Showing posts with label IMEI. Show all posts
Showing posts with label IMEI. Show all posts

Wednesday, January 10, 2018

URN Namespace and IMEI

RFC8141 - A Uniform Resource Name (URN) is a Uniform Resource Identifier (URI) [ RFC3986] that is assigned under the "urn" URI scheme and a particular URN namespace, with the intent that the URN will be a persistent, location-independent resource identifier. A URN namespace is a collection of such URNs, each of which is (1) unique, (2) assigned in a consistent and managed way, and (3) assigned according to a common definition. (https://tools.ietf.org/pdf/rfc8141.pdf).

Image courtesy of Diameter-Protocol

RFC7255 - This specification defines how the Uniform Resource Name (URN) reserved for the Global System for Mobile Communications Association (GSMA) identities and its sub-namespace for the International Mobile station Equipment Identity (IMEI) can be used as an instance-id. Its purpose is to fulfil the requirements for defining how a specific URN needs to be constructed and used in the ’+sip.instance’ Contact header field parameter for outbound behaviour. (https://www.rfc-editor.org/rfc/pdfrfc/rfc7255.txt.pdf).

RFC7254 - This specification defines a Uniform Resource Name (URN) namespace for the Global System for Mobile Communications Association (GSMA) and a Namespace Specific String (NSS) for the International Mobile station Equipment Identity (IMEI), as well as an associated parameter for the International Mobile station Equipment Identity and Software Version number (IMEISV) as per the namespace registration requirement found in RFC 3406 [ 1]. The Namespace Identifier (NID) ’gsma’ is for identities used in GSM, Universal Mobile Telecommunications System (UMTS), and Long Term Evolution (LTE) networks. The IMEI and the IMEISV are managed by the GSMA, so this NID is managed by the GSMA. (https://tools.ietf.org/pdf/rfc7254.pdf).

Saturday, January 04, 2014

Tracing Packet Switch (PS) Users

Investigations into mobile activity tend largely to concentrate on recovering data from the user handset, mast (tower) data and call records. The core network (CN) is less well understood and therefore picking through a GSM/3GPP standard can often assist in understanding the identity and form of tarried/empheral data surviving in a network. The standard to be used for this discussion is:

3GPP TS 25.413 V12.0.0 (2013-12)
3rd Generation Partnership Project;
Technical Specification Group Radio Access Network;
UTRAN Iu interface
Radio Access Network Application Part (RANAP) signalling
(Release 12)


Now with an investigation underway initial enquiries lead to an active smartphone user operating in the pack switched (PS) domain. The target under surveillance requires the investigator to combine visual logs and the use of the of the handset. Unlike CS, packet data communications requires a range of information BUT for the purposes of the current investigation understanding the services being used and the geographical area where services are being obtained the trainee investigator can start with understanding what can be learned from:

Cell ID - Cell Identity
C-ID - Common Identity
IMEI - International Mobile Equipment Identity

IMSI - International Mobile Subscriber Identity
IPAddress - Internet Protocol Address
SAI - Service Area Identifier

SAP - Service Access Point
LAI  - Location Area Identifier
RNC - Radio Network Controller

RNS  - Radio Network Subsystem

Some examples of trainee investigation elements for consideration:

Para 8.16.1

The purpose of the Common ID procedure is to inform the RNC about the permanent NAS UE Identity (i.e. IMSI) of a user. This is used by the RNC e.g. to create a reference between the permanent NAS UE identity of the user and the RRC connection of that user for UTRAN paging co-ordination. The procedure may also be used to provide the SNA Access Information IE to the RNC or to provide the Management Based MDT Allowed IE to the RNC or to provide the Management Based MDT PLMN List IE to the RNC.


Para 8.17.2

If Trace Collection Entity IP Address IE is included and if the MDT Configuration IE is also included then the RNC shall, if supported, store the Trace Collection Entity IP address and use it when transferring Trace records, otherwise if MDT Configuration IE is not included, the RNC may use the Trace Collection Entity IP address when transferring trace records.


Para 8.35.2
When the transferred information in the Information Transfer Type IE relates to a Trace Session in the RNC, the Trace Activation Indicator IE indicates whether the Trace Session identified by the Trace Reference IE is activated or deactivated in the RNC. In case the Trace Session is activated, the Equipments To Be Traced IE gives the Equipment Identity of the UEs that the RNC has to trace. If the Trace Recording Session Reference IE, Trace Collection Entity IP Address IE, the IMSI IE and optionally the Serving Cell Identifier IE are included in the message, the CN shall take the information into account for anonymization of MDT data (TS 32.422 [10]).
 
The purpose of this brief discussion is to illustrate mobile networks naturally hold surviving data in the network for a range of reasons to enable the network to a have uniformed approach for the objective of operational performance, enquiry and, equally, to trace user terminals and roaming user terminals active in or obtaining services from a network.

Monday, November 26, 2012

US Handset Serial Number Databases

US Handset Serial Number Databases

US operators maintain their own stolen and blacklisted cellphone databases. As of the 31st October 2012 the GSM operators AT&T and T-Mobile began sharing their databases. CDMA operators Verizon and Sprint have taken the decision to merge their databases but that will not be complete until November 2013, so we are told.

The said objective of these initiatives are to improve track and trace. As an example, GSM uses a 56-bit decimal digit s/n, whereas CDMA uses a 56-bit hexadecimal digitals s/n. However, in the US there are variations of s/ns to consider.

The engine for these changes is driven by the FCC initiative - http://www.fcc.gov/document/announcement-new-initiatives-combat-smartphone-and-data-theft

To accommodate this and other cellphone/cellular changes I have altered my CDMA training material and GSM training material. As consequence these changes will also have an impact on WCDMA and LTE, either on a national level or international level. These training materials have also changed, too.

_________________
Institute for Digital Forensics (IDF) - LinkedIn
Mobile Telephone Examination Board (MTEB) - LinkedIn

Sunday, September 30, 2012

Kenya bans counterfeit mobiles being used

Kenya bans counterfeit mobiles being used

"Kenya is set to switch off all uncertified mobile phones in the country by the end of September in an effort to curb security threats and halt the illegal trade of counterfeit phones....." according to http://sabahionline.com/en_GB/articles/hoa/articles/features/2012/09/20/feature-01

The ban that is targetted towards mobile phones that do not have programmed an assigned IMEI could take huge resources to police. Confiscating handsets sold by traders is unlikely to achieve the intended results, which suggests the mobile network operators may be required to instruct handsets to transmit their IMEIs at registration or OACSU prior to calls/texts being sent or received. This effort being made by Kenya is probably welcome news to genuine brand-name manufacturers fed up with counterfeits eroding the marketplace.

Moreover, visitors using counterfeit mobile phones roaming on Kenya's mobile networks may well be caught up in the ban, too, due to the difficulty of using mobile phones, whilst attempting to make roaming calls, because the handsets may be uncertified. Most holiday-makers might not know to check to see if their handset is certified before travelling to the country.

It is assumed that the CCK have already planned beyond the stage of blocking handsets without IMEIs and detecting and blocking handsets programmed with cloned/false IMEIs in order to mask counterfeit devices.

Saturday, September 22, 2012

Threats and Forcing SMS delay

Following my article France Car Shootings and Mobile Evidence http://www.trewmte.blogspot.co.uk/2012/09/france-car-shootings-and-mobile-evidence.html an investigator, previously working with a well-known cellular and fixed network manufacturer, confirmed to me the results of an internal forensics investigation which he conducted.


An employee had made threats to a Director. The employee had been found to use a 'prepaid sim' card to send theat messages but added a delay period for the sent messages of 2-hours. The employee then switched OFF the handset and inserted the company SIM card into the same handset which had previously held the prepaid SIM that had sent the threat messages. The handset with the company SIM card in it was then switched ON; the employee claimed not to have been responsible for the threats sent from a different IMSI (SIM card).  The intention of the employee was to mask any connection with the threats. However, tracing the IMSIs of the prepaid SIM card and the company SIM card found both to have been operating in the same handset (IMEI). Such trace capability can be made from enquiries of network databases such as BTS, HLR etc. Moreover with high levels of text messaging that are sent and received whilst roaming there is trace capability that can be made by interrogating CAMEL.

There is also useful data that can be obtained for linking with cell site analysis (CSA), which is a bonus although there appears to be some confusion occuring in the US at the moment as to the value of CSA evidence http://www.forensicfocus.com/Forums/viewtopic/t=9679/ and how the material may be applied on a case by case basis. I am not convinced that licenced operators with highly developed as they are in the US cellular networks simply could not/would not sufficient call record/cell data available to know what is happening when an MS has been active in their networks, about the arrangement at a particular mast (cell tower) as used by an MS, the configuration of the radio network operating at the time an MS has been used and so on.

Monday, February 22, 2010

Humanitarian Aid or Pay As You Throw?

Humanitarian Aid or Pay As You Throw?


Vodafone's 150 design shape reminds me that this looks like a squared-edged version of the old rounded-edged Phillips Savvy (back when Virgin Mobile sold it in a box through their music chain stores) that use to be on the market. One distinction here though is that Vodi is selling the Vodafone-150 into developing countries India, Turkey and eight African countries including Lesotho, Kenya and Ghana at $15.00 (£10.00). The disclosed objective is a worthy and laudable aim that out there in the Africa countries communications relevant to voice calls, SMS, financial transfers and healthcare have more importance and relevance than touch screen functionality, games and posturing as to who has a weird app that they want to boast about.
.

The spec given for this product:
.

"Vodafone 150 device specification: Black candy bar device with 5-way navigation key; 1.0” monochrome graphic display 96x64 pixels; voice and SMS; GSM 900/1800; polyphonic ringtones; vibration; alarm clock; calculator; currency converter; 2 embedded games; memory for up to 100 entries in phonebook plus SMS storage; torch; battery: 500mAh (standby up to 400h, talk time up to 5h); mini USB connector."
.

A truly magnificent gesture on behalf of the international community would be to allow mobile phone credits to be used to purchase food and water, medicine, etc other than only allowing it to be solely used to make a mobile calls, whilst idly sitting by watching human life being put at risk. What could there ever be the point in watching people die of starvation and dehydration?
.

Imagine for each mobile phone user a maximum credit to purchase life sustaining essentials could be made available. Imagine that specialist supply waypoints (International Humanitarian Aid Points) were setup whereby the genuine user can get food/water, medicines etc, then the waypoints can check the applicants wanting the food/water, medicines are the genuine users of the phones. What a fantastic way that would be for finitely targetting humanitarian monetary aid to those in need.
.
Of course, it is not unrealistic to observe that there is also a calculated risk being taken here that cheap handsets can lead to their owners using them as disposal objects, as opposed to meaningful devices. Any owner migrating as a roaming-user are unlikely to be barred from making calls because the handsets are dual band RF chipset(s) (GSM MHz900/GSM MHZ1800) so should work in any GSM network.
.

Cheap handset can also make them a target for unlocking. It is not hard to imagine, cheap phones like these will not be long out of the cargo doors before they are being supplied into Europe. So this is one of the calculated risks (the other side of the coin so to speak). Such low-cost handsets (or officially "ULCH phones") are not new. We were already aware of ULCH's some years back but they have now grown in status as viable products because of the World recession. Cheap handsets are in Europe at the moment and regularly used in crime and thown away afterwards.
.
.

How might any operator stop such ULCH phones being used for making chargeable calls where such calls are being made for the purposes of the commission of a crime? Well, the first obvious point is to include a validity integrity key (VIK) to be transmitted along with the IMEI and associate the VIK to the IMEI at manufacturing production stage. Were someone to clone the IMEI of a handset it would not be associated with the VIK and therefore the network could detect this and block the handset from making calls. Equally, if the financial credits on the phone were from Humanitarian Aid, then the network operator could equally help in stopping that credit being spent on phone calls associated with crime because of the VIK conflict with cloned IMEI and/or because the phone isn't in the geographical region to which it was expected to operate (as a humanitarian aid phone). Moreover, the idea of security VIK/IMEI could be implemented in every new handset issued and maybe able to be implemented via SMS Class 1 messages to older handsets already in the marketplace. Realistically, how long would this take to be implemented? It depends, in as simpler statement that can be made, how long it takes to implement signalling in the network to the EIR and a response from the EIR.
.

I have sent this thread up to President of the United States of America, Mr Barack Obama, to the World Health Organisation, Oxfam, and to UK Government etc.

Friday, November 20, 2009

Chipping, flashing, jailbreaking

Chipping, flashing, jailbreaking
.
Past discussion here and at Forensic Focus have highlighted that when examining mobile phones avoid causing damage etc to them and about ownership of seized mobile phones.
.
A seized mobile phone remains the property of the owner until the owner is found guilty (then particular legal mechanisms come into play) or the owner has conducted certain activity or until an Order has been made to permenantly confiscate and dispose of the item.
.

I note the issues of those who might say but when we are IMEI checking on the street, confiscating and desposing of mobile phones is not a problem, that is not a blanket legal approach to be applied to everything but to deal with specific matters.
.

A further example of the police confirming they do not own seized goods and they may have to be returned to their rightful owner can be seen below.
.
http://www.policeprofessional.com/news.aspx?id=9537
"In an interview with The Register, Deputy Assistant Commissioner Janet Williams said work was being done to try to resolve the problem............problematic to people waiting for property to be returned."
.

The same applies to returning mobile phones. If you damage or break the mobile phone or alter it to make it irrepairably or lose/delete important data (say an email that constitutes a contract and may lead to economic loss) - these matters can be proceeded against in tort and/or contract law apart from other matters.

Tuesday, August 12, 2008

Dual International Mobile station Equipment Identity (IMEI)

Dual International Mobile station Equipment Identity (IMEI)


When we think of mobile telephones we mostly think in terms of them of having a single International Mobile station Equipment Identity number. For two decades, whether for an analogue or digital mobile 'phone, we have often associated, to assist in showing importance of, and drawing anology about, that mobile 'phone serial numbers are alike to vehicle chassis numbers - in essence IMEIs are intended to be unique numbers.
.
Because of that unique numbering scheme, it follows that each mobile phone should only have one IMEI. That has changed and mobile 'phone manufacturers can include two IMEIs. The two IMEIs can be viewed via the label under the battery pack (see photo below Samsung SGH-D888), or by entering *#06# (asterisk, octothorp, 0, 6, octothorp).
.



.

Having reviewed the Standards and other documentation and found no definitive statement about the requirement for a dual IMEI numbering scheme, I put out some enquiries and I am grateful to those who assisted. I am told it would appear the occurrence of the dual IMEIs are due to there being two radio chipsets in some handsets. As I understand it, also, I won't find anything in the Standards about this matter - just yet. Moreover, it does not automatically follow that a handset having Dual SIM/USIM slots implies or infers that the handset has two radio chipsets, thus two IMEIs.

.

Evidentially, of course it is noted this matter impacts in numerous ways when conducting examination using automated physical and/or logical harvesting of data and the much-needed handset (manual) examination.