Export compliance
“The key reduction was therefore needed to comply with the Wassenaar Arrangement.”
TCCA says TEA1 was conceived to be easily exportable and that its equivalent 32-bit key length permitted worldwide export.
Read the TCCA responseTETRA · TEA1 · Key Reduction
Run real TEA1, watch its 80-bit key collapse into a 32-bit register, then recover that effective key against the same cipher.
FIELD NOTE / TETRA AIR INTERFACE
TETRA is an ETSI trunked-radio standard used in more than 100 countries by police, military, transport, industry, and critical infrastructure. TEA1 is one air-interface stream cipher: it accepts ten key bytes, but its generator receives only one four-byte register.
PANE 01 / COMPLIANCE FIRST
TEA1 is a stream cipher: a key and frame number produce bytes that are XORed with radio traffic. This implementation is a TypeScript port of Midnight Blue's Apache-2.0 reference.
Fixture: frame 0x11111111, zero key, expected d3 3f d8 a6 05 a0 a1 bb 90 23.
PANE 02 / THE HEADLINE
Feed the ten key bytes into the exact initialization loop. Each round shifts the register and appends one S-box byte; after all ten rounds, only four bytes remain.
Register starts at 0x00000000.
| Round | Input | S-box index | S-box byte | Register after |
|---|
PANE 03 / SEARCH AND RECORD
For browser tractability, the page selects the 216 window containing its local fixture's register. Every candidate in that window is checked with the same TEA1 core; the full space contains 65,536 such windows.
0 / 65,536 tested
Ready. The full 32-bit space contains 65,536 windows of this size.
A previous result was retired because an input changed.
0 / 0 bytes reproduced
OK-AND-BROKEN — the cipher output matches byte-for-byte, and the working key is only 32 bits.
ONE LINE OF CODE / TWO FRAMINGS
“The key reduction was therefore needed to comply with the Wassenaar Arrangement.”
TCCA says TEA1 was conceived to be easily exportable and that its equivalent 32-bit key length permitted worldwide export.
Read the TCCA response“A computational step which serves no other purpose than to reduce the key's effective entropy.”
The researchers characterize that intentional reduction as a backdoor. This lab shows the step and leaves the label to the evidence.
Read TETRA:BURSTTHE DISCLOSURE RECORD
The professional radio standard goes on to serve public safety, military, transport, industry, and critical infrastructure in more than 100 countries.
Carlo Meijer, Wouter Bokslag, and Jos Wetzels disclose CVE-2022-24402, the TEA1 80→32-bit reduction, and CVE-2022-24401, an unauthenticated network-time route to induced keystream reuse.
The same researchers report algorithm ID 135 reducing AES-128 traffic-key entropy to 56 bits (associated with CVE-2025-52941), alongside replay and injection findings. This lab reports that result; it does not re-derive it.
Record status checked 22 September 2026: the central 2025 CVE entries remain reserved, so these mappings are attributed to the researchers.
REAL-WORLD BOUNDARY
This page uses local fixtures only. It includes no radio receiver, no deployed-network traffic, no TEA2, and no full TETRA stack. It does not imply that AES or modern radio cryptography shares TEA1's flaw.
PANE 04 / EXTRAPOLATION
Exhibit 3 tested a measured number of candidates in a measured amount of time. That is one rate, from one browser, on one machine. This pane divides larger keyspaces by that rate. Nothing here is a second search and nothing here is a prediction — every row is an extrapolation, and the arithmetic is printed beside it.
—
Bar length is the keyspace exponent on a log2 scale, 0 to 256 bits. The two marks are your own machine’s: the keyspace this rate clears in one second, and in one year.
WHAT THIS PANE DOES NOT SHOW
PANE 05 / PUBLISHED CRYPTANALYSIS
“Broken” means one thing in a paper and another on a radio. Every row below is a published key-recovery attack on AES at its full round count, read out of the primary paper’s own summary table. Each sits under its brute-force line — and none of them finishes.
Bar length is log2 of the attack’s stated time complexity, 0 to 256. The dashed rule in each group is that key size’s brute-force line.
| Target | Attack | Model | Goal | Time | Data | Memory | Source |
|---|
SAME WORD / DIFFERENT UNIVERSES
The reduction in Exhibit 2 moves the real cost of TEA1 to 232. At the rate your own browser measured, that is —. Exhibit 3 already finished a window of it while you watched.
Run Exhibit 3 to fill in your machine’s number.
The best published single-key attack moves AES’s cost to — — — below the brute-force line. At your measured rate that is —.
Academically broken. Practically untouched. The reduction in TEA1 was a different kind of event.
WHAT THIS PANE DOES NOT SHOW