Keep That Old Radio Alive With An ESP32

As the legacy AM broadcast bands fade away, what happens to the millions of devices built to receive them? Many of them will go into e-waste, but with a century of radios to choose from, some of them are collector’s items. Vintage tube radios like the ones [GarethDaviesLondon] has would go silent, so he’s made a small AM transmitter to keep them alive.

At its heart is an ESP32-S3, which takes an online radio stream and transmits it through RF generated with a pulse chain on a GPIO. Generating analogue signals from radio to video with a microcontroller is nothing new, but perhaps the more interesting part of this one comes in how he radiates enough from that pin. There’s a 3D printed box with stand-offs designed to take a widely spaced wire coil, which is enough for the vintage electronics to pick up. He makes the point that it may not be legal, but at that power we doubt anyone will notice.

The output on this one is 200kHz for the European long wave band, but we’re guessing a higher medium wave frequency could also be generated. Meanwhile if you are curious about AM, we’ve featured someone having a closer look at it.

The ESP32, An SDR In Itself

Perhaps the most famous of all the software-defined radio (SDR) receivers is the RTL-SDR, a digital TV receiver on which an undocumented feature was found. Perhaps other radio-enabled chips also have the same undocumented feature? It seems in the case of some members of the ESP32 family, they do. It’s a discovery made independently in two places, by Espargos, and a Reddit user by the name of h0m3us3r.

What’s happening is that the undocumented mode taps the I/Q stream off before the WiFi modem, and this can be read and processed by SDR software on an external computer. The undocumented mode can be found on ESP32 chips with the earlier Tensilica hardware onwards, so the low power Bluetooth only chips or the non-radio-equipped P4 won’t work. Sadly it’s also only possible with the receive side, with both 2.4 and 5 GHz bands being supported depending on the microcontroller in question.

This isn’t quite the general purpose SDR we got with the RTL-SDR, but there are still plenty of uses to which it can be put. We’re curious as to whether someone can implement the software side of an SDR on the same chip, but we are guessing that might be beyond their capabilities. Either way, we’re looking forward to what the community does with this new-found knowledge.

SDR– Lets You Patch Together Your Setup

It is often helpful to think of a radio as a series of interconnected functional blocks—hence the use of block diagrams to convey how a given radio operates. [Julian Haag] has brought this ethos to SDR–, a software-defined radio program where you can patch together your setup.

There are many software defined radio tools out there, with various interfaces and methods of configuration. [Julian] wanted to keep things intuitive and simple, and so built SDR– with an interface similar to that of a modular synth. You drop in blocks, like a radio, a demodulator, or a speaker, and then you link them together with patch cables to route the signals where they need to go.

[Julian] has populated the tool with plenty of useful decoders, too, so you can have lots of fun from the get go. You can play with things like ADS-B, POCSAG, SSTV, DAB, and RDS right out of the box. There’s also some fun passive radar and direction finding tools there too if you want to dive in. Files are on GitHub for the curious.

We’ve featured lots of neat SDR hacks over the years, like this neat real-time beamforming setup. Meanwhile, if you’re cooking up your own radio experiments in the homelab, don’t hesitate to let us know on the tipsline.

A drone is shown, carrying underneath it a white plastic box. On the side of the box are two patch antennas. A camera extends from one end of the box, and a large GPS antenna from the other end.

Synthetic Aperture Radar Drone Gets Interferometric Imaging

It’s been more than a year since [Henrik Forstén] built the first iteration of his synthetic-aperture radar (SAR) imaging drone, and he’s certainly been productive in the meantime. Not only did he develop a much more powerful autofocus algorithm to clean up the radar images, but he also extended the software to create high-resolution interferometric images.

The main limitation of the original radar system was the GPS, which only had a resolution of about one meter; the autofocus algorithm owed much of its improved clarity to an improved estimation of the drone’s position. A simpler, though more expensive, solution was to add an RTK-capable GPS receiver. RTK (Real-Time Kinematic) receivers use a fixed ground station to constantly transmit a correction signal, letting them reach a couple centimeters of accuracy. Since the drone doesn’t actually need to know its position in real time, it can also use PPK (Post-Processing Kinematic) positioning, which compares recorded GPS signals after the flight to obtain similarly accurate positions.

[Henrik] also implemented a few other hardware improvements, including stabilizing the phase-locked loop used to generate the radar’s frequency sweep. The controller FPGA’s SD card interface had too low a bandwidth to record data in real time, so [Henrik] also implemented a simple, fast compression algorithm to speed that up. Most significantly, he also developed a program for interferometric imaging. The drone flies the same path twice at different altitudes; by comparing phase information from different passes, it’s possible to detect a target’s elevation. Normally, the radar program assumes constant elevation, making tall objects seem to lean toward the radar source; an interferogram, on the other hand, allowed [Henrik] to generate a detailed elevation map.

[Henrik] is no stranger to synthetic aperture radar; we’ve previously covered a bike-mounted iteration and a budget SAR system. If the concepts behind this are still a bit fuzzy, we’ve also covered a guide to making your own SAR setup.

Handheld Scanner Is A Radio Multi-tool

These days, it’s possible to cram a whole lot of radio functionality into a very compact device. A great example of that is the LakeShark scanner from [SAMS0N1TE].

The LakeShark is based on the LilyGO T-Display P4—which combines an ESP32-P4 microcontroller with a 4.1 inch AMOLED touchscreen display. It comes with an onboard SX1262 LoRa radio module as well as GPS and a nine-axis Inertial Measurement Unit to boot. [SAMS0N1TE] then set it up to also hook up to an RTL-SDR Blog V3 or V4, providing all kinds of extra software-defined radio functionality.

It can scan everything from P25 Phase 1 trunking transmissions, to ADS-B, POCSAG, and even good old FM broadcast radio. If you want to listen in on what’s on the air, or see a minimap with tracks of the planes flying overhead, you can do it all with this rig. You can even investigate various bands with waterfall displays or try and look for activity from nearby nRF24 devices.

Ultimately, it’s a bit of a Swiss Army knife for radio fun—able to do all kinds of neat things, and it fits right in your pocket. We’ve featured some other great SDR hacks recently, too, like this $50 build with an impressive 20 MHz of bandwidth. If you’re cooking up your own gear for the ham shack and beyond, let us know on the tipsline.

A laptop is shown set up on a desk next to a spectrum analyser, an SDR, and two antennas. The antennas are aimed toward assorted electronics, including headphones and a phone handset.

Reviving TEMPEST Attacks With An Injected Signal

TEMPEST attacks are often the most effective way to break air-gapped security: rather than directly accessing a computer, the attacker records the system’s unintended radio emissions and uses them to reconstruct its internal operations. This kind of attack was much more effective in the days of noisy, high-voltage CRT displays, and has gradually become less effective as electronics migrate to quieter, less powerful components. A group of researchers, however, has found that even modern electronics can become effective TEMPEST transmitters when irradiated with an RF signal.

The RF a device emits depends on the unintentional antennas in its internal structure. These are difficult to eliminate, and it’s usually not worth the effort; they’re usually small enough that they only effectively radiate at much higher frequencies than the electronics carry. The researchers’ technique, called InjectEave, radiated these electronics with a radio frequency tuned to their internal antennas, injecting that frequency into the circuit. Nonlinear electronic components, such as amplifiers, then mix the injected frequency with the internal signal, creating RF sidebands. This mixed signal then radiates out of the device and can be picked up and demodulated to recover the device’s internal signal.

Continue reading “Reviving TEMPEST Attacks With An Injected Signal” →

A Bandpass Filter Pulls In The Signals

It’s an unfortunate side effect of proximity to a large transmitter that the received signal can overload a receiver’s front end even when tuned to other frequencies. [Rfrht]’s had this problem with nearby FM broadcast transmissions overloading the 2 metre and 70 centimetre amateur bands. The solution?  Design and build a bandpass filter. This allows the signals you want to pass through while rejecting or attenuating out-of-band frequencies. The resulting PCB is very nice indeed.

On board, aside from the filters themselves, are a low-noise preamplifier and relays to switch between receive and transmit. Everything is controlled by logic-level signals. All components are surface-mount, and the PCB layout clearly takes special care with RF routing.

Continue reading “A Bandpass Filter Pulls In The Signals” →