🤖 AI Summary
This study addresses a critical security gap in public safety communication systems—such as TETRA, TETRAPOL, and P25—whose signaling planes have long transmitted metadata in plaintext, even when voice payloads are encrypted. By leveraging software-defined radio (SDR) for passive eavesdropping, combined with protocol reverse engineering and metadata correlation analysis, this work demonstrates for the first time that nationwide network mapping and user tracking are feasible using signaling data alone. The research uncovers a standards-level confidentiality flaw in TETRAPOL’s emergency call mechanism and successfully recovers key operational parameters, including base station and terminal identities, group mobility patterns, key domain boundaries, and rotation cycles. Notably, it also extracts unencrypted voice content from TETRAPOL transmissions, underscoring fundamental weaknesses in the signaling confidentiality design of current public safety networks.
📝 Abstract
Public-safety agencies and critical infrastructure operators rely on trunked land-mobile radio (LMR) systems, based on P25, TETRA, and TETRAPOL. These systems are expected to protect not just the content of a communication but the fact of it. Yet LMR standards leave a stark gap between confidentiality of \emph{content} and of \emph{communication}: underneath an encrypted traffic plane, their signaling plane is almost entirely in the clear. We probe the depth and impact of adversarial inference from this exposed signaling.
Prior security analyses of these systems have concentrated on the content plane---recovering encryption keys or capturing accidental cleartext. We show that comparably sensitive information can be \emph{inferred from passively observed signaling even if the content encryption were perfect}.
In particular, we show that across the trunked LMR standards, a passive, receive-only software-defined radio (SDR) observer can recover operationally sensitive network topology and geography details, unit presence, mobility across cells and groups, organizational structure, as well as operational security details such as special key domains and key-epoch rotation. This signaling-plane inference reaches far beyond the observer's direct area of reception, turning \emph{local} sniffing into \emph{nationwide} network mapping capabilities that degrade or defeat LMR standards' identity obfuscation through timing and association. In the case of TETRAPOL, we demonstrate how inference and tracking of such signaling metadata and a standards-level confidentiality failure in emergency call handling enable unencrypted voice extraction.
Finally, we discuss potential countermeasures and mitigations, including specific recommendations for protecting inter-cell, base station and subscriber identities.