Hi Neels,
On Thu, Mar 10, 2016 at 10:51:45PM +0100, Neels Hofmeyr wrote:
today I saw an MM Authentication Response sent from a 3G UE that mismatches the GSM 04.08 spec. The spec says 0x14, the 3G phone sent 0x94. And wireshark agrees that 0x94 is an Authentication Response.
Please see 11.2.3.2.1 and 11.2.3.2.2 of 3GPP TS 24.007, e.g. the latest version 12.0.0 Release 12 as available from http://www.etsi.org/deliver/etsi_ts/124000_124099/124007/12.00.00_60/ts_1240...
There you can see that in Release99 and later networks, the message type for MM, CC and SS is defined as having the upper two bits as "N (SD)", whereas other protocols have other definitions for those bits.
"N (SD)" is described in 11.2.3.2.3 of the same spec