Showing posts with label GA-205. Show all posts
Showing posts with label GA-205. Show all posts

17 August 2026

UK DHFCS 16289.5 kHz Follow-up: DRS GA-205 TDM Evidence and 1536-bit Frame Analysis

Following up on the initial analysis of the UK Defence High Frequency Communications Service (DHFCS) transmissions on 16289.5 kHz [1] (observed in both 800 Bd / 800 Hz FSK and STANAG-4285 modes), further analysis of extended raw bitstream captures has provided concrete evidence regarding the deployment of the Leonardo DRS GA-205 Time Division Multiplexer (or a fully compatible framing engine) and additional structural characteristics. The 1536-bit period bitstreams were obtained by demodulating some STANAG-4285 recordings from my personal repository. 

1. DRS GA-205 Synchronization character
All examined bitstreams share the exact same 16-bit synchronization sequence — referred to as the "Synchronization character" — specified as 9C16 (hex) in the DRS GA-205 TDM datasheet for Frame Type 1 (Figure 1) which is user-programmable depending on the selected operational profile. In this context, DRS refers to Leonardo DRS (formerly DRS Technologies), a major defense contractor specializing in tactical military communications, naval digital networks, and signal processing hardware. Specifically, the DRS GA-205 is a 12-channel Time Division Multiplexer (TDM) widely deployed across NATO and Allied naval assets [2].

Figure 1: Excerpt from the DRS GA-205 datasheet showing the synchronization character specifications

In binary format, the hexadecimal value 0x9C16 corresponds to the 16-bit sequence 1001110010011100 (MSB Most Significant Bit first). When transmitted over the air in standard LSB-first (Least Significant Bit first) bit order, it translates to 0011100100111001. According to the manufacturer's specifications, this synchronization sequence is user-programmable per frame type (e.g., 9C16 for Frame 1 or 9D16 for Frame 2). Figure 2 illustrates an example of this alignment within the demodulated bitstream.

Figure 2: Alignment of the 1536-bit periodic stream showing the vertical synchronization column matching the DRS GA-205 Frame 1 sync character (9C16 / LSB 0011100100111001)

1.1 Framing Lock Mechanism
The receiving framer scans the incoming bitstream for the static, known 16-bit sequence (0x9C16). Its sole purpose is to establish word alignment at the start of the frame and determine bit clock timing, operating completely independently of the subsequent frame layout.
The persistence of the identical 9C16 sync character across bitstreams with varying overall internal layouts highlights a fundamental design principle of the DRS GA-205 architecture: the decoupling of Bit/Frame Alignment from Payload Demultiplexing. While the static 16-bit sync word ensures immediate physical-layer framing lock across all transmissions, the underlying TDM engine adapts the 1536-bit frame structure and sub-field distribution to match the active user port allocations.

2. 1536-bit bitstreams
Although these 1536-bit period bitstreams rely on the exact same 9C16 sync character for primary frame alignment, their internal structures may differ significantly. For instance, certain layouts do not lend themselves to straightforward structural description or tabular breakdown, as illustrated by the complex bitstreams shown in Figure 3. 

Figure 3: Examples of 1536-bit period bitstreams exhibiting highly complex or irregular sub-framing structures despite sharing the identical 9C16 primary synchronization sequence.

Conversely, other bitstreams — such as the one shown in Figure 4 — feature a highly regular structure that can easily be mapped and detailed using simple tables (Table I).

Figure 4:  Bitmap representation of a highly regular 1536-bit STANAG-4285 bitstream divided into 21 sub-blocks, highlighting alternating 48-bit payload fields (D) and static 16-bit filler/separator fields (F)

Table I: Structural breakdown of the 1536-bit frame layout shown in Figure 4

The bitstream shown in Figure 4 can be directly compared with the one analyzed in the previous post [1], reproduced in Figure 5 along with its structural breakdown (Table II) for convenience.

Figure 5: Asymmetric 1536-bit STANAG-4285 frame layout from the previous post [1], divided into 7 main sub-blocks with variable field lengths (F1,​D1-F5,​D5​).

Table II: Detailed structural breakdown of the 1536-bit frame layout shown in Figure 5

2.1 Channel Interleaving vs. Hardware Ports
A potential point of confusion when analyzing these bitstreams is the presence of up to 21 distinct sub-blocks (or "pseudo-channels") within a single 1536-bit frame, as in the bitstream of Figure 4, given that the DRS GA-205 is physically a 12-channel TDM.
The 12 channels of GA-205 correspond to the 12 physical input ports, which are not transmitted as 12 monolithic blocks. When user ports are configured for different baud rates (e.g., mixing 75 Bd and 300 Bd channels), higher-speed channels are assigned multiple timeslots within the same 1536-bit macro-frame, naturally resulting in a sub-block count higher than the number of physical input ports.

To multiplex them into a single continuous stream, the TDM engine samples higher-speed ports multiple times per frame cycle while sampling lower-speed ports only once. Consequently, the 21 sub-blocks visible in the bitstream bitmap do not represent individual hardware ports, but rather the cyclical sampling sequence (interleaving ratio) of the TDM frame. Each sub-block carries its respective slice of user payload (D) alongside necessary framing, control, and pulse-stuffing overhead (F).
Conversely, Figure 5 displays only 7 main sub-blocks. This lower count indicates either that only a subset of the 12 hardware channels was active, or that multiple low-speed user ports were aggregated within shared timeslots.
Without access to the specific TDM preset configuration used in these captures, drawing definitive conclusions about the exact channel mapping remains challenging. In operational scenarios, these layout variations are recognized either via pre-configured operational profiles (where sender and receiver share a pre-set TDM channel mask) or via in-band framing status bits transmitted immediately following the very first sync header. Once the receiving framer locks onto 9C16, it applies the designated slicing mask to route each sub-field to its respective low-speed channel processor. It should be noted that, at least across the recordings currently in my repository, no identical layouts were found but rather streams that are merely "architecturally" similar.

3. Parallel fields (counters)
Direct text decoding of the parallel fields shown in Figure 6 (one 8-bit and two 7-bit fields) reveals that they do not function as dynamic numeric counters, but rather as deterministic ASCII test/idle pattern generators.

Figure 6: Bitmap alignment of the 1536-bit STANAG-4285 bitstream highlighting the position of three parallel sub-fields (cnt-1, cnt-2, cnt-3) within the TDM frame structure.

The decoded text (Figure 7) shows sequential progressions of the printable ASCII character set:

!"#$%&'()*+,-./0123456789:;<=>?\ABCDEFGHIJKLMNOPQRSTUVWXYZ(\)`ABCDEFGHIJKLMNOPQRSTUVWXYZ(~)\
!"#$%&"()*+,-./0123456789:;<=>?`ABCDEFGHIJKLMNOPQRSTUVWXYZ(|)~`ABCDEFGHIJKLMNOPQRSTUVWXYZ(~)

This behavior is characteristic of:
- Channel Integrity (BERT): Enables continuous Bit Error Rate (BER) measurement and frame loss detection across individual TDM sub-channels by stepping through the ASCII sequence at one character per frame.
- Idle Filler Sequence: Maintains symbol clock synchronization and bit transition continuity across the link when user ports are inactive or sending null traffic.

It should be noted that these behaviors, while consistent with the GA-205 architecture, are not necessarily exclusive to it, as similar idle/test patterns and interleaving schemes are common across many military-grade TDM systems.

Figure 7: Decoded ASCII text representation of parallel sub-fields, revealing continuous printable ASCII sequence sweeps used for channel integrity monitoring and alignment.

4. A Second Test Pattern: Baudot/ITA-2 Pangram Sequence
The following analysis is based on a separate demodulated bitstream capture, distinct from the ones used in Figures 1–10 above — a further illustration that, as already noted in Section 2.1, not all captured bitstreams share the same internal sub-block layout.
Reshaping the raw 1536-bit stream into a 12×16 byte matrix (12 rows×16 byte-columns per frame) reveals a striking pattern in column K (the 11th byte of each row) at same intervals, highlighted in Figures 8,9. Across 12 independently captured frames — each clearly identified by the recurring 0x3939 sync character in columns A and B (LSB-first of 0x9C16 sync character) — a total of 129 out of 144 cells (89.6%) in column K share the pattern "XXXXX111" consisting of trailing 3-bit suffix, whereas the leading 5 bits vary dynamically.

Figure 8: Bitstream visualization of the reshaped data frames. The white bounding box on the right highlights the recurring structural pattern observed at fixed byte intervals across multiple independent transmissions.

Figure 9: Part of the Excel matrix alignment (12×16 bytes) of consecutive 1536-bit frames, highlighting the primary sync header and the persistent XXXXX111 pattern in column K (11th byte).

Extracting the variable 5-bit prefix from each of these 129 bytes and decoding it as International Telegraph Alphabet No. 2 (ITA-2 / Baudot-Murray, CCITT-2) produces a clearly recognizable result:

"…THE QUICK BROWN FOX (JUMPS) OVER THE LAZY DOG…" followed by a FIGS-shifted digit run (0–9).

Independent decode of the same demodulated bitstream using dedicated RTTY/Baudot decoding software (5×19 multiplex, positive polarity, correct bit order). The software's raw output (top) closely matches the ITA-2 reading derived manually above (white box, overlaid for comparison), corroborating the "THE QUICK BROWN FOX..." pangram test pattern (Figure 10).

Figure 10: Decode of the same demodulated bitstream using dedicated RTTY/Baudot decoding software

This is the classic pangram test string long used to exercise teleprinter and RTTY equipment, as it contains every letter of the alphabet. Notably, the small gaps observed in the decoded text in Figure 10 (e.g., "QUIC" instead of "QUICK") coincide exactly with the row-1/sync boundary of each frame where the character stream is interrupted — providing independent confirmation of the frame's periodicity.
Taken together with the printable-ASCII BERT/idle sweep documented in Section 3 (from the primary bitstream), this demonstrates that different GA-205 captures can carry structurally distinct low-speed test channels — one bitstream multiplexing a 7/8-bit ASCII test sequence, and another multiplexing a 5-bit Baudot/ITA-2 test sequence. This strongly reinforces the mixed-rate channel interleaving model discussed in Section 2.1.

The byte-matrix reshaping, statistical pattern analysis, and ITA-2/Baudot decoding presented in this section were carried out with the assistance of Claude (Anthropic AI), based on raw demodulated bitstream data provided by the author.

5. 1024-bit bitstreams & GA-205
Bitstream analysis of demodulated 800 Bd / 800 Hz FSK recordings (Figure 11) revealed a 1024-bit frame period that shares the exact same sub-block multiplexing architecture as the 1536-bit STANAG-4285 streams, yet lacks the standard 0x9C16 sync word. Instead, these streams consistently exhibit a 11-bit (LSB) synchronization sequence: 01100001101.
 
Figure 11: Alignment of the 1024-bit FSK periodic stream displaying the 11-bit vertical synchronization sequence (01100001101)
 
As outlined in the manufacturer specifications, and illustrated in the preset screenshot in Figure 12, the DRS GA-205 synchronization character is not hardcoded; it is user-programmable depending on the active operational profile or frame configuration — e.g., Frame Type 1 using 0x9C16 vs. Frame Type 2 using 0x9D16, or even a custom user-defined vector such as 01100001101. Naturally, this configuration must be agreed upon and shared between peers prior to transmission.
 
Figure 12: GA-205 TDM software control interface showing configurable aggregate parameters, sync code options, and individual user port rate allocations

6. Conclusions
To ground these bitstream findings in real-world military infrastructure, we must examine the hardware lineage and strategic deployments behind these transmissions. Specifically, looking at two major industrial partnerships highlights how the Leonardo DRS GA-205 Time Division Multiplexer is integrated across NATO and Allied HF network.

- Australian Defence Force (ADF) & MHFCS (Bellinger Systems):
In Australia, Bellinger Systems (a SYPAQ subsidiary) signed a long-term agreement with Leonardo DRS to procure, integrate, and support the GA-205 modernisation and delivery program. This program includes delivering approximately 100 modernised GA-205 TDM units to the Australian Defence Force to support their Modernised High Frequency Communications System (MHFCS) and transition towards Link 22 tactical data link architectures [3] (1).

Figure 13: Dimensional specifications comparison between the modernised Bellinger Systems GA-205 (left) and the original DRS Technologies (right).

- UK Defence High Frequency Communications Service (DHFCS / Babcock International):
Within the UK DHFCS infrastructure, primary defense contractors and service partners (such as Babcock International) manage the strategic HF communication sites, ground stations, and ship-to-shore links. In these strategic architectures, the GA-205 TDM serves as the key bridging multiplexer, interfacing legacy low-speed user channels with high-speed HF modems across UK Defence HF networks.

While absolute confirmation would require declassified operational documentation, there is strong circumstantial and technical alignment between the observed sub-block structures and the GA-205’s native support for the U.S. Navy High Speed Fleet Broadcast (HSFB) architecture(2). Designed specifically to aggregate heterogeneous low-speed naval messaging and tactical data streams over a single HF carrier, the HSFB framing profile provides a compelling explanation for the rigid slot allocation and deterministic frame synchronization observed across both STANAG-4285 and FSK transmissions in the DHFCS/MHFCS networks.

Notes
1. The dimensional discrepancies between the original DRS datasheet (standard 1U 19-inch rackmount) and Bellinger Systems' product sheet (200×132×620 mm) strongly point to a modernised form-factor evolution. Bellinger re-packaged the GA-205 TDM engine into a modular ATR-style / vertical-rack footprint for the Australian Defence Force's MHFCS project, integrating internal flash-upgradable firmware, higher aggregate data rate handling (up to 38.4 kbps), and built-in Link Local Controller (LLC) support for modern naval communication racks.
2. The U.S. Navy High Speed Fleet Broadcast (HSFB) is a U.S. Navy and NATO hardware architecture for shore-to-ship multi-channel fleet broadcast communications. HSFB replaced older single-channel low-speed (75-baud) broadcast links by aggregating multiple heterogeneous low-bitrate channels into a unified TDM stream over HF/UHF carriers. Native HSFB support within the Leonardo DRS GA-205 multiplexer ensured multi-channel broadcast interoperability across Allied naval communication networks (US Navy, UK DHFCS, and RAN MHFCS).
 
References
[1] 800Bd/800Hz (critical) FSK and STANAG-4285 Transmissions http://i56578-swl.blogspot.com/2026/08/800-bd-800-hz-critical-fsk-and-stanag.html
[2] Leonardo DRS, GA-205 Time Division Multiplexer datasheet — cleared for public release under OSR case no. 05-S-0976 (08.25.2007) https://www.leonardodrs.com/wp-content/uploads/2023/08/ga205.pdf
[3] https://www.sypaq.com.au/news/sypaq-subsidiary-bellinger-signs-historic-agreement-with-leonardo-drs/

12 June 2026

Simulating ADF ISB Transmissions: 12-Bit Repetition Coding on the USB Channel

The idea for this post stems from an interesting RAN (Royal Australian Navy) fleet broadcast originating from the MHFCS (Modernised High Frequency Communications System) utilized by the ADF (Australian Defence Force). The captured transmission employs STANAG-4285 at 600 bps/L in ISB (Independent SideBand) mode on 14874.0 kHz (Figure 1), and was successfully recorded thanks to the remote KiwiSDR VK6QS2 located in Augusta, Western Australia.

Data redundancy is a mission-critical asset in military HF communications. To ensure reliable delivery over thousands of miles, this transmission architecture departs from standard handling, utilizing the ISB spectrum to securely distribute the payload. 

Fig. 1: ADF MHFCS in ISB mode

As mentioned, the transmission relies on an asymmetric Independent Sideband (ISB) framework: the Upper Sideband (USB) delivers a redundant 600 bps stream wherein each individual bit is replicated 12 times, while the Lower Sideband (LSB) simultaneously transmits a "standard" signal at an identical 600 bps clock rate. This dual-path configuration mitigates severe ionospheric fading, allowing the receiver to cross-correlate the sidebands and reconstruct the payload without data loss. 

Technical analysis confirms that the LSB stream represents a broadcast encrypted by a KW-46 (or compatible) crypto-device, identified by the m-sequence of the generator polynomial x^31+x^3+1. This sequence is natively employed by the KW-46T transmitter for remote receiver synchronization (KW-46R). In contrast, the USB data structure exhibits 12-bit blocks of uniform logical states, most likely originated by a GA-205 12-channel Time-Division Multiplexer. This sideband similarly secures its payload using KW-46 protocols: as illustrated in Figure 2, by isolating a single multiplexed channel, stripping the remaining 11, and reshaping the data into a 7-bit architecture, the presence of the identical x^31+x^3+1 m-sequence was conclusively verified.

Fig. 2 : LSB and USB demodulated bitstreams

In this sample, both STANAG-4285 modems have the exact same clock speed and line rate of 600 bps on the physical serial line (the DTE/DCE interface) (1).  However, the amount of unique, useful information (the actual payload) is highly asymmetric: the USB channel carries a 50 bps information rate (Strategic Command & Control ?) protected by the 12x repetition code, while the LSB channel carries a native 600 bps information rate (Routine Data Traffic & Logistics ?).

The ultimate operational of ISB in this scenario is spectrum optimization.  Instead of requesting two distinct HF frequency allocations from military spectrum management, which would tie up vital radio assets and increase the station's electronic footprint, the user allocates a single suppressed carrier frequency. By utilizing ISB, the transmitter concurrently radiates two separate, parallel operational environments on a single RF assignment. 
A similar ISB paradigm is utilized, for example, by specific Portuguese Navy transmissions operating in STANAG-4285 600 bps/L mode, notably on the 12704.5 kHz Center Frequency (CF), using the HF callsign CTA12 (Figure 3). The bandwidth allocation is split as follows:
LSB Channel: Transmits the plain text Channel Availability and Receipt Broadcast (CARB), also frequently designated as the FAB (Frequency Availability Broadcast)
USB Channel: Carries a secure, encrypted fleet broadcast utilizing a legacy KW-46 cryptographic device.

Fig. 3: Portuguese Navy CT12 working in ISB mode

Concerning the source of the transmission, TDoA geolocation points to the 'Naval Communication Station Harold E. Holt' (NCS HEH), situated 6 km north of Exmouth (Figure 4). COMMSTA HEH is jointly operated by Royal Australian Navy and US Navy personnel. The High Frequency Transmitter (HFT) site houses an array of hardware, much of which is dedicated to point-to-point communication circuits linked to shore facilities and surface vessels operating within the station's operational footprint.


Fig. 4: Direction Finding (TDoA) results


The remainder of this post aims to simulate the generation of the baseband data stream for the USB (Upper Sideband) channel, alongside DTE-DCE timing management, using hardwired digital logic managed by Arduino microcontrollers. Naturally, this is a standalone proof of concept and does not reflect the actual hardware infrastructure utilized by the MHFCS.
To evaluate the generation of the cloned 12-bit redundant stream, the simulation leverages a CD4067 multiplexer (MUX) to closely mirror the hardware-level TDM implementation of the GA-205 12-channel multiplexer used by the Australian Defence Force. I followed the logical block diagram illustrated in Figure 5, implemented using breadboards, TTL and CMOS chips, and two Arduino microcontrollers. Figure 6 shows the components prior to wiring.

Fig. 5: USB channel formation

Fig. 6

A: extender buffer 
Implementing a 1-to-12 output bit extender (also known in electronics as a fan-out replicator or distribution buffer) using TTL logic is a classic and very straightforward project. The crucial factor is the current: a single output pin of a standard chip does not have the electrical strength to drive the 12 inputs of the following multiplexer (MUX) simultaneously while maintaining the correct voltage levels. For this reason, buffers are required. I used the 74LS04 chip, which contains 6 inverters (NOT gates). By routing the signal through two inverters in cascade, the bit is inverted twice, returning to its original state but with all the necessary driving power. Using the common 74LS04 chips we need to employ a 'cascade' logic: one gate acts as a pilot (inverting the signal the first time), and the other gates act as splitters (inverting it a second time, thus restoring the original signal). Given that each chip contains 6 gates, using 3 chips gives us a total of 18 gates: one will serve as the pilot, and 12 will provide the desired outputs.

B: multiplexer
The CD4067B module, a CMOS single-ended 16-channel pre-monted board, is utilized as a synchronous time-division multiplexer (TDM), serving as the critical link that generates the redundant serial stream. Driven by the binary addressing logic of Arduino #1, the CD4067B sequentially samples each input channel. By allocating an identical, deterministic time slot to every channel, the chip enforces the strict synchronous timing required to mimic real-world TDM hardware like the GA-205. The multiplexer acts as the true functional centerpiece of the system that replicates the structural signature observed in the original MHFCS transmission.

C: Arduino #1
The first microcontroller serves as the data source and hardware controller, driven by Arduino 2 clock. It is responsible for generating or forwarding the low-speed baseband bitstream (e.g., 50 bps) and generating the necessary addressing logic to drive the multiplexer. It ensures that the correct channel is actively routed into the system pipeline with precise timing.

D: Arduino #2 
The second microcontroller functions strictly as a downstream monitoring and simulation of the digital front-end of a STANAG-4285 modulator: it processes the incoming bitstream exactly as the STANAG-4285 hardware would see it, capturing the raw, synchronous 12-bit sequences directly from the multiplexer's output. The line tapped by the Arduino RX carries the exact, fully formed digital data that is ready to be applied to the physical input of the modem. This allows for comprehensive loopback testing, signal verification, and diagnostic analysis of the transmission line without needing to connect a physical modem unit.

This architecture functions as a redundant 12-bit serializer achieving high noise immunity and fault tolerance. On top of this hardware-level redundancy, the STANAG-4285 modem will introduce an extra layer of protection against fading and burst noise, thanks to its robust FEC (Forward Error Correction) and configurable interleaver mechanisms.

The fully wired circuit is depicted in Figure 7.


Fig. 7

Figure 8 displays the serial monitors of the two Arduino microcontrollers: the data source (top) and the receiver (bottom). Two "COM4" ports are displayed because the Arduino boards are driven by two separate PCs. Note that a very low clock rate was chosen in the firmware implementation allow easy reading of the serial monitors.

Fig. 8:serial monitors output of the two microcontrollers

A note about Bitrate Expansion vs. Datarate Preservation
The integration of the buffer-extender and the hardware multiplexer within this data pipeline serves a dual purpose: expanding the transmission bitrate while strictly preserving the baseline datarate (the actual information payload). 
Bitrate Expansion (50 bps→600 bps): The system ingests a baseline digital signal at 50 bps and up-rates the transmission frequency by a factor of 12, delivering a 600 bps synchronous stream at the final output. This high-speed clocking is structurally required to match the ingestion constraints of the STANAG-4285 modem. 
Datarate Preservation: While the physical signaling speed increases, the net information throughput remains exactly identical to the 50 bps input. The system does not inject new data or alter the original message content. Instead of increasing information capacity, the remaining bandwidth created by the 12x clock multiplier is entirely dedicated to data redundancy. Each original bit is algorithmically mapped across the 12-bit output frame.

https://disk.yandex.com/d/-9xhLnBZ-7RPKw  Royal Australian Navy, 14874.0 kHz CF
https://disk.yandex.com/d/MyzyM20VOnYTvg Portuguese Navy, 12704.5 kHz CF


(1) In professional HF communications (such as STANAG 4285 or MIL-STD-188-110A), the DCE (Data Circuit-terminating Equipment / Modem) acts as the master of the communications link, while the DTE (Data Terminal Equipment / Data Source) acts as a slave regarding timing and throughput.

11 November 2025

UK DHFCS FSK 800Bd/850 & STANAG-4285 1200bps/L

Interesting and unknown (at least for me) FSK transmission in 800Bd/850Hz mode sent to me by my friend cryptomaster. These transmissions have been heard during the evening (UTC) on the frequencies 8014, 8180, 10008 and 12414 kHz.

Fig. 1 - FSK parameters

The signal has an ACF of approximately 1280 ms which corresponds to a period of 1024 bits (Figure 2).

Fig. 2 - ACF value and relative bitmap
  

The bitstream obtained after demodulation has a complex and very interesting structure (Figure 3).

Fig. 3 - demodulated bitstream

The most interesting thing is that after a few days the FSK signals have disappeared and been replaced by STANAG-4285 signals in two of the above-mentioned frequencies: 8013.20 and 10008.20 KHz/USB (Figure 4).

Fig. 4 - FSK & STANAG-4285 transmissions

The S-4285 transmissions - which have also disappeared - were recorded in 1200bps/L mode and once demodulated show a bistream period of 1536 bits which is very similar to the 1024 bits bitstream of the previous FSK transmissions: just 512 bits of difference, see Figs. 3 and 5 (below).

Fig. 5 - 1536 bits period bitstream of the STANAG-4285 transmissions

The format of the bitstreams (both FSK and STANAG-4285) suggests the use of a TDM (Time Division Multiplexer), probably the GA-205 model, or a modified version of it, as already analyzed in other posts relating to UK DHFCS (Defense High Frequency Communications Service) and Australian MHFCS (Modernized High Frequency Communications System) transmissions [1]. The STANAG-4285 1200bps broadcasts utilize time-division multiplexing to carry up to 12 KW-46 encrypted streams on a single frequency. Moreover, FSK/STANAG-4285 transmissions on the same channel have already been observed previously and attributed to DHFCS: Tx site of Crimond [2].  a single frequency.

Direction Finding tests (TDoA algorithm), although slightly inaccurate, indicate St. Eval (DHFCS) as the likely site of signal transmission (Figure 6).

Fig. 6 - some Direction Finding tests

It's difficult to determine the purpose of these broadcasts; perhaps they're tests or specific needs. Let's hope we have better luck and catch more similar signals.

https://disk.yandex.com/d/qIF5cmD797W_iQ (FSK signal)

https://disk.yandex.com/d/Y50xjENZ50TPAg (STANAG-4285 signal)

[1] http://i56578-swl.blogspot.com/search/label/1536-bit%20TDM
[2] http://i56578-swl.blogspot.com/2024/06/300-bps-fsk-stanag-4285-fleet-broadcast.html

20 February 2024

KW-46 secured fleet broadcast over S-4285 in ISB mode (Humpty Doo, MHFCS)

Interesting fleet broadcast from the MHFCS (Modernised High Frequency Communications System) site in Humpty Doo, Northern Territory - Australia. The transmissions use STANAG-4285 600bps/L in ISB mode and are audible on 11145.0 KHz (Figure 1).

Fig. 1

Bitstream of the LSB channel (Figure 2) is a "classic" broadcast which is encrypted using KW-46 (or compatible) cipher device given the presence of the m-sequence generated by the polinomyal x^31 + x^3 +1 (KW-46T uses that M-sequences to synch the KW-46R receive devices).

Fig. 2 - bitstream of the LSB channel

The bitstream of the USB channel is more interesting since it consists of 12-bit strings where all the bits have the same logical value, likely originated by the GA-205 12-channel time division multiplexer: I already met such signal some years ago [1] but that time from the "Naval Communication Station Harold E. Holt" (NCS HEH) 6 km north of Exmouth. USB channel too transports a KW-46 secured traffic: as shown in Figure 3, I filtered out 11 channels and reshaped a single "column" into a 7-bit pattern then I successfully checked the presence of the x^31 + x^3 +1 m-sequence.

Fig. 3 - bitstream of the USB channel

As said, in this case the transmission is source by a Tx located in Humpty Doo, Northern Territory Australia.

Fig. 4 - DirectionFinding results (TDoA algorithm)
 

https://disk.yandex.com/d/cd6YKgpc18NPrw

[1] http://i56578-swl.blogspot.com/2019/05/kw-46kiv-7m-secured-fleet-broadcast.html


4 July 2019

110A 2400bps modem carrying 1536-bit protocol

Signal recorded on 14600.0 KHz/USB tranks to the KiwiSDR http://collie2.ddns.net:8073/ located in Western Australia. 
The used HF waveform is 188-110A Serial in 2400 bps mode, note the 48 symbols length frames (32+16 UK). ACF value is 200ms that makes 1440-bits/480-symbols: the length of the ACF is due to the short interleaver matrix dimensions for 2400 bps speed (40 rows x 70 columns) as discussed here.
Fig. 1
Once demodulated, we get a stream that has the well-known period of 1536 bits length that can be attributable to the GA-205 multiplexer: don't know if they were using 4 of 12 channels only. Also found the sync characters 9C16 and 9D16 ... but it might be a mere coincidence.  Most likely it's a naval broadcast by the Australian Navy RAN.

Fig. 2
Fig. 3


28 May 2019

KW-46 secured fleet broadcast using the GA-205 multiplex (Australian RAN)


This is a very interesting STANAG-4285 signal spotted on May 24 on 6378.0 KHz USB thanks to the KiwiSDR owned by VK6QS in Collie, Western Australia. About the 6378 KHz, some old WUN logs report the callsign VZD800, at that time attribuited to the Royal Australian Navy (RAN). On my side, on that same frequency I spotted the Australian MHFCS net operating in ISB/FSK: so, as also confirmed by the direction finding, the source is definitely in Australia. 
In my opinion, I believe this is a KW-46 (or KIV-7M) secured multichannel fleet broadcast originated by the GA-205 TDM [1]: a 12-channel time division multiplexer that was just deployed at RAN by DRS Technologies (Fig. 1).

Fig. 1

Now, the way I came up to this conclusion.
The HF waveform is STANAG-4285, here used in the usual "600bps/Long" sub-mode (Fig. 1): waveform that is easily recognizable and then demodulable by almost all software decoders. Given the evidence of regular patterns, I reshaped the demodulated stream to a 12-bit format, just as the number of the input ports of the GA-205 TDM. After reshaping, you can clearly see that the 12 input channels transport exactly the same data (Fig. 2).

Fig.2
Then I exctracted a single payload (i.e. a column of the stream), reshaped it to a 7-bit frames format and tested it for LFSR delimitation: as expected, the KW-46 "sign" was detected (Fig. 3). Indeed, as from STANAG-5065, the "Fibonacci bits" originated by the polynomial x^31+x^3+1 are used by KW-46 cryptographic equipment to provide  synchronization.  

Fig.3
In synchronous mode the TDM works by the muliplexer giving exactly the same time slot to each device connected to it even if one or more devices have nothing to transmit. The data rates of different input devices control the number of the slots: a device may have one slot, other may have two or three according to their data rate. In this case, all the input channels have the same data rate of 600:12=50 Baud, therefore share the same number of slots.  Managing a TDM requires that some control bits (sync, device tagging, ...) be appended to the beginning of each slot, but I did not find such bits in the streams I demodulated: a recording of the initial part of a similar transmission could help.
From what above, in my opinion the heard S4285 transmission is a fleet broadcast consisting of 12 "flat multiplexed" [2] channels that transport the same KW-46/KIV-7M secured payload (real traffic or pseudo-random chars).

Monitoring the 6378.0 KHz frequency, on May 25 I saw that they switched to the ISB mode (Fig. 4), more precisely: LSB for a single channel fleet broadcast and USB for a multi channel (GA-205 TDM) fleet broadcast; both the broadcasts are KW-46 secured and use the same STANAG-4285 600bps/L waveform. Don't know if they carry the same payloads. 
The same STANAG-4285 configuration and broadcast paradigm were also spotted on 7462, 8460.2, 9140, 10368, 10407, and 10847.2 KHz (logged on May, 28): surely there are many other operating frequencies that I do not currently know.


For what concerns the source of the signal, TDoA direction findings indicate the "Naval Communication Station Harold E. Holt" (NCS HEH) which is located 6km north of Exmouth (Fig. 5). COMMSTA HEH is jointly manned by Royal Australian Navy and US Navy Personnel. The High Frequency Transmitter (HFT) site building houses a number of transmitters, many of which are dedicated to point to point communication circuits. These circuits are established with shore facilities and navy surface ships operating within the station's area of communications responsibility.
My friend Eddy Waters (member of Utility DXers Forum) from Australia emailed me: "there seem to be transmitter site changes happen at different times of the day. Sometimes these signals come from Exmouth Western Australia, sometimes from Lyndoch, New South Wales, sometimes from Humpty Doo, Northern Territory. There are more and more frequencies changing over to the ISB STANAG setup that you describe".
 
Fig. 5

As far as I know, RAN fleet broadcasts come in using the GA-205 in a 6-channels configuration, it's not clear to me the use of 12-channels that - moreover- transport the same payload. I tried to reshape the stream to a 6-bit frames format (and 6-bit multiples)... but the KW-46 synch missed. By the way,  it's interesting to mention the KW-46 secured transmissions (probably also them from RAN) reported here: https://i56578-swl.blogspot.com/.../kw-46-secured-traffic-over-188-110a.html
 
[1]  https://www.yumpu.com/.../ga-205-time-division-multiplexer
[2] I used the term "flat multiplexed" to mean the fact that no classified multiplexing algorithm seems to be used.

2 September 2018

DHFCS 1536-bit TDM protocol (2)

In the previous post I associated the 1536-bit TDM protocol to the DHFCS network, and that's correct, but I wrongly ascribed this protocol to Rockwell Collins. Indeed, looking carefully at the two slides below you can see that they refer to the products GA-123 (HF modem) and GA-205 (TDM multiplexer), both are produced by DRS Technology, a Leonardo (formerly Finmeccanica) company.

Fig. 1
Reading the GA-205 datasheet [1] we can shed a bit of light on the 1536-bit protocol: GA-205 is a 12-channel Time Division Multiplexer (TDM) that provides full-duplex and half-duplex transmission and reception of data at selectable user port rates of 75 x 2n up to 9,600 bps. The system accommodates user data that do not share common timing sources and provides for isochronous, bit stuff, synchronous and asynchronous operation.

Fig. 2 - the GA-205 multiplexer

In Time Division Multiplexing (TDM) the communication resource is shared by assigning input channels the full spectral occupancy of the system for a fixed duration of time called time slots.
Synchronous TDM works by the muliplexer giving exactly the same time slot to each device connected to it even if one or more devices have nothing to transmit. The data rates of different input devices control the number of the slots: a device may have one slot, other may have two or three according to their data rate. 
Asynchronous TDM, or statistical TDM, is a more flexible method of TDM since slots are assigned dynamically as needed, ie slots are not assigned to devices that have nothing to transmit. Variable-Length Time Slots Asynchronous TDM can accommodate traffic of varying data rates by varying the length of the time slots. Stations transmitting at a faster data rate can be given a longer slot.

Since GA-205 multiplexer can handle up to 12 channels, the four ports you see in Figure 1 can be misleading: it is possible that the "preset" shown in the screenshot (identified as TDM1 in the upper right), refers to a particular configuration used to manage only 4 input channels of the 12 available. Maybe a default? who knows, the slide dates back to 2006. Notice that in the shown preset the input channels exhibit different baud rates: 600, 300, and 75. In that condition, bit stuffig or variable length slots can be used.
 

Given the above considerations:
1) at most, the DHFCS 1536-bit format carries up to 12 channels (by the way, 1536 bits = 1024+512, ie 1.5 Kb);
2) managing TDM requires that some control bits (sync, device tagging, ...) be appended to the beginning of each slot and this overhead is clearly part of the raw bitstream that we get after S4285 removal;
3) since we do not manage the control bits, when the the GA-205 is used in async mode we can't say the number of the channels currently transmitted; as well as we do not know the number of "traffic" channels when GA-205 is used in sync mode.

My guess is that the 1536-bit period could be the frame length (the slots gathered in a complete cycle), no matter if GA-205 works in sync or async mode. 
Channels are encrypted individually before being applied to the multiplexer, they probably use BID-950 or KIV-7 (KIV-7 may work as KW-46).

DHFCS STANAG-4285 stations logged and DF'ed so far:
05553.2 Cyprus Is.
07937.0 Crimond 
11015.0 Crimond 
14390.0 Ascension Is. 
14548.2 Cyprus Is. 
15812.1 Cyprus Is.
16106.3 St. Eval 
16287.0 Ascension Is. 
16398.2 Cyprus Is. 
17398.2 Cyprus Is. 







[1] http://www.drs-ds.com/media/1414/ga205.pdf