Phase 1 — Mobility (M1–M6)
Phase 1 — Mobility (M1–M6) · the contained 5G proving ground
Goal: Build an evidence-driven 4G/5G security range that moves from software truth to controlled RF transmission inside a Faraday cage. Use
~/code/CodeCollector/mobility/labto create known conditions,~/code/CodeCollector/mobility/cellscopeto observe and score them, and owned UEs/SIMs to validate the complete subscriber → RAN → core → detection chain.Definition of done: six published articles; one reusable software + contained-RF lab; a calibrated public
cellscope-lite; an MBX-01–18 evidence matrix; one physical-AI experiment; and one accepted/delivered talk.
Why this phase is the moat
The differentiator is no longer only passive observation. It is the ability to produce a condition in a software twin, reproduce it over a contained air interface, observe the UE and network consequences, and prove the detector responds. That gives every claim a controlled cause → RF/signaling effect → observable evidence → detection chain.
Canonical basis
This roadmap binds the detailed material in Published/4_Threat Modeling/Mobility/ into a six-month build:
- 0. Methodology supplies the lab-first execution order, evidence model, and phase gates.
- Theory_Threat_Model supplies assets, STRIDE categories, trust zones, and access levels.
- Master_Blackbox_UE_to_Node_Test_Plan supplies traceable MBX-01–18 test cases.
- Phase1_Core_Simulation supplies the known-good Open5GS/UERANSIM baseline.
- Phase2_UE_Android_SIM supplies UE, SIM/eSIM, carrier-app, and privacy assessment.
- Phase3_RF_Air_Interface and Phase3_RRC_NAS_Signaling supply RF, identity, AKA, ciphering, and mobility evidence.
- Phase4_5G_Specific and Phase4_Core_Network_GTP extend into SBI, slice, GTP, PFCP, and interconnect trust.
The detailed threat-model set remains the procedure library. This document is the delivery sequence and does not duplicate every command or legacy test note.
System and trust-boundary model
owned UE + lab SIM
↕ Uu (contained RF)
LibreSDR + srsRAN/OAI gNB/eNB
↕ N2/N3 or S1
Open5GS control plane ↔ subscriber/auth data
↕ N4/N6
UPF + isolated data network
↕
CellScope + PCAP/log pipeline + Atlas evidence store
| Trust zone | Assets | Principal failure modes | Required evidence |
|---|---|---|---|
| Subscriber edge | owned UE, lab SIM/eSIM, carrier/test apps | identity exposure, unsafe local state, weak app trust, recovery ambiguity | device baseline, screenshots, app/OS logs, UE-visible state |
| Air interface / RAN | SDR, gNB/eNB, RF configuration, timing | false peer, downgrade/fallback, weak security mode, RF spill, unstable timing | I/Q metadata, decoded RRC/NAS, power/config manifest, outside-cage monitor |
| Core control plane | AMF/MME, AUSF/HSS/UDM/UDR, SMF, NRF | auth or service-identity weakness, policy tampering, poor rejection/logging | control-plane PCAP, NF logs, config diff, expected/observed verdict |
| Core user plane | UPF/SGW/PGW, GTP, DNS, isolated DN | misrouting, isolation failure, session loss, telemetry blind spot | user-plane PCAP, route/session records, latency and continuity results |
| Management / evidence | hosts, containers, IAM, clocks, CellScope, dataset | privilege concentration, time drift, evidence mutation, model error | inventory, hashes, time-sync status, model/parser version, analyst disposition |
Actors: lab operator, analyst, owned UE, lab network functions, detector/model, and safety observer. There are no production subscribers, carrier peers, roaming partners, or emergency-service dependencies inside scope.
Faraday-cage transmission policy
The cage permits controlled transmission; it does not make transmission automatically safe or authorized. The project includes owned LTE/5G cell waveforms and lab signaling after the following TX-enable gate passes.
TX-enable gate
Six-month delivery plan
| M | Build layer | Threat-model binding | Active lab capability | Primary non-LLM AI | Article |
|---|---|---|---|---|---|
| 1 | System truth | Methodology; MBX-09/10/11 | software-only 4G/5G registration and mode comparison | digital twin + statistical baseline | “Building a 5G security range with ground truth” |
| 2 | Subscriber edge | MBX-01/02/03/06/08 | owned UE/SIM/app workflows; no RF dependency | privacy-risk graph + active learning | “From Android and SIM to the 5G core” |
| 3 | Contained air interface | MBX-04/05/12/16 | TX gate, controlled cell attach, isolated data path | RF representation learning + adaptive sensing | “Commissioning a contained 5G cell safely” |
| 4 | Identity, fallback, and false cells ⭐ | MBX-07/13/15 | controlled 4G/5G identity, auth, ciphering, fallback scenarios | Bayesian evidence fusion + sequence/state models | “Scoring false base stations with measured ground truth” |
| 5 | Mobility and robustness | MBX-14/18; Phase 4A/4B subsets | handover/reselection and bounded negative-path procedures | causal experiments + grammar/coverage-guided test selection | “What breaks across RRC, NAS, and mobility transitions?” |
| 6 | Detection capstone | MBX-17 + all prior cases | repeatable attack/condition → detect replay suite | edge inference + cross-layer temporal graph | “The contained mobility Atlas: UE to core” + talk |
Learning exercises by month
Use Published/4_Threat Modeling/Mobility/ as the procedure library. Run the drills below in order; do not skip RF/TX work past the TX-enable gate.
| M | Primary drills (run these) | Procedure / criteria docs | Optional deepen |
|---|---|---|---|
| 0 | Frame one trust zone with the 5 state-change questions | 0. Methodology, Theory_Threat_Model, 00-index | — |
| 1 | MBX-09 → MBX-10 → MBX-11; TP-00 then TP-01 TC-REG-01 |
Phase1_Core_Simulation, TP-00_resources_and_setup, TP-01_registration_mobility, 17_test_plan_4g_5g_holistic | open5gs_lab/01–06 theory/lab builds |
| 2 | MBX-01 → MBX-03 → MBX-06 → MBX-02/08 | Phase2_UE_Android_SIM, MBX-02_08_App_Interception_Toolkit, 16_android_cell_analysis, Support_Hardware_Pixel9 | carrier-app tabletop only |
| 3 | Passive MBX-04/05; then MBX-12 + MBX-16 after TX gate | Phase3_RF_Air_Interface, Faraday TX-enable gate (this note) | conducted-cable before radiated |
| 4 | MBX-07 → MBX-13 → MBX-15 | Phase3_RRC_NAS_Signaling, TP-02_authentication, TP-08_stride_threat_emulation | clean vs exposed identity contrast |
| 5 | MBX-14 → MBX-18; then selected Phase 4A/4B checks | Phase4_5G_Specific, Phase4_Core_Network_GTP, TP-01_registration_mobility, TP-03_sbi_security, TP-04_gtp_userplane, 18_test_plan_mobility_site_to_core | site-to-core as tabletop if no operator access |
| 6 | MBX-17 replaying M1–M5 evidence chains | Master_Blackbox_UE_to_Node_Test_Plan, TP-10_monitoring_detection | 11–15 real-world case notes for context only |
Next if M1 baseline already exists: re-run MBX-09 cold once, then start M2 (MBX-01 → 03 → 06 → 02/08). Keep MBX-12+ parked until the TX-enable gate is real.
Technical, AI, and evidence plan
M1 — Software truth before RF
- Build: instrument Open5GS/UERANSIM for clean LTE and 5G SA registration, authentication, PDU/bearer creation, and cross-mode comparison. Define the Atlas mobility schema, scenario manifest, clocks, hashes, parser versions, and expected-versus-observed matrix.
- Threat focus: establish normal identity, auth, session, and rejection behavior before testing the UE or RAN. Exercise MBX-09, MBX-10, and MBX-11 and map the core control/user-plane trust boundaries.
- Exercises (learn by doing):
- Phase1_Core_Simulation — stand up
~/code/CodeCollector/mobility/lab(core-up/4g-up/5gsa-up), capture CP/UP or IQ tap, get CellScopeSOURCE=mobilitylabclean-baseline verdict. - Master_Blackbox_UE_to_Node_Test_Plan MBX-09 (5G SA registration), MBX-10 (4G attach), MBX-11 (cross-mode compare).
- TP-00_resources_and_setup → TP-01_registration_mobility TC-REG-01 (normal 5G-AKA registration).
- 17_test_plan_4g_5g_holistic — core-focused validation pass/fail record.
- Phase1_Core_Simulation — stand up
- AI: treat the lab as a digital twin. Build robust statistical baselines for registration time, NF event sequence, message counts, session setup, and CellScope score. Use causal intervention records—configuration change on/off, expected mechanism, observed effect—rather than unlabeled anomaly hunting.
- Gate: each clean condition has a reproducible command/run ID, PCAP/log evidence, known truth label, CellScope verdict, and stable result over repeated fresh starts. Learning done: you can narrate AMF/AUSF/UDM/UPF roles from your own capture without notes.
M2 — UE, SIM/eSIM, application, and privacy posture
- Build: baseline owned handset firmware/baseband/carrier configuration, SIM/eSIM-visible state, app permissions/trust, and approved application data paths. Separate the carrier-joined observation device from a clean lab UE; never move a production subscriber profile into the cage test role.
- Threat focus: exercise MBX-01, MBX-02, MBX-03, MBX-06, and MBX-08. Model identity exposure, app/API trust, local privilege, provisioning state, and subscriber-to-core evidence without treating one identifier/message as a complete privacy conclusion.
- Exercises (learn by doing):
- Phase2_UE_Android_SIM — owned UE/SIM assessment criteria.
- MBX-01 local baseline → MBX-03 SIM/eSIM posture → MBX-06 privacy/identity-exposure baseline.
- MBX-02 + MBX-08 with MBX-02_08_App_Interception_Toolkit (authorized owned device only).
- 16_android_cell_analysis + Support_Hardware_Pixel9 for handset/cell observation notes.
- AI: build a typed entity/privacy graph linking workflow → permission → identifier class → destination → retention. Use active learning to prioritize uncertain app/telemetry events for analyst labeling and Bayesian risk aggregation to carry uncertainty. Do not let a model infer subscriber identity from raw data.
- Gate: every observation is tied to an owned workflow and access level; sensitive identifiers are tokenized; publishable derivatives pass a re-identification review; software-lab truth explains the expected 4G/5G behavior. Learning done: one owned-UE baseline + SIM posture + one tokenized app/data-path trust note.
M3 — Cage commissioning and controlled cell
- Build: pass the TX-enable gate, integrate LibreSDR with the lab RAN, produce a repeatable owned-UE attach, establish the isolated user-plane/DNS path, and correlate RF/RRC/NAS/core evidence. Exercise MBX-12 and MBX-16 while retaining MBX-04 and MBX-05 passive measurements as the comparison baseline.
- Exercises (learn by doing):
- Complete the TX-enable gate checklist in this note (transmitter off dry-run first).
- Passive first: MBX-04 serving cell + MBX-05 neighbors (Pixel; no TX).
- After gate: MBX-12 controlled lab-cell attach + MBX-16 user-plane/DNS path.
- Phase3_RF_Air_Interface for RF evidence criteria and pass/fail.
- Physical AI: learn a state estimate for containment/link health from inside/outside power, SNR, frequency error, timing, decoder health, UE state, and core state. Run an adaptive measurement policy in shadow mode; after review, let it select only allowlisted receiver settings or request a bounded transmitter-setting change that the operator approves. Hard power/time/frequency constraints remain outside the model.
- Signal AI: compare engineered DSP features with self-supervised I/Q or spectrogram embeddings. Use domain randomization across attenuation, gain, channel condition, and receiver session, and test on a held-out cage configuration so the model does not memorize the bench.
- Gate: repeatable attach and data service; no outside-cage threshold violation; complete RF/config manifest; synchronized UE, RAN, core, CellScope, and safety-monitor evidence. Learning done: owned-UE attach in cage with full RF/config manifest and zero outside threshold violations.
M4 — Identity, authentication, fallback, and controlled false-cell conditions
- Build: reproduce clean 5G concealed identity, deliberately exposed lab identity, LTE fallback, expected AKA/security-mode behavior, and controlled cell-identity/configuration anomalies. Exercise MBX-07, MBX-13, and MBX-15 with owned profiles only. Treat “false base station” as a scored hypothesis, not an automatic label.
- Exercises (learn by doing):
- MBX-07 fallback path (passive/field-safe first) → MBX-13 controlled lab fallback → MBX-15 identity/auth/ciphering outcomes.
- Phase3_RRC_NAS_Signaling — identity, AKA, security-mode evidence.
- TP-02_authentication — auth procedure validation in lab.
- TP-08_stride_threat_emulation — bounded STRIDE scenarios against known-good baseline.
- AI: fuse protocol invariants with identity novelty, neighborhood inconsistency, downgrade/fallback state, RF/timing residuals, message ratios, and UE behavior using calibrated logistic/boosted or Bayesian models. Compare with HMM/change-point sequence baselines and require conformal uncertainty or an abstain outcome.
- Physical AI: the experiment controller may advance between signed clean/anomalous scenario states only when the safety supervisor confirms cage closed, monitor healthy, power ceiling intact, owned UE present, and prior state safely stopped. The model never selects arbitrary waveform parameters or identifiers.
- Purple gate: held-out devices/runs/configurations; precision/recall and PR-AUC; false alarms/hour; time-to-detect; calibration error; missing-sensor robustness; and a causal replay showing which intervention changed which evidence. Learning done: clean vs deliberately-exposed lab identity contrast; CellScope verdict matches ground truth.
M5 — Mobility procedures, protocol robustness, and 5G/core controls
- Build: execute controlled handover/reselection/tracking-area behavior and bounded failure/rejection cases; add selected slice/SBI/GTP/PFCP trust-boundary checks only after clean RRC/NAS behavior is understood. Exercise MBX-14 and MBX-18 and use the Phase 4A/4B documents as the deeper procedure library.
- Exercises (learn by doing):
- MBX-14 handover/reselection → MBX-18 bounded abnormal/failure handling (must recover to known-good).
- TP-01_registration_mobility mobility cases after clean registration is solid.
- Selected core trust-boundary drills: TP-03_sbi_security, TP-04_gtp_userplane; criteria in Phase4_5G_Specific and Phase4_Core_Network_GTP.
- 18_test_plan_mobility_site_to_core as tabletop/architecture review when operator access is absent.
- AI: use change-point detection and factor-graph/state-machine residuals across UE, RAN, core, and user-plane telemetry. Apply grammar- or coverage-guided test generation and Bayesian optimization only to choose among pre-approved negative cases; reward new state/coverage plus clean recovery, not crashes or maximum disruption.
- Causal AI: randomize one bounded variable at a time where possible—handover trigger, attenuation profile, permitted config, or network impairment—and estimate effect on interruption time, auth state, detector delay, and recovery. Preserve confounders and failed hypotheses.
- Gate: no silent corruption or uncontrolled persistent state; every negative case returns to known-good; expected rejection/logging is visible; safety-envelope violations remain zero. Learning done: one measured mobility event + one negative case with clean recovery and visible rejection/logging.
M6 — Cross-layer detection and public capstone
- Build: complete MBX-17 by replaying representative M1–M5 scenarios and reconstructing each from UE symptom through RF/RRC/NAS, core control/user plane, CellScope finding, and analyst disposition. Package sanitized parsers, schemas, scorer, fixtures, CLI/API, minimal dashboard, SBOM, signed artifacts, threat model, and runbook.
- Exercises (learn by doing):
- MBX-17 — correlate UE symptom ↔ RAN/signaling ↔ core CP/UP ↔ CellScope ↔ disposition for representative M1–M5 runs.
- TP-10_monitoring_detection — detection/visibility checklist against your evidence store.
- Replay suite: pick one clean + one anomalous labeled scenario from each prior month; require same event counts within tolerance on a clean machine.
- Context only (not primary drills):
open5gs_lab/11–15real-world case notes for control mapping language.
- AI: deploy cascade inference—cheap protocol/DSP rules, compact quantized model, then offline correlation. Use a temporal/knowledge graph for evidence linking and failure localization. An optional LLM may explain cited events, but it is neither decoder, classifier, controller, nor ground truth.
- Physical-AI capstone: demonstrate one contained closed loop: observe lab state → estimate condition → recommend/choose an allowlisted next scenario or measurement → safety supervisor approves → execute → verify stop/recovery. Compare it with a fixed scripted policy and report safety interventions.
- Release gate: clean-machine software replay; fresh cage run under the TX policy; zero containment/safety violations; model/data cards; CPU/memory/latency results; public/private artifact review; no secrets, live subscriber data, unsafe defaults, or runnable active-RF configuration in the public package. Learning done: one full purple chain is reproducible from run ID to published-safe article evidence.
Measurement contract
| Dimension | Required metric |
|---|---|
| Containment | inside/outside baseline and TX sweep, run threshold, excursions, emergency-stop time |
| RF/link | configured power/gain, attenuation, SNR, frequency/timing error, dropped samples, link stability |
| Protocol | parser field accuracy, procedure success/rejection, message mix, security-mode outcome |
| Detection | precision, recall, PR-AUC, false alarms/hour, detection delay, calibration/abstention |
| Robustness | held-out UE/run/cage configuration, missing-sensor performance, recovery to known-good |
| Physical AI | policy value versus fixed baseline, safety-supervisor interventions, constraint violations |
| Reproducibility | clean-start success rate, event-count tolerance, versions, hashes, run-manifest completeness |
Public/private artifact boundary
Public: schemas, sanitized fixtures, synthetic I/Q where appropriate, parsers, detector logic, model/data cards, results, containment methodology, failure cases, and replay tooling.
Restricted lab evidence: raw UE/SIM identifiers, keys, cage-specific RF configuration, detailed active waveform profiles, full captures containing subscriber material, device secrets, and any setting that could be mistaken for a live-network recipe. Public articles explain controls and outcomes without turning the range into an uncontrolled deployment guide.
Deliverables
De-risk and cut line
Week 1: prove CodeCollector/mobility/lab → CellScope → evidence-store replay for one clean 5G registration before locking the calendar. Before M3: pass the TX-enable gate in a dry run with the transmitter off, then with the lowest-power validation waveform.
If schedule pressure appears, preserve the software truth baseline, cage containment controls, one controlled attach, one identity/fallback contrast, MBX-17 correlation, and reproducible release. Defer deep models, automated scenario selection, extra protocols, and elaborate UI work before reducing safety or evidence quality.