2. Disclaimer
I'm not an expert,
I'm a hacker.
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
3. I'm hacking WiMAX.
You should too.
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
4. Mobile WiMAX
●
Standardized by WiMAX Forum
●
Air interface - a profile of IEEE 802.16-
2009 OFDMA mode.
●
IEEE 802.16 — http://goo.gl/SUpqE
●
WiMAX profies — http://goo.gl/k1xjK
●
Deployed release 1.5.
●
Core network - IETF protocols
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
5. Mobile WiMAX vs LTE
Mobile WiMAX
● developed by Internet Providers community
● «evolution of WiFi»
● appeared first
LTE
● developed by telecom community
● based on WiMAX ideas
● but with other patents
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
6. Orthogonal frequency-division
multiplexing (OFDM)
Refer to "Intuitive Guide to Principles of Communications"
Tutorial 22 - Orthogonal Frequency Division Multiplex (OFDM, DMT):
http://www.complextoreal.com/chapters/ofdm2.
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
7. OFDMA (frequency)
combined
user 1
user 2
user 3
user 4
frequency
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
8. OFDMA (time and frequency)
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
9. TDD and FDD
Frequency Division Time Division
Duplexing (FDD) Duplexing (FDD)
default
DL DL DL UL DL UL
frequency
UL UL
radio radio radio radio
frame frame frame frame
time
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
13. Mobile WiMAX
●
Many bands, mostly 2 GHz — 5 GHz
●
Scalable bandwidth: 1.5 MHz — 20 MHz
●
Usually TDD
●
Supports various MIMO and beam-forming
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
14. LTE differences
●
Uplink uses SC-FDMA for power efficiency
●
Power efficient synchronization
●
More dynamic parameters at PHY level
●
Hierarchical telecom-like protocol
For details: http://goo.gl/HAAgm
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
15. wimax-scanner
●
Mobile WiMAX receiver
●
LGPL
●
Matlab code for broadcast decoding
●
Wireshark for MAC layer decoding
http://code.google.com/p/wimax-scanner
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
16. wimax-scanner ToDo
●
Port to C(++)
●
Improve algorithms in Matlab
●
More WiMAX recordings
●
More WiMAX recordings in MIMO mode
●
Transmitter side
http://code.google.com/p/wimax-scanner
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com
17. Other open-source 3G&4G
UMTS and LTE implementations in GPL
http://www.openairinterface.org
●
Closed style development
●
Targets academia
●
Hackers should engage
Alexander Chemeris @chemeris Alexander.Chemeris@gmail.com