Showing posts with label evidence. Show all posts
Showing posts with label evidence. Show all posts

Sunday, October 06, 2013

(U)ICC/(U)SIM Script Commands and Responses

(U)ICC/(U)SIM 3F00 7F10 6F4A

3GPP UICC/USIM script selecting Master File, Dedicated File and Elementary File





















GSM ICC/SIM script selecting Master File, Dedicated File and Elementary File






























Reason for script test : defining an examination procedure to isolate and test a single elementary file; determine the EF's status, file structure, coding etc; conrroborate the ability of the (U)ICC/(U)SIM to action responses from commands sent to card; provide corroborating evidence of commands sent to the card to demonstrate evidential integrity (transparency of practices and procedures); testing the examination card reader is functioning correctly; QA procedures. 

Script examination tool used : USIM Commander - http://www.quantaq.com/usimcommander.htm

Relevant Core Diplomas:-

Aims : MTEB Diploma for Mobile Evidence QA and Evidence Handling - Mobile Telephone Diploma Core CQAE1

Objectives : Device Maintenance and Calibration; Examination Procedure

Aims :  MTEB Diploma for SIM and USIM Technology Examination - Mobile Telephone
Diploma Core CSUT2

Objectives : Your understanding of roles and responsibilities and the importance of
appropriate practices and procedures for SIM and USIM Technology
Examination for acquiring evidence.

Reference Standards :
GSM11.11/3GPP TS51.011/3GPP TS31.102,
GSM11.12,
GSM11.17/3GPP TS51.017/3GPP TS31.120/3GPP TS31.121/3GPP TS31.122,
GSM11.18/3GPP31.101,

EU MTEB Diploma Student Note : Remember to check with ETSI Standards e.g. TS102.221 etc

US MTEB Diploma Student Note : Diploma Students remember to check e.g. C.S0065-0 v1.0, C.S0074-0 v1.0, C.S0074-A v1.0, N.S0009-0 v1.0, S.R0095-0 v1.0 etc

Generically speaking, apart from GSMA and 3GPP, there is also 3GPP2 which also includes ARIB, CCSA, TIA TTA, TTC that all have conditions that can impact/influence results on (U)ICC/(U)SIM.

The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear here to assist Diploma students with their course work.

The latest MTEB Diploma Modules Guide MTEdipl 2.2 can be downloaded here:
https://dl.dropboxusercontent.com/u/84491783/MTEdipl%202.2.pdf


Saturday, September 28, 2013

MTEB Diploma CSUT2 Partner

 


Diploma for SIM and USIM Technology Examination
Mobile Telephone Diploma Core
Diploma:CSUT2


Partner Support
The Mobile Telephone Examination Board (MTEB) are pleased announce that Quantaq Solutions (http://www.quantaq.com/about.htm) have agreed to be the MTEB Diploma CSUT2 Partner. Quantaq Solutions role is as a "Partner Support". This role entails

- providing trial copies of software
- respond to technical enquiries that a student may require to make

to assist with the student's Diploma.

Moreover, Quantaq Solutions will host an MTEB webpage solely for use by MTEB Diploma Students so that students can have acess to the software and post questions to seek technical assistance.

Quantaq logoMTEB selected to work with Quantaq Solutions as a "Partner Support" because of their existing experience with (U)SIM/smart card examination tools, their range of independent, stand-alone tools to analyse (action commands/receive responses) on SIM/Smartcard and their highly regarded technical knowledge and experience in the fields of:

SIM, smartcards, NFC, RFID, M2M, location, DRM, security, cryptography, Mobile Wallet, technology, innovation, patents, technical design authority, standardisation, proof-of-concepts and software development

Gary Waite

Leading the "Partner Support" on behalf of Quantaq Solutions is Gary Waite. Gary is very well known in the mobile forensics arena for his work on the tools the (U)SIM forensic tools USIM Detective (USIM-D) and USIM Detective Professional (USIM-DP).

His experience and technical background further underpin his credentials of his expertise:
- Founder of Quantaq Solutions
- Past Vice Chair of the Smart Card Group GSM Association
- Test software supplier to Global Certification Forum (GCF) Field Trial Guidelines
- Authored the original ETSI GSM 11.17 standard. This standard formalised the core test processes and procedures for SIM Cards and remains at the heart of (U)SIM testing, programming and examination today.
- First to introduce recording in CUST File (EF) a particular handset's IMEI on SIM Card, which is important, evidentially
- Employed as Technology Manager for the last 11 years with a well know international Mobile Network Operator
- Skilled in C/C++/Java
- Holds a Degree from the University of Abertay Dundee - Electrical & Electronic Engineering, Electronic Engineering

Diploma:CSUT2
Free trial access to the following tools will be made available to Diploma Students. 

USIMdetective - http://www.quantaq.com/usimdetective.htm
USIMexplorer - http://www.quantaq.com/usimexplorer.htm
USIMexplorer - http://www.quantaq.com/usimcommander.htm
USIMprofiler - http://www.quantaq.com/usimprofiler.htm

Diploma for SIM and USIM Technology Examination
Mobile Telephone Diploma Core
Diploma:CSUT2


The latest MTEB Diploma Modules Guide is MTEdipl 2.2 can be downloaded here:
https://dl.dropboxusercontent.com/u/84491783/MTEdipl%202.2.pdf



Sunday, October 11, 2009

Extra-Statutory

Extra-Statutory
.
Where, for illustrative purposes only, a Home Office circular regulates e.g. the use of listening devices and aural and visual procedures, the standards set by that document may be the same as those under a Stature (say RIPA or, previously, IOCA) but that Home Office circular does not mean by following its guidance it makes any acts or omissions compliant with the statutory provisions; conduct arising from following the circulars regulation, and not the statute, could be "wholly extra-statutory" and would probably contravene the European Convention on Human Rights - see Malone v Metropolitan Police Commissioner [1979] Ch 344; cf Malone v United Kingdom (1984) 7 EHRR 14.
.
The above represents past history events and matters have or should have moved on since then. When RIPA was introduced it was made clear that "no" extra-statutory conduct or operations were possible arising out of that new legislation. That any acts outside of that may amount to contravention and be unlawful.
.
Having illustrated a simplistic model about "extra-statutory" activity by public authority and public bodies or their personnel to avoid giving advice, direction or guidance which would/could probably mean such acts may operate in parallel to the statutory provisions instead of being enshrined within them, the same principle of extra-statutory can apply across many other areas covered by other statutes, too.
.
Advice, direction and guidance given to facilitate the transmission of sensitive and/or unlawfuly material over public systems to aid extraction and harvesting of data from device/s might probably be "wholly extra-statutory" conduct or operations. That is even where it is a one-off case. Where advice is given to do acts which appear to go against previously stated authority in dealing with certain types of materials, the expert/examiner should record all dealings with those acts that have been instructed.
.
I picked up on this whilst reading books and papers dealing with judicial review of administrative action, Blackstones Criminal Practice, Archbold, telecommunications law and practice and the laws of the internet etc etc. I also noted that ACPO Guidelines and other provisions in public sector procurement documents appear not to cover any examiner/expert who enters into extra-statutory acts.
.
These are only my observations based upon what I read, which may assist other examiners/experts. I am not giving legal advice and I do hold out to be a lawyer. It could be from what I have read that my observations may be wrong and therefore it is always recommended to seek legal advice about instructions given or past instructions acted upon, under the belief those instructing were authorised to give such directions to do such acts in the first place.

Friday, May 15, 2009

Undercover Officer Down, how might SIM Access Control Class help? Part 1

PART 1: Undercover Officer Down, how might SIM Access Control Class help?
.
The following is a scenario created to help examiners and experts know more about how to determine what data in SIM/USIM elementary files can mean and to appreciate what is required to be understood before examining SIM/USIM and giving evidence. Computer forensics has made a significant contribution to data recovery that can be used for harvesting data from mobile telephones and SIM cards, however data recovery is only one element of mobile telephone evidence and is not ‘the evidence’ to be considered in isolation to everything else.
.
Moreover, an examiner and an expert are expected to usefully advise with respect to investigations where data obtained from mobile telephones and SIMs/USIMs are involved, so, here to, this scenario will hopefully open examiners' and experts' eyes to new ways of considering data. What the law of evidence wants to know is, provided the data recovered is not a problem, what does the data actually mean and how should it be interpreted.
.
Scenario
An undercover officer working has infiltrated a criminal organisation involved in drugs and people trafficking. The undercover officer needs to keep details and seek answers without blowing his cover. The situation is always life threatening. The officer is required to report back by mobile phone to Control every 7-14 days.
.
PC0001 on patrol in the Shopping Mall sees a known drug dealer in the doorway of a Supermarket with an unknown IC1 female handing over a package. PC0001 calls and waits for back up before approaching. A stop and search is then conducted using the appropriate procedures under PACE 1984. A quantity of drugs is found, large bundle of money, along with two mobile telephones which were all subsequently put into evidential containers and the two individuals are carted off in the wagon to the local nick.
.
The alleged crime of drug selling (given the quantity seized) is fairly low down the scale and the money found was £1,780.00, but compared with other crimes wasn’t high and so priority won’t be given to this case over other cases in the system. The mobile phones are sent away for examination. The person assigned to deal with the examination of the mobile telephone and SIM card conducts a quick level examination for subscriber details, mobile telephone number, SIM serial number/ICCID, phonebook and text messages. Before starting examining the mobile telephone the examiner becomes ill and doesn’t complete the work.
.
The examination would need to be passed to another examiner who would have to start from scratch as the next examiner could not possibly give evidence about someone else’s work for the new examiner would have no knowledge about the previous examination. By chance the new examiner chosen for the work had just come back from Greg Smith’s TrewMTE SIM Card training course where he had undergone deep level training into being a professional examiner and taught about ethical working practices, understanding the symbiotic relation with other mobile telephone devices and network elements, technical standards, working practices and SIM Card examination and data investigation etc (well alright, but it is only a modest promotion about me).
.
The new examiner conducted a fresh examination, starting with the SIM Card. Having been trained to look for evidence of activity and indicators about the potential user of the SIM card, the new examiner immediately contacted the Senior Officer where PC0001 was stationed. The new examiner, having been trained to identify certain data and corroborate the finding with reference material to ensure the meaning of the data, explained to the Senior Officer that he was examining a mobile telephone SIM Card that may belong to someone in the Security Services and that if he, at the local level, was examining this SIM then it could mean there was a man [undercover] down in the field?
.
Asked why the new examiner might suspect this, he referred to the recent training he had had and had identified from a mandatory data file in the SIM Card an elementary file titled EFACC (Access Control Class). The SIM had recorded Access Class 12 which is referenced as “Security Services”. The examiner also informed the Senior Officer that he had acquired from the SIM the subscriber details and mobile telephone number but was not authorised to access personal details. The examiner also mentioned that as ex-British Army he had field experience and should “intel” suggest there may be a “man down” that he would rely on all efforts to be made to rescue him, he therefore considered the user of the SIM (being examined) would equally rely on the same.
.
The Senior Officer took the details and immediately set in motion a priority search. The details the new examiner had given to the Senior Officer had proven correct and were linked to an officer on field ops. It transpired the office had not been in contact for 14 days. Because of the work involved MI5 were called in for their superior network of intelligence and, given the nature of the criminal organisation, every school boys heroes were sent in, the SAS, to conduct ground surveillance, attack, capture and rescue. The undercover officer was rescued, badly beaten, bleeding and barely alive, but alive nonetheless.
.
To clear up some loose ends to this scenario: How did the drug dealer come to be in possession of the undercover officer's mobile phone? The undercover officer had been rumbled by the gang and when running away, before the gang captured him, he had thrown it away and working on the long shot he hoped that someone would find it and hand it in. The drug dealer had found it, assumed it had been dropped by a passer-by and considered it could provide anonymity for drug dealing. There is a separate story about other evidence the mobile tied to the drug dealer, but this scenario is about saving an important life.
.
So what can be learned from the above scenario and what facts are known:
.
a) that the examiner as fact needs proper training to know what data can be significant
b) that as a statement of fact there is an elementary file in SIM called EFACC (Access Control Class)
c) that as a statement of fact the elementary file EFACC (Access Control Class) can be assigned to a User with an Access Class 12 assigned to “Security Services”
d) the examiner should know the limitations of the tools s/he works with before using them
e) the examiner to have the tools that actually reveal the information that is significant
f) that a proper and full examination of a SIM is an absolute requirement rather than merely the examiner conducting a dumbed-down check, only looking at certain data sets
g) that checking the findings immediately following a SIM read is essential
h) to communicate straightaway of the potential for life threatening situations or national security
i) that “priority” check means “speed and instantly” and not manyarna
.
In part 2 it will identify the full 16 Access Classes, look at Class 12 technical elements for Access Control Class, how it works, its uses and its limitations. What will become abundantly clear, if Part 1 and Part 2 are only dealing with Access Class 12 what can be learned about all the other Access Classes? More importantly, why has proper checking about Access Control Class and other EFs in SIM Cards not become standard practice?

Wednesday, November 29, 2006

Switch On, Update, Lose Evidence

Switch On, Update, Lose Evidence

The focus of this article relates to what can happen when switching on a mobile telephone and how data can change on a SIM Card. Essentially how a mobile telephone updates a SIM card relating to location data is down to how each make and model of mobile telephone has been programmed. When dealing with location data in SIM Cards it should not be assumed that every make/model updates location data immediately or within a prescribed period. Certain events trigger location update data and therefore it is important to determine on a case by case basis how a mobile telephone and its SIM card should be examined.

I have received several comments from different sources saying that they found location data was not updated when the mobile telephone was held within a shielded device or bag. This is fine, but it has been found that data can change in such environments and it is not the case that it was only a few times, but the fact that it happened at all can mean unilaterally ignoring that such an event (loss of data) might occur may mean losing vital evidence.

A best practise methodology has been outlined in the article for those that wish to follow it and the justification for using such a stated methodology.

http://www.filebucket.net/files/1579_ov3rx/Switch%20On%20Update%20Lose%20Evidence%20.pdf