Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
1.1. SIM
Except for emergency calls, a GSM mobile phone CANNOT be used without the SIM.
So even in case of a defect in the users GSM telephone, any other GSM telephone
can be used instead, simply by changing the SIM.
Remarks
Note
Mandatory,
changeable,
Mandatory, fixed
Mandatory, fixed
Optional
(language =
mandatory)
Mandatory, fixed
Mandatory,
fixed, Check
again,
Key Kc
CKSN
Subscriber
data
IMSI
MSISDN
Access control
class
Roaming
data
TMSI
Location
updating
status, Value of
T3212 for LU,
LAI
PLMN data
NCC, mobile
country code
MCC, mobile
network code
MNC,
Absolute radio
freq channel
numbers
Mandatory,
changeable
Mandatory,
fixed, Check
again
optional, fixed
Mandatory,
changeable,
Check again
Mandatory,
changeable
Mandatory,
changeable
Mandatory, fixed
Network identifier
Mandatory, fixed
Mandatory, fixed
TMSI dc
assign boi
VLR toi MS
BTSs have many ways to configure: Standard Configuration All BTSs are assigned
different cell identities (Cis), and a number of BTSs form a location area. This
configuration is mostly used.
And Umbrella Configuration 1 high power, high ground with other low power and
small diameters.
Sectorized BTS: often Pi/3.
2.2. Base Station Controller
The BSC was defined with the intention of removing most of the radio-related load
from the MSC.
2.3.
TRAU
Parameters
Subscriber
specific
IMSI
Ki
TMSI
Service restrictions
Supplementary
services
MSISDN (basic)
MSISDN (other)
HLR/AuC
VLR
o
o
Note
o
o
o
o
o
o
o
Check again
Check again
Authentication
and Ciphering
A3
A5/X (in BSS)
A8
RAND up to 5 triplets
SNES up to 5 triplets
Kc up to 5 triplets
CKSN
o
o
o
o
o
o
o
o
o
Subscriber
location/ call
forwarding
HLR number
VLR number
MSC number
LAI
IMSI detach
MSRN
o
o
o
o
o
o
o
Check again
Mobile Station Roaming
Number
LMSI
Handover number
o
o
3.3. MSC
From a technical perspective, the MSC is just an ordinary Integrated Services Digital
Network (ISDN) exchange with some modifications specifically required to handle
the mobile application.
MSC is in charge of Registration, authentication, call location, inter-MSC handovers,
billing, call routing to a mobile subscriber
3.4. Gateway MSC
GMSC is an MSC with an interface to other networks.
IMSI changing
the Test IMSI is an IMSI number that you should create following the pattern
08091010xxxxxxxxxx. A SIM card with an IMSI such as that will not be blocked by the iPhone
BB.
To create a test IMSI SIM card, you need to get a SIM card whose IMSI can be changed, a
normal SIM card will not allow such change, there are some SIM cards that allow this such as
Super SIM 16 in 1 Super Sim Card Backup, Copy, Duplicate, Clone, Reader, Writer Kit at
Vavolo.com
Mr. Dill Huang suggests that first you insert you carrier SIM card, because its blocked you will
only be able to make emergency calls, so dial 112 for emergency call, after 2 seconds hang
up and switch to airplane mode, remove your carrier SIM card and insert your test SIM card
which you create with the Test IMSI, switch off your airplane mode and the phone should go
back to your carrier service, the BB will not block as the Test IMSI is unblocked by the BB
(even if it is a locked BB, because this is a test IMSI).
Mr. Dill even displays this on YouTube, check it here iPhone 4 SIM Unlock: Test IMSI and 112
Exploit - YouTube
Even if the technique works, the iPhone will at some point in time (not sure about the timers)
to refresh the IMSI and encryption keys from the SIM card, at which point it will not be able
to get the correct original IMSI and encryption keys, so you will need to keep doing this, not
to mention dialing the 112 number which could get answered! You can find this and more
information at the following "unofficial" FAQ by Mr. Dill himself here Singularity: Unofficial
Gevey FAQ
IMSI attach/detach [GSM 04.08, 09.02] The BTS permanently broadcasts the
parameter ATT in the BCCH / SYS_INFO 3 message. This parameter indicates
whether the IMSI attach/detach procedure is required. IMSI detach is a procedure to
inform the network that a mobile station will go into an inactive state and thus is no
longer available for incoming calls, for example, because of power-down or because
the SIM is removed. The mobile station sends an IMSI_DET_IND message to the
network each time it is powered down. The VLR keeps track of that state. The merit
of this approach is that it saves radio resources and processing time. The call
processing can switch to secondary call treatment, without the need of first sending
a PAGING message and then waiting for expiration of the respective timers.
Secondary call treatment means initiating call forwarding, voice mail, or simply
indicating to the caller that the subscriber is currently not reachable. The
complementary operation to IMSI detach is IMSI attach. It indicates to the network
that a mobile station is active again. IMSI attach is related to periodic location
updating. The location updating procedure is utilized to perform IMSI attach.
IMSI attach procedure:
1. MS/UE requests a signaling channel
2. The MSC/VLR receives the LU_REQ msg from the MS/UE indicating that the
purpose of this msg is the IMSI attach
3. The MSC/VLR sets the IMSI attach in the VLR => Mobile ready for normal call
handling
4. VLR returns ack to MS
Location update
Reason for LU:
- IMSI detach/attach
- Changes the location area when a periodic location update is active
Elements involved:
-
Process: