Showing posts with label Makhovik. Show all posts
Showing posts with label Makhovik. Show all posts

19 July 2024

CIS-1200 SDPSK 1200Bd ("Makhovik", T-230-1A)

updated (23 July 2024)

This transmission, along with a probably spurius emission 600 Hz above, was recorded on 13002.5 KHz (cf) thanks to the remote KiwiSDR located in Azumino-city Nagano, Japan [1].

Fig. 1 - main signal and its spurius

The signal that I assume is the "actual" one and that I analyzed is characterized by a SDPSK (Simmetrical Differential PSK) modulation at a speed of 1200 Baud. Indeed SDPSK is equivalent to π/2 DBPSK or PSK2 with phase rotation: ie, as shown by the transitions in absolute mode, SDPSK assumes that the phase is rotated by +π/2 for bit “0” and by -π/2 for bit “1” thus there is not a 180° turn (transitions do not pass through 0). The information transmitted is encoded in the transition and not in the state. The signal can be demodulated using the differential mode (diff=1).

Fig. 2 - SDPSK modulation

The transmission consists of some segments that differ by the presence or absence of an initial preamble (signals A and B in Figure 3) which consists of a repeated 511-bit length pseudo-random sequence generated by the polynomial x^9+x^5+1 (1) as for the ITU Recommendation O.153 [2] (188-110B "39-tone parallel mode" too uses that sequences).

Fig. 3
 
Fig. 4 - 511 bits length sequence

The presence of such sequences is one of the features of the so-called Makhovik (aka the "flywheel"), a well known Soviet-Mil crypto system. Although someone classifies Makhovik as vocoder, it can can be used for time-multiplexed encryption of both voice and data up to 9600 bps. It's official name is "T-230 bundle ciphering device for teleprinter and  data connections" and was designed to operate in UHF but very often is found in LF and in HF.
After the removal of the initial preamble, the following data block consists of a "common" sequence:

110101100100011110101100100011

followed by 240-bit Initialization Vectors that are sent in 8x30-bit groups, each group repeted three times (Figure 5): these 30-bit groups are another peculiar feature of  the Makhovik system.

010000111011001110010100001110
011101100101000011001010000111
110010100001110010000111011001
001110110010100000111011001010
001110110010100011001010000111
111111111111111000011101100101
001110110010100111011001010000
101100101000011011101100101000

Fig. 5

Segments sent w/out the initial preamble (type B in Figure 3) show exactly the same structure: note as the Initialization Vectors slightly differ (Figure 6): this feature should be further studied (it is probably somehow related to the presence/absence of the initial preamble) but it is necessary to obtain several more recordings.

010000111011001110010100001110
011101100101000011001010000111

110010100001110010000111011001
001110110010100000111011001010
001110110010100011001010000111
111111111111111000011101100101
001110110010100111011001010000
101100101000011011101100101000

010000111011001110010100001110
011101100101000011001010000111

011001010000111100001110110010
111011001010000110010100001110
010100001110110110110010100001
100101000011101001010000111011
111011001010000111111111111111
011101100101000100001110110010

Fig. 6

It's worth noting that in some previous Makhovik recordings I saw differential encoded data & BPSK, while this ones consist of  plain encoded data & SDPSK [3].

update (23 July 2024)
I willingly add a comment sent me by my friend cryptomaster.
The common sequence in Figs 5,6

110101100100011110101100100011

shall be right shifted to appear as

111101011001000111101011001000

which in turn is the repetition of the 15 bits length M-sequence generated by the polynomial x^4+x+1 (Figure 7).

111101011001000

Fig. 7 - the repetition of the 15 bits M-sequence generated by the polynomial x^4+x+1

https://disk.yandex.com/d/Vg5XruORhd8_5A

(1) the use of the polynomial x^9+x^5+1 is quite common in CIS waveforms,see http://i56578-swl.blogspot.com/p/polynomials.html

[1] http://jf0fumkiwi.ddns.net:8073/
[2] https://www.itu.int/rec/T-REC-O.153/en
[3] https://i56578-swl.blogspot.com/search/label/Makhovik 

31 March 2021

CIS-1200 BPSK 1200Bd ("Makhovik", T-230-1A)

Good quality CIS-1200 (T-230-1A, BPSK 1200Bd) transmission spotted on 9073.80 KHz (cf) thanks to the ArcticSDR. The transmission consists of a series of encrypted messages, the 240-bit Initialization Vectors are sent in 8x30-bit groups, each group repeted three times (Figure 2).

Fig. 1
Fig. 2

The transmission ends with a long "idling" part consisting of the 511-bit m-sequence generated by the polynomial x^9+x^5+1 (Figure 3). All is ok with previous CIS-1200 recordings [1].
Fig. 3

 

https://disk.yandex.com/d/599vbjcIfpRzrA

 
[1]  https://i56578-swl.blogspot.com/search/label/Makhovik

 

28 February 2020

Makhovik (T-230) secured CIS PSK2/1200Bd

This post is an update and a correction to a previous post to which reference. I want to thank an anonymous reader who in his comment to that post suggested to use differential PSK2 decoding.
In that post I verified the use of Makhovik crypto system (T-230 bundle ciphering device for teleprinter and data connections) in CIS-12 transmissions as well as in CIS PSK2/1200Bd (CIS-1200) transmissions. One of Makhovik's features that can be considered as a signature, in addition to the characteristic 30-bit Message Indicators, is the use of 511-bit pseudo-random sequences generated by the primitive polynomial x^9+x^5+1. These sequences follow the ITU Recommendation O.153 [1] and are primarily intended for error measurements at bitrates up to 14400bps  and synchronization purposes (188-110B "39-tone parallel mode" too uses that pattern).
I searched just these 511-bit sequences in three different CIS-1200 recordings (files psk2_a, psk2_b, and psk2_c) and the search was successful in all the three files but I did not find the right sequences, and then the generator polynomial x^9+x^5+1, in the _a recording (Fig. 1).

Fig. 1
As said above, an anonymous reader suggested to use differential decoding for the _a file: well, I took his advice and results are interesting: as shown in Fig. 2, after the differential decoding the bitstream have the right 511-bit sequences generated by the polynomial x^9+x^5+1 !

Fig. 2 - psk2_a diff. decoded bitstream
This is a further indication in favor of the use of  Makovik encryption with the CIS-1200 waveform,  in these cases the modem T-230-1A (a single channel version of T-230) should have been used. 
As usual, further recordings are needed.


16 September 2019

CIS Makhovik (T-230) in CIS-12 and PSK2/1200bps waveforms

Recently my friend KarapuZ gave me the chance to analyze a CIS-12 bitstream and I took the opportunity to wotk on the "format" of Makhovik and then compare the CIS-12 stream with other Makhovik  streams coming from PSK2/1200bps modulations. The results are rather interesting even if the lack of official documentation and the number of available samples do not allow any exact classification but only hypotheses.

Makhovik (the "flywheel") is a well known Soviet-Mil crypto system also used by The National People's Army of the former German Democratic Republic (NVA, Nationale Volksarmee). Although someone classifies Makhovik as vocoder, it can can be used for time-multiplexed encryption of both voice and data up to 9600 bps. It's official name is "T-230 bundle ciphering device for teleprinter and data connections" and was designed to operate in UHF but very often is found in LF and in HF.
T-230 main unit (Fig. 1) consists of four slots:
AT-3002M multi-channel modem for LF channels,
AT-3004D multi-channel modem for HF channels (CIS-12 waveform, also known as MS5 or "Fire"),
AT-3001M voice scrambler (five per unit system maximum),
AT-3025 signaling unit and pager (two per device system).
The T-230-1A is a single-channel version of the T-230. The device contains the cipher, modem and radio as well the vocoder. The system is constructed with 3 modules / blocks and provides  two 1200bps channels in its basic configuration. Several T-230-1A can be used in stationary operation with the modem of the multi-channel variant, AT-3002 and AT-3004D. 8 keys can be set for a maximum of 8 subscriber networks.

Fig.1 - a T-230 system
AT-3004D/AT-3104 (CIS-12)
CIS-12 is a pseudo OFDM 12-tone (+ 1 pilot) waveform using PSK2 or PSK4 modulation at speed of 120 Baud while the modem name is AT-3004D (or its newer counterpart AT-3104). Channels 1-10 are used for data, 11 and 12 are test/service channels, therefore the "aggregate" speed is 1200 Baud (just as the baudrate of the waveform of T-230-1A system).
The structure of the preamble (Fig. 2) in some way resembles the one described in MIL 188-220 Appendix D, "standards for COMSEC transmissions": I refer to that terminology just for the sake of clarity and to better illustrate my guess, as said there is no confirm about it. 
Fig.2 - CIS-12 Makhovik

The two "frame sync" blocks consist of a 15/30-bit repeating pattern. The block bewteen the two frame sync blocks is the more interesting (Fig. 3). It consists of 511 bits long pseudo-random sequences generated by the primitive polynomial x^9+x^5+1 [1], thus meeting with ITU Recommendation O.153 [2]. This pattern is primarily intended for error measurements at bitrates up to 14.4 kbit/s. Anyway, 511-bit length sequences are also used for synchronization purposes as in 188-110B "39-tone parallel mode" (see Appendix B #5.4.3). Since the 511-bit block is not reinserted, I tend to think that it's used to sync the receive side (the modem or the crypto device). It's worth noting that although ITU O.153 reports that the longest sequence of ZEROs is 8 (non-inverted signal), I found some sequences with a greater length: maybe it can depend on the OFDM demodulator or the quality of the signal, or maybe the used sequences are not fully ITU O.153 compliant.

Fig.3 - CIS-12 511-bit sequences
Finally, what I call here as the "Message Indicator" is a 720-bit long block consisting of 8-time triplicate 30-bit sequences. This part is composed of eight strings of 30 bits and each string is repeated 3 times (Fig. 4). The x3 redundancy, as well as in other krypto device as KG-84, is used to improve the accuracy and realiability of the reception. Encrypted data follow this block.

Fig.4 - CIS-12 720-bit MI
T-230-1A (PSK2 1200bps)
The same blocks (sync,511,MI), with a different arrangement, can be observed in a full sample of a PSK2 1200bps (file "_b" in the downloadable zip archive). In this case the 30-bit sync pattern is reinserted several times as well as the MI blocks (Fig. 5).

Fig.5 - T-230-1A Makhovik
In my archive I found other samples that presumably are attributable to T-230-1A (files "_a" and "_c" in the downloadable zip archive): unfortunately I went late on these transmissions therefore it was not possible to examine their preamble.
In these samples (Fig. 6) the 30-bit sync frame block is missing but, as I specified, it could be inserted at the start of the transmission. A second interesting feature is the use of sequences of 511 bits of length but which are not originated by the polynomial x^9+x^5+1! (fixed in this post)
 
Fig.6 - other PSK2 1200bps samples with Makhovik format

All the three PSK2 samples anyway have the same 30-bit MI structure as the one seen in CIS-12 (Fig. 7)


Fig.7 - 30-bit MI blocks

I would like to point out that this post does not claim to provide a description of the Makhovik encryption protocol but is just limited to the presentation of results obtained from the analysis of some samples: further (many) recordings are needed as well as tips and help from friends.

https://yadi.sk/d/j9HShkWFQo5z9g


[1] https://en.wikipedia.org/wiki/Linear-feedback_shift_register
[2] https://www.itu.int/rec/T-REC-O.153/en