We have all read various views expressed by those involved in the US
that location data are not kept and it is all too difficult to get any
sort of data. Have a read of the article below and maybe ask yourself if
the authors of this article are aware that such location data does
exists and are retained why others have expressed in other forums such
data doesn't exist or if the data did exist the location data isn't
retained.
Government Location Tracking: Cell Phones, GPS Devices, and License Plate Readers:
https://www.aclu.org/government-location-tracking-cell-phones-gps-devices-and-license-plate-readers
GSM(2G)-GPRS(2.5G)-HSCSD/EDGE-WCDMA(3G/UMTS)-HSPA/LTE(3.5G)-LTE-A(4G)- 5G; 5G NSA; 5G SA; 5G-A; IoT; 802.11xx; and now 6G; plus other radio & paging technologies: Analysis of Call Record Attribution, Network Record, Coverage, Masts, Location, Co-location, Movement for Commercial and In Building Solutions, Public and Tribunal Inquiries, Criminal Cases, Civil Cases, Human Rights and Investigation into tracking, lost and missing persons...
Showing posts with label evidence. Show all posts
Showing posts with label evidence. Show all posts
Sunday, December 29, 2013
Sunday, November 03, 2013
Directed Retry
A fundamental and vital goal of any mobile communication network is to maintain communications between the network and the mobile station (MS), whether the MS is dwelling in an area or on the move. To assist the aims and objectives GSM is commonly known to use 'Handover' for which there is a specific GSM standard TS03.09 [cf W-CDMA see 3GPP TS23.009].
The assumption being made for these cause values is that the MS is seeking to obtain a service for speech calls
│7 6 5│ 4 3 2 1│ │
│
│0 0 0│0 0 0 0│ │Radio interface message failure │
│
│0 0 0│0 0 0 1│ │Radio interface failure │
│
│0 0 0│0 0 1 0│ │Uplink quality │
│
│0 0 0│0 0 1 1│ │Uplink strength │
│
│0 0 0│0 1 0 0│ │Downlink quality │
│
│0 0 0│0 1 0 1│ │Downlink strength │
│
│0 0 0│0 1 1 0│ │Distance │
│
│0 0 0│0 1 1 1│ │O and M intervention │
│
│0 0 0│1 0 0 0│ │Response to MSC invocation │
│
│0 0 0│1 0 0 1│ │Call control │
│
│0 0 0│1 0 1 0│ │Radio interface failure, reversion to old channel │
│
│0 0 0│1 0 1 1│ ││
│
│0 0 0│1 1 0 0│ │Better Cell │
│
│0 0 0│1 1 0 1│ │Directed Retry │
│
│0 0 0│1 1 1 0│ ││
│
│0 0 0│1 1 1 1│ │Traffic
Key and germane to handover being successful is that operators can use various handover techniques controlled by handover triggering algorithms. These triggers activiate when detection mechanisms identify propagation or network conditions at the existing cell or for the target cell where neither meet a set criteria for usage. One such condition is referred to by Professor Sami Tabbane in Management of Radio Mobility: The Handover Procedure - 8.1.4.2 Intercell and Intra-BSC Handover "A handover that is triggered for reasons of traffic loading and occurs during call setup is called directed retry."
Examiners are expected to know about Directed Retry, to take account of its possibility when conducting CSA (cell site analysis) investigations and understand its influence and impact on evidence record in call records and associated cell data. A point of contention in evidence for often arises where a defendant states "I was not at the location claimed by the prosecution but was in a different area". Invariably this receives a response "Why does your mobile use the radio coverage from a particular sector (azimuth) from a particular fixed mast (BTS)?" Directed retry makes possible the scenario of having a mobile phone in an adjacent cell from the one shown in the call records. Directed Retry is not a trigger simply triggering every few minutes but arises as Professor Tabbane records, due to traffic loading at the time of call setup.
A mistake that experts and investigators could make would be to ignore the existence of Directed Retry and, even more problematical, not to have asked the question was Directed Retry active at cell/BSC level at the material time of the calls, apart from any intervention within the network.
GSM standards make Directed Retry explicit that which might be implicit to for a GSM radio location area. This logically raises questions how can Directed Retry be configured and activated? Mobile network radio equipment manufacturers offer the capability in their equipment for mobile network engineers to radio fine tune post-installation, and the parameters that can be fine tuned are the Handover triggers of which Directed Retry is one such trigger:
As each equipment manufacturer vary the way fine tuning may be implemented using a GUI to input the trigger parameters is one methiod. Another is to incorporate data into the .mdb or .xls file which has been scripted to produce e.g. an .xml output for uplifting to the radio base station database. This means Directed Retry can be checked that it is active in a particular GSM radio location area. Furthermore, due to continuing radio fine tuning updates to the trigger parameters can occur and older versions of .mdb/.xls maybe recovered from archive.
Experts and Investigators will need to be aware of the triggers Directed Retry (DR) and Forced Directed Retry (FDR) and identify when, in a mobile network, either of these triggers would be implemented and activated for the radio network. This equally means tracking down the equipment manufacturers that offer one form or another or both forms of Directed Retry.
The assumption being made for these cause values is that the MS is seeking to obtain a service for speech calls
│7 6 5│ 4 3 2 1│ │
│
│0 0 0│0 0 0 0│ │Radio interface message failure │
│
│0 0 0│0 0 0 1│ │Radio interface failure │
│
│0 0 0│0 0 1 0│ │Uplink quality │
│
│0 0 0│0 0 1 1│ │Uplink strength │
│
│0 0 0│0 1 0 0│ │Downlink quality │
│
│0 0 0│0 1 0 1│ │Downlink strength │
│
│0 0 0│0 1 1 0│ │Distance │
│
│0 0 0│0 1 1 1│ │O and M intervention │
│
│0 0 0│1 0 0 0│ │Response to MSC invocation │
│
│0 0 0│1 0 0 1│ │Call control │
│
│0 0 0│1 0 1 0│ │Radio interface failure, reversion to old channel │
│
│0 0 0│1 0 1 1│ ││
│
│0 0 0│1 1 0 0│ │Better Cell │
│
│0 0 0│1 1 0 1│ │Directed Retry │
│
│0 0 0│1 1 1 0│ ││
│
│0 0 0│1 1 1 1│ │Traffic
Key and germane to handover being successful is that operators can use various handover techniques controlled by handover triggering algorithms. These triggers activiate when detection mechanisms identify propagation or network conditions at the existing cell or for the target cell where neither meet a set criteria for usage. One such condition is referred to by Professor Sami Tabbane in Management of Radio Mobility: The Handover Procedure - 8.1.4.2 Intercell and Intra-BSC Handover "A handover that is triggered for reasons of traffic loading and occurs during call setup is called directed retry."
Examiners are expected to know about Directed Retry, to take account of its possibility when conducting CSA (cell site analysis) investigations and understand its influence and impact on evidence record in call records and associated cell data. A point of contention in evidence for often arises where a defendant states "I was not at the location claimed by the prosecution but was in a different area". Invariably this receives a response "Why does your mobile use the radio coverage from a particular sector (azimuth) from a particular fixed mast (BTS)?" Directed retry makes possible the scenario of having a mobile phone in an adjacent cell from the one shown in the call records. Directed Retry is not a trigger simply triggering every few minutes but arises as Professor Tabbane records, due to traffic loading at the time of call setup.
A mistake that experts and investigators could make would be to ignore the existence of Directed Retry and, even more problematical, not to have asked the question was Directed Retry active at cell/BSC level at the material time of the calls, apart from any intervention within the network.
GSM standards make Directed Retry explicit that which might be implicit to for a GSM radio location area. This logically raises questions how can Directed Retry be configured and activated? Mobile network radio equipment manufacturers offer the capability in their equipment for mobile network engineers to radio fine tune post-installation, and the parameters that can be fine tuned are the Handover triggers of which Directed Retry is one such trigger:
As each equipment manufacturer vary the way fine tuning may be implemented using a GUI to input the trigger parameters is one methiod. Another is to incorporate data into the .mdb or .xls file which has been scripted to produce e.g. an .xml output for uplifting to the radio base station database. This means Directed Retry can be checked that it is active in a particular GSM radio location area. Furthermore, due to continuing radio fine tuning updates to the trigger parameters can occur and older versions of .mdb/.xls maybe recovered from archive.
Experts and Investigators will need to be aware of the triggers Directed Retry (DR) and Forced Directed Retry (FDR) and identify when, in a mobile network, either of these triggers would be implemented and activated for the radio network. This equally means tracking down the equipment manufacturers that offer one form or another or both forms of Directed Retry.
Labels:
3GPP TS23.009,
call records.,
cell site analysis,
CSA,
directed retry,
evidence,
GPRS,
GSM,
GSM TS03.09,
mobile calls,
wcdma
Saturday, June 01, 2013
Examples of cell site maps used in evidence
Here are another two examples of specifically generated cell site maps
using network infrastructure and radio survey data from a particular
mobile network operator, in this case orange PCS, which formed part of
the jury bundle in an old murder case.
Equal Power Boundary Map
Character (Text) Composite Map
Monday, November 01, 2010
Location Update (LU) and Cell Site Analysis (CSA)
Location Update (LU) and Cell Site Analysis (CSA)
Heine, G; referred to the model "An MS performs LU on several occasions: every time it changes the location area, periodically, when a periodic location update is active, or with IMSI attach/ detach switched on at the time when it is subsequently turned on again."
That statement minimises, thus hides, a considerable body of mobile activity and, importantly, cell site analysis (CSA) suffers when students and practitioners fail to take into account the importance in the depth of knowledge and understanding that is needed to include the important facet of Location Update when conducting CSA. The following may assist students and practitioners with a simplified operational background as to events when Location Update (LU) takes place:
The MS requests a control channel from the BSC. The BTS decodes the CHAN_REQ, calculates the distance MS«BTS (timing advance), and forwards all this information to the BSC. Please note that the CHAN_REQ already indicates which service the MS requests (Location Update, in this case).
After the CHAN_RQD is received and processed, the BSC informs the BTS which channel type and channel number shall be reserved (CHAN_ACT).
The BTS confirms with a CHAN_ACT_ACK that it received and processed the CHAN_ACT.
The BSC sends the IMM_ASS_CMD, which activates the previously reserved channel. The BTS sends this information over an AGCH to the MS. The MS finds “its” IMM_ASS_CMD by means of the request reference, which is already contained in the CHAN_REQ.
Layer 2, the LAPDm connection is activated only now. The MS sends a SABM to the BTS, which (differently from LAPD) already contains data (LOC_UPD_REQ in this case).
The BTS confirms that a LAPDm connection was established by sending an UA message, which repeats the LOC_UPD_REQ.
The BTS passes LOC_UPD_REQ to the BSC. Although this is a transparent MM message, the BSC still processes the LOC_UPD_REQ in parts, because the BSC amongst others, requires the Mobile Station Classmark information. The BSC packs LOC_UPD_REQ, together with the current LAC, and CI into a CL3I message (Attention: the LOC_UPD_REQ from the MS contains the old LAC!) and then sends this within a SCCP CR
message to the MSC. The CR message carries not only the LOC_UPD_REQ to the MSC, but also requests establishment of an SCCP connection.
If the MSC is able to provide the requested SCCP connection,then the CR is answered with a CC. A logical connection from the MS to the MSC/VLR exists from this point in time on. The MSC/VLR answers the LOC_UPD_REQ with an AUTH_REQ This message is conveyed to the BSC via the established SCCP connection.
BSC and BTS transparently forward the AUTH_REQ to the MS. Most important content is the random number parameter (RAND). The MS (more precisely the SIM) calculates the result SRES by feeding RAND and Kj into the algorithm A3, then transparently sends SRES in an AUTH_RSP message to the MSC/VLR. The VLR compares SRES with the value provided by the HLR.
The MSC/VLR switches on ciphering, if the result from the authentication is correct. For this purpose, the MSC/VLR sends information to both, the MS and the BTS.
The BTS extracts its part form the ENCR_CMD message, which is Kc and sends the rest in a CIPH_MOD_CMD message to the MS. The CIPH_MOD_CMD message only contains the information, which cipher algorithm (A5/X) shall be used. The MS confirms, by sending a CIPH_MOD_COM message that ciphering was activated.
If Equipment Check is active, then the MSC/VLR requests the MS to provide its IMEI. This is done in an IDENT_REQ message, which is transparent for the BSS. Please note that the IDENT_REQ message also allows to request the TMSI or the IMSI. The equipment check may be performed at almost any time during the scenario, or in other words, is not tied to this place of the scenario.
The MS transparently transmits its IMEI in an IDENT_RSP message to the MSC/VLR, where it is checked by means of the EIR, whether that equipment is registered stolen or not approved.
The MSC/VLR assigns a TMSI, which is used instead of the IMSI in order to make tracking of subscribers more difficult. TMSI_REAL_CMD is also a transparent message between MSC/VLR and MS. The most important content of this message is the new TMSI. Please note that the assignment of a TMSI may also take place at the end within the LOC_UPD_ACC.
The MS confirms with a TMSI_REAL_COM that the new TMSI was received and stored. If the new TMSI is assigned with a LOC_UPD_ACC, then the TMSI_REAL_COM is obviously sent only after the LOC_UPD_ACC.
Sending of the transparent LOC_UPD_ACC message confirms that the MSC/VLR has stored the new Location Area (LAI). This concludes the Location Update process. The control channel that was occupied on the Air-interface has to be released, after the Location Update scenario has ended. For this purpose, the MSC sends the CLR_CMD message to the BSC. The BSC passes this command in a CHAN_REL to the BTS, which passes it to the MS. By sending a DEACT_SACCH, the BSC requests the BTS to cease sending of SACCH messages (SYS_INFO 5/6).The MS reacts on receiving a CHAN_REL message by sending a DISC (LAPDm).
This requests from the BTS to release its Layer 2 connection. The BTS confirms release of the Layer 2 connection by sending an UA message. Towards the BSC, the BTS confirms release of the Air-interface connection by sending of a REL_IND message. The BSC forwards this acknowledgment in a CLR_CMP to the MSC. The BSC requests the TRX in a RF_CHAN_REL to release the occupied resources on the Air-interface. RLSD requests release of the SCCP resources.
RF_CHAN_REL_ACK confirms release on the Air-interface. RLC confirms release of the SCCP resources.
Labels:
BSC,
BTS,
cell site analysis,
CHAN_ACT_ACK,
evidence,
GSM,
HLR,
IMM_ASS_CMD,
LAPDm,
LOC_UPD_REQ,
location update,
MSC,
SACCH,
SCCP,
SDCCH,
VLR,
wcdma
Friday, June 18, 2010
Cell Site Analysis - .DT1 Files
Cell Site Analysis - .DT1 Files
Why is this electronic file extension (.DT1) and significantly the data it contains important to the law of evidence and its relevance to generated original material obtained in criminal cases, but equally for civil cases, too? I will tell you more about that soon, its introduction into evidence and the technical and evidential arguments raised to get into evidence.
For now, what you can know is it is important to cell site analysis and here is a clue about the device that generated it.
Labels:
.DT1 files,
Anite,
cell site analysis,
civil,
criminal,
evidence,
law of evidence,
Nemo Handy
Subscribe to:
Posts (Atom)