Captured on one boat, from one set of instruments, in one night. Every number below was measured. Where something is inferred rather than proven, it says so.
The short version
Marine radar and sonar imagery are not encrypted. They are simply undocumented. The formats are private, they differ per manufacturer, and no one publishes them, so every open-source effort starts from nothing.
Radar was rescued years ago by one person who refused to let it go. Sonar never was. There is still no open-source sonar display for Signal K or OpenCPN. These notes are a small contribution toward changing that.
232.1.216.1:2574 · run-length compressed spokes
The stream looked far too small to be an image. Six kilobytes a second, where uncompressed spokes should be megabytes. We nearly wrote it off as status chatter.
It wasn't. Quantum spokes are run-length compressed, and on mostly-empty
water that compresses enormously. A second trap sat behind it: the switch
only forwards a multicast group to ports that have asked for it,
so passive sniffing with tcpdump will never show you the
whole picture. You have to actually join the group, and for a
232.x address that means an IGMPv3 source-specific join.
| Offset | Size | Meaning | Observed |
|---|---|---|---|
| 0 | u32 | message type | 03 00 28 00 |
| 8 | u16 | range cells per spoke | 173 |
| 10 | u16 | spokes per revolution | 250 |
| 16 | u16 | bearing, 0–249, +1 per spoke | wraps each turn |
| 18 | u16 | payload length | matched 4500 / 4500 |
0x5c introduces a 16-bit little-endian run of empty cells.
Anything else is one cell's echo strength, 0x00 to
0xfd. A spoke may stop early; the remaining cells are empty.
seq 55155 bearing 78/250 18 bytes
5c 26 00 5f fd 5c 16 00 39 5c 2d 00 60 fd aa 5c 3e 00
skip 38 empty - echo 95 - echo 253 (hard return) - skip 22 -
echo 57 - skip 45 - echo 96, 253, 170 - skip 62, nothing further out
0x5c is also a legal
echo strength, so escape and data are not perfectly separable. Where
treating it as an escape would overrun the known cell count, we read it
as a literal. That fallback fires on about 29% of spokes. It does not
visibly change the picture, but the codec is not solved.
The radar announces itself on 224.0.0.1:5800 as
QuantumRadar and Quantum_W3, and advertises its
own channels — report group and command port — inside those
beacons.
One practical trap worth recording: commands are unicast to the radar's
own address on the 198.18.0.0/16 network. If your computer
has no address on that network, the kernel hands those packets to the
default gateway and they go nowhere. Everything looks fine — the
software sends, the radar is visibly reachable by multicast — and
nothing works. Adding a secondary address on the radar's subnet fixes it
instantly.
226.192.224.0:3221 · ~157 kB/s · 71 pings a second
The sonar stream does not exist on the network until a sonar page is open on the multifunction display. Same lesson as the radar: nothing on the wire until something wants it.
| Offset | Size | Meaning | Observed |
|---|---|---|---|
| 2 | u16 | header length | 42 |
| 4 | u32 | packet length | 2107, matched every packet |
| 21 | u32 | ping counter | +1 on 100% of pings |
| 30 | ascii | channel name | "Auto (50/200kHz)" |
| 56–128 | — | sonar settings | constant while settings are |
This is the part worth pausing on. Sitting in every single packet, seventy-one times a second:
41 75 74 6f 20 28 35 30 2f 32 30 30 6b 48 7a 29
A u t o ( 5 0 / 2 0 0 k H z )
The sounder announces its own frequency setting, in English, in a field nobody was ever expected to read.
Four reasons, none of them "impossible"
The hard half is analogue. Decoding a format is a weekend. Building a transmitter is hundreds of volts into a ceramic disc, a switch fast enough that your own ping doesn't destroy your own receiver, and an amplifier spanning about 100 dB — an echo from 200 ft is almost nothing beside one from 10 ft. The people who write chart software are mostly not the people who do power electronics.
Depth is the number that sinks boats. Nobody wants to publish an uncalibrated sounder.
Radar had a champion. Sonar didn't.
Every brand is a separate job. What's above is Raymarine's. Garmin and Humminbird are different formats again.
Airmar manufactures transducers for Raymarine, Garmin, Simrad, Furuno and Humminbird, and the internals of their CHIRP transducers are the same part across brands. What differs is the connector, a resistor so the brand recognises its own, and the network format.
The lock-in is a connector, a resistor and a file format.
Things we got wrong on the way, kept on purpose
Left here deliberately. Protocol work is mostly being wrong in progressively better ways, and a write-up that hides that is less useful to the next person.