The Hidden Life of Public Safety Communications Signals: A Comparative Security Analysis of TETRA, TETRAPOL, and P25

📅 2026-08-05
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses a critical security gap in public safety communication systems—such as TETRA, TETRAPOL, and P25—whose signaling planes have long transmitted metadata in plaintext, even when voice payloads are encrypted. By leveraging software-defined radio (SDR) for passive eavesdropping, combined with protocol reverse engineering and metadata correlation analysis, this work demonstrates for the first time that nationwide network mapping and user tracking are feasible using signaling data alone. The research uncovers a standards-level confidentiality flaw in TETRAPOL’s emergency call mechanism and successfully recovers key operational parameters, including base station and terminal identities, group mobility patterns, key domain boundaries, and rotation cycles. Notably, it also extracts unencrypted voice content from TETRAPOL transmissions, underscoring fundamental weaknesses in the signaling confidentiality design of current public safety networks.
📝 Abstract
Public-safety agencies and critical infrastructure operators rely on trunked land-mobile radio (LMR) systems, based on P25, TETRA, and TETRAPOL. These systems are expected to protect not just the content of a communication but the fact of it. Yet LMR standards leave a stark gap between confidentiality of \emph{content} and of \emph{communication}: underneath an encrypted traffic plane, their signaling plane is almost entirely in the clear. We probe the depth and impact of adversarial inference from this exposed signaling. Prior security analyses of these systems have concentrated on the content plane---recovering encryption keys or capturing accidental cleartext. We show that comparably sensitive information can be \emph{inferred from passively observed signaling even if the content encryption were perfect}. In particular, we show that across the trunked LMR standards, a passive, receive-only software-defined radio (SDR) observer can recover operationally sensitive network topology and geography details, unit presence, mobility across cells and groups, organizational structure, as well as operational security details such as special key domains and key-epoch rotation. This signaling-plane inference reaches far beyond the observer's direct area of reception, turning \emph{local} sniffing into \emph{nationwide} network mapping capabilities that degrade or defeat LMR standards' identity obfuscation through timing and association. In the case of TETRAPOL, we demonstrate how inference and tracking of such signaling metadata and a standards-level confidentiality failure in emergency call handling enable unencrypted voice extraction. Finally, we discuss potential countermeasures and mitigations, including specific recommendations for protecting inter-cell, base station and subscriber identities.
Problem

Research questions and friction points this paper is trying to address.

LMR
signaling plane
metadata inference
public safety communications
confidentiality
Innovation

Methods, ideas, or system contributions that make the work stand out.

signaling-plane inference
trunked LMR security
metadata leakage
passive SDR eavesdropping
identity obfuscation failure
🔎 Similar Papers
No similar papers found.