Report Jammer
Report Jammer
Report Jammer
Abstract
The purpose of this project is to design, implement, and test a cellular phone radio
frequency (RF) jamming system. This system consists of a noise signal generator
circuit, a series of low noise amplifiers (LNAs) to amplify the signal, two VCO's
and mixers to modulate the signal to the 900MHz and 1800MHz cellular phone
frequencies, and two antennas to transmit the jamming signal at the two considered
frequency bands.
The implemented design was able to jam both 2G and 3G signals inside our
department's building with a distance of 2-3 meters from the antenna to the jammed
mobile device.
2
1 Introduction
Radio jamming devices are circuits that transmit noise at a certain frequency in
order to prevent radio frequency communication at that frequency, or degrade the
signal to cause a delay in transmission.
Armies all over the world have been using electronics in hopes of gaining
superiority over the enemy, and ever since electronics were used, attempts were
made to make these electronics less effective. One of those attempts led to the
creation of radio jammers: in World War II, the British used to jam German radio
communications [1],[2],[3].
Cellular phone jammers are devices that prevent signals coming from base stations
from reaching cellular phones. The need for cellular phone jammers rose as a result
of the increasing disruptions cellular phones introduced to everyday life. In our
community, we mostly need cellular phone jammers in mosques and schools [4].
The cellular phone jammer mainly consists of a noise generator, one or more
frequency up-conversion stages, an RF amplification stage, and an antenna to
transmit the noise signal. In most countries, it is illegal to own and operate a
cellular phone jammer [4].
the downlink signal is expected to be much lower than that of the uplink one.
Accordingly, the jammer will be designed to operate at the frequencies used for the
downlink in both the 900MHz and the 1800MHz frequency bands.
2 Methodology
infinite spectral density as shown in Figure 1 below, where is the power spectral
density of the white noise. The name White comes from the fact that white light
contains equal amounts of all frequencies within the visible band of
electromagnetic radiation [5]. White noise has infinite average power and infinite
bandwidth, which makes it a purely theoretical construction that cannot be
physically realized. However, some circuits can give an output signal that contains
approximately equal power within a certain bandwidth.
Sw (f)
In order to jam the cellular phone network, a sufficient amount of noise, 20dBm
or higher, has to lie in the frequency range of the cellular phones i.e. 900 MHz and
1800 MHz bands. Therefore, a noise signal has to be generated, amplified and up-
converted to the required bands. The details of the power level of the noise signal
after each stage will be discussed in detail in section 3.2.
Practically, the white noise generator will synthesize a wideband signal having
almost a 100 MHz bandwidth, as will be explained later. Connecting the noise
generator to the cascade of two high gain amplifiers, results in a baseband signal
with a sufficient amount of power to result in the required power level at the
jammer output. The mixer will up-convert the signal to 900MHz. This signal will
then be sent to two paths using a two-branch splitter. One part of the signal will be
further amplified before being transmitted to jam the cellular signal in the 900MHz
frequency band. The other part of the signal will be up-converted to the 1800MHz
frequency band after being amplified by two radio frequency amplifiers. This part
of the signal will be transmitted by the antenna designed to operate in the
1800MHz frequency band. The block diagram of the designed radio frequency
jamming system is shown in Figure 2.
5
This section will discuss the design of the noise circuit, the RF front end and the
antennas.
A lowcan
A low cost circuit costbecircuit can be implemented
implemented using Zener using
diode Zener
[1], asdiode
shown[6],
in as shown
Figure 3. in Figure 3.
+14 V
12 V Zener 470 pF
diode
30
Very low power noise can be generated by the Zener diode when a high voltage,
that exceeds the breakdown voltage of the diode, is applied to the cathode side
which makes the diode operate in the reversed-biased region. The noise results
from the random fluctuation of the current across the zener diode which is under
breakdown voltage. This noise signal will be input to the RF front end and
processed for transmission in the considered frequency bands.
The various components used to build the RF front-end of the jammer are listed
below:
+5V for the DC supply. As for the tuning, by changing the tuning voltage
between 0V and 28V, the output frequency will change. This voltage
controlled oscillator can draw a maximum of 35mA.
High frequency amplifier (ZFL-1000LN+): This amplifier can be used after
the first mixer in the design. It has a wide bandwidth from 0.1 to 1000MHz.
It amplifies the signal by approximately 20dB. It requires DC biasing of any
value in the range of 12 to 16V. As the value of the DC biasing increases, the
gain will increase. The gain can reach up to 23.6dB.
Splitter (ZFSC-2-2500+): The splitter has a very wideband characteristic as it
can handle signals ranging anywhere from 10 to 2500MHz. It has an
insertion loss of only 3dB. Its only limitation is that the signal power input
should not exceed 1W (30dBm). However, this is not an issue in our design
since the power levels are not expected to reach 30dBm anywhere in the RF
front-end.
3.3 Antennas
exact value of each dimension [2]. For this project, two patch printed antennas
operating at the frequencies 900 MHz and 1800 MHz will be used These antennas
are shown in Figure 4.
Table 1: 900 MHz and 1800 MHz path antennas parameters [7]
Both antennas were simulated on ADS[6], the results of the simulation are shown in
table (III)
BW: bandwidth
4 Results
There are three sets of results that are included in this paper. The first set is related
to the simulation of the circuit using the ADS software. The second set of results
presents the measurements performed using the circuit prototype implemented
using the hardware components and its measured output using the spectrum
analyzer. Finally, the ability of the designed system to jam phone calls and data
transmission is demonstrated.
The schematic used to simulate the jamming system in ADS software is shown in
Figure 6. The simulation is built using models based on the measurements of the
components. The output at v1 represents the output of the noise signal circuit
cascaded with the two amplifiers. The power of the signal at this stage is 40dBm.
The mixer will modulate the baseband signal to be centered at 900MHz. The local
11
The results obtained at the output of the schematic shown in Figure 6 are reported
in Figure 7. These correspond to the spectra, in dBm, of the jamming signals that
will be sent in each of the two frequency bands.
The results shown in Figure 7 represent the final output of the circuit using the
ADS software. This frequency spectrum illustrates that the center frequency of the
output will be 900MHz and 1800MHz, respectively. Since the power level of the
downlink signal in the vicinity of the cellular phone is unlikely to exceed 20dBm,
according to previous measurements performed within our department's building,
this will be enough to reduce the signal to noise ratio of the received signal
sufficiently; resulting in jamming the cellular phone bands. For the sake of
simplicity, a sinusoidal input was used in the ADS design instead of the noise
circuit. The purpose of designing the circuit in ADS is to study the amplification
and modulation process and the power levels throughout the system.
This section will show the results measured using the prototyped jammer. All of
these results were obtained using the spectrum analyzer. For a clearer display of the
plots, the data from the spectrum analyzer was transferred first to a PC using
'Engauge' software and then plotted using MATLAB software.
The output spectrum is shown in Figure 8. The center frequency of the signal is
around 100MHz, and the bandwidth is about 20 to 25MHz. This is less than the
expected value due to the simplicity of the circuit used to generate noise. The
maximum power of the signal achieved at this stage is 34dBm. The reason for
which the output before the two amplifiers was not displayed is that it was too low,
in terms of power, that the available spectrum analyzer could not distinguish
between the signal and the noise floor. The signal observed at 400MHz is due to
some interference and it is not intentionally generated by the jamming circuit.
Though, this is not a problem since the main objective of the designed system is to
transmitted unwanted signals that do not have any information content.
13
Figure 8: Output of the noise circuit and the two subsequent amplifiers
The output spectrum after the first mixer, centered at around 900 MHz, is shown in
Figure 9. Due to the +7dB power gain obtained from the up-conversion process, the
maximum output power level is now 26dBm.
14
The output spectrum of the signal after connecting the first mixer with two
amplifiers is shown in Figure 10. The center frequency is the same as the stage
before. However, the power has significantly increased to about +11dBm.
Figure 10: Spectrum of the amplified signal after the first mixer
15
Using another mixer, with a local oscillator signal centered at 900MHz, will result
in modulating the signal to 1800MHz as shown in Figure 11. The spectrum
analyzer showed that the power of the signal at 1800MHz is 15dBm. Thus, the
noise signal generated at this frequency band has sufficient power to prevent
communication from being established and maintained in this band.
phones, one can measure the signal that is being received from the base station to
the mobile phone. When this measurement was done, an increase in the level of the
received signal was noticed before the signal gets completely jammed. An
explanation for that behavior is that when the base station senses that the signal to
noise ratio is very low, it automatically increases the power level of the signal that
is being sent. But, after a couple of seconds the base station cannot increase the
power level further to dominate the level of noise which causes the signal to
disappear eventually.
the 900MHz and 1800MHz concurrently when both antennas are connected. In this
figure, jamming the 900MHz can be identified from the word searching and
jamming the 1800MHz used for data can be identified by the disappearance of the
3G sign that should appear when the 3G service is activated.
The designed system was simulated using harmonic balance analysis in ADS. This
was done to confirm that the design gives the right output at the antenna's input.
Once the system architecture was chosen based on satisfactory simulation results,
the hardware implementation was carried out. The prototype was intially test to
ensure its proper operation. Then the system ability to jam signals in the 900MHz
and the 1800MHz was tested. The jammer prototype was able to completely jam
both bands for all network providers (STC, Mobily, and Zain) inside our
department's building. For the 900MHz band, a noise with +8dBm and a bandwidth
of around 25 MHz was enough to cover the spectrum at 900MHz. The 1800MHz
signal was jammed with 15dBm noise signal with the same bandwidth.
Although the design in this project does not have a commercial advantage
compared to other jammers available in the market, it has the advantage of being
able to cover any frequency. Also, the fact that it is illegal to import jammers into
this country makes it worthwhile to build one from off-the-shelf components. This
knowledge can also be valuable for defense applications.
Although this project achieved its objective (jam the downlink connection), it is
important to note that this also involves blocking emergency calls. The system can
be improved by enabling emergency calls to pass through. France is finalizing a
technology that would let such calls pass through [8].
19
6 References