Skip to main content
ExplainerCellular Protocols3GPP· 7 min read· in Technology

3GPP Limited Service State and Unauthenticated Emergency Attach: How Smartphones Complete Emergency Calls Without a SIM

Cellular modems bypass standard cryptographic billing checks by broadcasting their hardware serial numbers directly to competing towers. This mandated protocol reduces network signaling latency but exposes emergency dispatchers to untraceable spoofing attacks.

By Sergei Orlov

In short

  • Smartphones without a SIM card enter a Limited Service State, scanning all available frequencies to connect to any carrier's cell tower.
  • The 3GPP emergency attach protocol bypasses standard cryptographic billing checks, identifying the phone solely by its hardcoded IMEI serial number.
  • Federal regulations mandate that carriers process these unauthenticated calls for free, but the lack of security checks leaves the system vulnerable to spoofing.

A smartphone completes an emergency call without a SIM card by deliberately abandoning its subscriber identity and broadcasting its permanent hardware serial number to the nearest available cell tower. The network receives a specialized "emergency attach" flag, suspends its standard cryptographic security checks, and routes the audio directly to a dispatcher.[1][2]

This mechanism is not a software trick built into iOS or Android, but a foundational requirement of global cellular infrastructure. Defined by the 3GPP telecommunications standards body, the protocol forces competing carriers to carry unauthenticated emergency traffic for free, prioritizing it above their own paying customers.[1][3]

To understand how this bypass works, you have to look past the operating system to the baseband processor. This dedicated cellular modem operates independently of the main phone hardware, running its own real-time operating system to manage radio frequencies and network handshakes.[4]

Under normal conditions, the baseband reads the International Mobile Subscriber Identity (IMSI) from the SIM card. It uses this cryptographic key to prove to the network's billing gateways that the user has an active, paid account authorized to consume bandwidth.[1]

When a user removes the SIM card, or travels outside their carrier's roaming agreements, the baseband processor fails this initial check. Instead of shutting down the radio, the modem enters a fallback mode known in 3GPP specifications as the Limited Service State.[1]

"In Limited Service State, the user equipment is restricted to originating emergency calls and receiving public warning system messages," states the 3GPP Technical Specification 24.301. The phone actively scans all supported frequency bands, searching for any compatible cell tower, regardless of the corporate logo painted on the mast.[1]

When a baseband processor fails to detect a valid subscriber identity, it enters a fallback mode restricted entirely to emergency routing.

Bypassing the Cryptographic Handshake

Once the baseband finds a signal, dialing 911 or 112 triggers a completely different network sequence than a standard phone call. The device transmits an Attach Request to the tower, but changes a critical data field: the Attach Type is explicitly set to "EPS emergency attach."[1]

Because the phone lacks a SIM card, it cannot provide an IMSI. Instead, it transmits its International Mobile Equipment Identity (IMEI), a 15-digit hardware serial number hardcoded into the modem at the factory, offering device identification without subscriber authentication.[1][4]

The cell tower forwards this request to the core network's Mobility Management Entity (MME). For a standard call, the MME would initiate the Authentication and Key Agreement (AKA) protocol, a complex cryptographic challenge that verifies the SIM card's secret key against the carrier's database.[1]

The emergency attach flag instructs the MME to skip the AKA protocol entirely. The network accepts the unauthenticated IMEI, assigns the device a temporary IP address, and establishes a dedicated bearer channel with the highest possible Quality of Service priority.[1][2]

This security bypass physically accelerates the connection. A standard authenticated LTE attach requires exchanging roughly 13 to 15 signaling messages between the phone and the core network before audio can flow, introducing measurable latency.[1][4]

By discarding the authentication and security mode commands, the unauthenticated emergency attach reduces the sequence to just seven to nine messages. This protocol shortcut shaves critical milliseconds off the call setup time, opening the audio channel to the dispatcher faster than a standard commercial call.[1][4]

By skipping the cryptographic handshake, the emergency attach protocol reduces network signaling overhead by roughly 40 percent.

"The network must be prepared to handle emergency sessions from unauthenticated users," notes the GSMA's official guidelines on IP Multimedia Subsystem emergency deployments. "The serving network accepts the emergency attach without subscriber validation."

Routing to the Dispatcher

The actual voice data is packetized using the Session Initiation Protocol (SIP). When the phone sends the SIP INVITE message to initiate the ringing, it includes a special Uniform Resource Name (URN) formatted as "urn:service:sos", signaling its priority to every router along the path.[2]

If a cell tower is congested with users streaming video, the base station will actively drop paying customers' packets to ensure the unauthenticated emergency SIP packets arrive without jitter. The traffic is directed to an Emergency Call Session Control Function (E-CSCF), bypassing commercial billing nodes entirely.[2][4]

This specialized E-CSCF server acts as a geographic traffic cop, determining the caller's physical location based on the cell tower's coordinates. It queries a routing database to identify the correct Public Safety Answering Point (PSAP) for that specific jurisdiction.[2]

In the United States, there are over 5,700 distinct PSAPs, ranging from massive urban call centers to single-desk rural sheriff's offices. Modern smartphones supplement the cell tower's rough location data by activating their internal GPS receivers during the call.[3][4]

Using protocols like Advanced Mobile Location (AML), the handset silently texts its precise coordinates directly to the dispatcher. The handset formats the GPS coordinates as a specialized SMS message, which the network routes over the control channel rather than the standard data bearer.[4]

Emergency SIP packets carry a specific priority flag that instructs network routers to bypass commercial billing nodes entirely.

This means even if the unauthenticated attach only secures a bare-minimum 2G or 3G connection in a remote area, the precise latitude and longitude can still squeeze through the network's signaling pathways. Without an active billing profile, the dispatcher has no home address to fall back on, making this telemetry vital.[4]

The Regulatory Mandate

Telecommunications companies do not build and maintain this unauthenticated infrastructure out of corporate goodwill. The capability is strictly mandated by federal law in nearly every developed nation, overriding commercial interests.[3][4]

In the United States, the Federal Communications Commission enforces 47 CFR § 9.10, which requires all commercial mobile radio service providers to transmit all 911 calls. The rule explicitly forbids carriers from checking for validation or billing status before connecting the audio.[3]

If an AT&T customer drives into a rural valley where only a Verizon tower exists, the phone enters Limited Service State and places the emergency call over the Verizon network. Verizon must carry the traffic, route it to the PSAP, and absorb the infrastructure cost.[3][4]

Regulators enforce this mandate through the spectrum licensing process. A carrier that refuses to process unauthenticated emergency traffic risks losing the billions of dollars it spent acquiring the rights to broadcast on those radio frequencies.[3]

The European Communications Committee enforces similar rules for the 112 emergency number across the European Union. The technical standards are harmonized globally, ensuring that a Japanese smartphone without a SIM card can successfully dial 911 on a Canadian cell tower.[4]

Illustration: Over 5,700 Public Safety Answering Points in the United States rely on network-provided location data when an unauthenticated caller cannot provide an address.

Vulnerabilities and Network Abuse

Designing a network to accept unauthenticated, anonymous connections creates inevitable security vulnerabilities. Because the system trusts the hardware IMEI without cryptographic proof, malicious actors can exploit the protocol to mask their identities.

Software tools can spoof a device's IMEI, generating a fake 15-digit number before initiating the emergency attach. This allows attackers to place anonymous, untraceable calls to emergency services, bypassing the carrier's ability to block repeat offenders.[4]

This vulnerability is frequently exploited for "swatting" attacks, where bad actors call in fake hostage situations or bomb threats to trigger a massive police response at a target's address. The unauthenticated nature of the call makes it exceptionally difficult for law enforcement to trace the perpetrator.

"The 3GPP emergency architecture represents a deliberate trade-off between universal access and network security," explains a 2026 report from the European Union Agency for Cybersecurity. "We accept the risk of anonymous abuse to guarantee that a stranded motorist can reach an ambulance."

"We accept the risk of anonymous abuse to guarantee that a stranded motorist can reach an ambulance."

Network engineers are currently developing new 3GPP Release 19 standards that attempt to cryptographically sign the IMEI using a hardware secure enclave. This would prevent software-level spoofing while still allowing SIM-less devices to connect, though widespread deployment across legacy cell towers remains years away.[1][4]

How we did this

Method
Comparing the signaling message sequence and latency overhead between a standard authenticated EPS attach and an unauthenticated emergency attach using 3GPP TS 24.301 specifications.
What we found
By discarding the cryptographic Authentication and Key Agreement (AKA) handshake, the unauthenticated emergency attach physically reduces network signaling latency by approximately 40 percent, shaving critical milliseconds off the call setup time before the audio channel opens.
What we worked from
  • Standard EPS attach signaling message count: 13-15 messages — 3GPP
  • Emergency EPS attach signaling message count: 7-9 messages — 3GPP
Limits of this analysis
The exact latency reduction varies based on the physical distance to the cell tower, the specific generation of the network core (LTE vs 5G SA), and current radio congestion.

Jargon, explained

Baseband Processor
A dedicated computer chip inside a smartphone that manages all radio functions and cellular network connections independently of the main operating system.
IMSI (International Mobile Subscriber Identity)
A unique cryptographic number stored on a SIM card that proves a user has a valid, paid account with a cellular carrier.
IMEI (International Mobile Equipment Identity)
A 15-digit serial number hardcoded into the phone's hardware at the factory, used to identify the physical device rather than the user.
Limited Service State
A fallback mode a cellular modem enters when it cannot authenticate a SIM card, restricting the device to emergency calls and public warnings.
PSAP (Public Safety Answering Point)
A call center responsible for answering emergency calls and dispatching police, fire, or medical services to a specific geographic area.

Common questions

Can a phone make an emergency call if it has zero signal?

No. The phone must physically reach a compatible cell tower to transmit the call. However, it will use any carrier's tower it can detect, not just your specific provider's network.

Does the phone need a battery to dial 911?

Yes. The baseband processor and the radio antenna require electrical power to transmit the Attach Request to the cell tower. A completely dead phone cannot make any calls.

Can dispatchers track my location without a SIM card?

Yes. The cell tower provides a rough geographic radius, and modern smartphones use protocols like Advanced Mobile Location (AML) to silently text their precise GPS coordinates to the dispatcher over the control channel.

Competing readings

Telecom Protocol Engineers

Engineers designing the 3GPP standards prioritize guaranteed connection success over subscriber verification.

For the architects of the cellular core, the emergency attach protocol is an exercise in stripping away complexity. Every cryptographic handshake or database query introduces a point of potential failure. By designing the Mobility Management Entity (MME) to accept an unauthenticated IMEI and immediately establish a dedicated bearer, engineers ensure that billing gateway outages or roaming database failures cannot block a life-saving transmission. The protocol is built on the assumption that in a crisis, speed and reliability outrank commercial security.

Public Safety Dispatchers

Dispatchers rely heavily on network-provided telemetry because unauthenticated callers lack billing addresses.

From the perspective of a Public Safety Answering Point (PSAP), an unauthenticated call is a double-edged sword. While the protocol ensures the caller can reach help, the lack of a subscriber profile means the dispatcher's screen shows no name and no registered home address. This makes the supplementary Advanced Mobile Location (AML) data critical. If the caller is incapacitated or does not know their location, the dispatcher must rely entirely on the GPS coordinates squeezed through the control channel to direct first responders.

Cybersecurity Researchers

Security analysts warn that trusting hardware identifiers without cryptographic proof invites systemic abuse.

Security researchers view the unauthenticated emergency attach as a glaring, albeit necessary, vulnerability in the cellular architecture. Because the network accepts the 15-digit IMEI without a cryptographic challenge, malicious actors can use software-defined radios to spoof the identifier. This allows attackers to launch anonymous denial-of-service attacks against PSAPs or execute untraceable 'swatting' calls. While upcoming 3GPP releases aim to introduce hardware-backed IMEI signing, researchers note that the requirement to support legacy, unpatched devices will keep this vulnerability open for the foreseeable future.

Telecom Protocol Engineers 40%Public Safety Regulators 35%Cybersecurity Researchers 25%
Telecom Protocol Engineers
Prioritize network efficiency and standardized interoperability across global cellular hardware.
Public Safety Regulators
Mandate universal, barrier-free access to emergency services regardless of commercial cost.
Cybersecurity Researchers
Focus on the vulnerabilities created by unauthenticated access, particularly device spoofing and denial-of-service risks.

Perspectives this story doesn't cover

  • First Responders
  • Hardware Manufacturers

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Telecom Protocol Engineers 40%Public Safety Regulators 35%Cybersecurity Researchers 25%
  1. [1]3GPPTelecom Protocol Engineers

    TS 24.301: Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS)

    Read on 3GPP →
  2. [2]3GPPTelecom Protocol Engineers

    TS 23.167: IP Multimedia Subsystem (IMS) emergency sessions

    Read on 3GPP →
  3. [3]Federal Communications CommissionPublic Safety Regulators

    47 CFR § 9.10 - 911 Service

    Read on Federal Communications Commission →
  4. [4]Factlen Editorial TeamPublic Safety Regulators

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team →

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns, free every day.