<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.recessim.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Blind</id>
	<title>RECESSIM - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.recessim.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Blind"/>
	<link rel="alternate" type="text/html" href="https://wiki.recessim.com/view/Special:Contributions/Blind"/>
	<updated>2026-09-02T12:45:59Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://wiki.recessim.com/w/index.php?title=Silver_Spring_Networks_Access_Point&amp;diff=3686</id>
		<title>Silver Spring Networks Access Point</title>
		<link rel="alternate" type="text/html" href="https://wiki.recessim.com/w/index.php?title=Silver_Spring_Networks_Access_Point&amp;diff=3686"/>
		<updated>2026-08-31T20:56:39Z</updated>

		<summary type="html">&lt;p&gt;Blind: Add on-air identification — EUI-64 addressing, mesh-root role, backhaul&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;gallery mode=&amp;quot;packed&amp;quot; heights=&amp;quot;250&amp;quot;&amp;gt;&lt;br /&gt;
File:SilverSpringRouter1.JPG| Top of Housing &lt;br /&gt;
File:SilverSpringRouter3.JPG| Interior showing cellular modem and circuit boards &lt;br /&gt;
File:SilverSpringRouter4.JPG| Inside of metal lid &lt;br /&gt;
File:SilverSpringRouter5.JPG| Model number &lt;br /&gt;
File:SilverSpringRouter6.JPG&lt;br /&gt;
File:SilverSpringRouter7.JPG| GPS and cellular antenna connector &lt;br /&gt;
File:SilverSpringRouter8.JPG| Power connector &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
== On-air identification and role ==&lt;br /&gt;
&lt;br /&gt;
(From passive capture of a fixed-AMI NIC 511 network — see&lt;br /&gt;
[[Silver Spring Networks Protocol]] for the frame format.)&lt;br /&gt;
&lt;br /&gt;
Access points are the root of a local mesh cell: endpoints and relays route&lt;br /&gt;
toward them, and they backhaul to the utility head-end over cellular (the modem&lt;br /&gt;
in the teardown photos above) or fibre.&lt;br /&gt;
&lt;br /&gt;
They are addressed by &#039;&#039;&#039;EUI-64&#039;&#039;&#039;, distinct from endpoint meters:&lt;br /&gt;
&lt;br /&gt;
* Access point / infrastructure: &amp;lt;code&amp;gt;00:13:50:FF:FE:60:xx:xx:xx&amp;lt;/code&amp;gt; — the&lt;br /&gt;
  Silver Spring OUI &amp;lt;code&amp;gt;00:13:50&amp;lt;/code&amp;gt; with the standard MAC-48 → EUI-64&lt;br /&gt;
  &amp;lt;code&amp;gt;FF:FE&amp;lt;/code&amp;gt; expansion. The Itron OUI &amp;lt;code&amp;gt;00:07:81&amp;lt;/code&amp;gt; is also seen&lt;br /&gt;
  post-acquisition.&lt;br /&gt;
* Endpoint meters: serial form &amp;lt;code&amp;gt;00:13:50:05:00:xx:xx:xx&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
An access point is &#039;&#039;&#039;not heard directly&#039;&#039;&#039; from an endpoint&#039;s vantage — it sits&lt;br /&gt;
on the far side of the tree on channels a fixed receiver near one meter does not&lt;br /&gt;
follow. It is identified instead by reference: a [[Silver Spring Networks Relay|relay]]&lt;br /&gt;
lists its uplink access point(s) in its beacon&#039;s neighbour records, each with a&lt;br /&gt;
link-quality metric. In one capture a relay was dual-homed to two access points&lt;br /&gt;
(a stable primary and a volatile secondary) for the whole observation window.&lt;/div&gt;</summary>
		<author><name>Blind</name></author>
	</entry>
	<entry>
		<id>https://wiki.recessim.com/w/index.php?title=Silver_Spring_Networks_Relay&amp;diff=3685</id>
		<title>Silver Spring Networks Relay</title>
		<link rel="alternate" type="text/html" href="https://wiki.recessim.com/w/index.php?title=Silver_Spring_Networks_Relay&amp;diff=3685"/>
		<updated>2026-08-31T20:52:40Z</updated>

		<summary type="html">&lt;p&gt;Blind: Add on-air behaviour — 120s beacon lattice, dual-homing, hop sequence&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;gallery mode=&amp;quot;packed&amp;quot; heights=&amp;quot;250&amp;quot;&amp;gt;&lt;br /&gt;
File:SilverSpringRelay Processor PanoTop.jpg|Top of processor board with metal shielding cans removed&lt;br /&gt;
File:SilverSpringRelay Processor PanoBottom.jpg|Bottom of processor board&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
== On-air behaviour ==&lt;br /&gt;
&lt;br /&gt;
(From passive capture of a fixed-AMI NIC 511 network — see&lt;br /&gt;
[[Silver Spring Networks Protocol]] for the frame format.)&lt;br /&gt;
&lt;br /&gt;
A relay is the one node type that beacons on a strict schedule: a &#039;&#039;&#039;120.000 s&lt;br /&gt;
lattice&#039;&#039;&#039;, phase holding to σ ≈ 0.25 s over 450+ cycles. Endpoint meters, by&lt;br /&gt;
contrast, are event-driven (their timing jitters by seconds). This makes the&lt;br /&gt;
relay easy to pick out.&lt;br /&gt;
&lt;br /&gt;
The beacon (frame length 111 in this variant) carries the relay&#039;s own serial&lt;br /&gt;
plus a neighbour table — its uplink [[Silver Spring Networks Access Point|access&lt;br /&gt;
points]] (EUI-64 form) and downstream endpoints, each with a link-quality byte.&lt;br /&gt;
Observed behaviour:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Dual-homed&#039;&#039;&#039;: a fixed primary + secondary access point, stable across the&lt;br /&gt;
  whole capture (one link metric steady, the other volatile).&lt;br /&gt;
* &#039;&#039;&#039;Channel follows the hop sequence&#039;&#039;&#039;: channel = &amp;lt;code&amp;gt;slot mod 83&amp;lt;/code&amp;gt; on&lt;br /&gt;
  the 120 s lattice, so the relay&#039;s next beacon channel is predictable from its&lt;br /&gt;
  slot index.&lt;br /&gt;
* &#039;&#039;&#039;~60 endpoints&#039;&#039;&#039; were seen routing through a single relay; the relay&lt;br /&gt;
  forwards their traffic toward the access points.&lt;br /&gt;
&lt;br /&gt;
The relay never sources a unicast we can read — only beacons and inbound&lt;br /&gt;
acknowledgements — so its own consumption upload goes out on the access point&#039;s&lt;br /&gt;
schedule, not its own.&lt;/div&gt;</summary>
		<author><name>Blind</name></author>
	</entry>
	<entry>
		<id>https://wiki.recessim.com/w/index.php?title=Silver_Spring_Networks_Protocol&amp;diff=3684</id>
		<title>Silver Spring Networks Protocol</title>
		<link rel="alternate" type="text/html" href="https://wiki.recessim.com/w/index.php?title=Silver_Spring_Networks_Protocol&amp;diff=3684"/>
		<updated>2026-08-31T20:48:22Z</updated>

		<summary type="html">&lt;p&gt;Blind: Add fixed-AMI NIC 511 variant: framing, degree-9 whitening (the &amp;quot;Mask&amp;quot; transform), CRC-32, 87-channel plan, hop sequence; distinct from the drive-by/water variant&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Data capture from a Silver Spring Networks smart meter that was initially powered on. The text is very wide so open the file in a text editor, it won&#039;t look right in the browser most likely.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Initial capture of data - small file&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[https://wiki.recessim.com/w/images/2/24/Silver_Spring_Networks_Smart_Meter_00135005008C900A.txt Silver_Spring_Networks_Smart_Meter_00135005008C900A.txt]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;170 samples sorted by &amp;quot;Mask&amp;quot; column, notice the data appears similar for each mask, need to figure out how it&#039;s being transformed.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[https://wiki.recessim.com/w/images/4/40/Silver_Spring_Networks_Extended_Parsed_02-22-2022_00135005008C900A.txt Silver_Spring_Networks_Extended_Parsed_02-22-2022_00135005008C900A.txt]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Capturing Itron/SSN traffic===&lt;br /&gt;
In 2012 a permissive change was filed at the FCC to certify and document an RF mode not initially supported.  Specifically, it uses 2-FSK over 64 channels from 902.4MHz to 927.6MHz (inclusive) and a data rate of 150kbps.  This appears to be the predominantly used mode today among such devices.  A summary of all modes of FCC ID SK9AMI7 are shown below.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Modulation&lt;br /&gt;
!Frequency range (MHz)&lt;br /&gt;
!Number of channels&lt;br /&gt;
!Channel separation (kHz)&lt;br /&gt;
!Data rates supported (kbps)&lt;br /&gt;
|-&lt;br /&gt;
|FSK&lt;br /&gt;
|902.25 - 927.75&lt;br /&gt;
|52&lt;br /&gt;
|500&lt;br /&gt;
|19.2&lt;br /&gt;
|-&lt;br /&gt;
|FSK&lt;br /&gt;
|902.25 - 927.75&lt;br /&gt;
|52&lt;br /&gt;
|500&lt;br /&gt;
|152.3&lt;br /&gt;
|-&lt;br /&gt;
|OOK&lt;br /&gt;
|909.6 - 921.8&lt;br /&gt;
|50&lt;br /&gt;
|200&lt;br /&gt;
|16.4&lt;br /&gt;
|-&lt;br /&gt;
|FSK&lt;br /&gt;
|902.4 - 927.6&lt;br /&gt;
|64&lt;br /&gt;
|400&lt;br /&gt;
|150.0&lt;br /&gt;
|}&lt;br /&gt;
The following capture file was created using this gnuradio file.  It has the 64 channels explicitly listed within the Center Freq Estimation block.  It uses a syncword of 0xAAAAAAAA (which is probably too short) and makes the assumption that data is transmitted most significant bit first, but this is an unverified guess.  No checking is done of the packets, so there are very likely to be many packets with errors.  In looking through this capture file, the majority of packets start with &amp;lt;syntaxhighlight&amp;gt;&lt;br /&gt;
aa aa aa aa aa aa aa aa de 9d 27 27 16 66 f0 6c&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;For that reason, it&#039;s likely that those packets are probably mostly correct, while the others should be viewed with suspicion.&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
[[File:Meter data capture.grc.txt|left|thumb|capture grc file (rename from txt to just .grc to run)]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Raw itron packet dump.zip|left|thumb|Raw dump of an Itron/Silver Springs Networks network.]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
== Fixed-AMI variant (Aclara I-210+c / NIC 511) ==&lt;br /&gt;
&lt;br /&gt;
Transport-layer documentation for the Silver Spring mesh format used by an Aclara&lt;br /&gt;
I-210+c meter with a NIC 511 module on a fixed AMI network (passive RTL-SDR&lt;br /&gt;
capture). The application payload is AES-CCM* encrypted; everything below is the&lt;br /&gt;
transport layer.&lt;br /&gt;
&lt;br /&gt;
This is a distinct on-air format from the other Silver Spring work — there are at&lt;br /&gt;
least three, with different sync words and scramblers:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Source !! Sync / SFD !! Scrambler !! CRC&lt;br /&gt;
|-&lt;br /&gt;
| This page&#039;s capture (&amp;lt;code&amp;gt;…008C900A&amp;lt;/code&amp;gt;) || post-preamble &amp;lt;code&amp;gt;de 9d 27 27 16 66 f0 6c&amp;lt;/code&amp;gt; || — || —&lt;br /&gt;
|-&lt;br /&gt;
| rtl_433 &amp;lt;code&amp;gt;silver_spring_mesh&amp;lt;/code&amp;gt; (drive-by/water) || &amp;lt;code&amp;gt;SFD 0xF3A0&amp;lt;/code&amp;gt;, 3-byte PHR || 8-bit &amp;lt;code&amp;gt;x⁸+x⁴+x³+x²+1&amp;lt;/code&amp;gt; || CRC-32/MPEG-2, 4-byte FCS&lt;br /&gt;
|-&lt;br /&gt;
| This variant (fixed-AMI NIC 511) || &amp;lt;code&amp;gt;0C 5F &amp;amp;lt;ch&amp;amp;gt; FF&amp;lt;/code&amp;gt;, 2-byte inverted PHR || degree-9 &amp;lt;code&amp;gt;x⁹+x⁸+x⁵+x²+1&amp;lt;/code&amp;gt; || CRC-32, 1-byte trailer&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The 8-bit and degree-9 scramblers are provably different: the 8-bit scrambler&lt;br /&gt;
descrambles no NIC 511 frame at any of its 255 seeds, and Berlekamp–Massey gives&lt;br /&gt;
the NIC 511 keystream linear complexity 9 (an 8-bit LFSR is ≤ 8).&lt;br /&gt;
&lt;br /&gt;
=== Summary ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Layer !! Result&lt;br /&gt;
|-&lt;br /&gt;
| Modulation || 2-GFSK, h≈0.5, 100/150/200 kBd (per-frame)&lt;br /&gt;
|-&lt;br /&gt;
| PHY header || &amp;lt;code&amp;gt;0C 5F &amp;amp;lt;channel&amp;amp;gt; FF&amp;lt;/code&amp;gt;; channel = 255 − byte 2&lt;br /&gt;
|-&lt;br /&gt;
| Channel plan || 87 channels, &amp;lt;code&amp;gt;f(N) = 902.2990 MHz + 299.991 kHz·N&amp;lt;/code&amp;gt;, 300 kHz spacing&lt;br /&gt;
|-&lt;br /&gt;
| Whitening || degree-9 LFSR &amp;lt;code&amp;gt;x⁹+x⁸+x⁵+x²+1&amp;lt;/code&amp;gt;, recovered by Berlekamp–Massey&lt;br /&gt;
|-&lt;br /&gt;
| Integrity || CRC-32 (poly 0x04C11DB7, MSB-first, init 0); trailer = MSB(crc) ⊕ K[len]&lt;br /&gt;
|-&lt;br /&gt;
| Framing || length-keyed header grammar; every byte of 12 length classes accounted for&lt;br /&gt;
|-&lt;br /&gt;
| Flags byte || &amp;lt;code&amp;gt;base(channel) ⊕ frame-type&amp;lt;/code&amp;gt; (0=broadcast, 2=unicast, 3=beacon)&lt;br /&gt;
|-&lt;br /&gt;
| Beacon timing || 120.000 s lattice, phase σ = 0.25 s over 450+ cycles&lt;br /&gt;
|-&lt;br /&gt;
| Hop sequence || channel = f(slot mod 83), 153/153 forward predictions&lt;br /&gt;
|-&lt;br /&gt;
| Topology || dual-homed relay → two EUI-64 access points → head-end (see [[Silver Spring Networks Relay]], [[Silver Spring Networks Access Point]])&lt;br /&gt;
|-&lt;br /&gt;
| Payload || AES-CCM* encrypted, not recovered&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PHY and channel ===&lt;br /&gt;
&lt;br /&gt;
2-GFSK, modulation index ≈ 0.5, 100/150/200 kBd. The 4-byte block after the&lt;br /&gt;
preamble is not a sync word: bytes 0/1/3 are fixed (&amp;lt;code&amp;gt;0C 5F .. FF&amp;lt;/code&amp;gt;) and&lt;br /&gt;
byte 2 is the channel, &amp;lt;code&amp;gt;N = 255 − X&amp;lt;/code&amp;gt;. Carrier vs. N:&lt;br /&gt;
&lt;br /&gt;
 f(N) = 902.2990 MHz + 299.991 kHz · N        N = 0..86   (87 channels, 300 kHz)&lt;br /&gt;
&lt;br /&gt;
Residuals &amp;lt; 2 kHz per channel. This differs from the FCC filing&#039;s 64 channels /&lt;br /&gt;
400 kHz (that filing is a different, earlier module).&lt;br /&gt;
&lt;br /&gt;
=== Whitening ===&lt;br /&gt;
&lt;br /&gt;
The PSDU is whitened by a degree-9 LFSR:&lt;br /&gt;
&lt;br /&gt;
 b[n] = b[n-1] ^ b[n-2] ^ b[n-5] ^ b[n-8] ^ b[n-9]        period 255&lt;br /&gt;
&lt;br /&gt;
Recovered by Berlekamp–Massey over the all-zero payload padding of long frames&lt;br /&gt;
(that region is raw keystream on the air; linear complexity comes out to 9).&lt;br /&gt;
Plaintext bytes 0–4 are the constant serial prefix &amp;lt;code&amp;gt;00 13 50 05 00&amp;lt;/code&amp;gt;,&lt;br /&gt;
so the mask for any frame is &amp;lt;code&amp;gt;cipher[0:5] ^ prefix&amp;lt;/code&amp;gt; (40 bits) extended&lt;br /&gt;
by the recurrence — no per-frame seed needed.&lt;br /&gt;
&lt;br /&gt;
=== Integrity ===&lt;br /&gt;
&lt;br /&gt;
The trailing byte is the top byte of a CRC-32 (poly &amp;lt;code&amp;gt;0x04C11DB7&amp;lt;/code&amp;gt;,&lt;br /&gt;
MSB-first, init 0) over the de-whitened frame, XORed with a per-length constant:&lt;br /&gt;
&lt;br /&gt;
 K = {9:0x78, 12:0x0E, 14:0x5B, 16:0x7A, 21:0xEB, 22:0xE8, 29:0x05,&lt;br /&gt;
      55:0xA6, 111:0x7D, 112:0x2D, 134:0x6E, 213:0x60}&lt;br /&gt;
&lt;br /&gt;
Validates on ~98% of frames (2816/2880 across the corpus); failures carry bit&lt;br /&gt;
errors visible as nonzero bytes in known-zero padding.&lt;br /&gt;
&lt;br /&gt;
=== Framing ===&lt;br /&gt;
&lt;br /&gt;
 frame := SRC(8) [DST(8)] {headers} payload TRAILER(1)&lt;br /&gt;
&lt;br /&gt;
 ln= 12   SRC | 04 81 xx | TRAILER&lt;br /&gt;
 ln= 14   SRC | 01 03 aa bb cc | TRAILER&lt;br /&gt;
 ln= 22   SRC | DST | 01 03 aa bb cc | TRAILER&lt;br /&gt;
 ln= 29   SRC | DST | 01 03 .. | PAYLOAD(7) | TRAILER&lt;br /&gt;
 ln= 55   SRC | 01 03 .. | 04 81 xx | PAYLOAD(38) | TRAILER&lt;br /&gt;
 ln=111   SRC | 01 80 | 00 82 .. | PAYLOAD(96) | TRAILER   (beacon)&lt;br /&gt;
 ln=213   SRC | 00 82 .. | 01 03 .. | PAYLOAD(195) | TRAILER  (encrypted)&lt;br /&gt;
&lt;br /&gt;
Addresses: 8 bytes, OUI &amp;lt;code&amp;gt;00:13:50&amp;lt;/code&amp;gt;. Endpoints serial-form&lt;br /&gt;
(&amp;lt;code&amp;gt;00:13:50:05:00:xx…&amp;lt;/code&amp;gt;); access points EUI-64&lt;br /&gt;
(&amp;lt;code&amp;gt;00:13:50:FF:FE:60:xx…&amp;lt;/code&amp;gt;, see [[Silver Spring Networks Access Point]]). PHR byte 2 = &amp;lt;code&amp;gt;base(channel) ⊕&lt;br /&gt;
frame-type&amp;lt;/code&amp;gt;, type ∈ {0 broadcast, 2 unicast, 3 beacon}.&lt;br /&gt;
&lt;br /&gt;
=== Beacon timing and hopping ===&lt;br /&gt;
&lt;br /&gt;
The relay node beacons on a 120.000 s lattice (phase σ 0.25 s over 450+ cycles).&lt;br /&gt;
By slot index, channel = &amp;lt;code&amp;gt;slot mod 83&amp;lt;/code&amp;gt; (verified by 153/153 strictly&lt;br /&gt;
causal forward predictions, permutation null 0/3000). Cycle = 83 × 120 s ≈ 2h46m.&lt;br /&gt;
&lt;br /&gt;
=== Payload ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;ln=213&amp;lt;/code&amp;gt; payloads are 195 bytes of uniform, zero-free, incompressible&lt;br /&gt;
data (full linear complexity under Berlekamp–Massey — not a linear scrambler,&lt;br /&gt;
unlike the whitened classes). This is AES-CCM* encryption (Itron/Certicom Suite&lt;br /&gt;
B). The key is provisioned by the head-end key manager and held in the meter&#039;s&lt;br /&gt;
secure element, not derivable from the air.&lt;br /&gt;
&lt;br /&gt;
=== References ===&lt;br /&gt;
&lt;br /&gt;
* Reproducible code and full write-up: [https://github.com/bash-tilde/silverspring-ami-rf github.com/bash-tilde/silverspring-ami-rf]&lt;br /&gt;
* rtl_433 &amp;lt;code&amp;gt;silver_spring_mesh.c&amp;lt;/code&amp;gt; (Benjamin Larsson) — the drive-by/water variant&lt;/div&gt;</summary>
		<author><name>Blind</name></author>
	</entry>
</feed>