Showing posts with label wcdma. Show all posts
Showing posts with label wcdma. Show all posts

Tuesday, September 23, 2014

CSA - Site Survey Method/LTE-UMTS SIBs

There is a huge volume of materials and standards to be considered when undertaking study or work as an InnerCity CSA (ICCSA) expert, technician or student. However, the materials and standards referred to at my webblog aim to control the flow of such volumous information and provide instead an easy guide to seeking out the information experts, technicians or students can be exposed to when involved with ICCSA.

A highly defined smartphone etc can be offered services by a range of mobile network access systems e.g. GSM, GERAN, UTRAN, e-UTRAN etc when switched ON and actively in use or in idle mode. Access system information for LTE and UMTS are mapped in System Information Blocks (SIBs). When conducting ICCSA test measurement it is useful to identify which broadcasted SIBs contain data to help understand the survey results. Knowing the content allocated to SIBs can assist enormously in interpretation and when considering the propositions highlighted in the previous discussion thread - http://cellsiteanalysis.blogspot.co.uk/2014/08/csa-site-survey-method4cell-types.html



Below are commonly referred to LTE/UMTS SIBs. GSM and GERAN data are mapped to System Information Types that will be given in the next discsssion.

LTE System Information Blocks
***************************
SIB 1 contains PLMN identity, tracking area code, and CI of the broadcasting cell. Q-RxLevMin minimumRSRP threshold that a broadcasting cell should be measured before initial cell selection, and later for random access performed by UE. SIB Mapping Info included to inform the UE which SIBs are transmitted and how they are scheduled.

SIB 2 contains timers and constants, access barring information, UL frequency information, and UL bandwidth information.

SIB 3 contains parameters for the cell reselection procedure.

SIB 4 contains neighbour cell information for intra-frequency cell reselection.

SIB 5 contains information for interfrequency cell reselection.

SIB 6 contains information for inter-RAT cell reselection to the UTRAN.

SIB 7 contains information for inter-RAT cell reselection to the GERAN.

SIB 8 contains information for inter-RAT cell reselection to CDMA2000.

SIB 9 is used to broadcast the home eNB name (HNB name).

SIB 10 and SIB 11 can be used to broadcast warning information to subscribers (e.g. tsunami warnings).

SIB 12 assigned for Commercial Mobile Alerting System (CMAS) information usage


UMTS System Information Blocks
*****************************
SIB 1 NAS System Information, UE Timer and counter for RRC idle and connected mode

SIB 2 URA Identity

SIB 3 Parameter for Cell Selection and Cell Reselection

SIB 4 Parameter for Cell Selection and Cell Reselection in RRC connected mode

SIB 5 Parameter for configuration of Common Physical Channel (CPCH) of actual cell

SIB 6 Parameter for configuration of Common and shared Physical Channel of actual cell

SIB 7 Fast changing parameter for uplink Interference and Dynamic Persistent Level

SIB 8 Static CPCH Information of actual cell [FDD only]

SIB 9 CPCH Information of actual cell [FDD only]

SIB 10 Information for UE, which DCH is controlled by Dynamic Resource Allocation Control Procedure

SIB 11 Measurement Control Information of actual cell

SIB 12 Measurement Control Information of actual cell in RRC connected mode

SIB 13 ANSI-41 System Information

SIB 13.1 ANSI-41 RAND Information

SIB 13.2 ANSI-41 User Zone Identification

SIB 13.3 ANSI-41 Private Neighbour List

SIB 13.4 ANSI-41 Global Service Redirection

SIB 14 UL outer loop power control information for common and dedicated physical channels in RRC idle and connected mode

SIB 15 Information for UE positioning method

SIB 15.1 Information for UE GPS positioning method with Differential Global Positionig System (DGPS) correction

SIB 15.2 Information for GPS Navigation-Model

SIB 15.3 Information for GPS Almanac, ionospheric and UTC Model

SIB 15.4 Ciphering Information of SIB 15.5

SIB 15.5 Information for OTDOA UE positioning method

SIB 16 Information of Radio Bearer, transport and physical channels for UE in RRC idle or connection mode in case of Handover to UTRA

SIB 17 Fast changing parameter for the configuration of Shared Physical Channels in RRC conected mode [FDD only]

SIB 18 PLMN Identifies neighbour cells

Tuesday, August 19, 2014

CSA - Site Survey Method4/Cell Types

Cell types
GSM reports, as far back as 20 years ago, distinguished three kinds of cells as the growth in GSM installations massively increased following popularity as a preferred digital cellular network: large cells, small (mini) cells and micro cells. The main difference between these kind of cells lay in the cell range, the antenna installation site, and the propagation model applying to each of them. Moreover, these cells could be overlayed one on top of another to provide coverage for varying traffic conditions and illustrated in the previous discussion http://cellsiteanalysis.blogspot.co.uk/2014/07/csa-site-survey-methodmobility-models.html.

CSA has been subjected to understanding cell layer tiering involvement in a particular geographical area and what impact the finding of tiering might have determined from radio test measurement results, and what impact the results might infer for a particular investigation. In the previous discussion on Mobility Models it highlighted a simple issue: why walk tests are important to mimic the pedestrian's experience of obtaining mobile services. Germane and relevant, whilst the mobile networks are highly intelligent networks and use memory and memoryless in their propagation models, CSA examiners, students and experts cannot apply intelligent algorithms in the manual function of their work when conducting site surveys. It is, therefore, necessary to distinguish processes and procedures hidden within the intelligent network functionality that provide us (CSA examiners, students and experts) with knowledge that helps us gain skills and experience in the performance of the work we do.

So  we know "walk tests" are unavoidable (thus inescapable) forming part of the methodology we should apply, where relevant, during site surveys. Whilst this requirement is a basic simple binary style approach to CSA that doesn't mean to suggest mobile networks aren't sophiscated, convoluted, NASA style complex system because mobile networks are very much the latter. These grass root levels are important to CSA. For instance a GSM mobile network may use Cell Selection Procedures C1 and C2. The network can use components from C2  (cell reselection) to identify coverage for a slow moving mobile (e.g. pedestrian/walk test) which can be used to understand the microcell coverage. Drive testing equally needs to be represented for the benefits it provides for CSA.



    



Above, three tiers of cell coverage have been illustrated. Microcells are distnguished as a cell type because predominantly this type of cell in GSM (or CDMA for that matter) is usually represented as localised coverage to a small area. Pedestrian is seen as relevant to it. However, vehicular mobile usage is largely predicted within the network as "fast moving". Let us take the case of the getaway car speeding away from the scene of crime. Would it not seem strange to you to find the target's mobile phone call records identifying a number of Microcell IDs designed to cope with long dwell time in an area associated with slow mobile movements (e.g.5~10mph) compared with Macrocell umbrella coverage designed to handle accelerated speeds (e.g. 30~70mph). Why would the getaway car be driving so slowly after a crime, unless the *bogey wanted to be caught red-handed and why s/he commited the crime in the first place just to be arrested? On first blush of the call record evidence it wouldn't make sense.

*The term bogey has been adopted from the military theatre of war identification procedure representing an un-identified (unknown criminal) target, whereas a bandit is an identified (known criminal) target. In criminal investigations the latter can also suggest surveillance in progress on the target's activities.

But drive testing can throw up unexpected issues. CSA demands keeping an open mind and, as previously mentioned at my blogs, CSA examiner, student and expert should be "not only be environmentally aware, but equally be environmentally astute." A case I dealt with in the North of England concerned a series of smash-n-grabs at wholesale and retail outlets.  From my radio tests I suggested the radio evidence did not follow the getaway route the police required that I test. CSA involves noticing factors that could impede or record a particular route. In this case a speed camera that was in lock-n-load (active) to capture speeding vehicles was located at an early stage on the suggested getaway route. When I asked did the speed camera record a speeding violation, the response came back "no", yet the ascertion by the police was the getaway vehicle was speeding. However, the radio test measurement survey along the complete route did not entirely match the cell IDs in the call records either as some of the cell IDs were for slower mobile traffic and cells covering a middle layer coverage area and the use of these cells suggested the mobile dwell time was not travelling outside a certain geographical area. Eventually, a more senior detective suggested a route that veered away from the first route getaway route. My attention was drawn to an area inbetween local buildings, a mud track leading to a field and a nearby cemetary and housing estate. Infact the bogeys turned out to be previously known bandits and the entire operation of the smash-n-grabs was orchestrated from a house on the estate sited perfectly for comings and goings for the many crimes but quite hard to detect. CSA played an effective part to support other evidence and intel.       




However, umbrella macrocell coverage in a geographical location can be used to support high speed getaways e.g. where CCTV has recorded or an eyewitness had seen the getaway vehicle speeding through dense urban area. Given the speed of the vehicle the network would be detecting the mobile's short dwell time in that area. The omission of use of overlayed microcells providing limited area coverage is a suggestion of fast moving traffic. The use of a macrocell would not be out of place supporting the notion of a fast moving mobile. This can be stated in relation to the density of non-used microcells and their cell boundarys compared to macrocell cell boundaries and, of course, any location updates, time, velocity etc.

Since 2010 Cells types have rapidly moved on with a split between voice/data and data-only cells transforming the way CSA is and will be conducted in the future. For instance, there are increases in carriers (2G frequencies allocation migrating (re-use) to 3G frequencies allocation) Moreover, with LTE linking with WiFi/WLAN etc there are enormous advantages and dis-advantages that have crept into CSA site survey methodology.

 
The impact of these changes requires improved comprehension about the various cells and as higher frequencies are used or are brought into use cell coverage gets smaller. This fact is a benefit because the approximated location of the mobile is improved and significantly improves where smaller cells are relevant. It may not be GPS accuracy but there seems no reason why it could not meet justification under an e.g. Daubert test. Furthermore, it doesn't means CSA should jettison early styles of CSA site survey method which will remain relevant for some years to come. But CSA will become even more localised creating a specialism in InnerCity CSA (ICCSA) compared with rural CSA. A beneficary of  ICCSA knowledge will be the neuromancer cybercrime arena utilising our forensic and investigative skills to comprehend the technicality behind a suspected crime defined by the outcome from particular usage of technology.

Site survey methods do not have to be overly complicated, merely identify the radio technology at given points and by using a structured appraisal, distinguishing each wireless carrier available at particular geographical locations, to show the relevance to an investigaion or crime scene.

So what are the potentially inter-connected Cell types that fall within the scope of CSA large cell and small cell environments:

Macrocells
Minicells
Microcells
Metrocells
Picocells
Nanocells
Femtocells
WIMAX cells
WLAN cells
WiFi cells
etc

And in support of that environment it should not under-estimate the importance of devices capability from providing services and to accessing services. This mean from not simply the network, but the radio network e.g. BTS/(e)NodeB/H(e)NB etc to the enhanced (U)SIM and handset terminal. That requires knowning which Release (R) is relevant to the investigation:

R99    (Release 1999)
Rel-4    (Release 4)
Rel-5    (Release 5)
Rel-6    (Release 6)
Rel-7    (Release 7)
Rel-8    (Release 8)
Rel-9    (Release 9)
Rel-10    (Release 10)
Rel-11    (Release 11)
Rel-12    (Release 12)  
etc

Sunday, November 03, 2013

Directed Retry

A fundamental and vital goal of any mobile communication network is to maintain communications between the network and the mobile station (MS), whether the MS is dwelling in an area or on the move. To assist the aims and objectives GSM is commonly known to use 'Handover' for which there is a specific GSM standard TS03.09 [cf W-CDMA see 3GPP TS23.009].

The assumption being made for these cause values is that the MS is seeking to obtain a service for speech calls

│7 6 5│ 4 3 2 1│ │

│0 0 0│0 0 0 0│ │Radio interface message failure │

│0 0 0│0 0 0 1│ │Radio interface failure │

│0 0 0│0 0 1 0│ │Uplink quality │

│0 0 0│0 0 1 1│ │Uplink strength │

│0 0 0│0 1 0 0│ │Downlink quality │

│0 0 0│0 1 0 1│ │Downlink strength │

│0 0 0│0 1 1 0│ │Distance │

│0 0 0│0 1 1 1│ │O and M intervention │

│0 0 0│1 0 0 0│ │Response to MSC invocation │

│0 0 0│1 0 0 1│ │Call control │

│0 0 0│1 0 1 0│ │Radio interface failure, reversion to old channel │

│0 0 0│1 0 1 1│ ││

│0 0 0│1 1 0 0│ │Better Cell │

│0 0 0│1 1 0 1│ │Directed Retry │

│0 0 0│1 1 1 0│ ││

│0 0 0│1 1 1 1│ │Traffic

Key and germane to handover being successful is that operators can use various handover techniques controlled by handover triggering algorithms. These triggers activiate when detection mechanisms identify propagation or network conditions at the existing cell or for the target cell where neither meet a set criteria for usage. One such condition is referred to by Professor Sami Tabbane in Management of Radio Mobility: The Handover Procedure - 8.1.4.2 Intercell and Intra-BSC Handover "A handover that is triggered for reasons of traffic loading and occurs during call setup is called directed retry." 

Examiners are expected to know about Directed Retry, to take account of its possibility when conducting CSA (cell site analysis) investigations and understand its influence and impact on evidence record in call records and associated cell data. A point of contention in evidence for often arises where a defendant states "I was not at the location claimed by the prosecution but was in a different area". Invariably this receives a response "Why does your mobile use the radio coverage from a particular sector (azimuth) from a particular fixed mast (BTS)?" Directed retry makes possible the scenario of having a mobile phone in an adjacent cell from the one shown in the call records. Directed Retry is not a trigger simply triggering every few minutes but arises as Professor Tabbane records, due to traffic loading at the time of call setup.

A mistake that experts and investigators could make would be to ignore the existence of Directed Retry and, even more problematical, not to have asked the question was Directed Retry active at cell/BSC level at the material time of the calls, apart from any intervention within the network.

GSM standards make Directed Retry explicit that which might be implicit to for a GSM radio location area. This logically raises questions how can Directed Retry be configured and activated? Mobile network radio equipment manufacturers offer the capability in their equipment for mobile network engineers to radio fine tune post-installation, and the parameters that can be fine tuned are the Handover triggers of which Directed Retry is one such trigger:




As each equipment manufacturer vary the way fine tuning may be implemented using a GUI to input the trigger parameters is one methiod. Another is to incorporate data into the .mdb or .xls file which has been scripted to produce e.g. an .xml output for uplifting to the radio base station database. This means Directed Retry can be checked that it is active in a particular GSM radio location area. Furthermore, due to continuing radio fine tuning updates to the trigger parameters can occur and older versions of .mdb/.xls maybe recovered from archive.

Experts and Investigators will need to be aware of the triggers Directed Retry (DR) and Forced Directed Retry (FDR) and identify when, in a mobile network, either of these triggers would be implemented and activated for the radio network. This equally means tracking down the equipment manufacturers that offer one form or another or both forms of Directed Retry.

Sunday, May 08, 2011

Requesting Cell Site Data

Requesting Cell Site Data


Engaging with defence solicitors or law enforcement with respect to seeking cell site evidence can be a tricky business. Invariably the request for data is largely governed by the type of case and the instruction of work. Problematical with the latter point is there maybe the notion that the person instructing actually has sufficient technical knowledge and understanding to comprehend the technical details to be analysed and the types of detail the CSA expert will need.

A mistake in common practice that I have noted with examiners and experts is to assume the CDR contains the complete cell site details, and clearly that cannot be the case. The structure and content of CDR vis-a-vis TAP files both are different and have different purposes, but ae not generated for the purposes to include cell site details. I have seen some company websites identifying themselves as experts and suggesting cell site details are found in extended CDRs. I do not agree as cell site details have absolutely nothing to do with a generated per call CDR or indeed TAP file for that matter. There are a minimal references to cell sites by way of cell ID (start/end) and a few other bits and pieces, but nothing more would be generated by the mobile phone, radio network, the switch or data capture machine for inclusion into a CDR/TAP file.

Another matter I have noted, when dealing with expert and examiner cell site reports and those conducting radio test measurements is this vague suggestion allude to an implicit fact that because the examiner took GPS measurements when conducting tests this somehow creates a fact that the cellular radio coverage is corroborated by this or the movements of the handset user is somehow tracked this way. There appears on the face of it at least a confusion between GPS and the mobile network. Neither GSM or WCDMA propagate GPS signals, merely they take data output in the form of a packet of data from a GPS module/unit and forward that packet through the device/network to the terminal that will somehow make use of the data. If I need support for that fact then I find it at first instance in the radio frequencies adopted for GSM and WCDMA and from which all else will follow when dealing with cellular radio propagation and communications.

So what are the data field elements that the examiner/expert might seek at first instance. Clearly there needs to be corroboration of a GSM originated/terminated and start and/or end of a mobile communication. The list below is not data (email/internet/download etc) communication related.

----------------------------------------
Date ?
Time ?
Calling party ?
Called party ?
Type of call ?
Duration ?
Registration (ringing time before answer) ?


Mast location Details for start of call
---------------------------------------
[Start of call] Site ID number?
[Start of call] Site Name?
[Start of call] Site Address?
[Start of call] Site Post code?
[Start of call] Type of transmission 3G WCMDA site or GSM site?
[Start of call] Frequency Range?
[Start of call] Macrocell or Microcell?
[Start of call] Height of Antennas?
[Start of call] Is this a omni-directional site?
[Start of call] How many sectors at site (e.g. 3, 6 etc)?
[Start of call] Easting and Northing?
[Start of call] Longitude and Latitude?
[Start of call] Cell ID (hex)?
[Start of call] Cell ID (dec)?
[Start of call] Cell ID (last digit as sector)?
[Start of call] Broadcast Control Channel (BCCH) number?
[Start of call] Azimuth (bearing of coverage)?


Mast location Details for end of call
-------------------------------------
[End of call] Site ID number?
[End of call] Site Name?
[End of call] Site Address?
[End of call] Site Post code?
[End of call] Type of transmission 3G WCMDA site or GSM site?
[End of call] Frequency Range?
[End of call] Macrocell or Microcell?
[End of call] Height of Antennas?
[End of call] Is this a omni-directional site?
[End of call] How many sectors at site (e.g. 3, 6 etc)?
[End of call] Easting and Northing?
[End of call] Longitude and Latitude?
[End of call] Cell ID (hex)?
[End of call] Cell ID (dec)?
[End of call] Cell ID (last digit as sector)?
[End of call] Broadcast Control Channel (BCCH) number?
[End of call] Azimuth (bearing of coverage)?

The cell site details should relate at minimum to the material time of the mobile communications and at least  upto the date the request for  information is being made in order to comprehend any changes at the Masts for the Mast that handled the start of the call and the Mast that handled the end of the call.

Request notification of any Mast alterations
-----------------------------------------
[Any change to Mast] Decommissioned?
[Any change to Mast] Height of Antenna altered?
[Any change to Mast] Azimuth Bearing of coverage?
[Any change to Mast] Mechanical or electrical tilt changes and to what degree?
[Any change to Mast] Licenced Power or Transmission power?
[Any change to Mast] Type of transmission from 2G GSM to 3G WCDMA or vice versa?

It is quite possible to seek considerably more about the arrangements at each Mast, but that often means dealing with each operator's specific matters on a case by case basis.   These elements are not included here.

Monday, November 01, 2010

Location Update (LU) and Cell Site Analysis (CSA)

Location Update (LU) and Cell Site Analysis (CSA)

Heine, G; referred to the model "An MS performs LU on several occasions: every time it changes the location area, periodically, when a periodic location update is active, or with IMSI attach/ detach switched on at the time when it is subsequently turned on again."

That statement minimises, thus hides, a considerable body of mobile activity and, importantly, cell site analysis (CSA) suffers when students and practitioners fail to take into account the importance in the depth of knowledge and understanding that is needed to include the important facet of Location Update when conducting CSA. The following may assist students and practitioners with a simplified operational background as to events when Location Update (LU) takes place:

The MS requests a control channel from the BSC. The BTS decodes the CHAN_REQ, calculates the distance MS«BTS (timing advance), and forwards all this information to the BSC. Please note that the CHAN_REQ already indicates which service the MS requests (Location Update, in this case).

After the CHAN_RQD is received and processed, the BSC informs the BTS which channel type and channel number shall be reserved (CHAN_ACT).

The BTS confirms with a CHAN_ACT_ACK that it received and processed the CHAN_ACT.

The BSC sends the IMM_ASS_CMD, which activates the previously reserved channel. The BTS sends this information over an AGCH to the MS. The MS finds “its” IMM_ASS_CMD by means of the request reference, which is already contained in the CHAN_REQ.

Layer 2, the LAPDm connection is activated only now. The MS sends a SABM to the BTS, which (differently from LAPD) already contains data (LOC_UPD_REQ in this case).

The BTS confirms that a LAPDm connection was established by sending an UA message, which repeats the LOC_UPD_REQ.

The BTS passes LOC_UPD_REQ to the BSC. Although this is a transparent MM message, the BSC still processes the LOC_UPD_REQ in parts, because the BSC amongst others, requires the Mobile Station Classmark information. The BSC packs LOC_UPD_REQ, together with the current LAC, and CI into a CL3I message (Attention: the LOC_UPD_REQ from the MS contains the old LAC!) and then sends this within a SCCP CR
message to the MSC. The CR message carries not only the LOC_UPD_REQ to the MSC, but also requests establishment of an SCCP connection.

If the MSC is able to provide the requested SCCP connection,then the CR is answered with a CC. A logical connection from the MS to the MSC/VLR exists from this point in time on. The MSC/VLR answers the LOC_UPD_REQ with an AUTH_REQ This message is conveyed to the BSC via the established SCCP connection.

BSC and BTS transparently forward the AUTH_REQ to the MS. Most important content is the random number parameter (RAND). The MS (more precisely the SIM) calculates the result SRES by feeding RAND and Kj into the algorithm A3, then transparently sends SRES in an AUTH_RSP message to the MSC/VLR. The VLR compares SRES with the value provided by the HLR.

The MSC/VLR switches on ciphering, if the result from the authentication is correct. For this purpose, the MSC/VLR sends information to both, the MS and the BTS.

The BTS extracts its part form the ENCR_CMD message, which is Kc and sends the rest in a CIPH_MOD_CMD message to the MS. The CIPH_MOD_CMD message only contains the information, which cipher algorithm (A5/X) shall be used. The MS confirms, by sending a CIPH_MOD_COM message that ciphering was activated.

If Equipment Check is active, then the MSC/VLR requests the MS to provide its IMEI. This is done in an IDENT_REQ message, which is transparent for the BSS. Please note that the IDENT_REQ message also allows to request the TMSI or the IMSI. The equipment check may be performed at almost any time during the scenario, or in other words, is not tied to this place of the scenario.

The MS transparently transmits its IMEI in an IDENT_RSP message to the MSC/VLR, where it is checked by means of the EIR, whether that equipment is registered stolen or not approved.

The MSC/VLR assigns a TMSI, which is used instead of the IMSI in order to make tracking of subscribers more difficult. TMSI_REAL_CMD is also a transparent message between MSC/VLR and MS. The most important content of this message is the new TMSI. Please note that the assignment of a TMSI may also take place at the end within the LOC_UPD_ACC.

The MS confirms with a TMSI_REAL_COM that the new TMSI was received and stored. If the new TMSI is assigned with a LOC_UPD_ACC, then the TMSI_REAL_COM is obviously sent only after the LOC_UPD_ACC.

Sending of the transparent LOC_UPD_ACC message confirms that the MSC/VLR has stored the new Location Area (LAI). This concludes the Location Update process. The control channel that was occupied on the Air-interface has to be released, after the Location Update scenario has ended. For this purpose, the MSC sends the CLR_CMD message to the BSC. The BSC passes this command in a CHAN_REL to the BTS, which passes it to the MS. By sending a DEACT_SACCH, the BSC requests the BTS to cease sending of SACCH messages (SYS_INFO 5/6).The MS reacts on receiving a CHAN_REL message by sending a DISC (LAPDm).

This requests from the BTS to release its Layer 2 connection. The BTS confirms release of the Layer 2 connection by sending an UA message. Towards the BSC, the BTS confirms release of the Air-interface connection by sending of a REL_IND message. The BSC forwards this acknowledgment in a CLR_CMP to the MSC. The BSC requests the TRX in a RF_CHAN_REL to release the occupied resources on the Air-interface. RLSD requests release of the SCCP resources.

RF_CHAN_REL_ACK confirms release on the Air-interface. RLC confirms release of the SCCP resources.

Friday, June 18, 2010

Orange and Vodka - mixing mobile networks

Orange and Vodka - mixing mobile networks
(shaken, not stirred)
.

Good title for a book or article that heading. I thought this would be a useful post regarding the unusual occurrence of roaming onto a forbidden UK network from the home UK network.These screenshots record an event that happened on my wireless broadband. In the area I was located at the time Orange provided GPRS at 56K but download rates of under 6.5kbps (no 3G) - so not very good at all.
.

.
Such a matter like this may have an influence, if understood that it may occur, on any post-obtained radio test measurements after an alleged crime, or may even taint what may be considered a flawless opinion or conclusion, that is when conducting cell site analysis (CSA) investigations for evidential purposes.
.

.
It is not the fact that post-obtained radio test measurements failed to replicate an earlier event, it is the fact that a 'possibility' that may need to be explored to provide a more rounded opinion or conclusion in a report and at Court maybe missed or overlooked.

.

There are answers to the above conundrum but this is not the point of this post, which has been to highlight a technical event that might impact on evidence.