Showing posts with label Chinese Waveforms. Show all posts
Showing posts with label Chinese Waveforms. Show all posts

24 October 2024

Chinese 4x4 modem (probably PLA Navy)

Chinese 4x4 waveform consisting of two groups of four PSK channels modulated at a rate of 75 Bd, the two groups are spaced by 450 Hz and channel separation is 300 Hz. The signal spreads about 2500 Hz bandwidth (Figure 1). The modem is probably used by the The People's Liberation Army Navy, also known as the People's Navy, PLA Navy or simply Chinese Navy.

Fig.1 - Chinese 4x4 modem

I isolated a single channel to identify speed and what kind of PSK modulation is used, the spectrum of the third order harmonics (x^3) shows the typical central line (subcarrier frequency) of PSK8 modulation; indeed, the phase plane exhibits a 8-ary constellation, but there is no transition paths through the center (as in case of PSK-8) and the relative constellation (Diff-1) is a 90 degrees rotated QPSK: this suggest the use of π/4 DQPSK  (Differential Quadrature phase Shift Keying) modulation.
The π/4 DQPSK modulation uses two QPSK constellations offset by 45 degrees (π/4 radians) and transitions occur from one constellation to the other making the illusion of a PSK-8 modulation; data bits are encoded by phase changes, instead of absolute value of the phase. By the way, the π/4 DQPSK modulation format is also used in TETRA.

Fig. 2 - π/4 DQPSK modulation @ 75 Baud (single data channel)

The resulting bitstream after differential demodulation has a 22-bit (11 dibit symbols) length period, as shown in Figure 3.

Fig. 3 - demodulated bistream (single data channel)

The preamble preceding the data is also modulated in π/4 DQPSK mode at a speed of 75 Baud (Figure 4). The bitstream resulting from its demodulation (Figure 5) is formed by the repetition of a 22 bits length pattern, likely for AGC, fine-tuning, and synchronizing. Attempts to find the generating polynomial suggest x^23+x^22+x+1. In addition to the same period length (22 bits), the "similarities" between the two bitstreams (data Vs preamble) is to be noted.

Fig. 4 - π/4 DQPSK modulation @ 75 Baud (single preamble)

Fig. 5 - demodulated bistream (single preamble)

Messages addressed to multiple recipients are queued in a same transmission and, as shown in Figure 6, messages may have three different "formats" which here I call mode-A, mode-B, and mode-C (please notice that the "designations" used are only mine and are introduced just for convenient reference). In a same transmission may cohexist messages sent in different modes.

Fig. 6 -  messages' formats

mode-A examples
3BLK 3BLK 3BLK DE JQ02 JQ02 JQ02
3BLK 3BLK 3BLK DE JQ02 JQ02 JQ02
3BLK 3BLK 3BLK DE JQ02 JQ02 JQ02
JYJYJYJYJYJY HR MSG GA
41149   25   51   1001   1605
UXEE---Y9R
1213 0044 4433 7814 2404 2166 5873 4084 6463 2053
3462 8669 3268 6541 0511 3039 3930 2944 3388 6895
7921 4851 3871 2507 0062
MSG AGN
41149   25   51   1001   1605
UXEE---Y9R
1213 0044 4433 7814 2404 2166 5873 4084 6463 2053
3462 8669 3268 6541 0511 3039 3930 2944 3388 6895
7921 4851 3871 2507 0062

B81L B81L B81L DE JQ02 JQ02 JQ02
B81L B81L B81L DE JQ02 JQ02 JQ02
B81L B81L B81L DE JQ02 JQ02 JQ02
JYJYJYJYJY HR MSG GA
82230   23   51   1001   1025
UXEE---YXE
1243 0255 1667 1611 3469 2053 0063 5501 7301 1940
2587 7681 6966 7814 0584 6978 0091 2647 7217 7042
7179 5854 5844
MSG AGN
82230   23   51   1001   1025
UXEE---YXE
1243 0255 1667 1611 3469 2053 0063 5501 7301 1940
2587 7681 6966 7814 0584 6978 0091 2647 7217 7042
7179 5854 5844

3BLK 3BLK 3BLK DE JQ02 JQ02 JQ02
3BLK 3BLK 3BLK DE JQ02 JQ02 JQ02
3BLK 3BLK 3BLK DE JQ02 JQ02 JQ02

3BLK called station address
from
JQ02 caller station address

JYJYJYJYJYJY HR MSG GA
JYJYJYJYJYJY ?
HR MSG GA  are telegraphic abbreviations:
HR = here or hear
MSG = message
GA = good afternoon

it is common to read other abbreviations such as "message repetition":
MSG AGN  
MSG = message
AGN = again 

or even the "link termination"
AHR ZNN SK
AHR = ?
ZNN = All clear of traffic now
SK = End of contact

41149   25   51   1001   1605
41149 ?
25 number of the 4FGs groups that make up the message (seems to be always odd)
51 message group identifier?
1001 date (mmdd)
1605 local time (hhmm), maybe for drafting

UXEE---Y9R
probably these are military addresses which are expressed as "source---destination"; at least in my recordings, the source address seems to be composed of 4 digits. Cross-referencing the callsigns of the initial calls gives this (small) table:

JQ02 = UXEE
82VP = YXY
3BLK = Y9R
B81L = YXE
IJDW = YXX
THGM = 21II
WMBZ = 227
F9ED = 201
LTPE = 811
FMRK = 818

The  messages consists of 4-digit codewords (here referred to as 4FGs groups or simply "groups") which are sent 10 per row in enumbered blocks, each block consisting of 100 groups. Given that the Chinese writing system is by nature nonalphabetic and thus noncipherable, Chinese cryptography was bound to the use of codebooks (Chinese Telgraph Code, Chinese Standard character table or another unknown military codebook) containing a max of 10000 characters (0000-9999). 

1213 0044 4433 7814 2404 2166 5873 4084 6463 2053
3462 8669 3268 6541 0511 3039 3930 2944 3388 6895
7921 4851 3871 2507 0062

Interestingly, the 9th and 10th groups of the first line of each message block do not follow the rules seen in the case of similar 4FGs messages sent via M-39 modem (Chinese Air Force/Air Defense) [1]. Also note that the message sent to B81L contains the string: 82230 23 51 1001 1025 i.e. same date (1001, October 1st) but earlier time (1025) than that reported in the same string of the message sent to 3BLK (1605). In this regard, it should be noted that the timestamp of the recording is 2024-10-01T14_40_13Z and the official time of China (CST, China Standard Time) is UTC+8 so at the time of transmission it was 2240 Chinese local time. Perhaps it is a selective repetition of some messages sent during the day, it could also be following specific requests (it happens also in NATO fleet broadcasts).

mode-B examples
82VP 82VP 82VP DE JQ02 JQ02 JQ02
82VP 82VP 82VP DE JQ02 JQ02 JQ02
82VP 82VP 82VP DE JQ02 JQ02 JQ02
JYJYJYJYJY HR ++ GA
++
59628   1724
UXEE---YXY
6475/0/0/07/8877/08677/96277/767/74
MSG AGN
++
59628   1724
UXEE---YXY
6475/0/0/07/8877/08677/96277/767/74

IJDW IJDW IJDW DE JQ02 JQ02 JQ02
IJDW IJDW IJDW DE JQ02 JQ02 JQ02
IJDW IJDW IJDW DE JQ02 JQ02 JQ02
JYJYJYJYJY HR ++ GA
++
27016   1724
UXEE---YXX
2624/9/4/07/8587/95777/92087/977/75
MSG AGN
++
27016   1724
UXEE---YXX
2624/9/4/07/8587/95777/92087/977/75
 
These types of messages are much more cryptic and beyond the initial "sentences" it is difficult to guess the meaning of the digits separated by slashes.

mode-C examples
NR920 CK93 35 1011 1447 --
215 203 011 326 314 004 773 353 246 351
420 938 407 445 486 382 005 773 353 246
351 403 938 417 445 486 382 006 773 353
246 351 403 938 417 445 486 382 008 773
353 403 938 417 445 486 382 009 773 357
403 938 417 445 466 486 382 010 773 357
403 446 486 382 011 773 353 403 938 417
445 466 486 382 012 773 357 403 447 486
384 938 383 013 773 357 372 403 446 486
758 483 382
MSG AGN
NR920 CK93 35 1011 1447 --
215 203 011 326 314 004 773 353 246 351
420 938 407 445 486 382 005 773 353 246
351 403 938 417 445 486 382 006 773 353
246 351 403 938 417 445 486 382 008 773
353 403 938 417 445 486 382 009 773 357
403 938 417 445 466 486 382 010 773 357
403 446 486 382 011 773 353 403 938 417
445 466 486 382 012 773 357 403 447 486
384 938 383 013 773 357 372 403 446 486
758 483 382

AHR MSG GA

NR921 CK165 35 1011 1447 --
215 203 011 326 004 773 318 357 407 445
486 319 353 938 354 373 418 445 486 758
483 005 773 318 353 417 938 407 445 486
319 357 372 407 938 418 445 486 758 483
006 773 318 357 417 938 407 445 486 319
357 372 407 445 486 338 758 482 008 773
318 357 417 445 486 319 357 372 417 938
418 445 486 338 758 482 009 773 318 357
372 417 445 466 486 758 483 319 354 372
417 938 418 445 486 758 483 010 773 318-1
357 403 446 486 319 357 403 446 938 445
486 011 773 318 357 417 445 466 486 319
357 372 417 938 407 445 486 758 483 012
773 318 353 403 447 938 446 467 486 319
353 403 446 938 445 466 486 013 773 318
354 246 353 403 445 466 486 319 357 372
404 445 486 758 483
MSG AGN
...
...

This type of message follows the same rules seen in mode-A except that the numeric groups are made up of 3 digits (3FGs) instead of 4.
 
Monitoring was possible thanks to KiwiSDRs located in Osaka and Okayama (Japan) [2][3].
(to be continued)
 

9 October 2023

Chinese Air Force/Air Defense (PLAAF) async M39

These transmissions were recorded on the 10 MHz band (10388.30, 10401.0, 10348, 10436.0, ... all KHz/USB) mostly after 1100UTC by means of the FlyDog SDR located in Oita, Japan [1].  Usually, op-chats and data transfers follow the link setup by MS 188-141 handshakes: some observed ALE IDs are:

111 164 166 184
212 219 220 222 223 231 236 254 257 273 283 290
320 347 383
428 438 455 476 485 490 498
513 526 552 583 595
603 609 612 620 653 658 696
738 747 758 775 778 781
839
910 966

According to a friend of mine, the op-chats are in Mandarin Chinese with a northern accent.

Fig. 1 - one of the recorded transmissions

The analysis of the traffic waveforms reveals the use of MIL 188-110A Appendix B (also referred to as M39): an OFDM modulation technique using 39 orthogonal subcarriers 56 Hz spaced and an additional unmodulated Doppler reference tone at 393.75Hz. The 39 tones are are PSK4 modulated the way that, although data rates can vary from 75 bit/s to 2400 bit/s, a fixed baud rate of 44.44 Bd arises in any case (see Figs 2,3). In these transmissions, usually, the speed of 150 and 300 bps is used.

Fig. 2 - OFDM analysis

Fig. 3 - analysis of a single tone

Given the operator's language, the ALE IDs and the used mode (188-110 App. B) I'm quite sure that the People's Liberation Army Air Force (PLAAF), also referred to as the Chinese Air Force/Air Defense, is the user of this net: since the signals strength, it could be the Southern Theater Command Air Force... but the latter is just a my guess. 

Analyzing in detail the Chinese M39 waveform, however, some differences emerge in the structure of the preamble compared to what is specified in the related MIL-STD #B.5.4.1: "Prior to the transmission of data, a three part preamble shall be transmitted. Part one shall last for 14 signal element periods and consist of four equal amplitude unmodulated data tones of 787.5, 1462.5, 2137.5, and 2812.5 hertz (Hz). Part two shall last for 8 signal element periods and consist of three modulated data tones of 1125.0, 1800.0, and 2475.0 Hz. Part three shall last for one signal element period and consist of all 39 data tones plus the Doppler correction tone". 

 
Indeed, as shown in Figure 4, since one signal element period corresponds to 22.5 ms, part one of the Chinese M39 preamble lasts for 11 signal element periods (247.5ms) thus is a bit shorter (I think we may accept an error of about 500µs). Block sync may depend on the speed and interleaver length. Also notice the lower amplitude of the 1462.5 tone, probably caused by modem malfunction.
 
Fig. 4 - plain and Chinese M39 waveforms

Figure 5 shows the two preambles as function of the 22.5ms signal element period: the difference, however marginal, do not affect the demodulation of the signal.  
 
Fig. 5

 
The demodulated bitstreams have a 8N1 asynchronous start/stop character format and exhibit a quite clear repeated "patterns" as shown in Figure 6.  

Fig. 6 - M39 demodulated bitstream

After the removal of the start/stop bits, the decoded messages consist of 4-digit codewords (here referred to as 4FGs groups or simply "groups") which are sent 10 per row in enumbered blocks, each block consisting of 100 groups: it's the same format of the messages used by the so-called "VC03" (a Chinese Air Defense net). Below a pretty long message consisting of  599 groups: 

3415 3415 3415 XXXXJGJGXXX 11
290 130191209032184  fb0237.txt230902190040                                                                                 
016/JC   599   42   0902   1900
6497---1549---1114---1113---1355---1822---3177---
1482---1362---4499---1896---1836---1547---6497

3421 8994 2267 1703 1963 0520 8446 4305 0147 0033
8234 6413 4554 2374 5684 5250 4025 9563 9069 9119
6871 0179 4924 0782 9157 6996 9815 4064 4061 5312
2104 4338 7161 2751 5486 9607 6046 3198 7947 8450
6379 4171 4671 3204 5836 1693 1067 6773 0508 7636
1205 2881 8767 2810 4537 8465 9718 7606 8460 8964
0973 4238 4192 3252 9602 5332 8917 5801 0870 2025
3204 7083 8983 7851 0818 7935 4658 9254 7035 1034
3530 2940 3279 5623 8282 9146 5949 9671 3504 3884
0424 1297 4832 2723 6395 6248 8661 0136 7304 6189-1

4927 2716 4521 6114 3627 2713 7346 0872 0147 0036
7124 6002 1205 9793 6873 9063 2598 4553 7238 5230
2417 5731 4632 7882 0024 8903 5881 4908 3413 4782
1645 9492 2871 2046 4529 8945 1400 3960 1606 6069
4536 6500 6930 9438 7990 3048 2317 1048 2194 6794
9505 6481 6721 3068 3012 6485 8269 8910 8425 9872
3693 3945 6290 5309 3041 8664 5278 2561 5214 1182
5026 4037 5737 0198 7194 6875 7871 9574 5860 4351
8702 3783 0552 2174 8260 6816 1464 1338 7970 8534
5467 5858 3591 9312 3415 9096 6505 1319 6787 9392-2

4823 5741 3721 8794 3447 6443 5719 9243 0147 0039
9838 2061 1301 7473 4990 2042 7942 9815 2474 4963
8575 3541 3992 7510 2596 1213 6767 8287 7648 9442
2064 5691 3532 6702 3065 5821 7042 1278 4397 9264
8118 1230 0787 2839 0565 8536 7865 5103 0805 2943
9596 2852 7545 0681 2070 8275 1526 9851 1009 8505
9095 7276 5781 6954 1090 0929 8196 3638 3708 8791
0290 4030 5894 8998 0680 1568 2369 6030 7573 1938
7423 7581 6426 6841 3667 1462 3290 3034 0557 1661
7672 4160 3484 6334 7595 6481 5994 1763 8012 2163-3

4591 7885 2907 3230 5731 3794 3807 6064 0147 0042
4082 3194 1908 7554 8100 6734 9446 8777 5392 0143
8207 5150 2467 2563 8196 4095 5250 5803 2634 3185
4328 4183 5618 9824 5841 6432 2939 9793 2964 2793
1030 3797 8002 3491 3209 5180 5415 8661 1267 3201
3446 9114 5060 0797 7509 9781 8776 6254 2550 8280
7621 9429 1627 9467 8105 0280 9032 4173 1002 1590
6778 9809 1903 7640 8325 1672 5723 5850 8949 6487
9831 6883 3604 6232 6452 0429 2681 8417 4118 9840
5771 0509 8367 0194 5170 2763 9449 9796 0303 8130-4

5059 5293 9063 2156 9489 9177 7371 9543 0147 0045
7017 4024 1685 6761 0236 1671 3746 1446 0023 2320
4603 9204 2881 6004 4217 5904 7218 2583 1023 9095
8767 1881 8784 6978 7327 7858 4241 9911 7885 3927
9182 0598 5797 0941 4513 2231 0530 3698 3551 7237
3175 5438 9756 5798 3652 2297 3523 0089 6867 6347
8438 8634 9150 7040 7090 4302 2361 9513 3465 6623
6548 3582 9066 6074 1874 6228 6708 8918 4925 6506
6815 6041 4016 5489 6432 5229 7195 7546 1408 7515
3968 3150 5926 4840 0401 5423 8941 3897 6327 0219-5

5831 1584 2697 6824 1508 2155 2370 5037 0147 0048
0360 6101 8113 1384 1920 7382 9193 2805 8949 8607
7008 4942 1396 5484 0425 0336 9724 0384 5954 1456
8193 7607 9551 6942 1345 0965 4617 5614 5719 2626
3783 8968 1982 7037 9832 9302 0404 4350 3167 5601
4670 8131 8104 2693 8978 3425 5780 3908 1954 2061
6095 1336 2823 4076 0348 8515 7184 3558 9667 7132
2781 3632 9504 7075 1225 5310 5030 8578 9487 9269
3616 8278 4240 9210 9764 8274 5963 9837 6049 7041
3299 0594 6226 7475 1496 5379 7668 2512 7247

Although I don't have a large number of demodulated messages at my disposal, only a few dozen so far, it's nevertheless possible to do some comments and parsings of the messages headers. As an example, Figure7 is an overall view of three complete 201-groups messages sent by the same station (the ALE ident 620) within minutes and on the same frequency (10401.0 KHz/USB), I also added the related ALE calls in the upper part of the messages. At this regard, unlike other protocols such as S-5066, must be noticed that the ALE addresses match those used in the message headers.

 
Fig. 7
 
As a format' example, I took the message #1 of Figure 7: you can check looking at the other two messages. 

MIL-STD 188-141A ALE:START TIS [620] TO [485]
the ALE call precceding op-chat and data transfer

1277 1277 1277 XXXXJGJGXXX 11
1277 1277 1277 type of message? some seed indicator? (always in the format "nnnn") 
XXXJGJGXXX this string is present in the headers of all the message I've heard, don't know its meaning/purpose. At glance, it looks like the Russian flash "XXX XXX" messages... By the way, in the Chinese 4x4 messages it's possible to see a similar string "JYJYJYJYJYJY"
11 precedence indicator of the message? (happens to be the length of the preceeding string 'XXXXJGJGXXX')

485 311291609032620 fb6183.txt230906192112
485 digit ALE ID of the called/destination node (as from the ALE call)
311291609032620 timestamp in reverse order (from right to left: ssmmhhddmmyy), ie 23.09.06 19:21:13
311291609032620 digit ALE ID of the caller/source node (as from the ALE call)
fb6183.txt the file name being sent, "6183" seems to be a sequence number
230906192112 timestamp in the format ymmddhhmmss, ie 23.09.06 19:21:13, no time zone indicator. Indeed, the transmission was registered at the same date at 11:21:45 UTC (a few seconds after) and that makes sense since the user time zone is UTC+8. In some messages this field is not present.
It's worth noting the difference of 1 second between the two times reported in the header, perhaps the earlier time is related to the file (its reception?) and the more recent one is the time related to the formation/sending of the message. Sometimes that interval is longer, as for example 17:50:54 Vs 17:53:22 (223571); probably a timestamp for transmission and another one for saving the .txt file

150 201 72 0906 1900
150 likely it's the daily serial number of the message sent by the sender, in these samples, message #151 miss. In certain cases it's reported  using the "nnn/CCK" format (see below)
201 number of the 4FGs groups that make up the message
72 message group identifier?
0906 date (mmdd)
1900 rough time (hhmm), maybe for drafting

0712---4771
0712 four digit military address of the originating establishment/unit?
4771 four digit military addresse(s) of destination establishment(s)/unit(s)?
(it's interesting to notice that there is a one-to-one matching between the mil address of the originating unit and the ALE ID of the caller/sender node: in Figure 7, for example, 0712 refers to the ALE ID 620, as well as 4771 to 485, 4321 to 476, 4351 to 747). Only the node with the ALE ID 111 seems to use more than one military address (I noted 6497, 7234, 8759).
If I'm right about the meaning of these fields, then the nodes seem to act like a forwarder, for example in the headers below the destination addresses are more than one. Note also the different format of the (supposed) daily serial number of the message:

3415 3415 3415 XXXXJGJGXXX 11
290 130191209032184  fb0237.txt230902190040                                                                                 
016/JC   599   42   0902   1900
6497---1549---1114---1113---1355---1822---3177---
1482---1362---4499---1896---1836---1547---6497

The same for the ALE global call issued by the node 198 (Figure 8):
[2023-09-14 11:17:04] MIL-STD 188-141A ALE: TIS [198] TO [@?@]
indeed this call was then followed by the transmission of a message originating from node 111 (not 198!) and addressed to node 222 (all ALE IDs)
 
1274 1274 1274  XXXXJGJGXXX  11         
222 957191419032111 fb5042.txt230914191456                                                                                 
 
The same message was transmitted three consecutive times using three M39 segments and leaving the headers unchanged.
 
By the way, the 8660 ms duration of the global ALE call (ie a "scanning call") provides some indications about the number of the available channels in the 10 MHz band: assuming full compatibility with MS-141, the scan list should consist of approximately 10 channels (1). As shown in Figure 8, in order to be sure to reach all the stations, the global call is five times transmitted (the first four global calls are followed by a TWAS).

Fig. 8

The number of the 4FGs groups in a message is always odd and message lengths seem to be standardized (199, 201, 499, 599 groups). Could this be due to the messages being stadardized reports or does it indicate fillers? Anyway, I do not know - and I don't care(!) - contents/purposes of these messages, however out of curiosity I did some research on the web and found some interesting articles and documents, even if they are historical [2][3][4].
Given that the Chinese writing system is by nature nonalphabetic and thus noncipherable, Chinese cryptography was bound to the use of codebooks rather than ciphers [2]. Therefore the use of 4FGs groups indicate either the use of the Chinese Telgraph Code (CTC, Mainland ed. 1983) (2), the Chinese Standard character table (GB 2312-83) or another unknown military codebook containing a max of 10000 characters (0000-9999).

It's interesting to study the values of the 9th and 10th groups of the first row of each block of the messages: as you see in Figure 7, the 9th has a costant value (0177) while the value of 10th is incremented by 1, also passing from one transmission to another (say a "transversal" increment): I noticed this feature in many messages:

message 1
4387 1271 8451 5086 9408 2928 9293 8639 0177 0029
9795 3224 4617 5389 5581 8337 9987 9763 0177 0030

message 2
9687 8557 2807 4801 5091 8197 5497 5683 0177 0031
8070 5341 9351 8807 3837 9663 0992 9425 0177 0032

message 3
5031 2635 3964 6880 5961 0957 0937 0613 0177 0033
8091 4724 1223 4879 8728 2646 4051 6061 0177 0034

In some messages, as the 599-group one reported before, while the 9th group does not change (0147) the 10th is incremented by 3

3421 8994 2267 1703 1963 0520 8446 4305 0147 0033
4927 2716 4521 6114 3627 2713 7346 0872 0147 0036
4823 5741 3721 8794 3447 6443 5719 9243 0147 0039
4591 7885 2907 3230 5731 3794 3807 6064 0147 0042
5059 5293 9063 2156 9489 9177 7371 9543 0147 0045
5831 1584 2697 6824 1508 2155 2370 5037 0147 0048

But this is not the only strangeness. Indeed, there are messages as the one shown below where both the 9th and 10th groups have always the value 0000: in these cases the message serial number has always the "nnn/CCK" format.

1274 1274  1274  XXXXJGJGXXX  11  
111 100371509032222 fb1945.txt230905170941                                                                                 
052/CCK   199   96   0905   1700
1836---6497

9385 5023 9762 6394 3051 5012 4576 2836 0000 0000
4682 2013 5471 1602 0749 9482 6073 6938 3182 4198
9674 9465 4075 5974 5437 4689 2043 3586 1498 7951
3561 1763 8105 4706 5087 4025 4387 9784 6470 8036
8039 8067 9135 1573 2765 2764 5196 0781 9056 9037
7308 4862 3194 4728 2381 6901 1556 5814 5162 3021
8075 9104 9536 8937 2560 9261 7032 9371 4825 9712
9682 3104 4190 1492 2981 2069 7853 4273 9156 1583
4728 1584 8609 3528 7249 9236 3961 4672 5104 6379
2016 6104 8910 9601 2037 2754 8357 2958 4285 3490-1

6485 9832 5902 7802 4504 7591 4973 9182 0000 0000
8501 2063 3872 6187 1398 5784 6482 6348 2637 6293
5674 2403 4865 9760 9406 1806 2651 1261 5670 3245
6591 2546 6851 2075 9304 7284 3729 1289 9674 3664
8140 3176 7392 4508 6072 6927 8592 8705 6053 8159
0549 5037 2681 3106 6334 0437 8014 6175 2091 9827
1603 7451 9134 7156 6546 5982 1379 5198 0159 9530
5632 7402 2087 7849 7545 4057 2160 4912 3284 4917
1793 1386 3418 8591 9603 9018 9256 3689 2879 4316
6018 7453 2097 9310 6513 8542 3247 5321 4758

Likely the 9th and 10th groups of the first row of each block have some "special" meaning and are not coded. At glance, the 9th seems related to the sender and the 10th seems something like a "block counter" ...but we have just seen that the value of 10th codeword maybe incremented by 3 or be "0000".

Some messages end with strings consisting of typical telegraphic abbreviations, as for example:
QSL ? = confirm?
HR NR 1271 TKS = here (I'm going to send) (message number) 1271 thanks
HR WK NR 1113 = here working/worked (message number) 1113
and a final sequence of "(unprintable)b Kvj" (hex 0862 4b766a) which could be the break and End-of-Message indicator.

Short messages (199, 201 groups) have 1-5 repeating groups while longer messages (499,599 groups) have 20-30 groups which repeat two or three times within the same message (except the group "0000"), common and usual characters such as space and linebreak don't seem emerge. It would be interesting to do a cross-checking of the messages in order to find the shared groups and their number, but to do this many other recordings are needed and therefore the opportunity to have a parked SDR and IQ recordings of that portion of the 10 MHz band.

(to be continued)

https://disk.yandex.com/d/ZvK55ZQMdTR4xQ

(1) 188-141 A.5.5.3.1 "If the called station (JOE) is known to be listening on the chosen channel (not scanning), the calling station (SAM) shall transmit a single-channel call that contains only a leading call and a conclusion (see upper frame in figure A-29). Otherwise, it (SAM) shall send a longer calling cycle that precedes the leading call with a scanning call of sufficient length to capture the called station’s receiver as it scans (lower frame in figure A-29). The duration of this scanning call shall be 2 Trw (784ms) for each channel that the called station is scanning". 

 
(2) The CTC is organised as 100 (1-100) pages each contaning 10 (0-9) lines of 10 characters (0-9). The 4 digits words in the message text are thus indices into the CTC and is interpreted as follows: two first digits = page, third digit = line and fourth digit = character position on line. CTC contains both simplified Chinese characters as well as Japanese kanji, cyrillic and latin characters and interpuncuation signs.
 

[1] http://flydog.web-sdr.net/?f=10388.30usnz11
[2] Ulug Kuzuoglu (2018): Chinese cryptography: The Chinese Nationalist Party and intelligence management, 1927–1949, Cryptologia https://disk.yandex.com/i/SbCtQ-Q02u8Slw
[3] http://cryptiana.web.fc2.com/code/chinesecrypto_e.htm
[4] https://en.m.wiktionary.org/wiki/Appendix:Chinese_telegraph_code/Mainland_1983 

3 October 2023

QPSK 2400Bd unid waveform (Chinese modem?)

QPSK 2400Bd waveform heard on 10221.0 KHz USB around 1400 UTC, probably a Chinese modem.

Fig. 1

Autocorrelation of the signal produces sharp 16.6 ms spikes tnat makes 80 bit or 40 dibit symbols (QPSK modulation) period at the rate of 2400 symbols/sec. Indeed, after demodulation the resulting bitstream has a framing of 40 symbols length consisting of 20 known symbols (probe)

33031002310112003303

followed by 20 unknown symbols (data): obviously, since QPSK, 1 symbol = 2 bit. 

Fig. 2 - autocorrelation and bitstream

After the removal of the 20 known symbols, the initial & ending data blocks show 64-symbols/128-bit patterns even if - actually - the ending blocks consist of a 32-symbols/64-bit pattern (as it was already visibile in Figure 2).

Fig. 3

Fig. 4

 As usually, comments are welcome.

[1] https://disk.yandex.com/d/5g-pEgBTLIxSmg

15 September 2023

Chinese Navy (PLA Ny) MFSK-8 125Bd & PSK2 2400Bd mixed mode

Complete and good quality data transfer session recorded on 10346.0 KHz/USB at 2153 UTC thanks to a KiwiSDR located in Oita, Japan [1].

Fig. 1 - Complete data transfer session

In the first part of the recording, the one related to the link setup, we can see standard MS 188-141 exchanges preceeded by bursts which use short MFSK-8 125Bd 250Hz segments (just the same tones of MS-141 but w/out the 6th tone). Perhaps they do not use this MFSK waveform as an ALE resource since they just use the standard 188-141. The involved ALE callsigns are AN1 & BN2, according to UDXF logs these IDs belong to the China's Navy (PLA Navy, People's Liberation Army Navy).

Fig. 2

The most interesting part is the one related to the data transfer. In my opinion, although constellation and state's transitions indicate a PSK4 modulation, the trajectories and the phase detector indicate that the main transmission mode is PSK2 (Figs. 3,4).

Fig. 3

Fig. 4

Probably, the four-state constellation is due to the inserts you may see below in Figure 5 (Figure 6).

Fig. 5

After PSK4 demdoulation, the resulting bitstream shows a well-defined 8-bit format.

Fig. 6

A Chinese PSK2 2400Bd serial waveform was already commented here: unfortunately, the bitstreams have different structure and patterns.

https://disk.yandex.com/d/IGweBYIwpB4dtg

[1] https://flydog.web-sdr.net/?f=10346.00usbz8

15 December 2021

Chinese PSK2 2400Bd serial waveform

This is my follow-up to an interesting post discussed on the radioscanner.ru forum about a PSK2 transmission of the Chinese Navy and started by my friend KarapuZ [1].  The raw demodulated stream consists of an initial preamble followed by data block consisting of a serie of 16-bit structures which are delimited by solid columns of "1"s or "0"s; the  period is calculated in 3072, 2048, and 1024 bit (128-bit length is due to the preamble sequences): the percentage values in figure 1 indicate respectively  the average ACF value for the given period, followed by the real value of the ACF for that period). Although the value of 1024 bit is the third positive result, both ACF and CCF indicate this as the most likely, being the other two integer multiples of it (x3, x2): this way, the stream consists of 64 "channels", each consisting of 16 bit.

Fig. 1

As noted by my friend Cryptomaster, the 15-bit information between the solid columns is parity-checked; thus, assuming the parity bit is added, as usual, after the data string, each row could consist of 14 bits for data (x) + 1 parity bit (p) + 1 delimiter bit (d): xxxxxxxxxxxxxxpd.
 
I proceeded to the parity check of some channels taking into account all sixteen bits, given that: 
 
* the add of a column of "0"s does not affect the parity checksum of the channel (even or odd); 
* the add of a column of "1"s switches the parity checksum (from even to odd and vice-versa).

The results for some channels are shown in figure 2, it's to be noticed that the max number of dd/even parity parity matches occurs after shifted the stream (offset >1). Looking at the sequence of the parity checksums of the examined channels, and considering the previous assumptions, we get an apparently random alternation of odd and even parity checksums. 

Fig. 2

After the differential decoding, the channels' "delimiters" disappear, so I tried to get the differential decoding of each channel resorting to some sort of workaround: basically I cut off the 16-bit channels from the plain decoding and then I differential decoded each of them. Yes I know, it's an hazard as it assumes that the channels are individually differential encoded (in real-world the first bit of the n channel depends on the last bit of the n-1 channel) ... however, in that way, the channels are all odd-parity checked and perfectly aligned (figure 3).

Fig. 3 - channels after their individual differential decoding

Since the use of a single parity bit cannot correct any errors, and given the amount of data transmitted, my idea is that they could use a kind of (16,k) coding with the overall parity bit added at the end of the codeword.

For what concerns the preamble sequence, it can be successfully descrambled using the polynomial x^18+x^13+x^11+x^5+x^2+1 (figure 4): it means that the preamble actually consists of a 128-bit pseudo-random sequence (PRBS) which is part of the M-sequence generated by the aforedmentioned polynomial.

Fig. 4 - 128-bit PRBS used as preamble

https://disk.yandex.com/d/b8oQdmhTJcJhPg

[1] http://www.radioscanner.ru/forum/topic40144-14.html#msg1540957 

30 September 2017

Chinese PSK-2 ...and errors in its baud rate measurement

Some days ago I had a talk (...email exchange) with my friend KarapuZ about the way to get correct measurements of the baud rate in noisy signals or in uncommon waveforms. I always relied on the tools provided by SA program as the "Auto define param" and mostly the amplitude detectors, but KarapuZ warned me that sometimes they may fail and notably the "Auto define param" tool fails in case of strictly filtered or weak signals.
As a test, KarapuZ sent me a sample (the "x-Bd" wav file in Figure 1) without specify its baudarate and asking me to measure it.

Fig. 1
I used the "Auto define" tool and the modified amplitude detector searching for the lower more bright line and got a baud rate of 1000 symbols/sec in both their outputs (Fig. 2).
 
Fig. 2
KarapuZ replied: "The speed line of manipulation is 1500 baud unchanged in the preamble! This is a Chinese PSK-2 modem". 
Indeed, in my measurement I simply took in consideration the lower line - as usual - and did not put attention to the discontinuity in the 1000 Hz (999.44) line between preamble and data segments (Figs. 3,4). Really a my hasty measurement (I already had this signal but I forgot).

Fig. 3
Fig. 4
KarapuZ also drawn my attention on the "raster" of the signal that clearly exhibits 15 bits within 10 msec, ie a speed of 1500 baud (Fig. 5)

Fig. 5
Apart from my error in the evaluation of the amplitude detector, why the SA "Auto define param" failed so clumsily?
Quoting KarapuZ "it can be assumed that in the transmitting equipment, filters are used at the output of the signal formation which in some circumstances may influence the determination of the speed of the manipulation of the SA program." So, in order to demonstrate the influence of the filtering in the Chinese PSK-2 signal, KarapuZ synthesized an absolute PSK-2 modulation at 1500 baud with the same 3-bit structure of the Chinese waveform and sent me that file (Fig. 6)

Fig. 6
Then I measured the manipulation speed of the syntesized signal just using the "Auto define param" and it works like a charm.

Fig. 7
 The influences of the filtering is thus well quantifiable (other than visible)

Fig. 8
Things are even more worse since the bitstream  has a relative form and a three-bit structure, visible in raster, which generates many harmonics in the power spectrum! This is China, they love such tricks :)

Fig. 9
Fig.10
Thanks to KarapuZ for the great lesson!

24 October 2016

Unid BPSK 1500Bd (prob. Chinese modem)


Unid modem (prob. Chinese origin) using BPSK modulation at 1500 Baud and 1500 Hz sub-carrier. Since the alternation of frames with different strength, this may be a duplex channel.

fig. 1
fig. 2
fig. 3
Once demodulated, the analysis of the bitstream reaveals an interesting 3 bit structure (fig. 4): my friend Karapuz suggested to try a differential (relative) decoding of the signal.

fig. 4
Differential decoding can be obtained directly by running the proper tool of  the bit-editor or by demodulating the signal using the SA demodulator with option "Diff 1" as in fig. 5

fig. 5
Results are similar and in the output bistream, visually more logical, is visible the sync bit and the two data bits (fig. 6).

fig. 6


7 March 2016

Chinese-64: MFSK-64, 37.5/18.7 Bd 37.5Hz


Since the weak signal I asked my friend KarapuZ to send me one of his recordings of the Chinese MFSK-64 modem: it's easy to verify that both the records show the same start sequence of symbols (pic. 1).

pic.1
The signal, copied on 16990.2 KHz (cf) around 0910 UTC, consists of 64 tones, 37.5 Hz spaced, modulated alternatively at 37.5 and 18.7 symbols/sec speed (pic. 2 for 37.5 Bd speed).

pic.2
It's worth nothing the characteristic "dual-speed" modulation, seen in both the two recordings: in some segments the speed switches from 37.5 to 18.7 Baud  and conversely (pics 3,4)
pic. 3
pic. 4
The initial part is always modulated at 18.7 Baud and - as said - seems to transport the same data (pic. 5):

pic. 5


https://yadi.sk/d/ZRGpFEoi3A9jkM