Showing posts with label SIM. Show all posts
Showing posts with label SIM. Show all posts

Thursday, January 19, 2017

Investigating AKA - USIM MILENAGE Attack

For the last two years Chapter 18, Smith et al have been studying AKA (authentication and key agreement). One candidate for AKA is MILENAGE which, in 2014 & published 2015, was hacked using DPA (a side channel attack).

Having spent 2016 researching through a huge range of document, presentation, test data and scripts etc., it was noted there had been nothing written as to what to look for and how practitioners could handle this information. It is hoped with the discussion, embedded links and those willing to learn this presentation goes some way to help in that regard.

fcord-2016-USIM-MILENAGE-0x48.pdf

Saturday, March 15, 2014

SIM Test Card Hardware Layouts










15/11/97
Interface for ASIM

README       This file.
EMUSIM.BMP   Artwork of Smart Card sized PCB
MAX232.BMP   Artwork of Smart Card sized PCB whith MAX232
MAX232LY.GIF Parts placement guide of max232 pcb.
CIRCLAY.GIF  Parts placement guide.

The bitmap file can be loaded into Windows Paintbrush then printed. They
are drawn 1:1 at 300 dpi so make sure you click "Use printer resolution" and
the Laser printer is set to 300 dpi before you print. The artwork is drawn as
seen from the copper side. It can be printed on a transparency as is and used
directly in a positive photo etch. The copper side of PCB not touches the
toner side of transparency.

Bye
by Giulio Cesare



Sunday, October 06, 2013

(U)ICC/(U)SIM Script Commands and Responses

(U)ICC/(U)SIM Script Commands and Responses

The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear to assist Diploma students with their course work.

http://sim2usim.blogspot.co.uk/2013/10/uiccusim-script-commands-and-responses.html

(U)ICC/(U)SIM Script Commands and Responses

(U)ICC/(U)SIM 3F00 7F10 6F4A

3GPP UICC/USIM script selecting Master File, Dedicated File and Elementary File





















GSM ICC/SIM script selecting Master File, Dedicated File and Elementary File






























Reason for script test : defining an examination procedure to isolate and test a single elementary file; determine the EF's status, file structure, coding etc; conrroborate the ability of the (U)ICC/(U)SIM to action responses from commands sent to card; provide corroborating evidence of commands sent to the card to demonstrate evidential integrity (transparency of practices and procedures); testing the examination card reader is functioning correctly; QA procedures. 

Script examination tool used : USIM Commander - http://www.quantaq.com/usimcommander.htm

Relevant Core Diplomas:-

Aims : MTEB Diploma for Mobile Evidence QA and Evidence Handling - Mobile Telephone Diploma Core CQAE1

Objectives : Device Maintenance and Calibration; Examination Procedure

Aims :  MTEB Diploma for SIM and USIM Technology Examination - Mobile Telephone
Diploma Core CSUT2

Objectives : Your understanding of roles and responsibilities and the importance of
appropriate practices and procedures for SIM and USIM Technology
Examination for acquiring evidence.

Reference Standards :
GSM11.11/3GPP TS51.011/3GPP TS31.102,
GSM11.12,
GSM11.17/3GPP TS51.017/3GPP TS31.120/3GPP TS31.121/3GPP TS31.122,
GSM11.18/3GPP31.101,

EU MTEB Diploma Student Note : Remember to check with ETSI Standards e.g. TS102.221 etc

US MTEB Diploma Student Note : Diploma Students remember to check e.g. C.S0065-0 v1.0, C.S0074-0 v1.0, C.S0074-A v1.0, N.S0009-0 v1.0, S.R0095-0 v1.0 etc

Generically speaking, apart from GSMA and 3GPP, there is also 3GPP2 which also includes ARIB, CCSA, TIA TTA, TTC that all have conditions that can impact/influence results on (U)ICC/(U)SIM.

The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear here to assist Diploma students with their course work.

The latest MTEB Diploma Modules Guide MTEdipl 2.2 can be downloaded here:
https://dl.dropboxusercontent.com/u/84491783/MTEdipl%202.2.pdf


Saturday, September 14, 2013

Blocked SIM

A regular question that arises, "is it possible to bypass a PIN blocked SIM card?"

For a quick solution it is best to go to the operator to obtain a PUK code where there has been 3 CHV1 attempts and access is now blocked.

If it is 10 CHV1 attempts and blocked ([unless you know and have the test tools to e.g. slow the card]) then the operator may request that you send it to them and they in turn (depending upon their security level) may need to send it to the (U)ICC producer / manufacturer.

Today's UICC (using improved silicon and security techniques) have significant security improvements within each operator's card where there are various levels of electronic counter-measures (traps doors/dead-man's trap etc). Many of us (including me) simply cannot access certain areas of the UICC unless a flaw in the security is discovered. Unless you are confident of what you know and what you are doing, my observation is take the safest route.


None of the opinions I express originate based upon my gut feeling about a particular matter. I research, like others, to establish the industry security protocols, practices and procedures and then consider the position from there. It is important to bare in mind that forensics and evidence is not about hacking everything in sight or writing a program to extract data but to be aware and comprehend how industry standard bodies intended security should be implement, which norms the manufacturer and operator follow and whether following implementation security flaws occur.


sim2usim


Examination and Evidence from SIM and USIM Cards. Now an open blog. 

http://sim2usim.blogspot.co.uk/


(U)SIM Examination (Physical) Pt2

(U)SIM Examination (Physical) Pt2

Before we can progress to consider various methods of (U)SIM physical examination there are more standards we need to be aware and there are reasons for that. Transitioning from GSM to 3GPP (*wcdma) standards required rewriting existing GSM standards to make the standards technology neutral to integrate GSM into future mobile developments under 3GPP global standards. Technology-wise, we know that GSM is a defined circuit-switched voice mobile communications system that has evolved with value-added data services (GPRS, HSCSD and EDGE). 3GPP (wcdma) as we know is a defined packet-switched technology and thus would be a pointless exercise to re-invent the wheel, so to speak, and introduce a new voice circuit-switched system and the matured installation base that went with it. That needs to be understood on many levels when dealing with mobile communications. Three examples of GSM and 3GPP working together:

(i) generally, we refer to Release 99 (R99) as a reference point whereby 3GPP could transition and re-write mobile communication technology standards with birthing-periods: GSM only before 3GPP Release 4 (Rel-4); GSM only (Rel-4 and later); 3GPP and beyond / GSM (R99 and later).  This enabled manufacturers, developers and operators and service providers to conintue with GSM standards in a pure GSM environment or evolve to a 3GPP environment but in the knowledge access and inter-connectivity to GSM would continue:

(ii) introduction of 3GPP (*wcdma) would take time and thus should avoid, as best possible, disruption to existing moble services;

(iii) GSM user/subscriber base was still growing at that time and has now reached over 3-billion users, from which we can draw a conclusion that GSM's importance in its relationship with 3GPP should not be under-estimated.GSM is by no means the junior partner.

In the mobile examination environment, we, as examiners, are exposed to multitude and multiple-layers of technical and technology standards many of which impact on (U)SIM, and particuarly so if the technical and technology generates a mobile communication outcome associated to/with a user/subscriber. 

(*) wcdma is one of a family of mobile technology standards under 3GPP and has been used for easy of reference. 

The scope of the tests and the requirements set down in GSM1117 were reproduced under the approved and adopted standard 3GPP TS51.017. In Pt1( usim-examination-physical-pt1.html ) reference was made to GSM11.11, however the approved and adopted standard (and the counterpart to GSM11.11) is 3GPP TS51.011:

PHY:    Physical characteristics - 3GPP TS 51.011 [1], clause 4.
ELEC:    Electronic signals and transmission protocols - 3GPP TS 51.011 [1], clause 5.
AFS:    Application and File structure - 3GPP TS 51.011 [1], clause 6.
SEC:    Security features - 3GPP TS 51.011 [1], clause 7.
CMD:    Description of the commands - 3GPP TS 51.011 [1], clause 9.
CEF:    Contents of the elementary files - 3GPP TS 51.011 [1], clause 10.
APP:    Application Protocol - 3GPP TS 51.011 [1], clause 11.

Whilst GSM11.17 standard is the starting point for ICC/SIM and 3GPP TS51.011 moved the technology to neutral ground to enable 3GPP to evolve 3G environment standards incorportating interconnectivity to and backward compatibility for ICC/UICC, the 3GPP evolution hasn't stopped there. There is, of course, 3GPP TS 31.120 the aim of which is to ensure interoperability between an UICC and a Terminal independently of the respective manufacturer, card issuer or operator. This is the expansion of the 3GPP domain going beyond specific limitations encumbent with a particular proprietory technology.

The run of standards doesn't end there. Attention and consideration should be given to:

ETSI standards
TS 102 230
TS 102 221

International standards
ISO/IEC 7816-pt1 to pt4

The standards referred to above are merely a starting point to identify the complexities involved in dealing with (U)SIM card and tasks involved in considering examination techniques that may not simply relate to recovery of data but other aspects and attributes of a card which may point to evidence. Readers should be prepared to delve into the standards above and release the huge number that haven't been mentioned. There are various analogies that may be used to imagine what I have in mind for this physical series, but I quite like the analogy about forensic vehicle tyre analysis. Evidentially, consideration is given to tyre size, tread, pressure, rubber, moulding, any wheel balacing and so on to assess a skid mark or tracks at the scene of a crime. It is equally possible to use an investigative and examination approach to SIM/USIM card materials, contacts, gold content, embossing etc to identify potential evidence.

Monday, May 06, 2013

(U)SIM Examination (Physical) Pt2

(U)SIM Examination (Physical) Pt2

Before we can progress to consider various methods of (U)SIM physical examination there are more standards we need to be aware and there are reasons for that. Transitioning from GSM to 3GPP (*wcdma) standards required rewriting existing GSM standards to make the standards technology neutral to integrate GSM into future mobile developments under 3GPP global standards. Technology-wise, we know that GSM is a defined circuit-switched voice mobile communications system that has evolved with value-added data services (GPRS, HSCSD and EDGE). 3GPP (wcdma) as we know is a defined packet-switched technology and thus would be a pointless exercise to re-invent the wheel, so to speak, and introduce a new voice circuit-switched system and the matured installation base that went with it. That needs to be understood on many levels when dealing with mobile communications. Three examples of GSM and 3GPP working together:

(i) generally, we refer to Release 99 (R99) as a reference point whereby 3GPP could transition and re-write mobile communication technology standards with birthing-periods: GSM only before 3GPP Release 4 (Rel-4); GSM only (Rel-4 and later); 3GPP and beyond / GSM (R99 and later).  This enabled manufacturers, developers and operators and service providers to conintue with GSM standards in a pure GSM environment or evolve to a 3GPP environment but in the knowledge access and inter-connectivity to GSM would continue:

(ii) introduction of 3GPP (*wcdma) would take time and thus should avoid, as best possible, disruption to existing moble services;

(iii) GSM user/subscriber base was still growing at that time and has now reached over 3-billion users, from which we can draw a conclusion that GSM's importance in its relationship with 3GPP should not be under-estimated.GSM is by no means the junior partner.

In the mobile examination environment, we, as examiners, are exposed to multitude and multiple-layers of technical and technology standards many of which impact on (U)SIM, and particuarly so if the technical and technology generates a mobile communication outcome associated to/with a user/subscriber. 

(*) wcdma is one of a family of mobile technology standards under 3GPP and has been used for easy of reference. 

The scope of the tests and the requirements set down in GSM1117 were reproduced under the approved and adopted standard 3GPP TS51.017. In Pt1( usim-examination-physical-pt1.html ) reference was made to GSM11.11, however the approved and adopted standard (and the counterpart to GSM11.11) is 3GPP TS51.011:

PHY:    Physical characteristics - 3GPP TS 51.011 [1], clause 4.
ELEC:    Electronic signals and transmission protocols - 3GPP TS 51.011 [1], clause 5.
AFS:    Application and File structure - 3GPP TS 51.011 [1], clause 6.
SEC:    Security features - 3GPP TS 51.011 [1], clause 7.
CMD:    Description of the commands - 3GPP TS 51.011 [1], clause 9.
CEF:    Contents of the elementary files - 3GPP TS 51.011 [1], clause 10.
APP:    Application Protocol - 3GPP TS 51.011 [1], clause 11.

Whilst GSM11.17 standard is the starting point for ICC/SIM and 3GPP TS51.011 moved the technology to neutral ground to enable 3GPP to evolve 3G environment standards incorportating interconnectivity to and backward compatibility for ICC/UICC, the 3GPP evolution hasn't stopped there. There is, of course, 3GPP TS 31.120 the aim of which is to ensure interoperability between an UICC and a Terminal independently of the respective manufacturer, card issuer or operator. This is the expansion of the 3GPP domain going beyond specific limitations encumbent with a particular proprietory technology.

The run of standards doesn't end there. Attention and consideration should be given to:

ETSI standards
TS 102 230
TS 102 221

International standards
ISO/IEC 7816-pt1 to pt4

The standards referred to above are merely a starting point to identify the complexities involved in dealing with (U)SIM card and tasks involved in considering examination techniques that may not simply relate to recovery of data but other aspects and attributes of a card which may point to evidence. Readers should be prepared to delve into the standards above and release the huge number that haven't been mentioned. There are various analogies that may be used to imagine what I have in mind for this physical series, but I quite like the analogy about forensic vehicle tyre analysis. Evidentially, consideration is given to tyre size, tread, pressure, rubber, moulding, any wheel balacing and so on to assess a skid mark or tracks at the scene of a crime. It is equally possible to use an investigative and examination approach to SIM/USIM card materials, contacts, gold content, embossing etc to identify potential evidence.

Sunday, October 02, 2011

EF-FPLMN

EF-FPLMN

There are many ways you may wish to approach examining a SIM Card elementary file (EF) and to the university students that wrote and asked for some ideas here are some observations. I would recommend, assuming you have access to SIM reading tools, that it is useful to target a particular EF in the GSM standard GSM11.11. Importantly, as there have been numerous versions and revisions of GSM11.11 it is an essential task to check the various versions and revisions taking account of any changes to the technical requirements for the EF: for instance

a) access conditions
b) content
c) coding
d) etc

To illustrate some of the points raised by this blog discussion I have selected the SIM forbidden list found in elementary file (EF) FPLMN (Forbidden PLMNs) 7F20:6F7B (7F21:6F7B). PLMNs MCC/MNC populated in this EF are those that the MS shall not camp on and provide a location update. 

ETS GSM11.11 v4.21.1 December 1999
GSM 11.11 v8.14.0 June 2007

Of course, when reading the conditions laid out in the standards it is also essential to appreciate the conditions under which a PLMN (MCC/MNC) may be updated into this EF. Trial test conditions should relate to 'automatic' update and update caused by 'manual' selection of a Forbidden PLMN. These are not simple tasks as one might imagine. There is the radio environment to consider? Which PLMNs are forbidden? Is roaming required? The coding of the data? ....and so on. So for an elementary file that largely gets overlooked during examination and ignored in evidence, an analysis of exactly the tasks this EF performs in the SIM module is quite surprising when considering its impact on the MS. That is from the perspective that its evidence could be considered when placing an MS within an PLMN's radio coverage and the follow on potential inference of a geographical location. EF-FPLMN adds an intriguing prospects to be considered, beyond handset and SIM analysis, and that is it can be used in cell site analysis and call record analysis, too.

Extracted and Harvested Data
It is inescapable, thus unavoidable, that validating data that has been extracted and harvested cannot be performed based upon using one tool. Moreover, tools vary in the way they present harvested data and will require the examiner to pay particular attention to ensure the output data (although presented in various arrangements) should be identical. If parity isn't possible then analysis of the tools should be undertaken. It is worth mentioning at this juncture, so as to avoid unduly raising concerns, many tools once released into the marketplace do not allow users to update the product. Changes to SIM techncial specifications or new services or new/change to operators may simply not be included in a tool. 

SIMSpy Trace file Output (Text file)


Other tools present data in varying layouts within the program:

SIM Explorer


SIMCON


SIMCOM


USIM Detective




In conclusion, students asked for some observations and I hope the above may help. Care should be taken when reading the binary not to corrupt content in the EF; to consider the use of reverse-nibble; writing scripts; APDU/PDU and so on, in addition to the automatic and manual tests to be conducted. Moreover, any discovery could also extend to the use of EF-FPLMN to cell site analysis and call record analysis.

Saturday, September 10, 2011

Smart phones overtake basic mobile phones in Europe

Smart phones overtake basic mobile phones in Europe

The Guardian newspaper, thursday 8/9/11,  reported "New data released by research company IDC show smartphone shipments up 48% compared to the same period in 2010, reaching nearly 22m, as Samsung, Apple, HTC and BlackBerry maker RIM dominated the market and Finland's Nokia saw its previous dominance wiped out. Last year smartphones made up just over a third of mobile phone sales in the region."

However, alternative research from IMS suggests that, infact, there is a SIM card sales explosion: "Of the 4.2 billion SIMs sold in 2010, 85% were to existing SIM card users, i.e. existing users of cellular handsets. This means that more than 80% of SIM-based cell phone users replaced their SIM cards last year. This may seem a little surprising as the proportion of cell phone users that replaced their actual handsets last year was much less than this. In fact at a global level, only 24% of cell phone users replaced their handsets with brand new handsets last year."

Moreover, IMS research further suggests when dealing with 4FF embedded SIMs: "With the current removable model, the volume of SIM cards sold in 2016 is set to pass 6 billion. If all cards were embedded by this time the number would be nearer 2 billion, around half what it was last year! As the SIM card market represents more than 80% of smart card volumes, this would be very bad news for many card and semiconductor suppliers."

On the basis of both reports the news in quite uplifting and a useful indicator of growth. At a time when the Prime Minister, David Cameron, looks to re-assess economic imbalance (services -v- manufacturing) in Britian, the elements to bring about the stimulus for wealth-creation, productivity and employment maybe here. Why would that be so? Because here is an area where services and manufacturing are required to forge a union in order that both can co-exist, such that they work not only in practice but in principle, too.

I am happy to revisit the sub-text of my 1988 proposal 'Putting Britain First' and reference to other reading materials if it would help put meat on the bones of this one.

Saturday, July 23, 2011

Mobile Markets: Nokia 'Mobile Man'...it tells of a story

Mobile Markets: Nokia 'Mobile Man'...it tells of a story

This excellent construction, made up entirely of mobile phones, is Nokia's collaborative project with Beijing postal service to encourage recycling of mobile phones that can be handed in at post offices, according to the news article at news.cnet.com.   


It's great to see projects like, which tend to draw promotions using creative and talented ideas demonstrating the evolving and transforming world of mobile phones and its market places. Back in 2007 I posted on another creative work cellphone-transformer, which, yet again, shows a design that captures the imagination displaying the versatile uses to which a mobile phone might be put.

The business and ecomonic philosophy that resides behind these creative images equally tells of a story of growth and success. If recycling is happening then, perhaps, that is as a likely consequence of mobile ubiquity taking hold. That is a nice statement, but can I back it up?  I don't have my finger on every financial and market research pulse, but, apart from anecdotal references, there are various stats out there from the market research firms. Indeed, back in 2008 I blogged (staggering-figures-for-mobile-phone) on the state of the mobile data market when the economic downturn (which appears to have started in 2007 so we are led to believe) had got a firmer grip on global markets. In 2010 the stats still showed extraordinary figures (text.it), although the exact detail where all this activity occurs to generate such figures may not be obvious. It may be compelling to want to know how many consumers send text and mms messages (see OFCOM website for stats), but that is not the full picture. There are the other data markets in business to consider, such as the M2M market place (winwin) and comments by industry pundits on the mobile payments market (cellular-news).

It is useful to see how industry people collate information and bring amassed facts together in order to express their views and vision on what all the facts mean to them in aggregrate. An example of this can be seen in Tomi Ahonen's enthusiastic commentary found in Insiders Guide To Mobile (lulu) with references to trillion dollar market, over 4 billion users and the segmented factors when drawn together identified to him what is forecast for mobile. A view of one segment of the mobile phone market, apps, is simply a further illustration of information to be sourced to underpin market trends (windows-phone-apps-reach-new-market), another is sales and market penetration, such as Apple's iPhone outrageously outstanding sales growth.

If I removed from the context of the above commentary discussion about modern technology, and simply focussed on what an image might communicate, I could have been talking about social, cultural and economic life that might have been depicted by way of an 18th/19th century painting (irrespective of whether the painting is by an impressionist or not). Whilst the image above may not be an old master piece, the image still has a story to explicitly convey and that, in forensic terms, requires understanding all or part of any implicit subtext the image can also communicate.

My forensic skills, acquired over the years, meant that my reaction to seeing this image (even though photo/art imagery is not my subject), was to look at it as evidence and then set out to see what I could deduce from there. In reality we do this everyday in our work. We see a SIM card. We then want to know what it is and what is inside. In order to know what we are dealing with we need to know how it works and what can be held inside and whether all or part thereof can be revealed. Moreover, we need to know what amounts to 'conformance' and within that framework which conforming element is 'mandatory' and which is 'optional'. Once we have that background we can then begin to understand what is 'non-conforming' and/or 'unusual'. This path can equally be taken when dealing with mobile phones and RF investigations.

In conclusion, the subtext of this discussion can be revealed. However mobile phones maybe presented to the world, it is our job in forensics not to change that messsage, but to break down the presentation into its various building block elements in order that we know how each piece works and then how the pieces fit together and work and cooperate together.  This is because a true forensic standard requires of the individual to obtain knowledge by way of commentary, appropriate training, standards, specs and investigation, that includes examination and testing (trial and error), which is one side of the coin. The other side of this coin is knowing what the 'thing' in its final state is intended to do, which requiries understanding of the market place it which the 'thing' is to be adopted.  Using skills and techniques like these provide for a rich source of experience, too. Essentially, learning to bring all the pieces that are needed into play and being able to demonstrate that identifies the forensic examiner working with a well hone, self-principled approach of high standard.

For MTEB students, the summer recess is now here. Sure, have a great time and relax and enjoy the break, but don't waste valuable time. Great people strive in life because they want to go beyond what has already been achieved. Take time out from relaxing to bring together the exposure you have had to mobile knowledge and experience you have acquired, thus far. Select a particular line of investigative enquiry and see how far you get with it. I have identified some links above to illustrate a way forward or choose a different subject matter; remember to be able to demonstrate the primary basics of 'bush' methodology.

Monday, May 30, 2011

Answer To Reset (ATR)

Answer To Reset (ATR)

It is an endless investigation when dealing with SIM/USIM. The intention of this discussion is to highlight discoveries that you may not be aware. In this instance ATR is the first data read from every SIM/USIM and can provide potentially useful information to an investigation or when making analysis about end-to-end (SIM to Network) mobile telephone evidence.  

What might be interpreted from first eight bytes of an ATR recovered? From research, this is an interpretation of the ATR from a particular manufacturer's GSM SIM:

[B1][B2][B3][B4][B5][B6][B7][B8]
3B....34...11...00...6B...C?..16...0?

Byte 6 - options
3B 34 11 00 6B C2 16 0? normal SIM+OTA
3B 34 11 00 6B C3 16 0? SIM-Toolkit (STK) SIM

Byte 7
16 EEPROM size (16K)

Byte 8 - options
3B 34 11 00 6B C? 16 01 GSM security algorithm
3B 34 11 00 6B C? 16 02
3B 34 11 00 6B C? 16 03
3B 34 11 00 6B C? 16 0A

  
As interpretation of the ATR can be possible, do all SIM ATRs follow the same identification process or when personalised uniquely characterise the ATR to instruct the handset/network with similar information about the SIM's technical profiling but identified at different byte locations in the ATR string?

Wednesday, November 03, 2010

Quad-SIM (4 in 1)

Quad-SIM (4 in 1)

Wonder how we will handle the examination of this beast? Which profile will need to be read first? Will the handset have different profiles? Will each SIM have its own password?  There are so many question this news story raises. Previous experience has shown care is needed with handling the examination of handsets containing two (dual) SIMs (http://sim2usim.blogspot.com/2008/11/cloning-test-sim-cards.html).


Spreadtrum Announces the World’s First Single Chip Quad-SIM Standby Solution
The SC6600L6 allows four GSM SIM cards simultaneously running on standby mode with only one set of baseband and RF. It integrates a processor engine and controller for supporting quadruple SIM cards and has an improved graphic user interface for Quad-SIM. The product supports different multi-SIM options, including dual SIM, triple SIM, and Quad-SIM in a single set of baseband and RF chip, provides more choices to handset designers and meets need of users from different regions.

http://www.spreadtrum.com/eng/showNews.asp?name=1&ID=306

Tuesday, November 02, 2010

Smart Card Hacking

Smart Card Hacking

Back in 2002 I wrote about SIM Card Cloning for examiners to demonstrate the state of the market place, where software and hardware was being openly promoted that researchers could obtain and what might an examiner be exposed to when examining a cloned SIM Card. A copy of that report can be downloaded here:

SIM Card Cloning
http://www.4shared.com/document/GMz_Gqcc/Special_Edition_2002_SIM_Cloni.html

In 1998 I circulated  a report (UPD5-1 Vol1 - FEN98) on Smart Card Hacking to members of the British Association of Criminal Experts (BACE). The archive report has been scanned page by page and put into acrobat.pdf format and can now be downloaded here:


Smart Card Hacking
http://www.4shared.com/file/kq5NGzns/UPD5-1_Vol1_-_FEN98.html

The smart card hacking report has an interesting description for classification of the various levels of criminal activity in addition to techniques of smart card hacking. This particular report was the one that inspired me to write about SIM Card Cloning for exmainers. Once again thanks and respect to Ross Anderson and Markus Kuhn.

It is important to consult the laws of the country you are in when dealing with research for cloning SIM Cards. This blog article does not promote or advocate anyone to break the law by cloning or attempting to clone SIM cards for the purposes of obtaining services or breaching property rights belonging to respective particular network operators etc.

Saturday, October 30, 2010

Mobile Face Recognition Might Replace Password/PIN

Mobile Face Recognition Might Replace Password/PIN

One exciting aspect about forensic examination of mobile handsets is the constant exposure to innovation and change in the variety of handsets with which we are exposed, sometimes on a daily basis. Legality and privacy are two imposing factors when in comes to dealing with content on mobile phones and the right of access. Where PIN and/or Password is not revealed by the suspect, authority is needed to continue to gain access to a device in order to reveal content.

Passwords/PIN are commonly alpha-numeric digits and there are ways and methods of dealing with those. When Android introduced symbol based password options for their handsets, this feature added a new dimension an examiner had to cope with during the examination process.  Now there is a new development to deal with, created from an EU funded project, MOBIOproject. MOBIO stands for Mobile Biometry. More on this subject.........

http://forensicmobex.blogspot.com/2010/10/mobile-face-recognition-might-replace.html

Monday, June 21, 2010

3G USIM 2G SIM Service Numbers

3G USIM 2G SIM Service Numbers

3G USIM (2010-04)
Service n°1: Local Phone Book
Service n°2: Fixed Dialling Numbers (FDN)
Service n°3: Extension 2
Service n°4: Service Dialling Numbers (SDN)
Service n°5: Extension3
Service n°6: Barred Dialling Numbers (BDN)
Service n°7: Extension4
Service n°8: Outgoing Call Information (OCI and OCT)
Service n°9: Incoming Call Information (ICI and ICT)
Service n°10: Short Message Storage (SMS)
Service n°11: Short Message Status Reports (SMSR)
Service n°12: Short Message Service Parameters (SMSP)
Service n°13: Advice of Charge (AoC)
Service n°14: Capability Configuration Parameters 2 (CCP2)
Service n°15: Cell Broadcast Message Identifier
Service n°16: Cell Broadcast Message Identifier Ranges
Service n°17: Group Identifier Level 1
Service n°18: Group Identifier Level 2
Service n°19: Service Provider Name
Service n°20: User controlled PLMN selector with Access Technology
Service n°21: MSISDN
Service n°22: Image (IMG)
Service n°23: Support of Localised Service Areas (SoLSA)
Service n°24: Enhanced Multi Level Precedence and Pre emption Service
Service n°25: Automatic Answer for eMLPP
Service n°26: RFU
Service n°27: GSM Access
Service n°28: Data download via SMS-PP
Service n°29: Data download via SMS CB
Service n°30: Call Control by USIM
Service n°31: MO-SMS Control by USIM
Service n°32: RUN AT COMMAND command
Service n°33: shall be set to '1'
Service n°34: Enabled Services Table
Service n°35: APN Control List (ACL)
Service n°36: Depersonalisation Control Keys
Service n°37: Co-operative Network List
Service n°38: GSM security context
Service n°39: CPBCCH Information
Service n°40: Investigation Scan
Service n°41: MExE
Service n°42: Operator controlled PLMN selector with Access Technology
Service n°43: HPLMN selector with Access Technology
Service n°44: Extension 5
Service n°45: PLMN Network Name
Service n°46: Operator PLMN List
Service n°47: Mailbox Dialling Numbers
Service n°48: Message Waiting Indication Status
Service n°49: Call Forwarding Indication Status
Service n°50: Reserved and shall be ignored
Service n°51: Service Provider Display Information
Service n°52 Multimedia Messaging Service (MMS)
Service n°53 Extension 8
Service n°54 Call control on GPRS by USIM
Service n°55 MMS User Connectivity Parameters
Service n°56 Network's indication of alerting in the MS (NIA)
Service n°57 VGCS Group Identifier List (EFVGCS and EFVGCSS)
Service n°58 VBS Group Identifier List (EFVBS and EFVBSS)
Service n°59 Pseudonym
Service n°60 User Controlled PLMN selector for I-WLAN access
Service n°61 Operator Controlled PLMN selector for I-WLAN access
Service n°62 User controlled WSID list
Service n°63 Operator controlled WSID list
Service n°64 VGCS security
Service n°65 VBS security
Service n°66 WLAN Reauthentication Identity
Service n°67 Multimedia Messages Storage
Service n°68 Generic Bootstrapping Architecture (GBA)
Service n°69 MBMS security
Service n°70 Data download via USSD and USSD application mode
Service n°71 Equivalent HPLMN
Service n°72 Additional TERMINAL PROFILE after UICC activation
Service n°73 Equivalent HPLMN Presentation Indication
Service n°74 Last RPLMN Selection Indication
Service n°75 OMA BCAST Smart Card Profile
Service n°76 GBA-based Local Key Establishment Mechanism
Service n°77 Terminal Applications
Service n°78 Service Provider Name Icon
Service n°79 PLMN Network Name Icon
Service n°80 Connectivity Parameters for USIM IP connections
Service n°81 Home I-WLAN Specific Identifier List
Service n°82 I-WLAN Equivalent HPLMN Presentation Indication
Service n°83 I-WLAN HPLMN Priority Indication
Service n°84 I-WLAN Last Registered PLMN
Service n°85 EPS Mobility Management Information
Service n°86 Allowed CSG Lists and corresponding indications
Service n°87 Call control on EPS PDN connection by USIM
Service n°88 HPLMN Direct Access
Service n°89 eCall Data
Service n°90 Operator CSG Lists and corresponding indications

------------------------------------------------------------------

2G SIM (2007-06)
Service n°1 : CHV1 disable function
Service n°2 : Abbreviated Dialling Numbers (ADN)
Service n°3 : Fixed Dialling Numbers (FDN)
Service n°4 : Short Message Storage (SMS)
Service n°5 : Advice of Charge (AoC)
Service n°6 : Capability Configuration Parameters (CCP)
Service n°7 : PLMN selector
Service n°8 : RFU
Service n°9 : MSISDN
Service n°10: Extension1
Service n°11: Extension2
Service n°12: SMS Parameters
Service n°13: Last Number Dialled (LND)
Service n°14: Cell Broadcast Message Identifier
Service n°15: Group Identifier Level 1
Service n°16: Group Identifier Level 2
Service n°17: Service Provider Name
Service n°18: Service Dialling Numbers (SDN)
Service n°19: Extension3
Service n°20: RFU
Service n°21: VGCS Group Identifier List (EFVGCS and EFVGCSS)
Service n°22: VBS Group Identifier List (EFVBS and EFVBSS)
Service n°23: enhanced Multi-Level Precedence and Pre-emption Service
Service n°24: Automatic Answer for eMLPP
Service n°25: Data download via SMS-CB
Service n°26: Data download via SMS-PP
Service n°27: Menu selection
Service n°28: Call control
Service n°29: Proactive SIM
Service n°30: Cell Broadcast Message Identifier Ranges
Service n°31: Barred Dialling Numbers (BDN)
Service n°32: Extension4
Service n°33: De-personalization Control Keys
Service n°34: Co-operative Network List
Service n°35: Short Message Status Reports
Service n°36: Network's indication of alerting in the MS
Service n°37: Mobile Originated Short Message control by SIM
Service n°38: GPRS
Service n°39: Image (IMG)
Service n°40: SoLSA (Support of Local Service Area)
Service n°41: USSD string data object supported in Call Control
Service n°42: RUN AT COMMAND command
Service n°43: User controlled PLMN Selector with Access Technology
Service n 44: Operator controlled PLMN Selector with Access Technology
Service n 45 HPLMN Selector with Access Technology
Service n 46: CPBCCH Information
Service n 47: Investigation Scan
Service n°48: Extended Capability Configuration Parameters
Service n°49: MExE
Service n°50 Reserved and shall be ignored

3G USIM 2G SIM Service Numbers

3G USIM 2G SIM Service Numbers

3G USIM (2010-04)
Service n°1: Local Phone Book
Service n°2: Fixed Dialling Numbers (FDN)
Service n°3: Extension 2
Service n°4: Service Dialling Numbers (SDN)
Service n°5: Extension3
Service n°6: Barred Dialling Numbers (BDN)
Service n°7: Extension4
Service n°8: Outgoing Call Information (OCI and OCT)
Service n°9: Incoming Call Information (ICI and ICT)
Service n°10: Short Message Storage (SMS)
Service n°11: Short Message Status Reports (SMSR)
Service n°12: Short Message Service Parameters (SMSP)
Service n°13: Advice of Charge (AoC)
Service n°14: Capability Configuration Parameters 2 (CCP2)
Service n°15: Cell Broadcast Message Identifier
Service n°16: Cell Broadcast Message Identifier Ranges
Service n°17: Group Identifier Level 1
Service n°18: Group Identifier Level 2
Service n°19: Service Provider Name
Service n°20: User controlled PLMN selector with Access Technology
Service n°21: MSISDN
Service n°22: Image (IMG)
Service n°23: Support of Localised Service Areas (SoLSA)
Service n°24: Enhanced Multi Level Precedence and Pre emption Service
Service n°25: Automatic Answer for eMLPP
Service n°26: RFU
Service n°27: GSM Access
Service n°28: Data download via SMS-PP
Service n°29: Data download via SMS CB
Service n°30: Call Control by USIM
Service n°31: MO-SMS Control by USIM
Service n°32: RUN AT COMMAND command
Service n°33: shall be set to '1'
Service n°34: Enabled Services Table
Service n°35: APN Control List (ACL)
Service n°36: Depersonalisation Control Keys
Service n°37: Co-operative Network List
Service n°38: GSM security context
Service n°39: CPBCCH Information
Service n°40: Investigation Scan
Service n°41: MExE
Service n°42: Operator controlled PLMN selector with Access Technology
Service n°43: HPLMN selector with Access Technology
Service n°44: Extension 5
Service n°45: PLMN Network Name
Service n°46: Operator PLMN List
Service n°47: Mailbox Dialling Numbers
Service n°48: Message Waiting Indication Status
Service n°49: Call Forwarding Indication Status
Service n°50: Reserved and shall be ignored
Service n°51: Service Provider Display Information
Service n°52 Multimedia Messaging Service (MMS)
Service n°53 Extension 8
Service n°54 Call control on GPRS by USIM
Service n°55 MMS User Connectivity Parameters
Service n°56 Network's indication of alerting in the MS (NIA)
Service n°57 VGCS Group Identifier List (EFVGCS and EFVGCSS)
Service n°58 VBS Group Identifier List (EFVBS and EFVBSS)
Service n°59 Pseudonym
Service n°60 User Controlled PLMN selector for I-WLAN access
Service n°61 Operator Controlled PLMN selector for I-WLAN access
Service n°62 User controlled WSID list
Service n°63 Operator controlled WSID list
Service n°64 VGCS security
Service n°65 VBS security
Service n°66 WLAN Reauthentication Identity
Service n°67 Multimedia Messages Storage
Service n°68 Generic Bootstrapping Architecture (GBA)
Service n°69 MBMS security
Service n°70 Data download via USSD and USSD application mode
Service n°71 Equivalent HPLMN
Service n°72 Additional TERMINAL PROFILE after UICC activation
Service n°73 Equivalent HPLMN Presentation Indication
Service n°74 Last RPLMN Selection Indication
Service n°75 OMA BCAST Smart Card Profile
Service n°76 GBA-based Local Key Establishment Mechanism
Service n°77 Terminal Applications
Service n°78 Service Provider Name Icon
Service n°79 PLMN Network Name Icon
Service n°80 Connectivity Parameters for USIM IP connections
Service n°81 Home I-WLAN Specific Identifier List
Service n°82 I-WLAN Equivalent HPLMN Presentation Indication
Service n°83 I-WLAN HPLMN Priority Indication
Service n°84 I-WLAN Last Registered PLMN
Service n°85 EPS Mobility Management Information
Service n°86 Allowed CSG Lists and corresponding indications
Service n°87 Call control on EPS PDN connection by USIM
Service n°88 HPLMN Direct Access
Service n°89 eCall Data
Service n°90 Operator CSG Lists and corresponding indications

------------------------------------------------------------------

2G SIM (2007-06)
Service n°1 : CHV1 disable function
Service n°2 : Abbreviated Dialling Numbers (ADN)
Service n°3 : Fixed Dialling Numbers (FDN)
Service n°4 : Short Message Storage (SMS)
Service n°5 : Advice of Charge (AoC)
Service n°6 : Capability Configuration Parameters (CCP)
Service n°7 : PLMN selector
Service n°8 : RFU
Service n°9 : MSISDN
Service n°10: Extension1
Service n°11: Extension2
Service n°12: SMS Parameters
Service n°13: Last Number Dialled (LND)
Service n°14: Cell Broadcast Message Identifier
Service n°15: Group Identifier Level 1
Service n°16: Group Identifier Level 2
Service n°17: Service Provider Name
Service n°18: Service Dialling Numbers (SDN)
Service n°19: Extension3
Service n°20: RFU
Service n°21: VGCS Group Identifier List (EFVGCS and EFVGCSS)
Service n°22: VBS Group Identifier List (EFVBS and EFVBSS)
Service n°23: enhanced Multi-Level Precedence and Pre-emption Service
Service n°24: Automatic Answer for eMLPP
Service n°25: Data download via SMS-CB
Service n°26: Data download via SMS-PP
Service n°27: Menu selection
Service n°28: Call control
Service n°29: Proactive SIM
Service n°30: Cell Broadcast Message Identifier Ranges
Service n°31: Barred Dialling Numbers (BDN)
Service n°32: Extension4
Service n°33: De-personalization Control Keys
Service n°34: Co-operative Network List
Service n°35: Short Message Status Reports
Service n°36: Network's indication of alerting in the MS
Service n°37: Mobile Originated Short Message control by SIM
Service n°38: GPRS
Service n°39: Image (IMG)
Service n°40: SoLSA (Support of Local Service Area)
Service n°41: USSD string data object supported in Call Control
Service n°42: RUN AT COMMAND command
Service n°43: User controlled PLMN Selector with Access Technology
Service n 44: Operator controlled PLMN Selector with Access Technology
Service n 45 HPLMN Selector with Access Technology
Service n 46: CPBCCH Information
Service n 47: Investigation Scan
Service n°48: Extended Capability Configuration Parameters
Service n°49: MExE
Service n°50 Reserved and shall be ignored

Friday, June 18, 2010

GSM Mast Installations (Density)

GSM Mast Installations (Density)
.
When planning a cellular radio network there are many aspects to consider. The matter of radio technology and their frequencies (carriers) are but two examples. A relevance to be understood from these examples relate to what services may be obtained and delivered through these carriers? GSM for basic voice and text services and W-CDMA providing high data rates for video, gaming and conferencing etc.
.
Germane and relevant to obtaining radio services are the radio access technologies needed for that - Masts and Antennas. In radio engineering terms, antennas provide the physical technology to access the services obtained in the radio coverage by use of transmitters and receivers, commonly referred to by the acronym TRXs. The Masts provide the physical location for the siting of the TRXs. An important aspect of Mast installations is knowing the potential customer numbers that will use the services obtained from them. The calculation used for the number of customers and the number of calls that can be handled by one Mast's TRXs is calculated using the Erlang formulae - the number of calls and time length of each call in an hour.
.
Generally, though, to understand how Erlang can be used to determine the number of Masts and TRXs for an area let's just say there are 50,000 potential customers for a particular area. Let us also say to retain quality of service three sectors with 2 or 4 TRXs per sector, s222 or s444 respectively, are required. Let's also indicate that it is known that:
.
=======
.
1 TRX = 3 erlang, 2 TRXs = 5 erlang, 3 TRXs = 15 erlang, 4 TRXs = 20 erlang
.
The relevant TRXs selected for this Mast installation scenario are 2 TRXs and 4 TRXs.
.
Let:
.
50,000 x 0.02 erlang, where 0.02 erlang is used per customer = **1000 erlang
.
Each sector of an s444 may carry up to 20 erlang x 3 sectors = **60 erlang
.
**1000/**60 = 16.7
.
Therefore:
.
16.7 (17) Mast installations would be needed where a configuration of TRXs s444
.
or where
.
33.4 (35) Mast installations would be needed where a configuration of TRX s222
.
================
.
Remember the above is intended only to be illustrative so that it can be used to draw inferences about Masts installations and potential user numbers based upon the density of Masts in an area. An inference, such as, why a Mast further away than Masts sited closer to where a mobile station (MS) may be located routed the text message to the MS?
.
There are a large number of issues to be considered but let us take iwo important issues to be considered are:
.
- Point-to-Area predictions for terrestrial services 30 MHz to 3000 MHz
- Point-to-Point short message service (SMS)
.
In relation to point-to-area it could be the height of buildings surrounding the MS may be a cause for a distant Mast routing a point-to-point SMS text message. Alternatively, it may be the routing of the point-to-point SMS text message from a distant Mast occurred because the MS, in the idle mode, was surrounded by Masts that were at call traffic capacity. Alternatively it could be because of a combination of both buildings and call traffic capacity.
.
Knowing matters like these are very useful when dealing cell site analysis and a reason why they are incorporated into the Core Skills Knowledge of the TrewMTE training courses:
.
GSM Cell Site Analysis Training Course
-------------------------------------------------------
.
Course One: GSM Core Skills Knowledge Course (CSA Part 1)
3-days training
.
Course Two: GSM Cell Site Analysis Course (CSA Part 2)
3-days training
.
Course Three: GSM Cell Site Analysis Course (CSA Part 3)
3-days training
.
3G Cell Site Analysis Training Course
----------------------------------------------------
Course One: 3G Core Skills Knowledge Course (CSA Part 1)
4-days training
.
Course Two: 3G Cell Site Analysis Course (CSA Part 2)
3-days training
.
Course Three: 3G Cell Site Analysis Course (CSA Part 3)
3-days training
.
SIM Card Training
-------------------------
GSM SIM Card Training Course
3-days training
.
USIM/UICC Card Training
------------------------------------
3G USIM/UICC Training Course
3-days training
.
GSM/3G Handset Examination Training
------------------------------------------------------
GSM/3G Mobile Telephone Training Course
4-days training
------------------------------------------------------
MTEB Mobile Telephone Evidence Diplomas (MTEdipl).

Tuesday, June 08, 2010

Evidence and Admissibility Part 1

Evidence and Admissibility Part 1

The analysis that can never stop relates to issues associated with evidence and admissibility. We need thought provoking discussions to inform our knowledge. Also, we need to exercise our understanding of the work we are doing and whether it meets an acceptable criteria in the practices and procedures we follow. Moroever we should challenge perceptions we hold to discover where things could go wrong and make revelation of them to see how best they can be put right.

The discussion below contains references to Statutory Law and Case Law. I am not legally qualified and do not hold myself out to be giving legal advice. The legal references that have been used are there to help identify requirements that are in place or to merely demonstrate an interpretation.

STATEMENTS, TOOLS & PROCEDURES
The independence, objectivity and impartiality of a witness or expert can only be seen if each are responsible for producing their own research, analysis and reports and their own exhibits and the content in them unfettered from control by others who are not giving the evidence. Problemical is that any desire to achieve these laudable principles can be thwarted due to deficiencies in the system.

Using mobile phone examination tools to acquire data, that data maybe subjected to the limited capability of the tool that extracted the data in the first place from the target device (the "exhibit"). The accuracy of the harvested data can again have limitations if the tool that extracts data is equally set to work to translate the data. Most of 'the' tools do this. When I put the word 'the' in parenthesis I do so because I am of course referring to mobile phone tools and not every tool. Notwithstanding the aforementioned limitations, a further limitation can occur from which a tool outputs the data into datafields. This largely leaves the examiner to believe, any data that does not appear or cannot fit into a datafield, it is not (worthy) evidence for inclusion and doesn't get served. Extracted data that are not the subject of translations remains in a raw state in the electronic file and doesn't get served. If the examiner doesn't know what data to look for or does not understand the relevance of the data this too can contribute to evidence not seeing the light of day. If this is not revealed in the report/statement, and left unchallenged, it corrodes the principles and right to fair trail by diluting revelation in the criminal justice system.

It can also be the case that where the report/exhibit design and datafields for cell site analysis evidence are predefined and examiners/experts are told the format they must follow, again this leads to corruption of the principles mentioned at the outset. If the format is predefined it causes the examiner/expert to look only at a certain set of criteria and only the data for that criteria; other data that should have been considered gets ignored, and again does not see the light of day. Furthermore, it prevents the examiner/experts from corroborating facts prior to disclosure.

What observations might be drawn from the views above? One observation might be to look at the Industry Standards, Technical Standards (GSM/3GPP, ETSI/ITU/ISO, proprietory, etc) and QA Standards (ISO etc) to determine discovery and revelations that should be made. For instance, using the example of the proposed QA Standards of ISO17025 and ISO17020 the principles in them are drawn from ISO9000, an international QA Standard having principles in it that originated from the British QA Standard BS5750. So there is as an historical reference and appreciation to be aware that Britain is fully aware of using a quality approach when dealing with 'technical' material and the importance of its revelation. However, the different between ISO17025/ISO17020 and ISO9000/BS5750 is that the former are said to be directly applicable for forensic evidence where as the latter have never been directly applicable for forensic evidence, but have often been suggested as achieving a criteria sufficient for evidence.

More importantly, to this discussion, would the tools used for examination fail the crietria set out in ISO17025 and ISO17020? An example to look at might be the QA criteria relating to "non-conforming" product. If the examination tool does not possess the capability to know if the product (the "exhibit") is non-conforming or by use of that tool it introduces non-conformance into the product (the "exhibit"), then the tools output may fail the test. The analysis of the failure thus requires to be determined: to define whether the coding in the tools have been written incorrectly or the coding incorporates commands of a generic nature - meaning device-specific commands may not have been considered or used? The latter might cause data changes residing in the handset. Changes to data and failure to reveal that prior to disclosure undermines the discovery to be understood about served data and can affect a tribunal's understanding of the "defendant's behaviour in relation to the data" (s129 CJA (Criminal Justice Act) 2003). Under s69 of the Police and Criminal Evidence (PACE) Act 1984 (repealed) that occurrence would have been less likely because s69 compulsorily required prior consideration and affirmation before admissibility and allowed transparency upto the point that enabled probative enquiries and tests of the system (in some cases) to seek validation about a system's performance.

Evidence submitted in the past (pre s69 PACE repeal) came with a meaningful statement that was naturally attached with the evidence; post s69 PACE there is no equivalent technical statement of any compliance whatsoever, unless it is voluntarily made but simply not referenced to s69. When such a statement in the past was made it contained references to affirming the position required by s69 PACE 1984 as to the operation of the computer/s and affirmation (certificate) required by other provisions.

One might be forgiven for thinking the Police when they present evidence are excluded from making at least some declarations about the operational performance of their computer/s and program/s generating evidence. They are not excluded from doing so, there is simply no enforcement to include good QA declarations in their statements/reports about evidence they generate - whether obtained from mobile phones, computers, CCTV/Video and so on. In contrast, currently mobile operators producing billing records etc (served as evidence generated from a computer and program/application) still make a QA reliability statement that the computer that generated the evidence operated properly and if not it would not as such cause alteration to the state of the business record (data). So why shouldn't the Police and examiners make the same statements? Afterall they do use computers and programs to extract and harvest data from an exhibit and it is that data from the computers that the court sees.

CONTROLING REVELATION
The discussion, having dwelt on the subject of identifying some aspects of limitations that can occur with examiner skillsets, flawed tools, contaminated evidence, conflicts with standards and lack of appropriate procedural requirements, there are still the issues of 'control' of revelation as to how evidence is presented and what might influence that to happen?

Where examiners are forced to extract, harvested, examine and report evidence with preset requirements for revelation that may not fully corroborate "behaviour" when compared with the data that has been revealed under any enforced procedure, it may amount to undue preference or undue discrimination. The words 'preference' and 'discrimination' do not attract prohibition. Instead, the emphasis is on 'undue', which in dictionary terms can mean "improper", "unreasonable" and, in particular, "excessive". That emphasis might be applicable where commercial contracts, such as public sector contracts for the employment of outsourced services occurs that may have legal requirements, either express or implied, associated with them, that require the contracted party to use discrimination when revealing data by predicting only particular data to be available and be served (disclosed).

The matters of undue preference and undue discrimination have been dealt with by the House of Lords previously. Lord Keith and Lord Merriman outlined definitions in two separate actions involving the same case - South of Scotland Electricity Board -v- The British Oxygen Company - that concerned disputes with the provision of costs and supply of electricity as to how the meaning of 'undue' may have influence. These cases may provide useful pointers where controlled evidence is being used. Lord Keith in the first action ( [1956] 1 W.L.R. 1069 ) stated that the word "undue" encompassed not only illegitimate reasons but could also mean "excessive". In the later action ( [1959] 2 All E.R. 225 ) Lord Merriman addressed the matter in three parts. The first is use of the phrase "shall not exercise any undue discrimination" had to be considered as a whole. Secondly, making reference to objectives he identified "a fair distribution of the cost of supplying electricity as between one class of users and another is not to be left out of consideration any more...." followed by the use of the incisive comments for the third part "....'than any other circumstance which would affect mens' minds."

If the above principles are applied to evidence, then it would suggest the need to re-instate encumbent obligations (like s69 PACE) requiring performance of fair acquisition of data and fair distribution of evidence for delivery to a class of users (eg the Courts, Prosecution and Defence) and to protect against blind-siding and stumbling blocks that may cause undue discrimination. In addition, public sector contracts may well benefit from containing a contractual clause protection mechanism to enable the immediate use of the law to act as a 'shield and not a sword' when a penalty is threatened or issued against the outsourcer where the outsourcer has identified that the data under the schedules supporting the contract does not permit other important data to be incorporated into the datafields of the template that is being enforced to be used, thus prevents revelation. Such omission of data prevents the Prosecution from meeting their obligations under the Golden Rule enunciated by the noble Lord, Lord Bingham in the case of R .v. C & H (February 2004) to conduct a fair risk assessment when in possession of all the evidence and the facts in order to determine the risk, if any, that the evidence poses. The impeccable logic behind the requirement: if there is fundamental misunderstanding about the evidence and there are too many twist and turns being used to skew the path to appropriate discovery and revelation, that may interfere with others (who are not technical) in allowing them to meet their duty required by the statutory provisions, e.g. s9(2) Criminal Procedures and Investigations Act 1996?

Saturday, June 05, 2010

MTEdipl Diplomas

MTEdipl Diplomas
.
For registered students and those going through the process of registering for the Diplomas for the start of the September 2010 intake:
.
Three Months Notice (June/July/August) Advanced reading to help you prepare for the distance learning and self study. The following book comes highly recommended and will help you with setting your objectives particularly for the research and study modules for each Diploma.
.
LITERATURE:

Skills for Success, The Personal Development Planning Handbook
Author: Stella Cottrell Paperback: 312 pages
Publisher: Palgrave Macmillan (2 May 2003)
Language English ISBN-10: 1403911320
.
Amazon link:
http://www.amazon.co.uk/Skills-Success-Personal-Development-Planning/dp/1403911320