Base Jumping. Attacking the GSM baseband and base station

Size: px
Start display at page:

Download "Base Jumping. Attacking the GSM baseband and base station"

Transcription

1 Base Jumping Attacking the GSM baseband and base station

2 Overview GSM Base Station Base Band Conclusion 2

3 GSM: The Protocol 3

4 Documents Dozens of docs Thousands of pages Important one (defines L3) GSM

5 5

6 6

7 Logical Channels Broadcast Channels (BCH) Broadcast Control Channel (BCCH) Frequency Correction Channel (FCCH) Synchronization Channel (SCH) Cell Broadcast Channel (CBCH) 7

8 Logical Channels, cont. Common Control Channels (CCCH) Paging Channel (PCH) Random Access Channel (RACH) Access Grant Channel (AGCH) 8

9 Logical Channels, cont. Standalone Dedicated Control Channel (SDCCH) Associated Control Channel (ACCH) Fast Associated Control Channel (FACCH) Slow Associated Control Channel (SACCH) 9

10 GSM Channels Opening a channel is slow Can take seconds Specific channels for specific uses 10

11 Opening a channel 11

12 12

13 RACH 12

14 RACH AGCH 12

15 RACH AGCH LCH 12

16 13

17 PCH 13

18 PCH RACH 13

19 PCH RACH AGCH 13

20 PCH RACH AGCH LCH 13

21 ARFCN MSC BSC BTS MS BTS 14

22 Mobile Station MS Mobile Station Controller MSC Base Station Controller BSC Base Transceiver Station BTS Base Station Sub-System BSS 15

23 VLR HLR MSC BSS MS 16

24 Mobile Identifiers 17

25 18

26 IMSI 18

27 IMSI IMEI 18

28 IMSI IMEI 18

29 IMSI IMEI 18

30 IMSI IMEI 18

31 IMSI IMEI 18

32 IMSI IMEI 18

33 GSM Attacks 19

34 20

35 RACHell Request channel allocation Flood the BSS with requests First announced by Dieter Spaar at DeepSec Prevent everyone from using that cell 21

36 RACHell 22

37 RACHell 22

38 RACHell 22

39 RACHell 22

40 RACHell 22

41 RACHell 22

42 RACHell? 22

43 23

44 Our Target 23

45 Demo - RACHell 24

46 IMSI Flood Send IMSI ATTACH messages pre-authentication Overload the HLR/VLR infrastructure Prevent everyone using the network 25

47 IMSI Flood 26

48 IMSI Flood 26

49 IMSI Flood 26

50 IMSI Flood 26

51 IMSI Flood 26

52 IMSI Flood 26

53 IMSI Flood 26

54 IMSI DETACH Send multiple Location Update Requests including a spoofed IMSI Unauthenticated Prevent SIM from receiving calls and SMS Discovered by Sylvain Munaut 27

55 IMSI DETACH 28

56 IMSI DETACH 28

57 IMSI DETACH 28

58 IMSI DETACH 28

59 IMSI DETACH 28

60 IMSI DETACH 28

61 IMSI DETACH 28

62 How hard to get an IMSI? 29

63 Baseband Fuzzing 30

64 How to make a smartphone + = 31

65 Two separate computers 32

66 Two separate computers 32

67 Baseband Controls the radio Separate CPU and code base RTOS Written in C Typically legacy code base (decades) 33

68 GSM Frame Delivery OpenBTS + XML-RPC lch_open(char * IMSI) lch_send(int fd, char *buf, size_t len) lch_recv(int fd, char *buf, size_t len) lch_close(int fd) 34

69 GSM Fuzzing Framework USRP + OpenBTS for delivery GSM900 band BugMine case generation & mutation No Instrumentation Very bad visibility on bugs 35

70 Coseinc GSM FuzzFarm Targetting iphone HTC (Android) Palm Pre Blackberry Nokia 36

71 37

72 38

73 Conclusion 39

74 GSM Trouble GSM is no longer a walled garden GSM spec has security problems Expect many more issues as OSS reduces costs for entry 40

75 Future work More GSM stack fuzzing Next gen protocol stacks 41

76 Thanks to Harald Welte, Osmocom-bb & OpenBTS 42

77 Questions? 43

GSM LOGICAL CHANNELS

GSM LOGICAL CHANNELS GSM LOGICAL CHANNELS There are two types of GSM logical channels 1. Traffic Channels (TCHs) 2. Control Channels (CCHs) Traffic channels carry digitally encoded user speech or user data and have identical

More information

9.1 Introduction. 9.2 Roaming

9.1 Introduction. 9.2 Roaming 9 Location Updating Objectives After this chapter the student will: be able to define the concepts of roaming and location updating. be able to name the different types of location updating and why they

More information

GSM: PHYSICAL & LOGICAL CHANNELS

GSM: PHYSICAL & LOGICAL CHANNELS GSM: PHYSICAL & LOGICAL CHANNELS AN OVERVIEW Prepared by Learntelecom.com 1. GSM: PHYSICAL AND LOGICAL CHANNELS GSM uses a mix of Frequency Division Multiple Access (FDMA) and Time Division Multiple Access

More information

GSM - Global System for Mobile Communications

GSM - Global System for Mobile Communications GSM - Global System for Mobile Communications VLR BTS BSC GMSC PSTN MS HLR 1) Overview of GSM architecture 2) GSM channel structure 05-1 GSM - Global System for Mobile Communications VLR BTS BSC GMSC PSTN

More information

GSM System. Global System for Mobile Communications

GSM System. Global System for Mobile Communications GSM System Global System for Mobile Communications Introduced in 1991. Settings of standards under ETSI (European Telecommunication Standards Institute) Services - Telephone services - Data services -

More information

Global System for Mobile Communication (GSM)

Global System for Mobile Communication (GSM) Global System for Mobile Communication (GSM) Li-Hsing Yen National University of Kaohsiung GSM System Architecture Um (ME/SIM) C E C PSTN, ISDN, PSPDN, CSPDN A-bis A F A-bis C B BTS BSS BSC HLR VLR EIR

More information

GSM Channels. Physical & Logical Channels. Traffic and Control Mutltiframing. Frame Structure

GSM Channels. Physical & Logical Channels. Traffic and Control Mutltiframing. Frame Structure GSM Channels Physical & Logical Channels Traffic and Control Mutltiframing Frame Structure Engr. Mian Shahzad Iqbal Lecturer Department of Telecommunication Engineering Radio Interface The radio interface

More information

GSM BASICS GSM HISTORY:

GSM BASICS GSM HISTORY: GSM BASICS GSM HISTORY: In 1982 the Nordic PTTs sent a proposal to CEPT (Conference of European Postal & telegraph Administration) to study and to improve digital cellular technology by forming a team

More information

Integration of Open-Source GSM Networks

Integration of Open-Source GSM Networks Integration of Open-Source GSM Networks Thomas A. Cooper Thesis submitted to the faculty of the Virginia Polytechnic Institute and State University in partial fulfillment of the requirements for the degree

More information

How To Test Gsm Cell Phone Network On A Cell Phone

How To Test Gsm Cell Phone Network On A Cell Phone G S M C E L L B R O A D C A S T S E RV I C E S E C U R I T Y A N A LY S I S arturo cedillo torres Department of Mathematics and Computer Science Eindhoven University of Technology Supervisors: Nicola Zannone

More information

Mobile Security. Practical attacks using cheap equipment. Business France. Presented the 07/06/2016. For. By Sébastien Dudek

Mobile Security. Practical attacks using cheap equipment. Business France. Presented the 07/06/2016. For. By Sébastien Dudek Mobile Security Practical attacks using cheap equipment Presented the 07/06/2016 Business France By Sébastien Dudek For Content Security measures Recent publications in the hacking community Practical

More information

Ch 2.3.3 GSM PENN. Magda El Zarki - Tcom 510 - Spring 98

Ch 2.3.3 GSM PENN. Magda El Zarki - Tcom 510 - Spring 98 Ch 2.3.3 GSM In the early 80 s the European community decided to work together to define a cellular system that would permit full roaming in all countries and give the network providers freedom to provide

More information

CS 8803 - Cellular and Mobile Network Security: GSM - In Detail

CS 8803 - Cellular and Mobile Network Security: GSM - In Detail CS 8803 - Cellular and Mobile Network Security: GSM - In Detail Professor Patrick Traynor 9/27/12 Cellular Telecommunications Architecture Background Air Interfaces Network Protocols Application: Messaging

More information

GSM GSM 05.01 TECHNICAL May 1996 SPECIFICATION Version 5.0.0

GSM GSM 05.01 TECHNICAL May 1996 SPECIFICATION Version 5.0.0 GSM GSM 05.01 TECHNICAL May 1996 SPECIFICATION Version 5.0.0 Source: ETSI TC-SMG Reference: TS/SMG-020501Q ICS: 33.060.50 Key words: Digital cellular telecommunications system, Global System for Mobile

More information

MRN 6 GSM part 1. Politecnico di Milano Facoltà di Ingegneria dell Informazione. Mobile Radio Networks Prof. Antonio Capone

MRN 6 GSM part 1. Politecnico di Milano Facoltà di Ingegneria dell Informazione. Mobile Radio Networks Prof. Antonio Capone Politecnico di Milano Facoltà di Ingegneria dell Informazione MRN 6 GSM part 1 Mobile Radio Networks Prof. Antonio Capone A. Capone: Mobile Radio Networks 1 General characteristics of the system A. Capone:

More information

GSM Architecture and Interfaces

GSM Architecture and Interfaces GSM.05 Page 71 Monday, November 30, 1998 2:07 PM C H A P T E R 5 GSM Architecture and Interfaces 5.1 INTRODUCTION In this chapter we present an overview of the GSM as described in ETSI s recommendations.

More information

-The equipment was limited to operate only within the boundaries of each country. -The market for each mo bile equipment was limited.

-The equipment was limited to operate only within the boundaries of each country. -The market for each mo bile equipment was limited. 1 History of GSM During the early 1980s, analog cellular telephone systems were experienced a very fast growth in Europe, particularly in Scandinavia and the United Kingdom, but also in France and Germany.

More information

Frequency [MHz] ! " # $ %& &'( " Use top & bottom as additional guard. guard band. Giuseppe Bianchi DOWNLINK BS MS 890.4 UPLINK MS BS 890.2.

Frequency [MHz] !  # $ %& &'(  Use top & bottom as additional guard. guard band. Giuseppe Bianchi DOWNLINK BS MS 890.4 UPLINK MS BS 890.2. Frequency [MHz] 960 DOWNLINK BS MS 935 915 UPLINK MS BS 890 890.4 890.2 guard band Use top & bottom as additional guard! " # $ %& &'( " 1 2 3 4 5 6 7 8 F F uplink dwlink ( n) = [ 890.2 + 0.2( n 1) ] (

More information

GSM GPRS. Course requirements: Understanding Telecommunications book by Ericsson (Part D PLMN) + supporting material (= these slides)

GSM GPRS. Course requirements: Understanding Telecommunications book by Ericsson (Part D PLMN) + supporting material (= these slides) GSM Example of a PLMN (Public Land Mobile Network) At present most successful cellular mobile system (over 200 million subscribers worldwide) Digital (2 nd Generation) cellular mobile system operating

More information

GSM Radio Part 1: Physical Channel Structure

GSM Radio Part 1: Physical Channel Structure GSM Radio Part 1: Physical Channel Structure 1 FREQUENCY BANDS AND CHANNELS...2 2 GSM TDMA...4 3 TDMA FRAME HIERARCHY...6 4 BURST STRUCTURE...7 5 TDMA MULTIFRAME STRUCTURE...9 5.1 Traffic Multiframe (26-Multiframe)...10

More information

Roadmap for Establishing Interoperability of Heterogeneous Cellular Network Technologies -3-

Roadmap for Establishing Interoperability of Heterogeneous Cellular Network Technologies -3- Roadmap for Establishing Interoperability of Heterogeneous Cellular Network Technologies -3- Hasni Neji Innov COM Lab, Higher School of Communications of Tunis, Sup Com University of Carthage, Tunis, Tunisia

More information

How To Make A Cell Phone Network More Efficient

How To Make A Cell Phone Network More Efficient Cellular Network Planning and Optimization Part V: GSM Jyri Hämäläinen, Communications and Networking Department, TKK, 18.1.2008 GSM Briefly 2 General GSM was the first digital cellular system. GSM was

More information

Global System for Mobile Communications (GSM)

Global System for Mobile Communications (GSM) Global System for Mobile Communications (GSM) Nguyen Thi Mai Trang LIP6/PHARE Thi-Mai-Trang.Nguyen@lip6.fr UPMC/PUF - M2 Networks - PTEL 1 Outline Principles of cellular networks GSM architecture Security

More information

GSM Network Architecture, Channelisation, Signalling and Call Processing

GSM Network Architecture, Channelisation, Signalling and Call Processing GSM Network Architecture, Channelisation, Signalling and Call Processing Dr Bhaskar Ramamurthi Professor Department of Electrical Engineering IIT Madras Dr Bhaskar Ramamurthi GSM 1 Call Routing in Wireline

More information

Wireless Phone GSM tracking. Denis Foo Kune, John Koelndorfer, Nick Hopper, Yongdae Kim

Wireless Phone GSM tracking. Denis Foo Kune, John Koelndorfer, Nick Hopper, Yongdae Kim Wireless Phone GSM tracking Denis Foo Kune, John Koelndorfer, Nick Hopper, Yongdae Kim Can someone track your phone? GPS Need access to phone Cell network trilateration/triangulation Multiple base stations

More information

The Global System for Mobile communications (GSM) Overview

The Global System for Mobile communications (GSM) Overview The Global System for Mobile communications (GSM) Overview GSM D-AMPS Japan Digital PCS 1900 DCS 1800 CDMA Digital Cellular Systems World-wide Multiple Access Techniques In the GSM/DCS mobile system each

More information

Let Me Answer That For You: Exploiting Broadcast Information in Cellular Networks

Let Me Answer That For You: Exploiting Broadcast Information in Cellular Networks Let Me Answer That For You: Exploiting Broadcast Information in Cellular Networks Nico Golde, Kévin Redon, and Jean-Pierre Seifert, Technische Universität Berlin and Deutsche Telekom Innovation Laboratories

More information

Global System for Mobile (GSM) Global System for Mobile (GSM)

Global System for Mobile (GSM) Global System for Mobile (GSM) Global System for Mobile (GSM) David Tipper Associate Professor Graduate Program of Telecommunications and Networking University of Pittsburgh Telcom 2720 Slides 8 Based largely on material from Jochen

More information

Using TEMS Pocket. Johan Montelius

Using TEMS Pocket. Johan Montelius Using TEMS Pocket Johan Montelius Introduction In this laboration you will get acquainted with the TEMS Pocket tool. You will examine both the Monaco network and a commercial network. Since this is your

More information

Mobile Communications Chapter 4: Wireless Telecommunication Systems

Mobile Communications Chapter 4: Wireless Telecommunication Systems Mobile Communications Chapter 4: Wireless Telecommunication Systems Market GSM Overview Services Sub-systems Components GPRS DECT Not a part if this course! TETRA Not a part if this course! w-cdma (rel

More information

CS 8803 - Cellular and Mobile Network Security: CDMA/UMTS Air Interface

CS 8803 - Cellular and Mobile Network Security: CDMA/UMTS Air Interface CS 8803 - Cellular and Mobile Network Security: CDMA/UMTS Air Interface Hank Carter Professor Patrick Traynor 10/4/2012 UMTS and CDMA 3G technology - major change from GSM (TDMA) Based on techniques originally

More information

GSM GSM 05.02 TECHNICAL May 1996 SPECIFICATION Version 5.0.0

GSM GSM 05.02 TECHNICAL May 1996 SPECIFICATION Version 5.0.0 GSM GSM 05.02 TECHNICAL May 1996 SPECIFICATION Version 5.0.0 Source: ETSI TC-SMG Reference: TS/SMG-020502Q ICS: 33.060.50 Key words: Digital cellular telecommunications system, Global System for Mobile

More information

The GSM and GPRS network T-110.300/301

The GSM and GPRS network T-110.300/301 The GSM and GPRS network T-110.300/301 History The successful analog 1:st generation mobile telephone systems proved that there is a market for mobile telephones ARP (AutoRadioPuhelin) in Finland NMT (Nordic

More information

MAP/C SEND ROUTING INFO FOR SM. Destination Mobile Number. Obtain the SS7 address of the MSC VLR currently serving the specified Mobile Number

MAP/C SEND ROUTING INFO FOR SM. Destination Mobile Number. Obtain the SS7 address of the MSC VLR currently serving the specified Mobile Number In this call flow we will look at how a terminating SMS is handled in GSM. Setting up a terminating SMS session is a multi-step process. (1) Interrogate the MSC to locate the subscriber (2)Setting SMS

More information

Wireless systems GSM 2015-05-04. Simon Sörman

Wireless systems GSM 2015-05-04. Simon Sörman Wireless systems GSM 2015-05-04 Simon Sörman Contents 1 Introduction... 1 2 Channels... 2 2.1 Physical channels... 2 2.1.1 FDMA/TDMA... 2 2.1.2 Bursts... 3 2.2 Logical channels... 3 2.3 Mapping of logical

More information

Dimensioning and Deployment of GSM Networks

Dimensioning and Deployment of GSM Networks Case Study: Dimensioning and Deployment of GSM Networks Acknowledgement: some of these slides are based on originals and information kindly provided by Ian O Shea of Altobridge Ltd. 2011 1 GSM System Architecture

More information

The Network Layer Layer 3

The Network Layer Layer 3 CHAPTER 7 The Network Layer Layer 3 Now it is time to hijack the GSM freight train, to see what is inside, to break into the time-slotted boxcars and spill the drums of unknown acids and solvents on the

More information

GSM GSM 05.08 TECHNICAL July 1996 SPECIFICATION Version 5.1.0

GSM GSM 05.08 TECHNICAL July 1996 SPECIFICATION Version 5.1.0 GSM GSM 05.08 TECHNICAL July 1996 SPECIFICATION Version 5.1.0 Source: ETSI TC-SMG Reference: TS/SMG-020508QR ICS: 33.060.50 Key words: Digital cellular telecommunications system, Global System for Mobile

More information

GSM Air Interface & Network Planning

GSM Air Interface & Network Planning GSM Air Interface & Network Planning Training Document TC Finland Nokia Networks Oy 1 (40) GSM Air Interface & Network Planning The information in this document is subject to change without notice and

More information

Wireless Cellular Networks: 1G and 2G

Wireless Cellular Networks: 1G and 2G Wireless Cellular Networks: 1G and 2G Raj Jain Professor of Computer Science and Engineering Washington University in Saint Louis Saint Louis, MO 63130 Audio/Video recordings of this lecture are available

More information

GLOSARIO. Authentication key, se usa en sistemas basados en TIA/EIA-41. Estándar de comunicación celular basado en TDMA.

GLOSARIO. Authentication key, se usa en sistemas basados en TIA/EIA-41. Estándar de comunicación celular basado en TDMA. GLOSARIO A AC o AuC Ack AGCH A-key AMPS ANSI-136 ó IS-136 ARFCN ASE Authentication Center. Acknowledgement. Access Grant Channel. Authentication key, se usa en sistemas basados en TIA/EIA-41. Advanced

More information

RELEASE NOTE. Recc)mmendation GSM 05.08. Previously distributed version :3.7.0 ( Updated Release 1/90

RELEASE NOTE. Recc)mmendation GSM 05.08. Previously distributed version :3.7.0 ( Updated Release 1/90 ETSI /TC SMG Release by : ETSI /PT 12 Release date : December 1995 RELEASE NOTE Recc)mmendation GSM 05.08 Radio Sub - system Link Control Previously distributed version :3.7.0 ( Updated Release 1/90 New

More information

Support for Cell Broadcast as Global Emergency Alert System

Support for Cell Broadcast as Global Emergency Alert System Rapport LITH-ITN-EX--07/021--SE Support for Cell Broadcast as Global Emergency Alert System Karin Axelsson Cynthia Novak 2007-06-19 Department of Science and Technology Linköpings universitet SE-601 74

More information

NAVAL POSTGRADUATE SCHOOL THESIS

NAVAL POSTGRADUATE SCHOOL THESIS NAVAL POSTGRADUATE SCHOOL MONTEREY, CALIFORNIA THESIS SOFTWARE-DEFINED RADIO GLOBAL SYSTEM FOR MOBILE COMMUNICATIONS TRANSMITTER DEVELOPMENT FOR HETEROGENEOUS NETWORK VULNERABILITY TESTING by Carson C.

More information

Mobile Communications

Mobile Communications October 21, 2009 Agenda Topic 2: Case Study: The GSM Network 1 GSM System General Architecture 2 GSM Access network. 3 Traffic Models for the Air interface 4 Models for the BSS design. 5 UMTS and the path

More information

GSM Research. Chair in Communication Systems Department of Applied Sciences University of Freiburg 2010

GSM Research. Chair in Communication Systems Department of Applied Sciences University of Freiburg 2010 Chair in Communication Systems Department of Applied Sciences University of Freiburg 2010 Dennis Wehrle, Konrad Meier, Dirk von Suchodoletz, Klaus Rechert, Gerhard Schneider Overview 1. GSM Infrastructure

More information

GSM Network and Services

GSM Network and Services GSM Network and Services GPRS - sharing of resources 1 What is the problem? Many data applications are very bursty in its traffic pattern: http, smtp, pop, telnet,... Why reserve physical resources at

More information

MicroNet dual band IMSI and IMEI catcher

MicroNet dual band IMSI and IMEI catcher MicroNet dual band IMSI and IMEI catcher Datasheet Models: MNG-300-01 (GSM 900, 1800) MNG-300-02 (GSM 850, 1900) Document Nr OTK-012010 Date: 10-09-2012, revision B Table of contents 1. Acronyms and abbreviations

More information

Implementation of Mobile Measurement-based Frequency Planning in GSM

Implementation of Mobile Measurement-based Frequency Planning in GSM Implementation of Mobile Measurement-based Frequency Planning in GSM Comp.Eng. Serkan Kayacan (*), Prof. Levent Toker (**) (*): Ege University, The Institute of Science, Computer Engineering, M.S. Student

More information

Chapter 10 ( PART-1) Existing Wireless Systems

Chapter 10 ( PART-1) Existing Wireless Systems Chapter 10 ( PART-1) Existing Wireless Systems 1 Outline AMPS IS-41 GSM PCS 2 AMPS 3 AMPS (Advanced Mobile Phone System) Design goals of AMPS Characteristics of AMPS Channel usage in AMPS AMPS frequency

More information

House intercoms attacks

House intercoms attacks House intercoms attacks When frontdoors become backdoors Presented the 02/07/2016 NDH 2016 By Sébastien Dudek For About me Company: Synacktiv Interests: radio-communications (Wi-Fi, RFID, GSM, PLC...),

More information

TSG-RAN Meeting #7 Madrid, Spain, 13 15 March 2000 RP-000034. Title: Agreed CRs to TS 25.301. Agenda item: 6.3.3

TSG-RAN Meeting #7 Madrid, Spain, 13 15 March 2000 RP-000034. Title: Agreed CRs to TS 25.301. Agenda item: 6.3.3 TSG-RAN Meeting #7 Madrid, Spain, 13 15 March 2000 RP-000034 Title: Agreed CRs to TS 25.301 Source: TSG-RAN WG2 Agenda item: 6.3.3 Doc-1st- Spec CR Rev Subject Cat Version Versio R2-000213 25.301 032 Correction

More information

Evaluating GSM A5/1 security on hopping channels

Evaluating GSM A5/1 security on hopping channels Evaluating GSM A5/1 security on hopping channels Bogdan Diaconescu v1.0 This paper is a practical approach on evaluating A5/1 stream cipher on a GSM hopping network air interface called Um. The end goal

More information

NETWORK AND RF PLANNING

NETWORK AND RF PLANNING NETWORK AND RF PLANNING Introduction Achieving maximum capacity while maintaining an acceptable grade of service and good speech quality is the main issue for the network planning. Planning an immature

More information

Cellular mobile communication is based on the. The Cellular Concept. GSM and PCNs. Moe Rahnema

Cellular mobile communication is based on the. The Cellular Concept. GSM and PCNs. Moe Rahnema GSM and PCNs Overview Of he GSM System and Protocol Architecture We can use GSM as a basic framework to define and develop the standards for handling the mobility-specific functions of next-generation

More information

Telecommunication Systems (GSM) Mobile Communications (Ch 4) John Schiller, Addison-Wesley

Telecommunication Systems (GSM) Mobile Communications (Ch 4) John Schiller, Addison-Wesley Telecommunication Systems (GSM) Mobile Communications (Ch 4) John Schiller, Addison-Wesley 1 Telecommunication System Wireless extension of traditional PSTN Telephony architecture (NOT computer net) Many

More information

Report of OpenBSC GSM field test August 2009, HAR2009 Vierhouten, The Netherlands

Report of OpenBSC GSM field test August 2009, HAR2009 Vierhouten, The Netherlands Report of OpenBSC GSM field test August 2009, HAR2009 Vierhouten, The Netherlands Harald Welte June 7, 2011 Abstract HAR2009 is a gathering and conference of technology enthusiasts

More information

Insert here your thesis task.

Insert here your thesis task. Insert here your thesis task. Czech Technical University in Prague Faculty of Information Technology Department of Computer Systems Master s thesis GSM Network Security Bc. Yelena Trofimova Supervisor:

More information

OsmocomBB. A Free Software GSM baseband firmware. Harald Welte. gnumonks.org gpl-violations.org OpenBSC airprobe.org hmw-consulting.

OsmocomBB. A Free Software GSM baseband firmware. Harald Welte. gnumonks.org gpl-violations.org OpenBSC airprobe.org hmw-consulting. Project A Free Software GSM baseband firmware gnumonks.org gpl-violations.org OpenBSC airprobe.org hmw-consulting.de Linux Kongress 2010, September 2010, Nuremberg/Germany Outline GSM/3G Network Security

More information

Handoff in GSM/GPRS Cellular Systems. Avi Freedman Hexagon System Engineering

Handoff in GSM/GPRS Cellular Systems. Avi Freedman Hexagon System Engineering Handoff in GSM/GPRS Cellular Systems Avi Freedman Hexagon System Engineering Outline GSM and GSM referemce model GPRS basics Handoffs GSM GPRS Location and Mobility Management Re-selection and routing

More information

Wireless and Mobile Network Architecture

Wireless and Mobile Network Architecture Wireless and Mobile Network Architecture Chapter 7: GSM Network Signaling Prof. Yuh-Shyan Chen Department of Computer Science and Information Engineering National Taipei University Nov. 2006 1 Outline

More information

General Packet Radio Service (GPRS)

General Packet Radio Service (GPRS) General Packet Radio Service (GPRS) What is GPRS? GPRS (General Packet Radio Service) a packet oriented data service for IP and X.25 over GSM networks enables packet-switched services on the resources

More information

GSM and Similar Architectures Lesson 07 GSM Radio Interface, Data bursts and Interleaving

GSM and Similar Architectures Lesson 07 GSM Radio Interface, Data bursts and Interleaving GSM and Similar Architectures Lesson 07 GSM Radio Interface, Data bursts and Interleaving 1 Space Division Multiple Access of the signals from the MSs A BTS with n directed antennae covers mobile stations

More information

2G/3G Mobile Communication Systems

2G/3G Mobile Communication Systems 2G/3G Mobile Communication Systems Winter 2012/13 Integrated Communication Systems Group Ilmenau University of Technology Outline 2G Review: GSM Services Architecture Protocols Call setup Mobility management

More information

How To Understand The Gsm And Mts Mobile Network Evolution

How To Understand The Gsm And Mts Mobile Network Evolution Mobile Network Evolution Part 1 GSM and UMTS GSM Cell layout Architecture Call setup Mobility management Security GPRS Architecture Protocols QoS EDGE UMTS Architecture Integrated Communication Systems

More information

Index. Common Packet Channel (CPCH) 25 Compression 265, 279 82, 288 header compression 284

Index. Common Packet Channel (CPCH) 25 Compression 265, 279 82, 288 header compression 284 bindex.fm Page 296 Tuesday, March 22, 2005 7:17 AM Index 2G, 2.5G, 3G 13 3GPP 118 Release 5 (Rel 5) 124 Release 6 (Rel 6) 125 Release 97/98 (Rel 97/98) 119 Release 99 (Rel 99) 120 4 3GPP2 129 4G 13, 44

More information

Karsten Nohl, karsten@srlabs.de. Breaking GSM phone privacy

Karsten Nohl, karsten@srlabs.de. Breaking GSM phone privacy arsten Nohl, karsten@srlabs.de Breaking GSM phone privacy GSM is global, omnipresent and wants to be hacked 80% of mobile phone market 200+ countries 5 billion users! GSM encryption introduced in 1987

More information

LTE security and protocol exploits

LTE security and protocol exploits LTE security and protocol exploits Roger Piqueras Jover Wireless Security Research Scientist Security Architecture Bloomberg LP ShmooCon January 2016 About me Wireless Security Researcher (aka Security

More information

Forensic Identification of GSM Mobile Phones

Forensic Identification of GSM Mobile Phones Forensic Identification of GSM Mobile Phones Jakob Hasse dence GmbH c/o Technische Universität Dresden jakob.hasse@dence.de Thomas Gloe dence GmbH c/o Technische Universität Dresden thomas.gloe@dence.de

More information

Pocket Guide for Fundamentals and GSM Testing

Pocket Guide for Fundamentals and GSM Testing Pocket Guide for Fundamentals and GSM Testing Publisher: Author: Wandel & Goltermann GmbH & Co Elektronische Meûtechnik P. O. Box 12 62 D-72795 Eningen u.a. Germany e-mail: solutions@wg.com http://www.wg.com

More information

International Journal of Computing and Business Research (IJCBR)

International Journal of Computing and Business Research (IJCBR) AN INVESTIGATION OF GSM ARCHITECTURE AND OVERLAYING WITH EFFICIENT SECURITY PROTOCOL Karun Madan, Surya World Institute of Engg. & Technology, Rajpura, Punjab ABSTRACT The Global System for Mobile Communications

More information

Theory and Practice. IT-Security: GSM Location System Syslog XP 3.7. Mobile Communication. December 18, 2001. GSM Location System Syslog XP 3.

Theory and Practice. IT-Security: GSM Location System Syslog XP 3.7. Mobile Communication. December 18, 2001. GSM Location System Syslog XP 3. Participant: Hack contacting... IT-Security: Theory and Practice Mobile Communication December 18, 2001 Uwe Jendricke uwe@iig.uni-freiburg.de Lecture Homepage: http://www.informatik.uni-freiburg.de/~softech/teaching/ws01/itsec/

More information

1 Introduction. 2 Assumptions. Implementing roaming for OpenBTS

1 Introduction. 2 Assumptions. Implementing roaming for OpenBTS Implementing roaming for OpenBTS 1 Introduction One of the main advantages of OpenBTS TM system architecture is absence of a legacy GSM core network. SIP is used for registering, call control and messaging.

More information

Handover management in GSM cellular system

Handover management in GSM cellular system Handover management in GSM cellular system Jahangir khan School of computer science PAF-KIET, Pakistan Air Force Base korangi Creek Karachi 75190 Pakistan ABSTRACT Handover mechanism is extremely important

More information

Security in cellular-radio access networks

Security in cellular-radio access networks Security in cellular-radio access networks Ravishankar Borgaonkar, Oxford University 5G Security Workshop Stockholm, Sweden 11 May 2016 Outline Radio Access Network Layered Security Emerging low cost attacks

More information

GSM Architecture Training Document

GSM Architecture Training Document Training Document TC Finland Nokia Networks Oy 1 (20) The information in this document is subject to change without notice and describes only the product defined in the introduction of this documentation.

More information

Cellular Network Organization. Cellular Wireless Networks. Approaches to Cope with Increasing Capacity. Frequency Reuse

Cellular Network Organization. Cellular Wireless Networks. Approaches to Cope with Increasing Capacity. Frequency Reuse Cellular Network Organization Cellular Wireless Networks Use multiple low-power transmitters (100 W or less) Areas divided into cells Each served by its own antenna Served by base station consisting of

More information

An investigation into the claims of IMSI catchers use in Oslo in late 2014. Centre for Resilient Networks and Applications Simula Research Laboratory

An investigation into the claims of IMSI catchers use in Oslo in late 2014. Centre for Resilient Networks and Applications Simula Research Laboratory An investigation into the claims of IMSI catchers use in Oslo in late 2014 Centre for Resilient Networks and Applications Simula Research Laboratory Publication date 01. July 2015 Contents 1 Introduction

More information

GSM GSM 08.52 TECHNICAL December 1996 SPECIFICATION Version 5.0.0

GSM GSM 08.52 TECHNICAL December 1996 SPECIFICATION Version 5.0.0 GSM GSM 08.52 TECHNICAL December 1996 SPECIFICATION Version 5.0.0 Source: ETSI TC-SMG Reference: TS/SMG-030852Q ICS: 33.020 Key words: Digital cellular telecommunications system, Global System for Mobile

More information

Mobile Communications Chapter 4: Wireless Telecommunication Systems slides by Jochen Schiller with modifications by Emmanuel Agu

Mobile Communications Chapter 4: Wireless Telecommunication Systems slides by Jochen Schiller with modifications by Emmanuel Agu Mobile Communications Chapter 4: Wireless Telecommunication Systems slides by Jochen Schiller with modifications by Emmanuel Agu Market GSM Overview Services Sub-systems Components Prof. Dr.-Ing. Jochen

More information

Cellular Technology Sections 6.4 & 6.7

Cellular Technology Sections 6.4 & 6.7 Overview Cellular Technology Sections 6. & 6.7 CSC 9 December, 0 Cellular architecture evolution Cellular telephony and internet terminology Mobility for cellular mobiles 6- Components of cellular architecture

More information

!!! "# $ % & & # ' (! ) * +, -!!. / " 0! 1 (!!! ' &! & & & ' ( 2 3 0-4 ' 3 ' Giuseppe Bianchi

!!! # $ % & & # ' (! ) * +, -!!. /  0! 1 (!!! ' &! & & & ' ( 2 3 0-4 ' 3 ' Giuseppe Bianchi !!! "# $ % & & # ' (! ) * +, -!!. / " 0! 1 (!!! ' &! & & & ' ( 2 3 0-4 ' 3 ' "#$!!% "&'! #&'!%! () *+,, 3 & 5 &,! #-!*! ' & '.! #%!* //!! & (0)/!&/, 6 5 /, "! First system: NMT-450 (Nordic Mobile Telephone)

More information

Analysis of Methods for Mobile Device Tracking. David Nix Chief Scientific Advisor

Analysis of Methods for Mobile Device Tracking. David Nix Chief Scientific Advisor Analysis of Methods for Mobile Device Tracking David Nix Chief Scientific Advisor October 2013 Table of Contents 1. Document Purpose and Scope 3 2. Overview 3 2.1 Mobile Device Penetration 3 2.2 Mobile

More information

Mobile network security report: Poland

Mobile network security report: Poland Mobile network security report: Poland GSM Map Project gsmmap@srlabs.de Security Research Labs, Berlin February 2015 Abstract. Mobile networks differ widely in their protection capabilities against common

More information

Yu.M. Tulyakov, D.Ye. Shakarov, A.A. Kalashnikov. Keywords: Data broadcasting, cellular mobile systems, WCDMA, GSM.

Yu.M. Tulyakov, D.Ye. Shakarov, A.A. Kalashnikov. Keywords: Data broadcasting, cellular mobile systems, WCDMA, GSM. Аnalysis of data broadcasting in modern cellular mobile systems of ground radio communications Yu.M. Tulyakov, D.Ye. Shakarov, A.A. Kalashnikov At the analysis of channel formation in WCDMA networks the

More information

Mobile Wireless Overview

Mobile Wireless Overview Mobile Wireless Overview A fast-paced technological transition is occurring today in the world of internetworking. This transition is marked by the convergence of the telecommunications infrastructure

More information

Optimization. Log File Analysis GSM

Optimization. Log File Analysis GSM Optimization and Log File Analysis in GSM by Somer GOKSEL January 26, 2003 2 Contents 1 INTRODUCTION...04 1.1 PURPOSE and SCOPE of OPTIMIZATION... 04 1.2 OPTIMIZATION PROCESS... 05 1.2.1 PROBLEM ANALYSIS...

More information

A practical attack against GPRS/EDGE/UMTS/HSPA mobile data communications ABSTRACT

A practical attack against GPRS/EDGE/UMTS/HSPA mobile data communications ABSTRACT A practical attack against GPRS/EDGE/UMTS/HSPA mobile data communications David Perez - david@taddong.com Jose Pico - jose@taddong.com Black Hat DC 2011 (Jan. 18-19) ABSTRACT In this article we present

More information

Attacking GSM Networks as a Script Kiddie Using Commodity Hardware and Software

Attacking GSM Networks as a Script Kiddie Using Commodity Hardware and Software Attacking GSM Networks as a Script Kiddie Using Commodity Hardware and Software Christoforos Ntantogian 1, Grigoris Valtas 2, Nikos Kapetanakis 2, Faidon Lalagiannis 2, Georgios Karopoulos 3, Christos

More information

Karsten Nohl, Chris Paget 26C3, Berlin GSM SRSLY?

Karsten Nohl, Chris Paget 26C3, Berlin GSM SRSLY? Karsten Nohl, Chris Paget 26C3, Berlin GSM SRSLY? Summary: GSM Encryption needs to be shown insecure GSM is constantly under attack: A5/1 cipher shown insecure repeatedly Lack of network authentication

More information

Worldwide attacks on SS7 network

Worldwide attacks on SS7 network Worldwide attacks on SS7 network P1 Security Hackito Ergo Sum 26 th April 2014 Pierre-Olivier Vauboin (po@p1sec.com) Alexandre De Oliveira (alex@p1sec.com) Agenda Overall telecom architecture Architecture

More information

Provides a communication link between MS and MSC; Manages DB for MS location. Controls user connection. Transmission.

Provides a communication link between MS and MSC; Manages DB for MS location. Controls user connection. Transmission. Provides a communication link between MS and MSC; Manages DB for MS location Controls user connection CM MM RR Transmission Several RR functions considered in previous part!"# Surprise! handover is part

More information

Wireless Telecommunication Systems GSM, GPRS, UMTS. GSM as basis of current systems Satellites and

Wireless Telecommunication Systems GSM, GPRS, UMTS. GSM as basis of current systems Satellites and Chapter 2 Technical Basics: Layer 1 Methods for Medium Access: Layer 2 Chapter 3 Wireless Networks: Bluetooth, WLAN, WirelessMAN, WirelessWAN Mobile Networks: Wireless Telecommunication Systems GSM, GPRS,

More information

Cellular Telephone Systems

Cellular Telephone Systems CELLULAR TELEPHONE SYSTEMS First- Generation Analog Cellular Telephone, Personal Communications system, Second- Generation, N-AMPS, Digital Cellular Telephone, Interim Standard, North American Cellular

More information

Mobile network security report: Greece

Mobile network security report: Greece Mobile network security report: Greece GSM Map Project gsmmap@srlabs.de Security Research Labs, Berlin October 2012 Abstract. Mobile networks differ widely in their protection capabilities against common

More information

Authentication and Secure Communication in GSM, GPRS, and UMTS Using Asymmetric Cryptography

Authentication and Secure Communication in GSM, GPRS, and UMTS Using Asymmetric Cryptography ISSN (Online): 1694-0784 ISSN (Print): 1694-0814 10 Authentication and Secure Communication in GSM, GPRS, and UMTS Using Asymmetric Cryptography Wilayat Khan 1 and Habib Ullah 2 1 Department of Electrical

More information

Role and Evolution of Radio Network Controllers

Role and Evolution of Radio Network Controllers 01001000100000110000001000001100 010010001000 Role and Evolution of Radio Network Controllers Pekka Varis SPRP501 Senior R&D Manager / Senior Specialist Nokia pekka.ju.varis@nokia.com Agenda Radio Network

More information

OsmocomBB. A tool for GSM protocol level security. Harald Welte. gnumonks.org gpl-violations.org OpenBSC airprobe.org hmw-consulting.

OsmocomBB. A tool for GSM protocol level security. Harald Welte. gnumonks.org gpl-violations.org OpenBSC airprobe.org hmw-consulting. Project A tool for GSM protocol level security gnumonks.org gpl-violations.org OpenBSC airprobe.org hmw-consulting.de SSTIC 2010, June 2010, Rennes/France Outline GSM/3G Network Security Introduction Project

More information

Lecture overview. History of cellular systems (1G) GSM introduction. Basic architecture of GSM system. Basic radio transmission parameters of GSM

Lecture overview. History of cellular systems (1G) GSM introduction. Basic architecture of GSM system. Basic radio transmission parameters of GSM Lecture overview History of cellular systems (1G) GSM introduction Basic architecture of GSM system Basic radio transmission parameters of GSM Analogue cellular systems 70 s In the early 70 s radio frequencies

More information

3GPP LTE Channels and MAC Layer

3GPP LTE Channels and MAC Layer 3GPP LTE s and MAC Layer 2009 Inc. All Rights Reserved. LTE MAC Layer Functions Mapping between Transparent and Logical s Error Correction Through Hybrid ARQ MAC Priority Handling with Dynamic Scheduling

More information