Phase 1 — Mobility (M1–M6)

Phase 1 — Mobility (M1–M6) · the contained 5G proving ground

Goal: Build an evidence-driven 4G/5G security range that moves from software truth to controlled RF transmission inside a Faraday cage. Use ~/code/CodeCollector/mobility/lab to create known conditions, ~/code/CodeCollector/mobility/cellscope to observe and score them, and owned UEs/SIMs to validate the complete subscriber → RAN → core → detection chain.

Definition of done: six published articles; one reusable software + contained-RF lab; a calibrated public cellscope-lite; an MBX-01–18 evidence matrix; one physical-AI experiment; and one accepted/delivered talk.

Why this phase is the moat

The differentiator is no longer only passive observation. It is the ability to produce a condition in a software twin, reproduce it over a contained air interface, observe the UE and network consequences, and prove the detector responds. That gives every claim a controlled cause → RF/signaling effect → observable evidence → detection chain.

Canonical basis

This roadmap binds the detailed material in Published/4_Threat Modeling/Mobility/ into a six-month build:

The detailed threat-model set remains the procedure library. This document is the delivery sequence and does not duplicate every command or legacy test note.

System and trust-boundary model

owned UE + lab SIM
        ↕ Uu (contained RF)
LibreSDR + srsRAN/OAI gNB/eNB
        ↕ N2/N3 or S1
Open5GS control plane ↔ subscriber/auth data
        ↕ N4/N6
UPF + isolated data network
        ↕
CellScope + PCAP/log pipeline + Atlas evidence store
Trust zone Assets Principal failure modes Required evidence
Subscriber edge owned UE, lab SIM/eSIM, carrier/test apps identity exposure, unsafe local state, weak app trust, recovery ambiguity device baseline, screenshots, app/OS logs, UE-visible state
Air interface / RAN SDR, gNB/eNB, RF configuration, timing false peer, downgrade/fallback, weak security mode, RF spill, unstable timing I/Q metadata, decoded RRC/NAS, power/config manifest, outside-cage monitor
Core control plane AMF/MME, AUSF/HSS/UDM/UDR, SMF, NRF auth or service-identity weakness, policy tampering, poor rejection/logging control-plane PCAP, NF logs, config diff, expected/observed verdict
Core user plane UPF/SGW/PGW, GTP, DNS, isolated DN misrouting, isolation failure, session loss, telemetry blind spot user-plane PCAP, route/session records, latency and continuity results
Management / evidence hosts, containers, IAM, clocks, CellScope, dataset privilege concentration, time drift, evidence mutation, model error inventory, hashes, time-sync status, model/parser version, analyst disposition

Actors: lab operator, analyst, owned UE, lab network functions, detector/model, and safety observer. There are no production subscribers, carrier peers, roaming partners, or emergency-service dependencies inside scope.

Faraday-cage transmission policy

The cage permits controlled transmission; it does not make transmission automatically safe or authorized. The project includes owned LTE/5G cell waveforms and lab signaling after the following TX-enable gate passes.

TX-enable gate

Six-month delivery plan

M Build layer Threat-model binding Active lab capability Primary non-LLM AI Article
1 System truth Methodology; MBX-09/10/11 software-only 4G/5G registration and mode comparison digital twin + statistical baseline “Building a 5G security range with ground truth”
2 Subscriber edge MBX-01/02/03/06/08 owned UE/SIM/app workflows; no RF dependency privacy-risk graph + active learning “From Android and SIM to the 5G core”
3 Contained air interface MBX-04/05/12/16 TX gate, controlled cell attach, isolated data path RF representation learning + adaptive sensing “Commissioning a contained 5G cell safely”
4 Identity, fallback, and false cells MBX-07/13/15 controlled 4G/5G identity, auth, ciphering, fallback scenarios Bayesian evidence fusion + sequence/state models “Scoring false base stations with measured ground truth”
5 Mobility and robustness MBX-14/18; Phase 4A/4B subsets handover/reselection and bounded negative-path procedures causal experiments + grammar/coverage-guided test selection “What breaks across RRC, NAS, and mobility transitions?”
6 Detection capstone MBX-17 + all prior cases repeatable attack/condition → detect replay suite edge inference + cross-layer temporal graph “The contained mobility Atlas: UE to core” + talk

Learning exercises by month

Use Published/4_Threat Modeling/Mobility/ as the procedure library. Run the drills below in order; do not skip RF/TX work past the TX-enable gate.

M Primary drills (run these) Procedure / criteria docs Optional deepen
0 Frame one trust zone with the 5 state-change questions 0. Methodology, Theory_Threat_Model, 00-index
1 MBX-09 → MBX-10 → MBX-11; TP-00 then TP-01 TC-REG-01 Phase1_Core_Simulation, TP-00_resources_and_setup, TP-01_registration_mobility, 17_test_plan_4g_5g_holistic open5gs_lab/0106 theory/lab builds
2 MBX-01 → MBX-03 → MBX-06 → MBX-02/08 Phase2_UE_Android_SIM, MBX-02_08_App_Interception_Toolkit, 16_android_cell_analysis, Support_Hardware_Pixel9 carrier-app tabletop only
3 Passive MBX-04/05; then MBX-12 + MBX-16 after TX gate Phase3_RF_Air_Interface, Faraday TX-enable gate (this note) conducted-cable before radiated
4 MBX-07 → MBX-13 → MBX-15 Phase3_RRC_NAS_Signaling, TP-02_authentication, TP-08_stride_threat_emulation clean vs exposed identity contrast
5 MBX-14 → MBX-18; then selected Phase 4A/4B checks Phase4_5G_Specific, Phase4_Core_Network_GTP, TP-01_registration_mobility, TP-03_sbi_security, TP-04_gtp_userplane, 18_test_plan_mobility_site_to_core site-to-core as tabletop if no operator access
6 MBX-17 replaying M1–M5 evidence chains Master_Blackbox_UE_to_Node_Test_Plan, TP-10_monitoring_detection 1115 real-world case notes for context only

Next if M1 baseline already exists: re-run MBX-09 cold once, then start M2 (MBX-01 → 03 → 06 → 02/08). Keep MBX-12+ parked until the TX-enable gate is real.

Technical, AI, and evidence plan

M1 — Software truth before RF

M2 — UE, SIM/eSIM, application, and privacy posture

M3 — Cage commissioning and controlled cell

M4 — Identity, authentication, fallback, and controlled false-cell conditions

M5 — Mobility procedures, protocol robustness, and 5G/core controls

M6 — Cross-layer detection and public capstone

Measurement contract

Dimension Required metric
Containment inside/outside baseline and TX sweep, run threshold, excursions, emergency-stop time
RF/link configured power/gain, attenuation, SNR, frequency/timing error, dropped samples, link stability
Protocol parser field accuracy, procedure success/rejection, message mix, security-mode outcome
Detection precision, recall, PR-AUC, false alarms/hour, detection delay, calibration/abstention
Robustness held-out UE/run/cage configuration, missing-sensor performance, recovery to known-good
Physical AI policy value versus fixed baseline, safety-supervisor interventions, constraint violations
Reproducibility clean-start success rate, event-count tolerance, versions, hashes, run-manifest completeness

Public/private artifact boundary

Public: schemas, sanitized fixtures, synthetic I/Q where appropriate, parsers, detector logic, model/data cards, results, containment methodology, failure cases, and replay tooling.

Restricted lab evidence: raw UE/SIM identifiers, keys, cage-specific RF configuration, detailed active waveform profiles, full captures containing subscriber material, device secrets, and any setting that could be mistaken for a live-network recipe. Public articles explain controls and outcomes without turning the range into an uncontrolled deployment guide.

Deliverables

De-risk and cut line

Week 1: prove CodeCollector/mobility/lab → CellScope → evidence-store replay for one clean 5G registration before locking the calendar. Before M3: pass the TX-enable gate in a dry run with the transmitter off, then with the lowest-power validation waveform.

If schedule pressure appears, preserve the software truth baseline, cage containment controls, one controlled attach, one identity/fallback contrast, MBX-17 correlation, and reproducible release. Defer deep models, automated scenario selection, extra protocols, and elaborate UI work before reducing safety or evidence quality.