GBCS 16.2 / 0x8F3F / Message Patterns
Unauthorised Physical Access - Tamper Detect
Select a generating device type above to see the alert delivery pattern.
Message Pattern
Success Examples
The device detects the condition and generates GBCS event/alert code 0x8F3F.
The device transmits a GBCSResponse/DeviceAlertMessage to the DSP via the WAN. Payload contains alert code and timestamp only (Generic Alert Structure).
DF090300000000000000010800DB1234
567890010890B3D51F30010000000A10
0090B3D51F30020000190F2000000100
0202128F3F090C07EA0501FF0C000000
80000040E8A4D05EDA959BB6E6787636
765698A898219FE06B9A45BD62D81CA7
EAA9B0C8365C757C3DF68318E7965B2C
68A245B5BE37D19AA990D083FF0FEADA
239EB032
View in GBCS Parser →DSP authenticates the GBCSResponse against the device certificate and validates the alert content.
DSP delivers the alert to the relevant Known Remote Party based on the alert code and triggering device type. The DUIS Response (sr:Response) wraps the raw GBCS payload in sr:GBCSPayload (base64).
<?xml version="1.0" encoding="UTF-8"?>
<sr:Response schemaVersion="5.4" xmlns:ns5="http://www.dccinterface.co.uk/sm" xmlns:ns4="http://www.dccinterface.co.uk/S1SP" xmlns:sr="http://www.dccinterface.co.uk/ServiceUserGateway" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:ns3="http://www.dccinterface.co.uk/ResponseAndAlert">
<sr:Header>
<sr:ResponseID>00-DB-12-34-56-78-90-01:90-B3-D5-1F-30-01-00-00:1</sr:ResponseID>
<sr:ResponseCode>I0</sr:ResponseCode>
<sr:ResponseDateTime>2026-05-01T12:00:00.00Z</sr:ResponseDateTime>
</sr:Header>
<sr:Body>
<sr:DeviceAlertMessage>
<sr:AlertCode>8F3F</sr:AlertCode>
<sr:GBCSPayload>3wkDAAAAAAAAAAEIANsSNFZ4kAEIkLPVHzABAAAAChAAkLPVHzACAAAZDyAAAAEAAgISjz8JDAfqBQH/DAAAAIAAAEDopNBe2pWbtuZ4djZ2VpiomCGf4GuaRb1i2Byn6qmwyDZcdXw99oMY55ZbLGiiRbW+N9GaqZDQg/8P6tojnrAy</sr:GBCSPayload>
</sr:DeviceAlertMessage>
</sr:Body>
</sr:Response>
<?xml version="1.0" encoding="UTF-8"?>
<sr:Response schemaVersion="5.4" xmlns:ns5="http://www.dccinterface.co.uk/sm" xmlns:ns4="http://www.dccinterface.co.uk/S1SP" xmlns:sr="http://www.dccinterface.co.uk/ServiceUserGateway" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:ns3="http://www.dccinterface.co.uk/ResponseAndAlert">
<sr:Header>
<sr:ResponseID>00-DB-12-34-56-78-90-01:90-B3-D5-1F-30-02-00-00:1</sr:ResponseID>
<sr:ResponseCode>I0</sr:ResponseCode>
<sr:ResponseDateTime>2026-05-01T12:00:00.00Z</sr:ResponseDateTime>
</sr:Header>
<sr:Body>
<sr:DeviceAlertMessage>
<sr:AlertCode>8F3F</sr:AlertCode>
<sr:GBCSPayload>3wkDAAAAAAAAAAEIANsSNFZ4kAEIkLPVHzABAAAAChAAkLPVHzACAAAZDyAAAAEAAgISjz8JDAfqBQH/DAAAAIAAAEDopNBe2pWbtuZ4djZ2VpiomCGf4GuaRb1i2Byn6qmwyDZcdXw99oMY55ZbLGiiRbW+N9GaqZDQg/8P6tojnrAy</sr:GBCSPayload>
</sr:DeviceAlertMessage>
</sr:Body>
</sr:Response>
The DCC User runs the received DUIS Response through the Parse tool, which decodes the GBCS payload and produces an ra:GBCSResponse (MMC) document containing the structured alert data.
Body path: ra:GBCSResponse/ra:Body/ra:DeviceAlertMessage/ra:DeviceAlertContent
Header fields
| Field | Type | Mandatory | Description |
|---|---|---|---|
BusinessOriginatorID | ra:EUI / identifier | Yes | Entity identifier of the message originator. |
BusinessTargetID | ra:EUI / identifier | Yes | Entity identifier of the message target. |
OriginatorCounter | xs:nonNegativeInteger | Yes | Originator counter in the response/alert header. |
SupplementaryRemotePartyID | identifier | Conditional | Supplementary party identifier; only present for alert families whose header table permits it. |
SupplementaryRemotePartyCounter | xs:nonNegativeInteger | Conditional | Supplementary party counter; only present for alert families whose header table permits it. |
SupplementaryOriginatorCounter | xs:nonNegativeInteger | Conditional | Only present where the specific header table permits it. |
Timestamp | xs:dateTime | Conditional | Only present where the specific header table permits it. |
GBCSHexadecimalMessageCode | xs:hexBinary | Yes | GBCS/MMC message code used to identify the alert use case. |
ra:DeviceAlertContent fields
| Field | Type | Mandatory | Description |
|---|---|---|---|
GBCSHexAlertCode | xs:hexBinary | Yes | Device Alert code as parsed from the GBCS payload. |
AlertDescription | xs:string (maxLength = 250) | Yes | Human-readable alert description. |
Timestamp | xs:dateTime | Yes | Device Alert timestamp as sent by the Device, in UTC time. |
Payload | choice | Conditional | Optional payload element present for the alert families in section 15.4. |
Identical MMC will be produced from both parties' received DUIS Responses and so is only shown once here.
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<ra:GBCSResponse xmlns:ra="http://www.dccinterface.co.uk/ResponseAndAlert" xmlns:sr="http://www.dccinterface.co.uk/ServiceUserGateway" schemaVersion="5.4">
<ra:Header>
<ra:BusinessOriginatorID>00-DB-12-34-56-78-90-01</ra:BusinessOriginatorID>
<ra:BusinessTargetID>90-B3-D5-1F-30-01-00-00</ra:BusinessTargetID>
<ra:OriginatorCounter>1</ra:OriginatorCounter>
<ra:SupplementaryRemotePartyID>90-B3-D5-1F-30-02-00-00</ra:SupplementaryRemotePartyID>
<ra:GBCSHexadecimalMessageCode>1000</ra:GBCSHexadecimalMessageCode>
</ra:Header>
<ra:Body>
<ra:DeviceAlertMessage>
<ra:DeviceAlertContent>
<ra:GBCSHexAlertCode>8F3F</ra:GBCSHexAlertCode>
<ra:AlertDescription>Unauthorised Physical Access - Tamper Detect</ra:AlertDescription>
<ra:Timestamp>2026-05-01T12:00:00.00Z</ra:Timestamp>
</ra:DeviceAlertContent>
</ra:DeviceAlertMessage>
</ra:Body>
</ra:GBCSResponse>