New Delhi: IT firm iGate today said it has called off announcement of its "significant corporate development", where it was expected to notify its deal for buying 63 percent stake in Patni Computer Systems.
"The significant corporate development that was set to be announced on Monday is off," iGate said in a brief statement tonight without assigning any reasons.
2011 New Year Resolution for India: Which one needs to be removed as priority?
Corruption
Terrorism
View result
A company official when contacted declined to elaborate on the development.
The iGate-Apax consortium, which is tipped to be the front-runner for acquisition of a majority stake in India's sixth largest IT firm, was expected to make the announcement tomorrow.
Patni brothers -- - Narendra Patni, Ashok Patni and Gajendra Patni -- were in talks to sell their 46 per cent stake, while private equity firm General Atlantic was selling its roughly 17 percent holding in the software services exporter.
Patni's promoters and General Atlantic have made several efforts to sell their stake since 2007, which failed because of disagreements between the brothers and the high valuation expectations of the sellers.
The iGate-Apax consortium, which is tipped to be the front-runner for acquisition of a majority stake in the Indian IT firm, had earlier in the day said it will announce a "significant corporate development" on Monday.
Sources in-the-know said the deal was related to the iGate-Apax consortium's estimated $1 billion bid to buy a majority stake in Patni Computer.
The announcement was to have been made by iGate Chief Executive Officer Phaneesh Murthy in Bangalore tomorrow.
A consortium led by private equity firm Carlyle was the iGate-Apax consortium's main rival in the take-over bid, but is understood to have dropped out of the race on account of the high valuation of the firm.
According to industry analysts, the iGate-Apax consortium will pay 500-550 for each share of Patni Computer to be acquired, besides a non-compete fee to the promoters.
On Friday, shares of Patni closed at 476.65 on the Bombay Stock Exchange, up 0.77 percent from the previous close.
Patni, a mid-sized IT services firm, provides solutions to verticals like insurance, telecom, utilities and retail. Patni's revenues for the year ended December, 2009, stood at 1,751.33 crore ($391.79 million, at an exchange rate of 44.70 per U.S. dollar).
iGate's revenues, on the other hand stood at $74.8 million for the quarter ended September, 2010, and $193.09 million for the whole of 2009.
Closure of the deal would mark the culmination of several efforts by Patni's promoters and General Atlantic to sell their stake since 2007. Earlier attempts to sell a stake failed because of disagreements between the brothers and the high valuation expectations of the sellers.
iGate had also expressed interest in buying Satyam Computer Services , after the multi-crore scam perpetrated by founder Chairman B Ramalinga Raju broke out. Satyam has since been rebranded Mahindra Satyam, following its acquisition by Tech Mahindra .
This blog contains all the technological news and information. It also provides the investment ideas.
Showing posts with label 3G Technology. Show all posts
Showing posts with label 3G Technology. Show all posts
Tuesday, January 4, 2011
Monday, December 20, 2010
How to Remove autorun.inf Virus from USB/Pen Drive?
Pen drives these days are more vulnerable to viruses and the biggest problem most PC users face is “Autorun.Inf” which automatically installs virus in other folders. In order to remove Auto Run virus, you just need to replace to the file with a new one “Autorun.Inf”.
Steps to Remove Autorun.Inf Virus from Pen Drive
1.Open a notepad and leave it blank (don’t type anything)
2.Save it as “Autorun.Inf” in the destination drive (Your Pen Drive)
Autorun.Inf
That’s it. The autorun virus is now removed from your pendrive.
The actual logic behind this is to overwrite the autorun.inf file with an empty one. Because an empty autorun file can’t execute automatically.
This is the basic and very simple step to get rid of Autorun.Inf virus without having to use any Anti-virus software’s.
Pen drives these days are more vulnerable to viruses and the biggest problem most PC users face is “Autorun.Inf” which automatically installs virus in other folders. In order to remove Auto Run virus, you just need to replace to the file with a new one “Autorun.Inf”.
Steps to Remove Autorun.Inf Virus from Pen Drive
1.Open a notepad and leave it blank (don’t type anything)
2.Save it as “Autorun.Inf” in the destination drive (Your Pen Drive)
Autorun.Inf
That’s it. The autorun virus is now removed from your pendrive.
The actual logic behind this is to overwrite the autorun.inf file with an empty one. Because an empty autorun file can’t execute automatically.
This is the basic and very simple step to get rid of Autorun.Inf virus without having to use any Anti-virus software’s.
Friday, December 10, 2010
Rectifiers
Rectifier
Rectifier is an electrical device which converts alternating current into direct current. This process of converting ac to dc is known as rectification
Rectifiers are used as components of power supplies and as detectors of radio signals. Rectifiers may be made of solid state diodes, vacuum tube diodes, and other components.
The circuit which performs the function of converting dc to ac is known as inverter.
Half-wave Rectifier
Types of Full-wave rectifier
• 1)Center-trapped Rectifier
2) Bridge Rectifier
Applications
• The primary application of rectifiers is to derive usable DC power from an AC supply. Virtually all electronics except simple motor circuits such as fans require a DC supply but mains power is AC so rectifiers are used inside the power supply of all electronics.
Rectifier is an electrical device which converts alternating current into direct current. This process of converting ac to dc is known as rectification
Rectifiers are used as components of power supplies and as detectors of radio signals. Rectifiers may be made of solid state diodes, vacuum tube diodes, and other components.
The circuit which performs the function of converting dc to ac is known as inverter.
Half-wave Rectifier
Types of Full-wave rectifier
• 1)Center-trapped Rectifier
2) Bridge Rectifier
Applications
• The primary application of rectifiers is to derive usable DC power from an AC supply. Virtually all electronics except simple motor circuits such as fans require a DC supply but mains power is AC so rectifiers are used inside the power supply of all electronics.
Semi-Conductors
Semiconductors
Metals which have conductivity less than conductors and more than insulators or resistivity more than conductors and less than insulators are known as semiconductors.
e. g silicon, germanium etc
Types of semiconductors
1)Intrinsic semiconductors
2) Extrinsic semiconductors
Intrinsic semiconductors
When in pure germanium or silicon the amount of impurity level is less than 1 part in10^8, that semiconductor is known as intrinsic semiconductor
Extrinsic Semiconductor
When in pure silicon or germanium, impurity of element is added in very small proportion, it is called extrinsic semiconductor
The process of adding impurity element in pure semiconductor is known as doping
Extrinsic semiconductors may be of two types :-
1)N-type Semiconductor
2)P-type Semiconductor
N-Type Semiconductors
When in pure germanium or silicon the impurity of the penta valent element like arsenic, antimony or phosphorus is added in very small definite proportion, N-type semiconductor results
Energy band diagram for N-type semiconductor
P-type Semiconductor
When in pure germanium or silicon, impurity of the trivalent element having three valence electrons is added in small definite proportion, P-type results.
Energy band diagram of P-type semiconductor
Applications
1)Diodes
2)I.C
3)Transistor
Metals which have conductivity less than conductors and more than insulators or resistivity more than conductors and less than insulators are known as semiconductors.
e. g silicon, germanium etc
Types of semiconductors
1)Intrinsic semiconductors
2) Extrinsic semiconductors
Intrinsic semiconductors
When in pure germanium or silicon the amount of impurity level is less than 1 part in10^8, that semiconductor is known as intrinsic semiconductor
Extrinsic Semiconductor
When in pure silicon or germanium, impurity of element is added in very small proportion, it is called extrinsic semiconductor
The process of adding impurity element in pure semiconductor is known as doping
Extrinsic semiconductors may be of two types :-
1)N-type Semiconductor
2)P-type Semiconductor
N-Type Semiconductors
When in pure germanium or silicon the impurity of the penta valent element like arsenic, antimony or phosphorus is added in very small definite proportion, N-type semiconductor results
Energy band diagram for N-type semiconductor
P-type Semiconductor
When in pure germanium or silicon, impurity of the trivalent element having three valence electrons is added in small definite proportion, P-type results.
Energy band diagram of P-type semiconductor
Applications
1)Diodes
2)I.C
3)Transistor
Thursday, December 9, 2010
Bluetooth Hacking
Bluetooth is a wireless technology that enables any electrical device to wirelessly communicate in the 2.5 GHz ISM (license free) frequency band. It allows devices such as mobile phones, headsets, PDA's and portable computers to communicate and send data to each other without the need for wires or cables to link to devices together. It has been specifically designed as a low cost, low power, radio technology, which is particularly suited to the short range Personal Area Network (PAN) application. (It is the design focus on low cost, low size and low power, which distinguishes it from the IEEE 802.11 wireless LAN technology).
The Main Features of Bluetooth:
- Operates in the 2.4GHz frequency band without a license for wireless communication.
- Real-time data transfer usually possible between 10-100m.
- Close proximity not required as with infrared data (IrDA) communication devices as Bluetooth doesn't suffer from interference from obstacles such as walls.
- Supports both point-to-point wireless connections without cables between mobile phones and personal computers, as well as point-to-multipoint connections to enable ad hoc local wireless networks.
- It uses unlicensed ISM (Industrial, Scientific and Medical) band, 2400 - 2483.5 MHz, Modulation - Gaussian frequency shift keying,. Frequency Hopping Spread Spectrum - 1600 hops/sec, amongst 79 channels, spaced at 1 MHz separation.
When and How was it Conceived?
Bluetooth was originally conceived by Ericsson in 1994, when they began a study to examine alternatives to cables that linked mobile phone accessories.
Where did the Name Come From?
Bluetooth was named after Herald Blatand (or Bluetooth), a tenth century Danish Viking king who had united and controlled large parts of Scandinavia which are today Denmark and Norway. The name was chosen to highlight the potential of the technology to unify the telecommunications and computing industries
SIG Membership?
Since its original foundation, the Bluetooth SIG has transitioned into a not-for-profit trade association, Bluetooth SIG, Inc. Membership is open to all companies wishing to develop, market and promote Bluetooth products at two levels - Associate and Adopter Members.
Bluetooth Security
1 The Bluetooth pairing & authentication process
The Bluetooth initialization procedures consist of 3 or 4 steps:
1. Creation of an initialization key (Kinit).
2. Creation of a link key (Kab).
3. Authentication.
After the 3 pairing steps are completed, the devices can derive an encryption key to hide all future communication in an optional fourth step.
Before the pairing process can begin, the PIN code must be entered into both Bluetooth devices. Note that in some devices (like wireless earphones) the PIN is fixed and cannot be changed. In such cases, the fixed PIN is entered into the peer device. If two devices have a fixed PIN, they cannot be paired, and therefore cannot communicate. In the following sections we go into the details of the steps of the pairing process.
1 Creation of Kinit
The Kinit key is created using the E22 algorithm, whose inputs are:
1. a BD_ADDR.
2. the PIN code and its length.
3. a 128 bit random number IN_RAND.
This algorithm outputs a 128-bit word, which is referred to as the initialization key (Kinit).
Figure 1 describes how Kinit is generated using E22. Note that the PIN code is available at both Bluetooth devices, and the 128 bit IN_RAND is transmitted in plaintext. As for the BD_ADDR: if one of the devices has a fixed PIN, they use the BD_ADDR of the peer device. If both have a variable PIN, they use the PIN of the slave device that receives the IN_RAND. In Figure 1, if both devices have a variable PIN, BD_ADDRB shall be used. The Bluetooth device address can be obtained via an inquiry routine by a device. This is usually done before connection establishment begins
This initialization key (Kinit) is used only during the pairing process. Upon the creation of the link key (Kab), the Kinit key is discarded.
Figure 1: Generation of Kinit using E22
2.1.2 Creation of Kab
After creating the initialization key, the devices create the link key Kab. The devices use the initialization key to exchange two new 128 bit random words, known as LK_RANDA and LK_RANDB. Each device selects a random 128 bit word and sends it to the other device after bitwise xoring it with Kinit. Since both devices know Kinit, each device now holds both random numbers LK_RANDA and LK_RANDB. Using the E21 algorithm, both devices create the link key Kab. The inputs of E21 algorithm are:
1. a BD_ADDR.
2. The 128 bit random number LK_RAND.
Note that E21 is used twice is each device, with two sets of inputs. Figure 2 describes how the link key Kab is created.
Figure 2: Generation of Kab using E21
2.1.3 Mutual authentication
Upon creation of the link key Kab, mutual authentication is performed. This process is based on a challenge-response scheme. One of the devices, the verifier, randomizes and sends (in plaintext) a 128 bit word called AU_RANDA. The other device, the claimant, calculates a 32 bit word called SRES using an algorithm E1. The claimant sends the 32 bit SRES word as a reply to the verifier, who verifies (by performing the same calculations) the response word. If the response word is successful, the verifier and the claimant change roles and repeat the entire process. Figure 3 describes the process of mutual authentication. The inputs to E1 are:
1. The random word AU_RANDA.
2. The link key Kab.
3. Its own Bluetooth device address (BD_ADDRB).
Note that as a side effect of the authentication process, both peers calculate a 96 bit word called ACO. This word is optionally used during the creation of the encryption key. The creation of this encryption key exceeds our primary discussion and shall not be described in this paper.
Figure 3: Mutual authentication process using E1
2.2 Bluetooth cryptographic primitives
As we described above, the Bluetooth pairing and authentication process uses three algorithms: E22, E21, E1. All of these algorithms are based on the SAFER+ cipher with some modifications. Here we describe features of SAFER+ that are relevant to our attack.
2.2.1 Description of SAFER+
SAFER+ is a block cipher with a block size of 128 bits and three different key lengths: 128, 192 and 256 bits. Bluetooth uses SAFER+ with 128 bit key length. In this mode, SAFER+ consists of:
1. KSA - A key scheduling algorithm that produces 17 different 128-bit subkeys.
2. 8 identical rounds.
3. An output transformation - which is implemented as a xor between the output of the last round and the last subkey.
Figure 4 describes the inner design of SAFER+, as it is used in Bluetooth.
Figure 4: Inner design of SAFER+
The key scheduling algorithm (KSA)
The key scheduling algorithm used in SAFER+ produces 17 different 128-bit subkeys, denoted K1 to K17. Each SAFER+ round uses 2 subkeys, and the last key is used in the SAFER+ output transformation. The important details for our discussion are that in each step of the KSA, each byte is cyclic-rotated left by 3 bit positions, and 16 bytes (out of 17) are selected for the output subkey. In addition, a 128 bit bias vector, different in each step, is added to the selected output bytes.
The SAFER+ Round
As depicted, SAFER+ consists of 8 identical rounds. Each round calculates a 128 bit word out of two subkeys and a 128 bit input word from the previous round.
3 Bluetooth PIN Cracking
3.1 The Basic Attack:
Table 1: List of messages sent during the pairing and authentication process. ``A'' and ``B'' denote the two Bluetooth devices.
# Src Dst Data Length Notes
1 A B IN_RAND 128 bit plaintext
2 A B LK_RANDA 128 bit XORed with Kinit
3 B A LK_RANDB 128 bit XORed with Kinit
4 A B AU_RANDA 128 bit plaintext
5 B A SRES 32 bit plaintext
6 B A AU_RANDB 128 bit plaintext
7 A B SRES 32 bit plaintext
Assume that the attacker eavesdropped on an entire pairing and authentication process, and saved all the messages (see Table 1). The attacker can now use a brute force algorithm to find the PIN used. The attacker enumerates all possible values of the PIN. Knowing IN_RAND and the BD_ADDR, the attacker runs E22 with those inputs and the guessed PIN, and finds a hypothesis for Kinit. The attacker can now use this hypothesis of the initialization key, to decode messages 2 and 3. Messages 2 and 3 contain enough information to perform the calculation of the link key Kab, giving the attacker a hypothesis of Kab. The attacker now uses the data in the last 4 messages to test the hypothesis: Using Kab and the transmitted AU_RANDA (message 4), the attacker calculates SRES and compares it to the data of message 5. If necessary, the attacker can use the value of messages 6 and 7 to re-verify the hypothesis Kab until the correct PIN is found. Figure 6 describes the entire process of PIN cracking.
Note that the attack, as described, is only fully successful against PIN values of under 64 bits. If the PIN is longer, then with high probability there will be multiple PIN candidates, since the two SRES values only provide 64 bits of data to test against. A 64 bit PIN is equivalent to a 19 decimal digits PIN.
Figure 6: The Basic Attack Structure.
4 The Re-Pairing attack
4.1 Background and motivation
This section describes an additional attack on Bluetooth devices that is useful when used in conjunction with the primary attack described in Section 3. Recall that the primary attack is only applicable if the attacker has eavesdropped on the entire process of pairing and authentication. This is a major limitation since the pairing process is rarely repeated. Once the link key Kab is created, each Bluetooth device stores it for possible future communication with the peer device. If at a later point in time the device initiates communication with the same peer - the stored link key is used and the pairing process is skipped. Our second attack exploits the connection establishment protocol to force the communicating devices to repeat the pairing process. This allows the attacker to record all the messages and crack the PIN using the primary attack described in this paper.
4.2 Attack details
Assume that two Bluetooth devices that have already been paired before now intend to establish communication again. This means that they don't need to create the link key Kab again, since they have already created and stored it before. They proceed directly to the Authentication phase (Recall Figure 3). We describe three different methods that can be used to force the devices to repeat the pairing process. The efficiency of each method depends on the implementation of the Bluetooth core in the device under attack. These methods appear in order of efficiency:
1. Since the devices skipped the pairing process and proceeded directly to the Authentication phase, the master device sends the slave an AU_RAND message, and expects the SRES message in return. Note that Bluetooth specifications allow a Bluetooth device to forget a link key. In such a case, the slave sends an LMP_not_accepted message in return, to let the master know it has forgotten the link key. Therefore, after the master device has sent the AU_RAND message to the slave, the attacker injects a LMP_not_accepted message toward the master. The master will be convinced that the slave has lost the link key and pairing will be restarted. Restarting the pairing procedure causes the master to discard the link key. This assures pairing must be done before devices can authenticate again.
2. At the beginning of the Authentication phase, the master device is supposed to send the AU_RAND to the slave. If before doing so, the attacker injects a IN_RAND message toward the slave, the slave device will be convinced the master has lost the link key and pairing is restarted. This will cause the connection establishment to restart.
3. During the Authentication phase, the master device sends the slave an AU_RAND message, and expects a SRES message in return. If, after the master has sent the AU_RAND message, an attacker injects a random SRES message toward the master, this will cause the Authentication phase to restart, and repeated attempts will be made. At some point, after a certain number of failed authentication attempts, the master device is expected to declare that the authentication procedure has failed (implementation dependent) and initiate pairing.
4. The three methods described above cause one of the devices to discard its link key. This assures the pairing process will occur during the next connection establishment, so the attacker will be able to eavesdrop on the entire process, and use the method described in Section 3 to crack the PIN.
In order to make the attack ``online'', the attacker can save all the messages transferred between the devices after the pairing is complete. After breaking the PIN (0.06-0.3 sec for a 4 digit PIN), the attacker can decode the saved messages, and continue to eavesdrop and decode the communication on the fly. Since Bluetooth supports a bit rate of 1 Megabit per second, a 40KB buffer is more than enough for the common case of a 4 digit PIN.
Notes:
1. The Bluetooth specification does allow devices to forget link keys and to require repeating the pairing process. This fact makes the re-pairing attack applicable.
2. Re-Pairing is an active attack, that requires the attacker to inject a specific message at a precise point in the protocol. This is most likely needs a custom Bluetooth device since off-the-shelf components will be unable to support such behavior.
3. If the slave device verifies that the message it receives is from the correct BD_ADDR, then the attack requires the injected message to have its source BD_ADDR ``spoofed'' - again requiring custom hardware.
4. If the attack is successful, the Bluetooth user will need to enter the PIN again - so a suspicious user may realize that his Bluetooth device is under attack and refuse to enter the PIN.
5 Countermeasures
This section details the countermeasures one should consider when using a Bluetooth device. These countermeasures will reduce the probability of being subjected to both attacks and the vulnerability to these attacks.
1. Since Bluetooth is a wireless technology, it is very difficult to avoid Bluetooth signals from leaking outside the desired boundaries. Therefore, one should follow the recommendation in the Bluetooth standard and refrain from entering the PIN into the Bluetooth device for pairing as much as possible. This reduces the risk of an attacker eavesdropping on the pairing process and finding the PIN used.
Most Bluetooth devices save the link key (Kab) in non-volatile memory for future use. This way, when the same Bluetooth devices wish to communicate again, they use the stored link key. However, there is another mode of work, which requires entering the PIN into both devices every time they wish to communicate, even if they have already been paired before. This mode gives a false sense of security! Starting the pairing process every time increases the probability of an attacker eavesdropping on the messages transferred. We suggest not to use this mode of work.
2. Finally, the PIN length ranges from 8 to 128 bits. Most manufacturers use a 4 digit PIN and supply it with the device. Obviously, customers should demand the ability to use longer PINs.
3.Instead of passing messages in plain text, they should be encoded before transmission.
The Future of Bluetooth
The next version of Bluetooth, currently code named Lisbon, includes a number of features to increase security, usability and value of Bluetooth. The following features are defined:
- Atomic Encryption Change
- Extended Inquiry Response
- Sniff Subrating QoS Improvements
- Simple Pairing
Types of attacks in Bluetooth
The SNARF attack:
It is possible, on some makes of device, to connect to the device without alerting the owner of the target device of the request, and gain access to restricted portions of the stored data therein, including the entire phonebook (and any images or other data associated with the entries), calendar, realtime clock, business card, properties, change log, IMEI (International Mobile Equipment Identity [6], which uniquely identifies the phone to the mobile network, and is used in illegal phone 'cloning'). This is normally only possible if the device is in "discoverable" or "visible" mode, but there are tools available on the Internet that allow even this safety net to be bypassed.
The BACKDOOR attack:
The backdoor attack involves establishing a trust relationship through the "pairing" mechanism, but ensuring that it no longer appears in the target's register of paired devices. In this way, unless the owner is actually observing their device at the precise moment a connection is established. Device grants access to services. This means that not only can data be retrieved from the phone, but other services, such as modems or Internet, WAP and GPRS gateways may be accessed without the owner's knowledge or consent. Indications are that once the backdoor is installed, the above SNARF attack will function on devices that previously denied access, and without the restrictions of a plain SNARF attack, so we strongly suspect that the other services will prove to be available also.
The BLUEBUG attack:
The bluebug attack creates a serial profile connection to the device, thereby giving full access to the AT command set, which can then be exploited using standard off the shelf tools, such as PPP for networking and gnokii for messaging, contact management, diverts and initiating calls. With this facility, it is possible to use the phone to initiate calls to premium rate numbers, send sms messages, read sms messages, connect to data services such as the Internet, and even monitor conversations in the vicinity of the phone. This latter is done via a voice call over the GSM network, so the listening post can be anywhere in the world. Bluetooth access is only required for a few seconds in order to set up the call. Call forwarding diverts can be set up, allowing the owner's incoming calls to be intercepted, either to provide a channel for calls to more expensive destinations, or for identity theft by impersonation of the victim.
Scanning for Bluetooth addresses
The Bluetooth address itself is a unique 48bit device identifier, where the first 3 bytes of the address are assigned to a specific manufacturer by the IEEE (www.ieee.org/), and the last 3 bytes are freely allocated by the manufacturer. For example, the hexadecimal representation of a Sony Ericsson P900 phone's Bluetooth address may look like 00:0A:D9:EB:66:C7, where the first 3 bytes of this address (00:0A:D9) are registered to Sony Ericsson by the IEEE, meaning that all P900 phones will have their Bluetooth address starting with same 3 bytes. The last 3 bytes (EB:66:C7) of the sample address are assigned to this device by Sony Ericsson and should be different for each P900 phone -- but is not always, unfortunately.
In theory, enabling the non-discoverable mode on a Bluetooth device should protect users from unauthorized connections, yet in practice it is still quite possible to find these devices. There are software tools available which allow brute-force discovery of non-discoverable devices. An example of such an application is RedFang by Ollie Whitehouse, a small application which simply tries to connect to a unique Bluetooth address one by one, until finally a hidden device answers the request sent that was sent to that particular address. Author's initial test is a minimum of 6 seconds to achieve a good level of accuracy (it varies from 2.5 to 10 seconds, on average). It is certainly possible to find a hidden device in less than 3 seconds, The address space used by Sony Ericsson has 16,777,216 possible addresses. If we assume 6 seconds are required per device, the total scan would take us 1165 days, meaning we would need more than 3 years to discover all hidden Sony Ericsson phones in a conference room.
Conclusion:
With the advancement of digital convergence on M-commerce, usuage of bluetooth in connecting different devices is going to be significant. But to make communication more secure advancement in the prospect of security must not be neglected.
The Main Features of Bluetooth:
- Operates in the 2.4GHz frequency band without a license for wireless communication.
- Real-time data transfer usually possible between 10-100m.
- Close proximity not required as with infrared data (IrDA) communication devices as Bluetooth doesn't suffer from interference from obstacles such as walls.
- Supports both point-to-point wireless connections without cables between mobile phones and personal computers, as well as point-to-multipoint connections to enable ad hoc local wireless networks.
- It uses unlicensed ISM (Industrial, Scientific and Medical) band, 2400 - 2483.5 MHz, Modulation - Gaussian frequency shift keying,. Frequency Hopping Spread Spectrum - 1600 hops/sec, amongst 79 channels, spaced at 1 MHz separation.
When and How was it Conceived?
Bluetooth was originally conceived by Ericsson in 1994, when they began a study to examine alternatives to cables that linked mobile phone accessories.
Where did the Name Come From?
Bluetooth was named after Herald Blatand (or Bluetooth), a tenth century Danish Viking king who had united and controlled large parts of Scandinavia which are today Denmark and Norway. The name was chosen to highlight the potential of the technology to unify the telecommunications and computing industries
SIG Membership?
Since its original foundation, the Bluetooth SIG has transitioned into a not-for-profit trade association, Bluetooth SIG, Inc. Membership is open to all companies wishing to develop, market and promote Bluetooth products at two levels - Associate and Adopter Members.
Bluetooth Security
1 The Bluetooth pairing & authentication process
The Bluetooth initialization procedures consist of 3 or 4 steps:
1. Creation of an initialization key (Kinit).
2. Creation of a link key (Kab).
3. Authentication.
After the 3 pairing steps are completed, the devices can derive an encryption key to hide all future communication in an optional fourth step.
Before the pairing process can begin, the PIN code must be entered into both Bluetooth devices. Note that in some devices (like wireless earphones) the PIN is fixed and cannot be changed. In such cases, the fixed PIN is entered into the peer device. If two devices have a fixed PIN, they cannot be paired, and therefore cannot communicate. In the following sections we go into the details of the steps of the pairing process.
1 Creation of Kinit
The Kinit key is created using the E22 algorithm, whose inputs are:
1. a BD_ADDR.
2. the PIN code and its length.
3. a 128 bit random number IN_RAND.
This algorithm outputs a 128-bit word, which is referred to as the initialization key (Kinit).
Figure 1 describes how Kinit is generated using E22. Note that the PIN code is available at both Bluetooth devices, and the 128 bit IN_RAND is transmitted in plaintext. As for the BD_ADDR: if one of the devices has a fixed PIN, they use the BD_ADDR of the peer device. If both have a variable PIN, they use the PIN of the slave device that receives the IN_RAND. In Figure 1, if both devices have a variable PIN, BD_ADDRB shall be used. The Bluetooth device address can be obtained via an inquiry routine by a device. This is usually done before connection establishment begins
This initialization key (Kinit) is used only during the pairing process. Upon the creation of the link key (Kab), the Kinit key is discarded.
Figure 1: Generation of Kinit using E22
2.1.2 Creation of Kab
After creating the initialization key, the devices create the link key Kab. The devices use the initialization key to exchange two new 128 bit random words, known as LK_RANDA and LK_RANDB. Each device selects a random 128 bit word and sends it to the other device after bitwise xoring it with Kinit. Since both devices know Kinit, each device now holds both random numbers LK_RANDA and LK_RANDB. Using the E21 algorithm, both devices create the link key Kab. The inputs of E21 algorithm are:
1. a BD_ADDR.
2. The 128 bit random number LK_RAND.
Note that E21 is used twice is each device, with two sets of inputs. Figure 2 describes how the link key Kab is created.
Figure 2: Generation of Kab using E21
2.1.3 Mutual authentication
Upon creation of the link key Kab, mutual authentication is performed. This process is based on a challenge-response scheme. One of the devices, the verifier, randomizes and sends (in plaintext) a 128 bit word called AU_RANDA. The other device, the claimant, calculates a 32 bit word called SRES using an algorithm E1. The claimant sends the 32 bit SRES word as a reply to the verifier, who verifies (by performing the same calculations) the response word. If the response word is successful, the verifier and the claimant change roles and repeat the entire process. Figure 3 describes the process of mutual authentication. The inputs to E1 are:
1. The random word AU_RANDA.
2. The link key Kab.
3. Its own Bluetooth device address (BD_ADDRB).
Note that as a side effect of the authentication process, both peers calculate a 96 bit word called ACO. This word is optionally used during the creation of the encryption key. The creation of this encryption key exceeds our primary discussion and shall not be described in this paper.
Figure 3: Mutual authentication process using E1
2.2 Bluetooth cryptographic primitives
As we described above, the Bluetooth pairing and authentication process uses three algorithms: E22, E21, E1. All of these algorithms are based on the SAFER+ cipher with some modifications. Here we describe features of SAFER+ that are relevant to our attack.
2.2.1 Description of SAFER+
SAFER+ is a block cipher with a block size of 128 bits and three different key lengths: 128, 192 and 256 bits. Bluetooth uses SAFER+ with 128 bit key length. In this mode, SAFER+ consists of:
1. KSA - A key scheduling algorithm that produces 17 different 128-bit subkeys.
2. 8 identical rounds.
3. An output transformation - which is implemented as a xor between the output of the last round and the last subkey.
Figure 4 describes the inner design of SAFER+, as it is used in Bluetooth.
Figure 4: Inner design of SAFER+
The key scheduling algorithm (KSA)
The key scheduling algorithm used in SAFER+ produces 17 different 128-bit subkeys, denoted K1 to K17. Each SAFER+ round uses 2 subkeys, and the last key is used in the SAFER+ output transformation. The important details for our discussion are that in each step of the KSA, each byte is cyclic-rotated left by 3 bit positions, and 16 bytes (out of 17) are selected for the output subkey. In addition, a 128 bit bias vector, different in each step, is added to the selected output bytes.
The SAFER+ Round
As depicted, SAFER+ consists of 8 identical rounds. Each round calculates a 128 bit word out of two subkeys and a 128 bit input word from the previous round.
3 Bluetooth PIN Cracking
3.1 The Basic Attack:
Table 1: List of messages sent during the pairing and authentication process. ``A'' and ``B'' denote the two Bluetooth devices.
# Src Dst Data Length Notes
1 A B IN_RAND 128 bit plaintext
2 A B LK_RANDA 128 bit XORed with Kinit
3 B A LK_RANDB 128 bit XORed with Kinit
4 A B AU_RANDA 128 bit plaintext
5 B A SRES 32 bit plaintext
6 B A AU_RANDB 128 bit plaintext
7 A B SRES 32 bit plaintext
Assume that the attacker eavesdropped on an entire pairing and authentication process, and saved all the messages (see Table 1). The attacker can now use a brute force algorithm to find the PIN used. The attacker enumerates all possible values of the PIN. Knowing IN_RAND and the BD_ADDR, the attacker runs E22 with those inputs and the guessed PIN, and finds a hypothesis for Kinit. The attacker can now use this hypothesis of the initialization key, to decode messages 2 and 3. Messages 2 and 3 contain enough information to perform the calculation of the link key Kab, giving the attacker a hypothesis of Kab. The attacker now uses the data in the last 4 messages to test the hypothesis: Using Kab and the transmitted AU_RANDA (message 4), the attacker calculates SRES and compares it to the data of message 5. If necessary, the attacker can use the value of messages 6 and 7 to re-verify the hypothesis Kab until the correct PIN is found. Figure 6 describes the entire process of PIN cracking.
Note that the attack, as described, is only fully successful against PIN values of under 64 bits. If the PIN is longer, then with high probability there will be multiple PIN candidates, since the two SRES values only provide 64 bits of data to test against. A 64 bit PIN is equivalent to a 19 decimal digits PIN.
Figure 6: The Basic Attack Structure.
4 The Re-Pairing attack
4.1 Background and motivation
This section describes an additional attack on Bluetooth devices that is useful when used in conjunction with the primary attack described in Section 3. Recall that the primary attack is only applicable if the attacker has eavesdropped on the entire process of pairing and authentication. This is a major limitation since the pairing process is rarely repeated. Once the link key Kab is created, each Bluetooth device stores it for possible future communication with the peer device. If at a later point in time the device initiates communication with the same peer - the stored link key is used and the pairing process is skipped. Our second attack exploits the connection establishment protocol to force the communicating devices to repeat the pairing process. This allows the attacker to record all the messages and crack the PIN using the primary attack described in this paper.
4.2 Attack details
Assume that two Bluetooth devices that have already been paired before now intend to establish communication again. This means that they don't need to create the link key Kab again, since they have already created and stored it before. They proceed directly to the Authentication phase (Recall Figure 3). We describe three different methods that can be used to force the devices to repeat the pairing process. The efficiency of each method depends on the implementation of the Bluetooth core in the device under attack. These methods appear in order of efficiency:
1. Since the devices skipped the pairing process and proceeded directly to the Authentication phase, the master device sends the slave an AU_RAND message, and expects the SRES message in return. Note that Bluetooth specifications allow a Bluetooth device to forget a link key. In such a case, the slave sends an LMP_not_accepted message in return, to let the master know it has forgotten the link key. Therefore, after the master device has sent the AU_RAND message to the slave, the attacker injects a LMP_not_accepted message toward the master. The master will be convinced that the slave has lost the link key and pairing will be restarted. Restarting the pairing procedure causes the master to discard the link key. This assures pairing must be done before devices can authenticate again.
2. At the beginning of the Authentication phase, the master device is supposed to send the AU_RAND to the slave. If before doing so, the attacker injects a IN_RAND message toward the slave, the slave device will be convinced the master has lost the link key and pairing is restarted. This will cause the connection establishment to restart.
3. During the Authentication phase, the master device sends the slave an AU_RAND message, and expects a SRES message in return. If, after the master has sent the AU_RAND message, an attacker injects a random SRES message toward the master, this will cause the Authentication phase to restart, and repeated attempts will be made. At some point, after a certain number of failed authentication attempts, the master device is expected to declare that the authentication procedure has failed (implementation dependent) and initiate pairing.
4. The three methods described above cause one of the devices to discard its link key. This assures the pairing process will occur during the next connection establishment, so the attacker will be able to eavesdrop on the entire process, and use the method described in Section 3 to crack the PIN.
In order to make the attack ``online'', the attacker can save all the messages transferred between the devices after the pairing is complete. After breaking the PIN (0.06-0.3 sec for a 4 digit PIN), the attacker can decode the saved messages, and continue to eavesdrop and decode the communication on the fly. Since Bluetooth supports a bit rate of 1 Megabit per second, a 40KB buffer is more than enough for the common case of a 4 digit PIN.
Notes:
1. The Bluetooth specification does allow devices to forget link keys and to require repeating the pairing process. This fact makes the re-pairing attack applicable.
2. Re-Pairing is an active attack, that requires the attacker to inject a specific message at a precise point in the protocol. This is most likely needs a custom Bluetooth device since off-the-shelf components will be unable to support such behavior.
3. If the slave device verifies that the message it receives is from the correct BD_ADDR, then the attack requires the injected message to have its source BD_ADDR ``spoofed'' - again requiring custom hardware.
4. If the attack is successful, the Bluetooth user will need to enter the PIN again - so a suspicious user may realize that his Bluetooth device is under attack and refuse to enter the PIN.
5 Countermeasures
This section details the countermeasures one should consider when using a Bluetooth device. These countermeasures will reduce the probability of being subjected to both attacks and the vulnerability to these attacks.
1. Since Bluetooth is a wireless technology, it is very difficult to avoid Bluetooth signals from leaking outside the desired boundaries. Therefore, one should follow the recommendation in the Bluetooth standard and refrain from entering the PIN into the Bluetooth device for pairing as much as possible. This reduces the risk of an attacker eavesdropping on the pairing process and finding the PIN used.
Most Bluetooth devices save the link key (Kab) in non-volatile memory for future use. This way, when the same Bluetooth devices wish to communicate again, they use the stored link key. However, there is another mode of work, which requires entering the PIN into both devices every time they wish to communicate, even if they have already been paired before. This mode gives a false sense of security! Starting the pairing process every time increases the probability of an attacker eavesdropping on the messages transferred. We suggest not to use this mode of work.
2. Finally, the PIN length ranges from 8 to 128 bits. Most manufacturers use a 4 digit PIN and supply it with the device. Obviously, customers should demand the ability to use longer PINs.
3.Instead of passing messages in plain text, they should be encoded before transmission.
The Future of Bluetooth
The next version of Bluetooth, currently code named Lisbon, includes a number of features to increase security, usability and value of Bluetooth. The following features are defined:
- Atomic Encryption Change
- Extended Inquiry Response
- Sniff Subrating QoS Improvements
- Simple Pairing
Types of attacks in Bluetooth
The SNARF attack:
It is possible, on some makes of device, to connect to the device without alerting the owner of the target device of the request, and gain access to restricted portions of the stored data therein, including the entire phonebook (and any images or other data associated with the entries), calendar, realtime clock, business card, properties, change log, IMEI (International Mobile Equipment Identity [6], which uniquely identifies the phone to the mobile network, and is used in illegal phone 'cloning'). This is normally only possible if the device is in "discoverable" or "visible" mode, but there are tools available on the Internet that allow even this safety net to be bypassed.
The BACKDOOR attack:
The backdoor attack involves establishing a trust relationship through the "pairing" mechanism, but ensuring that it no longer appears in the target's register of paired devices. In this way, unless the owner is actually observing their device at the precise moment a connection is established. Device grants access to services. This means that not only can data be retrieved from the phone, but other services, such as modems or Internet, WAP and GPRS gateways may be accessed without the owner's knowledge or consent. Indications are that once the backdoor is installed, the above SNARF attack will function on devices that previously denied access, and without the restrictions of a plain SNARF attack, so we strongly suspect that the other services will prove to be available also.
The BLUEBUG attack:
The bluebug attack creates a serial profile connection to the device, thereby giving full access to the AT command set, which can then be exploited using standard off the shelf tools, such as PPP for networking and gnokii for messaging, contact management, diverts and initiating calls. With this facility, it is possible to use the phone to initiate calls to premium rate numbers, send sms messages, read sms messages, connect to data services such as the Internet, and even monitor conversations in the vicinity of the phone. This latter is done via a voice call over the GSM network, so the listening post can be anywhere in the world. Bluetooth access is only required for a few seconds in order to set up the call. Call forwarding diverts can be set up, allowing the owner's incoming calls to be intercepted, either to provide a channel for calls to more expensive destinations, or for identity theft by impersonation of the victim.
Scanning for Bluetooth addresses
The Bluetooth address itself is a unique 48bit device identifier, where the first 3 bytes of the address are assigned to a specific manufacturer by the IEEE (www.ieee.org/), and the last 3 bytes are freely allocated by the manufacturer. For example, the hexadecimal representation of a Sony Ericsson P900 phone's Bluetooth address may look like 00:0A:D9:EB:66:C7, where the first 3 bytes of this address (00:0A:D9) are registered to Sony Ericsson by the IEEE, meaning that all P900 phones will have their Bluetooth address starting with same 3 bytes. The last 3 bytes (EB:66:C7) of the sample address are assigned to this device by Sony Ericsson and should be different for each P900 phone -- but is not always, unfortunately.
In theory, enabling the non-discoverable mode on a Bluetooth device should protect users from unauthorized connections, yet in practice it is still quite possible to find these devices. There are software tools available which allow brute-force discovery of non-discoverable devices. An example of such an application is RedFang by Ollie Whitehouse, a small application which simply tries to connect to a unique Bluetooth address one by one, until finally a hidden device answers the request sent that was sent to that particular address. Author's initial test is a minimum of 6 seconds to achieve a good level of accuracy (it varies from 2.5 to 10 seconds, on average). It is certainly possible to find a hidden device in less than 3 seconds, The address space used by Sony Ericsson has 16,777,216 possible addresses. If we assume 6 seconds are required per device, the total scan would take us 1165 days, meaning we would need more than 3 years to discover all hidden Sony Ericsson phones in a conference room.
Conclusion:
With the advancement of digital convergence on M-commerce, usuage of bluetooth in connecting different devices is going to be significant. But to make communication more secure advancement in the prospect of security must not be neglected.
Monday, November 8, 2010
3G spectrum
3G Spectrum
When you read about radio spectrum this means a range of radio frequencies. The bandwidth of a radio signal is defined as being the difference between the upper and lower frequencies of the signal. For example, in the case of a voice signal having a minimum frequency of 300 hertz (Hz) and a maximum frequency of 3,300 Hz, the bandwidth is 3,000 Hz (3 KHz).The amount of bandwidth needed for 3G services could be as much as 15-20 MHz. Compare this with the bandwidth of 30-200 KHz used for current 2G communication and you can see that there is as much as a 500-fold increase in the amount of bandwidth required. Now you can appreciate why radio spectrum has become such a precious and scarce resource in the information age - everybody from television broadcasters to the military wants spectrum, and it is in short supply. Michael Powell, the chairman of the U.S. Federal Communications Commission (FCC), has suggested that spectrum demand "is going to forever outstrip supply". The telecoms operators have had to buy 3G spectrum from governments around the world, and those governments - realising that they own a precious, valuable resource - have sought to sell that spectrum at the highest possible price.
Radio spectrum is often organised (and sold) as paired spectrum - a bit of spectrum in a lower frequency band, and a bit of spectrum in an upper frequency band (see the section on 3G Technology for an explanation of paired spectrum). Paired spectrum is often specified in a form like "2x15MHz" meaning 15MHz in a lower band and 15MHz in an upper band. This technique of two users talking to each other on two separate frequencies is called Frequency Division Duplex, or FDD (see the section on 3G Technology for an explanation of FDD). W-CDMA is an FDD technique (i.e., it requires paired spectrum) whereas TD-CDMA is a TDD technique (i.e., it can use unpaired spectrum).
Europe
CDMA2000 1X is very flexible in its spectrum requirements being designed to operate on all existing allocated spectrum for wireless communications. Unfortunately, the same cannot be said for UMTS which is quite specific about its spectrum requirements (this has resulted in the recent European bidding wars for UMTS spectrum). It has been suggested that choosing the rigid spectrum requirement for UMTS was a political move, aimed at creating a new export engine for Europe. CDMA2000's spectrum flexibility is one reason why the operational 3G systems have so far used CDMA2000 1X (also because CDMA2000 systems are being implemented on existing CDMA (CDMAone) networks).UMTS specifies the bands 1900-2025 MHz and 2110-2200 MHz for 3G transmission. The satellite service uses the bands 1980-2010 MHz (uplink), and 2170-2200 MHz (downlink). This leaves the 1900-1980 MHz, 2010-2025 MHz, and 2110-2170 MHz bands for terrestrial UMTS (see the diagram below):
Diagram based on UK Official Licence Auction Site: Information Memorandum (3G Mobile Appendix)
As can be seen from the diagram, UMTS FDD is designed to operate in paired frequency bands, with uplink in the 1920-1980 MHz band, and downlink in the 2110-2170 MHz band. UMTS TDD is left with the unpaired frequency bands 1900-1920 MHz, and 2010-2025 MHz.
The UK Government auctioned five licences in these UMTS bands (for details, see the official UK licence auction site). After 150 rounds of bidding, the licences were sold for extraordinary sums (let's just say the "Buy-2-Get-1-Free" offer did not prove popular ...):
| Licence Name | Frequencies | Winner | Final Amount Bid |
|---|---|---|---|
| Licence A (reserved for a new entrant to the industry) | 2x15 MHz paired spectrum plus 5 MHz unpaired spectrum | Hutchison 3G | £4,384,700,000 |
| Licence B | 2x15 MHz paired spectrum | Vodafone | £5,964,000,000 |
| Licence C | 2x10 MHz paired spectrum plus 5 MHz unpaired spectrum | BT | £4,030,100,000 |
| Licence D | 2x10 MHz paired spectrum plus 5 MHz unpaired spectrum | One2One | £4,003,600,000 |
| Licence E | 2x10 MHz paired spectrum plus 5 MHz unpaired spectrum | Orange | £4,095,000,000 |
It is possible to show the position of these licences (A, B, C, D, and E) in the paired spectrum diagram (you can see that some licences were for 10 MHz and some licences were for 15 MHz):
Why did these licences go for so much money? One answer is that the auction was very cleverly structured. Read about Professor Ken Binmore and his game theory. Professor Binmore explains how Sotheby's mistakenly auctioned American satellite transponders in sequential fashion, as if they were selling paintings. As a result, the transponders went for wildly different prices. This is clearly not ideal if you want to raise the maximum total amount of money at your auction. By using many rounds of bidding, Professor Binmore's auction design ensured that the final winning bids were quite close in value - pulling in loadsamoney for the UK Government.
USA
As has just been explained, in Europe and Asia the choice of frequency band for implementing UMTS was clear. However, these frequency bands were not available in the U.S., so at the World Radio Conference (WRC-2000) in Instanbul, Turkey in May 2000, three frequency bands were suggested for implementing UMTS in the United States. The bands suggested were:- the 806-890 MHz band (now being used for cellular and other mobile services),
- the 1710-1885 MHz band (largely used by the U.S. Department of Defense),
- the 2500-2690 MHz band (used by commercial users for instructional TV and wireless data providers).
On March 30th, 2001, the FCC produced their final report into the possibility of using the 2500-2690 MHz band for 3G transmission (for more details, see the FCC 3G site). Basically, they thought that the TV industry was very heavily entrenched in this band and it would take between $10.2 billion and $30.4 billion to relocate the incumbent users.
The NTIA (National Communications and Information Administration) was given the task of evaluating the 1755-1850 MHz band for possible 3G transmission (for more details, see the NTIA 3G site). The NTIA reported that the U.S. Army and Navy have refused to move their communications to another frequency band. As a result of the September 11th attacks, there was considerable resistance to any further reduction in military spectrum.
A new plan, known as the "3G Viability Assessment", was proposed to consider the availability of the 1710-1770 MHz band, and the 2110-2170 MHz band. The result of that assessment is that 45MHz of space in the 1710-1755 MHz band and 45 Mhz of space in the 2110-2170 band is to be made available for 3G services.
3G standards
3G Standards
The dream of 3G is to unify the world's mobile computing devices through a single, worldwide radio transmission standard. Imagine being able to go anywhere in the world secure in the knowledge that your mobile phone is compatible with the local system, a scenario known as "global roaming". Unfortunately, the process of unifying the numerous international standards has proved to be extremely difficult. After difficult negotiation, a 3G "standard" called IMT-2000 emerged as a rather unsatisfactory compromise. IMT-2000, in fact, represents several incompatible standards lumped together under one banner. The hope of IMT-2000 is that phones using these different standards will be able to move seamlessly between all networks, thus providing global roaming.The rather fragmented nature of IMT-2000 has resulted in a proliferation of confusion acronyms (e.g., TDMA, UMTS, EDGE) often referred to as "alphabet soup". Possibly the most important acronym to remember is "UMTS": this is the 3G standard for Europe and Japan.
UMTS is the successor to the current ultra-successful GSM mobile phone standard in Europe. UMTS is being very heavily sold as the 3G standard (some sources use the terms "3G" and "UMTS" synonymously, though this is really not correct and just adds to the confusion).
The main global competitor to UMTS is CDMA2000, the 3G standard developed in the U.S. by Qualcomm. UMTS and CDMA2000 look set to battle it out for global supremacy. However, other less-publicised standards will not let those two have it all their own way. It is hoped that the following guide will act as a roadmap through the confusing subject of 3G standards. Let's start by stepping back a "G"...
2G Standards
The existing mobile phone market is referred to as the "second generation" of digital mobile communications, or "2G" (analogue mobile phones were "1G"). The European market is controlled by the Global System for Mobile communications (GSM) digital wireless standard. This uses TDMA as its radio transmission technology (RTT) (see the section on 3G Technology for a description of TDMA). GSM has proven to be the great success story of mobile standards as it has become the unifying standard in Europe - it is possible to use one phone throughout Western Europe. Because of the number of wireless users are in Europe this has greatly strengthened GSM's position as the basis for a potential global standard. The hegemony of GSM has resulted in Finland's Nokia and the UK's Vodafone becoming the powerhouses of the wireless economy.In North America the situation is not nearly so unified. The situation is divided three-ways between GSM, a TDMA-based system from AT&T Wireless (IS-136), and a CDMA system called CDMAone (IS-95A) from Sprint and Verizon. This confusion of standards has resulted in the reduced popularity of cellphones in the US. CDMAone has perhaps the strongest grip on the American market, as well as being popular in Asia.
2G data transmission rates do not exceed 9.6Kbps (kilobits per second). This is not nearly fast enough to achieve complex 3G functionality. So let's move on ...
2.5G Standards
The transition from 2G to 3G is technically extremely challenging (requiring the development of radically new transmission technologies), and highly expensive (requiring vast capital outlay on new infrastructure). For both of these reasons it makes sense to move to 3G via intermediate 2.5G standards.2.5G radio transmission technology is radically different from 2G technology because it uses packet switching (see the section on 3G Technology for an explanation of packet switching). GPRS (General Packet Radio Service) is the European 2.5G standard, the upgrade from GSM. GPRS overlays a packet-switched architecture onto the GSM circuit-switched architecture. It is a useful evolutionary step on the road to 3G because it gives telecoms operators experience of operating packet networks, and charging for packet data. Data transfer rates will reach 50Kbps.
EDGE (Enhanced Data for Global Evolution) is another 2.5G upgrade path from GSM. EDGE is attractive for American operators as it is possible to upgrade to EDGE from both TDMA (IS-136) networks as well as from GSM. You might see the full EGDE standard referred to as UWC-136.
EDGE data rates are three times faster than GPRS. Realistically, the maximum rate that EDGE will be able to achieve will be 150Kbps. Even so, EDGE might be used for some pseudo-3G networks (the minimum cut-off data rate for 3G systems is 144Kbps) though this is not generally regarded as a bona fide 3G solution.
As EDGE would be cheaper than a full-blown 3G solution, this makes it attractive, especially for operators which cannot afford a licence for the full 3G radio spectrum. Most notably, AT&T has announced it is to use EDGE. AT&T has claimed a maximum data rate of 384Kbps for EDGE, although experts point out that "this is based on the ideal scenario of one person using the network standing next to a base station"(!). AT&T's wireless division, after receiving a $9.8 billion stake from Japan's NTT DoCoMo i-mode service, plans to overlay the 3G standard, W-CDMA, onto their EDGE networks in the American market.
Deploying EDGE might prove surprisingly complex - it's more than just a software upgrade. It may require additions to the hardware subsystems of base stations, changes to base station antennas, and possibly require the construction of new base stations. For these reasons, some GSM operators might not adopt EDGE but might migrate from GSM or GPRS directly to the 3G standard (W-CDMA, considered later).
The 2.5G upgrade from CDMAone (IS-95A) is to CDMAone (IS-95B) which adds packet-switched capability. It offers data rates up to 115Kbps.
3G Standards
The 3G standard was created by the International Telecommunication Union (ITU) and is called IMT-2000. The aim of IMT-2000 is to harmonize worldwide 3G systems to provide global roaming. However, as was explained in the introduction to this section, harmonizing so many different standards proved extremely difficult. As a result, what we have been left with is five different standards grouped together under the IMT-2000 label:- W-CDMA
- CDMA2000
- TD-CDMA/TD-SCDMA
- DECT
- UWC-136
So that leaves W-CDMA, CDMA2000, and TD-SCDMA - the bona fide 3G solutions - which will now be covered in more detail:
Based on a presentation from the ITU.
W-CDMA The 3G standard that has been agreed for Europe and Japan (very important markets) is known as UMTS. UMTS is an upgrade from GSM via GPRS or EDGE. UMTS is the European vision of 3G, and has been sold as the successor to the ultra-successful GSM.
The terrestrial part of UMTS (i.e., non-satellite) is known as UTRA (UMTS Terrestrial Radio Access - don't you just love acronyms made from other acronyms!). The FDD component of UTRA is based on the W-CDMA standard (a.k.a. UTRA FDD). This offers very high (theoretical!) data rates up to 2Mbit/sec (the rumour is that the achievable rate is far lower: W-CDMA systems have been plagued with technical difficulties). The TDD component of UTRA is called TD-CDMA (or UTRA TDD) and will be considered later.
The standardisation work for UMTS is being carried-out under the supervision of the Third Generation Partnership Project (3GPP).
W-CDMA has recently been renamed 3GSM (to avoid confusion with CDMA2000).
Cingular Video In the USA, Cingular has launched a UMTS service called Cingular Video. Cingular Video is the only service to offer Fox News clips in addition to news broadcasts from CNN and NBC. Cingular Video will initially be available in the markets of Atlanta, Austin, Baltimore, Boston, Chicago, Dallas, Houston, Las Vegas, New York, Phoenix, Portland, Salt Lake City, San Diego, San Francisco, San Jose, Seattle, Tacoma and Washington, D.C. with additional areas expanding rapidly. For more details, see the Cingular 3G demonstration here.
FOMA NTT DoCoMo has gone live with 3G in Tokyo. Its service is called FOMA. This is the world's first IMT-2000 W-CDMA service (there are small but significant differences between the Japanese and European versions of W-CDMA - nothing is ever simple in 3G).
Since the launch of the service, coverage has been extended to almost 100% of the Japanese population, and the release of new terminals with higher level functionality continues to attract ever more subscribers - now exceeding 20 million users.
New phones in the FOMA lineup include the Sharp SH700i (shown below):
CDMA2000 The chief competitor to Europe's UMTS standard is San Diego-based Qualcomm's CDMA2000 (Qualcomm have done quite well out of CDMA - see here). The standardisation work for CDMA2000 is being carried-out under the supervision of the Third Generation Partnership Project 2, (3GPP2). The CDMA Development Group offers advice to 3GPP2.
Even though "W-CDMA" and "CDMA2000" both have "CDMA" in their names, they are completely different systems using different technologies. However, it is hoped that mobile devices using the two systems will be able to talk to each other.
CDMA2000 has two phases: phase one is 1XRTT (144 Kbps) (also known as 1X). The next evolutionary step is to the two CDMA2000 1X EV ("EV" = "Evolution") standards. CDMA2000 1X EV-DO ("Data Only") will use separate frequencies for data and voice. The following step is to CDMA2000 1X EV-DV ("Data and Voice") which will integrate voice and data on the same frequency band.
South Korea's SK Telecom launched the world's first 3G system in October 2000. Their system is based on CDMA2000 1X. They were followed by LG Telecom and KT Freetel (both Korean). Operational 3G systems based on CDMA2000 1X are now appearing around the world.
In the USA, Sprint has launched its nationwide CDMA2000 1X service called Sprint Power Vision. With Sprint PCS Vision Multimedia Services, customers get streaming audio and video content from familiar sources, including ABC News Now, NFL Network, Fox Sports, ESPN, NBC Discovery Channel, and many more. Sprint offer a range of multimedia phones including the Fusic:
Also in the USA, Verizon has launched its high-speed 1X EV-DO service featuring three phones including the Chocolate (shown below).
These phones are able to download content from the V CAST video service (see their great website). The on-demand clips offered currently are under four categories:
- News-NBC, CNN to go, NBC market watch
- Entertainment: V Cast Showcase, Just for laughs
- Sports: Fox Sports, ESPN
- Weather: AccuWeather.com Breaking news and Forecasts
TD-CDMA/TD-SCDMA The UMTS standard also contains another radio transmission standard which is rarely mentioned: TD-CDMA (a.k.a. TDD UTRA because it is the TDD component of UTRA). TD-CDMA was developed by Siemens. While W-CDMA is an FDD technology (requiring paired spectrum), TD-CDMA is a TDD technology and thus can use unpaired spectrum (see the section on 3G Technology for an explanation of TDD and FDD). TDD is well-suited to the transmission of internet data (see the section on symmetric transmission vs. asymmetric transmission for an explanation).
China has more mobile phone users than any other country in the world, so anything China does in 3G cannot be ignored. The Chinese national 3G standard is a TDD standard similar to TD-CDMA: TD-SCDMA. TD-SCDMA was developed by the China Academy of Telecommunications Technology (CATT) in collaboration with Siemens. TD-SCDMA eliminates the uplink/downlink interference which affects other TDD methods by applying "terminal synchonisation" techniques (the "S" in TD-SCDMA stands for "synchronisation"). Because of this, TD-SCDMA allows full network coverage over macro cells, micro cells, and pico cells. Hence, TD-SCDMA stands alongside W-CDMA and CDMA2000 as a fully-fledged 3G standard. The 3GPP have extended the TD-CDMA standard to include TD-SCDMA as an official IMT-2000 standard.
Unfortunately, TD-SCDMA has performed poorly in trials, and Chinese network operators may prefer W-CDMA over TD-SCDMA.
Based on a presentation from the ITU. In many ways, it's almost TOO simple ...
Subscribe to:
Posts (Atom)