8 September 2026

STANAG-4415/MS-110A 75 bps Robust Waveform — Physical Layer Reference

A consolidated technical reference on the 75 bps STANAG-4415/MS-110A waveform observed on 18503.0 kHz, combining the physical-layer characterization from [1] with the framing findings from [2]. This post exists because that characterization was originally split across two separate write-ups — one on the RF/physical layer, one on framing behaviour. The split obscured a connection between them: the physical-layer absence of mini-probes (§2.2) means the base waveform has no built-in way for a receiver to join a transmission already in progress — and preamble re-injection (§3.2) is precisely what closes that gap, through a modification not present in the base STANAG-4415/MS-110A specification itself (though, as §3.2 details, with real precedent elsewhere in the STANAG family). Reading the two findings together makes that connection visible in a way that reading either post alone does not. Site attribution is deliberately out of scope here — see the two source posts for that discussion.

1. Operational overview
At the reception level, this waveform cannot be told apart from a standard MIL-STD-188-110A 75 bps transmission. STANAG-4415 and the MS-110A 75 bps robust mode are, at the RF signature level, the same waveform: same DSSS Walsh modulation, same fixed 2400 Bd symbol rate. A receiver — even a military-grade one, such as the L3Harris RF-5710A — demodulates both interchangeably; the distinction between the two standard labels comes down to a front-panel setting, not anything recoverable from the intercepted signal itself.
The relationship between the two standards was formalized over time: MS-110B (2000) §5.3.1.3.h lists the robust 75 bps mode as optional, specifying it "shall be in accordance with STANAG 4415." In other words, from MS-110B onward the US standard defines this mode by reference to the NATO one rather than specifying it natively — a distinction that matters for conformance testing, not for what a receiver actually sees.
The one real difference sits on the receiver design side: a modem built to fully meet STANAG-4415's stricter performance requirements can decode at lower SNR (down to roughly -9/-11 dB in 3 kHz AWGN) than one meeting only the baseline MS-110A target. This is a measurable difference in comparative lab testing (BER vs. SNR/multipath/Doppler) — not something inferable from intercepted bursts.

2.  Physical layer — signal and modulation characteristics
2.1 Signal acquisition

Initial demodulator lock shows a carrier at 1801.29 Hz (USB, +1801.4 Hz offset), a symbol rate of ~2400.22–2400.33 Bd, and an 8-ary constellation — consistent with the 2400 Bd, 8-PSK tribit-symbol architecture shared across the MS-110A serial-tone family.

Figure 1: signal acquisition and demodulator lock; arrow marks the preamble at the start of a new message.

2.2 Absence of mini-probes
Neither STANAG-4415 nor the MS-110A 75 bps mode uses mini-probes (the periodic resync sequences found in 150–4800 bps serial-tone modes). At 75 bps this isn't needed: DSSS Walsh spreading at a fixed 2400 Bd is inherently redundant per bit, so channel tracking and noise immunity come from the spreading itself rather than periodic re-training. MIL-STD-188-110A Table XIX confirms this directly — the 75 bps row lists 0 known symbols for this purpose.

Figure 2: MIL-STD-188-110A, Table XIX: the 75 bps row shows 0 known symbols.

At the architecture level (per STANAG-4415 Figure 2.1), switches SW2/SW3 toggle only between "sync preamble" and "data" phases, with no third state for reinserting an intermediate probe sequence — consistent with the absence of mini-probes. SW1 stays fixed on "input data" throughout both phases, since preamble and each interleave block share the same duration, keeping the interleaver continuously pre-loaded.
 

Figure 3: 75 bps modem architecture — SW2/SW3 switching between "b" (sync preamble) and "a" (data phase), while SW1 remains fixed, continuously pre-loading the interleaver with input data throughout both phases.

A practical consequence: a single preamble with no mid-stream mini-probes cannot, on its own, support late-entry acquisition — the base standard has no built-in mechanism for a receiver to join an in-progress transmission (see §3 below for how this implementation addresses that gap).

2.3 Walsh modulation, verified
Though Walsh modulation is formally specified in both standards, its presence was verified directly via carrier regeneration (squarer/m-th power loop). Squaring at exponent n=2 produces a clean spectral line confined to the preamble — proof of an underlying BPSK-type modulation beneath the Walsh chips. At exponent n=8, that line disappears completely across both preamble and data, confirming the underlying signal is masked BPSK rather than native 8-PSK.

Figure 4: squaring-loop spectral analysis at n=2 and n=8.

2.4 Preamble structure
Per MS-110A §5.3.2.3.7.2.1, the synchronization pattern consists of either three or twenty-four superframes, depending on the interleave setting. For the long-interleave 75 bps mode observed here: a 4.8 s preamble comprising 24 superframes of 200 ms each, each carrying 15 orthogonally Walsh-modulated channel symbols — 480 tribit symbols, or 1440 bits, per superframe. Measured ACF confirms both the 200 ms superframe period and the 4.8 s total preamble length.

Figure 5a: MS-110A frame structure (Preamble, interleaved data, EOM & Flush), showing how the preamble is composed of superframes (SF1...SFm).

Figure 5b: ACF of the sync preamble: peaks recurring at ~200 ms (dT = 200.609 ms) confirm the STANAG-4415/MS-110A sync pattern over the 4.8 s long-interleave preamble (dT = 4.799999 s).

Figure 5c: Initial section (preamble) of the bitstream showing the 1440-bit frame width across 24 superframes.

2.5 Data block ACF
The data segment following the preamble shows periodic ACF peaks every 66.67 ms (160 over-the-air symbols) — not a framing artifact, but the result of MS-110A's own data-scrambling sequence (per §5.3.2.3.8).
 
Figure 6 — ACF of the data segment.

3. Physical layer — framing behaviour beyond the base specification
Extended monitoring surfaced two characteristics of this 75 bps implementation that are not accounted for in the STANAG-4415/MS-110A reference specification.

3.1 Preamble onset delay
Although transmissions appear to begin "from nothing," some instances open with two extended tones at 1000 Hz and 1600 Hz, followed by a segment of 8-PSK modulation that cannot be demodulated without a preamble lock. In these cases the preamble is not transmitted at the start of the signal, but with measurable delays on the order of 50–60 seconds.

Figure 7: Comparison of signal start structures: anomalous transmission with initial 1000/1600 Hz tones and a delayed preamble (~50–60 s) (top), and standard transmission beginning immediately with the preamble before data (bottom).

3.2 Preamble re-injection
The more significant feature. In long transmissions, the full preamble is regularly re-injected every 115.2 seconds of data, forming a fixed 120-second cycle (4.8 s preamble + 115.2 s data) that repeats until the transmission ends. This 115.2-second span is exact, not approximate: it equals 24 blocks of long-interleave data, 4.8 seconds each — matching, block for block, the 24-superframe structure of the preamble itself (§2.4). Re-injection only engages once a transmission exceeds one full 24-block cycle; shorter transmissions carry a single preamble followed directly by up to 24 data blocks and end-of-message.

Figure 8: waterfall confirming the claims above — top: four consecutive re-injection cycles over roughly 8 minutes, showing the pattern repeats for as long as the transmission continues; bottom: zoomed view of one cycle, with a measured interval of 120.064 s between Preamble n and Preamble n+1, matching the nominal 120 s (2 mins) cycle to within 64 ms.

Figure 9: block structure of the repeating cycle — top: preamble followed by up to 24 data blocks per 120 s cycle, repeating until a final partial cycle closes with EOM; bottom: transmissions shorter than one cycle, carrying a single preamble followed directly by up to 24 data blocks and EOM.

This alignment is unlikely to be coincidental: 24 is also the number of superframes making up the long interleaver itself, meaning the reinsertion point falls precisely on the interleaver's structural boundary — and its strict periodicity points to a predefined acquisition mechanism rather than a reactive response to poor channel conditions.
Since this waveform is not autobaud and does not use mini-probes (§2.2), retransmitting the full preamble at known intervals adds:
(a) greater transmission robustness ;
(b) easier synchronization on late entry — a receiver joining mid-transmission gets a re-entry window every 115.2 seconds instead of having to wait for the entire transmission (which, for broadcasts, can run for tens of minutes) to end.

This isn't an isolated, one-off invention: it looks like a synchronization method already standardized elsewhere in the STANAG family, reused here. STANAG 4539 §4.3.1 explicitly defines a "reinserted preamble," distinct from the initial synchronisation preamble, whose stated purpose is to facilitate acquisition of an ongoing transmission (acquisition on data) — functionally identical to what's observed here — as does MIL-STD-188-110C Appendix D §D.5.4. However, MIL-STD-188-110C Change Notice-1 later removed the corresponding sentence, because the feature was considered obsolete in that context. No trace of any equivalent clause appears in STANAG-4415/MS-110A's own 75 bps text, so within this specific waveform it remains an addition beyond the base specification — one with real, if since-contested, precedent elsewhere in the STANAG/MIL-STD family.

References

4 September 2026

18503.0 kHz from Cyprus — New Waveform Findings, and Akrotiri Confirmed

A follow-up to the 75 bps serial tone (4415/110A) from Cyprus post [1] 

A friend and colleague pointed me to a few mailing list posts regarding receptions on 18503.0 kHz, shared by the users F1GOC, Kosmod, Linkz, and mco. These messages address the questions and doubts raised in the original post about the origin of the transmission ("Was it Akrotiri?"). They date to February and to August–November 2025, predating both the original post and this addendum, and are therefore independent of them. Their posts indicate receptions of STANAG-4415 75L, STANAG-4285 1200L, and even FSK 800/850 waveforms that are all consistent with the operational modes used by DHFCS. The STANAG-4285 1200/Long case is the most important one: demodulation yields a 1536-bit bitstream, observed and analysed across multiple sessions, that is as a distinctive signature of DHFCS rather than a generic mode match. Further bitstream analysis on the same capture (source Linkz) turned up a recurring alphabet/numbers test pattern, which could point to routine calibration or test sessions rather than live operational traffic.
Based on their receptions & TDoA results, the origin can now be treated as confirmed: DHFCS Akrotiri. 

The extended monitoring behind this analysis turned up more than an answer to where the signal originates: it also documented two new characteristics of the STANAG-4415/MS-110A 75 bps waveform — informally known as the Robust Waveform — that are not covered by the reference specification, which are discussed below before we return to the TDoA and UDXF points raised in the previous post and now resolved.

1. New waveform-level characteristics
Both are detailed below: a delay in the onset of the preamble, and its periodic re-injection during long transmissions.

1.1. Preamble onset delay
Although transmissions appear to begin "from nothing," some instances open with two extended tones at 1000 Hz and 1600 Hz, followed by a segment of 8-PSK modulation that cannot be demodulated without a preamble lock (Figure 1). In these cases the preamble is not transmitted at the start of the signal, but with measurable delays on the order of 50–60 seconds.

Figure 1. Comparison of signal start structures: anomalous transmission with initial 1000/1600 Hz tones and a delayed preamble (~50–60 s) (top), and standard transmission beginning immediately with the preamble before data (bottom).

1.2. Preamble re-injection
This is the more significant feature. In long transmissions, the full preamble is regularly re-injected every 115.2 seconds of data, forming a fixed 120-second or 2 minutes cycle (4.8 s preamble + 115.2 s data) that repeats until the transmission ends (Figure 2). This 115.2-second span is not approximate: it equals exactly 24 blocks of long-interleave data, 4.8 seconds each, matching the frame structure shown in Figure 3.
Re-injection only happens once a transmission exceeds one full 24-block cycle; shorter transmissions have a single preamble followed directly by up to 24 data blocks and EOM, as shown in the bottom row of Figure 3. This is unlikely to be coincidental: the number 24 is also the number of superframes that make up the long interleaver itself, meaning the reinsertion point falls precisely on the interleaver's structural boundary — and its strict periodicity points to a predefined acquisition mechanism rather than a reactive response to poor channel conditions.

Figure 2: waterfall confirming the claims above — top: four consecutive re-injection cycles over roughly 8 minutes, showing the pattern repeats for as long as the transmission continues; bottom: zoomed view of one cycle, with a measured interval of 120.064 s between Preamble n and Preamble n+1, matching the nominal 120 s (2 mins) cycle to within 64 ms.

Figure 3: block structure of the repeating cycle — top: preamble followed by up to 24 data blocks per 120 s cycle, repeating until a final partial cycle closes with EOM; bottom: transmissions shorter than one cycle, carrying a single preamble followed directly by up to 24 data blocks and EOM.

In my assessment, this preamble re-injection is an addition beyond the base STANAG-4415/MS-110A 75 bps specification. Since this waveform is not autobaud and does not use mini-probes, retransmitting the full preamble at known intervals adds:
a) greater transmission robustness;
b) easier synchronization on late entry — by offering a re-entry window every 115.2 seconds. This way, receiving modems don't need to wait for the current transmission to end (which, for broadcasts, can run for several tens of minutes) to lock onto a new preamble. This no longer looks like something invented just for this signal. It looks more like a synchronization method already standardized elsewhere in the STANAG family, simply reused here.

Indeed, the concept itself has NATO precedent: STANAG-4539 (08-JUN-2025) §4.3.1 explicitly defines a "reinserted preamble," distinct from the initial synchronisation preamble, whose stated purpose is to facilitate acquisition of an ongoing transmission (acquisition on data) — functionally identical to what's observed here, as does MS-110C Appendix D §D.5.4 (23-SEP-2011). However, MS-110C Change Notice-1 (03-JAN-2012) later removed the sentence "The reinserted preamble facilitates acquisition (or re-acquisition) of an ongoing broadcast transmission." because the feature was considered obsolete.

2. Specific objections, now resolved
With the origin no longer in question, it's worth revisiting the two points raised earlier — not to re-argue them, but to show plainly why they couldn't have closed the case on their own.
 
2.1. Why the TDoA result alone couldn't resolve it
The original post described the geolocation as "consistent with, but not uniquely pinpointing" the TRNC area. The KiwiSDR TDoA extension doesn't output formal error-ellipse statistics (axis lengths, confidence level) — it only renders the solution ellipse visually. What it does give is the receiver geometry actually used: which Kiwis contributed to the result, their baseline separation, and an approximate ellipse size read off the map scale.
Geometry is the dominant factor here. A cluster of receivers — close to each other, regardless of their distance from the target — produces nearly parallel hyperbolas in the area of the transmitter, meaning poor resolution, or high GDOP (Geometric Dilution of Precision)(1), as shown below in Figure 4.

Figure 4: Simplified schematic, not to scale: clustered receivers (left) yield nearly parallel sightlines and an elongated uncertainty area; spread receivers (right) yield wide-angle sightlines and a compact one.

This is visible in Figure 9a of the original post: the solution lines converge at a shallow angle, and their angling shifts depending on which cluster produced them — which is exactly why the resulting ellipses ran elongated along the Cyprus–southern Turkey axis rather than closing down to a point.
The KiwiSDR network has always had poor coverage in the Mediterranean and Southern Europe: this means relying mostly on receivers in Northern Europe, which degrades the GDOP for a target actually located in the Mediterranean.
However, the geometric limitation is not a flaw in the method — it is simply a result of which KiwiSDR receivers were available. Other TDoA results, like those behind the F1GOC/mco/Linkz/Kosmod mailing-list posts, may have benefited from a better receiver cluster and better HF propagation conditions at that time than those available for the analysis in the previous post.

2.2. The anomalous UDXF entry, and why open-web search missed all of this
The anomalous STANAG-4285/18503.2 kHz log (UDXF logs: WO, 8 May 2026), cited in the original post, now has a plausible match in Linkz's post from less than a year prior (13 August 2025): that same frequency carried, among other modes, DHFCS STANAG-4285 1200/Long traffic.
That connection didn't come from previous searches, though. I ran broad OSINT and open-web searches both before and after the earlier post was published, looking for confirmation of the transmitter's origin. Those searches turned up nothing substantial — not the above-mentioned F1GOC/mco/Linkz/Kosmod posts, despite those predating this analysis by close to a year. It took a colleague's direct pointer to surface the relevant mailing lists.

This isn't about a lack of evidence, but about where that evidence lives: specialist mailing lists of this kind are effectively invisible to general web search engines and OSINT tooling — they aren't indexed, aren't crawled, and aren't reachable through the kind of queries that usually work for open-source material. I'm subscribed to some of the lists in question myself, and I still missed the relevant messages at the time — a gap in my own monitoring discipline, not proof that the material wasn't circulating. 

 3. Open questions
A few points remain genuinely unresolved. Without more specific sources or hard evidence, discussing them further here would mean speculating rather than analysing — so they're simply indicated, to be revisited if better information comes along:

- Why this particular, modified 75 bps Robust Waveform at all, when STANAG-4285, conventional MIL-STD-188-110A modes, and FSK are all in routine use on the same frequency and by the same operator.
- The encryption in use doesn't match what's typically expected in this kind of context (KG-84/KW-46).
- What these transmissions are actually for.
- Frequent listening sessions (10–20 minutes, about every hour) have found no daytime activity at all on 18503.0 kHz on some days — a real pattern, given how often I listened. Night hours weren't checked, but that gap may not matter much: HF propagation on 18 MHz usually gets much weaker after dark, so — assuming some days do carry an exclusively night-time schedule — such transmissions might not reach here anyway.

The original post wasn't written to argue a case, but to lay out an open question with its uncertainties stated plainly. That the answer turned out to be traceable — independently, by others, before this piece was even written — is the outcome that kind of approach is meant to produce.

Notes
1. GDOP is a measure of how much receiver geometry amplifies timing error into position error — the more parallel the hyperbolas the worse the result.

References

29 August 2026

75 bps serial tone (4415/110A) from Cyprus: what if it's not UK DHFCS?

Cyprus has long been synonymous, in the utility monitoring community, with a single name: Akrotiri (DHFCS/RAF). The island's dense HF military traffic tends to get filed under that one well-documented facility almost by reflex — and for good reason, given how thoroughly its fingerprint has been logged over the years.  This post starts from an unusual waveform intercepted on 18503.0 kHz that doesn't quite fit that story. 

18503.0 kHz/USB — the signal at the center of this investigation

What follows is an attempt to characterize it properly, before eventually asking a question that felt worth asking: what if, this time, it isn't Akrotiri at all?
A note on the post structure: Sections 1 through 3 are essentially about establishing what this signal actually is — confirming its identity as a 75 bps STANAG-4415/MS-110A waveform, down to the preamble structure, the lack of mini-probes, and its cryptographic fingerprint. If you're here mainly for the "who's transmitting" question, Section 4 is where that discussion happens, and you're welcome to jump ahead. But that identification work is what turns the final hypothesis into something more than a guess — so if you have the patience for it, it's worth the detour.
Fair warning: the technical analysis is solid, but the attribution that follows it is a personal hypothesis, offered for what it's worth — and, as always, open to correction.

Transmission received on 18503.0 kHz/USB, first logged by me on 19 August 2026, and monitored regularly, though not continuously, since. Although the transmission looks, to the naked eye on the waterfall, like a classic STANAG-4285 fleet broadcast, its "sound" and subsequent analysis reveal a serial waveform of the MS-110A type operating in 75 bps Long Interleaver mode — a rather unusual configuration that prompted a closer look. Captures, recordings, and waterfall screenshots thanks to the KiwiSDR receivers kindly shared by my friend Linkz [1]. 

Notably, the transmission scheme is not a typical 24/7 active fleet broadcast; instead, it alternates between "off" states and active periods (for either short or extended periods). The transmissions start "out of the blue", without prior ALE sounding or handshake calls. This points either to scheduled transmission windows (though not strictly starting on the hour or half-hour) or to receivers parked on the listening frequency (18503.0 kHz).
In this regard, I have repeatedly noticed transmissions beginning in the morning around 06:50 UTC, lasting just a few minutes (recordings available in the Downloads section at the bottom of the post). I cannot confirm this to be a fixed daily start time, but such repetition seems unlikely to be mere coincidence.
Transmissions may consist of isolated single messages or extended continuous streams containing multiple messages — which are not necessarily contiguous. In the latter case, individual messages within the stream remain identifiable by their distinct preambles, which likely serve to trigger or re-synchronize waiting receivers. This behavior is otherwise consistent with NATO broadcast protocols.

## 1. Waveform analysis and confirmation
Figure 1 shows the initial SA (Signals Analyzer) demodulator lock on the intercepted signal: a carrier at 1801.29 Hz (USB, +1801.4 Hz offset), a symbol rate of ~2400.22–2400.33 Bd, and an 8-ary constellation — all consistent with the 2400 Bd, 8-PSK tribit-symbol architecture shared across the MS-110A serial-tone family.
The decoding software used correctly classifies the signal as MS-110A, tagging it "110A/75L" — i.e. the 75 bps mode with the long interleave setting. It's worth noting, however, that at the waveform level this 75 bps mode is identical to STANAG-4415's NATO Robust Waveform — same DSSS (Direct Sequence Spread Spectrum)(1) Walsh modulation, same fixed 2400 Bd symbol rate — so for logging purposes labeling the signal definitively as "MS-110A" or "STANAG-4415" from its RF fingerprint alone isn't strictly accurate.

Figure 1: Signal acquisition and demodulator lock; arrow marks the preamble at the start of a new message.
 
## 1.1 STANAG-4415 and MS-110A
As mentioned, at the waveform level STANAG-4415 and MS-110A are the same signal and fully interoperable, but STANAG-4415 layers stricter performance/conformance requirements on top of what MS-110A specifies natively.  MS-110A is a broad US standard covering an entire family of serial- and parallel-tone HF modem waveforms; the 75 bps robust mode is just one entry in that family. STANAG-4415, by contrast, is a narrowly-scoped NATO standard dedicated only to that robust 75 bps mode.
The relationship got formalized over time: MS-110B (dated 2000) §5.3.1.3.h explicitly lists the robust 75 bps mode as an optional mode, stating it "shall be in accordance with STANAG 4415" — i.e., in the newer US MIL-STDs (110B, 110C, 110D), the robust 75 bps entry is defined by reference to STANAG-4415 rather than re-specified in-house, whereas 110A originally carried its own native 75 bps definition before this harmonization. As per MS-110B (dated 2000) §5.3.4: "The optional robust serial tone mode shall employ the waveform specified above for 75 bps operation, and shall meet the performance requirements of STANAG 4415". 
 
Thus, if you're seeing a 75 bps DSSS-Walsh burst at 2400 Bd, you generally can't distinguish "it's STANAG-4415" from "it's the MS-110A 75 bps mode" from the RF signature alone — they're the same waveform. The distinction only really matters for conformance testing/interoperability certification, not for what hits your receiver.
Where the difference actually exists is on the receiver design side, not the bitstream side: a modem built to fully meet the STANAG-4415 spec will have a receiver capable of decoding at much lower SNR (down to roughly -9/-11 dB in 3kHz AWGN) than a receiver that only implements the baseline MIL-STD-188-110A target — but this is a performance difference, measurable only through comparative lab testing (BER vs SNR/multipath/Doppler), not something the modem can read or infer from a single intercepted burst. 
The L3Harris RF-5710A, a military-grade modem, demodulates either waveform interchangeably (Figure 2), as this essentially comes down to a different front-panel label on the modem.


Figure 2: Harris RF-5710A front panels displaying the two equivalent modulation settings: STANAG-4415 (top) and SERIAL MS-110 mode (bottom).

## 1.2 Lack of miniprobes
Neither STANAG-4415 nor the MS-110A 75 bps mode uses mini-probes. Mini-probes (periodic resync sequences) only appear in serial-tone waveforms with 150–4800 bps rates (Figure 3a), needed there because long burst duration allows channel drift between preamble and end-of-transmission. 75 bps mode doesn't need it: DSSS Walsh spreading at fixed 2400 Bd is inherently redundant per bit, so channel tracking/noise immunity comes from the spreading itself, not periodic re-training. Thus, a single preamble without mid-stream mini-probes cannot support late-entry acquisition, further justifying the above hypothesis of parked receivers standing by on a pre-assigned frequency.
 
Figure 3a: MIL-STD-188-110A, Table XIX: the 75 bps row shows 0 known symbols, confirming the absence of mini-probes at this rate.

Figure 3b (adapted from STANAG-4415, Figure 2.1) illustrates the 75 bps modem architecture, showing SW1, SW2, and SW3 across the two operational phases. SW2 and SW3 switch between position "b" (synchronization preamble phase) and position "a" (data phase) — with no third state available for either. SW1, by contrast, remains in the same "input data" position throughout both phases: since the preamble and each Interleave Block share the same duration, the interleaver is continuously pre-loaded with incoming input data even while the preamble itself is being transmitted, ensuring the data phase can begin without delay once the preamble ends. No third switch state exists for SW2/SW3: once transmission moves to the data phase, the Preamble Generator and Sync-mode PN Generator are permanently disengaged, with no provision for reintroducing an intermediate re-synchronization ("probe") sequence — consistent with the absence of mini-probes discussed above.

Figure 3b: 75 bps modem architecture — SW2/SW3 switching between "b" (sync preamble) and "a" (data phase), while SW1 remains fixed, continuously pre-loading the interleaver with input data throughout both phases.

## 1.3 Walsh modulation
Although the use of Walsh modulation is formally specified in the reference standards (STANAG-4415 and MS-110A), its presence can be directly verified through carrier regeneration via the squarer/m-th power loop technique implemented in SA.
The presence of a clean spectral line at exponent n=2 in the non-linear analysis (Figure 4, center) provides mathematical proof that the preamble carries an underlying BPSK-type modulation associated to Walsh chips. Squaring a two-state structure (0°/180°) collapses the phase, producing a single coherent line.  With exponent n=8 (Figure 4, bottom) this spectral line vanishes completely across both preamble and data sections, confirming that the underlying signal is a masked BPSK rather than a native 8-PSK modulation.  
Although the data payload also employs BPSK-mapped Walsh modulation followed by 8-PSK scrambling, the spectral line at n=2 is confined to the preamble. This is because the preamble uses a fixed, highly repetitive PN synchronization sequence; the combination of BPSK phase symmetry and strict structural periodicity concentrates the squared energy into a discrete peak. Conversely, the data payload transmits high-entropy user data.
While squaring (n=2) mathematically removes the BPSK phase transitions from individual Walsh chips, the non-repetitive, pseudo-random nature of the payload (further randomized by interleaving) spreads the energy evenly across the bandwidth, dissolving the discrete tone into the spectral noise floor.
 
Figure 4: Top: Original signal spectrogram highlighting the preamble region.  Center (n=2): Carrier regeneration revealing a sharp spectral line confined to the preamble, proving the underlying BPSK-type modulation.  Bottom (n=8): Complete absence of the spectral line across preamble and data payload, confirming a BPSK base waveform rather than a native 8-PSK constellation

## 2. Preamble structure and ACF analysis
As per MS-110A §5.3.2.3.7.2.1 "The synchronization pattern shall consist of either three or twenty four superframes (depending on whether either zero, short, or long interleave periods are used)", as illustrated in Figure 5a. It is possible to analyze the initial synchronization preamble preceding the data (Figure 5b).
The 200 ms ACF value is compliant with the sync pattern of MS-110A. The 4.8 s length of the sync preamble indicates the long interleaver setting with its 24 superframes (4800:24=200), each superframe consisting of the transmission of 15 orthogonally Walsh-modulated channel symbols. At a speed of 2400 symbols/s, each 200 ms superframe corresponds to a length of 480 tribit symbols or 1440 bits (15 channel symbols × 32 Walsh chips = 480).
 
Figure 5a: MS-110A frame structure (Preamble, interleaved data, EOM & Flush), showing how the preamble is composed of superframes (SF1...SFm).
 
Figure 5b: ACF of the sync preamble: peaks recurring at ~200 ms (dT = 200.609 ms) confirm the STANAG-4415/MS-110A sync pattern over the 4.8 s long-interleave preamble (dT = 4.799999 s).

Figure 5c shows the bitstream resulting from 8-PSK demodulation of the over-the-air symbols (truncated initially for space and visual clarity). Note the expected length of the highlighted preamble section: 1440 bits (480 tribit symbols) across 24 superframes. 

Figure 5c: Initial section (preamble) of the bitstream showing the 1440-bit frame width across 24 superframes.

## 2.1 Data block ACF analysis
The waveform following the preamble (the data segment) still shows strong periodic peaks at 66.67 ms intervals, corresponding to 160 over-the-air symbols, see Figure 6. This is because MS-110A scrambles the data symbols against a pseudo-randomized sequence that produces a periodic pattern of 160 transmit symbols in length (as per MS-110A §5.3.2.3.8).

Figure 6: ACF of the data segment following the preamble, showing periodic peaks at 66.67 ms (160 symbols).

## 3. Analysis of a demodulated bitstream
The demodulated bitstream shown in Figure 7 displays high-entropy data with no discernible periodicity or autocorrelation peaks, and shows no repetitive patterns such as Initialization Vectors or series of reversals. The statistical analysis (Figure 8) confirms this assessment: a balanced bit distribution (50/50), a relatively flat byte histogram, and near-zero autocorrelation across all tested lags, yielding an overall score of 5/6 — consistent with encrypted or well-scrambled data. This should not be confused with the periodic ACF peaks noted in Section 2.1 Figure 6: those stem entirely from the standard's own known data-scrambling sequence — applied uniformly regardless of payload content — and are removed during proper demodulation, unlike the analysis here, which targets the fully descrambled, actual user payload.

Figure 7: Demodulated MS-110A 75 bps bitstream showing no visible framing patterns or periodicity.

Figure 8: Statistical analysis of a demodulated bitstream.

## 4. Geolocation and hypothesis on the source
Figure 9a shows the signal geolocation results obtained using the TDoA (Time Difference of Arrival) method across clusters of KiwiSDR receivers. The elongated solution ellipses place the source along a line running from Cyprus into southern Turkey. Taking the map overlays at face value, the fix is consistent with, but does not uniquely pinpoint, the northeastern portion of Cyprus known as TRNC (Turkish Republic of Northern Cyprus)(2); the same geometry is equally consistent with a source on the adjacent Turkish mainland coast.

Figure 9a: TDoA geolocation results across KiwiSDR clusters targeting Cyprus area.

Since the Akrotiri UK DHFCS (Defence High Frequency Communications Service) facility in Cyprus — and specifically its Salt Lake transmitter site (3) — is widely recognized and well known within the utility/SIGINT community, HF transmissions geolocated to Cyprus are almost automatically attributed to this site. Figure 9b shows exactly the kind of installation behind that reputation: a satellite view of the Salt Lake site itself, its CDAA-type circular antenna arrays clearly visible on the ground.

Figure 9b: Satellite view of the DHFCS Salt Lake transmitter site, showing several circular antenna arrays (CDAA-type) consistent with a major HF installation. Source: Google Earth.

## 4.1 But what if it's not UK DHFCS?
The presence of military communications infrastructure beyond Akrotiri, in the Turkish-administered sector of Cyprus, is not just easily imaginable — it is a matter of public record too. Wikipedia's own entry on the Security Forces Command (GKK)(4) [2], the TRNC's military and security force, also publicly documents its organizational structure, which includes a dedicated Communications & IT Command (Figure 10).

Figure 10: GKK organizational chart; highlight added to indicate the Communications & IT Command. Source: Wikipedia.

Naval infrastructure adds a further, more concrete data point: as of late 2025, Cypriot press reports indicate that Turkish warships are now permanently stationed at Famagusta, alongside separate naval base works reportedly under way at Bogazi and a vessel traffic monitoring system [3] — reportedly involving several dedicated stations — being installed in the Karpasia area. None of these reports specifically confirm HF transmission capability, but the EW/radar installations reported in the Pentadaktylos range [4] are exactly the kind of electronic infrastructure that could plausibly include HF communication capability — reinforcing the general picture of an expanding, communications-dependent military footprint in the TRNC's eastern coastal area, geographically consistent with the TDoA bearing discussed above.
 
It should be noted, however, that open-source documentation of this kind rarely goes beyond such general, high-level information: precise, named confirmation of specific HF transmitter sites — let alone their operational role — remains historically scarce, even by ordinary OSINT standards.
Still, this general picture opens the door to an alternative attribution: a Turkish-operated transmitter site, even if one that cannot be pinned down to a specific, named installation.
It's a purely personal hypothesis, admittedly one that may seem far-fetched or even provocative — but it is supported, in my opinion, by the following points.
 
## 4.2 The used Waveforms
Although the DHFCS HF band plan is not publicly disclosed, technical and operational needs undoubtedly require DHFCS to use multiple frequencies simultaneously. These concurrent frequencies can, in principle, originate from a single transmitter site (5). An example is shown in Figure 11, where a DHFCS-consistent STANAG-4285 fleet broadcast at 1200 bps (20123.2 kHz) is captured alongside a separate STANAG-4415/MS-110A signal at 75 bps (18503.0 kHz, the signal being analyzed). Note that the captures below merely illustrate concurrent HF activity observed, not a common point of origin.
 
Figure 11: Concurrent HF activity captured from Cyprus area (both geolocated) on two different KiwiSDRs.

As shown in Figure 12, the upper capture (24 August 2026, 17:04 UTC) shows an active STANAG-4285 1200 bps/L transmission (1536-bit TDM frames) on 18534.20 kHz, while the 18503.0 kHz channel — associated with the 75 bps/L serial signal — is inactive. The lower capture (25 August 2026, 11:20 UTC, ~18 hours later) shows both the 75 bps/L serial and the STANAG-4285 1200 bps/L transmissions active simultaneously. Both captures are geolocated to the Cyprus area.
 
Figure 12: Waterfall display over an observation timeframe.

It must be noted that the 1200 bps STANAG-4285 signals match DHFCS's well-documented fingerprint, while the 75 bps STANAG-4415/MS-110A signal is atypical for that profile. My hypothesis here is that the two waveforms could originate from two distinct stations on the same island/area rather than a single site — namely the well-known DHFCS site, and perhaps a Turkish-operated site. As above,  neither band plans nor transmitter locations are publicly disclosed by Turkish military or other civil authorities.
Attentive readers may have noticed a discrepancy in fading profiles between the two signals in Figure 12 (bottom). It is worth noting that this, on its own, does not prove distinct transmitter sites: due to frequency-selective fading and the limited coherence bandwidth of the ionospheric channel, two signals separated by a few tens of kHz can exhibit completely uncorrelated fading dynamics even when originating from the exact same facility — or even the same antenna array. The relative strength difference between the two signals, however, has at times been observed to persist for several minutes — longer than the coherence time typical of fast ionospheric fading (on the order of seconds). This points to slower-scale propagation variability, or simply a genuine difference in transmit power between the two services, rather than fast fading — and, again, does not by itself indicate separate transmitter sites.

Turning back to the waveforms, I processed the UDXF(6)[5] logs from 2006 to date (currently more than 300K log entries), using Agent Ransack — a file searching tool from Mythicsoft [6] — and filtering for the term "Akrotiri" (case-insensitive). After excluding entries relating to MS-141A ALE soundings, wx/sitrep, 4-tone FSK, GMDSS/DSC, OTHR "Pluto" (and similar), the remaining logs exclusively report the use of the STANAG-4285 waveform, in either 600 or 1200 bps mode. Only two log entries, both from the same observer (F1GOC), report a MS-110A transmission, intercepted on 18503.0 kHz on 11 August 2025, though not identified with certainty by the analysis software:
 
"18503 : UNID (UK MIL DHFCS AKROTIRI?) MIL-STD-188-110A 2400BD, PSK-8, ACF 66 MS/160 BITS. HOWEVER, K500 DOES NOT RECOGNIZE IT. I FOUND NOTHING ON THE NET FOR THIS FREQUENCY. (F1GOC)"
"18503.0 : UK DHFCS-AKROTIRI, GBR, USB, MIL-STD-188-110A (11AUG25 1653) (F1GOC)"

(courtesy of UDXF Group)

Filtering the same logs by frequency (18503), only one further entry emerged alongside the ones above, relating to an unspecified STANAG-4285 transmission on 18503.2 kHz, logged on 8 May 2026:

"18503.2 : UNID, STANAG 4285 (08MAY26) (WO)"
(courtesy of UDXF Group)

Note that unlike the two entries above, this log carries no technical parameters (baud rate, ACF, or similar) to substantiate the waveform call — it is markedly sparser, raising the possibility of an aural (by-ear) identification rather than one backed by actual demodulation with the help of commonly used decoders (Sorcerer, Multipsk, Sigmira, Code300,...). For what it's worth, in my own monitoring of 18503 kHz — admittedly not exhaustive — I have not detected any STANAG-4285 activity on that specific frequency as of this writing (which could hint at a possible misidentification by the WO observer).
It should be stressed that the considerations above rest solely on the UDXF archives — a very large database, admittedly, but a single source nonetheless — and do not necessarily amount to a smoking gun. Combined with the direction-finding results, however, they can reasonably be said to support my hypothesis put forward here.
 
## 4.3 The used encryption
Regarding the type of encryption used, I cross-referenced the 75 bps demodulated bitstream against known synchronization sequences — such as those for KG-84 or KW-46, commonly used within NATO for fleet broadcasts — but found no matches. Assuming encryption is indeed present, it likely employs a different or non-standard/proprietary cipher.
As it happens, I reached the same negative results — no recognizable, well-known encryption signature — when examining DHFCS's 1536-bit bitstreams.  However, in the case being analyzed the negative result carries considerably more weight:
a) the demodulated 75 bps stream is a single, well-defined user data bitstream, applied directly to the HF modem after the cipher engine.
b) DHFCS's demodulated 1536-bit bitstreams are formed by multiplexing n-channels at the input ports of the multiplexer (DRS GA-205 TDM); since the algorithm governing the multiplexer is unknown, it's impossible to correctly reconstruct the individual per-channel bitstreams.
Thus, a negative result there is far less conclusive, since it simply reflects a raw demodulation of the multiplexer output — i.e., it's a "failed" demultiplexing rather than a genuine absence of known synchronization patterns.
 
The absence of a recognizable NATO cryptographic signature could plausibly be explained by the use of proprietary, domestic encryption rather than a NATO-standard cipher. Notably, Turkey maintains separate cryptographic algorithms for national versus NATO-approved devices — nationally-developed algorithms are never shared with NATO. 
A genuinely national Turkish HF link would therefore be expected to show no correlation with known NATO cipher signatures such as KG-84 or KW-46 [7][8].
It's tempting to speculate that opting for an indigenous, non-NATO cipher might serve a further purpose: shielding this traffic even from the SIGINT facilities hosted within the nearby British Sovereign Base Areas of Akrotiri and Dhekelia. HF skip propagation means physical proximity is no strict prerequisite for interception, but a same-island transmitter would still offer those facilities an unusually short, high-quality intercept path — making a domestic cipher a sensible extra safeguard, even among nominal NATO allies.

## 5. Conclusions
Taken together, the elements discussed above point toward the possibility of a second, Turkish-operated transmitter site sharing the Cyprus/southern-Turkey HF environment, rather than a DHFCS Akrotiri origin, as the source of the 18503.0 kHz traffic. To summarize, this working hypothesis rests on:

a) an atypical waveform choice (75 bps STANAG-4415/MS-110A) for a site whose UDXF-documented profile is dominated by 1200 bps STANAG-4285;
b) the absence of any recognizable NATO cryptographic framing structure in the demodulated bitstream — a stronger indicator than entropy analysis alone, and one reinforced by the fact that the 75 bps stream, unlike DHFCS's multiplexed TDM output, is a single well-defined bitstream where a negative result actually carries weight;
c) a TDoA bearing consistent with the TRNC area, though not uniquely so;
d) the existence of a documented, indigenous Turkish military crypto program (ASELSAN/TÜBİTAK MİLSEC family) capable of explaining the negative crypto match;
e) publicly documented Turkish military communications infrastructure in the TRNC, including the GKK's own Communications & IT Command.
 
This remains a personal working hypothesis, not a confirmed attribution. The UDXF log records, while suggestive, represent a single archival source — albeit a large one, currently containing more than 300K entries; the TDoA geometry constrains bearing but not range; and the cryptographic argument, however methodologically sound, is ultimately built on an absence of evidence rather than a positive match. Nor can I entirely exclude the possibility that this is simply DHFCS itself, running test transmissions of an atypical waveform — though the extended timeframe over which this traffic has been observed is more consistent with an established, "in-production" capability than with a short-lived trial. A third, unverified log entry (18503.2 kHz, STANAG-4285, 8 May 2026) also remains to be independently checked, and could complicate or reshape this picture.

Continued monitoring of 18503.0 kHz — together with further TDoA passes and, ideally, independent corroboration of the anomalous STANAG-4285 log entry — should help either strengthen or falsify this hypothesis over time. None of this amounts to proof, and I hold this hypothesis loosely. If you have documented information, direct monitoring experience, or technical arguments that support, refine, or contradict it, I'd genuinely welcome hearing from you — constructive criticism, backed by evidence, is exactly what a case like this needs.
 
Downloads

Notes
1. In Direct Sequence Spread Spectrum each data symbol is spread across a fixed 32-chip orthogonal code sequence rather than transmitted as a single symbol, trading bandwidth for resilience at very low SNR.
2. TRNC is a de facto state comprising the northeastern portion of the island of Cyprus. Declared in 1983, it is recognized internationally only by Turkey, while the rest of the international community considers it territory of the Republic of Cyprus under military occupation.
3. In the Western Sovereign Base Area of Cyprus, DHFCS sites include the Salt Lake transmitter (34°36'50"N 32°56'12"E), near Akrotiri, and the Episkopi receiver (34°40'47"N 32°51'24"E), roughly 13 km to the west. Positioned in the eastern Mediterranean, these installations facilitate communications for UK and NATO forces in the Middle East and beyond, enhancing resilience in a key geopolitical theater.
4. The GKK integrates units for tactical communications (HF/VHF/UHF), data encryption, and electronic warfare, part of the wider C4ISR network across Northern Cyprus. Connectivity to the mainland is presumably provided by TAFICS, Turkey's own military communications backbone [9] — which also relies on TÜBİTAK-supplied cryptography, consistent with the indigenous crypto capability discussed in Section 4.2.
5. In military HF operations, the concurrent use of a high-throughput waveform alongside a low-rate, robust-mode waveform for degraded channels or high-priority traffic is common practice, and both can originate from the same transmitter. Modern station architectures employ matrix switches to route multiple HF modems to separate, concurrently active transmitters/antennas, or digitally synthesized exciters generating independent I/Q streams combined at IF/RF. Consequently, simultaneous, multi-frequency dual-waveform operation from a single facility is architecturally unremarkable on its own.
6. UDXF stands for Utility DXers Forum, an online community of radio enthusiasts monitoring non-broadcast HF stations below 30 MHz — including military, maritime, aeronautical, and other "utility" signals, as opposed to broadcasting, pirate, or amateur radio traffic. Active since 2006, it maintains a mailing list through which members exchange logs and technical observations.

References

17 August 2026

UK DHFCS 16289.5 kHz Follow-up: DRS GA-205 TDM Evidence and 1536-bit Frame Analysis

Following up on the initial analysis of the UK Defence High Frequency Communications Service (DHFCS) transmissions on 16289.5 kHz [1] (observed in both 800 Bd / 800 Hz FSK and STANAG-4285 modes), further analysis of extended raw bitstream captures has provided concrete evidence regarding the deployment of the Leonardo DRS GA-205 Time Division Multiplexer (or a fully compatible framing engine) and additional structural characteristics. The 1536-bit period bitstreams were obtained by demodulating some STANAG-4285 recordings from my personal repository. 

1. DRS GA-205 Synchronization character
All examined bitstreams share the exact same 16-bit synchronization sequence — referred to as the "Synchronization character" — specified as 9C16 (hex) in the DRS GA-205 TDM datasheet for Frame Type 1 (Figure 1) which is user-programmable depending on the selected operational profile. In this context, DRS refers to Leonardo DRS (formerly DRS Technologies), a major defense contractor specializing in tactical military communications, naval digital networks, and signal processing hardware. Specifically, the DRS GA-205 is a 12-channel Time Division Multiplexer (TDM) widely deployed across NATO and Allied naval assets [2].

Figure 1: Excerpt from the DRS GA-205 datasheet showing the synchronization character specifications

In binary format, the hexadecimal value 0x9C16 corresponds to the 16-bit sequence 1001110010011100 (MSB Most Significant Bit first). When transmitted over the air in standard LSB-first (Least Significant Bit first) bit order, it translates to 0011100100111001. According to the manufacturer's specifications, this synchronization sequence is user-programmable per frame type (e.g., 9C16 for Frame 1 or 9D16 for Frame 2). Figure 2 illustrates an example of this alignment within the demodulated bitstream.

Figure 2: Alignment of the 1536-bit periodic stream showing the vertical synchronization column matching the DRS GA-205 Frame 1 sync character (9C16 / LSB 0011100100111001)

1.1 Framing Lock Mechanism
The receiving framer scans the incoming bitstream for the static, known 16-bit sequence (0x9C16). Its sole purpose is to establish word alignment at the start of the frame and determine bit clock timing, operating completely independently of the subsequent frame layout.
The persistence of the identical 9C16 sync character across bitstreams with varying overall internal layouts highlights a fundamental design principle of the DRS GA-205 architecture: the decoupling of Bit/Frame Alignment from Payload Demultiplexing. While the static 16-bit sync word ensures immediate physical-layer framing lock across all transmissions, the underlying TDM engine adapts the 1536-bit frame structure and sub-field distribution to match the active user port allocations.

2. 1536-bit bitstreams
Although these 1536-bit period bitstreams rely on the exact same 9C16 sync character for primary frame alignment, their internal structures may differ significantly. For instance, certain layouts do not lend themselves to straightforward structural description or tabular breakdown, as illustrated by the complex bitstreams shown in Figure 3. 

Figure 3: Examples of 1536-bit period bitstreams exhibiting highly complex or irregular sub-framing structures despite sharing the identical 9C16 primary synchronization sequence.

Conversely, other bitstreams — such as the one shown in Figure 4 — feature a highly regular structure that can easily be mapped and detailed using simple tables (Table I).

Figure 4:  Bitmap representation of a highly regular 1536-bit STANAG-4285 bitstream divided into 21 sub-blocks, highlighting alternating 48-bit payload fields (D) and static 16-bit filler/separator fields (F)

Table I: Structural breakdown of the 1536-bit frame layout shown in Figure 4

The bitstream shown in Figure 4 can be directly compared with the one analyzed in the previous post [1], reproduced in Figure 5 along with its structural breakdown (Table II) for convenience.

Figure 5: Asymmetric 1536-bit STANAG-4285 frame layout from the previous post [1], divided into 7 main sub-blocks with variable field lengths (F1,​D1-F5,​D5​).

Table II: Detailed structural breakdown of the 1536-bit frame layout shown in Figure 5

2.1 Channel Interleaving vs. Hardware Ports
A potential point of confusion when analyzing these bitstreams is the presence of up to 21 distinct sub-blocks (or "pseudo-channels") within a single 1536-bit frame, as in the bitstream of Figure 4, given that the DRS GA-205 is physically a 12-channel TDM.
The 12 channels of GA-205 correspond to the 12 physical input ports, which are not transmitted as 12 monolithic blocks. When user ports are configured for different baud rates (e.g., mixing 75 Bd and 300 Bd channels), higher-speed channels are assigned multiple timeslots within the same 1536-bit macro-frame, naturally resulting in a sub-block count higher than the number of physical input ports.

To multiplex them into a single continuous stream, the TDM engine samples higher-speed ports multiple times per frame cycle while sampling lower-speed ports only once. Consequently, the 21 sub-blocks visible in the bitstream bitmap do not represent individual hardware ports, but rather the cyclical sampling sequence (interleaving ratio) of the TDM frame. Each sub-block carries its respective slice of user payload (D) alongside necessary framing, control, and pulse-stuffing overhead (F).
Conversely, Figure 5 displays only 7 main sub-blocks. This lower count indicates either that only a subset of the 12 hardware channels was active, or that multiple low-speed user ports were aggregated within shared timeslots.
Without access to the specific TDM preset configuration used in these captures, drawing definitive conclusions about the exact channel mapping remains challenging. In operational scenarios, these layout variations are recognized either via pre-configured operational profiles (where sender and receiver share a pre-set TDM channel mask) or via in-band framing status bits transmitted immediately following the very first sync header. Once the receiving framer locks onto 9C16, it applies the designated slicing mask to route each sub-field to its respective low-speed channel processor. It should be noted that, at least across the recordings currently in my repository, no identical layouts were found but rather streams that are merely "architecturally" similar.

3. Parallel fields (counters)
Direct text decoding of the parallel fields shown in Figure 6 (one 8-bit and two 7-bit fields) reveals that they do not function as dynamic numeric counters, but rather as deterministic ASCII test/idle pattern generators.

Figure 6: Bitmap alignment of the 1536-bit STANAG-4285 bitstream highlighting the position of three parallel sub-fields (cnt-1, cnt-2, cnt-3) within the TDM frame structure.

The decoded text (Figure 7) shows sequential progressions of the printable ASCII character set:

!"#$%&'()*+,-./0123456789:;<=>?\ABCDEFGHIJKLMNOPQRSTUVWXYZ(\)`ABCDEFGHIJKLMNOPQRSTUVWXYZ(~)\
!"#$%&"()*+,-./0123456789:;<=>?`ABCDEFGHIJKLMNOPQRSTUVWXYZ(|)~`ABCDEFGHIJKLMNOPQRSTUVWXYZ(~)

This behavior is characteristic of:
- Channel Integrity (BERT): Enables continuous Bit Error Rate (BER) measurement and frame loss detection across individual TDM sub-channels by stepping through the ASCII sequence at one character per frame.
- Idle Filler Sequence: Maintains symbol clock synchronization and bit transition continuity across the link when user ports are inactive or sending null traffic.

It should be noted that these behaviors, while consistent with the GA-205 architecture, are not necessarily exclusive to it, as similar idle/test patterns and interleaving schemes are common across many military-grade TDM systems.

Figure 7: Decoded ASCII text representation of parallel sub-fields, revealing continuous printable ASCII sequence sweeps used for channel integrity monitoring and alignment.

4. A Second Test Pattern: Baudot/ITA-2 Pangram Sequence
The following analysis is based on a separate demodulated bitstream capture, distinct from the ones used in Figures 1–10 above — a further illustration that, as already noted in Section 2.1, not all captured bitstreams share the same internal sub-block layout.
Reshaping the raw 1536-bit stream into a 12×16 byte matrix (12 rows×16 byte-columns per frame) reveals a striking pattern in column K (the 11th byte of each row) at same intervals, highlighted in Figures 8,9. Across 12 independently captured frames — each clearly identified by the recurring 0x3939 sync character in columns A and B (LSB-first of 0x9C16 sync character) — a total of 129 out of 144 cells (89.6%) in column K share the pattern "XXXXX111" consisting of trailing 3-bit suffix, whereas the leading 5 bits vary dynamically.

Figure 8: Bitstream visualization of the reshaped data frames. The white bounding box on the right highlights the recurring structural pattern observed at fixed byte intervals across multiple independent transmissions.

Figure 9: Part of the Excel matrix alignment (12×16 bytes) of consecutive 1536-bit frames, highlighting the primary sync header and the persistent XXXXX111 pattern in column K (11th byte).

Extracting the variable 5-bit prefix from each of these 129 bytes and decoding it as International Telegraph Alphabet No. 2 (ITA-2 / Baudot-Murray, CCITT-2) produces a clearly recognizable result:

"…THE QUICK BROWN FOX (JUMPS) OVER THE LAZY DOG…" followed by a FIGS-shifted digit run (0–9).

Independent decode of the same demodulated bitstream using dedicated RTTY/Baudot decoding software (5×19 multiplex, positive polarity, correct bit order). The software's raw output (top) closely matches the ITA-2 reading derived manually above (white box, overlaid for comparison), corroborating the "THE QUICK BROWN FOX..." pangram test pattern (Figure 10).

Figure 10: Decode of the same demodulated bitstream using dedicated RTTY/Baudot decoding software

This is the classic pangram test string long used to exercise teleprinter and RTTY equipment, as it contains every letter of the alphabet. Notably, the small gaps observed in the decoded text in Figure 10 (e.g., "QUIC" instead of "QUICK") coincide exactly with the row-1/sync boundary of each frame where the character stream is interrupted — providing independent confirmation of the frame's periodicity.
Taken together with the printable-ASCII BERT/idle sweep documented in Section 3 (from the primary bitstream), this demonstrates that different GA-205 captures can carry structurally distinct low-speed test channels — one bitstream multiplexing a 7/8-bit ASCII test sequence, and another multiplexing a 5-bit Baudot/ITA-2 test sequence. This strongly reinforces the mixed-rate channel interleaving model discussed in Section 2.1.

The byte-matrix reshaping, statistical pattern analysis, and ITA-2/Baudot decoding presented in this section were carried out with the assistance of Claude (Anthropic AI), based on raw demodulated bitstream data provided by the author.

5. 1024-bit bitstreams & GA-205
Bitstream analysis of demodulated 800 Bd / 800 Hz FSK recordings (Figure 11) revealed a 1024-bit frame period that shares the exact same sub-block multiplexing architecture as the 1536-bit STANAG-4285 streams, yet lacks the standard 0x9C16 sync word. Instead, these streams consistently exhibit a 11-bit (LSB) synchronization sequence: 01100001101.
 
Figure 11: Alignment of the 1024-bit FSK periodic stream displaying the 11-bit vertical synchronization sequence (01100001101)
 
As outlined in the manufacturer specifications, and illustrated in the preset screenshot in Figure 12, the DRS GA-205 synchronization character is not hardcoded; it is user-programmable depending on the active operational profile or frame configuration — e.g., Frame Type 1 using 0x9C16 vs. Frame Type 2 using 0x9D16, or even a custom user-defined vector such as 01100001101. Naturally, this configuration must be agreed upon and shared between peers prior to transmission.
 
Figure 12: GA-205 TDM software control interface showing configurable aggregate parameters, sync code options, and individual user port rate allocations

6. Conclusions
To ground these bitstream findings in real-world military infrastructure, we must examine the hardware lineage and strategic deployments behind these transmissions. Specifically, looking at two major industrial partnerships highlights how the Leonardo DRS GA-205 Time Division Multiplexer is integrated across NATO and Allied HF network.

- Australian Defence Force (ADF) & MHFCS (Bellinger Systems):
In Australia, Bellinger Systems (a SYPAQ subsidiary) signed a long-term agreement with Leonardo DRS to procure, integrate, and support the GA-205 modernisation and delivery program. This program includes delivering approximately 100 modernised GA-205 TDM units to the Australian Defence Force to support their Modernised High Frequency Communications System (MHFCS) and transition towards Link 22 tactical data link architectures [3] (1).

Figure 13: Dimensional specifications comparison between the modernised Bellinger Systems GA-205 (left) and the original DRS Technologies (right).

- UK Defence High Frequency Communications Service (DHFCS / Babcock International):
Within the UK DHFCS infrastructure, primary defense contractors and service partners (such as Babcock International) manage the strategic HF communication sites, ground stations, and ship-to-shore links. In these strategic architectures, the GA-205 TDM serves as the key bridging multiplexer, interfacing legacy low-speed user channels with high-speed HF modems across UK Defence HF networks.

While absolute confirmation would require declassified operational documentation, there is strong circumstantial and technical alignment between the observed sub-block structures and the GA-205’s native support for the U.S. Navy High Speed Fleet Broadcast (HSFB) architecture(2). Designed specifically to aggregate heterogeneous low-speed naval messaging and tactical data streams over a single HF carrier, the HSFB framing profile provides a compelling explanation for the rigid slot allocation and deterministic frame synchronization observed across both STANAG-4285 and FSK transmissions in the DHFCS/MHFCS networks.

Notes
1. The dimensional discrepancies between the original DRS datasheet (standard 1U 19-inch rackmount) and Bellinger Systems' product sheet (200×132×620 mm) strongly point to a modernised form-factor evolution. Bellinger re-packaged the GA-205 TDM engine into a modular ATR-style / vertical-rack footprint for the Australian Defence Force's MHFCS project, integrating internal flash-upgradable firmware, higher aggregate data rate handling (up to 38.4 kbps), and built-in Link Local Controller (LLC) support for modern naval communication racks.
2. The U.S. Navy High Speed Fleet Broadcast (HSFB) is a U.S. Navy and NATO hardware architecture for shore-to-ship multi-channel fleet broadcast communications. HSFB replaced older single-channel low-speed (75-baud) broadcast links by aggregating multiple heterogeneous low-bitrate channels into a unified TDM stream over HF/UHF carriers. Native HSFB support within the Leonardo DRS GA-205 multiplexer ensured multi-channel broadcast interoperability across Allied naval communication networks (US Navy, UK DHFCS, and RAN MHFCS).
 
References
[1] 800Bd/800Hz (critical) FSK and STANAG-4285 Transmissions http://i56578-swl.blogspot.com/2026/08/800-bd-800-hz-critical-fsk-and-stanag.html
[2] Leonardo DRS, GA-205 Time Division Multiplexer datasheet — cleared for public release under OSR case no. 05-S-0976 (08.25.2007) https://www.leonardodrs.com/wp-content/uploads/2023/08/ga205.pdf
[3] https://www.sypaq.com.au/news/sypaq-subsidiary-bellinger-signs-historic-agreement-with-leonardo-drs/