A great many radio users, and a fair number of the supervisors who set policy for them, believe that a PL tone, a DPL code or a move to a digital system keeps outsiders from hearing their traffic. None of those three things does that, and none of them was ever designed to. CTCSS and DCS are squelch controls that decide what your own receiver unmutes for, digital modulation is a way of representing voice as data, and the only thing on a land mobile radio that actually denies your audio to a listener is encryption. This is part one of two.

CTCSS, and the trade name that caused the trouble

Continuous Tone Coded Squelch System is a scheme for sending a low frequency tone alongside the voice audio for the whole duration of a transmission, so that a receiver programmed to look for that particular tone can decide whether to open its audio path. The tones sit below the range a communications receiver passes to the speaker, which is where the description sub-audible comes from, and the transmitting radio sends the tone at a deviation well below that of the voice so it does not dominate the channel. The earliest EIA standard for the system, RS-220, dates to 1959 and defined 37 tones running from 67.0 Hz to 254.1 Hz, and manufacturers later added tones between and above the standard set, which is why a modern radio or scanner typically offers around fifty selectable CTCSS tones rather than 37.

Motorola’s designators for those tones are two-character reed codes, so 67.0 Hz appears in old programming documentation as XZ and 151.4 Hz as 5Z, and the reed reference is literal because the early decoders used a mechanical resonant reed tuned to one tone. Motorola’s registered trade name for the whole system is Private Line, abbreviated PL. General Electric marketed the same function as Channel Guard, or CG, and other manufacturers of the era used their own names. Repeater-Builder’s technical history of tone squelch notes that Private Line has drifted into use as a generic term for CTCSS despite Motorola’s efforts, in the way other trademarks have, and in practice you will hear PL used by people who have never owned a Motorola radio.

That name is the source of the misconception this article exists to correct, so I will state my point plainly. PL keeps you from hearing other users on a shared frequency. It confers nothing at all that prevents anyone else from hearing you. The tone is transmitted in the clear as part of your signal, and it carries no instruction to any radio anywhere that could make your voice unavailable to a receiver that simply leaves its own squelch wide open. The technology performs exactly one function, which is to give a receiver a reason to stay quiet during traffic that is not addressed to it, and the trade name promises something the function was never built to deliver.

There is a genuine operational benefit here and it is worth naming, because dismissing tone squelch as useless is the opposite error. On a shared VHF or UHF channel with three departments and two tow companies on it, tone squelch is what keeps a crew’s portable from unmuting for every unrelated transmission, and it is what lets a repeater ignore a distant co-channel signal instead of retransmitting it. Those are noise problems, and CTCSS solves noise problems well enough that it has stayed in continuous use for more than sixty years. The site’s companion piece on CTCSS, DPL and squelch covers the other end of that, which is why you cannot hear the department across the county line when the tones do not match.

DCS: the same job with a code in place of a tone

Digital Coded Squelch, also written CDCSS in some standards documents, does the same squelch job with a slow digital bitstream instead of a single tone. The transmitting radio sends a 23-bit codeword continuously throughout the transmission at 134.4 bits per second, low enough in rate that its energy stays below the passband of the voice audio in the same way a CTCSS tone does. The codeword is a Golay (23,12) block code, meaning twelve data bits followed by eleven check bits, and the error correction that structure provides lets a decoder recover the code in the presence of a few bit errors rather than dropping squelch every time the signal fades.

Three of the twelve data bits are fixed, which leaves nine bits and 512 arithmetic possibilities, and those are conventionally written as three-digit octal numbers, so a codeplug shows 023, 174, 431 and so on. Not all 512 are usable in practice, because some codewords alias into each other or into the fixed pattern, and manufacturers publish a working set that commonly runs somewhere between roughly 83 and 104 codes depending on the radio and on whether the inverted forms are counted separately. If the exact count matters to a channel plan you are building, take it from the manufacturer’s programming documentation for the specific model rather than from any general article, including this one.

Motorola’s trade name for DCS is Digital Private Line, abbreviated DPL, and the same problem attaches to the same word. For the purposes of everything that follows, you can treat DCS as CTCSS with a code in place of a tone, since the mechanism, the placement in the audio path and the complete absence of any privacy function are identical between them. The only meaningful practical differences are the larger number of available codes, which helps in congested areas where the tone set has run out of useful separation, and the behavior at the end of a transmission, where a DCS radio typically sends a short turn-off burst so the receiving radio closes its squelch cleanly instead of producing a noise tail.

The rule of thumb worth memorizing

Any receiver on your frequency that is set to carrier squelch hears every transmission on that frequency, whatever tone or code you are sending. Carrier squelch is the default state of every scanner sold, and it is a selectable mode on essentially every commercial and amateur radio. Whether your traffic can be heard is decided entirely by the listener’s equipment and by whether the audio was encrypted before it left your antenna, and not at all by the tone you programmed.

Squelch is a receiver decision, not a transmission property

Squelch is the circuit or the software routine that keeps a receiver’s audio muted until some condition is met, and the whole family of squelch schemes differs only in what that condition is. Carrier squelch, sometimes shown on a radio as CSQ or noise squelch, unmutes when there is enough signal on the frequency to quiet the receiver’s own noise. Tone squelch adds a second condition, which is that a decoder must find the programmed CTCSS tone in the recovered audio, and DCS adds the same kind of condition with a codeword in place of a tone. In every case the decision is being made inside the receiving radio, after the signal has already arrived, and nothing about that decision reaches backward to affect the transmission.

This is why the doorbell comparison holds better than the lock comparison. A lock on a door denies entry to everyone without the key, whereas tone squelch works more like a doorbell your own radio has chosen to answer, because the sound is available to the whole street and only your radio is listening for that particular chime. The tone itself is not even a secret, since it travels in the clear as part of your signal and is straightforward for a listener to identify with ordinary equipment, and county and regional channel plans routinely publish tones because publishing them is how mutual aid works.

The same logic applies at the repeater, and this is where supervisors most often get the idea that a tone controls access to a system. A repeater programmed to require a specific CTCSS tone on its input will not retransmit a signal that arrives without that tone, which does keep unrelated traffic and some kinds of interference off the output. What it does not do is prevent that unrelated signal from occupying the repeater’s receive frequency and desensing it, and it certainly does not prevent anybody from listening to the repeater’s output, which is a transmitter deliberately radiating from the highest point the agency could get to for the express purpose of being heard over a wide area.

There is one more variation on the theme, which is the practice of programming a receive tone on a channel and then handing users a monitor button or a carrier squelch position on the same channel. Fire and EMS agencies do this on purpose so that a crew can check whether a shared channel is busy before keying. It is a useful habit and I recommend it, but notice what it demonstrates, which is that the tone was only ever a filter on the user’s own side, removable at the user’s own discretion with one button, and available to be removed just as easily by anyone else who is listening.

Digital is an encoding: P25, DMR and NXDN

Digital voice radio takes the analog waveform from the microphone, runs it through a vocoder that describes the sound as a stream of bits at a rate low enough to fit a narrow channel, and modulates those bits onto the carrier. The vocoder is a compression scheme rather than a protection scheme, and the reason a P25 radio from one manufacturer can decode a P25 transmission from another is that the vocoder and the frame structure are both defined in published standards that anybody can buy and implement. Faithful reproduction of the audio in any conforming receiver is the entire purpose of writing the standard down, and the standard cannot deliver interoperability to your mutual aid partners while withholding it from a listener with a conforming receiver.

The access method is worth getting right because it is often confused with security. P25 Phase 1 is FDMA, one voice path in a 12.5 kHz channel, with subscriber units transmitting C4FM and site equipment transmitting C4FM or the CQPSK variant used in linear simulcast. P25 Phase 2, approved in 2010, is two-slot TDMA inside the same 12.5 kHz channel, which is where the 6.25 kHz equivalent efficiency claim comes from, and it applies to trunked voice channels while the control channel continues to use Phase 1 modulation. DMR, as defined in the ETSI standard, is also two-slot TDMA in a 12.5 kHz channel. NXDN is FDMA, offered in 6.25 kHz and 12.5 kHz channel bandwidths.

Read that list again as an engineer would, because every item on it answers the question of how the channel is divided up among users and how many conversations fit in a given slice of spectrum, and not one of them answers the question of who is permitted to listen. TDMA divides a channel in time so that two calls share it, whereas FDMA gives each call its own channel, and both arrangements are published in enough detail that a receiver can find the slot or the channel, recover the bits, and hand them to the vocoder. The site’s plain English comparison of DMR, NXDN, P25 and analog covers the selection trade-offs for volunteer departments, and none of those trade-offs is a privacy trade-off.

The practical result is that a digital system with no encryption is monitorable with commercially available scanners that anyone can buy at retail. I am stating that without hedging because hedging it has consequences. Several consumer receiver product lines have handled P25 Phase 1 for many years and later added Phase 2, and there are hobbyist software receiver projects that do the same work, all of it built on the published standards rather than on anything obtained improperly. If your policy assumption is that digital modulation bought you confidentiality, the correct move is to check what your talkgroups are actually configured to do before you rely on that assumption for another shift.

The layer that does the work, and where it sits

Encryption is a separate operation applied to the digitized voice after the vocoder has produced its bitstream and before that bitstream is modulated onto the carrier. Picture the order of events in the radio: the microphone audio is sampled and encoded, and then, only if that channel or talkgroup is configured for it and a valid key is loaded and selected, the resulting bits are encrypted with an algorithm and a key before transmission. Without that second step, the bits go out exactly as the standard describes them, and the traffic is in the clear in every sense that matters operationally even though nothing about it sounds like speech to an analog receiver.

For American public safety, the relevant algorithm is AES, normally with a 256-bit key. The P25 block encryption protocol document in the TIA-102 series defines AES for the standard, and the DHS and NPSTC guidance material on encryption in land mobile radio systems states that the P25 standard “relies on AES 256-bit to ensure the best level of protection”, with 128-bit and 192-bit keys permitted but the 256-bit key strongly recommended. Federal practice has consolidated on AES-256, which is why an interoperability discussion with a federal partner on a secure channel is usually an AES-256 discussion. Cite the standards documents rather than a vendor data sheet when you are writing this into a policy, and note that the algorithm families themselves are covered in the site’s article on DES, AES, ADP and scrambling, so I will not repeat that ground here.

What the layering means for a working agency is that encryption is a configuration state that can be present, absent, partial, or silently broken, and that it has to be verified rather than assumed. A fleet can have AES-256 capable radios with no keys loaded. A talkgroup can be set to clear while the radios on it are perfectly capable of encrypting. A single radio issued from the cache with an expired keyset can force a whole conversation into the clear if the system is configured to allow that, which is the case the site’s article on finding out whether your encryption is actually on was written to address.

This article is the layer beneath that one. It covers the situation where there was never any encryption in the picture to begin with, and where the belief in confidentiality rests on a tone, a code, or the word digital in a system description. That belief is more common than the misconfiguration case, in my experience, and it is more dangerous because there is no alarm state to find and no log entry to check, since the system is doing exactly what it was configured to do.

Where the awareness level ends

This piece is written to help a radio user recognize a situation and know who to call, and it deliberately stops short of being a technical manual. I do not publish monitoring procedure for any agency’s traffic, direction finding instructions, or receiver and antenna configurations for locating a transmitter. If your role gives you a bona fide operational need beyond awareness level, reach me through the contact form on this site. Credentials are required, and depending on the circumstances I will refer some inquiries to the appropriate government agency rather than answering them myself.

Why the belief survives the cutover to digital

The strongest reason this misconception persists is that on the day an agency cuts over from analog to digital, it genuinely looks as though privacy arrived. The analog scanners in living rooms and pickup trucks across the county stop producing intelligible audio, the online feeds that had been rebroadcasting dispatch go quiet or start carrying nothing but a warbling noise, and the phone calls from people who follow every call in town simply stop. From inside the agency that reads as a security improvement, and it gets reported up the chain as one, and it becomes the shared understanding of what going digital accomplished.

What actually happened is narrower than that. The listeners’ equipment fell behind for a while, because a receiver built to demodulate analog FM cannot reconstruct the frames of a digital transmission any more than a cassette deck can play a data file. The quiet period lasted as long as it took for digital-capable consumer receivers to reach the price point and the availability that analog scanners had occupied, and then for the same thing to happen again when Phase 2 TDMA systems came into service and the existing digital scanners initially could not follow them. Both gaps closed. I will not put specific model numbers or dates on that because the market has moved repeatedly, and the current state of consumer receiver capability is easy enough to establish by looking at what is being sold and what the hobbyist feed sites are carrying from systems like yours.

The institutional damage is done during the quiet period, because that is when policy language and radio habits form around a false premise. A supervisor who watched the neighborhood scanners go silent in the year of the cutover has direct personal evidence, as he understands it, that the digital system is confidential, and that understanding gets passed to new members as fact and written into the informal rules about what gets said on which channel. When the scanners come back, nothing announces it, so the traffic that was being handled a certain way because it was believed to be private simply continues to be handled that way while the audience returns.

I would add one thing about the audience, since it comes up whenever this is discussed at a committee table. Monitoring unencrypted public safety radio is a long-standing practice with a large and mostly benign following of hobbyists, news organizations, volunteer responders and residents who want to know why the engine went past their house. The site’s article on scanners, live feeds and transparency covers that landscape. Treating listeners as the problem is not a strategy, because the traffic is either protected by encryption or it is available, and the composition of the audience does not change that arithmetic.

What may be said on a talkgroup with no encryption

Start from a plain rule for anything carrying no encryption, which is that it should be treated as a public statement made by your agency, on the record, into a medium with an unknown number of listeners and a very good chance of being recorded by somebody outside the organization. That standard is not as restrictive as it sounds for most routine work, since dispatch traffic, apparatus assignments, status changes and general fireground and EMS coordination have been conducted in the clear for the entire history of the service and can continue to be. The rule matters for the categories where broadcast in the clear does specific harm.

Tactical and investigative traffic is the first of those categories, because a surveillance position read out on the air tells anyone monitoring exactly where the officers are sitting, and the same holds for a staging point, an entry time, the address on an active warrant, or the description of a vehicle officers are following, all of which describe what officers are about to do before they have done it and describe it to people who may have a direct interest in the outcome. A useful test that I have heard used in training, and I do not know who originated it, is that anything you would not say on the six o’clock news does not belong on a clear talkgroup. Patient information is the second category, and the site’s article on protecting personal information on the air covers the detail of names, dates of birth, identifiers and medical specifics that should not be in the clear regardless of what the radio can do.

The habit that needs the most direct attention is the instruction to switch to another channel for something sensitive. When the receiving channel is also unencrypted, that instruction changes nothing about who can hear the conversation, and it usually makes things worse in two ways. It signals to anyone monitoring that something worth hearing is about to be said, which is an invitation rather than a precaution, and it moves the traffic to a channel that may not be recorded by the dispatch logging system, so the agency loses its own record of the exchange while gaining no confidentiality at all. If the traffic genuinely needs to be off the main channel, it needs to go to an encrypted talkgroup, to a telephone, or to a face to face conversation.

The last item is language, and it is the cheapest fix available. The phrase “this is a private channel” should be struck from the way supervisors, training officers and dispatchers describe frequencies, and so should describing a tone or code as security. Call a channel by what it is, which might be a tactical channel, a car to car channel, an administrative channel or an encrypted talkgroup, and if it is encrypted say so and say with what. Members calibrate their own behavior on the words their supervisors use, and a member who has been told a channel is private will eventually say something on it that assumed privacy.

The sentence to stop using

“Go to the private channel” tells a member that the conversation is protected. If that channel carries no encryption, the sentence is false, the member acts on it, and the agency finds out how false it was when a recording of the exchange appears somewhere inconvenient. Name channels by function and state the encryption status explicitly in the channel plan and in the ICS-205 you build for incidents, so nobody has to infer it from a label.

Tones, coordination, and what your license actually gives you

The regulatory side reinforces the same point and leads directly into the companion piece. Under the FCC’s Part 90 rules the general position is that land mobile frequencies are assigned on a shared basis and are not given over to any one licensee for exclusive use, with exclusivity available only in the specific circumstances the rules provide for, which vary by band and by service. A tone or a code has no role in that framework. Choosing a CTCSS tone does not give an agency any greater claim to a frequency, and it does not create any obligation on another licensee on the same channel to stay off the air. If exclusivity or the loading criteria for your band matter to a decision you are making, verify the current requirements with your certified frequency coordinator rather than relying on a summary.

Coordinators do consider tones and codes as a practical matter, because separating the squelch coding on nearby co-channel assignments reduces the nuisance each system causes the other, and a regional channel plan will often specify tones for exactly that reason. That is interference management between cooperating licensees. It is worth knowing what your own authorization actually contains, which is built around the frequency, the emission designator, the power, the antenna structure and the area of operation, and asking your license administrator to confirm what appears on the record for each of your call signs rather than assuming a tone assignment is part of it.

The consequence for a shared frequency is straightforward. A shared frequency stays shared regardless of what tone is programmed on it, so another authorized user transmitting on your channel with a different tone is not necessarily doing anything wrong, and your radios staying quiet through their traffic is not evidence that the channel is yours. That distinction between an authorized co-channel user, an unauthorized user, and actual malicious interference is the one that decides who you should call, and it is where part one stops.

Part two of this pair is “When someone else is on your frequency”, and it takes up interference and its sources, what deliberate jamming looks like from the victim’s side, how FCC enforcement is initiated and what it can and cannot do, and the licensing choices available to an agency that keeps having the problem. Read this one first if the question in front of you is what your existing tones and your digital system are actually protecting, and read that one when the question is what to do about the signal that should not be there.

What to do at your agency

  • Have your system administrator or radio shop produce a one page list of every talkgroup and channel in the current codeplug with its encryption status marked as encrypted or clear, and file it with the channel plan so that nobody has to guess.
  • Take that list to the next officers’ meeting or communications committee meeting that is already scheduled, and get agreement on which categories of traffic are permitted on the clear talkgroups and which require an encrypted one.
  • Ask your training officer to correct the language used in radio training and in the channel plan, removing the word private from any description of a tone, a code or an unencrypted channel, and replacing it with the channel’s function.
  • Have a supervisor or QA reviewer pull one week of dispatch recordings and listen specifically for names, dates of birth, addresses of subjects, tactical positions and the instruction to switch channels for something sensitive, then brief what was found without naming individuals.
  • Confirm with whoever builds your ICS-205 for incidents that the form shows encryption status for each assigned channel, and add that column or notation if it is missing before the next planned event.
  • Ask your license administrator to pull each of your FCC call signs and confirm the frequencies, emission designators and areas of operation on record, so that any conversation about interference in part two starts from your actual authorization.
  • If your agency believes it needs encryption on traffic that is currently in the clear, have the system administrator establish what the existing subscriber fleet supports and what key management would be required, and put a cost figure in front of the chief this budget cycle rather than next.

Takeaways

  • CTCSS sends a continuous low frequency tone alongside the voice, with the original EIA RS-220 standard of 1959 defining 37 tones from 67.0 Hz to 254.1 Hz and manufacturers later extending the set to around fifty selectable tones.
  • Motorola’s Private Line and Digital Private Line, PL and DPL, are trade names for CTCSS and DCS, and the word private in both names describes a benefit the technology does not provide.
  • DCS sends a 23-bit Golay coded word continuously at 134.4 bits per second and can be understood as CTCSS with a code in place of a tone, offering more available codes and no more confidentiality.
  • Both schemes are squelch controls that decide what your own receiver unmutes for, so any receiver set to carrier squelch, which is the default on every scanner, hears your traffic regardless of the tone or code you send.
  • P25 Phase 1 is FDMA, P25 Phase 2 is two-slot TDMA in a 12.5 kHz channel, and DMR is also two-slot TDMA, and all of those describe how the channel is shared rather than who is allowed to listen.
  • A digital system with no encryption is monitorable with commercially available scanners, because faithful reproduction of the audio in any conforming receiver is the purpose of publishing the standard.
  • Encryption is a separate layer applied to the digitized voice before transmission, and for public safety that means AES, normally AES-256, defined for P25 in the block encryption protocol document of the TIA-102 series and recommended at 256 bits in DHS and NPSTC guidance.
  • The belief that digital brought privacy took hold during the period after each cutover when listeners’ equipment had fallen behind, and it outlasted the closing of that gap because nothing announced that the scanners had returned.
  • A shared frequency stays shared whatever tone is programmed on it, and Part 90 frequencies are generally assigned on a shared basis, so verify any question of exclusivity with your certified frequency coordinator.
Questions or a different view?

Reach me through the contact page. I read every message.