Monday, November 08, 2010

CSA and seamless roaming

CSA and seamless roaming

UK seamless roaming on the H3G to O2 and H3G to Orange always added further dimensions needing to be investigated when conducting cell site analysis (CSA). However, with Orange's announcement today (08/10/10), sent by text message to its customers, will mean extending seamless roaming investigations now to Orange and T-Mobile too.

https://kareena.orange.co.uk/share/

Call and text in even more places

Now you can pick up a signal from both the Orange and T-Mobile networks in the UK which means that you can call and text in even more places.
  • Your phone will use T-Mobile signal if it doesn't pick up an Orange signal
  • Your charges stay the same when you use T-Mobile signal
  • Nothing else will change, you'll just get more network coverage
This provides further corroboration that simplifying investigations and not spending the appropriate time conducting radio tests and cross-referencing to the appropriate network records can lead to erroneous findings and reported flawed opinions to the client and court.

Monday, November 01, 2010

Location Update (LU) and Cell Site Analysis (CSA)

Location Update (LU) and Cell Site Analysis (CSA)

Heine, G; referred to the model "An MS performs LU on several occasions: every time it changes the location area, periodically, when a periodic location update is active, or with IMSI attach/ detach switched on at the time when it is subsequently turned on again."

That statement minimises, thus hides, a considerable body of mobile activity and, importantly, cell site analysis (CSA) suffers when students and practitioners fail to take into account the importance in the depth of knowledge and understanding that is needed to include the important facet of Location Update when conducting CSA. The following may assist students and practitioners with a simplified operational background as to events when Location Update (LU) takes place:

The MS requests a control channel from the BSC. The BTS decodes the CHAN_REQ, calculates the distance MS«BTS (timing advance), and forwards all this information to the BSC. Please note that the CHAN_REQ already indicates which service the MS requests (Location Update, in this case).

After the CHAN_RQD is received and processed, the BSC informs the BTS which channel type and channel number shall be reserved (CHAN_ACT).

The BTS confirms with a CHAN_ACT_ACK that it received and processed the CHAN_ACT.

The BSC sends the IMM_ASS_CMD, which activates the previously reserved channel. The BTS sends this information over an AGCH to the MS. The MS finds “its” IMM_ASS_CMD by means of the request reference, which is already contained in the CHAN_REQ.

Layer 2, the LAPDm connection is activated only now. The MS sends a SABM to the BTS, which (differently from LAPD) already contains data (LOC_UPD_REQ in this case).

The BTS confirms that a LAPDm connection was established by sending an UA message, which repeats the LOC_UPD_REQ.

The BTS passes LOC_UPD_REQ to the BSC. Although this is a transparent MM message, the BSC still processes the LOC_UPD_REQ in parts, because the BSC amongst others, requires the Mobile Station Classmark information. The BSC packs LOC_UPD_REQ, together with the current LAC, and CI into a CL3I message (Attention: the LOC_UPD_REQ from the MS contains the old LAC!) and then sends this within a SCCP CR
message to the MSC. The CR message carries not only the LOC_UPD_REQ to the MSC, but also requests establishment of an SCCP connection.

If the MSC is able to provide the requested SCCP connection,then the CR is answered with a CC. A logical connection from the MS to the MSC/VLR exists from this point in time on. The MSC/VLR answers the LOC_UPD_REQ with an AUTH_REQ This message is conveyed to the BSC via the established SCCP connection.

BSC and BTS transparently forward the AUTH_REQ to the MS. Most important content is the random number parameter (RAND). The MS (more precisely the SIM) calculates the result SRES by feeding RAND and Kj into the algorithm A3, then transparently sends SRES in an AUTH_RSP message to the MSC/VLR. The VLR compares SRES with the value provided by the HLR.

The MSC/VLR switches on ciphering, if the result from the authentication is correct. For this purpose, the MSC/VLR sends information to both, the MS and the BTS.

The BTS extracts its part form the ENCR_CMD message, which is Kc and sends the rest in a CIPH_MOD_CMD message to the MS. The CIPH_MOD_CMD message only contains the information, which cipher algorithm (A5/X) shall be used. The MS confirms, by sending a CIPH_MOD_COM message that ciphering was activated.

If Equipment Check is active, then the MSC/VLR requests the MS to provide its IMEI. This is done in an IDENT_REQ message, which is transparent for the BSS. Please note that the IDENT_REQ message also allows to request the TMSI or the IMSI. The equipment check may be performed at almost any time during the scenario, or in other words, is not tied to this place of the scenario.

The MS transparently transmits its IMEI in an IDENT_RSP message to the MSC/VLR, where it is checked by means of the EIR, whether that equipment is registered stolen or not approved.

The MSC/VLR assigns a TMSI, which is used instead of the IMSI in order to make tracking of subscribers more difficult. TMSI_REAL_CMD is also a transparent message between MSC/VLR and MS. The most important content of this message is the new TMSI. Please note that the assignment of a TMSI may also take place at the end within the LOC_UPD_ACC.

The MS confirms with a TMSI_REAL_COM that the new TMSI was received and stored. If the new TMSI is assigned with a LOC_UPD_ACC, then the TMSI_REAL_COM is obviously sent only after the LOC_UPD_ACC.

Sending of the transparent LOC_UPD_ACC message confirms that the MSC/VLR has stored the new Location Area (LAI). This concludes the Location Update process. The control channel that was occupied on the Air-interface has to be released, after the Location Update scenario has ended. For this purpose, the MSC sends the CLR_CMD message to the BSC. The BSC passes this command in a CHAN_REL to the BTS, which passes it to the MS. By sending a DEACT_SACCH, the BSC requests the BTS to cease sending of SACCH messages (SYS_INFO 5/6).The MS reacts on receiving a CHAN_REL message by sending a DISC (LAPDm).

This requests from the BTS to release its Layer 2 connection. The BTS confirms release of the Layer 2 connection by sending an UA message. Towards the BSC, the BTS confirms release of the Air-interface connection by sending of a REL_IND message. The BSC forwards this acknowledgment in a CLR_CMP to the MSC. The BSC requests the TRX in a RF_CHAN_REL to release the occupied resources on the Air-interface. RLSD requests release of the SCCP resources.

RF_CHAN_REL_ACK confirms release on the Air-interface. RLC confirms release of the SCCP resources.

Thursday, October 21, 2010

Four Blogs

Four Blogs

I have four open webblogs that are active:

http://trewmte.blogspot.com
http://cellsiteanalysis.blogspot.com
http://sim2usim.blogspot.com
http://forensicmobex.blogspot.com

The focus of these webblogs involves dealing with all forms of forensics and evidence relevant to mobile communications in the open arena that may impact now or in the future relevant to:

- Advancing forensic evidence and analysis by challenging methodology and entrenchment in out of date concepts
- Balanced technical evidence for fair trials

I have been developing new materials for the blogs that will be gradually rolled out over the next six months.

Friday, August 13, 2010

US Case: Daubert and Cell Site Analysis Maps

US Case: Daubert and Cell Site Analysis Maps

I having been an advocate, as many of you know, for many years for the use in evidence of network operator generated analogue and digital cellular radio maps (eg best server plots/density maps & single cell prediction plots/density maps). That is because they are a composite compiled from collection of visible and discrete detail relevant to the operator's predication. They illustrate, if you will, a visual demonstration of a radio coverage strategy in an area. A recent US Case dealt with cell site maps as part of the evidence. The case of the US v Benford discussed by Law Professor Susan Brenner, at her webblog, makes interesting reading indeed:

http://cyb3rcrim3.blogspot.com/2010/08/daubert-and-cell-site-data.html

There are examples of cell site maps here at Mobile Telephone Evidence (link below):

http://trewmte.blogspot.com/2009/08/cell-site-analysis-csa-images.html

Saturday, June 19, 2010

CSA: Directed Retry Can Alter Mobile Phone's Location

CSA: Directed Retry Can Alter Mobile Phone's Location

Class│Value│
0 0 0│1 1 0 1│ Directed Retry

The accuracy or inaccuracy of cell site analysis testing measurements largely depends upon what has been considered and there are indeed many points to consider. One handover (HO) procedure, if it is included within a mobile network's radio-availability and traffic-flow arsenal, is called Directed Retry (DR). The GSM and 3GPP standards refers to this procedure.



What is Directed Retry (DR)?
Directed retry has adjustable parameters in order to define thresholds that once passed can trigger DR. When DR is set as Not Use it is inactive. Once set to Use the default value is set until the parameter is adjusted. That is to say a 'value' that is set as default can be modified in response to condtions eg quality of service (QoS) or traffic observations. A manufacturer of the say the BSS may provide recommended values, but it might be the OMC-R or BSS engineering team may require to make their own determination about values for internal or external handover procedures.

Use DR enables for example the BSS to move a mobile phone's communications to another cell (Mast or sector of a Mast) prior to call set up. That can be for an outgoing or incoming communication.

DR may be triggered by, for instance, due to 'congestion' and therefore may require internal or external handover procedures to combat that traffic condition. An outcome is that a mobile phone that receives service from the current serving cell (maybe the Mast is seen as closer to the mobile phone as well) is handed over to a cell that originates from a Mast that could be eg:

- some distance from the mobile phone's actual location
- coverage from a adjacent Mast in an area
- etc

This is one of many radio cases that when conducting radio test measurments a 2G/3G passive radio detection device and its readings may not record the appropriate network messages and thus mis-inform their users attempts in assessing a mobile phone's general location when conducting cell site analysis, as the device's readings may be incomplete. The Cell ID obtained from a call detail record (CDR) can only reflect the antenna identities on a fixed-positioned Mast and that a mobile phone has had its communications routed to and from the network using a particular Mast (so to speak). It doesn't automatically follow that the Cell ID confirms the general local area in which the mobile phone was actually located without certain radio data and other necessary checks being made.

Friday, June 18, 2010

Orange and Vodka - mixing mobile networks

Orange and Vodka - mixing mobile networks
(shaken, not stirred)
.

Good title for a book or article that heading. I thought this would be a useful post regarding the unusual occurrence of roaming onto a forbidden UK network from the home UK network.These screenshots record an event that happened on my wireless broadband. In the area I was located at the time Orange provided GPRS at 56K but download rates of under 6.5kbps (no 3G) - so not very good at all.
.

.
Such a matter like this may have an influence, if understood that it may occur, on any post-obtained radio test measurements after an alleged crime, or may even taint what may be considered a flawless opinion or conclusion, that is when conducting cell site analysis (CSA) investigations for evidential purposes.
.

.
It is not the fact that post-obtained radio test measurements failed to replicate an earlier event, it is the fact that a 'possibility' that may need to be explored to provide a more rounded opinion or conclusion in a report and at Court maybe missed or overlooked.

.

There are answers to the above conundrum but this is not the point of this post, which has been to highlight a technical event that might impact on evidence.