Demo Environment
Technical Architecture

Three-layer, privacy-by-design pipeline

Passive acquisition, anonymizing processing, and analytics — identifiers never persist beyond the processing edge.

Layer 1

Data Acquisition (Passive Probes)

  • SS7 (MAP) — 2G/3G signalling capture
  • Diameter (S6a, S13) — 4G LTE signalling capture
  • HTTP/2 (5G N12, N8) — 5G SA service-based interfaces
  • GTP-C (S11, S5) — mobility and session management
  • All probes feed parsed events into Kafka message bus
  • Non-intrusive: passive optical taps or mirrored ports
Core Network
Optical Taps / Mirrored Ports
Passive Probes
Kafka Message Bus
Layer 2

Processing & Anonymization Engine

  • Real-time stream processing (Apache Flink or similar)
  • IMSI/MSISDN hashing and immediate discard — no persistent PII storage
  • Aggregation engine: groups by home country (MCC+MNC), region, time window
  • Statistical anomaly detection (surge/drop vs rolling baselines)
  • Cell plan database integration for region mapping
  • Configurable aggregation windows: 1-hour, 24-hour, 7-day, 30-day
Kafka Stream
Hash & Discard PII
Aggregate by Dimension
Anomaly Detection
Statistics Store
Layer 3

Analytics & Visualization

  • Real-time heatmap dashboard (regional roamer density)
  • Time-series charts (hourly/daily/weekly trends)
  • Country-of-origin breakdown (top-N home countries)
  • Anomaly alert feed (statistical outliers only — no individual targeting)
  • REST API for government system integration
  • Exportable reports (CSV, PDF, JSON)
Statistics Store
Analytics Services
Dashboards / API
Exports & Integration