5GDescrambler
Locating, Descrambling, and Decoding 5G Scheduling Information
1KASTEL Security Research Labs, Karlsruhe Institute of Technology, Germany
About
In this paper we present a novel technique exploiting algebraic structure to reverse Downlink Control Information (DCI) scrambling in 5G without knowledge of the required input parameters, fully integrated into an open-source end-to-end binary DCI sniffing pipeline. It provides enabling input for subsequent attacks like live tracking of users and supports automatic detection of control channel configurations used.
5GDescrambler is entirely passive and, compared to previous approaches, does not rely on any side-channel leakage.
Citing
@inproceedings{windisch20265GDescrambler, author = {Windisch, Fritz and Strufe, Thorsten}, booktitle = {Proceedings of the 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS '26)}, title = {5GDescrambler: Locating, Descrambling, and Decoding 5G Scheduling Information}, year = {2026}, doi = {10.1145/3830454.3846809}, location = {The Hague, Netherlands}, keywords = {5G, sniffing, scrambling, physical downlink control channel} }
A long version of the paper including the full appendix is available on arXiv.