Search papers, labs, and topics across Lattice.
This paper conducts a comparative security analysis of trunked land-mobile radio (LMR) systems, specifically P25, TETRA, and TETRAPOL, revealing significant vulnerabilities in their signaling planes. The authors demonstrate that even with perfect content encryption, adversaries can infer sensitive operational details such as network topology, unit presence, and mobility patterns from passively observed signaling data. Their findings highlight a critical gap in LMR standards, where the exposure of signaling information undermines the intended confidentiality and security of public safety communications.
Adversaries can extract sensitive operational intelligence from public safety communications even when content is encrypted, revealing a critical flaw in LMR security standards.
Public-safety agencies and critical infrastructure operators rely on trunked land-mobile radio (LMR) systems, based on P25, TETRA, and TETRAPOL. These systems are expected to protect not just the content of a communication but the fact of it. Yet LMR standards leave a stark gap between confidentiality of \emph{content} and of \emph{communication}: underneath an encrypted traffic plane, their signaling plane is almost entirely in the clear. We probe the depth and impact of adversarial inference from this exposed signaling. Prior security analyses of these systems have concentrated on the content plane---recovering encryption keys or capturing accidental cleartext. We show that comparably sensitive information can be \emph{inferred from passively observed signaling even if the content encryption were perfect}. In particular, we show that across the trunked LMR standards, a passive, receive-only software-defined radio (SDR) observer can recover operationally sensitive network topology and geography details, unit presence, mobility across cells and groups, organizational structure, as well as operational security details such as special key domains and key-epoch rotation. This signaling-plane inference reaches far beyond the observer's direct area of reception, turning \emph{local} sniffing into \emph{nationwide} network mapping capabilities that degrade or defeat LMR standards' identity obfuscation through timing and association. In the case of TETRAPOL, we demonstrate how inference and tracking of such signaling metadata and a standards-level confidentiality failure in emergency call handling enable unencrypted voice extraction. Finally, we discuss potential countermeasures and mitigations, including specific recommendations for protecting inter-cell, base station and subscriber identities.