Demo Environment
Technical Architecture
Three-layer, privacy-by-design pipeline
Passive acquisition, anonymizing processing, and analytics — identifiers never persist beyond the processing edge.
Layer 1
Data Acquisition (Passive Probes)
- SS7 (MAP) — 2G/3G signalling capture
- Diameter (S6a, S13) — 4G LTE signalling capture
- HTTP/2 (5G N12, N8) — 5G SA service-based interfaces
- GTP-C (S11, S5) — mobility and session management
- All probes feed parsed events into Kafka message bus
- Non-intrusive: passive optical taps or mirrored ports
Core Network
Optical Taps / Mirrored Ports
Passive Probes
Kafka Message Bus
Layer 2
Processing & Anonymization Engine
- Real-time stream processing (Apache Flink or similar)
- IMSI/MSISDN hashing and immediate discard — no persistent PII storage
- Aggregation engine: groups by home country (MCC+MNC), region, time window
- Statistical anomaly detection (surge/drop vs rolling baselines)
- Cell plan database integration for region mapping
- Configurable aggregation windows: 1-hour, 24-hour, 7-day, 30-day
Kafka Stream
Hash & Discard PII
Aggregate by Dimension
Anomaly Detection
Statistics Store
Layer 3
Analytics & Visualization
- Real-time heatmap dashboard (regional roamer density)
- Time-series charts (hourly/daily/weekly trends)
- Country-of-origin breakdown (top-N home countries)
- Anomaly alert feed (statistical outliers only — no individual targeting)
- REST API for government system integration
- Exportable reports (CSV, PDF, JSON)
Statistics Store
Analytics Services
Dashboards / API
Exports & Integration