5G Cell Site Analys...
 
Notifications
Clear all

5G Cell Site Analysis (Positioning)

26 Posts
4 Users
0 Reactions
3,492 Views
(@tinybrain)
Reputable Member
Joined: 9 years ago
Posts: 354
Topic starter  

Positioning of mobiles only via MOCN by the INITIAL DIRECT TRANSFER parameter. All other options of V2V or Iot not important. The positioning failure of a 5GNR fake cell tower and how to detect the Kseaf keys false authentication I should contribute internally to the project team.

Positioning based on an involved fake 5GNR cell tower (EN-DC mode) I have to understand.


   
ReplyQuote
(@tinybrain)
Reputable Member
Joined: 9 years ago
Posts: 354
Topic starter  

You will laugh. I asked to find this other guy Gutmann from Zurich Police. And - I found him. But he is old and not willing to share anything, he is contrite. 5G he knows very well but no chance.

Any 'new' (may younger) 5G expert here on FF?


   
ReplyQuote
(@trewmte)
Noble Member
Joined: 19 years ago
Posts: 1877
 

Positioning of mobiles only via MOCN by the INITIAL DIRECT TRANSFER parameter. All other options of V2V or Iot not important. The positioning failure of a 5GNR fake cell tower and how to detect the Kseaf keys false authentication I should contribute internally to the project team.

Positioning based on an involved fake 5GNR cell tower (EN-DC mode) I have to understand.

TB whilst this is a very interesting subject the various lines of enquiry you are using for this matter (actually it is a language issue I think) creates complications as to what you see as possible connected evidence.

Although you mentioned inertial measurement unit (IMU) this alone is unlikely to achieve your goals. Regarding some suggested positioning protocols (e.g. GNSS) as you originally were looking at 4g-to-5g scenario

In LTE, the assistance data with respect to the following GNSS are supported
• GPS (Global Positioning System)
• SBAS (Satellite/Space Based Augmentation System)
• QZSS (Quasi-Zenith Satellite System)
• GLONASS (Global Navigation Satellite System)
• Galileo
• BDS (BeiDou Navigation Satellite System)

Therefore, you could if it is helpful to suggest clarify which mobile networks use which positioning protocols and what internal systems they deploy for RSS. This would be in addition to Cell ID etc.

I do believe the narrow vision of those that instruct you by singling out items, such as Kseaf, 5GNR fake base stations, etc, whilst interesting, you may think might be better served by looking at the network architecture and proposed architecture for network sharing. To that end can I invite you to review some of the following areas. For instance in the 5G poster you proposed we all look at, consider what is happening under New Radio (NR) End To End (E2E) Core Network. Consider e.g. 5G NSSF, 5G AMF. How would vSSF impact on your research question? That is to say you may wish to consider how the fake base station is to advertise itself?

Turning to Kseaf, there was a report back in February 2018 'Security vulnerability in 5G-AKA draft (3GPP TS 33.501 draft v0.7.0)' from researchers at the Department of Computer Science, University of Oxford which highlights issues of vulnerabilities and risks associated with false credentials.

All the above is not a secret and easily available in the public domain by researching.

You will laugh. I asked to find this other guy Gutmann from Zurich Police. And - I found him. But he is old and not willing to share anything, he is contrite. 5G he knows very well but no chance.

Any 'new' (may younger) 5G expert here on FF?

Just as an observation only. I note there was a suggestion put to you for you to communicate directly to Interpol which you didn't respond. Some of your posts here at FF suggest you work on behalf of or are a stakeholder to or work in association with law enforcement. It wasn't clear to me why you haven't gone down that route given the questions you ask (that is not a criticism) as you mentioned in another post here at FF (above) that you were able to assist the Zurich Police to track down 'Gutmann', presumably Rolf Gutmann (a previous poster here at FF). Surely with the same good-will approach as given to the Zurich Police maybe you could also see if Interpol or Europol or the UK National Crime Agency (NCA) would be interested in your research? Just a thought.


   
ReplyQuote
(@tinybrain)
Reputable Member
Joined: 9 years ago
Posts: 354
Topic starter  

I appreciate your advice and support. The IMU is UE domain and just the second layer of evidence if a fake 5GNR cell tower is in operation. My focus is on the network side (fronthaul) not GNSS systems.

What is the 5GNR positioning protocol and where to learn in 3GPP?
If EN-DC 5GNR mode how do combine the LTE and 5GNR positioning protocols?

Please help me as a cryptographer to learn the 5G Cell Site Analysis methods.


   
ReplyQuote
(@trewmte)
Noble Member
Joined: 19 years ago
Posts: 1877
 

I appreciate your advice and support. The IMU is UE domain and just the second layer of evidence if a fake 5GNR cell tower is in operation. My focus is on the network side (fronthaul) not GNSS systems.

What is the 5GNR positioning protocol and where to learn in 3GPP?
If EN-DC 5GNR mode how do combine the LTE and 5GNR positioning protocols?

Please help me as a cryptographer to learn the 5G Cell Site Analysis methods.

TB, YOU have had help. Review the standards, specifications, technical publications, books and white papers and conduct tests.

Good luck.


   
ReplyQuote
(@tinybrain)
Reputable Member
Joined: 9 years ago
Posts: 354
Topic starter  

Accept your refusal. May other Police corps are testing 5GNR Cell Site Analysis and can report their experience? Has anybody experience with the NRPPa?


   
ReplyQuote
(@trewmte)
Noble Member
Joined: 19 years ago
Posts: 1877
 

Accept your refusal. May other Police corps are testing 5GNR Cell Site Analysis and can report their experience? Has anybody experience with the NRPPa?

Accept your refusal to speak with clarity and avoid adding false extras after each response to your vague post. Speak the truth TB.


   
ReplyQuote
(@tinybrain)
Reputable Member
Joined: 9 years ago
Posts: 354
Topic starter  

Thank you subujoseph for the PM and detailled explainations. Which of the Nlmf data types do you think are most accurate AND in-field available (moderate environmental space conditions e.g.)?


   
ReplyQuote
(@tinybrain)
Reputable Member
Joined: 9 years ago
Posts: 354
Topic starter  

Which cities in the U.S. are fully equipped with 5GNR at 3,5GHz?
Which U.S. police is already in ops with 5GNR CSA?

U.S. guys please support me -)


   
ReplyQuote
(@armresl)
Noble Member
Joined: 21 years ago
Posts: 1011
 

What does this information do for you and your job?

Which cities in the U.S. are fully equipped with 5GNR at 3,5GHz?
Which U.S. police is already in ops with 5GNR CSA?

U.S. guys please support me -)


   
ReplyQuote
Page 2 / 3
Share: