{"id":49075220,"url":"https://github.com/mangobanaani/cirradio","last_synced_at":"2026-04-20T09:36:19.433Z","repository":{"id":344914932,"uuid":"1183469434","full_name":"mangobanaani/cirradio","owner":"mangobanaani","description":"Tactical UHF FHSS mesh radio: Zynq-7045 + AD9361, SystemVerilog RTL, C++20 comms stack, AES-256 PKCS#11 crypto","archived":false,"fork":false,"pushed_at":"2026-03-16T21:41:25.000Z","size":687,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"master","last_synced_at":"2026-03-17T08:22:15.200Z","etag":null,"topics":["ad9361","aes-256","cpp20","fhss","fpga","mesh-networking","sdr","systemverilog","tactical-radio","transec","uhf","zynq"],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mangobanaani.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-03-16T16:31:30.000Z","updated_at":"2026-03-16T21:41:51.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/mangobanaani/cirradio","commit_stats":null,"previous_names":["mangobanaani/cirradio"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/mangobanaani/cirradio","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mangobanaani%2Fcirradio","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mangobanaani%2Fcirradio/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mangobanaani%2Fcirradio/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mangobanaani%2Fcirradio/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mangobanaani","download_url":"https://codeload.github.com/mangobanaani/cirradio/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mangobanaani%2Fcirradio/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32041842,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-20T00:18:06.643Z","status":"online","status_checked_at":"2026-04-20T02:00:06.527Z","response_time":94,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ad9361","aes-256","cpp20","fhss","fpga","mesh-networking","sdr","systemverilog","tactical-radio","transec","uhf","zynq"],"created_at":"2026-04-20T09:36:15.053Z","updated_at":"2026-04-20T09:36:19.424Z","avatar_url":"https://github.com/mangobanaani.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# CIRRADIO\n\n\u003e Full-stack SDR — UHF FHSS ad-hoc mesh radio with AES-256 frequency hopping,\n\u003e PKCS#11 HSM crypto, TDMA MAC, QPSK+Viterbi modem, and TRANSEC (11,480-channel\n\u003e anti-jam FHSS, EMCON 0/1/2 emission control, adaptive per-link power control).\n\u003e SystemVerilog RTL (Zynq-7045 PL) through embedded Linux (PetaLinux/Yocto)\n\u003e to a C++20 comms stack, validated in simulation end-to-end.\n\n![License](https://img.shields.io/github/license/mangobanaani/cirradio)\n![C++](https://img.shields.io/badge/C%2B%2B-20-blue)\n![SystemVerilog](https://img.shields.io/badge/RTL-SystemVerilog-orange)\n![CMake](https://img.shields.io/badge/CMake-3.20%2B-064F8C)\n![Platform](https://img.shields.io/badge/platform-Linux%20%7C%20macOS-lightgrey)\n![Tests](https://img.shields.io/badge/tests-128%20passing-brightgreen)\n\n---\n\n## What It Is\n\nCIRRADIO is a tactical UHF frequency-hopping spread-spectrum (FHSS) mesh radio\ndesigned to NSA/MIL-STD-inspired requirements. It covers the 225–512 MHz\nmilitary UHF band with 11,480 hop channels at 25 kHz spacing, GPS-locked 100\nhops/sec AES-256-ECB sequencing, TDMA slot MAC, and a PKCS#11-abstracted HSM\ncrypto layer. The TRANSEC subsystem adds three-tier emission control (EMCON\n0/1/2), FEC block interleaving, burst-mode PA ramping, and adaptive per-link\npower control. The target hardware is a custom Zynq-7045 + AD9361 board; the\nfull software stack runs and passes tests today on any Linux or macOS machine\nwithout hardware.\n\n---\n\n## Architecture\n\n```\nRF Front-End  (LNA · PA · bandpass filter · T/R switch)\n      │ SMA\n  AD9361  Transceiver  (70 MHz – 6 GHz direct-conversion SDR)\n      │ LVDS 6-bit DDR  (ad9361_if.sv — IBUFDS/ISERDESE2 RX, OSERDESE2 TX)\n  ┌───────────────────────── Zynq-7045 PL ──────────────────────────┐\n  │  Channelizer     CIC + RRC FIR DDC/DUC  (4× oversample)        │\n  │  QPSK Modem      RRC MF · Gardner TED · Costas · Viterbi K=7   │\n  │  FHSS Engine     AES-256-ECB hop seq · blacklist · GPS 1PPS     │\n  │  TDMA MAC        Slot engine · TXNRX control · preamble         │\n  │  AXI Regs        4 KB AXI4-Lite slave  (PS ↔ PL control plane) │\n  └────────────────────────── AXI / DMA ───────────────────────────┘\n      │ AXI4-Lite + AXI DMA\n  ┌───────────────────────── Zynq-7045 PS ──────────────────────────┐\n  │  PetaLinux 2024.2 / Yocto BSP  (device tree · meta-cirradio)   │\n  │  Zynq7045HAL  →  libiio (AD9361) · UIO mmap (AXI regs) · gpsd  │\n  │  ┌─────────────────── C++20 Comms Stack ──────────────────────┐ │\n  │  │  SCA Core · FHSS scheduler · TDMA scheduler                │ │\n  │  │  Mesh Router (OLSR) · Peer Discovery · Net Join (ECDSA)    │ │\n  │  │  CryptoEngine (AES-256-GCM) · KeyManager (PKCS#11 HSM)    │ │\n  │  │  Voice Pipeline (Codec2 3200 bps) · CLI Management Shell   │ │\n  │  └────────────────────────────────────────────────────────────┘ │\n  └─────────────────────────────────────────────────────────────────┘\n```\n\n---\n\n## Stack\n\n| Layer               | Technology                          | Purpose                                    | Status          |\n|---------------------|-------------------------------------|--------------------------------------------|-----------------|\n| RF Front-End        | Custom KiCad board (Zynq-7045)      | LNA, PA, bandpass filter, T/R switch       | Board designed  |\n| RF Transceiver      | AD9361                              | 70 MHz–6 GHz direct-conversion SDR         | RTL complete    |\n| FPGA DSP            | SystemVerilog, Zynq-7045 PL         | Channelizer, modem, FHSS engine, TDMA MAC  | XSim verified   |\n| Embedded Linux      | PetaLinux 2024.2 / Yocto            | BSP, device tree, Yocto app layer          | Config complete |\n| Hardware HAL        | libiio, UIO mmap, gpsd              | IRadioHal + IGpsHal for Zynq ARM           | Code complete   |\n| Comms Stack         | C++20, CMake, Boost, OpenSSL        | Full SCA-inspired radio stack              | 128 tests pass  |\n| TRANSEC             | C++20 + SystemVerilog               | Anti-jam FHSS, EMCON, adaptive power       | Complete        |\n| Crypto / HSM        | OpenSSL, PKCS#11, SoftHSM2          | AES-256-GCM, ECDSA P-384, key management  | Tests pass      |\n| Mesh Networking     | Custom OLSR adaptation              | Ad-hoc peer discovery, net join            | Tests pass      |\n| Voice               | Codec2 (3200 bps)                   | Open voice codec; MELPe placeholder        | Tests pass      |\n\n---\n\n## What Makes It Milspec-Capable\n\n- **11,480-channel UHF FHSS** (225–512 MHz, 25 kHz spacing) — GPS-locked 100 hops/sec\n  AES-256-ECB hop sequencer with `hop_index` field for deterministic intra-second\n  sequences; FHEK cryptographically separate from TEK so TEK compromise does not\n  reveal the hop pattern\n- **TRANSEC subsystem** — three-tier EMCON (0=silence, 1=beacon-only −20 dB,\n  2=normal), hardware-enforced lock bit with one-time unlock token, tamper→EMCON-0\n  callback; FEC block interleaver (N×512 BRAM, depth 1–32, default 10 = 100 ms\n  jammer dwell); burst-mode PA ramp (configurable attenuation step, 10 µs default);\n  adaptive per-link power control from beacon RSSI table (max 256 peers, 300 s expiry)\n- **PKCS#11 HSM abstraction** — `IHsmEngine` interface + `Pkcs11Hsm` dlopen loader\n  accepts any PKCS#11-compliant HSM module (Thales, Utimaco, YubiHSM, etc.) without\n  code changes; SoftHSM2 used for development/CI\n- **TDMA slot engine** with GPS 1PPS synchronisation and AXI Timer holdover on GPS loss;\n  slot bitmap register lets each node own multiple traffic slots\n- **QPSK modem** with rate-1/2 K=7 Viterbi FEC (CCSDS generators), Gardner timing\n  error detector, and Costas loop carrier recovery — full closed-loop demodulation\n- **ECDSA P-384 net join** — challenge-response authentication against a trusted node\n  list; new node signs nonce, TEK+FHEK delivered encrypted under its public key;\n  join target \u003c 2 seconds\n- **OTAR key distribution** architecture — over-the-air rekeying; TEK rotated hourly\n- **Three-key hierarchy** — KEK (HSM-bound, wraps all other keys), TEK\n  (per-session AES-256-GCM traffic key), FHEK (hop sequence key)\n- **Secure boot chain design** — Zynq eFuse → FSBL → U-Boot → Linux → application;\n  FPGA bitstream encrypted and authenticated in production configuration\n\n---\n\n## Build \u0026 Run (Software Stack — no hardware required)\n\nThe C++20 comms stack builds and runs on any Linux or macOS machine today.\n\n**Dependencies (macOS):**\n```bash\nbrew install cmake boost openssl spdlog softhsm codec2 catch2\n```\n\n**Dependencies (Ubuntu 24.04):**\n```bash\nsudo apt-get install -y cmake libboost-dev libssl-dev libspdlog-dev \\\n    libcodec2-dev softhsm2 pkg-config\n# Catch2 v3 from source:\ngit clone --depth 1 --branch v3.5.4 https://github.com/catchorg/Catch2.git\ncmake -S Catch2 -B Catch2/build -DBUILD_TESTING=OFF\nsudo cmake --build Catch2/build --target install -j\n```\n\n**Build:**\n```bash\ncmake -S software -B software/build\ncmake --build software/build -j$(nproc)\n```\n\n**Test:**\n```bash\nctest --test-dir software/build --output-on-failure\n# Expected: 100% tests passed, 0 tests failed out of 128\n```\n\n---\n\n## Repository Layout\n\n```\nfpga/               FPGA RTL (SystemVerilog) + XSim testbenches\n  src/              Six RTL modules: axi_regs, ad9361_if, channelizer,\n                    fhss_engine, modem, tdma_mac\n  sim/              Testbenches (*_tb.sv) — all pass XSim simulation\n  scripts/          Vivado project TCL, simulation runner, check_regmap.py\n  constraints/      Pin assignments (pinout.xdc) and timing (timing.xdc)\n\nhardware/           KiCad dev board (Zynq-7045 + AD9361, 8-layer PCB)\n  cirradio-devboard/  Python generators produce .kicad_sch and .kicad_pcb\n  fab/              Fabrication notes\n\nsoftware/           C++20 comms stack (builds on desktop today)\n  src/              HAL, FHSS, TDMA, network, security, voice, CLI\n  tests/            Catch2 test suite (97 tests)\n  embedded/         Cross-compile HAL for Zynq ARM (libiio, UIO, gpsd)\n\nfirmware/           Embedded Linux stack\n  device-tree/      PetaLinux device tree overlays (pl.dtsi, system-user.dtsi)\n  petalinux/        meta-cirradio Yocto layer with app recipe + systemd service\n\ntools/\n  board-test/       Board bring-up scripts (SSH + serial, all support --dry-run)\n\ndocs/               Architecture deep-dive, design specs, implementation plans\n```\n\n---\n\n## See Also\n\n- [`fpga/README.md`](fpga/README.md) — RTL module details and Vivado instructions\n- [`hardware/README.md`](hardware/README.md) — Dev board overview and KiCad generation\n- [`docs/architecture.md`](docs/architecture.md) — Key hierarchy, FHSS math, net join\n  protocol, TDMA structure, AXI register map\n- [`SECURITY.md`](SECURITY.md) — Crypto posture and responsible disclosure\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmangobanaani%2Fcirradio","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmangobanaani%2Fcirradio","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmangobanaani%2Fcirradio/lists"}