GBCS 16.2 / 0x8F76 / Message Patterns
Unauthorised Physical Access - Terminal Cover Removed
Select a generating device type above to see the alert delivery pattern.
Message Pattern
Success Examples
The device detects the condition and generates GBCS event/alert code 0x8F76.
The device transmits a GBCSResponse/DeviceAlertMessage to the DSP via the WAN. Payload contains alert code and timestamp only (Generic Alert Structure).
DF090300000000000000010800DB1234
567890010890B3D51F30010000000A10
0090B3D51F30020000190F2000000100
0202128F76090C07EA0501FF0C000000
80000040748F6ED888095C77DBFC63AB
B9D195F28F1FFB658B506FC1E09FAD6A
11B12891374FAF6EF2E3C4FB8D45F89F
2F8B897AA10A655DBB0AD65FC80693DD
201F1A7C
View in GBCS Parser →DSP authenticates the GBCSResponse against the device certificate and validates the alert content.
DSP delivers the alert to the relevant Known Remote Party based on the alert code and triggering device type. The DUIS Response (sr:Response) wraps the raw GBCS payload in sr:GBCSPayload (base64).
<?xml version="1.0" encoding="UTF-8"?>
<sr:Response schemaVersion="5.4" xmlns:ns5="http://www.dccinterface.co.uk/sm" xmlns:ns4="http://www.dccinterface.co.uk/S1SP" xmlns:sr="http://www.dccinterface.co.uk/ServiceUserGateway" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:ns3="http://www.dccinterface.co.uk/ResponseAndAlert">
<sr:Header>
<sr:ResponseID>00-DB-12-34-56-78-90-01:90-B3-D5-1F-30-01-00-00:1</sr:ResponseID>
<sr:ResponseCode>I0</sr:ResponseCode>
<sr:ResponseDateTime>2026-05-01T12:00:00.00Z</sr:ResponseDateTime>
</sr:Header>
<sr:Body>
<sr:DeviceAlertMessage>
<sr:AlertCode>8F76</sr:AlertCode>
<sr:GBCSPayload>3wkDAAAAAAAAAAEIANsSNFZ4kAEIkLPVHzABAAAAChAAkLPVHzACAAAZDyAAAAEAAgISj3YJDAfqBQH/DAAAAIAAAEB0j27YiAlcd9v8Y6u50ZXyjx/7ZYtQb8Hgn61qEbEokTdPr27y48T7jUX4ny+LiXqhCmVduwrWX8gGk90gHxp8</sr:GBCSPayload>
</sr:DeviceAlertMessage>
</sr:Body>
</sr:Response>
<?xml version="1.0" encoding="UTF-8"?>
<sr:Response schemaVersion="5.4" xmlns:ns5="http://www.dccinterface.co.uk/sm" xmlns:ns4="http://www.dccinterface.co.uk/S1SP" xmlns:sr="http://www.dccinterface.co.uk/ServiceUserGateway" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:ns3="http://www.dccinterface.co.uk/ResponseAndAlert">
<sr:Header>
<sr:ResponseID>00-DB-12-34-56-78-90-01:90-B3-D5-1F-30-02-00-00:1</sr:ResponseID>
<sr:ResponseCode>I0</sr:ResponseCode>
<sr:ResponseDateTime>2026-05-01T12:00:00.00Z</sr:ResponseDateTime>
</sr:Header>
<sr:Body>
<sr:DeviceAlertMessage>
<sr:AlertCode>8F76</sr:AlertCode>
<sr:GBCSPayload>3wkDAAAAAAAAAAEIANsSNFZ4kAEIkLPVHzABAAAAChAAkLPVHzACAAAZDyAAAAEAAgISj3YJDAfqBQH/DAAAAIAAAEB0j27YiAlcd9v8Y6u50ZXyjx/7ZYtQb8Hgn61qEbEokTdPr27y48T7jUX4ny+LiXqhCmVduwrWX8gGk90gHxp8</sr:GBCSPayload>
</sr:DeviceAlertMessage>
</sr:Body>
</sr:Response>
The DCC User runs the received DUIS Response through the Parse tool, which decodes the GBCS payload and produces an ra:GBCSResponse (MMC) document containing the structured alert data.
Body path: ra:GBCSResponse/ra:Body/ra:DeviceAlertMessage/ra:DeviceAlertContent
Header fields
| Field | Type | Mandatory | Description |
|---|---|---|---|
BusinessOriginatorID | ra:EUI / identifier | Yes | Entity identifier of the message originator. |
BusinessTargetID | ra:EUI / identifier | Yes | Entity identifier of the message target. |
OriginatorCounter | xs:nonNegativeInteger | Yes | Originator counter in the response/alert header. |
SupplementaryRemotePartyID | identifier | Conditional | Supplementary party identifier; only present for alert families whose header table permits it. |
SupplementaryRemotePartyCounter | xs:nonNegativeInteger | Conditional | Supplementary party counter; only present for alert families whose header table permits it. |
SupplementaryOriginatorCounter | xs:nonNegativeInteger | Conditional | Only present where the specific header table permits it. |
Timestamp | xs:dateTime | Conditional | Only present where the specific header table permits it. |
GBCSHexadecimalMessageCode | xs:hexBinary | Yes | GBCS/MMC message code used to identify the alert use case. |
ra:DeviceAlertContent fields
| Field | Type | Mandatory | Description |
|---|---|---|---|
GBCSHexAlertCode | xs:hexBinary | Yes | Device Alert code as parsed from the GBCS payload. |
AlertDescription | xs:string (maxLength = 250) | Yes | Human-readable alert description. |
Timestamp | xs:dateTime | Yes | Device Alert timestamp as sent by the Device, in UTC time. |
Payload | choice | Conditional | Optional payload element present for the alert families in section 15.4. |
Identical MMC will be produced from both parties' received DUIS Responses and so is only shown once here.
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<ra:GBCSResponse xmlns:ra="http://www.dccinterface.co.uk/ResponseAndAlert" xmlns:sr="http://www.dccinterface.co.uk/ServiceUserGateway" schemaVersion="5.4">
<ra:Header>
<ra:BusinessOriginatorID>00-DB-12-34-56-78-90-01</ra:BusinessOriginatorID>
<ra:BusinessTargetID>90-B3-D5-1F-30-01-00-00</ra:BusinessTargetID>
<ra:OriginatorCounter>1</ra:OriginatorCounter>
<ra:SupplementaryRemotePartyID>90-B3-D5-1F-30-02-00-00</ra:SupplementaryRemotePartyID>
<ra:GBCSHexadecimalMessageCode>1000</ra:GBCSHexadecimalMessageCode>
</ra:Header>
<ra:Body>
<ra:DeviceAlertMessage>
<ra:DeviceAlertContent>
<ra:GBCSHexAlertCode>8F76</ra:GBCSHexAlertCode>
<ra:AlertDescription>Unauthorised Physical Access - Terminal Cover Removed</ra:AlertDescription>
<ra:Timestamp>2026-05-01T12:00:00.00Z</ra:Timestamp>
</ra:DeviceAlertContent>
</ra:DeviceAlertMessage>
</ra:Body>
</ra:GBCSResponse>