Jamming LTE Signals: Rafał Krenz, Soumya Brahma
Abstract—In a majority of European countries a digital trunk- House on telecom and information policy, issued in 2012 a
ing TETRA system is used for Public Safety communication. Request For Comment on the Development of the Nationwide
This system offer voice communication and narrowband data Interoperable Public Safety Broadband Network. One of the
services only. Since the introduction of first LTE commercial
networks, LTE is rapidly gaining momentum within the Public responses was prepared by the wireless research group at
Safety industry as well. Therefore it is important to verify the Virginia Tech, led by Dr. Jeffrey H. Reed, who described the
immunity of the system, originally designed for civil applications, vulnerabilities of LTE system to intentional jamming attacks
to intentional jamming. In this paper some potential ways [4]. In fact the issue has been studied in many papers recently,
of attacks are discussed and an easy-to-implement method is however some of them use analytical approach only [5, 8, 9,
analyzed in details. The results suggest that jamming LTE signals
is relatively easy and can be done using low cost off-the-shelf 10, 11] while the others present results based on simulations
equipment. [6, 7]. This was a motivation to analyse the problem more
Index Terms—public safety communication, LTE, jamming deeply and the original experimental results of this study are
described in this work.
I. I NTRODUCTION In order to understand the possible methods of attacks, some
Public safety and security services require reliable and important aspects of LTE physical layer are desribed in Section
interoperable communication to respond effectively to an II. Section III identifies a few scenarios of efficient attacks that
emergency or natural disaster situations. In many European are designed to cause denial of service. Laboratory setup used
countries public safety communication is based on TETRA for the experiments is discussed in Section IV. The results of
trunking system. The standard has proven its usefulness for laboratory experiments are presented in Section V. Finally, the
many years, however, it offers primarily voice connections conclusions are drawn in Section VI.
and narrowband data services (max. 28.8 kbps) [1]. There are
situations where wideband data services would bring benefits,
e.g. to fire brigades checking floor plans of burning building A. Transmission in the downlink
or checking database of hazardous chemicals and ambulance Transmission in the LTE downlink is based on OFDM
teams transmitting an ECG trace from ambulance to doctor modulation and OFDMA multiplexing scheme. OFDM is well
in hospital or transmitting pictures from scene so doctors can known from its immunity to multipath fading, which is very
predict injury and make more accurate predictions. important property in mobile systems. Due to the serial-to-
Critical communications users such as Public Safety and parallel conversion, which extends symbol duration, the trans-
Security and Public Protection and Disaster Relief agencies mitted signal over a frequency-selective (i.e. multipath) chan-
are currently evaluating their own needs for future wireless nel is converted into a transmission over many parallel flat-
wideband services, with LTE and its future extensions emerg- fading channels in the frequency domain and the equalization
ing to be the favoured technology. So far, LTE networks have is much simpler than for single-carrier systems and consists
been implemented in many countries for commercial use but of just one complex multiplication per subcarrier. OFDMA
the technology must be adapted to provide services like push- adds the ability of adaptive user-to-subcarrier assignment,
to-talk, one-to-one and one-to-many group-based calls with based on feedback information about the frequency-selective
inherent fast call setup times as well as a range of other channel conditions from each user. Additionally, the downlink
features important to critical communications applications. resources may be easily partitioned to meet the bandwidth
Currently, such vendor-specific solutions are available on the requirements of each individual user.
market and a number of Public Safety LTE trials are already The LTE subcarrier spacing has been set to 15 kHz with
underway in regions like Middle East, Asia Pacific and Latin a cyclix prefix length of approximately 5 us. Subcarriers are
America [2], [3]. grouped in 180 kHz blocks, consisting of 12 subcarriers. In
But does the current LTE standard provide sufficiently the time domain 7 consecutive OFDM symbols (6 in case of
robust, resilient, secure and reliable services to meet the the extended cyclic prefix) are transmitted in 0.5 ms slot. Two
demanding needs of critical communications users? Having slots form a 1 ms subframe and 10 subframes constitutes a 10
in mind the terrorist attack threat, which has been increasing ms frame (Fig. 1 for FDD mode). All the symbols transmitted
in recent years all over the world, one can imagine an ’elec- in a single slot on all subcarriers in a block form a Resource
tronic attack’ on public safety communication infrastructure, Block, thus comprised of 84 (72) resource elements (Fig.
resulting in service disruption e.g. during a serious bomb 2). Within certain resource blocks, some resource elements
attack rescue operation. National Telecommunications and are reserved for special purposes: synchronization signals,
Information Administration (NTIA), which advises the White reference signals, control signalling and critical broadcast
system information. The remaining resource elements are used synchronization, but also provides the UE with the physical
for user data transmission. layer identity of the cell and the cyclic prefix length, and
The system was designed to allow operation in channels informs the UE whether the cell uses FDD or TDD mode.
with bandwidth varying from 1.4 MHz to 20 MHz. For The PSS is constructed from a frequency-domain Zadoff-Chu
different channel bandwidth the number of resource blocks sequence of length 63 (3 for each group of cells/sectors) and
available in a single slot varies from 6 (1.4 MHz channel) to the SSS is constructed by interleaving two lenght-31 maximum
110 (20 MHz channel). lenght sequences (M-sequences). Both synchronisation signals
are sent twice per frame (Fig. 3).