If you liked it, or content was helpful to you please add "+1" to article you used or share it on facebook or so.
Make it easier to find for others who could need those information, allow them find these articles on the spot. But.. it's your call.
Recommendations until now


Jan 15, 2014

Resource: SIM Card Forensics - Introduction

Just few moments ago I have found quite interesting article that covers in details how the SIM card is build and works. Maybe for Terminal-side guys this is obvious but myself I found few new things for myself.
As the title says this is just introduction, more information could be coming.

SIM Structure and File Systems

A SIM card contains a processor and operating system with between 16 and 256 KB of persistent, electronically erasable, programmable read-only memory (EEPROM). It also contains RAM (random access memory) and ROM (read-only memory). RAM controls the program execution flow and the ROM controls the operating system work flow, user authentication, data encryption algorithm, and other applications. The hierarchically organized file system of a SIM resides in persistent memory and stores data as names and phone number entries, text messages, and network service settings. Depending on the phone used, some information on the SIM may coexist in the memory of the phone. Alternatively, information may reside entirely in the memory of the phone instead of available memory on the SIM.
Fig. 1. SIM Card File System

follow the link to get more - resource.

Source:
Internet

Jan 14, 2014

Combined Attach in LTE/4G

Some time ago I'v covere the Attach Procedure, from then many times I saw questions about the Combined Attach.
So here it is, the Combined Attach himself.

First it has to be addressed what is the Combined Attach and why it's so different from Attach procedure already covered.

What Combined Attach is?

It's attach for both EPS and non-EPS services, or both EPS services and "SMS only".
The combined attach procedure is also used by a UE in CS/PS to attach for EPS services if it is already IMSI attached for non-EPS services.

How Combined Attach is triggered?

When the UE initiates a combined attach procedure, the UE shall indicate "combined EPS/IMSI attach" in the EPS attach type IE.


If the UE is in EMM state EMM-DEREGISTERED, the UE initiates the combined attach procedure by sending an ATTACH REQUEST message to the network, starting timer T3410 (More about EMM timers? Check the EMM timers or ESM timers article) and entering state EMM-REGISTERED-INITIATED.

If timer T3402 is currently running, the UE shall stop timer T3402. If timer T3411 is currently running, the UE shall stop timer T3411.

Jan 2, 2014

New year, another year online!

Hi everyone!,
It has been 2 years since the blog is up and running, or it will be in exactly 4 days from now. ;-)

Few things has changed during this time in my private life, I have definitely moved forward with what I'm doing for living, and definitely running this blog helped me to evolve.

Your comments and inputs to whatever I'm posting keeps me up to speed and motivated. Anyone of them is important to me, thanks for everything. With few of you I'm having conversations on telecom topics on monthly basis. Thanks for your trust in me.
Thanks for all your questions and for the opportunities to help in problems you had. Solving those also pushed me forward.

If you have any questions or propositions I could take into consideration to write about simply let me know.

Hope you will stick with me next 2 years or even longer.

Wish you all great 2014, success at work and ample of energy to self improve.

Regards, Cheers!,
Bart Barton

Nov 30, 2013

S-TMSI usage and allocation process

During which procedure the S-TMSI  (SAE-Temporary Mobile Subscriber Identity) is allocated?

Answer could be put as a one-liner, during the Attach procedure.

Going little bit deeper into the details..
At the time of initial attach (so I would say IMSI not GUTI attach, what is the difference? Check here What is GUTI and IMSI attach) procedure, the UE sends Att Req with IMSI to the Network to process the Request. If it's successful the MME will reply with Attach Accept message which contain the GUTI as one of the IE (Information Element).

Based on article IMSI, TMSI and GUTI - how they are created (and 3GPP Specs) we know that GUTI consist from MCC, MNC, MME Group ID, MME Code and M-TMSI.

What is M-TMSI (MME-Temporary Mobile Subscriber Identity)?
M-TMSI represents a TMSI in MME area.


Last statement on allocation topic is left to say that S-TMSI is being created from MME Code and M-TMSI. The S-TMSI represents the TMSI in MME pool area.

During the Attach process MME creates the UE Context and assigns the S-TMSI to it. Later this UE Context holds user subscription information fetched from HSS in Authentication process. The local (in MME) storage of subscription allows faster execution of procedures such as bearer establishment because it removes the need to consult the HSS each time.


Source(s):
own experience,
3GPP Spec

DIAMETER based interfaces in EPC, UMTS and IMS

Recently I've seen question regarding on which interface in LTE or UMTS the DIAMETER protocol is used.

Basically DIAMETER is an Authentication, Authorization & Accounting (AAA)  protocol. That is why any of you will see DIAMETER used for these functions.

                    S6a - Authentication, more in TS 29.272
                    Gy - Prepaid charging, more in TS 23.203, TS 32.299;
                    Gz - Postpaid charging;
                    Gx - QoS/Policy, more in TS 29.211, TS 29.212;
                    Rf - Charging, more in TS 32.299;
                    Ro - Charging, more in TS 32.299;
                    Rx - QoS/Policy, more in TS 29.214;
                    S6d - Authentication;
                    S9 - QoS/Policy;
                    Sh - Subscriber Profile;
                    Cx - Subscriber Profile;
                    e2 - Location.
But also few others specific to IMS

Nov 9, 2013

Resource: Basic LTE call flows and tutorials

Found this when surfing the web, maybe any of you will find it useful.
Most of the topics I've covered here, but this looks good for a Radio/Device reference.

Follow the link to get more, resource


Source:
LinkedIn, Internet

Nov 4, 2013

Extended Service Request procedure

The Extended Service Request and Service Request are same procedure just used for different purposes.
To make it simple, the below are color-coded. The cases when the Extended Service Request are triggered are marked light blue, the cases in black trigger Service Request procedure.

 Service Request triggers

a)    the UE in EMM-IDLE mode receives a paging request with CN domain indicator set to "PS" from the network;
b)    the UE, in EMM-IDLE mode, has pending user data to be sent;
c)    the UE, in EMM-IDLE mode, has uplink signalling pending;
d)    the UE in EMM-IDLE or EMM-CONNECTED mode is configured to use CS fallback and has a mobile originating CS fallback request from the upper layer;
e)    the UE in EMM-IDLE mode is configured to use CS fallback and receives a paging request with CN domain indicator set to "CS", or the UE in EMM-CONNECTED mode is configured to use CS fallback and receives a CS SERVICE NOTIFICATION message;
f)    the UE in EMM-IDLE or EMM-CONNECTED mode is configured to use 1xCS fallback and has a mobile originating 1xCS fallback request from the upper layer;
g)    the UE in EMM-CONNECTED mode is configured to use 1xCS fallback and accepts cdma2000® signalling messages containing a 1xCS paging request received over E-UTRAN;
h)    the UE, in EMM-IDLE mode, has uplink cdma2000® signalling pending to be transmitted over E-UTRAN;
i)    the UE, in EMM-IDLE or EMM-CONNECTED mode, is configured to use 1xCS fallback, accepts cdma2000® signalling messages containing a 1xCS paging request received over cdma2000®  1xRTT, and the network supports dual Rx CSFB or provide CS fallback registration parameters; or
j)    the UE, in EMM-IDLE or EMM-CONNECTED mode, has uplink cdma2000® signalling pending to be transmitted over cdma2000® 1xRTT, and the network supports dual Rx CSFB or provide CS fallback registration parameters.


Sep 30, 2013

Sep 26, 2013

LTE EPS mobility management timers - EMM timers

Lately many times I had to reach towards the EPS Mobility Management (EMM) timers, because it took me some time to google them here you go. Hope any one will find them as useful I did. 
In the two tables you can easily find the times name it's default or suggested value, what is triggering it and what happens in case it will finally expire.

Sep 24, 2013

Circuit Switched Fallback CSFB - Mobile Terminating call in idle mode

Previously I've covered the topic of CSFB when MT is in active mode. Today the below will cover situation when UE MT is in idle mode.

Fig. 1. CS Call with CSFB with MT UE in IDLE




1. G MSC receives IAM.
2. For the Send Routing Info (SRI) procedure please go to TS 23.018 3GPP.
3. G MSC sends IAM to the MSC on the terminating side.
4. The MME receives a Paging Request with MT side IMSI message from the MSC over a SGs interface. IMSI is used by the MME to find the S TMSI which is used as the paging address on the radio interface. If location information is reliably known by MME (i.e. MME stores the list of TAs), the MME shall page the UE in all the TAs. If the MME does not have a stored TA list for the UE, the MME should use the location information received from the MSC to page the UE.
This procedure takes place before step 3, immediately after MSC receives MAP_PRN from HSS, if pre-paging is deployed.
If the MME receives a Paging Request message for an UE which is considered as detach for EPS services, the MME sends the Paging reject message to the MSC with an appropriate cause value. This rejection triggers the MSC to page the UE over A or Iu-cs interface.
In case of a CS fallback capable UE in NMO II or III, there is a case where, for example, the MME releases the SGs association due to the UE idle mode mobility while the VLR still maintains the SGs association.
5. If the MME did not return an "SMS-only" indication to the UE during Attach or Combined TA/LA Update procedures, the MME sends a Paging message to each eNodeB. The Paging message includes a suitable UE Identity (i.e. S TMSI or IMSI) and a CN Domain Indicator that indicates which domain (CS or PS) initiated the paging message. In this case it shall be set to "CS" by the MME.
If the MME returned the "SMS-only" indication to the UE during Attach or Combined TA/LA Update procedures, the MME shall not send the paging to the eNodeBs and sends Paging Reject towards MSC to stop CS Paging procedure and this CSFB procedure stops.
6. The radio resource part of the paging procedure takes place. The message contains a suitable UE Identity (i.e. S TMSI or IMSI) and a CN Domain indicator.
7a. The UE establishes an RRC connection and sends an Extended Service Request (CS Fallback Indicator) to MME. The UE indicates its S-TMSI in the RRC signalling. The Extended Service Request message is encapsulated in RRC and S1 AP messages. The CS Fallback Indicator indicates to the MME that CS Fallback for this UE is required. The MME sends the SGs Service Request message to the MSC containing an indication that the UE was in idle mode (and hence, for example, that the UE has not received any Calling Line Identification information). Receipt of the SGs Service Request message stops the MSC retransmitting the SGs interface Paging message.
In order to avoid the calling party experiencing a potentially long period of silence, the MSC may use the SGs Service Request message containing the idle mode indication as a trigger to inform the calling party that the call is progressing.
7b.MME sends S1 AP: Initial UE Context Setup to indicate the eNodeB to move the UE to UTRAN/GERAN. The registered PLMN for CS domain is identified by the PLMN ID included in the LAI, which is allocated by the MME.
7c. (not visable above) The eNodeB shall reply with S1-AP: Initial UE Context Setup Response message.