control channel decoding help

Status
Not open for further replies.

fpo701

OH DB Admin
Database Admin
Joined
Dec 19, 2002
Messages
950
Reaction score
27
Location
Akron, OH
Hey gang!

I need some help. I'm a software engineer. I do a lot of personal dabbling to help broaden my skills. I'm also and avid scanner listener (30+ years now).

My next purchase will be a BCD-396XT. I'm interested in the control channel output stuff. I thought I get a head start on something to decode/interpret/whatever the control channel data.

I want to start simple. Everything I listen to is Motorola TypeII. In reading the 396XT's spec, messages would look like:

MOT,<cmd>,<prv>,<id>
<cmd> = command or LCN (Hex 3 digits, 10 bits)
<prv> = private bit (1 bit)
<id> = ID (Hex 4 digit, 16 bits)

Great! Now, what? How does that help? Don't I need some kind of command reference?

Is there some place you trunking decoding experts can point me to on how to interpret the control channel data?

Thanks,
Frank
 

slicerwizard

Member
Joined
Sep 19, 2002
Messages
7,802
Reaction score
2,197
Location
Toronto, Ontario
Examples of over 99% of the OSWs seen on a Type II system (channel grant, late entry, status, SysID, CC marker, zone number/alias, neighbour zone, patch/MSEL announcement, affiliation, deaffiliation, idle) are show below.

Command 308 indicates first OSW of multi-OSW command; 320 indicates second OSW of triple OSW command. 321 is digital version of 308 command.

VHF/UHF systems replace the 308 in call grants with the call's input channel number.


Of the 000 to 3FF command values, most represent channel numbers: http://home.ica.net/~phoenix/wap/TRUNK88/Motorola Channel Numbers.txt

Most of the "invalid" channel numbers in that table are used by various commands, e.g. 2F8 = idle, 360 through 39F = current zone number (1 to 64), etc.


The I/G group bit generally indicates if a command is directed at one or more radios, e.g. it is set (G) for group call references, but not set (I) for radio to radio calls, phone calls, affiliations, deaffiliations, etc.

Code:
3BF G 600C  Net status #3; Wide area trunking; Site rotation 0; Astro wide pulse; 2 level secure signalling
308 G 1123  Patch 1112 includes TG 112
340 G 1112
2F8 I 0B19  Idle
3BF I 4B00  Net status #2; Secure channels available; Clear to secure upgrade enabled; Reduced data mode; No digital comms echo delay
308 G 1303  Patch 1130 includes TG 130
340 G 1130
308 G 4032  SysID; SysID=4032  ctl chan=CC
30B G 28CC
0CC I 1FF2  Control channel marker; Control Chan=CC
308 G 1113  Patch 1112 includes TG 111
340 G 1112
308 G 1283  Patch 1130 includes TG 128
340 G 1130
308 G 0EE1  Group call grant; TG=101  RID=EE1  Chan=F6
0F6 G 1013
308 G 0EE1  Group call grant; TG=101  RID=EE1  Chan=F6
0F6 G 1013
3BF G 3040  Net status #1; Affiliate on PwrUp; Connect tone: 83.72 Hz; No dispatch timeout; No interconnect timeout
3C0 G 4800  System status #2; Secure channels available; Clear to secure upgrade enabled; Reduced data mode; No digital comms echo delay
3C0 G 3040  System status #1; Affiliate on PwrUp; Connect tone: 83.72 Hz; No dispatch timeout; No interconnect timeout
308 G 1078  Group call grant; TG=148  RID=1078  Chan=1DE
1DE G 1480
308 I 0CA5  Affiliation request; RID=CA5
30B I 261B
309 I 12CB  Affiliation; RID=12CB  TG=104
310 I 104A
3BF G 3040  NS1
308 G 1323  Patch 1132 includes TG 132
340 G 1132
308 G 27D3  Group call grant; TG=152  RID=27D3  Chan=1CA
1CA G 1520
321 G 4DBF  Secure digital group call grant; TG=4BA  RID=4DBF  Chan=267
267 G 4BA8
1CA G 1520  Group call; TG=152  Chan=1CA
267 G 4BA8  Secure group call; TG=4BA  Chan=267
309 I 0CA5  Affiliation; RID=CA5  TG=132
310 I 132A
308 G 1323  Patch 1132 includes TG 132
340 G 1132
309 I 0CA5  Affiliation; RID=CA5  TG=132
310 I 132A
3C0 G 4800  SS2
3C0 G 3040  SS1
3BF G 600C  NS3
309 I 12CB  Affiliation; RID=12CB  TG=104
310 I 104A
308 I 121A  Deaffiliation; RID=121A
30B I 261C
309 I 00AA  Affiliation; RID=AA  TG=148
310 I 148A
308 G 4032  Net info; Neighbour site; SysID=4032  Cell#=6  PCC=11E
320 G 159C    Features: Astro and analog; Wide area trunking
30B G 611E
308 G 1303  Patch 1130 includes TG 130
340 G 1130
308 G 1113  Patch 1112 includes TG 111
340 G 1112
308 G 3C08  SysID; SysID=3C08  ctl chan=1E8
30B G 29E8
308 G 4032  Net info; Current site; SysID=4032  Cell#=49  ACC=D6
320 G C19C    Features: Astro and analog; Wide area trunking
30B I 60D6
308 I 2C4E  Private call; From RID=2C59 to RID=2C4E  Chan=12A
12A I 2C59
390 I 34C8  Site ID; Site #49; Site letters: 'TR____'
0AC I 2528  Type2 interconnect; RID=2528  Chan=AC
390 I 69E8  Site ID; Site #49; Site letters: '__IZ__'
390 I A58C  Site ID; Site #49; Site letters: '____EC'
 

fpo701

OH DB Admin
Database Admin
Joined
Dec 19, 2002
Messages
950
Reaction score
27
Location
Akron, OH
Cool. Now, can I get some explanation of when some things happen?

1) what the difference between 'affiliation' and 'affiliation request'?

2) when does a radio affiliate?

Some time ago, someone I know was using trunker (or some equivalent). I thought from his explanation that when a radio was in scan mode, you'd see what talkgroups he was scanning. It sounded as if he didn't have to be talking to see this information. Is that what the affiliate is doing? Is this only something that is broadcast when needed?

Thanks...
 

WayneH

Forums Veteran
Super Moderator
Joined
Dec 16, 2000
Messages
7,555
Reaction score
95
Location
Your master site
I would recommend reading up on as much Motorola Type II information you can find. It will assist you in what's happening as there's a lot of background activity on these types of systems. Take a look at the Wiki if you haven't yet. Searching here as well as Google will give you a lot of info too as it's a very old protocol.

An affiliation is sent only in the following conditions: the radio is requested to, it powers up or it changes channels. Long ago there was a certain model of radio introduced that had buggy firmware. When it scanning it would affiliate on whichever channel scan decided to monitor. This overloaded the system due to all the scanning radios on the system sending aff reqs. It was a clusterf...
 

fpo701

OH DB Admin
Database Admin
Joined
Dec 19, 2002
Messages
950
Reaction score
27
Location
Akron, OH
That's my problem. I understand that I need to read up on Type II information. That's the problem. I can't find any. Hence, I posted a message here.

I have yet to figure out the magical conbination of words to enter in Google to get anything close to a message/protocol spec.
 

fpo701

OH DB Admin
Database Admin
Joined
Dec 19, 2002
Messages
950
Reaction score
27
Location
Akron, OH
Thanks, but not really. I understand trunked systems. What I want to understand is all the "funky" data like is in the first reply. Someone has to have this documented somewhere. How else would things like Trunker be able to be developed?
 

davidbond21

Member
Joined
May 18, 2005
Messages
531
Reaction score
0
Location
New Braunfels, TX
If you are a software engineer, then I assume you learned C++ somewhere along the way. You can actually download the source code for the Trunker program. I haven't used this, but it does EDACS and Motorola types(at least from the description of it).

I'm sure that you could look at the code for this and glean from it how the control channel data is used, since the program has to interpret those commands to work.

http://wiki.radioreference.com/index.php/Trunker#Source_Code_.2F_Compiling_Yourself
 

fpo701

OH DB Admin
Database Admin
Joined
Dec 19, 2002
Messages
950
Reaction score
27
Location
Akron, OH
Yes. I have the misfortune of having C++ under my belt (along with many other languages I shutter to mention, like LISP and Bison). I had already taken a look at that code. It seemed to be about the best source. I figure they had to learn those codes somewhere. I was hoping to have someone point me to the master list of codes. Many of the codes seem to take the form of needing two or more "messages" to complete.

Having the spec would make life much easier.
 

SCPD

QRT
Joined
Feb 24, 2001
Messages
0
Reaction score
115
Location
Virginia
Having the spec would make life much easier.
Motorola is the only trunking format for which there is no published specification. Every other format has been published in some form.

The code you're looking at is the result of many hours empirically observing control channel behavior. Someone observed a pattern; they added or adjusted code to match that pattern; repeating the process over and over with each iteration reducing the number of unknown messages.
 

K8TEK

Completely Banned for the Greater Good
Banned
Joined
Jul 13, 2004
Messages
681
Reaction score
3
Location
Ohio
Motorola is the only trunking format for which there is no published specification. Every other format has been published in some form.

The code you're looking at is the result of many hours empirically observing control channel behavior. Someone observed a pattern; they added or adjusted code to match that pattern; repeating the process over and over with each iteration reducing the number of unknown messages.
Exactly. There are no published white papers on the protocol. That is why people like EF Johnson has to pay a ton of money to make a smartzone/smartnet radio.
 

fpo701

OH DB Admin
Database Admin
Joined
Dec 19, 2002
Messages
950
Reaction score
27
Location
Akron, OH
How does one parse the 390 message?

(from first reply above)
390 I 34C8 Site ID; Site #49; Site letters: 'TR____'
0AC I 2528 Type2 interconnect; RID=2528 Chan=AC
390 I 69E8 Site ID; Site #49; Site letters: '__IZ__'
390 I A58C Site ID; Site #49; Site letters: '____EC'

Also, is there no way to tell when a patch is removed?
 

slicerwizard

Member
Joined
Sep 19, 2002
Messages
7,802
Reaction score
2,197
Location
Toronto, Ontario
How does one parse the 390 message?
Commands 360 through 39F (what a waste of 64 command slots) identify the current SmartZone zone number; 360 = zone 1, 361 = zone 2, etc.

If the OSW's group bit is not set, the ID field contains two letters of the zone's six character zone alias string. The highest 2 bits indicate which of the three letter pairs is encoded. The next 6 + 6 bits each encode a character. The two low order bits are ignored.


// extract two characters (0 to 63 = ' ' to '_')
// " !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_"

n = (ID & 0xc000) >> 13; // (valid) n = 0, 2 or 4

if (n < 6)
{
alias_text[n] = ' ' + ((ID & 0x3f00) >> 8);
alias_text[n + 1] = ' ' + ((ID & 0xfc) >> 2);
}


Also, is there no way to tell when a patch is removed?
On a non-networked system, you should see the [308 G TG] [30B G 2021] patch/MSEL termination sequence when a patch or MSEL terminates.

On a networked SmartZone site (e.g. a site on a multi-zone system), you might see patch announcements start appearing when a radio using a patched talkgroup affiliates to the site; when the radio leaves the site, the announcements can just stop (if no other users on the site are using the patched group) and you will not see a termination sequence if/when the patch is terminated.
 
Last edited:

fpo701

OH DB Admin
Database Admin
Joined
Dec 19, 2002
Messages
950
Reaction score
27
Location
Akron, OH
Qucik question on Neighbor Info sequence. From what I've come to understand, when a nrighbor site is given, the control channel in the message is the Primary Control Channel of the neighbor.

I just stumbled on an article (Freq Of Nature How a SmartZone System Works) that says:
Also part of the OSW datastream is the current control channel frequency at up to 7 adjacent radio sites. The subscriber radios also store that in memory.

Note CURRENT, not Primary, of the neighbor. To me that makes more sense. If the user roams into an adjacent site, the radio would want to know what to tune to. It makes more sense to tell it what to tune to currently, in case the neighbor site is not on the primary control channel.

From this, I would sermise that all one can get from the neighbors is a list of control channels, not the primary. The same would apply to the current site on SmartNet systems. There should be no way of knowing which is the primary, since they rotate daily and the one being broadcast is the current, not the primary.

Is that correct, or am I once again clueless?

Thanks,
Frank
 

slicerwizard

Member
Joined
Sep 19, 2002
Messages
7,802
Reaction score
2,197
Location
Toronto, Ontario
Qucik question on Neighbor Info sequence. From what I've come to understand, when a nrighbor site is given, the control channel in the message is the Primary Control Channel of the neighbor.
Correct.


I just stumbled on an article (Freq Of Nature How a SmartZone System Works) that says:
Also part of the OSW datastream is the current control channel frequency at up to 7 adjacent radio sites. The subscriber radios also store that in memory.
Correct.


Note CURRENT, not Primary, of the neighbor.
Same thing, as far as I can tell.


To me that makes more sense. If the user roams into an adjacent site, the radio would want to know what to tune to. It makes more sense to tell it what to tune to currently, in case the neighbor site is not on the primary control channel.

From this, I would sermise that all one can get from the neighbors is a list of control channels, not the primary.
If it's active on a SmartZone site, we call it the primary control channel.

Since some SmartZone systems rotate their control channels daily and some don't (e.g. they have preferred control channels), but decoding software has no way to determine this, what labels are you going to use besides current = primary and others = alternate?


The same would apply to the current site on SmartNet systems. There should be no way of knowing which is the primary, since they rotate daily and the one being broadcast is the current, not the primary.
SmartNet sites only broadcast the channel number of the current CC; there are no references to alternates, so we tend to not use the primary/alternate tags. They're just control channels and one is the current one.
 

WayneH

Forums Veteran
Super Moderator
Joined
Dec 16, 2000
Messages
7,555
Reaction score
95
Location
Your master site
SmartZone systems won't rotate their control channels like the older systems under control of a 6809 controller unless a fault occurs. I'm pretty sure the newer MTS3600 controllers don't either.

One thing left out of the article is radios will sample the adjacent site control channel signal levels and roam off when one meets the radio's programming acceptable levels. Losing the CC is not the deciding factor like the article says it is.
 
Last edited:

fpo701

OH DB Admin
Database Admin
Joined
Dec 19, 2002
Messages
950
Reaction score
27
Location
Akron, OH
So on SmartZone, it is pretty safe to assume that "Primary" and "Current" are almost always the same meaning?

It sounds like a rare case when the current channel isn't the primary channel. In that case, the channel being broadcast on the neighbor list of a neighbor (that sounds cofusing :)) is new "current" channel. Right?

Thanks for the help on this guys.

Frank
 

WayneH

Forums Veteran
Super Moderator
Joined
Dec 16, 2000
Messages
7,555
Reaction score
95
Location
Your master site
Almost always, yes. The use of Primary is really up to one's vernacular. I'd call it a dated term.

In some cases what's considered the primary may have failed so it obviously would not be the current control channel hence "almost always".
 
Status
Not open for further replies.
Top