The Hidden Life of Public Safety Communications Signals: A Comparative Security Analysis of TETRA, TETRAPOL, and P25
arXiv SecurityArchived Aug 07, 2026✓ Full text saved
arXiv:2608.05247v1 Announce Type: new Abstract: Public-safety agencies and critical infrastructure operators rely on trunked land-mobile radio (LMR) systems, based on P25, TETRA, and TETRAPOL. These systems are expected to protect not just the content of a communication but the fact of it. Yet LMR standards leave a stark gap between confidentiality of \emph{content} and of \emph{communication}: underneath an encrypted traffic plane, their signaling plane is almost entirely in the clear. We probe
Full text archived locally
✦ AI Summary· Claude Sonnet
Computer Science > Cryptography and Security
[Submitted on 5 Aug 2026]
The Hidden Life of Public Safety Communications Signals: A Comparative Security Analysis of TETRA, TETRAPOL, and P25
Larry Hernandez, Sergey Bratus
Public-safety agencies and critical infrastructure operators rely on trunked land-mobile radio (LMR) systems, based on P25, TETRA, and TETRAPOL. These systems are expected to protect not just the content of a communication but the fact of it. Yet LMR standards leave a stark gap between confidentiality of \emph{content} and of \emph{communication}: underneath an encrypted traffic plane, their signaling plane is almost entirely in the clear. We probe the depth and impact of adversarial inference from this exposed signaling.
Prior security analyses of these systems have concentrated on the content plane---recovering encryption keys or capturing accidental cleartext. We show that comparably sensitive information can be \emph{inferred from passively observed signaling even if the content encryption were perfect}.
In particular, we show that across the trunked LMR standards, a passive, receive-only software-defined radio (SDR) observer can recover operationally sensitive network topology and geography details, unit presence, mobility across cells and groups, organizational structure, as well as operational security details such as special key domains and key-epoch rotation. This signaling-plane inference reaches far beyond the observer's direct area of reception, turning \emph{local} sniffing into \emph{nationwide} network mapping capabilities that degrade or defeat LMR standards' identity obfuscation through timing and association. In the case of TETRAPOL, we demonstrate how inference and tracking of such signaling metadata and a standards-level confidentiality failure in emergency call handling enable unencrypted voice extraction.
Finally, we discuss potential countermeasures and mitigations, including specific recommendations for protecting inter-cell, base station and subscriber identities.
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:2608.05247 [cs.CR]
(or arXiv:2608.05247v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.05247
Focus to learn more
Submission history
From: Larry Hernandez [view email]
[v1] Wed, 5 Aug 2026 15:39:45 UTC (4,943 KB)
Access Paper:
view license
Current browse context:
cs.CR
< prev | next >
new | recent | 2026-08
Change to browse by:
cs
References & Citations
NASA ADS
Google Scholar
Semantic Scholar
Export BibTeX Citation
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Demos
Related Papers
About arXivLabs
Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)