CS 8803 - Cellular and Mobile Network Security: CDMA/UMTS Air Interface



Similar documents
Yu.M. Tulyakov, D.Ye. Shakarov, A.A. Kalashnikov. Keywords: Data broadcasting, cellular mobile systems, WCDMA, GSM.

GSM: PHYSICAL & LOGICAL CHANNELS

GSM LOGICAL CHANNELS

EPL 657 Wireless Networks

CS Cellular and Mobile Network Security: GSM - In Detail

TSG-RAN Meeting #7 Madrid, Spain, March 2000 RP Title: Agreed CRs to TS Agenda item: 6.3.3

Chapter 6 Wireless and Mobile Networks

Mobile & Wireless Networking. Lecture 5: Cellular Systems (UMTS / LTE) (1/2) [Schiller, Section 4.4]

Chapter 6 WCDMA. Chapter 6

CS Cellular and Mobile Network Security: Cellular Networking

3GPP LTE Channels and MAC Layer

GSM System. Global System for Mobile Communications

CS263: Wireless Communications and Sensor Networks

GSM Channels. Physical & Logical Channels. Traffic and Control Mutltiframing. Frame Structure

Frequency [MHz] ! " # $ %& &'( " Use top & bottom as additional guard. guard band. Giuseppe Bianchi DOWNLINK BS MS UPLINK MS BS

Mobile Communications TCS 455

GSM GPRS. Course requirements: Understanding Telecommunications book by Ericsson (Part D PLMN) + supporting material (= these slides)

How To Understand The Theory Of Time Division Duplexing

Index. Common Packet Channel (CPCH) 25 Compression 265, , 288 header compression 284

PDF vytvořeno zkušební verzí pdffactory UMTS

Pradipta Biswas Roll No. 04IT6007 M. Tech. (IT) School of Information Technology Indian Institute of Technology, Kharagpur

10. Wireless Networks

Global System for Mobile Communication (GSM)

W-CDMA/UMTS Wireless Networks

How To Understand And Understand The Power Of A Cdma/Ds System

How To Understand The Power Of A Cell Phone Network

Module 5. Broadcast Communication Networks. Version 2 CSE IIT, Kharagpur

Revision of Lecture Eighteen

Evolution of GSM in to 2.5G and 3G

Cellular Network Organization. Cellular Wireless Networks. Approaches to Cope with Increasing Capacity. Frequency Reuse

GSM Radio Part 1: Physical Channel Structure

Lecture 1. Introduction to Wireless Communications 1

Chapter 6 CDMA/802.11i

Implementation of Mobile Measurement-based Frequency Planning in GSM

CDMA Network Planning

EETS 8316 Wireless Networks Fall 2013

Global System for Mobile Communications (GSM)

Wireless systems GSM Simon Sörman

How To Understand The Gsm And Mts Mobile Network Evolution

ECE/CS 372 introduction to computer networks. Lecture 13

GSM and Similar Architectures Lesson 07 GSM Radio Interface, Data bursts and Interleaving

Ch GSM PENN. Magda El Zarki - Tcom Spring 98

GSM GSM TECHNICAL May 1996 SPECIFICATION Version 5.0.0

Hello viewers, welcome to today s lecture on cellular telephone systems.

Lecture 18: CDMA. What is Multiple Access? ECE 598 Fall 2006

UMTS overview. David Tipper Associate Professor. Graduate Telecommunications and Networking Program University of Pittsburgh 2720 Slides 12 UMTS

Wireless Cellular Networks: 1G and 2G

Cellular Network Planning and Optimization Part XI: HSDPA. Jyri Hämäläinen, Communications and Networking Department, TKK, 25.1.

Performance Issues of TCP and MPEG-4 4 over UMTS

The Evolution of 3G CDMA Wireless Networks. David W. Paranchych IEEE CVT Luncheon January 21, 2003

Exercise 2 Common Fundamentals: Multiple Access

Multiple Access Techniques

Cellular Network Organization

GSM - Global System for Mobile Communications

GSM Network and Services

FIGURE 12-1 Original Advanced Mobile Phone Service (AMPS) frequency spectrum

9.1 Introduction. 9.2 Roaming

Solution for cell edge performance improvement and dynamic load balancing. Qualcomm Technologies, Inc.

3GPP Wireless Standard

2G/3G Mobile Communication Systems

COMP 3331/9331: Computer Networks and Applications

Mobility and cellular networks

Role and Evolution of Radio Network Controllers

LTE Evolution for Cellular IoT Ericsson & NSN

GSM BASICS GSM HISTORY:

Computer Networks. Wireless and Mobile Networks. László Böszörményi Computer Networks Mobile - 1

The GSM and GPRS network T /301

Wireless Cellular Networks: 3G

ERLANG CAPACITY EVALUATION IN GSM AND CDMA CELLULAR SYSTEMS

Chapter 6 Bandwidth Utilization: Multiplexing and Spreading 6.1

GSM GSM TECHNICAL July 1996 SPECIFICATION Version 5.1.0

CHAPTER - 4 CHANNEL ALLOCATION BASED WIMAX TOPOLOGY

Mobility Management in UMTS

CDMA TECHNOLOGY. Brief Working of CDMA

HSDPA Mobile Broadband Data A Smarter Approach to UMTS Downlink Data

MRN 6 GSM part 1. Politecnico di Milano Facoltà di Ingegneria dell Informazione. Mobile Radio Networks Prof. Antonio Capone

Data Center Networks, Link Layer Wireless (802.11)

GSM GSM TECHNICAL May 1996 SPECIFICATION Version 5.0.0

GSM Air Interface & Network Planning

Customer Training Catalog Course Descriptions WCDMA RNP&RNO Technical Training

Mobile Communications Chapter 4: Wireless Telecommunication Systems slides by Jochen Schiller with modifications by Emmanuel Agu

Mobile Computing. Basic Call Calling terminal Network Called terminal 10/25/14. Public Switched Telephone Network - PSTN. CSE 40814/60814 Fall 2014

Wireless Phone GSM tracking. Denis Foo Kune, John Koelndorfer, Nick Hopper, Yongdae Kim

The Global System for Mobile communications (GSM) Overview

Telesystem Innovations. LTE in a Nutshell: Protocol Architecture WHITE PAPER

How To Make A Base Transceiver Station More Powerful

How To Test Gsm Cell Phone Network On A Cell Phone

Impact of Flexible RLC PDU Size on HSUPA Performance

How To Make A Multi-User Communication Efficient

Evaluating GSM A5/1 security on hopping channels

Attenuation (amplitude of the wave loses strength thereby the signal power) Refraction Reflection Shadowing Scattering Diffraction

ITU-T RECOMMENDATION J.122, SECOND-GENERATION TRANSMISSION SYSTEMS FOR INTERACTIVE CABLE TELEVISION SERVICES IP CABLE MODEMS

LoRaWAN. What is it? A technical overview of LoRa and LoRaWAN. Technical Marketing Workgroup 1.0

Wireless Mobile Telephony

Support for Cell Broadcast as Global Emergency Alert System

Chapter 3 Cellular Networks. Wireless Network and Mobile Computing Professor: Dr. Patrick D. Cerna

Dimensioning, configuration and deployment of Radio Access Networks. Lecture 2.1: Voice in GSM

Positioning in GSM. Date: 14th March 2003

How To Make A Cell Phone Network More Efficient

Transcription:

CS 8803 - Cellular and Mobile Network Security: CDMA/UMTS Air Interface Hank Carter Professor Patrick Traynor 10/4/2012

UMTS and CDMA 3G technology - major change from GSM (TDMA) Based on techniques originally employed by Verizon (IS-95) Signal is encoded so that it can be recovered from noise (other signals) 2

New Considerations Technology differences Power control Frequency re-use & handoffs Number of users Modulation (Phase Shift Keying) Traffic differences What is the primary difference between 2G and 3G? 3

Code Division Multiple Access used in several wireless broadcast channels (cellular, satellite, etc) standards unique code assigned to each user; i.e., code set partitioning all users share same frequency, but each user has own chipping sequence (i.e., code) to encode data encoded signal = (original data) X (chipping sequence) decoding: inner-product of encoded signal and chipping sequence allows multiple users to coexist and transmit simultaneously with minimal interference (if codes are orthogonal ) What does it mean for two vectors to be orthogonal? 4

CDMA Encode/Decode channel output Z i,m data bits d 1 = -1 d 0 = 1 Z i,m = d i. cm -1-1 -1 1-1 1 1 1 1 1 1 1 1-1- 1-1- sender code 1 1 1 1 1-1- 1-1- 1 1 1 1 1-1- 1-1- slot 1 channel output slot 0 channel output slot 1 slot 0 M D i = Σ Z i,m. cm m=1 received input -1-1 -1 1-1 1 1 1 1 1 1 1 1-1- 1-1- M d 1 = -1 d 0 = 1 code 1 1 1 1 1-1- 1-1- 1 1 1 1 1-1- 1-1- slot 1 channel output slot 0 channel output receiver slot 1 slot 0 5

CDMA: two-sender interface 6

CDMA Benefits Higher capacity interference limited = high efficiency uses voice activity detection to reduce transmission bandwidth Improved quality soft handoff CDMA has frequency, spatial, and time diversity to adapt to errors Ease of deployment no frequency planning; frequency reuse = 1 Increased talk time power control ensures that the UE transmits at optimum power, resulting in longer battery life. 7

CDMA Privacy Given that all signals look like noise unless you have the despreading sequence, what sort of privacy does CDMA offer? 8

Universal Mobile Telecommunications System: UMTS Specifications: Frequencies: 700, 850, 900, 1700, 1900, 2100 MHz (5 MHz channels) worldwide; FDD Chipping codes: up to 512 bits Power control: up to1500x per second Time division: 10 ms frames, 1 frame = 15 time slots Borrows extensively from GSM protocols Major changes: CDMA Technology: Channel structure/handoffs/power control Security -- increased use of cryptographic constructions Data infrastructure 9

Entities: New names, old faces BSC RNC MS UE BTS Node-B BTS Node-B BTS Node-B UE = User Equipment Node-B RNC = Radio Network Controller 10

Channels: Old & New GSM BCCH PCH AGCH SDCCH TCH RACH SCH CCCH UMTS BCCH PCH AICH DCCH DTCH RACH SCH CCCH 11

Channel Types Logical: defines a logical task or use in the network Transport: defines the way logical data is prepared Physical: defines the actual channel (i.e. chipping code) used to transmit data 12

Logical Channels Broadcast Control Channel (BCCH): Provides common information about the cell to UEs. Paging Control Channel (PCCH): Provides information about incoming calls and how to listen for them. Dedicated Control Channel (DCCH): A two-way assigned channel that carries control information to and from a single UE. Common Control Channel (CCCH): A two-way shared channel that carries control information. Dedicated Traffic Channel (DTCH): A two-way assigned channel that carries traffic to and from a single UE. 13

Transport Channels Dedicated Transport Channel (DCH): carries data to and from a specific UE Broadcast Channel (BCH): Broadcasts network and cell information Forward Access Channel (FACH): Carries control information to UEs for shared channels. Random Access Channel (RACH): Carries channel requests to the network from the UE. Paging Channel (PCH): Carries incoming call alerts. Uplink Common Packet Channel (CPCH): Carries packet data to the network. Downlink Shared Channel (DSCH): Carries packet data to the UE. 14

Physical Channels: Signaling Forward (to UE): Primary Common Control Physical Channel (PCCPCH): Carries the BCH Secondary Common Control Physical Channel (SCCPCH): Carries the FACH and the PCH Synchronization Channel (SCH): Synchronizes time with the network Common Pilot Channel (CPICH): Informs the user of the Primary Scrambling Code (PSC) Acquisition Indicator Channel (AICH): Used to carry dedicated channel assignments to UEs Paging Indication Channel (PICH): Provides the UE with information about how pages are sent. This informs the UE how often to wake up and listen for pages. Reverse (to Node-B): Physical Random Access Channel (PRACH): Carries the RACH 15

Physical Channels: Traffic Bi-Directional: Dedicated Physical Data Channel (DPDCH): Carries a DCH Dedicated Physical Control Channel (DPCCH): Carries control information (e.g., identifiers, power control) Forward (to UE): Physical Downlink Shared Channel (PDSCH): carries packet data to a UE. CPCH Status Indication Channel (CSICH): Indicates the status of the CPCH Collision Detection/Channel Assignment Indication Channel (CD/CA-ICH): Indicates if data sent over the CPCH has been successfully received or if a collision occurred. Reverse (to Node-B): Physical Common Packet Channel (PCPCH): Carries the CPCH 16

How a connection is made Synchronize Time (SCH) Acquire PSC (CPICH) Acquire cell information (PCCPCH) Node-B UE 17

How a call is sent/received Page sent over PCH (SCCPCH) Page response over RACH (PRACH) Chipping & scrambling code assigned (AICH) Authentication over DCCH (DPDCH + DPCCH) Call connect over DTCH (DPDCH + DPCCH) Node-B UE 18

Mappings Source: http://www.authorstream.com/presentation/3627946-387767-wcdma-air-interface-fundamentals-sciencetechnology-ppt-powerpoint/ 19

Spreading Codes Orthogonal Variable Spreading Factor (OVSF) vs scrambling codes OVSF codes are typical chipping/spreading codes Scrambling codes can be multiplied into OSVF codes to provide more user channels Long vs. short codes Uplink: code lengths up to 256 (+ 16.8 M scrambling codes) Downlink: code lengths up to 512 Why are these numbers different? 20

Power Control CDMA provides optimal performance when all signals are received at approximately the same strength. When a DTCH is assigned, the Node-B sends reports of the RSS (received signal strength) to the UE, alerting it at what power to transmit. Power control commands sent up to 1500 times per second 21

Handoffs 4 types: hard, soft, softer, network (2G 3G) Soft handoff overview: Frequency reuse = 1 UE will receive signal from multiple Node-Bs. Extract signals of old and new tower simultaneously using different chipping codes. Remain connected to old Node-B until re-registered with new Node-B 22