16 February 2017

STANAG-4538 "Circuit Mode" (a 3G-2G switching)


an interesting sample of a 3G-2G switching copied on 7780.0 KHz/USB: the handshake is performed with FLSU bursts (ie 3G-ALE) and user data are sent using MIL 188-110A serial (a 2G HF waveform), last FLSU bursts terminate the link (Fig. 1).

Fig. 1

In this scenario the traffic service is termed “Circuit Mode” in STANAG-4538 and  is used when an HF data continuous waveform (not a burst waveform) will be used to convey traffic after link establishment. The FLSU_Request specifies the traffic waveforms that will be used during circuit mode, for example MIL 188-110A (as in this recording), STANAG 4285, STANAG-4539 or other. Once circuit mode begins, any station can initiate transmissions using the specified traffic waveform. A CSMA/CA process is recommended to avoid collisions (Fig. 2)

Fig. 2

Same operational contest was copied on 11132.0 KHz/USB (Figs. 3a, 3b): these are more likely  test sessions that involves both the packet mode (the used datalink protocols are HDL+ and LDL over BW3-BW4 burst waveforms) and the circuit mode (the HF waveform is MIL 188-110A serial). These (test?) transmissions are probably from Algerian Military.

Fig. 3a
Fig. 3b


A STANAG-4538 circuit mode traffic was also copied by my friend Mike (ak mco) on 9003.0 KHz/USB (Fig. 4) who sent me his recording.  The sample consists of n-transmissions, each composed of a MIL 188-110A transfer running at 300bps, preceeded and terminated by BW5 bursts which control the link. More precisely, 188-110A frames transport Harris proprietary Citadel encrypted data, Fig. 5, so it's difficult to say what sits behind.

Fig. 4
Fig. 5

(9003.0 KHz)
https://yadi.sk/d/GCq28TAjzSYzU

8 February 2017

STANAG-4538: 3G-ALE FLSU Async call with Linking Protection

Another decoded sample of FLSU Async call is shown in Figure 1: the first 15 PDUs clearly exhibit alternating patterns that, in my opinion, make sense only in case of Linking Protection mode enabled.

Fig.1
But how Linking Protection works in 3G-ALE networks?
Linking Protection (LP) encrypts only the PDUs used for link setup, traffic setup, link maintenance, link termination, and data link acknowledgement. LP scrambles PDUs using a scrambling algorithm that depends on a key variable, the time of transmission of the PDU, and the frequency on which it is sent (the latter two dependencies enter via a so-called “seed” that is distinct from the key variable): this achieves the two purposes of authenticating each transmission, and combining the called-PU network number with the other bits in an LSU PDU. Indeed, the network number of the called station is used in the linking protection as shown in Figure 2:  the network number is replicated to match the length of the LP encryption key in use in the network, and then exclusive-ored with that key for use as the key in the LP algorithm. 

Fig.2
The seed format is shown in Figure 3, one may read the description of the fields in the paragraph "9.2 Seed Format" of STANAG-4538 profile: for the scope of this post I consider only the fields CVI and Word 

Fig.3
The CVI (Code Validity Interval) field specifies time-units within each day. Normally, this field contains a count of the number of CVIs that have completely elapsed since midnight network time; the Word field is used to count PDUs within a CVI.

For what concerns the formation of the seed and the scrambling procedure, it's important to note that  once a linking process is started using a specific CVI, the calling PU must not change the CVI even if a CVI boundary is crossed during the linking process.
That said, the scanning asynchronous-mode call PDUs are scrambled using alternating Word Numbers 00000000 and 00000001 and the call PDU that concludes an asynchronous-mode call is scrambled using Word Number = 00000010. This means that the same 50-bit PDU is scrambled 15 times (in this sample) using two alternating keys, that's the reason of the alternating patterns seen above (Fig. 4).

Fig.4
One could say that  the last PDU contains a valid 3-bit identifier in the protocol field  ("001") but I think it's a coincidence. Indeed, the scrambling procedure use the SoDark-6 algorithm (48-bit length) and then only the last rightmost 48 bits of each FLSU PDU are scrambled so the remaining bits, ie the first leftmost two bits, are sent without scrambling.
An example of "unprotected" asynchronous FLSU call can be read here

7 February 2017

a modified/proprietary MIL 188-110B/C Appendix C waveform

(updated)
It may happen that manufacturers sometimes modify one or more parameters of standard HF waveforms and then obtain proprietary waveforms (and modems) as in the case of these signals, copied today on 8207.0 KHz/USB around 0940 UTC (Fig. 1).

Fig. 1
The different fadings that affect the bursts lead to think to two stations operating in half-duplex mode. Each burst has a ~2520 msec duration and consists of a 1500Hz single tone modulated with PSK-8 modulation at a costant symbol rate of 1800Bd (Fig. 2): that's a bit odd since we are used to observe PSK-8 modulations coupled with 2400Bd speed and 1800Hz sub-carrier.

Fig. 2
Things get more interesting analyzing preamble and data blocks structure. The first part of the preamble consists of seven blocks of 184 PSK-8 symbols and the data blocks are structured in frames consisting of 287 PSK-8 symbols (ie 861-bit period), as shown in Figure 3.

Fig. 3a
Fig. 3b

This is clearly a MIL 188-110B/C Appendix C (or STANAG-4539) modem, but what about the symbol-rate (1800Bd) and the sub-carrier (1500Hz)?
As said above, modem manufacturers may change one or more parameters of the HF waveforms: in this case we face a sort of underclocked STANAG-4539 modem, ie the modulation speed is reduced from 2400 to 1800 Baud as well as the sub-carrier frequency from 1800 to 1500 Hz.
Let's see a trick (thanks to KarapuZ) that prove that it's a S4539 modem: correcting the baud-rate and shifting the signal (Fig. 4) we get the right S4539 3200bps/short interleaving waveform which can be easily processed and demodulated (Fig. 5).

Fig. 4
Fig. 5
By the way, the signals transport STANAG-5066 data.

Another clue to identify the modem/manufacturer is the 1250Hz "roger beep" sometimes heard during voice-comms before the data transmissions. Helps are welcome.

A good "candidate" could be the CODAN 3212 HF-modem, this modem use a modified STANAG-4539 (188-110B App.C) to fit 2400 Hz channels (thanks to Johannes for the hint):
https://www.codanradio.com/product/3212-7200-bps/ 







5 February 2017

CV-786 (TRC-75) FSK 75Bd/850Hz bursts


CV-786 is a synchronous wideband FSK mode compliant with STANAG-4481, shore-to-ship RATT FSK 75Bd/850 waveform: in this sample the bursts transport KG-84C on-line encrypted contents. I copied a long-run transmission (...hours) on 11464.0 KHz/USB with 2 KHz offset; given the strong signal, the tx site could be the US military base in Niscemi, Sicily Island Italy.

CV-786 mode is built in Rockwell-Collins MDM-2001 HF Modems and used in TRC-75 transceivers: