1 Introduction

Low Power Wide Area Networks (LPWANs) [1] enable the transmission of small amounts of data across several kilometers while operating on battery or solar power. Initially developed for sensors and actuators in the industrial Internet of Things (IoT), they have high potential to enable emergency communication services, such as text messaging, that are independent of telephony systems, mobile networks, and Internet access, using inexpensive, commercial-off-the-shelf devices.

In the summer of 2023, the Austrian municipality of Neuhaus in Carinthia, near the Slovenian border, faced an extreme rainfall event that destroyed roads and bridges, disrupted telephone and Internet landlines, and cut off several small towns from the outside world for several days. In a rural region with limited mobile network coverage due to mountainous terrain, forests, and border regulations, relief units were unable to communicate with the population or safely access cut-off areas. To prepare for future disasters and potential disruptions to the public electricity and drinking water supply, the municipality of Neuhaus has been collaborating with the EU-funded dtec.bw project ROLORAN (Resilient Operation of LoRa Networks) since the fall of 2023 to develop a resilient crisis communication system. This system was first transitioned to continuous testing at the end of 2024 as a research prototype, developed based on requirements resulting from discussions with representatives of the municipality, regional authorities, emergency services, and affected citizens. This first prototype was subsequently improved and replaced by a second-generation prototype in September 2025, which has been in continuous testing under the name MERLIN (Messaging with regional LoRa infrastructure) since then.

The European policy, Directive (EU) 2022/2557 [2] defines critical entities as organizations whose disruption would significantly impact the provision of essential services and requires them to implement appropriate technical, security, and organizational measures to prevent, mitigate, respond to, and recover from incidents, including the establishment of crisis management, alert routines, and preparedness for large-scale disruptions such as communication system outages. While small municipalities are not always formally classified as critical entities under the Directive, they rely on and operate critical infrastructure vital to local crisis response and public safety. Municipality Neuhaus, as a testing environment for MERLIN, represents a class of municipalities characterized by limited resources, dispersed populations, and challenging topographical conditions. In such contexts, communication failures can directly endanger lives and severely impair crisis management. This paper presents MERLIN, a locally operated, self-sufficient communication system that provides a resilient fallback layer for municipal crisis coordination and implements resilience requirements defined for critical entities, while preserving local control and digital sovereignty.

We introduce the core components of the MERLIN system in Section 2 and compare them to similar approaches. Section 3 presents preliminary evaluation results and lessons learned after several months of operations, including demand for improvements. We conclude with a summary, an outlook on future work, and immediate next steps.

2 The MERLIN system and its components

MERLIN implements the Disaster Communication Protocol (RDCP), developed in the ROLORAN project, which is based on a tiered LoRa network operating on two independent frequencies. LoRa is a low-power wide-area (LPWAN) radio technology offering long range, energy efficiency, resilience to interference, and low operating costs, and is widely used in industrial IoT and smart city applications [3,4,5]. Using RDCP, MERLIN establishes data exchange between stationary and mobile MERLIN Bases, personal MERLIN Messengers, and a crisis management software used by emergency services to operate the infrastructure and to send and receive messages (Fig. 1).

Fig. 1
Fig. 1
Full size image

The MERLIN infrastructure with the distributed MERLIN Messengers, representative MERLIN Bases that transmit text messages via RDCP protocol, and the software for the crisis management team operating the system

2.1 ROLORAN Disaster Communication Protocol (RDCP)

RDCP is a text-based communication protocol for data exchange between crisis management teams, MERLIN Bases, and MERLIN Messengers. It can operate over LPWAN technologies, including LoRa. Prior work on LoRa-based emergency communication systems has addressed delay tolerance, multi-hop dissemination, and message flooding [6]. Schmidt et al. [7] propose a delay-tolerant overlay for LoRa networks, while Sciullo et al. [8] rely on smartphone-based gateways for emergency message dissemination. Other studies explore multi-hop and flooding approaches to increase coverage and resilience in rural or large-scale deployments [9, 10]. In contrast, RDCP combines a tiered architecture with redundant multi-path message delivery optimized for fast dissemination in municipal crisis scenarios. Unlike other LPWAN-based messaging solutions such as Meshtastic or Meshcore, RDCP operates multiple radio channels in parallel, typically in the license-free 433 MHz and 868 MHz frequency ranges, and integrates flooding-based mesh routing with star network topologies to distribute messages throughout the network. RDCP prioritizes the reliable delivery of critical messages such as official announcements from crisis management teams and emergency messages from citizens, while avoiding unnecessary congestion of radio channels. To this end, messages are transmitted redundantly and cached, allowing retrieval by devices that connect to the network later. In addition to bidirectional communication, RDCP supports multiple message types, including official announcements and telemetry data. It enables tunneling of other protocols, e.g., IPv4 or LoRaWAN, to integrate data from critical sensors such as weather stations and soil moisture sensors in scenarios where conventional communication infrastructure has failed.

The RDCP version currently in use is designed for rural areas and theoretically supports around 60,000 connected end devices per infrastructure based on the protocol-specific device address space, adequate device settings, and the assumption (according to task force interviews) that a burst of emergency reports is highly unlikely in our context; a new version currently in development will also support urban application scenarios with a multitude of devices. RDCP supports secure and resilient communication, including broadcasts to all end devices, group communication, and communication with individual devices. The messages are encrypted and authenticated using state-of-the-art methods (AES-256-GCM and Schnorr signatures) to ensure the confidentiality of emergency messages, i.e., to prevent the circulation of fake messages. In the current version deployed in Neuhaus, one radio channel is used to distribute messages between the MERLIN Bases, and a second radio channel connects end devices such as the MERLIN Messengers and the crisis management team to the RDCP infrastructure. To avoid interference from devices transmitting simultaneously, the RDCP protocol provides for deterministic clocking, applying pre-configured delays between reception and transmission based on available MERLIN base links, a derived minimum spanning tree, and optimal relay nodes (i.e., source-based routing). Transmission timing based on receipt timestamps results in implicit device synchronization. Clocking is combined with standard measures such as channel activity detection and timed back-off strategies to ensure fair channel use and coexistence with other LoRa devices such as smart water meters and smoke detectors on the same radio channels.

The RDCP protocol specification is publicly available and actively under development.Footnote 1 Since work on MERLIN began, the routing algorithm has been optimized, and additional message types have been introduced that allow the system to be used beyond acute crisis situations, for example, for disseminating municipal information, supporting digital notice boards, or providing local weather and climate data for smart agriculture. Figure 2 shows the exemplary message structure of an official announcement with header, containing common address and transmission fields as well as chosen next hops one, two, and three, and payload, consisting of announcement subtype, a unique identifier as message reference, information about the message validity period, the fragmentation state, and unishox-compressed (and for other private messages encrypted) content. While the primary purpose of the system remains robust operation under degraded communication conditions, these non-crisis functionalities promote regular use by operators and citizens, increasing familiarity with the system and reducing usability issues during actual crisis situations. To support reliable operation in all scenarios, it is essential to use short, compact messages whose content is additionally compressed to enable reliable transmission even over poor radio connections and to allow parallel use by a large number of devices.

Fig. 2
Fig. 2
Full size image

RDCP message frame for the message type OFFICIAL ANNOUNCEMENT with header (white) and payload (grey)

2.2 MERLIN Bases

MERLIN Bases (Fig. 5 and 6) form the backbone of the distributed RDCP communication infrastructure, providing a resilient, locally operated communication layer. Their placement determines radio signal coverage, and each base must be within range of at least one neighboring base, with redundant connections to compensate for individual failures. MERLIN Bases operate at least two channels simultaneously in interconnect with other bases and communicate with MERLIN Messengers, typically using elevated antennas to maximize coverage. In Neuhaus, the antennas were mounted on the roofs of refurbished telephone booths, achieving ranges of several kilometers even with line-of-sight restrictions from mountains and forests.

Scalability and deployment of LoRa-based emergency communication infrastructure have been studied in large-scale disaster response scenarios. Centelles et al. [9] report performance limitations in message retransmission when networks scale to tens of thousands of end nodes. In contrast, MERLIN targets municipal deployments with a controlled number of bases and messengers, prioritizing reliable coverage, redundancy, and operational robustness over large-scale message flooding.

MERLIN Bases can be operated in stationary configurations, as in Neuhaus, and in mobile configurations. Mobile bases can be used to temporarily reinforce coverage in remote or affected areas, while stationary bases may additionally serve as interactive communication points when personal devices are unavailable. In Neuhaus, these bases offer similar functionalities to the MERLIN Messengers and are equipped with an E‑Ink display, a keyboard, and solar panels and battery buffers, allowing operation for several months without sunlight. This is vital for Neuhaus, as extreme temperature changes in winter and fall prevent the batteries from being charged at sub-zero temperatures. The multi-channel LoRa radios used in Neuhaus were developed as open hardware in the project;Footnote 2 the software is also available as open source.Footnote 3 Deployment planning must consider radio coverage, seasonal sunlight availability, accessibility, and regulatory constraints. In the Neuhaus deployment, ten stationary bases were installed at crisis-relevant locations identified through site-specific measurements [11]. The on-site measurements with a handful of MERLIN messengers indicate sufficient network coverage at relevant locations in the municipal region, as seen in Fig. 3.

Fig. 3
Fig. 3
Full size image

Overview of network coverage with MERLIN Messengers in the municipality of Neuhaus with hexagon size corresponding to amount of sent packages and color for high (purple) and low (red) RSSI values

2.3 MERLIN Messengers

MERLIN Messengers (Fig. 4a) are mobile devices for households and emergency services, similar to smartphones but using LoRa radio and limited to text-based communication. They feature a touch display and a small physical keyboard and can run on an internal battery or a standard power bank. The devices used in Neuhaus achieve up to 14 days of runtime with a power bank. A screen saver and shutdowns during periods of non-use further reduce the energy consumption, with automatic data resynchronizing upon reactivation. However, no sleep modes are currently used, and incoming messages are handled immediately.

Fig. 4
Fig. 4
Full size image

MERLIN Messengers and software in use: a customized GUI of Messengers, and b crisis management notebook connected to a MERLIN Messenger

MERLIN Messengers serve two purposes. Firstly, they receive messages from the crisis management team, who can broadcast messages to all devices, selected districts or groups, or individual devices, enabling the population to stay informed about the crisis situation and relief measures. Second, during acute crises, these messengers allow citizens to send messages to the crisis management team, including structured emergency reports based on common emergency call questions, as well as non-urgent messages such as reports of infrastructure damage or needs for food or medicine.

Around 100 MERLIN Messengers are currently in use in Neuhaus. They are based on inexpensive, commercial off-the-shelf hardware (LILYGO T‑Deck) and run project-specific firmware with an intuitive graphical user interface developed within the project and released as open source software, which is continuously refined.Footnote 4 Dedicated stand-alone LoRa devices were deliberately chosen over smartphone-based approaches. While systems such as LOCATE [8] rely on smartphones connected to LoRa transceivers via Bluetooth Low Energy (BLE), MERLIN Messengers are designed for autonomous operation during crises, offering longer battery life, reduced dependency on personal devices, and more predictable availability.

2.4 MERLIN software for the crisis management team

The MERLIN software for the crisis management team (Fig. 4b) runs on standard PCs or notebooks with a reliable power supply and supports operational coordination during communication outages. It enables crisis managers to compose and disseminate official announcements, read and respond to messages from MERLIN Bases and Messengers, and categorize, annotate, and export messages for coordination and post-crisis documentation. In addition, the software provides monitoring and management functions for the entire MERLIN infrastructure, including an overview of bases’ status, battery levels, and link quality, as well as remote configuration of selected operating parameters. Its provisioning interface uses a custom serial command interface to configure wired MERLIN Messengers, which can be assigned to districts and securely managed using cryptographic key material to ensure authenticated access.

Currently, four notebooks with this software are in use in Neuhaus, operated by the municipal crisis management team and the volunteer fire departments. The notebooks support mobile operation and can be used at arbitrary locations within the RDCP infrastructure, enabling flexible and resilient crisis coordination even if primary operating locations become unavailable or during joint crisis exercises.

3 Evaluation results and potential for improvements

In the municipality of Neuhaus in Carinthia, Austria, an area of around 36 square kilometers at an altitude of 400 to 1000 m above sea level needs to be covered, posing challenges for radio communication due to extensive large forests and urban sprawl [12]. In late 2023, systematic measurements in ten sensitive districts identified suitable base locations [11]. In 2024, initial prototypes using DIY wooden structures with built-in electronics (Fig. 5) were deployed at five of these sites. The second generation, deployed as the longitudinal MERLIN system in late 2025, uses converted telephone booths as bases (Fig. 6) and extends the infrastructure with messengers.

Fig. 5
Fig. 5
Full size image

First generation MERLIN Base

Fig. 6
Fig. 6
Full size image

Second generation MERLIN Base

Beyond communication between the population and the crisis management team, the integration of selected sensor technology and data from critical entities is particularly relevant in Neuhaus. This includes current weather data from isolated districts, as well as river water levels and water tank pressures for the drinking water supply. The senior citizens’ center located in the municipal area is considered critical infrastructure, as it not only accommodates particularly vulnerable groups but also functions as the region’s only commercial kitchen and provides medical care to individuals who must leave their homes for an emergency shelter.

Since the end of 2025, crisis exercises have been conducted regularly in the municipality of Neuhaus using the MERLIN infrastructure. On the one hand, the goal is to practice and improve organizational processes to better prepare for real crisis situations. On the other hand, they are used to test more technical aspects, such as radio coverage in remote households, delays in the delivery of individual messages when many devices are active simultaneously, and the user-friendliness of the current software. Long-term testing across different seasons helps identify weaknesses in the current MERLIN infrastructure and inspire improvements for the third generation of the system. For example, although the E‑Ink displays deployed at the bases are particularly energy-efficient, they freeze at low ambient temperatures below \(0\,^{\circ}\mathrm{C}\) and cannot display legible text until they thaw, in accordance with the manufacturer’s (Waveshare) specifications. In our observations, this effect was noticeable at temperatures of around \(-5\,^{\circ}\mathrm{C}\) and several winter days with around \(-15\,^{\circ}\mathrm{C}\) rendered the displays temporarily useless. At one location, tall trees in the surrounding area prevented sufficient sunlight from reaching the solar panels to fully recharge the battery during the darker months of the year. In another area, condensation collects in the antenna cable connectors, deteriorating radio reception over time. During crisis exercises, it was found that a batch of small antennas for the mobile MERLIN Messengers were not well-tuned to the frequency range used and therefore had significantly poorer range than the other devices. We analyzed the antennas planned for distribution using network analyzer measurements and found that several antennas from the same batch (same vendor, same model) did not meet the specified standing wave ratio (VSWR) of up to 2.0. Antennas with a VSWR exceeding 2.4 were therefore excluded from deployment. It is somewhat obvious that this is sort of “bad luck” for our research prototype where budget and time constraints limit explorable options; when creating a real product, this issue would have to be addressed by quality management in the supply chains. Additionally, after prolonged use, some messenger touch displays required a device restart to function properly.

Some of these limitations are acceptable for a research prototype, but they do impose requirements on future generations of devices, especially if industrial partners can be found for professional manufacturing so that an improved solution can also be made available to other municipalities and cities.

4 Conclusion and outlook

Based on the deployment of the MERLIN system in Neuhaus, Austria, we conclude that locally operated, LoRa-based communication infrastructures can provide secure and resilient text-based communication under large-scale communication outages, serving as a critical backup layer for municipal crisis management. Through iterative refinement and field testing, we developed a robust, operationally suitable system comprising MERLIN Bases, Messengers, and crisis management software, which we continue to evaluate. Key improvements include weather-resistant base hardware, improved energy supply concepts, enhanced communication protocols, and additional functionalities, including dedicated messenger devices, that enable citizen participation. These insights and design principles are transferable to other municipalities facing similar challenges and crisis scenarios involving communication outages.

Future work will focus on further improving operational reliability and maintainability, with particular emphasis on fault tolerance and remote management. In addition, integrating external systems and sensor data, such as weather station data, will enhance infrastructure-related situational awareness and support decision-making for critical entities during crises.