Showing posts with label 8-ary/12800bps. Show all posts
Showing posts with label 8-ary/12800bps. Show all posts

19 May 2021

UK MoD 12800bps bursts: other oddities

I was just monitoring some interesting sequences of 2400Bd PSK bursts occupying 3 out of 6 channels (each 3 KHz width) according to alternate timings of 40 and 20 seconds: frequencies 5742.5, 5748.5, and 5757.5 (all USB). The 119.6 ms ACF value corresponds to a framing of 287 symbols @2400Bd, ie the waveform STANAG-4539: more precisely, according to its self-identifying feature, a 32QAM modulation at 8000bps speed (Figure 1).

Fig. 1 - STANAG-4539 framing structure

Unfortunately, I was not able to get the expected 32QAM constellation but only few states of the outer 32QAM ring (Figure 2).

Fig. 2

I was a bit puzzled until I realized I was seeing an already known signal, more precisely the UK MoD 12800 bps 64QAM bursts [1]: the signals were just badly-tuned (300 Hz frequency offset).
A question arose almost immediately: why, despite the out-of-tuning, the signals are recognized as a 32QAM/8000bps modulation with a sub-carrier error of only 0.2 Hz?  I thought about a decoder error, but examining the 103 preamble' symbols that carry information regarding the data rate and interleaver settings, I found that those are actually different in the two cases of 5757.20 and 5757.50 Hz (Figure 3).

Fig. 3 - data rate and interleaver settings

I repeated the measurements of modulation and speed using other tuning frequencies, results are in the table below. Notice the discrepancies between the tuning frequency and the error detected by the decoder, expecially in 5757.20 and 5757.50 cases where the signal seems to be exactly tuned:

According to SATANAG-4539 #2.1, the accuracy of the sub-carrier frequency shall be 3×10^-5, ie a max tollerance of ±172 Hz @5,757 MHz is allowed: probably the autobaud feature fails since that kind of "symbols distortion"?

Assuming 64QAM/12800bps as the actual mode (as already assumed at the time), I tried to demodulate a same single burst using two different decoders (say A and B, without naming them). The expected length of the bitstream will be:

13 frames × 256 = 3328 symbols × 6 = 19968 bit

Fig. 4
Results are a bit perplexing:

- decoder A, 1536-bit length of the resulting bitstream, seems to successfully demodulate only one frame (1 × 256 × 6)
- decoder B, 36864-bit length of the resulting bitstream, seems to demodulate 12-out-of-13 frames and, in some way, duplicate the results (12 × 256 × 6 × 2)

(the 5750.20 KHz signal was resampled to 8000 Hz before its demodulation).

Fig. 5

I don't know if the use of only 8 out of 20 points of the 64QAM outer ring confuses the decoders, however I think these bursts (and maybe the waveform?) are not fully clarified yet.

5 April 2019

8-ary constellation bursts at 12800bps data rate (4)

Just another followup about the 8-ary constellation bursts. By the way, I also want to point out the interesting work that Christoph is pursuing in his blog.

Recently, Martin G8JNJ pointed out two new series of bursts on 2501.2 KHz and 2668.2 KHz USB. Bursts are STANAG-4539 12800bps compliant and use 8 points of the outer ring of the QAM-64 constellation, just like those covered here. The timing of the bursts is a further analogy and appears "connected" to the two previous and following clusters (Fig. 1): this way - if my guess is confirmed- we have now a total of seven clusters, or sets, of channels.

Fig. 1
It's worth noting in the tables below that the sequence 2082.2->7822.2 KHz now lasts about 40 seconds (A-G) while the same sequence had previously (i.e. before the two new bursts appear) a duration of 36 seconds (A-F). Therefore, since the introduction of the 2501.2 & 2668.2 KHz bursts have affected the duration of the 2082.2->7822.2 KHz sequence, I'm quite positive that all the bursts belong to the same sequence. But it's just a my guess.


 
Fig. 2 - the whole sequence A->G

downloads:
https://yadi.sk/d/RlxGYd3sYkWH-A
https://yadi.sk/d/ozXrjS54njfLGw

31 January 2019

8-ary constellation bursts at 12800bps data rate (3)

This is a follow-up of the posts about the "clusters" of S4539 12800bps bursts, all posts including this one are grouped here.
Since a couple of days it's possible to hear both the peers, don't know if it's due to new test sites or increased powers but previously the "called" station was not heard (or maybe it did not even exist). As you see, the "called" listens on f2 while it simultaneously replies on f1 (the same for f2/f3 and in all the six clusters) as well as the "caller" station puts its call on f2 while it simultaneously listens on f1 (Fig. 1); the interval between the call and the reply is about 319 ms. Maybe they use staring and synched SDRs?

Fig. 1
This simultaneity is also noted between the lower frequency of a cluster and the higher frequency of the preceding one, as shown in Fig. 2. Particularly, Figure 3 shows the timings between the last and the first cluster (the different signal strengths in Fig. 3 depend on the different locations of the two used KiwiSDRs).


Fig. 2 - timings between two consecutive clusters
Fig. 3 - timings between the last and the first cluster


25 November 2018

8-ary constellation bursts at 12800bps data rate (2)

Some other observations and updates about the S4539 12800bps 8-ary constellation already discussed here: this post was possible thanks to the collaboration of my friends AngazU, Christoph, Martin G8JNJ, and Sergio.

As shown in Figure 1, the polarity of mini-probes matches the 12800Ubps (6,6,2) setting so no doubt about the proper operation of the used decoders, primarily the Harris RF-5710A model.

Fig. 1a) 287 symbols preamble and sync sequence (red);
Fig. 1b) the actual "6,6,2" setting read from the preamble;
Fig. 1c) the theoretic "6,6,2" setting

Now look at the on-air symbols shown in Fig. 2: S4285 symbols (Fig. 2a) are exactly mapped to a PSK-8 constellation but the S4539 symbols being analyzed occupy different points (Figs. 2b,2c). It looks like a subset of the QAM-64 symbols is used for data  while the 4 "circled" points are the QPSK symbols of the mini-probes. Thus, since no interleaving and no coding are used in 6,6,2 mode (12800bps), the source data must be prepared such that after the scrambling the resulting 6-bit numbers will be mapped only to a 8-point subset of the QAM-64 outer ring. This makes sense and clarify the 12800bps speed, though we do not figure out why this is done.
 
Fig. 2
Figure 3 shows the plots of one frame obtained by Christoph: 256 data symbols + 31 mini-probe symbols: the 31 mini-probe symbols were descrambled and are at I=1,Q=0. As you can see the other points fit perfectly the 8 out-of-20 points of the QAM-64 outer ring [7 3 24 56 35 39 60 28].

Fig. 3 - 256 data symbols + 31 mini-probe symbols
These eight symbols have interesting structure: the 3,7,24,28 symbols are the same of  35,39,56,60 unless the left-most bit and they are at the same distance (32)

 3 000011
 7 000111
24 011000
28 011100

35 100011
39 100111
56 111000
60 111100

According to Christoph, the 6 bits are ABBCDD where ABC identify the point and D+B=1 mod 2. The ABC bits stream exhibit a 480-bit leghth period (Fig. 4).

Fig. 4
Back to the transmissions, our monitoring revealed that the entire sequence lasts about 36 seconds and consists of 6 "clusters", or "sets", each consisting of three channels with same spacing and arrangement:


Lately, our friend Martin G8JNJ noticed in the lower cluster A1 A2 A3 one weaker set (TDoA 100% St Eval) every 30 seconds (approx) and one set of stronger ones every three to five  minutes (approx) which he wasn't able to TDoA. "So that I think I'm hearing more than one transmitter site. It's proving to be very difficult to TDoA the second one, as they transmit much less frequently, but there is a big difference in RX signal strength between the transmissions", Martin says.
A friend of AngazU suggested that they could be developing some kind of turbo equalizer or similar. These emissions would be tests of a  training sequence and they would be measuring errors, convergence time and other parameters under different conditions. Just a guess, if they  succeed, we will see the  full constellation.

By the way, subjecting for example the F1 channel to the k500 decoder it prints out only 1536 decoded bits although it correctly recognizes the 12800U setting. As shown in Figure 5, each burst is made up of 13 frames for a total of 256x13=3328 QAM-64 data symbols that make 3328x6=19968 bits of data! (no interleaving neither coding is used in 12800U mode). Thus it seems that only one data frame (256 x 6) is processed by k500 (possibly the first one?): maybe it's a decoder limitation due the short burst duration? Note that it does not happen when I use the RF-5710A modem.

Fig. 5
(to be continued)

25 September 2018

8-ary constellation bursts at 12800bps data rate (likely UK-MoD)


These transmissions consist of spread band "cluster bursts" which are sent in sequential order on several frequencies, ie the clusters are not sent simultaneously (Figure 1). Each cluster lasts about 5200ms and is composed of three 1600ms bursts separated by 200ms and spaced by 6000Hz (b1-b2) and 9000Hz (b2-b3). My friend KarapuZ spotted other clusters on 3.3, 4.0, and 4.7 MHz and published a youtube clip that shows a complete cycle [1], therefore it seems that "five" is the number of the used clusters, for a total of 3x5 = 15 "burst channels".


Fig. 1 - 5.7 and 7.8 MHz clusters
Probably they use staring SDRs, and in my opinion it could be an implementation of STANAG-4539 Annex H "Technical specifications to ensure interoperability of application communication systems using multiple discrete HF channels serial waveform", also provided in 110C Appendix F.
 
The bursts use the STANAG-4539 2400Bd and a 8-ary like constellation with a data-rate of 12800bps uncoded (!?!), a similar waveform (S-4539 12800bps/U bursts) was heard on 14 June on 7807.2 KHz/usb [2], just the same frequency of burst b1 of the 7.8 MHz cluster!
12800bps, also detected by my Harris RF-5710A, is clearly unlikely since PSK-8 modulation at a symbol rate of 2400Bd makes a gross bit transfer of 2400x3 = 7200 bit/sec, which in turn allows max data rates of 3200bps and 4800bps (if uncoded). So, 12800bps or PSK-8 seems an inconsistent data rate.
Fig. 2 - incosistent data rates
The frame structure of the bursts matches the one specified in S4539 #4.3. An initial
preamble is followed by data frames of alternating data and known symbols. Each data frame consists of a data block (256 data symbols), followed by a mini-probe (31 symbols of known data).  It's worth noting that each burst (consisting of 12 data blocks) curiously ends up with a half (½) data block.
Since the waveforms match, I wonder if they use an alternative/reserved coding that somehow deceives the RF-5710A modem. The only way to shed light on the wrong data rate is look at the received preamble.
Data rate and interleaver settings are explicitly transmitted as a part of the waveform in the second 103 symbols of the initial preamble and are coded as described in S4539 #4.3.1.1 "Synchronisation preamble" page B-11

The tribit symbols D0, D1, and D2 take one of 30 possible sets of values to indicate the data rate and interleaver settings:


The Modulo operations are meant to signify that the data rate and interleaver coded values (D0,D1,D2) are used to shift the phase of the Barker code 0,4,0,4,0,0,4,4,0,0,0,0,0.
Now look at the phase diagram of the received preamble (Fig. 3): data rate setting consists of two equal sequences plus a third one, such a symbols pattern can be originated only by the values "0,0,4", "6,6,2", and "2,2,6" of the Table 4.3.1.1-1 above reported.

Fig. 3 - phase variations of the received preamble
I'm less than a novice GNU-Octave coder so I asked my friend Christoph to write a little script to extract the symbols from the received preambles, results are surprising: quoting his email "the first few symbols of the preamble are not transmitted but the rest fits perfectly D0,D1,D2 = 6,6,2", therefore the 12800bps setting seems to be coded into the received preambles. I edit his script to improve the display of the 39 symbols related to the setting and replicated the tests: results are shown in Figure 4.
Fig. 4 - a) 287 symbols preamble and its sync (red); b) the actual "6,6,2" setting read from the preamble; c) the theoretic "6,6,2" setting
Since the 12800bps settings is correct, the used 8-ary constellation can't be a PSK-8 modulation!

But oddities do not end there.
Assuming that - in some ways - the decoding is correct, what you get is that each single burst carries 1536 bits of data and by aggregating the bursts of a single channel you will end up to see a 1536-bit protocol which looks like the DHFCS multiplexed stream (Figure 5).

Fig. 5 - demodulated streams of the 7.8 MHz cluster
Notice that each burst carries different contents: maybe the source contents are spread on the five clusters (ie on the 15 burst channels)?
I just add that all TDoA runs point to Cornwall, maybe St.Eval? if so, I wonder if Babcock/DHFCS are testing/using a  S4539 burst system in addition to the S4285 based system.
Fig. 9 - result of TDoA

(to be continued here)

[1] https://youtu.be/iZCq4DnlNxo
[2] http://i56578-swl.blogspot.com/2018/06/stanag-4539-unexpected-data-rate-of.html

https://yadi.sk/d/EhPc_M8G7jC-mg 

15 June 2018

STANAG-4539: unexpected data rate of 12800 bps

Long transmission (hours) of STANAG-4539 8PSK 2400 Bd bursts spotted on 14 June morning on 7807.2/usb:  each burst lasting 1680 ms and composed of 13 x 287 tribit symbols frames. It's interesting to note the uncoded 12800 bps speed detected by the 5710-A modem: using 8PSK at a modulation rate of 2400Bd, the the maximum data rate obtainable is 4800 bps (7200 bps on-air) therefore there is something wrong somewhere (a data rate of 12800 bps is obtainable using QAM64 modulation at 2400 Bd). STANAG-4539 is an "auto-baud" waveform, so perhaps they use a modified preamble that misleads the modem.
A run of TDoA multilateration says Cornwall (UK) as Tx location, possibly UK MoD DHFCS tests from St.Eval? 

Fig. 1
Fig. 2
Fig. 3


https://yadi.sk/d/bpzDxsBX3Xzkn3