This is very interesting perspective on another forum "How a law firm tested "phantom" AT&T smartphone data use posted by "yorthen"
# # #
Since there seems to be a bit of confusion about how the charging is performed I’d like to give a short description of charging in a 3GPP packet switched network (which to my knowledge is what AT&T uses).
As data travels between the UE (User Equipment – the phone) and the internet it will pass through several different nodes, several (or all) of these nodes will generate CDRs (Charging Data Records). These CDRs will be compared against each other to make sure that everything is OK. Normal policy for operators is that if they detect something wrong with a CDR it (and possibly earlier and later CDRs) will be discarded. This means that the operator will lose money and the user will get some data usage for free, but the alternative is that the operator might charge for something the user haven’t done which is a big no-no (can turn ugly if brought to court).
The last node between the UE and the internet is called the GGSN, which is responsible for authorisation and charging of the data packages, and thus also the main source of changing data. At minimum a GGSN CDR will contain the opening time and closing time of the CDR (the times for which the information in the CDR is valid) and the volume (number of bytes uplink and downlink), and the reason for closing the CDR. Common reasons for closing a CDR is time-limit or volume-limit, that is that the CDR has been open for too long (usually 5-15 minutes) or that too much volume is included in the CDR (amount varies with the speed of the connection, can be a couple of KB to many MB). The volume is the total volume of the data traffic including IP-headers and all.
In addition to this information more detailed information can be included which is up to the operator, but it could typically include information such as volume (and time) per service, where a service is defined by the operator but it could be Skype, Netflix, or BBC news. A service could also be the aggregation of several services that for charging purposes are considered equal (such as free services). The way that different services are detected is by packet inspection, or when needed deep packet inspection (yes, it is heavily used in mobile networks). Sometimes operators defines a number of different services but still only charges for the total volume to be able to get statistics of network usage.
The CDRs seldom contains timestamps for individual events since normally there is no single event to record, just the signalling to setup a connection to a web-server is 3 packets, sending the HTTP request to get a page is one packet and getting the page with all the content can be tens of packets so there is no single event which represents getting the page.
What kind of makes it possible to get timestamps for specific events is the fact that the UE is normally not connected to the internet, when you need some data it has to set up a connection and get it, and when the data is received it will disconnect again (usually after a timeout). This is done to preserve both the UE’s battery and to reduce the resources used in the radio network. Each of these connects and disconnects will generate a CDR.
These CDRs are sent to the billing system and I suspect that this is what is referred to with "AT&T captures your data activity nightly to create a bill record in our systems." Why they cannot use the timestamp in the CDRs I do not know, but billing systems are large and complex with lots of wrinkles and oddities.
# # #