Decoding Bluetooth Packet Types: Control, ACL, SCO & eSCO
Advertisement
Introduction : If you capture Bluetooth traffic over the air using a protocol analyzer, you are going to see a massive stream of binary data. To make sense of it, you have to look at the “TYPE” field located in the packet header. Bluetooth Classic (BR/EDR) defines dozens of packet types, but they all fall into a few major families viz. Control/Common Packets, Discovery Packets, Asynchronous Data (ACL) Packets and Synchronous Audio (SCO/eSCO) Packets.
Let us explore each of the major bluetooth packet types and how major fields (e.g. LT_ADDR, TYPE, FLOW, SEQN, ARQN, HEC and CRC) change as per purpose of the packet.
1. The Control Packet
⇒ Example : POLL Packet
- Purpose: The Central device sends this to a Peripheral to ask, “Do you have any data to send me?” The Peripheral is required to respond.
- Size: 1 time slot.
The Decoding of this Bluetooth POLL packet contains following fields.
| Field | Details |
|---|---|
| Access Code | Matches the Piconet’s Central Address — Wakes up the receiver. |
| Header - LT_ADDR | 010 (Addresses Peripheral #2) |
| Header - TYPE | 0001 (This binary code explicitly identifies a POLL packet) |
| Header - FLOW | 1 (GO — receiver buffers are open) |
| Header - ARQN | 0 or 1 (Not actively used for POLL packets, as they don’t acknowledge data) |
| Header - SEQN | 0 or 1 (Sequence number is ignored here) |
| Header - HEC | [8-bit checksum] (Validates the header) |
| Payload | [NONE] |
| CRC | [NONE] |

The figure depicts bluetooth General Basic Rate packet format. As shown, bluetooth packet consists of access code, header and payload (including CRC).
2. The Device Discovery Packet
⇒ Example : Frequency Hop Synchronization Packet
- Purpose: Used during pairing and connection setup. When you scan for Bluetooth devices on your phone, the devices you find are broadcasting their existence using FHS packets.
- Size: 1 time slot.
The Decoding of this Bluetooth FHS packet contains following fields.
| Field | Details |
|---|---|
| Access Code | Inquiry Access Code — A special general code used before devices are officially paired. |
| Header - LT_ADDR | 000 (All-zeroes are used because a formal connection hasn’t been established yet) |
| Header - TYPE | 0010 (Identifies the FHS packet) |
| Header - HEC | [8-bit checksum] |
| Payload | [240 bits total] — Unlike standard data payloads, the FHS payload has a highly rigid structure containing the sender’s Bluetooth MAC Address (BD_ADDR), its Class of Device (e.g., “I am an audio headset”), and its current Clock value. |
| CRC | [16-bit checksum] (Crucial here, because if the clock or MAC address is corrupted, the connection will fail.) |
3. The Asynchronous Data (ACL) Packet
⇒ Example : The DH5 (Data High Rate, 5-Slot) Packet
- Purpose: Bulk data transfer. If you are sending a JPEG file to a laptop or streaming high-bitrate music, you are using ACL packets.
DH5means it occupies 5 radio time slots and uses no Forward Error Correction (FEC) in the payload to maximize speed.
The Decoding of this Bluetooth ACL packet contains following fields.
| Field | Details |
|---|---|
| Access Code | Matches the Piconet |
| Header - LT_ADDR | 001 (Addressed to Peripheral #1) |
| Header - TYPE | 1111 (Identifies a DH5 packet) |
| Header - ARQN | 1 (ACK — “I successfully received your last packet”) |
| Header - SEQN | 1 (Sequence toggle — “This is a new packet, not a duplicate”) |
| Header - HEC | [8-bit checksum] |
| Payload Header - LLID | 10 (Indicates this is the start of a fragmented L2CAP message) |
| Payload Header - LENGTH | 339 (Tells the receiver to expect exactly 339 bytes of user data) |
| Payload | [339 Bytes of file data] |
| CRC | [16-bit checksum] (If this fails, the receiver will send an ARQN=0 in its next packet to request a retransmission.) |
4. The Legacy Audio (SCO) Packet
⇒ Example: The HV3 (High Quality Voice 3) Packet
- Purpose: Real-time, two-way audio for legacy Bluetooth headsets.
- Size: 1 time slot.
The Decoding of this Bluetooth SCO packet contains following fields.
| Field | Details |
|---|---|
| Access Code | Matches the Piconet |
| Header - LT_ADDR | 011 (Addressed to Peripheral #3) |
| Header - TYPE | 0111 (Identifies an HV3 packet on a SCO transport) |
| Header - ARQN | [Ignored] |
| Header - SEQN | [Ignored] |
| Header - HEC | [8-bit checksum] |
| Payload | 30 Bytes of CVSD encoded audio |
| CRC | [NONE] |
5. The Modern Audio (eSCO) Packet
⇒ Example: The EV3 (Extended Voice 3) Packet
- Purpose: High-quality voice calls (like Hands-Free Profile in modern cars). It bridges the gap between ACL’s reliability and SCO’s real-time delivery.
- Size: 1 time slot.
The Decoding of this Bluetooth eSCO packet contains following fields.
| Field | Details |
|---|---|
| Access Code | Matches the Piconet |
| Header - LT_ADDR | 100 (Using a secondary address specifically assigned for the eSCO link) |
| Header - TYPE | 0111 (Identifies an EV3 packet on an eSCO transport) |
| Header - ARQN | 0 (NAK — “I didn’t get your last audio packet clearly, please re-send it!”) |
| Header - SEQN | 0 (Sequence toggle) |
| Header - HEC | [8-bit checksum] |
| Payload | [1 to 30 Bytes of voice data] |
| CRC | [16-bit checksum] |
References & Further Reading
- Bluetooth SIG : Bluetooth Core Specification Version 6.3, May 5, 2026.
- Bluetooth SIG : Bluetooth Core Specification change history
- Bluetooth SIG : Bluetooth Technology Overview
Continue Learning Bluetooth Packet & its fields
Continue Learning Bluetooth Basic Concepts
- What are new features in Bluetooth 6.3 Version
- Bluetooth GATT Vs. ATT Vs. GAP : Key Comparison
- Bluetooth Service Vs. Characteristic Vs. Descriptor
- Bluetooth Central Vs. Peripheral : Key Differences
- Bluetooth pairing Vs. Bonding Phase
- Bluetooth Notifications Vs. Indications
- Bluetooth Channel Sounding Vs. RSSI
- Bluetooth Direction Finding Methods : AoA Vs. AoD
- Bluetooth HID Over GATT
- Bluetooth IRK Vs. LTK : Key Differences
- Bluetooth PHY : 1M Vs. 2M Vs. Coded Differences
- What is ATT MTU Size in Bluetooth
- Bluetooth Ranging : Phase Based Vs. RTT Based
- Bluetooth Error Codes Guide : Meanings, Causes & Fixes
- Bluetooth L2CAP and HCI : Key Differences
Continue Learning Bluetooth Technology
- Bluetooth Basics Tutorial
- Bluetooth Low Energy (BLE) Basics Tutorial
- Bluetooth Protocol Stack & Device State Diagram
- Bluetooth Physical Layer Modules
- Bluetooth MAC Layer Overview
- Bluetooth Channel Frequency List
- Bluetooth Network Security
- Bluetooth Low Energy (BLE) Connection Establishment Procedure
- Bluetooth Profiles: HFP, HSP, A2DP, AVRCP, PBAP & MAP
- Bluetooth Mesh Node Types & Protocol Stack Layer Functions
Compare Bluetooth With Other Technologies
- Bluetooth V5.0 Vs. V5.1 Vs. V5.2 Vs. V5.3
- Bluetooth Vs BLE : Key Differences
- Bluetooth Vs UWB Technology : Key Differences
- Bluetooth Vs Wi-Fi Vs UWB
- Comparison Between All Bluetooth Versions from 1.0 to 6.3
Explore Deep Insight Bluetooth Technology
- Bluetooth AFH Explained: Adaptive Frequency Hopping & FAQs
- Bluetooth Error Recovery : ARQ, ACK, NAK
- Bluetooth Bit Stream Processing: HEC, CRC, FEC & More
- Bluetooth Routing: How Devices Know a Packet is for Them
- Bluetooth Flow Control: Understanding GO & STOP Bits
- Bluetooth Power Management: Sniff, Hold & Active Modes
