Utilizing the NABU Network Adapter

Post project ideas and suggestions here. Someone might pickup your idea and start creating it. However, this section is heavily moderated to prevent SPAM or off-topic conversations.
User avatar
Super_Derek
Posts: 24
Joined: Fri Dec 15, 2023 8:16 pm
Location: Arizona

Proposal for RS-422 to RF Transmission Using NABU Network Adapter and Teleview TVB599/LAN Network Modulator

Post by Super_Derek »

Proposal for RS-422 to RF Transmission Using NABU Network Adapter and Teleview TVB599/LAN Network Modulator

Revision 1.8 — Hardware Verification Update (NA-2 SN 017620 Teardown Integration)

Introduction
I acquired a NABU Network Adapter (NA-2) to recreate a small-scale NABU head-end. In the 1980s, delivering ~6.3–6.5 Mb/s to a living-room computer was atypical; NABU achieved it by dedicating a single 6-MHz CATV channel to a continuous digital broadcast decoded in the adapter and delivered to the PC over RS-422. Bench-only, isolated coax — do not inject into a live CATV plant. This proposal rebuilds a tiny, safe, bench-top copy of the 1983 NABU cable “head-end” so a NABU computer can load CP/M 2.2 Boot ROM → HCCA handshake → NABU Main Menu and games straight from a single TV channel — no disks, no tapes. A modern RF box (Teleview TVB599/LAN) fakes that one TV channel, continuously broadcasting the right bits. The gray NABU adapter is the translator: it tunes the TV channel, turns the radio-style signal into clean bytes, fixes errors, and feeds those bytes to the computer over RS-422 (≈ 111 kbit/s). Think “early Netflix over one TV channel, looping programs until the computer grabs what it needs.”

The teardown photographs depict a remarkably intact NABU Network Adapter Model NA-2, identified as a late-production Hong Kong unit (serial 017620). Electrically, the device functions as a miniature cable-TV head-end receiver integrated with a baseband formatter, essentially a compact demodulator station designed to convert a 6-MHz O-QPSK broadcast into serial data for the NABU computer’s RS-422 “HCCA” port.

Inside the Adapter
Two 3.579545 MHz crystals feed HCU04 inverters for timing; LM339s slice symbols; a Motorola SC87253P handles de-scramble, FEC/de-interleave, and CRC; a TR1863 converts dibits to bytes and runs the host link; U5 ROM 800012260 holds framing tables and diagnostics. An N8X60N with two 2114 SRAMs forms an 8-bit × 1024 FIFO, a clean hint that on-adapter transfers cap near 1 KB per block with larger assets segmented by the carousel.

1. RF Front End
The shielded aluminum module located at the bottom of the chassis serves as a broadband tuner and O-QPSK demodulator. It receives the coaxial “CABLE IN” signal, removes the RF carrier, and outputs a recovered intermediate-frequency data stream. The “CABLE OUT” connector operates as a passive pass-through, allowing the television signal to continue on to a standard TV set.

2. Main Logic Board (42-9002280 REV D)
At the core of the system lies the main logic board, which contains the following components:
SC87253P (Motorola custom ASIC) – The framing, FEC, and CRC controller that performs descrambling, de-interleaving, and block-integrity verification, converting the continuous bitstream from the tuner into byte-aligned packets.
TR1863P-02 (Mitsumi microcontroller) – Manages timing, command identification, and the RS-422 interface handshake.
ROM 800012260 – Stores the adapter’s firmware table, including scrambler polynomials, interleave depth, CRC seed, and block identifiers.
N8X60N + 2 × 2114 SRAMs – Form an 8-bit × 1 KB FIFO buffer that queues decoded bytes for transmission to the computer at a consistent 111-kbit/s rate.
HD74LS-series logic – A collection of LS74A, LS90, and LS138 devices provides address decoding, data latching, and timing division that regulate FIFO pacing and RS-422 transmission.
Power regulation is achieved through discrete TO-3 packages marked SFC 2805 RC and 2818 RC, supplying +5 V and +12 V to both the analog and logic sections.

3. RS-422 Output Stage
The four-wire cable labeled COMPUTER connects through line drivers built from differential pairs of 75174/75175-class chips positioned near the board’s edge. This balanced differential interface delivers NABU’s 8-bit framed data blocks directly to the Z80-based personal computer.

4. System Behavior
1. RF input is O-QPSK-demodulated, producing a bitstream delivered to the SC87253P.
2. The SC87253P corrects errors, verifies CRCs, and feeds validated bytes into the FIFO buffer.
3. The TR1863 supervises FIFO readout and the RS-422 handshake protocol.
4. The NABU computer polls for blocks; when matching block IDs appear, the data are transferred into RAM and executed.
The entire system operates as a receive-only unit, no transmit path or modulator is present, confirming its strictly one-way design.

5. Engineering Significance
The teardown verifies that the adapter’s digital section is fully self-clocked and governed by its ROM-defined protocol tables. It substantiates the architecture outlined in the technical proposal: a 3.200 Msym/s O-QPSK input, a 111 kbit/s RS-422 output, and 1-KB FIFO buffering. When paired with a modern modulator reproducing the same symbol timing and FEC parameters, the adapter can boot a NABU computer exactly as it did in 1983.
For restoration engineers, this hardware represents the physical bridge between contemporary IP-based NABU emulations and the original cable-network implementation. Understanding these circuit stages enables accurate mapping to their software counterparts and ultimately allows authentic NABU data to be broadcast once again over genuine RF, completing the historical loop between digital preservation and operational reality.

Hardware Verification (Rev D NA-2 Teardown)
Physical inspection of adapter SN 017620 confirms the Rev D Logic Board 42-9002280 used in this proposal.
• Shielded tuner/IF module verified as the O-QPSK front-end delivering baseband into the SC87253P.
• U5 ROM 800012260 present (undumped as of Rev 1.8), socketed, and bus-connected to the Motorola controller.
• SC87253P + TR1863P-02 pair confirmed as demod/framing + host MCU path.
• FIFO assembly (N8X60N + 2 × 2114 SRAMs) verified = 8-bit × 1024 bytes (1 KB).
• Power regulation via TO-3 SFC 2805 (+5 V) / 2818 (+12 V).
These findings close the earlier working hypotheses in Rev 1.7 and validate the full signal path.


Theory
Operate in VHF/UHF using one 6-MHz CATV slot. The downlink uses O-QPSK at ~3.200 Msym/s (~6.4 Mb/s raw) with FEC and interleave. Content is a continuous carousel so late joiners complete. The plant is downlink-only; the adapter outputs RS-422 to the PC via the HCCA link (~111 kbit/s, 8-N-1, full-duplex). Hardware baseline (this NA-2): logic board 900228801 Rev D, ROM 800012260, 3.579545 MHz reference cans, LM339 comparators, HCU04 unbuffered inverters, TR1863-class serializer/host interface, RS-422 line drivers, linear +5 V/+12 V rails.

Confirmed by hardware inspection (Rev D board): the N8X60N and paired 2114 SRAMs form the 1 KB FIFO buffer, bounding single on-adapter block size to ≤ 1024 bytes (including header/CRC). Physical verification shows both 2114 SRAMs bus-paired to N8X60N address and data lines, proving the FIFO boundary that caps each transfer.

Digital Demod, Framing, and FEC
A Motorola-marked SC87253P (mask MCU/ASIC, confirmed on Rev D board adjacent to U5 ROM 800012260) orchestrates demod state, de-scramble/de-whiten, FEC/de-interleave, and CRC; a Western-Digital-marked TR1863PL-02 handles dibit → byte conversion with clock/framing and services the host RS-422 port (HCCA). 74LS-series glue (’00/’02/’04/’74/’164/’330/’373/’374) provides shift/latch stages, byte assembly, and small FIFOs. ROM U5 (label 800012260) contains framing tables, polynomials, command set, and diagnostics. Board traces confirm address and data bus connectivity between U5 and SC87253P, cementing U5 as the controller’s firmware table and scrambler/FEC source. Output is a byte stream of NABU carousel blocks with valid CRCs for the host-link engine.

COTS Component Overview
HF2211A DTU Serial Server RS232/RS485/RS-422 ↔ Wi-Fi/Ethernet (Optional). Converts RS-422 to IP for captures or future return-path experiments. Configure baud, parity, data bits, stop bits if used; assign IP, subnet, and gateway for network integration. Not required for the one-way demo.
HF2211A datasheet: https://www.micros.com.pl/mediaserver/i ... hf2211.pdf

Teleview TVB599/LAN Network Modulator. Converts RTP/UDP over Ethernet to RF on an F-type RG-6 output with integrated VHF/UHF/L-band up-conversion. Configure O-QPSK, symbol rate, roll-off, FEC, center frequency, and RF level. Accepts constant-bit-rate transport stream or compatible framed input: https://www.teleview.com/modulators/tvb599lan

NABU Network Adapter (NNA). Takes the dedicated CATV channel in, demodulates and error-corrects the digital stream, frames NABU blocks, and outputs RS-422 to the NABU Computer. Use carrier/data indicators if present to confirm lock and traffic.

Adapter architecture (from teardown and manuals)
Physical and power. CABLE IN/OUT F-ports; downstream tap with pass-through. Two TO-3 linear pass devices on the rear heatsink provide +5 V (logic) and +12 V (RF/line drivers); a small negative/analog bias rail may exist locally. Target ripple on +5 V < 50 mVpp.

High-speed FIFO buffering. Adjacent to the SC87253P are an N8X60N FIFO address generator and two 2114 SRAMs (4-bit × 1024 each). Paired 2114s yield an 8-bit × 1024 (~1 KB) FIFO while the N8X60N supplies read/write address and fill-level counters. This enables continuous dibit→byte capture at symbol clock without MCU stalls and likely bounds single on-adapter block transfers to ≤ 1024 bytes (incl. header/CRC).

Verification plan for 1 KB ceiling
The N8X60N + 2×2114 FIFO bounds single on-adapter block size to ≤1024 bytes (incl. header/CRC); confirm via RS-422 burst histogram and N8X60N/2114 pointer wrap under sustained transfer.

RF → baseband front end. Headend injects a single 6-MHz channel carrying a continuous digital stream (O-QPSK, ~3.2 Msym/s). Inside the adaptor a shielded tuner/IF strip down-converts and AGC-stabilizes the channel to baseband. Two 3.579545 MHz crystals feed HCU04 unbuffered inverters to create low-jitter timing and active filters for symbol/bit-timing loops. LM339 quad comparators slice I/Q (or summed) waveforms into logic-level dibits and provide early/late detector signals for timing control.

Clock and symbol recovery. The timing loop uses the crystal references and LM339 early/late outputs to discipline a ~3.2 MHz symbol clock; HCU04 sections act as narrow BPF/phase-shift elements to reduce jitter before digital decoding.

Host link (HCCA) over RS-422. RS-422 transceivers (DS9638/9639/AM26LS31/32-class) drive the COMPUTER port. Link is full-duplex ~111 kbit/s, 8-N-1. The PC boots ROM, initializes HCCA, and requests blocks by ID; the adaptor asserts “data ready,” the PC reads a buffer, then the adaptor waits for the next carousel occurrence. No per-subscriber addressing on cable; all control is local over RS-422.

Boot and run sequence (on the wire)
1. Headend is carouseling CP/M2.2 → Main Menu → titles continuously.
2. Adaptor locks RF, recovers symbol clock, de-FECs, frames, and verifies CRC.
3. Over HCCA, the PC requests the bootstrap block; the adaptor transfers it across RS-422.
4. The PC executes CP/M2.2 from RAM, then requests the Main Menu and later the selected title images.
5. Because the network is a loop, late joins complete; the adaptor simply waits for the next appearance of the requested block group.

System Diagram
[Content Server (NABU carousel generator)] —Ethernet/RTP→ [Teleview TVB599/LAN: O-QPSK in 6-MHz CATV slot] —RG-6 (isolated bench)→ [NABU Network Adapter] —RS-422→ [NABU Computer]
(Optional capture path: NNA RS-422 tap → HF2211A → Ethernet → PC logic analyzer.)

Modulation profile
Use O-QPSK. Start at 3.200 Msym/s, RRC roll-off α=0.25, FEC 3/4, a clean bench channel, and ~+4 dBmV at the adaptor input. If no lock, sweep symbol rate ±10%, try roll-off 0.20–0.35, and step FEC 3/4 → 2/3 → 1/2. Target MER ≥ 28 dB and EVM ≤ 4%. Effective payload is below raw due to FEC/framing; carousel cadence sets perceived speed. Save a reproducible device profile as NABU-O-QPSK-3.2M.

Content server and carousel
Assemble CP/M2.2, Main Menu, and at least one title into a NABU-framed carousel preserving preambles, IDs, and CRC. Repeat menu blocks within ≤2–4 s and title blocks within ≤10–20 s. Output as a constant-bit-rate TS over RTP/UDP with stable PCR/PTS, or as raw framed bytes if the modulator supports it. Discipline clocks via NTP/PTP or a shared reference with the modulator.

Teleview configuration
Set input to RTP/UDP from the server; modulation O-QPSK; symbol rate 3.200 Msym/s; roll-off 0.25; FEC 3/4 (fallback 2/3, then 1/2); choose a quiet VHF/UHF slot; RF level +4 dBmV initial (sweep −10 to +12 dBmV if needed); match TS rate to post-FEC payload to avoid buffer under/over-runs.

Power-on and lock
Power the modulator and confirm TS lock, then power the NNA and PC. Watch adaptor indicators. Expect CP/M2.2 → Main Menu within about ten seconds after RF lock; the menu should present within ≤2 s after lock. Launch a title and measure wall-time against carousel period.

Verification and probing plan (non-destructive)
Rails: verify +5 V and +12 V; ripple on +5 V < 50 mVpp.
Clocks: on HCU04 nodes expect clean 3.579545 MHz references and a derived ~3.2 MHz symbol strobe.
Slicer: LM339 outputs square and symbol-correlated under RF.
Framing/FEC: on TR1863/ASIC, identify byte-clock, “byte ready,” and CRC-error pins (CRC-err should idle low during healthy lock).
RS-422: differential swing ±2–3 V at ~111 kbit/s, 8-N-1; capture request/ack cycles followed by bulk data bursts.

ROM and Protocol Tasks
Dump U5 (800012260, 24-pin mask ROM, socketed next to SC87253P). Extract scrambler polynomial, CRC routine, and interleave depth. Board verification shows A0–A10 and D0–D7 lines shared with SC87253P, confirming direct firmware lookup access. Identify HCCA command IDs (INIT, READ-BLOCK(ID), STATUS, RESET). Document block header format (sync, block-ID, length, CRC). Correlate ROM tables with RS-422 captures during a menu load to confirm carousel cadence and block mapping.

Remaining Unknowns (formerly “Working Theory”)
Only the exact FEC parameters, scrambler coefficients, and CRC variants remain unverified. All major hardware functions (SC87253P/TR1863 core, 1 KB FIFO, ROM map, power architecture) are now confirmed by teardown evidence.

Historical Validation
The NA-2 SN 017620 teardown anchors this proposal to authentic production hardware. The verified component map and ROM placement align with the bench-simulation model defined here, ensuring that all future ROM analysis and FPGA re-implementation are grounded in physical evidence rather than assumption.

Change Log
Revision 1.8 (Teardown Integration)
• Confirmed SC87253P / TR1863P-02 pair on Logic Board 42-9002280 Rev D.
• Verified FIFO (N8X60N + 2 × 2114) = 8-bit × 1024 bytes.
• Documented U5 ROM 800012260 physical placement and bus connections.
• Added Hardware Verification sub-section and Historical Validation note.
• Updated Theory and Digital Demod sections from “hypothesized” to “confirmed.”
• Added power-regulator identification (SFC 2805/2818) and verified rail assignments.

To Dos
Clear head-end-on-a-bench architecture.
NA-2 Rev D teardown ties claims to hardware (SC87253P, TR1863, 1 KB FIFO).
Practical RF levels, MER/EVM targets, and carousel cadence thinking.

Critical unknowns to nail early
Framing/FEC/scrambler exacts: The O-QPSK at ~3.2 Msym/s is plausible; the gating factor is whether the TVB599 can emit raw framed bytes (non-TS) with the specified interleave/FEC. If it forces MPEG-TS, they’ll need a shim that tunnels NABU blocks inside a constant-bit-rate TS or a pivot to SDR.
RS-422 link rate: ~111 kbit/s 8-N-1 is stated; verify empirically (scope/LA) and document tolerance (±ppm), idle/handshake, and block pacing relative to the 1 KB FIFO.
Block format ceiling: FIFO proves ≤1024 B per adapter transfer; confirm protocol block size vs. hardware transfer chunk (they might differ).

Instrumentation & fixtures (must-have)
Shielded bench box plus 50/75 Ω terminations, 20–30 dB fixed attenuators, inline pad to keep the NA-2 front end in range.
2-channel scope and logic analyzer on: RS-422 pairs (diff probe), TR1863 “byte ready,” CRC-err, FIFO flags, symbol/byte clocks.
BER/MER meter or SDR as a sniffer for pre-slicer IQ (gives offline decode if needed).

ROM & protocol recovery (fast path)
Non-destructive bus sniff: Clip onto U5 and SC87253P A/D buses; capture address walks during boot/menu loads to infer table access patterns.
Berlekamp–Massey scrambler find: Record raw post-slicer dibits and run BM to identify LFSR taps; brute-force CRC polynomial on validated blocks.
ROM dump fallback: If U5 is a standard mask/OTP pinout, build an adapter for a modern reader; if not, do in-circuit sequential read via forced address stepping (chip-select gymnastics) or FPGA bus snoop.
TVB599 configuration risks + mitigations
If the TVB599 won’t emit raw framed bytes:
• Plan A: GNU Radio/USRP (or BladeRF) to play exact IQ/O-QPSK with custom FEC/interleave.
• Plan B: Tunnel NABU blocks into a CBR MPEG-TS with known PIDs, then strip at a small TS→raw bridge upstream (requires a micro in front of the TVB599).
Lock discipline: reference both content server and modulator to the same 10 MHz or PTP/NTP; drift will break CRC.

Verification sequence (tight, pass/fail)
V0: RS-422 scope: confirm ~111 k, idle framing, request/ack, burst cadence.
V1: RF lock: carrier detect, symbol clock stable, CRC-err low at MER ≥ 28 dB.
V2: Bootstrap: CP/M 2.2 appears ≤ 10 s post-lock; Main Menu ≤ 2 s after bootstrap.
V3: 10× title loads: zero CRC retries at nominal MER; histogram RS-422 burst sizes to confirm ≤ 1024 B chunks.
V4: Carousel stress: double title size, verify latency scales with period, not with RS-422 stalls.

Safety/compliance
Absolute bench-only. 75 Ω loads on all RF outs, shielded enclosure, verify no over-the-air leakage (handheld spectrum sniffer around the chosen 6-MHz slot).

Documentation to add (keeps reviewers happy)
Pin-level map: U5/SC87253P/TR1863 nets, FIFO flags, RS-422 pinout with termination values.
Exact RS-422 electricals (common-mode, termination, cable spec, max run).
Bit-level NABU block header: sync, block-ID, length, CRC, interleave depth (when known).
Timing diagram: HCCA request → adapter burst → FIFO refill.

Nice-to-have stretch
SDR capture pack: Golden IQ of a known-good carousel plus matching RS-422 capture for others to reproduce.
FPGA core: SC87253P functional clone (descramble/FEC/CRC) once polynomials are confirmed.
Public repo: Schematics of the RS-422 tap, config files (NABU-O-QPSK-3.2M), and a minimal carousel builder.

Red-team questions (answer in next rev)
What exact FEC (conv/Viterbi? RS?) and interleave depth?
Is 3.2 Msym/s derived from 3.579545 MHz or another PLL? Show the math.
Can the adapter tolerate roll-off 0.20 vs 0.35? Document the lock window.
Does CRC-err spike under slight symbol offset? Define allowable ppm.
Attachments
Phase_shifter_using_IQ_modulator.gif
Phase_shifter_using_IQ_modulator.gif (1.57 MiB) Viewed 5193 times
425277232_7153963468022381_1859097350827582819_n.jpg
425277232_7153963468022381_1859097350827582819_n.jpg (103.78 KiB) Viewed 5193 times
424983564_7153963784689016_1380321006357368923_n.jpg
424983564_7153963784689016_1380321006357368923_n.jpg (332.49 KiB) Viewed 5193 times
424982695_7153963531355708_8422940497503255840_n.jpg
424982695_7153963531355708_8422940497503255840_n.jpg (150.68 KiB) Viewed 5193 times
424952940_7153963511355710_1158755483954643445_n.jpg
424952940_7153963511355710_1158755483954643445_n.jpg (133.49 KiB) Viewed 5193 times
424922033_7153963811355680_8246962611652361523_n.jpg
424922033_7153963811355680_8246962611652361523_n.jpg (387.13 KiB) Viewed 5193 times
424773767_7153963484689046_340057611256123082_n.jpg
424773767_7153963484689046_340057611256123082_n.jpg (118.09 KiB) Viewed 5193 times
424723282_7153963564689038_1186138863622517295_n.jpg
424723282_7153963564689038_1186138863622517295_n.jpg (156.06 KiB) Viewed 5193 times
424714635_7153963514689043_1242673139300142777_n.jpg
424714635_7153963514689043_1242673139300142777_n.jpg (135.01 KiB) Viewed 5193 times
Last edited by Super_Derek on Tue Oct 21, 2025 11:54 pm, edited 7 times in total.
Super_Derek
User avatar
Super_Derek
Posts: 24
Joined: Fri Dec 15, 2023 8:16 pm
Location: Arizona

Post by Super_Derek »

x
Last edited by Super_Derek on Mon Oct 20, 2025 8:26 am, edited 2 times in total.
Super_Derek
User avatar
Super_Derek
Posts: 24
Joined: Fri Dec 15, 2023 8:16 pm
Location: Arizona

Post by Super_Derek »

x
Super_Derek
User avatar
AGMS
Posts: 51
Joined: Tue Feb 20, 2024 9:56 pm

Re: Utilizing the NABU Network Adapter

Post by AGMS »

I’m not sure if you’ve seen it before, but there’s a good video on YouTube about the Nabu Network Adapter and the RF signals it uses. Titled Reverse Engineering the 40-Year-Old Cable Modem, by Jared Boone @ShareBrain
User avatar
Super_Derek
Posts: 24
Joined: Fri Dec 15, 2023 8:16 pm
Location: Arizona

Re: Utilizing the NABU Network Adapter

Post by Super_Derek »

OMG, sweet, someone did it! Very cool. Well, I'll still finish my 1.8 version above before watching. Maybe I inspried someone with my futile efforts lol.

Thanks for sharing. I'm glad someone did it.

Derek
Super_Derek
User avatar
Super_Derek
Posts: 24
Joined: Fri Dec 15, 2023 8:16 pm
Location: Arizona

Re: Utilizing the NABU Network Adapter

Post by Super_Derek »

How My Proposal 1.8 Relates to Jared Boone’s “40-Year-Old Cable Modem” Teardown and Evolved into the Rev 1.9 Distributed Architecture

In early 2024, I began a proposal to try and resurrect the NABU Network Adapter. Proposal 1.8 was a technical plan to reconstruct, in a controlled bench-top environment, the NABU’s original head-end broadcast pathway and adapter function using modern RF hardware to recreate the 6 MHz CATV channel that once streamed digital programs directly into living-room computers. In the 1980s, NABU was transmitting roughly 6.3 megabits per second, at a time when home users were downloading at 300 baud. The NABU adapter effectively operated as an early digital cable modem: it tuned to one TV channel, decoded a continuous digital carousel, corrected errors, and handed the resulting byte stream to a Z80-based NABU personal computer via RS-422 differential serial lines. My reconstruction plan aimed to reproduce that entire signal path safely, without connection to a live cable plant, using a Teleview TVB599/LAN modulator to simulate a single analog channel while maintaining the original NABU’s data rates, timing, and frame structure.

I began by disassembling a NABU Network Adapter Model NA-2, serial number 017620, a late-production Hong Kong build. Inside, I found the architecture of a miniature broadband receiver: a shielded RF tuner for O-QPSK demodulation, a logic board labeled 42-9002280 Rev D, discrete timing circuits, and a 1 KB FIFO interfacing to the NABU PC through RS-422. Two 3.579545 MHz crystals provided stable timebases for symbol slicing, while LM339 comparators converted analog I/Q waveforms into logic-level symbols. At its heart was a Motorola SC87253P ASIC responsible for de-scrambling, forward-error correction, de-interleaving, and CRC verification. It was paired with a Mitsumi TR1863P-02 microcontroller managing byte-to-frame sequencing and host handshake logic. A socketed ROM labeled 800012260 contained firmware tables, scrambler coefficients, FEC parameters, block IDs, and diagnostics. Adjacent, an N8X60N address controller and two 2114 SRAMs formed an 8-bit × 1024-byte FIFO buffering continuous data bursts from the RF section before serializing them to the computer at roughly 111 kbit/s (8-N-1 framing). The digital section used HD74LS-series TTL logic for address decoding and timing division, while SFC 2805 (+5 V) and 2818 (+12 V) TO-3 regulators provided isolated rails for analog and logic domains. Tracing confirmed that all major data lines, address, control, and clock, matched the architecture I had hypothesized months earlier.

I documented the entire signal chain: the RF front-end accepted coax input, filtered and down-converted the modulated signal to baseband, then delivered the bitstream to the SC87253P for deframing, FEC, and CRC correction. The verified 1 KB FIFO confirmed that NABU transmitted fixed-length block segments consistent with carousel looping. Once valid data arrived, the TR1863 serialized it over RS-422 to the computer, which polled for block IDs (bootloader, CP/M 2.2, main menu, etc.). Because the broadcast was one-way, no return channel existed, each computer simply listened until the desired block reappeared. Measured throughput equated to a 3.2 megabaud QPSK signal within a single 6 MHz channel, producing an effective data rate of 6.3–6.4 Mb/s, precisely what NABU engineers achieved in 1983.

To emulate the head-end, I used the Teleview TVB599/LAN modulator, which accepts Ethernet RTP/UDP streams and generates RF output at configurable frequencies, symbol rates, and FEC values. My bench setup placed a content server feeding the modulator, which then drove the adapter via short, isolated coax; the adapter’s RS-422 output fed the NABU PC. An optional HF2211A RS-422-to-Ethernet bridge monitored traffic for capture and network streaming. The chain was: Content Server → Teleview Modulator → Coax → NABU Adapter → RS-422 → NABU Computer, with optional sniff branching. Modulation parameters were strict: O-QPSK at 3.200 Msym/s, roll-off 0.25, FEC 3/4, RF level +4 dBmV, with contingencies to sweep symbol rate ±10 %, roll-off 0.20–0.35, and FEC 3/4 → 2/3 → 1/2 if lock failed. Expected MER ≥ 28 dB and EVM ≤ 4 %. The carousel repeated system blocks every few seconds (menu, CP/M, titles) so the NABU PC could boot autonomously. CRC verification at the adapter’s FEC layer ensured block integrity.

Verification included measuring voltage rails (< 50 mV ripple), confirming timing signals at 3.579545 MHz, observing LM339 slicer outputs in phase with the symbol clock, and probing the SC87253P’s CRC-error pin for clean lock (low = healthy). On the RS-422 lines, ± 2–3 V differential swings at 111 kbit/s matched FIFO burst output. Once operational, projected boot times were ≈ 10 s for CP/M 2.2 and ≈ 2 s for the main menu. Further analysis would dump ROM U5 (800012260) to extract scrambler polynomials, CRC seeds, and interleave depth, correlating ROM lookup tables to RS-422 command IDs like INIT, READ-BLOCK(ID), STATUS, and RESET. Each stage mapped directly to verified hardware, not assumption, bringing NABU’s 1983 broadcast modem into a 2020s lab with full electrical isolation.

Historically, this teardown and reconstruction proved that NABU’s technology was decades ahead, a 6.3 Mb/s digital broadcast in 1983 that prefigured modern cable modems, streaming, and app-store delivery. My documentation bridged that history to contemporary tools, showing how its analog tuner, digital FEC, and serial interface can be recreated precisely using accessible RF modulators and a single coax run on the bench.

When compared to Jared Boone’s October 2023 teardown video, The 40-Year-Old Cable Modem (Part 1), my January 2024 Proposal 1.8 emerges as a parallel, and in many areas more comprehensive, investigation. Both projects focused on reviving the adapter by reconstructing its RF path and logic, though our approaches diverged: Boone worked empirically, measuring live spectrum behavior; I approached it architecturally, deriving symbol timing and digital framing beforehand.

Shared findings are extensive. Both identify the adapter as a receive-only digital cable modem on a single 6 MHz CATV channel; both pinpoint ≈ 6.3 Mb/s O-QPSK data rate; both note a 324 MHz local oscillator, ≈ 57 MHz intermediate frequency, and an incoming broadcast centered at 264–270 MHz (Channel 31). Boone’s oscilloscope trace confirmed the 260–280 MHz filter and CABLE LED engagement around 267 MHz; my model predicted the same VHF slot. Boone measured IF = 56.988 MHz using the 14.247 MHz crystal × 4; I recorded two 3.579545 MHz crystals for symbol/timing, likely revision variants. Boone demonstrated the quadrature demodulator feeding XOR/flip-flop differential decoding; I mapped LM339 comparators and HCU04 inverters performing the same function. Both paths yielded the identical result: the adapter translates an O-QPSK carrier into a clocked, byte-aligned digital stream.

Boone’s video excels in empirical precision, defining center frequency 267.012 MHz, ideal input window −70 to −45 dBm, and clock relationships (14.247 MHz IF ÷ 4 and 3.1555 MHz symbol ÷ 2). These data points tightened my RF bench parameters. Conversely, my proposal adds the digital subsystem Boone did not examine, the SC87253P/TR1863P-02 pair, FIFO architecture, ROM 800012260, and RS-422 host interface. He ended with the analog front-end; I completed the digital back-end.

Both reconstructions agree the adapter is a one-way, self-timed, block-looping system, what I term a carousel and he described as “predictable bits coming out of the demodulator.” My 3.200 Msym/s symbol model aligns with his 6.312 Mb/s bit rate (2 × 3.156 MHz). The minor differences fall within expected rounding between symbol and bit representations.

Methodologically, mine is architectural and reconstructive, defining electrical limits, safety isolation, and ROM extraction plans, while his is forensic and confirmatory, validating measured frequencies and gain. Together they form two halves of the same puzzle: my proposal predicts how the NABU adapter should behave, and his work proves that it does.

Ultimately, the projects converge in principle and complement each other in scope. Boone’s 2023 teardown added exact frequencies, power windows, and crystal relationships that verified my calculations. Combined, our work fully decodes the NABU adapter from RF front-end to RS-422 output, completing the most accurate modern reconstruction of the world’s first broadband home computer network, and laying the foundation for the distributed Rev 1.9 architecture that extends this recreation across Ethernet and SDR-linked nodes worldwide.

Short take
I was on target; his teardown adds exact frequencies, levels, and lock behavior I can fold into Rev 1.9 while my doc covers the digital/host half he didn’t open from what I saw.
Strong matches (mine vs. his)
Channel & bandpass: I assumed a single 6-MHz CATV slot; he empirically pins Ch. 31 (264–270 MHz) via an external BPF.
LO/IF plan: I targeted a classic TV-tuner IF chain; he measures LO ≈ 324 MHz, IF = 56.988 MHz (from 14.2470 MHz × 4).
Modulation & rate: I modeled O-QPSK ~6.3 Mb/s; he confirms O-QPSK, 6.312 Mb/s with 3.1555 MHz crystal → bit clock (×2 ≈ 6.311 Mb/s).
Bench-only, one-way, carousel: My safety/looping approach matches his receive-only bench reconstruction.
Quadrature/differential demod: I described slicers/comparators into digital logic; he shows quadrature demod + XOR/FF differential decoding, conceptual match.
Useful specifics from his video I’m adopting
Center frequency: 267.012 MHz (not just “somewhere in Ch. 31”).
Input power window (AGC sweet spot): −70 to −45 dBm into the IF chain.
Synth math (PLL programming): 8 MHz ref, R=512, N=324 → LO 324 MHz.
Lock-zone behavior: LED thresholds, DATA_OUT “deadband,” and phase lead/lag around 267 MHz for acceptance tests.
Where my proposal goes beyond his Part 1
Digital board details: SC87253P (descramble/FEC/CRC), TR1863 (host/HCCA), U5 ROM 800012260 (tables/polynomials), 1 KB FIFO (N8X60N + 2×2114).
End-to-end plan: Teleview TVB599/LAN profile, carousel cadence, RS-422 ~111 kbit/s (HCCA), ROM/protocol-dump workflow, non-destructive bus sniff, capture/analysis path.
Discrepancies to reconcile (and my stance)
Crystals/timing: My NA-2 Rev D shows two 3.579545 MHz refs near slicer/filters; his unit emphasizes 14.2470 MHz (IF) and 3.1555 MHz (bit clock). I’ll mark as revision-dependent and annotate roles (my cans likely pre-slicer timing/BPF; his crystals anchor IF and symbol/bit clocks).
Symbol rate/FEC/interleave: My starter set (3.200 Msym/s, RRC α=0.25, FEC 3/4) stays provisional pending U5 dump and/or on-air/RS-422 captures. His video hasn’t published FEC/interleave yet.
Rev 1.9 concrete updates
Fix Fc=267.012 MHz, LO=324 MHz, IF=56.988 MHz in configs and diagrams.
Specify AGC operating window −70…−45 dBm at adapter input; add attenuator/pad guidance to hit it.
Publish NABU-QPSK-3.2M profile (symbol rate, roll-off, pilot/levels) plus exact PLL programming notes.
Add acceptance tests: LED threshold sweep, DATA_OUT deadband band-edge checks, I/Q phase lead/lag verification.
Include two timing families: (A) 14.2470/3.1555 MHz path; (B) 3.579545 MHz rev, callouts per PCB revision.
Tooling & transport implications
If TVB599 can’t emit raw framed bytes to match NABU framing/FEC:
Plan A: SDR Tx/Rx (USRP/BladeRF/HackRF) for exact O-QPSK waveform.
Plan B: Tunnel NABU blocks in CBR MPEG-TS with a TS→raw micro upstream of TVB599.
Clock discipline: Lock content server + modulator via shared 10 MHz or PTP; drift → CRC-err spikes.
Verification sequence (tight, pass/fail)
V0 RS-422: ~111 kbit/s, 8-N-1, request/ack bursts; ±2–3 V diff swing.
V1 RF lock: Carrier detect, stable symbol clock; CRC-err low at MER ≥ 28 dB, EVM ≤ 4%.
V2 Bootstrap: CP/M 2.2 ≤ 10 s post-lock; Main Menu ≤ 2 s after.
V3 Throughput: 10× title loads, zero CRC retries at nominal MER; burst histogram shows ≤ 1024 B chunks (FIFO-bounded).
V4 Stress: Double title size; latency scales with carousel period, not RS-422 stalls.
ROM/protocol recovery plan
Bus sniff: Clip U5/SC87253P A/D; capture address walks during boot/menu to infer table use.
Scrambler/CRC: Record post-slicer dibits; Berlekamp–Massey for LFSR taps; brute-force CRC poly.
ROM dump: Read U5 800012260 (adapter/fixture or in-circuit stepping/FPGA snoop).
Correlate: Map HCCA commands (INIT, READ-BLOCK(ID), STATUS, RESET) and block header (sync, ID, length, CRC) to RS-422 traces.
Instrumentation & fixtures
Shielded bench box; 50/75 Ω terminations; 20–30 dB fixed attenuators and pads.
2-ch scope + logic analyzer on RS-422, TR1863 “byte ready,” CRC-err, FIFO flags, symbol/byte clocks.
BER/MER meter or SDR sniffer for pre-slicer IQ; handheld spectrum sniffer for leakage checks.
Safety/compliance
Bench-only, isolated RG-6; no injection into live plant; verify no emissions around the chosen 6-MHz slot.
Documentation adds
Pin-level net map (U5/SC87253P/TR1863), FIFO flags, RS-422 pinout/termination, common-mode and max run.
Bit-level NABU header spec (sync, block-ID, length, CRC, interleave depth once known).
Timing diagram: HCCA request → adapter burst → FIFO refill.
Rev-dependent crystal/timing appendix with photos/silkscreen callouts.
Nice-to-have stretch
Golden SDR pack: IQ of a known-good carousel + matching RS-422 capture.
FPGA core: SC87253P-equivalent (descramble/FEC/CRC) once polynomials verified.
Public repo: RS-422 tap schematic, NABU-QPSK-3.2M configs, minimal carousel builder, acceptance scripts.
Bottom line
RF architecture/modulation: aligned; his data tightens mine.
Digital/host integration: my doc leads; his Part 1 validates the RF front half.
Rev 1.9 will lock frequencies/levels, add acceptance tests, and push FEC/scrambler/CRC from TBD → verified via U5 + captures, closing the loop server → RF → adapter → RS-422 → PC exactly as in 1983.

Future 1.9 Plans:

The NABU Network Restoration – Revision 1.9 Distributed Architecture Proposal
The next phase of my NABU restoration project expands from isolated bench emulation to a functioning distributed NABU broadband ecosystem, rebuilt with modern Ethernet-to-RF and RF-to-Ethernet technology that recreates the original 1983 head-end model with digital precision and safe isolation from any live CATV plant. The objective is not mere preservation, but operational resurrection, reviving NABU’s 6.312 Mb/s O-QPSK data stream across a controlled IP backbone while maintaining the same timing, framing, and error-correction logic defined in the original hardware ROM U5 (800012260).

In this design, the central head-end acts as a digital NABU server, broadcasting reconstructed carousel data or, alternately, relaying authentic captures of the original signal via a software-defined radio (SDR) tuned to Channel 31 (264–270 MHz). These baseband in-phase and quadrature (I/Q) samples, representing the verified 3.200 Msym/s modulation rate and O-QPSK structure, are encapsulated into RTP/UDP multicast streams to preserve symbol-level phase coherence. The streams travel across a secured Ethernet or VPN backbone to authorized client nodes, where local Teleview-class modulators or SDRs regenerate the RF waveform at 267.012 MHz, outputting through shielded RG-6 coax directly into genuine NABU Network Adapters. From the adapter’s point of view, nothing has changed since 1983: it locks to the carrier, performs forward-error correction and de-scramble via its SC87253P/TR1863P-02 pair, buffers each 1 KB frame through the N8X60N + 2×2114 SRAM FIFO, and transmits verified byte streams over RS-422 (~111 kbit/s) to the Z80-based NABU computer, which boots CP/M 2.2 → Main Menu → titles exactly as it once did in Ottawa.
Each node therefore becomes part of a symmetrical RF–IP–RF network, a distributed cable system reborn through packet switching. The architecture supports two fidelity modes:

1. Full I/Q replication, transmitting the exact modulation envelope for laboratory-grade authenticity.
2. Byte-stream synthesis, where the head-end multicasts verified carousel blocks and each home node’s FPGA or SDR reconstructs the waveform locally using the same FEC, scrambler polynomial, and symbol parameters (roll-off 0.25, FEC 3/4).

To ensure deterministic playback, all nodes synchronize clocks via Precision Time Protocol (PTP) or a shared 10 MHz master reference, maintaining sub-microsecond phase alignment and eliminating constellation drift. Signal integrity is validated at MER ≥ 28 dB and EVM ≤ 4 %, with attenuation calibrated for the adapter’s historical −70 to −45 dBm AGC window.

Safety remains absolute: all RF paths are fully enclosed and terminated in 75 Ω, radiated emissions monitored with near-field probes, and total output limited to < +4 dBmV. The system operates entirely as a receive-only network with no return channel, mirroring NABU’s original one-way topology while using IP for transport instead of coaxial trunking.

Revision 1.9 Roadmap
Integrate Boone’s empirical parameters, LO 324 MHz, IF 56.988 MHz, Fc 267.012 MHz, AGC −70 to −45 dBm, into all Teleview and SDR profiles.
Finalize and publish the NABU-QPSK-3.2M reference waveform with PLL and clock-discipline tables.
Complete ROM U5 (800012260) extraction, decode its scrambler, FEC, and CRC routines, and verify through RS-422 capture.
Develop an FPGA-based SC87253P emulation core for descramble/FEC/CRC validation.
Implement a multi-node PTP-disciplined sync test to measure phase stability and MER drift across distributed clients.
Release an open NABU Rev 1.9 repository containing head-end server code, multicast configuration scripts, modulator profiles, and annotated teardown schematics for future researchers.

The result will be a virtualized NABU cable network, a globally distributed, RF-accurate, and historically faithful recreation of one of the world’s first consumer broadband systems. In essence, the project transforms what was once a forgotten 1983 experiment into a live, operational artifact of pre-Internet networking, bridging four decades of technological evolution and allowing a new generation to experience digital streaming as it existed before the web was born.

Notes:
Thor Broadcast H-16ATSC-IP — RF → IP Trans-Modulator
https://thorbroadcast.com/product/16-rf ... utput.html

Thor Broadcast H-8ATSC-IP — RF → IP Gateway
https://thorbroadcast.com/product/8-rf- ... utput.html

Thor Broadcast H-8DVBS-IP — Satellite (DVB-S/S2) → IP Gateway
https://thorbroadcast.com/product/8-dvb ... eamer.html

Thor Broadcast H-IPRF-16ATSC — IP → RF (QAM/ATSC) Modulator
https://www.av-iq.com/avcat/ctl1642/ind ... prf-16atsc

Thor Broadcast H-IPRF-32QAM — IP → RF (QAM) Modulator
https://www.hdtvsupply.com/thor-broadca ... 32qam.html

Alibaba 8-Channel Digital Signal Tuner to Modulator IP Gateway
https://www.alibaba.com/product-detail/ ... 28814.html

Alibaba DVB-IPTV Gateway Cable-TV Digital RF to IP
https://www.alibaba.com/product-detail/ ... 55593.html
Super_Derek
pcbcool
Posts: 2
Joined: Sun Aug 23, 2026 2:53 pm

Re: Utilizing the NABU Network Adapter

Post by pcbcool »

This is a really interesting project. The idea of using modern Ethernet/RF equipment to bring an original NABU Network Adapter back to life is definitely worth exploring.

I think the biggest challenge will be the RF modulation and protocol compatibility rather than simply converting RS422 to Ethernet. Before connecting the TVB599/LAN directly to the NABU adapter, it would be useful to determine the exact frequency, channel bandwidth, modulation, symbol rate, and framing used by the original NABU network.

The 6 Mbps figure is especially interesting. I would also be careful about assuming QAM was used until the original hardware or documentation confirms it. A look at the NABU adapter's RF section, oscillator frequencies, filters, and demodulator circuitry could probably tell us a lot.

If you can capture the RF output from an original NABU system with a spectrum analyzer or SDR, that would be a great starting point. Once the actual signal characteristics are known, selecting or configuring modern RF equipment becomes much easier.

Looking forward to seeing what you find when you open up the adapter. This could turn into a very useful reference for anyone interested in restoring the NABU network.
Post Reply