, H.248 protocols can be managed.

All details related to these codes can be found on the Protocol Naming and Numbering page on the ETSI Portal.

To request one of these codes, please contact [email protected]

TETRA Algorithms

The TEA1 / TEA3 / TEA4 / TEA6 / TEA7 / TAA1 and TAA2 algorithms are distributed by ETSI.

Please note that ETSI is NOT the Custodian for the TEA2 and TEA5 algorithms.

For further details, please contact TCCA at [email protected].

Information related to TETRATM  algorithms can be found in the following specifications:

3GPP cellular algorithms

The 256-bit algorithms 256-NEA4, 256-NIA4, 256-NCA4, 256-NEA5, 256-NIA5, 256 NCA5, 256-NEA6, 256-NIA6, 256-NCA6 were developed for 5G in order to provide Confidentiality, Integrity and Authenticated Encryption protection of user-plane data and/or control plane data.

These algorithms can be organised in three families: firstly the 256-NEA1, 256-NIA1, and 256-NCA1 based on the Snow 5G. Secondly the 256-NEA2, 256-NIA2, and 256-NCA2 based on the AES-256 as the key stream generator, and thirdly the 256-NEA3, 256-NIA3, and 256 NCA3 based on the ZUC-256.

The specification of the 3GPP 256-bit Confidentiality and Integrity algorithms for the Air Interface is divided into three separate documents. Each document either specifies elements of the algorithm or provides reference code data and test data of the algorithm.

The 3GPP specifications for the 256-bit security algorithms are:

Specification of the Snow 5G based 256-bits algorithm set: The 256-NEA4 encryption algorithm, the 256-NIA4 integrity algorithm, and the 256-NCA4 authenticated encryption algorithm for 5G:

  • 3GPP TS 35.240: algorithm specification;
  • 3GPP TS 35.241: implementation test data;
  • 3GPP TS 35.242: design conformance test data.

Specification of the AES based 256-bits algorithm set: The 256-NEA5 encryption algorithm, the 256-NIA5 integrity algorithm, and the 256-NCA5 authenticated encryption algorithm for 5G:

  • 3GPP TS 35.243: algorithm specification;
  • 3GPP TS 35.244: implementation test data;
  • 3GPP TS 35.245: design conformance test data.

Specification of the ZUC based 256-bits algorithm set: The 256-NEA6 encryption algorithm, the 256-NIA6 integrity algorithm, and the 256-NCA6 authenticated encryption algorithm for 5G:

  • 3GPP TS 35.246: algorithm specification;
  • 3GPP TS 35.247: implementation test data;
  • 3GPP TS 35.248: design conformance test data.

The algorithms A5/3-GEA3, A5/4-GEA4, UEA1 & UIA1, UEA2 & UIA2, EEA3 & EIA3, as well as the authentication algorithm sets MILENAGE and TUAK, are specified in the 3GPP security specification series (TS 35.xxx).

These specifications describe the confidentiality, integrity protection, and authentication mechanisms used in UMTS™, LTE™, and 5G mobile communication systems.

The algorithm specifications and supporting documentation are publicly available free of charge through the relevant 3GPP Technical Specifications (TS) and Technical Reports (TR) listed below.

  • A5/3 and GEA3 are encryption algorithms for GSM and GPRS respectively based on the KASUMI block cipher.

    The algorithms are specified in 3GPP TS 55.216.

    Please note that customers are required to sign a Restricted Usage Undertaking and pay an associated administrative fee. For further details please refer to the GSMA website.

  • A5/4 is an encryption algorithm for GSM/ECSD and GEA4 is an encryption algorithm for GPRS. Each of these algorithms is based on the KASUMI block cipher.

    The algorithms are specified in 3GPP TS 55.226.

    Please note that customers are required to sign a Restricted Usage Undertaking and pay an associated administrative fee. For further details please refer to the GSMA website.

Information related to UMTS™  and LTE™  algorithms can be found in the following specifications:

  • UEA2 & UIA2:

    The LTE algorithms 128-EEA1 and 128-EIA1 correspond to UEA2 and UIA2 with a defined mapping of LTE parameters.

    Please note that customers are required to sign a Restricted Usage Undertaking and pay an associated administrative fee. For further details please refer to the GSMA website.

  • EEA3 & EIA3:

    Please note that customers are required to sign a Restricted Usage Undertaking and pay an associated administrative fee. For further details please refer to the GSMA website.

Milenage

MILENAGE is an example algorithm set for authentication and key generation in UMTS, LTE and 5G, providing implementations of the functions f1, f1*, f2, f3, f4, f5 and f5*.

TUAK

TUAK is an alternative algorithm set for UMTS, LTE and 5G authentication and key generation, based on the KECCAK (SHA-3) hash function family.

 

Old generation algorithms

The following algorithms have been removed from the ETSI website; for enquiries about these algorithms please the algorithms and codes service.

  • The DSAA (DECTTM Standard Authentication algorithm)
  • The DSC (DECTTM standard cipher)
  • TESA-7 (TE9 authentication algorithm)
  • USA-4 (UPT authentication algorithm)
  • HIPERLAN (High PERformance Local Area Network)
  • GSM-CTS (Cordial)
  • A5-GMR1 (Encryption Algorithm)

DVB CSA licences

The DVB CSA Descrambling Technology is licensed to manufacturers of decoders and their components, and to providers, designers and other entities engaged in conditional access.

The DVB CSA Scrambling Technology is licensed to manufacturers of scramblers, who will in turn sub-license to the purchasers of scramblers.

To license DVB algorithms please contact:

SISVEL – DVB CSA team [email protected]

SISVEL SpA
Via Sestriere, 100-10060 None Torinese (TO)
Italy