Sherzod Boltaev, Fan Yiming
The fifth-generation (5G) mobile communication protocol has significantly enhanced security compared with its fourthgeneration (4G) predecessor through several improvements to its authentication mechanism. However, the encryption algorithms implemented in 5G Universal Subscriber Identity Module (USIM) cards remain vulnerable to side-channel attacks. This paper first analyzes the architecture and operational procedure of the 5G Authentication and Key Agreement (AKA) protocol and identifies vulnerabilities in its key-generation phase. Subsequently, correlation power analysis (CPA) is performed on commercial 5G USIM cards, successfully recovering the secret cryptographic parameters. Based on these results, 5G USIM card cloning, network registration, and authentication experiments were successfully conducted, thereby demonstrating the susceptibility of commercial 5G USIM cards to side-channel attacks.