5GDescrambler

5GDescrambler

Locating, Descrambling, and Decoding 5G Scheduling Information

Fritz Windisch1   Thorsten Strufe1

1KASTEL Security Research Labs, Karlsruhe Institute of Technology, Germany

About

In this paper we present a novel technique exploiting algebraic structure to reverse Downlink Control Information (DCI) scrambling in 5G without knowledge of the required input parameters, fully integrated into an open-source end-to-end binary DCI sniffing pipeline. It provides enabling input for subsequent attacks like live tracking of users and supports automatic detection of control channel configurations used.

5GDescrambler is entirely passive and, compared to previous approaches, does not rely on any side-channel leakage.

Citing

BibTeX
@inproceedings{windisch20265GDescrambler,
    author    = {Windisch, Fritz and Strufe, Thorsten},
    booktitle = {Proceedings of the 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26)},
    title     = {5GDescrambler: Locating, Descrambling, and Decoding 5G Scheduling Information},
    year      = {2026},
    doi       = {10.1145/3830454.3846809},
    location  = {The Hague, Netherlands},
    keywords  = {5G, sniffing, scrambling, physical downlink control channel}
}

A long version of the paper including the full appendix is available on arXiv.