RF Wireless World

Browse articles, tutorials, tools, and vendors.

Decoding Bluetooth Packet Types: Control, ACL, SCO & eSCO

By RF Wireless Expert Team

Introduction : If you capture Bluetooth traffic over the air using a protocol analyzer, you are going to see a massive stream of binary data. To make sense of it, you have to look at the “TYPE” field located in the packet header. Bluetooth Classic (BR/EDR) defines dozens of packet types, but they all fall into a few major families viz. Control/Common Packets, Discovery Packets, Asynchronous Data (ACL) Packets and Synchronous Audio (SCO/eSCO) Packets.

Let us explore each of the major bluetooth packet types and how major fields (e.g. LT_ADDR, TYPE, FLOW, SEQN, ARQN, HEC and CRC) change as per purpose of the packet.

1. The Control Packet

⇒ Example : POLL Packet

  • Purpose: The Central device sends this to a Peripheral to ask, “Do you have any data to send me?” The Peripheral is required to respond.
  • Size: 1 time slot.

The Decoding of this Bluetooth POLL packet contains following fields.

FieldDetails
Access CodeMatches the Piconet’s Central Address — Wakes up the receiver.
Header - LT_ADDR010 (Addresses Peripheral #2)
Header - TYPE0001 (This binary code explicitly identifies a POLL packet)
Header - FLOW1 (GO — receiver buffers are open)
Header - ARQN0 or 1 (Not actively used for POLL packets, as they don’t acknowledge data)
Header - SEQN0 or 1 (Sequence number is ignored here)
Header - HEC[8-bit checksum] (Validates the header)
Payload[NONE]
CRC[NONE]

Bluetooth Packet Format

The figure depicts bluetooth General Basic Rate packet format. As shown, bluetooth packet consists of access code, header and payload (including CRC).

2. The Device Discovery Packet

⇒ Example : Frequency Hop Synchronization Packet

  • Purpose: Used during pairing and connection setup. When you scan for Bluetooth devices on your phone, the devices you find are broadcasting their existence using FHS packets.
  • Size: 1 time slot.

The Decoding of this Bluetooth FHS packet contains following fields.

FieldDetails
Access CodeInquiry Access Code — A special general code used before devices are officially paired.
Header - LT_ADDR000 (All-zeroes are used because a formal connection hasn’t been established yet)
Header - TYPE0010 (Identifies the FHS packet)
Header - HEC[8-bit checksum]
Payload[240 bits total] — Unlike standard data payloads, the FHS payload has a highly rigid structure containing the sender’s Bluetooth MAC Address (BD_ADDR), its Class of Device (e.g., “I am an audio headset”), and its current Clock value.
CRC[16-bit checksum] (Crucial here, because if the clock or MAC address is corrupted, the connection will fail.)

3. The Asynchronous Data (ACL) Packet

⇒ Example : The DH5 (Data High Rate, 5-Slot) Packet

  • Purpose: Bulk data transfer. If you are sending a JPEG file to a laptop or streaming high-bitrate music, you are using ACL packets. DH5 means it occupies 5 radio time slots and uses no Forward Error Correction (FEC) in the payload to maximize speed.

The Decoding of this Bluetooth ACL packet contains following fields.

FieldDetails
Access CodeMatches the Piconet
Header - LT_ADDR001 (Addressed to Peripheral #1)
Header - TYPE1111 (Identifies a DH5 packet)
Header - ARQN1 (ACK — “I successfully received your last packet”)
Header - SEQN1 (Sequence toggle — “This is a new packet, not a duplicate”)
Header - HEC[8-bit checksum]
Payload Header - LLID10 (Indicates this is the start of a fragmented L2CAP message)
Payload Header - LENGTH339 (Tells the receiver to expect exactly 339 bytes of user data)
Payload[339 Bytes of file data]
CRC[16-bit checksum] (If this fails, the receiver will send an ARQN=0 in its next packet to request a retransmission.)

4. The Legacy Audio (SCO) Packet

⇒ Example: The HV3 (High Quality Voice 3) Packet

  • Purpose: Real-time, two-way audio for legacy Bluetooth headsets.
  • Size: 1 time slot.

The Decoding of this Bluetooth SCO packet contains following fields.

FieldDetails
Access CodeMatches the Piconet
Header - LT_ADDR011 (Addressed to Peripheral #3)
Header - TYPE0111 (Identifies an HV3 packet on a SCO transport)
Header - ARQN[Ignored]
Header - SEQN[Ignored]
Header - HEC[8-bit checksum]
Payload30 Bytes of CVSD encoded audio
CRC[NONE]

5. The Modern Audio (eSCO) Packet

⇒ Example: The EV3 (Extended Voice 3) Packet

  • Purpose: High-quality voice calls (like Hands-Free Profile in modern cars). It bridges the gap between ACL’s reliability and SCO’s real-time delivery.
  • Size: 1 time slot.

The Decoding of this Bluetooth eSCO packet contains following fields.

FieldDetails
Access CodeMatches the Piconet
Header - LT_ADDR100 (Using a secondary address specifically assigned for the eSCO link)
Header - TYPE0111 (Identifies an EV3 packet on an eSCO transport)
Header - ARQN0 (NAK — “I didn’t get your last audio packet clearly, please re-send it!”)
Header - SEQN0 (Sequence toggle)
Header - HEC[8-bit checksum]
Payload[1 to 30 Bytes of voice data]
CRC[16-bit checksum]

References & Further Reading

  1. Bluetooth SIG : Bluetooth Core Specification Version 6.3, May 5, 2026.
  2. Bluetooth SIG : Bluetooth Core Specification change history
  3. Bluetooth SIG : Bluetooth Technology Overview

Continue Learning Bluetooth Packet & its fields

Continue Learning Bluetooth Basic Concepts

Continue Learning Bluetooth Technology

Compare Bluetooth With Other Technologies

Explore Deep Insight Bluetooth Technology

Keep Reading