Showing posts with label dual SIM. Show all posts
Showing posts with label dual SIM. Show all posts

Monday, October 24, 2011

Shake your profile

Shake your profile

Some may have seen the adverts on television where the film director on set shouts "action" and then, suddenly his phone starts to ring. He flips the phone onto its screen-face and the phone stops ringing. Motion sensors since 2009 have becoming one of the features on smart phones and devices, and a new release from Micromax Mobile X395 is another example where motion sensors (once switched ON) are included as a feature of this dual-SIM phone, but in this case allows the user to switch between one of the SIMs installed in this dual-SIM handset.

Photobucket

Media GIF Photo Courtesy of Micromax Mobile X395 (c)

Examiners should be aware that this java (according to its spec) smart phone requires manual examination to determine other user-defined SIM settings and Motion Sensor settings, apart from SIM1/SIM2 profiles -

Menu>SIM Manager:
- Dual SIM Settings- Set the dual settings as per your requirement
- Default SIM Selection- Choose the default SIM slot to be used

Menu > Settings > Motion Sensor Settings:
- An incoming call can be put on silent mode by simply turning it upside down

Some previous discussions at my blog about dual-SIMs or devices that may provide some useful observations about examining dual-SIM devices:

- http://trewmte.blogspot.com/2008/11/cloning-test-sim-cards.html
- http://trewmte.blogspot.com/2008/08/dual-international-mobile-station.html
- http://trewmte.blogspot.com/2007/06/china-mobile-telephones.html
- http://trewmte.blogspot.com/2006/11/super-ghost-sim.html

Research on 'tilt' and 'three axis way' motion sensors:

- http://en.wikipedia.org/wiki/Tilt_sensor
http://en.wikipedia.org/wiki/Accelerometer

Friday, June 18, 2010

GSM Timers

GSM Timers

In the thread Cell Site Analysis-Call Analysis it highlighted the range of Cause Failures for mobile calls. The overview it provided can be quite helpful, but behind those Cause Failures there can be a range of Timers and some of them can be the reason a Cause Failure occurs (positive or negative outcome). For example we can see that timer T3216 (below) in essence relates to the failure of a Immediate Assignment Request, but the "root cause" of the failure can infact be due to SDCCH congestion or poor radio link, such as: interference, coverage restriction or radio path imbalance. Understanding the "Causes for the cessation or loss of mobile communication" requires more than knowing the Cause Code or Timer but all the "root cause" behind them.

The Timer table below provides a useful but not exhaustive list. It essential to keep monitoring the GSM and 3GPP standards. Finally, it is important to recognise that Timers have different durations dependent upon when the timer is applicable. For instance, for radio resources management the durations are often denoted in seconds and some timers are in milliseconds.

However, other timer durations (expiration) are used for internal operation for devices such as mobile telephone or SIM and can be in minutes and in some instances hours. An example of the latter can be the elementary file EFHPLMN (7F206F31) - see GSM11.11. The Timer is set in decimal-digit increments e.g. 01, 02, 03 and so on. Each increment represents a value of n-minutes which the standard GSM0211 refers to as 6 minutes, but commonly rapid updates can cause drain on the mobile telephone's battery it is understood that n-minutes can be 30-minutes. The maximum the timer can be set for is 8-hours. The timer value is network operator dependent, which means either timer method may be used.

Timers and counters for radio resource management

Timers on the mobile station side
T3122: This timer is used during random access, after the receipt of an IMMEDIATE ASSIGN REJECT message.Its value is given by the network in the IMMEDIATE ASSIGN REJECT message.


T3124: This timer is used in the seizure procedure during a hand-over, when the two cells are not synchronized.Its purpose is to detect the lack of answer from the network to the special signal. Its value is set to 675 ms if the channel type of the channel allocated in the HANDOVER COMMAND is an SDCCH (+ SACCH); otherwise its value is set to 320 ms.

T3126:This timer is started either after sending the maximum allowed number of CHANNEL REQUEST messages during an immediate assignment procedure. Or on receipt of an IMMEDIATE ASSIGNMENT REJECT message, whichever occurs first. It is stopped at receipt of an IMMEDIATE ASSIGNMENT message, or an IMMEDIATE ASSIGNMENT EXTENDED message. At its expiry, the immediate assignment procedure is aborted. The minimum value of this timer is equal to the time taken by T+2S slots of the mobile station's RACH. S and T. The maximum value of this timer is 5 seconds.

T3128:This timer is started when the mobile station starts the uplink investigation procedure and the uplink is busy.It is stopped at receipt of the first UPLINK FREE message. At its expiry, the uplink investigation procedure is aborted. The value of this timer is set to 1 second.

T3130:This timer is started after sending the first UPLINK ACCESS message during a VGCS uplink access procedure.It is stopped at receipt of a VGCS ACCESS GRANT message.At its expiry, the uplink access procedure is aborted.The value of this timer is set to 5 seconds.

T3110:This timer is used to delay the channel deactivation after the receipt of a (full) CHANNEL RELEASE. Its purpose is to let some time for disconnection of the main signalling link. Its value is set to such that the DISC frame is sent twice in case of no answer from the network. (It should be chosen to obtain a good probability of normal termination (i.e. no time out of T3109) of the channel release procedure.)

T3134:This timer is used in the seizure procedure during an RR network commanded cell change order procedure. Its purpose is to detect the lack of answer from the network or the lack of availability of the target cell. Its value is set to 5 seconds.

T3142:The timer is used during packet access on CCCH, after the receipt of an IMMEDIATE ASSIGNMENT REJECT message. Its value is given by the network in the IMMEDIATE ASSIGNMENT REJECT message.

T3146:This timer is started either after sending the maximum allowed number of CHANNEL REQUEST messages during a packet access procedure. Or on receipt of an IMMEDIATE ASSIGNMENT REJECT message during a packet access procedure, whichever occurs first. It is stopped at receipt of an IMMEDIATE ASSIGNMENT message, or an IMMEDIATE ASSIGNMENT EXTENDED message. At its expiry, the packet access procedure is aborted. The minimum value of this timer is equal to the time taken by T+2S slots of the mobile station's RACH. S and T are defined in section 3.3.1.2. The maximum value of this timer is 5 seconds.

T3164:This timer is used during packet access using CCCH. It is started at the receipt of an IMMEDIATE ASSIGNMENT message. It is stopped at the transmission of a RLC/MAC block on the assigned temporary block flow, see GSM 04.60. At expire, the mobile station returns to the packet idle mode. The value of the timer is 5 seconds.

T3190:The timer is used during packet downlink assignment on CCCH. It is started at the receipt of an IMMEDIATE ASSIGNMENT message or of an PDCH ASSIGNMENT COMMAND message when in dedicated mode.It is stopped at the receipt of a RLC/MAC block on the assigned temporary block flow, see GSM 04.60. At expiry, the mobile station returns to the packet idle mode. The value of the timer is 5 seconds.

Timers on the network side
T3101:This timer is started when a channel is allocated with an IMMEDIATE ASSIGNMENT message. It is stopped when the MS has correctly seized the channels. Its value is network dependent. NOTE: It could be higher than the maximum time for a L2 establishment attempt.

T3103:This timer is started by the sending of a HANDOVER message and is normally stopped when the MS has correctly seized the new channel. Its purpose is to keep the old channels sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the HANDOVER COMMAND, plus the value of T3124, plus the maximum duration of an attempt to establish a data link in multiframe mode.)

T3105:This timer is used for the repetition of the PHYSICAL INFORMATION message during the hand-over procedure. Its value is network dependent. NOTE: This timer may be set to such a low value that the message is in fact continuously transmitted.

T3107:This timer is started by the sending of an ASSIGNMENT COMMAND message and is normally stopped when the MS has correctly seized the new channels. Its purpose is to keep the old channel sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the ASSIGNMENT COMMAND message plus twice the maximum duration of an attempt to establish a data link multiframe mode.

T3109:This timer is started when a lower layer failure is detected by the network, when it is not engaged in a RF procedure. It is also used in the channel release procedure. Its purpose is to release the channels in case of loss of communication. Its value is network dependent. NOTE: Its value should be large enough to ensure that the MS detects a radio link failure.

T3111:This timer is used to delay the channel deactivation after disconnection of the main signalling link. Its purpose is to let some time for possible repetition of the disconnection. Its value is equal to the value of T3110.

T3113:This timer is started when the network has sent a PAGING REQUEST message and is stopped when the network has received the PAGING RESPONSE message. Its value is network dependent. NOTE: The value could allow for repetitions of the Channel Request message and the requirements associated with T3101.

T3115:This timer is used for the repetition of the VGCS UPLINK GRANT message during the uplink access procedure. Its value is network dependent. NOTE: This timer may be set to such a low value that the message is in fact continuously transmitted.

T3117:This timer is started by the sending of a PDCH ASSIGNMENT COMMAND message and is normally stopped when the MS has correctly accessed the target TBF. Its purpose is to keep the old channel sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the PDCH ASSIGNMENT COMMAND message plus T3132 plus the maximum duration of an attempt to establish a data link in multiframe mode.

T3119:This timer is started by the sending of a RR-CELL CHANGE ORDER message and is normally stopped when the MS has correctly accessed the new cell. Its purpose is to keep the old channels sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent.NOTE: It could be higher than the maximum transmission time of the RR_CELL CHANGE ORDER, plus T3134, plus the maximum duration of an attempt to establish a data link in multiframe mode.

T3141:This timer is started when a temporary block flow is allocated with an IMMEDIATE ASSIGNMENT message during a packet access procedure. It is stopped when the mobile station has correctly seized the temporary block flow. Its value is network dependent.

Tuesday, August 12, 2008

Dual International Mobile station Equipment Identity (IMEI)

Dual International Mobile station Equipment Identity (IMEI)


When we think of mobile telephones we mostly think in terms of them of having a single International Mobile station Equipment Identity number. For two decades, whether for an analogue or digital mobile 'phone, we have often associated, to assist in showing importance of, and drawing anology about, that mobile 'phone serial numbers are alike to vehicle chassis numbers - in essence IMEIs are intended to be unique numbers.
.
Because of that unique numbering scheme, it follows that each mobile phone should only have one IMEI. That has changed and mobile 'phone manufacturers can include two IMEIs. The two IMEIs can be viewed via the label under the battery pack (see photo below Samsung SGH-D888), or by entering *#06# (asterisk, octothorp, 0, 6, octothorp).
.



.

Having reviewed the Standards and other documentation and found no definitive statement about the requirement for a dual IMEI numbering scheme, I put out some enquiries and I am grateful to those who assisted. I am told it would appear the occurrence of the dual IMEIs are due to there being two radio chipsets in some handsets. As I understand it, also, I won't find anything in the Standards about this matter - just yet. Moreover, it does not automatically follow that a handset having Dual SIM/USIM slots implies or infers that the handset has two radio chipsets, thus two IMEIs.

.

Evidentially, of course it is noted this matter impacts in numerous ways when conducting examination using automated physical and/or logical harvesting of data and the much-needed handset (manual) examination.

Tuesday, July 15, 2008

Join MTEB Forum if your are in wireless / telecomms

Join MTEB Forum if your are in wireless / telecomms

.
If you work in forensics and/or examination devices, investigations or deal with evidence then the MTEB forum puts you in contact with other professionals when you need help with technical issues, technical discussions or generally want to stay up to date. Due to the make up of the forum members: experts, high level security, law enforcement and senior investigators requests to join are vetted.
.
.
Invitation to Join Mobile Telephone Examination Board
--------------------------------------------------------
The MTEB forum is dedicated to evidential standards, forensic examination and lawful interception dealing with mobile telephones/SIM/USIM/MMC, bluetooth, IrDA, USB, cell site analysis and mobile networks GSM, CDMA, 3G, 4G.
.
Link if you are NOT a LinkedIn member:

http://www.linkedin.com/groupInvitation?groupID=141739&sharedKey=35E59F107179

Link if you are a LinkedIn member:
http://www.linkedin.com/groupsDirectory?results=&sik=1216135556335

Join MTEB Forum if your are in wireless / telecomms

Join MTEB Forum if your are in wireless / telecomms

.
If you work in forensics and/or examination devices, investigations or deal with evidence then the MTEB forum puts you in contact with other professionals when you need help with technical issues, technical discussions or generally want to stay up to date. Due to the make up of the forum members: experts, high level security, law enforcement and senior investigators requests to join are vetted.
.
.
Invitation to Join Mobile Telephone Examination Board
--------------------------------------------------------
The MTEB forum is dedicated to evidential standards, forensic examination and lawful interception dealing with mobile telephones/SIM/USIM/MMC, bluetooth, IrDA, USB, cell site analysis and mobile networks GSM, CDMA, 3G, 4G.
.
Link if you are NOT a LinkedIn member:

http://www.linkedin.com/groupInvitation?groupID=141739&sharedKey=35E59F107179

Link if you are a LinkedIn member:
http://www.linkedin.com/groupsDirectory?results=&sik=1216135556335

Friday, March 07, 2008

GSM Timers

GSM Timers


In the thread cell site anslysis call analysis <http://trewmte.blogspot.com/2006/12/cell-site-analysis-call-analysis.html> it highlighted the range of Cause Failures for mobile calls. The overview it provided can be quite helpful, but behind those Cause Failures there can be a range of Timers and some of them can be the reason a Cause Failure occurs (positive or negative outcome). For example we can see that timer T3216 (below) in essence relates to the failure of a Immediate Assignment Request, but the "root cause" of the failure can infact be due to SDCCH congestion or poor radio link, such as: interference, coverage restriction or radio path imbalance. Understanding the "Causes for the cessation or loss of mobile communication" requires more than knowing the Cause Code or Timer but all the "root cause" behind them.



The Timer table below provides a useful but not exhaustive list. It essential to keep monitoring the GSM and 3GPP standards. Finally, it is important to recognise that Timers have different durations dependent upon when the timer is applicable. For instance, for radio resources management the durations are often denoted in seconds and some timers are in milliseconds.



However, other timer durations (expiration) are used for internal operation for devices such as mobile telephone or SIM and can be in minutes and in some instances hours. An example of the latter can be the elementary file EFHPLMN (7F206F31) - see GSM11.11. The Timer is set in decimal-digit increments e.g. 01, 02, 03 and so on. Each increment represents a value of n-minutes which the standard GSM0211 refers to as 6 minutes, but commonly rapid updates can cause drain on the mobile telephone's battery it is understood that n-minutes can be 30-minutes. The maximum the timer can be set for is 8-hours. The timer value is network operator dependent, which means either timer method may be used.



Timers and counters for radio resource management



Timers on the mobile station side

T3122: This timer is used during random access, after the receipt of an IMMEDIATE ASSIGN REJECT message.Its value is given by the network in the IMMEDIATE ASSIGN REJECT message.




T3124: This timer is used in the seizure procedure during a hand-over, when the two cells are not synchronized.Its purpose is to detect the lack of answer from the network to the special signal. Its value is set to 675 ms if the channel type of the channel allocated in the HANDOVER COMMAND is an SDCCH (+ SACCH); otherwise its value is set to 320 ms.



T3126:This timer is started either after sending the maximum allowed number of CHANNEL REQUEST messages during an immediate assignment procedure. Or on receipt of an IMMEDIATE ASSIGNMENT REJECT message, whichever occurs first. It is stopped at receipt of an IMMEDIATE ASSIGNMENT message, or an IMMEDIATE ASSIGNMENT EXTENDED message. At its expiry, the immediate assignment procedure is aborted. The minimum value of this timer is equal to the time taken by T+2S slots of the mobile station's RACH. S and T. The maximum value of this timer is 5 seconds.



T3128:This timer is started when the mobile station starts the uplink investigation procedure and the uplink is busy.It is stopped at receipt of the first UPLINK FREE message. At its expiry, the uplink investigation procedure is aborted. The value of this timer is set to 1 second.



T3130:This timer is started after sending the first UPLINK ACCESS message during a VGCS uplink access procedure.It is stopped at receipt of a VGCS ACCESS GRANT message.At its expiry, the uplink access procedure is aborted.The value of this timer is set to 5 seconds.



T3110:This timer is used to delay the channel deactivation after the receipt of a (full) CHANNEL RELEASE. Its purpose is to let some time for disconnection of the main signalling link. Its value is set to such that the DISC frame is sent twice in case of no answer from the network. (It should be chosen to obtain a good probability of normal termination (i.e. no time out of T3109) of the channel release procedure.)



T3134:This timer is used in the seizure procedure during an RR network commanded cell change order procedure. Its purpose is to detect the lack of answer from the network or the lack of availability of the target cell. Its value is set to 5 seconds.



T3142:The timer is used during packet access on CCCH, after the receipt of an IMMEDIATE ASSIGNMENT REJECT message. Its value is given by the network in the IMMEDIATE ASSIGNMENT REJECT message.



T3146:This timer is started either after sending the maximum allowed number of CHANNEL REQUEST messages during a packet access procedure. Or on receipt of an IMMEDIATE ASSIGNMENT REJECT message during a packet access procedure, whichever occurs first. It is stopped at receipt of an IMMEDIATE ASSIGNMENT message, or an IMMEDIATE ASSIGNMENT EXTENDED message. At its expiry, the packet access procedure is aborted. The minimum value of this timer is equal to the time taken by T+2S slots of the mobile station's RACH. S and T are defined in section 3.3.1.2. The maximum value of this timer is 5 seconds.



T3164:This timer is used during packet access using CCCH. It is started at the receipt of an IMMEDIATE ASSIGNMENT message. It is stopped at the transmission of a RLC/MAC block on the assigned temporary block flow, see GSM 04.60. At expire, the mobile station returns to the packet idle mode. The value of the timer is 5 seconds.



T3190:The timer is used during packet downlink assignment on CCCH. It is started at the receipt of an IMMEDIATE ASSIGNMENT message or of an PDCH ASSIGNMENT COMMAND message when in dedicated mode.It is stopped at the receipt of a RLC/MAC block on the assigned temporary block flow, see GSM 04.60. At expiry, the mobile station returns to the packet idle mode. The value of the timer is 5 seconds.



Timers on the network side

T3101:This timer is started when a channel is allocated with an IMMEDIATE ASSIGNMENT message. It is stopped when the MS has correctly seized the channels. Its value is network dependent. NOTE: It could be higher than the maximum time for a L2 establishment attempt.



T3103:This timer is started by the sending of a HANDOVER message and is normally stopped when the MS has correctly seized the new channel. Its purpose is to keep the old channels sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the HANDOVER COMMAND, plus the value of T3124, plus the maximum duration of an attempt to establish a data link in multiframe mode.)



T3105:This timer is used for the repetition of the PHYSICAL INFORMATION message during the hand-over procedure. Its value is network dependent. NOTE: This timer may be set to such a low value that the message is in fact continuously transmitted.



T3107:This timer is started by the sending of an ASSIGNMENT COMMAND message and is normally stopped when the MS has correctly seized the new channels. Its purpose is to keep the old channel sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the ASSIGNMENT COMMAND message plus twice the maximum duration of an attempt to establish a data link multiframe mode.



T3109:This timer is started when a lower layer failure is detected by the network, when it is not engaged in a RF procedure. It is also used in the channel release procedure. Its purpose is to release the channels in case of loss of communication. Its value is network dependent. NOTE: Its value should be large enough to ensure that the MS detects a radio link failure.



T3111:This timer is used to delay the channel deactivation after disconnection of the main signalling link. Its purpose is to let some time for possible repetition of the disconnection. Its value is equal to the value of T3110.



T3113:This timer is started when the network has sent a PAGING REQUEST message and is stopped when the network has received the PAGING RESPONSE message. Its value is network dependent. NOTE: The value could allow for repetitions of the Channel Request message and the requirements associated with T3101.



T3115:This timer is used for the repetition of the VGCS UPLINK GRANT message during the uplink access procedure. Its value is network dependent. NOTE: This timer may be set to such a low value that the message is in fact continuously transmitted.



T3117:This timer is started by the sending of a PDCH ASSIGNMENT COMMAND message and is normally stopped when the MS has correctly accessed the target TBF. Its purpose is to keep the old channel sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the PDCH ASSIGNMENT COMMAND message plus T3132 plus the maximum duration of an attempt to establish a data link in multiframe mode.



T3119:This timer is started by the sending of a RR-CELL CHANGE ORDER message and is normally stopped when the MS has correctly accessed the new cell. Its purpose is to keep the old channels sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent.NOTE: It could be higher than the maximum transmission time of the RR_CELL CHANGE ORDER, plus T3134, plus the maximum duration of an attempt to establish a data link in multiframe mode.



T3141:This timer is started when a temporary block flow is allocated with an IMMEDIATE ASSIGNMENT message during a packet access procedure. It is stopped when the mobile station has correctly seized the temporary block flow. Its value is network dependent.




More on Cell Site Analysis: http://cellsiteanalysis.blogspot.com

GSM Timers

GSM Timers

In the thread cell site anslysis call analysis <http://trewmte.blogspot.com/2006/12/cell-site-analysis-call-analysis.html; it highlighted the range of Cause Failures for mobile calls. The overview it provided can be quite helpful, but behind those Cause Failures there can be a range of Timers and some of them can be the reason a Cause Failure occurs (positive or negative outcome). For example we can see that timer T3216 (below) in essence relates to the failure of a Immediate Assignment Request, but the "root cause" of the failure can infact be due to SDCCH congestion or poor radio link, such as: interference, coverage restriction or radio path imbalance. Understanding the "Causes for the cessation or loss of mobile communication" requires more than knowing the Cause Code or Timer but all the "root cause" behind them.

The Timer table below provides a useful but not exhaustive list. It essential to keep monitoring the GSM and 3GPP standards. Finally, it is important to recognise that Timers have different durations dependent upon when the timer is applicable. For instance, for radio resources management the durations are often denoted in seconds and some timers are in milliseconds.

However, other timer durations (expiration) are used for internal operation for devices such as mobile telephone or SIM and can be in minutes and in some instances hours. An example of the latter can be the elementary file EFHPLMN (7F206F31) - see GSM11.11. The Timer is set in decimal-digit increments e.g. 01, 02, 03 and so on. Each increment represents a value of n-minutes which the standard GSM0211 refers to as 6 minutes, but commonly rapid updates can cause drain on the mobile telephone's battery it is understood that n-minutes can be 30-minutes. The maximum the timer can be set for is 8-hours. The timer value is network operator dependent, which means either timer method may be used.

Timers and counters for radio resource management

Timers on the mobile station side
T3122: This timer is used during random access, after the receipt of an IMMEDIATE ASSIGN REJECT message.Its value is given by the network in the IMMEDIATE ASSIGN REJECT message.


T3124: This timer is used in the seizure procedure during a hand-over, when the two cells are not synchronized.Its purpose is to detect the lack of answer from the network to the special signal. Its value is set to 675 ms if the channel type of the channel allocated in the HANDOVER COMMAND is an SDCCH (+ SACCH); otherwise its value is set to 320 ms.

T3126:This timer is started either after sending the maximum allowed number of CHANNEL REQUEST messages during an immediate assignment procedure. Or on receipt of an IMMEDIATE ASSIGNMENT REJECT message, whichever occurs first. It is stopped at receipt of an IMMEDIATE ASSIGNMENT message, or an IMMEDIATE ASSIGNMENT EXTENDED message. At its expiry, the immediate assignment procedure is aborted. The minimum value of this timer is equal to the time taken by T+2S slots of the mobile station's RACH. S and T. The maximum value of this timer is 5 seconds.

T3128:This timer is started when the mobile station starts the uplink investigation procedure and the uplink is busy.It is stopped at receipt of the first UPLINK FREE message. At its expiry, the uplink investigation procedure is aborted. The value of this timer is set to 1 second.

T3130:This timer is started after sending the first UPLINK ACCESS message during a VGCS uplink access procedure.It is stopped at receipt of a VGCS ACCESS GRANT message.At its expiry, the uplink access procedure is aborted.The value of this timer is set to 5 seconds.

T3110:This timer is used to delay the channel deactivation after the receipt of a (full) CHANNEL RELEASE. Its purpose is to let some time for disconnection of the main signalling link. Its value is set to such that the DISC frame is sent twice in case of no answer from the network. (It should be chosen to obtain a good probability of normal termination (i.e. no time out of T3109) of the channel release procedure.)

T3134:This timer is used in the seizure procedure during an RR network commanded cell change order procedure. Its purpose is to detect the lack of answer from the network or the lack of availability of the target cell. Its value is set to 5 seconds.

T3142:The timer is used during packet access on CCCH, after the receipt of an IMMEDIATE ASSIGNMENT REJECT message. Its value is given by the network in the IMMEDIATE ASSIGNMENT REJECT message.

T3146:This timer is started either after sending the maximum allowed number of CHANNEL REQUEST messages during a packet access procedure. Or on receipt of an IMMEDIATE ASSIGNMENT REJECT message during a packet access procedure, whichever occurs first. It is stopped at receipt of an IMMEDIATE ASSIGNMENT message, or an IMMEDIATE ASSIGNMENT EXTENDED message. At its expiry, the packet access procedure is aborted. The minimum value of this timer is equal to the time taken by T+2S slots of the mobile station's RACH. S and T are defined in section 3.3.1.2. The maximum value of this timer is 5 seconds.

T3164:This timer is used during packet access using CCCH. It is started at the receipt of an IMMEDIATE ASSIGNMENT message. It is stopped at the transmission of a RLC/MAC block on the assigned temporary block flow, see GSM 04.60. At expire, the mobile station returns to the packet idle mode. The value of the timer is 5 seconds.

T3190:The timer is used during packet downlink assignment on CCCH. It is started at the receipt of an IMMEDIATE ASSIGNMENT message or of an PDCH ASSIGNMENT COMMAND message when in dedicated mode.It is stopped at the receipt of a RLC/MAC block on the assigned temporary block flow, see GSM 04.60. At expiry, the mobile station returns to the packet idle mode. The value of the timer is 5 seconds.

Timers on the network side
T3101:This timer is started when a channel is allocated with an IMMEDIATE ASSIGNMENT message. It is stopped when the MS has correctly seized the channels. Its value is network dependent. NOTE: It could be higher than the maximum time for a L2 establishment attempt.

T3103:This timer is started by the sending of a HANDOVER message and is normally stopped when the MS has correctly seized the new channel. Its purpose is to keep the old channels sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the HANDOVER COMMAND, plus the value of T3124, plus the maximum duration of an attempt to establish a data link in multiframe mode.)

T3105:This timer is used for the repetition of the PHYSICAL INFORMATION message during the hand-over procedure. Its value is network dependent. NOTE: This timer may be set to such a low value that the message is in fact continuously transmitted.

T3107:This timer is started by the sending of an ASSIGNMENT COMMAND message and is normally stopped when the MS has correctly seized the new channels. Its purpose is to keep the old channel sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the ASSIGNMENT COMMAND message plus twice the maximum duration of an attempt to establish a data link multiframe mode.

T3109:This timer is started when a lower layer failure is detected by the network, when it is not engaged in a RF procedure. It is also used in the channel release procedure. Its purpose is to release the channels in case of loss of communication. Its value is network dependent. NOTE: Its value should be large enough to ensure that the MS detects a radio link failure.

T3111:This timer is used to delay the channel deactivation after disconnection of the main signalling link. Its purpose is to let some time for possible repetition of the disconnection. Its value is equal to the value of T3110.

T3113:This timer is started when the network has sent a PAGING REQUEST message and is stopped when the network has received the PAGING RESPONSE message. Its value is network dependent. NOTE: The value could allow for repetitions of the Channel Request message and the requirements associated with T3101.

T3115:This timer is used for the repetition of the VGCS UPLINK GRANT message during the uplink access procedure. Its value is network dependent. NOTE: This timer may be set to such a low value that the message is in fact continuously transmitted.

T3117:This timer is started by the sending of a PDCH ASSIGNMENT COMMAND message and is normally stopped when the MS has correctly accessed the target TBF. Its purpose is to keep the old channel sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent. NOTE: It could be higher than the maximum transmission time of the PDCH ASSIGNMENT COMMAND message plus T3132 plus the maximum duration of an attempt to establish a data link in multiframe mode.

T3119:This timer is started by the sending of a RR-CELL CHANGE ORDER message and is normally stopped when the MS has correctly accessed the new cell. Its purpose is to keep the old channels sufficiently long for the MS to be able to return to the old channels, and to release the channels if the MS is lost. Its value is network dependent.NOTE: It could be higher than the maximum transmission time of the RR_CELL CHANGE ORDER, plus T3134, plus the maximum duration of an attempt to establish a data link in multiframe mode.

T3141:This timer is started when a temporary block flow is allocated with an IMMEDIATE ASSIGNMENT message during a packet access procedure. It is stopped when the mobile station has correctly seized the temporary block flow. Its value is network dependent.


More on Cell Site Analysis: http://cellsiteanalysis.blogspot.com

Saturday, June 16, 2007

China Mobile Telephones

China Mobile Telephone Exports
It wasn't difficult to guess that with China's industrial revolution into manufacturing everything and its growth markets in mobile telephones that China would aim to compete with the world's best known handset brandnames, such as Nokia, Motorola, Samsung, SonyEricsson, Alcatel, Sagem etc. I thought it might be helpful for mobile telephone examiners to be aware of the new China mobile telephone imports and publish a list of new arrivals of mobile telephones from China. The list is not exhaustive and covers those models that are available now. All of these handsets are operating in the frequency ranges of: 900MHz, 1800MHz and 1900MHz.

A818 Multi-media Phone +Bluetooth
BEST D2000 Multi-media Phone
BOEING 777 Dual SIM Card Phone
BELLWAVE 830 Dual SIM Card Phone
CECT Q500
CECT C1000+ Dual SIM Card Phone
CECT 1000D
CECT A800
CECT Jie Bao
CECT N90 Dual SIM Card Phone
CECT V8 Multi-media Phone + Bluetooth
CECT Q500 Dual SIM Card Phone + Bluetooth
CECT N538 Dual SIM Card Phone
CECT 1000D Dual SIM Card Phone
CECT A800 Dual SIM Card Phone + Bluetooth
CECT A706-2 Dual SIM Card Phone + Bluetooth
CECT N95 Dual SIM Card Phone + Bluetooth
CECT Y890 Dual SIM Card Phone
CECT C1000I Dual SIM Card Phone
CECT W958 Multi-media Phone
CECT N788 Multi-media Phone
CECT C99 Dual SIM Card Phone
CECT Q500 Dual SIM Card Phone
CECT N55 Multi-media Phone
CECT A900 Dual SIM Card Phone + Bluetooth
CECT V007 Multi-media Phone
CoolPAD 728B GSM + CDMA
CoolPAD 298 GSM + CDMA
CoolPAD 288 GSM + CDMA
HUI FENG 666 Multi-media Phone
HUI BAO 520 Dual SIM Card Phone + Bluetooth
ICOOL D66 Dual SIM Card Phone + Bluetooth
JIN SHA A203 Dual SIM Card Phone
JIA XIN N95 Dual SIM Card Phone + Bluetooth
K007 Multi-media Phone + Bluetooth
KAI RUI 666 Multi-media Phone
KAI RUI 169 Multi-media Phone
LANG XING M558 Dual SIM Card Phone
Long Run L821 Dual SIM Card Phone + Bluetooth
Ma Bao 99 Dual SIM Card Phone
NCKIA E95 Dual SIM Card Phone + Bluetooth
O3 838 Multi-media Phone + Bluetooth
Qi Tai X689+ / ZT 68 Dual SIM Card Phone + Bluetooth
San Sunc N96 Dual SIM Card Phone + Bluetooth
TIAN Long 788 Multi-media Phone
TIAN SHI XING T900 Dual SIM Card Phone
Ya Qi Yi Hao Dual SIM Card Phone + Bluetooth
Zhong Than 199 Dual SIM Card Phone + Bluetooth
ZT 988 Dual SIM Card Phone
ZTC 988 Multi-media Phone
ZTC C2000 Dual SIM Card Phone

Tuesday, November 07, 2006

Super Ghost SIM

Interesting product but which 3F002FE27F206F07 would be relevant? ... happy mobile telephone evidence hunting...



Super Ghost SIM

- NEW FEATURE! Switch between SIMs via the phone's menu!
- NEW FEATURE! Option to auto switch between SIMs every 1-99 minutes
- use the manual sim selection option if you don't want to auto switch
- allows you to use two SIM cards in one phone
- no need to cut your SIM card like with similar products
- more convenient than removing your back cover/battery every time you want to swap SIM cards
- combine business/personal lines and address books on one handset
- switch between networks easily - no more coverage problems!
- take advantages of cheaper rates from different phone companies
- saves your previous calls, received calls, time and date settings etc.
- new ultra slim design - sits inbetween your battery and back cover
- no need to replace your phone's back cover - the ghost SIMs sit inbetween your battery and standard back cover
- works with all SIMs (including 3)
- can be used to add another 200 contacts to your phone book via the second sim card (sim dependent)
- works with virtually all makes and models
- also known as dual SIMs/twin SIMs

http://www.formymobile.co.uk/proddetail.php?prod=supersim

Super Ghost SIM

Interesting product but which 3F002FE27F206F07 would be relevant? ... happy mobile telephone evidence hunting...



Super Ghost SIM

- NEW FEATURE! Switch between SIMs via the phone's menu!
- NEW FEATURE! Option to auto switch between SIMs every 1-99 minutes
- use the manual sim selection option if you don't want to auto switch
- allows you to use two SIM cards in one phone
- no need to cut your SIM card like with similar products
- more convenient than removing your back cover/battery every time you want to swap SIM cards
- combine business/personal lines and address books on one handset
- switch between networks easily - no more coverage problems!
- take advantages of cheaper rates from different phone companies
- saves your previous calls, received calls, time and date settings etc.
- new ultra slim design - sits inbetween your battery and back cover
- no need to replace your phone's back cover - the ghost SIMs sit inbetween your battery and standard back cover
- works with all SIMs (including 3)
- can be used to add another 200 contacts to your phone book via the second sim card (sim dependent)
- works with virtually all makes and models
- also known as dual SIMs/twin SIMs

http://www.formymobile.co.uk/proddetail.php?prod=supersim