Observing my cellphone switch towers
fabiensanglard.net
fabiensanglard.net
- Badly configured basebands (for example lack of summer/winter time change flag!)
- Broken PTP
- Stations that take time from NTP which does not exist or does not have route to.
- I don't know the name for it, but getting time from local Nodeb is an feature - and sometimes features are not active or licensed[1].
- Station setup with GPS instead PTP/NTP (let's say for 2G or some slower HDSPA modes) with broken GPS module itself
- Software error [basebands have multiple versions of software, same goes for APG's, SCU'S, RRU's and dozen other black boxes. Even cabinet itself have some software. This is big pain in the ass to keep them all updated in large network - as upgrade process can be disruptive and sometimes it is better to not upgrade [cases of some really wacky stations]...
- Problem with software in terms of PTP implemetation. For example there are some discrepancies between Huawei and Ericsson software when it comes to PTP.
[1]. This is big shocker for Open Source Software community:
- EVERY SINGLE FEATURE in base station is not only NOT free, but Telecoms needs to pay them every single month[all manufactures: Nokia, Ericsson, HUA do that]. We are talking here in about 100-200 licenses for various features per site alone. If you don't buy new license every 28 days - your base station will turn off and it's nothing you can do.
- Hardware provider can also refuse to give you new licenses in theory...
- This is real hell of SaS world that NO ONE is talking about.
The problem i had is, that the time in my case was in the future, so when i called someone (personA) from within that cell, the call was made sometime in 2025... this wouldn't bother me in general, but when you use the redial function in your headset (double tap on the button), the phone would call the last dialed number (which means max(timestamp), not the actual last call), and instead of ringing the last person dialed (eg. personB), it would redial the personA I called from the affected cell, and after misdialing them by accident, a couple of times, I had to manual remove that call from the calllog, to get the redial to work again... until I entered that cell again and called someone from there again.
Eventually somebody figured out that he wasn’t going away, and a couple of very pleasant guys popped in and dropped off their business cards. They told him it wouldn’t be a problem anymore and to give them a call if it became a problem again.
End of the day, if someone is creating interference, they need to stop. If you have the time and inclination, complain and they will.
Since it took me a minute to parse: the guy on the team, not the university police, was the one who walked the hierarchy?
> End of the day, if someone is creating interference, they need to stop.
I'm not sure which way to interpret this, your username might check out after all.
During the summer Utah is on daylight savings time, Arizona does NOT observe daylight savings time but the Navajo Nation within Arizona DOES observe daylight savings time.
Antelope Canyon is on Navajo Nation land and requires a tour guide from a licensed tour guide company. The canyon and tour guides DO observe daylight savings time.
The canyon is only about 5 miles from the Utah border and many people are traveling from Utah. Because of all the competing cell phone towers you end up with people that show up at the wrong time.
I purposely brought an old school watch for my trip.
edit: it is West Wendover NV
They probably want to stay on Mountain time because 99% of their visitors/customers are from Salt Lake City on mountain time and their TV stations are also probably from Salt Lake City
Since then, I've not trusted that automatic network time adjustment, and I leave it disabled. Periodically, I check if it's drifted too much, and if it has, I quickly enable and then disable the network time adjustment (in a place far from the misconfigured tower).
But not if it is a stingray as that's not managed by the network.
This was when SMS were still widely used, so that made for very messed up chats since received messages carried the correct timestamp
I have worked on an IoT device with builtin SIM in the personal alarm space. Often when a device is indoors no GPS fix can be found, but the GSM module can report all celltower ids in range with signal strengths. These can be used to triangulate the device location. Google has an API for this where you can pass celtower ids and signal strengths.
edit: and of course similar triangulation fallbacks/methods can be applied to WiFi AP's or Bluetooth Beacons, if you have a database with APs or beacons and their location. This database can be externally sourced but also built automatically by sending celltower ids/aps/beacons along with GPS fixes. I assume this is one of the many things Google is doing with their fleet of Streetview cars.
~~Passive location requests are, as you say, when an app wants location updates, but doesn't care when and how often - when one makes an active request, all the passive listeners get called.
Passive location sources are methods of getting your location with the data already available - so WiFi if it's on and cellular if the modem is on.~~
...and Google services-enabled Android smartphones.
Source: I have used a single access points in many locations across the country in a relatively short period of time. When there's no GPS fix, Google always thinks I'm where I just was. (And there are no Streetview cars in some of these locations.)
It should have been able to figure out that this was nonsense based on the unfeasible speed of travel, or from the fact that the area covered by the cell I was in did not contain the WiFi location, or probably from other WiFi networks in the area that hadn't moved.
In my case I don't even need the gps coords, the cellid is enough, as my devices travel on fixed lines through various countries. For cars or buses you would need it though.
Are there any resources to that project? Comercial or free?
It only had 2G which is already retired in some countries and I don’t know if they’re doing an 3/4/5G refresh.
A fun space to work in though. A space where a small bit of tech can save lives and where tracking is actually helpful.
Edit: but stressful as well. As bugs in the code or platform can lead to people in distress not getting the help they need.
”There are no open source LTE stack to learn from”
That is not true, srsRAN is a opensource LTE project.
That has both cell phone and tower versions. Runs on SDR boards like the limeSDR.Most people are blissfully unaware of how much radio chatter and constant adjustment is actually holding up their browsing session from second to second, with the UE negotiating the best possible terms (power, throughput, etc.) with adjacent cell towers before it decides (or is prompted) to hand-over to a new cell.
Optimizing cell hand-over and adjacency matrices is something that operators need to do quite frequently as traffic patterns and network topology change and a computationally neat problem that can be scaled horizontally (I once optimized one such job to run in 4 hours instead of 24).
Anyway, I wish there was something like Wireshark to which I could connect a phone and see it talk to the cell towers in real time. This would really help understand how this all works.
The ability to switch to a different tower papers over all sorts of moment-to-moment connectivity issues.
My experience in my networking class in college and how complex even a TCP/IP connection is over a reliable wired connection was enough to make me run screaming from the field as a profession.
The fact that I can get 200/mbit on my phone today still astounds me.
It's an interesting, but even to me an intimidating field.
Or maybe it's simply https://en.wikipedia.org/wiki/Mobile_cell_sites
I'm pretty sure gps location is derived from signals from GPS satellites and ground stations. You can see this if you're somewhere with no cell signal but have gps, or visa versa.
Also worth calling out ShareTechnote which is basically the personal notebook of a (brilliantly prolific) telecom engineer (now at Apple): https://www.sharetechnote.com/. It's incredibly comprehensive and well linked -- a much easier reference than paging through hundreds of pages of PDFs.
Can someone shed some light on this?
I worked in 5G mmWave on the UE side so can imagine some of the scheduling complexity. However for a basic mmW stack, like one to be implemented by OAI or srsRAN would likely scale the problem down to something more basic
I could see srsRAN making a lowband (<6 GHz) impl of 5G, but not the crazily complicated high freqs. At least without some crazy funding.
I always have put my phone in air plane mode when i was in a train due to the modem consuming a lot more energy.
I always assumed and still doe its due switching towers and less connecitivy which means using more power.
Whenever people argue that public transport doesn't need wifi i would argue against it due to power usage and also for more accessablity of the internet in general.
[0] Phones
[1] The system which sits immediately behind cell towers and coordinates handoffs
[2] Tower
The cool solution would be base stations built into train carriages that then uplink through some kind of backhaul.
I think (but need to properly evaluate) that some Australian trains use something like this. EDIT: Nooope nope nope, horribly misread. https://goughlui.com/2014/03/23/random-post-railcorp-gsm-r-r...
As the essay notes, it's through TelephonyManager on Android. On iOS it used to be possible through CoreTelephony private APIs, but I think Apple cracked down on these a few years back and either removed them entirely or locked them down behind entitlements, as they were getting abused by analytics frameworks.
For example "Signal strength" APK. It's just matter of time until you will find one with logging and export ability. You can always write it down with pencil :)
What I don't get is why the author didn't draw the signal strength of all towers that were visible. This info is also trivially available.
What public transport needs are microcells, and to hell with wifi.
I don’t remember the details but it has to do with selecting which cell tower is the best and how strong the cell phone needs to boost the signal are two different steps. Or at least used to be 10 years ago.
> According to the LTE specs, cell-towers don't have to perform UE hand-overs like in GSM/UMTS. The phone starts camping on the next tower while remaining in RCC_IDLE mode without emitting data. Not only does this save battery, it also means operators don't really know where the phone is as long as it remains in the same LAC.
And another tip: I wanted to know what "very expensive" means for LTE-related literature, so I searched DuckDuckGo for the first book mentioned (sold on Amazon for $105) and the second result was an OCR'd PDF at huaweicup.ru
The engineering me needs to place antennas optimally! Even though burying the phone in a pit and it still works it still irks me and I want to see it in an optimal placement where it is minimally shielded. Why don't car manufacturers have a place for the phone in the roof or something so that it gets optimal antenna placement? Yes it would be unseemly but wouldn't we get much better reception?
It's an easy way to extend the phone antenna to the whole vehicle.
Don’t you answer your own question? It would be unseemly. Phones still get signal and consumers aren’t demanding an option for optimal antenna placement. If they did install them, would consumers even notice battery savings when most people charge their phones in the car anyway? So for car manufacturers, it seems like all downsides.
Examples:
The Nokia 3310 is from the end of 2000 but 2G mobile phones were already in everybody's hands by then, at least here in Italy. The boom started in 1997. I resisted until 1999, then my boss gave one to me because "I don't want to call [another guy with a mobile] to talk with you" :-) It was the Nokia 8110 (Neo's phone in The Matrix.)
3G/UMTS was launched in Europe in 2003, much before the first 3G capable iPhone (2008). The marketing word in 2003 for UMTS was UMTS. The first device was the NEC 606 [1], from the 3 mobile operator (Italy, UK and a number of other countries.) There were a number of popular 3G phones in the 5 years before the iPhone 3G.
By the way, the NEC 6060 did video calls too. The screen was low resolution (not by the standards of the time) and the price was outrageous (4 times the voice calls?) Not a very popular feature and yet it was there.
[1] https://www.mobileindustryreview.com/2015/04/classic-handset...
http://www.architectureofradio.com
The iOS application:
https://apps.apple.com/us/app/architecture-of-radio/id103516...
Worth to mention that there are 3 types of handovers:
- Intra-relations: user can be switched between various cells at same tower.
- Intra-relations but with handover to lower technology (let's say when 4g is not available[too much traffic], so you will be dropped to let's say 3g or even 2g cell)
- External-relations: relations between cells on different towers.
As for towers:
- Not all operators allows for local roaming between various operators.
- Most towers have 3-5 sectors (pizza slices), but it's not that unusual to see OMNI antennas(single sector for 360 degrees).
I can also highly recommend the book "High Performance Browser Networking" by Ilya Grigorik referenced by this post. Although it's almost 8 years old most of is still very relevant. Although it would be wonderful if he would update it to reflect changes in TLS and 5G.
I also really liked the layout and fonts on this person's site. It has an almost 'zine aesthetic. Very easy on the eyes. Does anyone know what they might be using to produce this?
shudder
What does this mean? Whats the diff between tower and cell?
The first graphic visualizes this. Recption of the same cell is indicated by the same color there, while towers are at the points that these colored cones radiate from. Several cones of different colors start at the same points, visualizing that there are towers that are providing more than one cell. Observe that the reception can jump back and forth between the same cells as can be seen on the brown and blue colored cells in the top left corner of the graphic.
>- Several cellIDs map to the same eNB lat/long coordinates. That's because the antennas mounted on an eNB don't have 360° coverage. The angle and range of each antenna carves the space into pizza slice shaped cells.
a tower is just a mast on which radios are mounted. a site is the location of the equipment. a node is the name for a set of radios and base systems. a nodes service can be divided in to sectors. a cell is usually a certain coverage area served, the frequency of cells will differ a bit from it's neighbor to stop interface. and a beam is specific focused radio that serves one UE.
The tower is what it sounds like, it is one physical structure containing the communications equipment, also called a Base Transceiver Station (BTS) [1]. The cell is the individual communications panel on the tower, also known as a CellID [2]. There are typically 3 panels on a tower, each covering 1/3rd of the surrounding area. So the tower gives you the physical location, and the cell gives you the general direction.
Anybody knows of such an app?
Despite not being real-time, it's the best / most accurate app I've found of its kind and has a good community behind it.
Given known EMI patterns along the path of propagation of course.
Great developers know why things work.
- Steve Souders, High Performance Browser Networking Forewords"
https://help.ui.com/hc/en-us/articles/115004662107-UniFi-Fas...