MotoTRBO Restricted Access to System (RAS)

Status
Not open for further replies.

Forts

Mentor
Database Admin
Joined
Dec 19, 2002
Messages
6,889
Location
Ontario, Canada
If they don't want to be monitored all they need to do is check that little Privacy box. RAS + Enhanced Privacy works pretty good.

Sent from my SM-N9005 using Tapatalk
 

natedawg1604

Member
Premium Subscriber
Joined
Jun 29, 2013
Messages
2,734
Location
Colorado
The bad checksums? Should be a dead giveaway, I would think.

I'm afraid I don't know much about crc's, in the log excerpts below which section of the messages contain the checksums?


2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 Voice Hdr ECC/RAS Cap+ Enc GC TG=10 RID=1396 RestCh=1
2016.04.28 20:46:44
2016.04.28 20:46:44 +DMR slot1 BS DATA DCC=13 CSBK Cap+ RestCh=1 ActiveCh:TG=2:10
2016.04.28 20:46:44 [LB=1 CSBKO=62 (?) FID=16 v16=C140 id1=655360 id2=0]
2016.04.28 20:46:44 3E 10 C140 0A0000 000000
2016.04.28 20:46:44 101111100001000011000001010000000000101000000000000000000000000000000000000000000110111010010011
2016.04.28 20:46:44 Cap+ Site=3 RestCh=1
2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 Voice Hdr ECC/RAS Cap+ Enc GC TG=10 RID=1396 RestCh=1
2016.04.28 20:46:44
2016.04.28 20:46:44 +DMR slot1 BS DATA DCC=13 CSBK Cap+ RestCh=1 ActiveCh:TG=2:10
2016.04.28 20:46:44 [LB=1 CSBKO=62 (?) FID=16 v16=C140 id1=655360 id2=0]
2016.04.28 20:46:44 3E 10 C140 0A0000 000000
2016.04.28 20:46:44 101111100001000011000001010000000000101000000000000000000000000000000000000000000110111010010011
2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 PI Header ECC/RAS KID=10 MI=BE884957 Tgt=10
2016.04.28 20:46:44 []
2016.04.28 20:46:44 21100ABE8849570000
2016.04.28 20:46:44 001000010001000000001010101111101000100001001001010101110000000000000000000010100100111011101001
2016.04.28 20:46:44 +DMR slot1 BS DATA DCC=13 CSBK Cap+ RestCh=1 ActiveCh:TG=2:10
2016.04.28 20:46:44 [LB=1 CSBKO=62 (?) FID=16 v16=C140 id1=655360 id2=0]
2016.04.28 20:46:44 3E 10 C140 0A0000 000000


2016.04.28 20:46:45 +DMR slot1 BS DATA DCC=13 CSBK Cap+ RestCh=1 ActiveCh:TG=2:10
2016.04.28 20:46:45 [LB=1 CSBKO=62 (?) FID=16 v16=C140 id1=655360 id2=0]
2016.04.28 20:46:45 3E 10 C140 0A0000 000000
2016.04.28 20:46:45 101111100001000011000001010000000000101000000000000000000000000000000000000000000110111010010011
2016.04.28 20:46:45 Cap+ Site=3 RestCh=1
2016.04.28 20:46:45 +DMR slot2 BS DATA DCC=13 TLC ECC/RAS GC End TG=10 RID=1396
2016.04.28 20:46:45 [FLCO=0 FID=16 v8=40 id1=10 id2=1396]
2016.04.28 20:46:45 00 10 40 00000A 000574
2016.04.28 20:46:45 000000000001000001000000000000000000000000001010000000000000010101110100010110110000101101111101
2016.04.28 20:46:45 +DMR slot1 BS DATA DCC=13 CSBK Cap+ RestCh=1 ActiveCh:TG=2:10
2016.04.28 20:46:45 [LB=1 CSBKO=62 (?) FID=16 v16=C140 id1=655360 id2=0]
2016.04.28 20:46:45 3E 10 C140 0A0000 000000
2016.04.28 20:46:45 101111100001000011000001010000000000101000000000000000000000000000000000000000000110111010010011
2016.04.28 20:46:45 +DMR slot2 BS DATA DCC=13 TLC ECC/RAS GC End TG=10 RID=1396
2016.04.28 20:46:45 [FLCO=0 FID=16 v8=40 id1=10 id2=1396]
2016.04.28 20:46:45 00 10 40 00000A 000574
2016.04.28 20:46:45 000000000001000001000000000000000000000000001010000000000000010101110100010110110000101101111101
2016.04.28 20:46:45 4114 radio records saved; 49 aliases
2016.04.28 20:46:45 +DMR slot1 BS DATA DCC=13 CSBK Cap+ RestCh=1 ActiveCh:TG=2:10
2016.04.28 20:46:45 [LB=1 CSBKO=62 (?) FID=16 v16=C140 id1=655360 id2=0]
2016.04.28 20:46:45 3E 10 C140 0A0000 000000
2016.04.28 20:46:45 101111100001000011000001010000000000101000000000000000000000000000000000000000000110111010010011
2016.04.28 20:46:45 Cap+ Site=3 RestCh=1
 

slicerwizard

Member
Joined
Sep 19, 2002
Messages
7,714
Location
Toronto, Ontario
I'm afraid I don't know much about crc's, in the log excerpts below which section of the messages contain the checksums?
Well, it's easy to see which messages DSD+ is flagging as having bad checksums:

2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 Voice Hdr ECC/RAS Cap+ Enc GC TG=10 RID=1396 RestCh=1
2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 Voice Hdr ECC/RAS Cap+ Enc GC TG=10 RID=1396 RestCh=1
2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 PI Header ECC/RAS KID=10 MI=BE884957 Tgt=10
2016.04.28 20:46:45 +DMR slot2 BS DATA DCC=13 TLC ECC/RAS GC End TG=10 RID=1396
2016.04.28 20:46:45 +DMR slot2 BS DATA DCC=13 TLC ECC/RAS GC End TG=10 RID=1396

It's not actually displaying the checksums, though.

Looks like you're dealing with a locked down system (RAS plus EP)
 

natedawg1604

Member
Premium Subscriber
Joined
Jun 29, 2013
Messages
2,734
Location
Colorado
Well, it's easy to see which messages DSD+ is flagging as having bad checksums:

2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 Voice Hdr ECC/RAS Cap+ Enc GC TG=10 RID=1396 RestCh=1
2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 Voice Hdr ECC/RAS Cap+ Enc GC TG=10 RID=1396 RestCh=1
2016.04.28 20:46:44 +DMR slot2 BS DATA DCC=13 PI Header ECC/RAS KID=10 MI=BE884957 Tgt=10
2016.04.28 20:46:45 +DMR slot2 BS DATA DCC=13 TLC ECC/RAS GC End TG=10 RID=1396
2016.04.28 20:46:45 +DMR slot2 BS DATA DCC=13 TLC ECC/RAS GC End TG=10 RID=1396

It's not actually displaying the checksums, though.

Looks like you're dealing with a locked down system (RAS plus EP)

Yeah I knew the system was using ENC + RAS. So, is it possible to see the checksum hex blocks in DMRDecode? Or any other SDR program? Or perhaps wireshark (not quite sure how that would be configured...)?
 

natedawg1604

Member
Premium Subscriber
Joined
Jun 29, 2013
Messages
2,734
Location
Colorado
Probably, yes. What are you looking to do with them?

I suppose nothing beyond morbid curiosity, at least for now. I can't code with anything other than python, I'm just interested getting a better understanding of DMR messages coming across the ether...
 

slicerwizard

Member
Joined
Sep 19, 2002
Messages
7,714
Location
Toronto, Ontario
Well, at most, you'd find that a specific message, like a voice header for RID x on TG y, has one 16 bit CRC on a non-RAS system, and a totally different jumble of 16 CRC bits on a RAS system. Then what? Doesn't lead anywhere. Of course, that assumes you can match everything else in the voice header (DCC, Rest channel number, ...), as any difference, even a single bit, will also create a vastly different CRC.
 

gvodvarka

Member
Joined
Nov 10, 2009
Messages
71
Location
Ontario, Ca.
RAS TX

The Uniden DMR scanners can decode RAS-enabled transmissions. I can't speak for the Whistler models.

Thanks, I want to purchase the new Whistler model for my two-way radio shop but I need it to hear everything like DMR Decode does. Caring a service monitor and a computer around gets old. Gary
 

hamtrektng

Member
Joined
Aug 9, 2015
Messages
75
Location
Plymouth, UK
Unicode related to RAS?

Hi guys,

Whilst busying myself with scanning DMR systems I came across this at my local fuel station frequency. on DSD+ I look at the console screen and it appears with 'Unicode string. As I understand from the systems info, it is a EP enabled TX. I have tried getting a possible key from DSD but have said that it can't be decyrpted as it is not a standard DMR enabled algorithm system. Can anyone please explain what this is in screenshot?
 

Attachments

  • Untitled.jpg
    Untitled.jpg
    83.3 KB · Views: 1,493

Forts

Mentor
Database Admin
Joined
Dec 19, 2002
Messages
6,889
Location
Ontario, Canada
Hi guys,

Whilst busying myself with scanning DMR systems I came across this at my local fuel station frequency. on DSD+ I look at the console screen and it appears with 'Unicode string. As I understand from the systems info, it is a EP enabled TX. I have tried getting a possible key from DSD but have said that it can't be decyrpted as it is not a standard DMR enabled algorithm system. Can anyone please explain what this is in screenshot?

DMR has many different possible encryption schemes, depending on the vendor. None of this information will be revealed by DSD however as keys are not transmitted over the air (which makes perfect sense).
 

gvodvarka

Member
Joined
Nov 10, 2009
Messages
71
Location
Ontario, Ca.
RAS and TXR-1

If they don't want to be monitored all they need to do is check that little Privacy box. RAS + Enhanced Privacy works pretty good.

Sent from my SM-N9005 using Tapatalk

It look like the txr-1 scanner decodes with RAS on in the search mode but not in a programmed slot. I sent the info to one of the beta testers today to confirm what was going on. Hope they can fix it. Gary
 

gvodvarka

Member
Joined
Nov 10, 2009
Messages
71
Location
Ontario, Ca.
It look like the txr-1 scanner decodes with RAS on in the search mode but not in a programmed slot. I sent the info to one of the beta testers today to confirm what was going on. Hope they can fix it. Gary



TRX1&2 RAS no longer a problem. Decodes perfect now.


Sent from my iPad using Tapatalk
 
Status
Not open for further replies.
Top