Satellite time service system and method for preventing deception and suppressing interference

Through the dual GNSS RF module and the dual BDS signal spoofing interference identification module, combined with the CPU and FPGA to control the radio frequency switch, the problem of the satellite timing system being disturbed in complex electromagnetic environments is solved, and the identification and isolation of suppressed and spoofed interference is achieved, ensuring the stability and accuracy of the timing system.

CN120295088APending Publication Date: 2025-07-11STATE GRID INTELLIGENCE TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510556848.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing satellite timing system is susceptible to suppression and deceptive interference in complex electromagnetic environments, making it difficult to quickly and accurately identify interfering signals, resulting in a decrease in timing accuracy and reliability. The system lacks adaptability in different environments, and the system is paralyzed when a single module fails or interferes, so it is unable to continuously provide stable timing services.

Method used

The dual GNSS RF module and dual BDS signal spoofing interference identification module are used, combined with the CPU and FPGA to control the RF switch, and through AGC interference detection and Doppler offset detection, the interference signal is identified and isolated, ensuring the accuracy of signal output and the stability of the system.

Benefits of technology

It realizes effective identification and isolation of suppressed and deceptive interference, ensures the stability and reliability of the satellite timing system in complex environments, and improves timing accuracy and system fault tolerance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120295088A_ABST
    Figure CN120295088A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of satellite time service, and provides a satellite time service system and method for preventing cheating and suppressing interference, and the system is characterized in that double GNSS radio frequency modules are integrated in a GNSS radio frequency board, and each GNSS radio frequency module is responsible for receiving a BDS satellite signal; a double-BDS signal deception jamming recognition module is integrated in the satellite receiving board, and each BDS signal deception jamming recognition module is provided with a GNSS signal suppressing jamming detection method and a GNSS signal deception jamming detection method so as to perform jamming detection on one path of BDS satellite signals to obtain a satellite signal jamming state; the CPU is used for reading serial port message data for the two satellite signal deception jamming identification modules and analyzing UTC time; meanwhile, according to the satellite signal interference state, a radio frequency switch instruction is determined; and the FPGA is used for controlling the two GNSS radio frequency modules to output or reject BDS satellite signals according to the radio frequency switch instruction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of satellite timing, and in particular relates to a satellite timing system and method for preventing deception and suppressive interference. Background Art

[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.

[0003] In the existing field of satellite timing technology, there are a series of technical problems that need to be solved urgently, including the following:

[0004] Satellite signals are susceptible to interference: In a complex electromagnetic environment, satellite signals face a variety of interference threats. On the one hand, suppressive interference methods are constantly evolving, and high-power interference signals generated by criminals or in special environments can cover the satellite signal frequency band, making it difficult for satellite receiving equipment to capture effective satellite signals, resulting in a significant decrease in receiving sensitivity or even the inability to receive signals. On the other hand, deceptive interference technology is becoming more and more covert and complex. By forging false signals that are extremely similar to real satellite signals, it misleads satellite receiving equipment to calculate incorrect time, location and other information, thereby seriously affecting the accuracy and reliability of timing. However, the existing satellite timing system has technical shortcomings in interference detection, and it is difficult to quickly and accurately identify these two types of interference signals.

[0005] Timing accuracy is difficult to guarantee: Since satellite signals are easily interfered with during transmission and the performance of the receiving device itself is limited, the parsed time information has large errors. In some application scenarios that require extremely high time accuracy, such as the synchronous operation of power grids in power systems, accurate timestamp recording of financial transactions, and base station clock synchronization in communication networks, the existing satellite timing system cannot meet the needs of high-precision timing. Time errors may cause confusion in system operation, errors in transaction data, and a decline in communication quality.

[0006] Lack of flexibility in signal processing: When satellite signals are interfered with, existing satellite timing systems often lack effective response strategies and cannot flexibly adjust the signal reception and processing methods according to the type and degree of interference. Either the signal reception is blindly interrupted when the signal is slightly interfered with, resulting in the system being unable to continue to provide timing services; or the system continues to receive erroneous signals in the face of severe interference, causing the system to output erroneous timing results. In addition, the system's lack of adaptability in different working environments and interference scenarios makes it difficult to achieve intelligent control and optimized processing of signals.

[0007] System reliability needs to be improved: Existing satellite timekeeping systems usually adopt a single signal reception and processing module. Once this module fails or is severely interfered with, the entire system will be paralyzed and unable to provide timekeeping services normally. Moreover, in some harsh working environments, such as high temperature, low temperature, high humidity, or strong radiation environments, the performance of the module is easily affected, resulting in a reduction in the reliability of the system. At the same time, the mechanism for quickly detecting and repairing module failures is not perfect enough, further affecting the availability and stability of the system. Summary of the Invention

[0008] To solve the technical problems existing in the above-mentioned background technology, the present invention provides a satellite timekeeping system against spoofing and jamming. The CPU determines the RF switch instruction according to the satellite signal interference state, and the FPGA executes this instruction to control the GNSS RF module to output or reject the BDS satellite signal, which can flexibly adjust the reception and processing of signals according to the actual interference situation. Moreover, the CPU can read two BDS satellite signals from the satellite receiving board and parse out the UTC time. Due to the existence of the interference detection mechanism, when the signal is normal, the signal output is allowed to ensure that the system can continuously obtain accurate satellite signals and maintain a stable timekeeping function.

[0009] To achieve the above object, the present invention adopts the following technical solutions:

[0010] The first aspect of the present invention provides a satellite timekeeping system against spoofing and jamming, which includes a satellite receiving board, a CPU, an FPGA, and a GNSS RF board connected in sequence, and the GNSS RF board is also connected to the satellite receiving board;

[0011] The GNSS RF board integrates a dual GNSS RF module, and each GNSS RF module is responsible for receiving one BDS satellite signal;

[0012] The satellite receiving board integrates a dual BDS signal spoofing and jamming identification module. Each BDS signal spoofing and jamming identification module is configured with a GNSS signal jamming detection method and a GNSS signal spoofing detection method to detect the interference of one BDS satellite signal and obtain the satellite signal interference state;

[0013] The CPU is used to read the serial port message data for the two satellite signal spoofing and jamming identification modules and parse out the UTC time; at the same time, according to the satellite signal interference state, determine the RF switch instruction;

[0014] The FPGA is used to control the two GNSS RF modules to output or reject the BDS satellite signal according to the RF switch instruction.

[0015] Furthermore, it also includes a crystal oscillator;

[0016] The FPGA and the crystal oscillator jointly establish a counter for precise 64-bit second counting and 27-bit nanosecond counting, and timestamp the PPS of each input time.

[0017] Furthermore, the RF board has two RF input interfaces and four RF output interfaces. Each RF input interface is connected to a BDS antenna feeder. Two of the RF output interfaces are correspondingly output to the satellite receiving board, and the other two RF output interfaces are used as BDS satellite signal outputs.

[0018] Furthermore, the CPU sends and outputs the expected second interval count value, and the FPGA judges the arrival to generate the LC_PPS time pulse.

[0019] Furthermore, the message includes satellite signal interference status, positioning time, latitude, and longitude information.

[0020] Furthermore, the method for detecting GNSS signal jamming by suppression is as follows: monitor the output correlation value of the AGC in the GNSS RF board and compare it with the interference detection threshold. If the output correlation value of the AGC is greater than or equal to the interference detection threshold, it is determined that interference exists.

[0021] Furthermore, the interference detection threshold is set by measuring the distance between the interference transmitter and the GNSS RF board and the change of the output correlation value of the AGC.

[0022] Furthermore, the method for detecting GNSS signal spoofing interference is as follows: for the BDS satellite signal, use the Doppler offset detection algorithm to estimate the Doppler frequency shift, and perform multiple estimations at different times to obtain multiple Doppler frequency shift sequences; according to the estimated Doppler frequency shift sequences, calculate the Doppler change rate of each BDS satellite signal; compare the calculated Doppler change rates of each BDS satellite signal; if the difference between the Doppler change rates is less than the threshold, it is considered consistent.

[0023] Furthermore, the steps of the Doppler offset detection algorithm include:

[0024] Use a phase-locked loop to track the carrier phase and frequency of the BDS satellite signal. By adjusting the parameters of the phase-locked loop, make its output signal reach phase and frequency synchronization with the received BDS satellite signal. When the phase-locked loop reaches a stable state, the output frequency control signal is the estimated value of the Doppler offset.

[0025] The received BDS satellite signal is input into a phase-locked loop (PLL). The PLL compares the phase difference between the input signal and the locally generated reference signal through a phase detector, and adjusts the output frequency of the voltage-controlled oscillator according to the phase difference, so that the frequency and phase of the local reference signal gradually approach the input signal. When the PLL is locked, the output frequency of the voltage-controlled oscillator is equal to the Doppler shift frequency of the BDS satellite signal.

[0026] The second aspect of the present invention provides a satellite timing method for anti-spoofing and jamming suppression, which adopts a satellite timing system for anti-spoofing and jamming suppression as described in the first aspect, including:

[0027] Each GNSS RF module in the GNSS RF board receives a BDS satellite signal.

[0028] The dual BDS signal spoofing and jamming identification module integrated in the satellite receiving board performs interference detection on a BDS satellite signal respectively through the GNSS signal jamming suppression detection method and the GNSS signal spoofing detection method to obtain the satellite signal interference state.

[0029] The CPU reads the serial port message data for the two satellite signal spoofing and jamming identification modules and parses out the UTC time. At the same time, according to the satellite signal interference state, it determines the RF switch command.

[0030] The FPGA controls the two GNSS RF modules to output or reject the BDS satellite signal according to the RF switch command.

[0031] Compared with the prior art, the beneficial effects of the present invention are:

[0032] The present invention innovatively proposes a satellite timing system for anti-spoofing and jamming suppression. The CPU determines the RF switch command according to the satellite signal interference state, and the FPGA executes this command to control the GNSS RF module to output or reject the BDS satellite signal, which can flexibly adjust the reception and processing of signals according to the actual interference situation. Moreover, the CPU can read two BDS satellite signals from the satellite receiving board and parse out the UTC time. Due to the existence of the interference detection mechanism, when the signal is normal, the signal output is allowed, ensuring that the system can continuously obtain accurate satellite signals and maintain a stable timing function.

[0033] The present invention innovatively proposes a BDS signal spoofing and jamming identification module, and each module has the GNSS signal jamming suppression detection technology and the GNSS signal spoofing detection technology, which can comprehensively detect the received BDS satellite signal, timely discover and identify various types of interference signals (including jamming suppression and spoofing interference), thereby effectively resisting external interference, ensuring the reliability and accuracy of satellite signals, and improving the survival ability and working stability of the system in a complex electromagnetic environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The accompanying drawings forming a part of this invention are used to provide a further understanding of the invention. The schematic embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.

[0035] Figure 1 is a composition diagram of a satellite time synchronization system for anti-deception and suppression interference in the first embodiment of the present invention;

[0036] Figure 2 is a hardware architecture diagram of a satellite time synchronization system for anti-deception and suppression interference in the first embodiment of the present invention;

[0037] Figure 3 is a software architecture diagram of a satellite time synchronization system for anti-deception and suppression interference in the first embodiment of the present invention;

[0038] Figure 4 is a software module function module division diagram of a satellite time synchronization system for anti-deception and suppression interference in the first embodiment of the present invention;

[0039] Figure 5 is a composition diagram of a GNSS receiver in the first embodiment of the present invention;

[0040] Figure 6 is a schematic diagram of the quantization rule of a common 2bit ADC sampler in the first embodiment of the present invention;

[0041] Figure 7 is a schematic diagram of an ideal AGC loop in the first embodiment of the present invention;

[0042] Figure 8 is a schematic diagram of the AGC sampling values of more than 60,000 s in the first embodiment of the present invention;

[0043] Figure 9 is a schematic diagram of the change of the AGC gain value under jamming suppression in the first embodiment of the present invention;

[0044] Figure 10 is the AGC loop circuit diagram in Ublox in the first embodiment of the present invention;

[0045] Figure 11 is the schematic diagram of the signal duty cycle calculation principle in the first embodiment of the present invention;

[0046] Figure 12 is the schematic diagram of the GNSS B1I and B2I signal structures in the first embodiment of the present invention;

[0047] Figure 13 is the schematic diagram of the ranging code generation principle in the first embodiment of the present invention;

[0048] Figure 14 It is a schematic diagram of the PRN8 autocorrelation curve in the first embodiment of the present invention;

[0049] Figure 15 It is a schematic diagram of the cross-correlation curve between PRN8 and PRN9 in the first embodiment of the present invention;

[0050] Figure 16 It is a schematic diagram of generative deception in the first embodiment of the present invention;

[0051] Figure 17 It is a schematic diagram of retransmission deception interference in the first embodiment of the present invention;

[0052] Figure 18 It is a schematic diagram of the principle of retransmission deception interference in the first embodiment of the present invention;

[0053] Figure 19 It is a schematic diagram of the overall scheme for interference detection in the first embodiment of the present invention. Specific embodiments

[0054] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.

[0055] It should be noted that the following detailed description is illustrative and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0056] Embodiment 1

[0057] This embodiment provides a satellite time service system for anti-deception and jamming suppression.

[0058] The interference that the time-frequency system may suffer mainly targets GNSS time service terminal devices. According to different interference implementation methods, it can be roughly divided into two types: jamming suppression and deception.

[0059] Suppressive jamming refers to the use of a jammer to transmit a certain interference signal to mask the enemy's signal spectrum in a certain way, so that the enemy's receiver reduces or completely loses its normal operating ability. Suppressive jamming can be further divided into three types: ① Spot jamming: Spot jamming uses frequency targeting technology to accurately align the interference carrier frequency with the signal carrier frequency, and interferes with satellite signals of specific code patterns, making the signal ineffective in a certain area. ② Blocking jamming: The basic method of blocking jamming is to use a jammer to disrupt all GNSS satellite signals appearing in this area. According to the technical route, it can be divided into single-frequency jamming and wideband uniform spectrum jamming and other methods. Among them, the wideband uniform spectrum jamming system has better effects. Under this system, most of the interference signals generated by the jammer can pass through the narrowband filter of the receiver without being filtered out, so better interference effects can be produced. ③ Correlative jamming: By designing and generating interference signals with a large correlation with the pseudo-code sequence of GNSS signals, the navigation signals are interfered. Compared with spot jamming and blocking jamming, it has more energy that can pass through the narrowband filter of the receiver. Therefore, it can achieve effective interference equivalent to other methods with relatively small power.

[0060] Deceptive signals use false signals similar to navigation satellites as interference signals. Utilizing the characteristics of good concealment, they deceive the receiver to capture and track the false signals and obtain incorrect solution results. When the receiver has already tracked the correct satellite signal, according to the properties of the pseudo-random spread-spectrum code, at this time, after the spread-spectrum despreading of the deceptive signal after code synchronization, the amplitude will be greatly attenuated and it will be difficult to track the loop. Therefore, in order to lock the tracking loop of the receiver to the deceptive signal, the correct lock established by the receiver originally must be removed. Deceptive jamming can be divided into two types: generation jamming and retransmission jamming: ① Generation jamming means that the interference device generates navigation signals identical to the GNSS system to deceive the receiver and produce incorrect solution results. Generation deception requires obtaining the code pattern of the target signal and the synchronized satellite ephemeris and broadcast ephemeris parameters, and it is more difficult to interfere with encrypted signal types with unknown characteristics. ② Retransmission jamming is that the interference device receives the GNSS signal and then retransmits it to form a false signal. This method mainly uses the additional time delay of the signal and does not require generating highly realistic signals. It is relatively easy to implement technically. The main difficulty lies in extracting and analyzing the signal from the original navigation signal with a low signal-to-noise ratio and amplifying it, while reducing signal distortion.

[0061] The impacts of various interference means on GNSS timing are significantly different. If the jamming is of a relatively low level, the impact on the timing accuracy is small and can be ignored. If the signal strength is extremely high, resulting in GNSS signal loss of lock, then the GNSS timing is directly interrupted and users cannot obtain the external time. The spoofing interference signal is more complex. When using repeat-back jamming, due to the introduction of additional time delay, it directly causes the pseudorange measurement to increase, resulting in deviation in the time difference solution and obvious jumps in the time obtained by users. When using generation jamming, in addition to the change in time delay, the navigation message can also be modified, leading to incorrect calculation of the propagation time delay correction and affecting the user's timing result.

[0062] A satellite timing system against spoofing and jamming provided in this embodiment uses a dual BeiDou Navigation Satellite System (BDS), which is mainly deployed in scenarios such as the information computer room of the combat command post, satellite signal communication stations, communication command vehicles, and surface ships, to provide security protection for satellite signals in these application scenarios, ensuring accurate time for each device and normal operation.

[0063] The main function of the satellite timing system against spoofing and jamming is that, under normal circumstances, the RF switch in the satellite timing system against spoofing and jamming is closed, and the active antennas of BDS2 and BDS1 receive signals and directly output them to the next-level satellite synchronous clock. The satellite synchronous clock receives the satellite signals and is in the satellite timing working state. When there is a spoofing signal, the satellite timing system against spoofing and jamming shuts off the RF switch to isolate the spoofing interference signal and prevent it from being conducted to the next-level satellite synchronous clock.

[0064] The satellite timing system against spoofing and jamming adopts a modular design concept. Each module works independently. When a certain function needs to be improved, only the corresponding module needs to be modified, without affecting other parts, reducing the complexity and maintenance cost of the overall system. Modularity allows developers to reuse existing modules on different applications or hardware platforms, improving resource utilization efficiency and reducing the development time of new projects. New functions can be easily added by adding or replacing modules, enabling the system to adapt to changing requirements and technological progress. Each module focuses on a specific function, which helps team collaboration, improves the efficiency of coding and testing, and is also beneficial for understanding and documentation writing.

[0065] Such as Figure 1As shown in the figure, the satellite time synchronization system for anti-spoofing and jamming is mainly composed of a Global Navigation Satellite System (GNSS) RF module, a Beidou signal spoofing and jamming identification module, a switching control module (also known as the RF switch control module), a display and alarm module (also known as the display alarm module), and a configuration and management module (also known as the management configuration module).

[0066] The satellite time synchronization system for anti-spoofing and jamming provided in this embodiment receives two Beidou signals, identifies spoofing and jamming through the Beidou signal spoofing and jamming identification module, and notifies the switching control module of the identification result to control whether the GNSS RF module outputs satellite RF signals; when the satellite signal is not interfered, the GNSS RF module outputs the satellite signal without loss; when the satellite signal is interfered, the switching control module controls the GNSS RF module to isolate the interference signal.

[0067] Specifically, as Figure 2 shown, the satellite time synchronization system for anti-spoofing and jamming is designed in a 1U structure and mainly consists of a CPU board, a GNSS RF board, a satellite signal receiving board, a display board, and a power board inside.

[0068] The CPU board deploys a CPU, an FPGA, and a crystal oscillator, all of which are domestic chips and components. The CPU board provides: two Ethernet network ports NET1 and NET2 (which can be used for network management interfaces), two serial ports for the CPU to receive information from the BDS1 spoofing and jamming identification module and the BDS2 spoofing and jamming identification module, two control IO ports (input and output ports of BDS2_PPS and BDS1_PPS), an alarm contact interface, and a serial port for communicating with the display board. Data exchange between the CPU and the FPGA is carried out in an SPI manner, and at the same time, an LC_PPS signal for the CPU to keep time updated.

[0069] The GNSS RF board deploys two GNSS RF modules. The RF board has two RF input interfaces, which are respectively connected to the BDS1 antenna feeder and the BDS2 antenna feeder; and provides 4 RF output interfaces: two corresponding outputs are sent to the satellite receiving board for identifying interference and spoofing; two are used as satellite signal outputs.

[0070] In the present invention, two GNSS RF modules are configured in the GNSS RF board, and each module receives one BDS satellite signal. The satellite receiving board is also configured with two BDS signal spoofing and jamming identification modules. This redundant design increases the reliability of the system. Even if one of the modules fails or is severely interfered, the other module may still work normally, ensuring that the system will not be completely paralyzed and can still maintain a certain degree of time synchronization function, improving the fault tolerance and availability of the system.

[0071] On the satellite receiving board, a BDS1 satellite signal spoofing interference recognition module and a BDS2 satellite signal spoofing interference recognition module are deployed, and the satellite signals of BDS1 and BDS2 from the GNSS RF board are respectively connected; the input recognition status is output to the CPU through the serial port.

[0072] Two power supply boards provide redundant power for the device, improving the reliability of the device in terms of power supply.

[0073] On the display board, status indicator lights, an LED liquid crystal, and buttons are deployed, a serial port for communicating with the display board, and a 51CPU responsible for display and button processing.

[0074] The functional module relationship on the CPU is as Figure 3 shown. The CPU software completes functions such as information reception of two satellite signal spoofing interference recognition modules, running of the holdover clock, multi-time source judgment and selection, pulse interval estimation, control of the PPS output of satellite signals, and uploading of IEC61850 MMS communication information.

[0075] The FPGA and the crystal oscillator jointly establish an accurate 64-bit second count and 27-bit nanosecond count tick counter, and use this counter to stamp high-precision timestamps on the PPS of each input time; the generation of the local time LC_PPS is that the CPU sends and outputs the expected second interval count value, and the FPGA judges the arrival and generates the LC_PPS time pulse.

[0076] Local time LC_PPS: The PPS second pulse generated by the crystal oscillator through the LC oscillation circuit is used for internal time counting, and the 10Mhz signal of the crystal oscillator needs to be converted into a second pulse to be used.

[0077] According to the functions of the application, the application layer is modularly designed, and the overall module division is as Figure 4 shown, mainly divided into 5 working areas: data preparation and self-check, timing source drive, time processing, data uploading.

[0078] Data preparation and self-check include common variable initialization, inter-CPU communication, and self-check modules.

[0079] The time source driver is responsible for parsing and storing the information of two clock sources. For the two satellite signal spoofing and jamming identification modules, the CPU reads the serial port message data. The message follows the NMEA0183 "National Marine Electronics Association" protocol. Each message is in ASCII format with data streams separated by commas. The message contains information such as the satellite signal interference status (whether there is spoofing interference or jamming interference), positioning time, latitude, longitude, etc., and can parse out the UTC time and quality. At the same time, obtain the GNSS PPS timestamp generated by the FPGA, which is the clock source of the FPGA, that is, BDS_PPS.

[0080] Among them, the two satellite signal spoofing and jamming identification modules output message data, including satellite signal spoofing and jamming status, positioning time, latitude and longitude information. To compare the accuracy and consistency of the positioning time in the message information of the two-way signals, methods such as weighted average can be used. According to the reliability of the two-way signals, the same or different weights are assigned to obtain a more accurate and stable UTC time result, which is the UTC time.

[0081] The time processing task is responsible for implementing the multi-time source selection function, maintaining the local time, and is responsible for maintaining the hard clock established inside the FPGA, and adjusting the output frequency and phase of the FPGA.

[0082] The RF switch control module, according to the obtained satellite spoofing and jamming status, sends the RF switch command to the FPGA through SPI, and the two-way IO control signals of the FPGA control the GNSS RF module to output or reject satellite signals.

[0083] The data uploading module is responsible for the maintenance of the liquid crystal interface and the uploading of IEC61850 data. It can output self-check information such as the number of locked satellites, the status of lost satellites, clock error, etc. to the monitoring background through MMS messages to meet the monitoring requirements of the power system. Each module is coupled through the time source data. Their functions are independent of each other, and each module is scheduled by the main task loop.

[0084] In this embodiment, both the BDS1 signal spoofing and jamming identification module and the BDS2 signal spoofing and jamming identification module are configured with a GNSS signal jamming detection method and a GNSS signal spoofing detection method.

[0085] The suppression interference detection technology is used to detect suppression interference, including aiming interference, blocking interference, and correlation interference; the deception interference detection technology is used to detect deception interference, including generation interference and retransmission interference. Read the message to identify the interference status of the satellite signal. Whether it is suppression interference or deception interference, both GNSS RF modules will be controlled to reject the BDS satellite signal. Only when both the BDS1 signal deception interference recognition module and the BDS2 signal deception interference recognition module confirm no interference, will both GNSS RF modules be controlled to output the BDS satellite signal.

[0086] 1. GNSS signal suppression interference detection method.

[0087] GNSS suppression interference detection technologies mainly include AGC (Automatic Gain Control) interference detection technology, signal-to-noise ratio detection method, etc. Among them, the signal-to-noise ratio detection method mainly uses the sudden change in the ratio of satellite signal energy to noise energy to detect interference. The result of this detection method is very intuitive and has high sensitivity. However, in the actual operation process, the signal-to-noise ratio in the receiver will vary greatly with the satellite's position number in the orbit, weather changes, and changes in the surrounding environment. Therefore, the signal-to-noise ratio detection method often needs to be used together with other interference detection technologies to achieve better detection effects. The AGC interference detection technology uses the automatic gain control module built in the GNSS receiver to monitor the energy of the surrounding signals, and judges whether there is an interference signal around based on the signal energy entering the receiver. Compared with the signal-to-noise ratio detection method, the AGC interference detection technology has a simple principle, is easy to use, and has a good detection effect on interference with energy greater than the environmental thermal noise. Moreover, the energy of the blocking interference signal is generally greater than the environmental thermal noise.

[0088] Among them, AGC is a key module in the RF front-end of the GNSS receiver. In the GNSS receiver, the AGC module is often used to adjust the amplifier coefficient to control the signal voltage entering the ADC (Analog-to-Digital Conversion) module. This voltage must ensure the minimum quantization error during the AD conversion process. When there is a RF interference signal around the receiver, the AGC gain value will change. If this change is large enough, then the AGC module can be used for interference detection.

[0089] For the GNSS receiver, in order to minimize the quantization error as much as possible, the signal energy entering the ADC module is determined by L / σ. Where L represents the sampling threshold or voltage in the ADC, and σ represents the root mean square value of the noise at the ADC input. A commonly used quantization rule for a 2-bit AD sampler is as Figure 6 shown.

[0090] (101) AGC interference detection principle.

[0091] A GNSS receiver generally consists of an antenna, a frequency converter, an automatic gain controller, an AD converter, a correlator code / carrier tracking loop, and a digital processing section, as Figure 5 shown.

[0092] Among them, the AGC is a key module in the RF front-end of the GNSS receiver. In a GNSS receiver, the AGC module is often used to adjust the amplifier coefficient to control the signal voltage entering the ADC module. This voltage must ensure that the quantization error generated during the AD conversion process is minimized. When there are RF interference signals around the receiver, the AGC gain value will change. If this change is large enough, then the AGC module can be used for interference detection.

[0093] For a GNSS receiver, in order to minimize the quantization error as much as possible, the signal energy entering the ADC module is determined by L / σ, where L represents the sampling threshold or voltage in the ADC, and σ can represent the root mean square value of the noise at the ADC input. A common quantization rule for a 2-bit AD sampler is as Figure 6 shown.

[0094] The optimal L / σ value can be obtained through the probability distribution of the output value after signal correlation in a direct sequence pseudo-random noise receiver. For a 2-bit AD sampler, its optimal L / σ = 0.996. When the sampling threshold L is 2V, σ IF should be obtained through the formula 2 / 0.996 = 2.00. As Figure 7 shown, the AGC loop will adjust the VGA gain value g until σ IF equals σ IDEAL = 2.00.

[0095] Ideally, the gain of the AGC will change linearly with σ IF , that is to say, the gain coefficient g of the AGC will change linearly with the signal energy, that is: g·σ IF = σ IDEAL .

[0096] By monitoring the AGC, the value of the AGC gain when there is no interference signal can be obtained. If this value changes rapidly, it means that there is strong signal energy around, which does not conform to the characteristics of satellite signals, proving that there are interference signals in the surrounding environment. At the same time, the interference noise ratio of the environment can also be estimated through the change of the AGC gain. The formula is as follows:

[0097] g1·σ IF = σ IDEAL

[0098]

[0099] Among them, g1 represents the gain value of AGC without interference, g2 represents the gain value of AGC with interference, and σ RFI 2 represents the variance of the interference signal. Measuring the interference signal ratio (J / N) through AGC does not require measuring the inherent noise level of the receiver, etc., which is more convenient and effective than other methods.

[0100] The actual circuit diagram for implementing AGC is not as described above because the standard deviation of the signal level is difficult to obtain directly. Usually, the discrete signal after sampling is used to calculate the standard deviation of the signal level.

[0101] Based on the working principle of AGC, when the receiver is in a normal environment, since the satellite signal energy is very low, only about -130 dBm, the gain of AGC will not change significantly. Even if the receiver moves from outdoors to indoors, the value of AGC will not change because this value depends entirely on the ambient thermal noise level (the GNSS signal energy is much smaller than the Gaussian thermal noise). When there is an interference signal, the signal energy increases and can be compared with the ambient thermal noise, the standard deviation of the signal level increases, and the AGC gain will continuously decrease. Therefore, it is entirely possible to judge whether there is a jamming interference signal in the surrounding environment based on the change of the AGC value.

[0102] (102) AGC interference detection experiment.

[0103] To actually verify the effect of AGC interference detection, this embodiment uses a Ublox receiver to conduct an AGC interference detection experiment. The Ublox receiver itself can directly output the relevant values of AGC, which provides convenience for testing the effect of AGC interference detection. The experimental equipment includes a Ublox receiver, a BDS1 signal receiving antenna blocking interference generator, and a PC. The experiment includes two parts. The first part is mainly used to test the change of the relevant AGC values output by the Ublox receiver without interference; the second part is mainly used to test the change of the relevant AGC values after turning on the interference transmitter. During the experiment, the PC receives the relevant AGC values output by the Ublox every second and transmits the data values to an Excel document. Figure 8 The relevant AGC values when the Ublox works continuously for more than 60000 s without interference.

[0104] Figure 8In it, the abscissa is the operating time of the receiver, and the ordinate is the AGC-related value output by the Ublox receiver. This value is a dimensionless number. It can be seen that most of the output values of the AGC are concentrated between 5600 and 5720 (the larger the value, the smaller the AGC gain), and the change range does not exceed 200. This experimental result proves that the AGC-related value in the Ublox receiver has a very small change under the condition of no interference. The stability of the AGC-related value under the condition of no interference is the basis for further interference detection experiments. Next, turn on the interference transmitter, transmit the jamming signal, and continue to record the AGC-related value. Since the jamming signal will block the surrounding GNSS signals, the experimental time is not long, and the experimental results are as Figure 9 shown.

[0105] Figure 9 In it, the abscissa is the operating time of the receiver, and the ordinate is the AGC-related value output by the Ublox receiver. This value is a dimensionless number. It can be seen that around 115s, the AGC-related value in Ublox jumps instantaneously from about 5700 to above 6200, and the change range exceeds 500, which is much larger than the change range of the AGC under no interference, proving that the energy of the surrounding signals has changed greatly and the signal energy has increased significantly. This time period is also exactly the time when the jamming generator is turned on. The experimental results verify that the AGC has very good sensitivity to the jamming signal and is very suitable for interference detection.

[0106] (103) Setting the threshold for AGC interference detection.

[0107] The above experiments have verified the feasibility of the AGC as an interference detection module. However, on the one hand, since not all GNSS receivers provide the output of the AGC-related value, it is necessary to further study the meaning of the AGC-related value in Ublox; on the other hand, since the experiment is carried out in the vicinity of a high-power jamming signal source, it is necessary to study how to set the threshold of the related value to detect interference to the greatest extent. This can make the AGC detect the jamming signal existing in the surrounding environment more accurately. Because how the threshold is set and whether the setting is correct will directly affect the accuracy of AGC interference detection.

[0108] In the Ublox receiver, the output-related value of the AGC is not equal to the gain of the amplifier in the AGC. It can only reflect the change of the AGC gain from the side. Figure 10 is the circuit schematic diagram of the AGC module in the Ublox receiver.

[0109] From Figure 10As can be seen, the satellite signal is divided into two paths after amplification and filtering. One of the signals is processed and the corresponding output is SIGHI, and the other signal is processed and the corresponding output is SIGLO. In the Ublox receiver, the count value of the high level after the XOR operation of the two digital signals is used as a feedback signal to adjust the gain of the amplifier, and this value is also used as the output-related value of the AGC in the Ubox to reflect the magnitude of the AGC gain. In fact, the count value after the XOR operation of the SIGHI path signal and the SIGLO path signal is the duty cycle after the sampling of the satellite signal. When the satellite signal is divided into two paths, the value of one of the signals remains unchanged, and the other signal is compared with a set threshold. If the signal amplitude is greater than the threshold, the signal is "digitally inverted", and if it is less than the threshold, the signal is "digitally unchanged". Finally, the two signals are XORed, the number of high levels is read out, and then divided by the total number of levels to obtain the duty cycle of the signal energy. This duty cycle well reflects the energy level of the signal. When the signal energy increases, the part of the signal exceeding the threshold will increase, resulting in more "inversion" operations. This will cause the count value of the high level after the XOR operation of the two signals to increase and the duty cycle to rise. Conversely, the count value of the high level decreases and the duty cycle decreases. The specific process is as Figure 11 shown.

[0110] Figure 11 It also well explains why in the Ublox receiver, the output-related value of the AGC is a dimensionless integer, which actually reflects the number of high levels after the XOR operation of the signals. As the interference increases from none to some and the energy increases, the signal duty cycle will continuously increase, and the count value of the high level after the XOR operation of the two digital signals will continuously decrease, which is equivalent to the decrease of the output-related value of the AGC in Ublox.

[0111] Understanding the meaning of the output-related value of the AGC in Ublox provides ideas for designing one's own GNSS receiver and adding an interference detection module. On the other hand, according to the meaning of the output value of the AGC in Ublox and the degree of attenuation of the signal during propagation in the air, a threshold can be set for the output-related value of the AGC to improve the accuracy of interference detection.

[0112] When the GNSS receiver is not affected by interference signals, the carrier-to-noise ratio of the signal is determined by formula (1):

[0113]

[0114] where, S r represents the GNSS signal power, G r represents the antenna gain, 101g(kT0) represents the receiver noise density, N f represents the antenna and cable loss, and L(Db / Hz) represents the processor loss.

[0115] Assume the antenna gain is 0 dB, the receiver thermal noise density is -204 (BW / Hz), the antenna and cable loss is 4 dB, and the processor loss is 2 dB. After calculation, the minimum carrier-to-noise ratio of the L1C / A code without interference is 38.4 dB / Hz, the minimum carrier-to-noise ratio of the L1P code without interference is 35.4 dB / Hz, and the minimum carrier-to-noise ratio of the L2P(Y) code without interference is 32.4 dB / Hz.

[0116] When affected by GNSS interference, the carrier-to-noise ratio of the signal received by the receiver will be reduced to an equivalent C / N0 due to interference, which is called the equivalent carrier-to-noise ratio [C / N0]. eq :

[0117]

[0118] where f c represents the PRN rate of BDS1, which is 1023000 for the C / A code, Q is the spreading processing factor (1 for narrowband and 2 for wideband), C / N0 represents the interference-free carrier noise power at 1 Hz bandwidth (dB / Hz), and J / S represents the interference signal power ratio.

[0119] Here, only the L1C / A code is considered. When there is a jamming signal, Table 1 can be obtained through calculation.

[0120] Table 1. Relationship between interference signal power ratio and equivalent carrier-to-noise ratio after GNSS is interfered

[0121]

[0122]

[0123] It can be seen from Table 1 that narrowband interference has a greater impact on GNSS receivers.

[0124] For wireless signals, the communication distance is related to the signal transmission power, receiver sensitivity, and signal frequency. The loss of the signal during propagation can be expressed by Equation (3):

[0125] [Lfs](dB) = 32.44 + 20 log g d(km) + 20 log g f(MHz) (3)

[0126] In the formula, d is the signal communication distance, and f is the signal frequency. From the above formula, when [Lfs] is 50 dB for the GNSS interference signal, f is approximately 1575.42 MHz, and the calculated communication distance is 0.0048 km, that is, 4.8 m. That is to say, when the interference signal propagates 4.8 m, the interference signal will lose 50 dB of energy. For every 10-fold increase in this distance, the interference signal energy will lose an additional 20 dB.

[0127] For the jammer in the laboratory, assume that the transmitted signal energy is -50 dBm and the antenna gain is 10 dBi. Then the output signal energy is -40 dBm, while the satellite signal energy is about -130 dBm. It can be calculated by the formula that if the receiver is about 1 m away from the jammer antenna, the interference signal loss is 36.4 dB, and the interference signal energy reaching the receiver is about -76.4 dBm. At this time, J / S is 53.6 dB, and the equivalent carrier-to-noise ratio is 5.1 dB / Hz. In this case, the receiver will be severely interfered. In fact, the Ublox receiver in the experiment cannot receive the BDS1 signal at all when the jammer is operating. Based on the above data, a suitable interference detection threshold can be set by measuring the distance between the jammer and the receiver and the change of the relevant value of the AGC output.

[0128] In this embodiment, the specific steps of the GNSS signal jamming detection method include:

[0129] Step 1: Set an interference detection threshold by measuring the distance between the jammer and the receiver (GNSS RF board) and the change of the relevant value of the AGC output.

[0130] (1) It is known that when the receiver is about 1 m away from the jammer antenna, the interference signal loss is 36.4 dB, the interference signal energy reaching the receiver is about -76.4 dBm, at this time J / S is 53.6 dB, the equivalent carrier-to-noise ratio is 5.1 dB / Hz, and the receiver is severely interfered (the Ublox receiver in the experiment cannot receive the GPS signal at all when the jammer is operating).

[0131] (2) Measure the parameters at different distances: Change the distance between the jammer and the receiver, and measure the interference signal loss at different distances (which can be calculated according to the signal propagation model, etc.), the interference signal energy reaching the receiver (which can be calculated from the transmitted signal energy, antenna gain and interference signal loss), the J / S value (calculated from the interference signal energy reaching the receiver and the known satellite signal energy of about -130 dBm), and the relevant value of the AGC output.

[0132] (3) Analyze the data relationship: Analyze the relationship between the distance of the jammer and the interference signal loss, the interference signal energy reaching the receiver, the J / S value, and the relevant value of the AGC output. For example, a curve of distance and the relevant value of the AGC output can be plotted, etc.

[0133] (4) Determine the threshold: According to the analysis result, find one or more key points of the relevant value of the AGC output. The interference conditions corresponding to these points cause the performance of the receiver to degrade to a certain extent (such as being unable to receive the signal, etc.), and determine these key relevant values of the AGC output as the interference detection threshold.

[0134] Step 2, Real-time monitoring of the AGC output: During the operation of the receiver, the relevant values of the AGC output are monitored in real time.

[0135] Step 3, Comparison with the threshold: Compare the relevant values of the AGC output monitored in real time with the established interference detection threshold.

[0136] Step 4, Determine whether there is interference:

[0137] If the relevant values of the AGC output monitored in real time are greater than or equal to the interference detection threshold, it indicates that the intensity of the interference signal has reached or exceeded the level that will cause serious interference to the receiver. At this time, it can be judged that there is interference.

[0138] If the relevant values of the AGC output monitored in real time are less than the interference detection threshold, it indicates that the intensity of the interference signal is weak and has little impact on the receiver. At this time, it can be judged that there is no interference or the interference level is within an acceptable range.

[0139] Assume that the relevant value of the AGC output corresponding to the interference detection threshold is T, and the relevant value of the AGC output monitored in real time is A. Then the judgment logic is:

[0140] If A ≥ T, there is interference;

[0141] If A < T, there is no interference or the interference level is within an acceptable range.

[0142] 2. GNSS signal spoofing interference detection method.

[0143] (201) Signal structure and vulnerability analysis

[0144] (a) BeiDou signal structure.

[0145] The signals transmitted by satellites are structurally divided into three levels: carrier wave, ranging code, and data code. The ranging code and data code are attached to the carrier wave in the form of a sine wave through modulation. Example: The B1I and B2I signals of the BeiDou navigation system both use BPSK modulation. The BPSK modulation signal is expressed as:

[0146] S BPSK (t) = AC(t)D(t)sin(2πft + φ)

[0147] In the formula, A is the signal amplitude, C is the ranging code, D is the data code, f is the signal carrier frequency, and φ is the initial phase of the carrier wave.

[0148] Figure 12It is a schematic diagram of the Beidou B1I and B2I signal structures. At the satellite signal transmitting end, the satellite with the PRN number i first performs exclusive OR addition on the data code and the ranging code, thus completing the modulation of the data code on the ranging code. Then, the combined code of the two is subjected to BPSK modulation on the carrier wave, so that the entire ranging code signal is transmitted by the satellite at the center frequency of the carrier wave.

[0149] Carrier signal.

[0150] The nominal carrier frequency of the civilian B1I signal of the Beidou satellite navigation system is 1561.098 MHz, and the B2I signal is 1207.140 MHz. The purpose of using the carrier wave is that the frequency of the ranging code belongs to the low-frequency electromagnetic wave band and is easily affected by electromagnetic interference, while the frequency of the carrier signal belongs to the ultra-high-frequency electromagnetic wave band, and its propagation mode is in the form of direct wave, which is conducive to the signal penetrating the ionosphere and buildings and reducing noise interference. The navigation receiver can also use the basic measurement value of the carrier phase for precise positioning.

[0151] Ranging code.

[0152] The ranging codes of the Beidou B1I and BI2 signals are a kind of pseudo-random code. A pseudo-random code is a binary sequence that seemingly appears as a random sequence but actually has periodicity. The principle of the code generator is as Figure 13 shown.

[0153] As Figure 13 shown, the ranging code is generated by two 11-stage linear shift registers inside each satellite to generate G1 and G2 sequences, and the Gold code generated by the G1 linear sequence and the G2 linear sequence is truncated by 1 chip. The initial code phases of the two shift register sequences are 01010101010. The characteristic polynomials of the G1 and G2 sequences are:

[0154] G1(x) = 1 + x + x 7 + x 8 + x 9 + x 10 + x 11

[0155] G2(x) = 1 + x + x 2 + x 3 + x 4 + x 5 + x 8 + x 9 + x 11

[0156] C B1I code and C B2I code have good autocorrelation and cross-correlation characteristics. The autocorrelation and cross-correlation functions are:

[0157]

[0158] Wherein, a(i) and b(i) respectively represent the i-th chip of the BC B1I and C B2I codes, L p is the number of code elements in one period, and τ is the number of code elements equivalent to the delay time between two sequences. Figure 14 shows the autocorrelation curve of the normalized satellite PRN8.

[0159] From Figure 14 it can be seen that the maximum autocorrelation value of PRN8 is 1, and the correlation values at other times are close to 0. Figure 15 shows the cross-correlation curve of satellites PRN8 and PRN9. The cross-correlation peak value is very small, almost 0. The GNSS receiver can utilize the good autocorrelation and cross-correlation characteristics of the ranging code to capture the target satellite.

[0160] Data code.

[0161] The data code is a binary code carrying navigation messages. The navigation messages of the satellite include important positioning information such as the orbital parameters of the satellite's motion, ionospheric delay, and signal emission time. The data code of the GNSS satellite signal mainly includes D1 navigation message and D2 navigation message.

[0162] Doppler frequency.

[0163] When the receiver receives the navigation signal, due to the relative motion between the receiver and the satellite, the carrier frequency received by the receiver deviates from the carrier frequency transmitted by the satellite. This difference is the Doppler shift. The calculation formula of the Doppler frequency is expressed as:

[0164]

[0165] Wherein, f r is the carrier frequency of the received signal, f c is the satellite signal transmission frequency, and v r is the relative velocity vector between the satellite and the receiver.

[0166] In the case where the receiver is stationary, the Doppler of the received signal is mainly caused by the motion of the satellite. The calculation formula of the satellite Doppler is:

[0167]

[0168] Wherein, f d is the Doppler shift, f r is the signal transmission frequency, v d is the projection velocity of the satellite in the direction of the receiver connection line, and c is the speed of light. The maximum velocity in the projection of the satellite and receiver connection line is:

[0169]

[0170] where \(v\) s is the running speed of the satellite, and \(r\) s is the magnitude of the orbital radius, and \(r\) e is the magnitude of the Earth's radius. According to Equation (2 - 6), the maximum Doppler frequency shift generated by satellite motion when the receiver is stationary is calculated to be 4.83 kHz. Therefore, the Doppler frequency shift caused by satellite motion is approximately within ±5000 Hz. For a receiver in a moving state, the motion of the receiver will also introduce another part of the Doppler frequency shift. Assuming that the maximum speed of the receiver is also 929 m / s, then the motion of the receiver will also generate a Doppler frequency shift with a value between ±5000 Hz.

[0171] (b) GNSS Signal Vulnerability Analysis

[0172] Due to the inherent and intrinsic disadvantages of GNSS satellite signals, they have certain vulnerabilities. Spoofing interference precisely utilizes the vulnerabilities of GNSS signals to interfere with the receiver. The signal vulnerabilities will be analyzed from three aspects below.

[0173] Openness of the signal structure.

[0174] The structure and modulation method of GNSS signals are almost all open except for military codes. Due to this openness, people can freely copy the pseudo - codes of each satellite according to the generation mechanism of the pseudo - codes. At the same time, the structure of each sub - frame of the navigation message is also open. Such characteristics provide convenience for people to obtain real - time ephemeris and generate simulated navigation messages, creating conditions for the interference and spoofing of GNSS signals.

[0175] Extremely low signal strength.

[0176] The orbits of GNSS satellites are extremely high. High - orbit satellites are 30000 km away from the Earth. In this case, when the satellite signal is transmitted through the atmosphere to the Earth's surface, its strength has become very weak and the signal power is extremely low. The strength of the GNSS satellite signal reaching the Earth's surface is only - 160 dBW. Compared with the received signal power of mobile communication, the receiver power of satellite navigation signals is 1 million to 10 million times lower. Therefore, it is very easy to be interfered accordingly.

[0177] Vulnerability of signal processing.

[0178] Since the power of satellite signals received on the Earth's surface is extremely low, and at the same time to ensure that the amplitude of the output signal of the receiver remains constant or varies within a small range. The navigation receiver generally adopts automatic gain control (AGC) technology at the RF front end, which can automatically adjust the power of the input satellite signals. This creates conditions for spoofing signals with relatively high power, enabling the spoofing signals to be properly down-converted by the receiver and then subjected to subsequent acquisition, tracking, and positioning. Therefore, when the signal processing process of the receiver is well-known, the spoofing interferer can forge spoofing signals similar to the real signals, causing the user to obtain incorrect positioning results without any awareness.

[0179] (202) Spoofing interference analysis.

[0180] The man-made interferences suffered by satellite navigation systems are mainly divided into two types: jamming and spoofing signals. Jamming covers useful signals through similar noise or directly using noise, making the receiver unable to work. Its working mode mainly occupies power, and the intensity of the emitted interference signal is much greater than the signal intensity of normal satellites reaching the ground, so that the receiver cannot obtain GNSS signals at all and thus loses the positioning ability. Because the interference signal has a large power, it is easy to be detected during implementation, and the space for jamming to play is thus getting smaller and smaller. Different from jamming, spoofing signals are more threatening because the target receiver simply cannot be aware of this kind of interference. Spoofing signals deliberately create false or disguised real satellite signals, thus inducing the other party to wrongly understand and use the obtained navigation information for positioning to achieve the purpose of spoofing. Spoofing signals usually have the following characteristics:

[0181] (1) In order for the spoofing interferer to enable the target receiver to track the spoofing signal, the power of the emitted signal usually has a large dynamic range. During the implementation of the interference, the transmitted power will gradually increase to make the target receiver lock onto the spoofing signal.

[0182] (2) The spoofing signal has the same or similar signal format as the real signal.

[0183] (3) Due to the Doppler frequency shift, the spoofing signal and the real signal cannot be of the same frequency, and there will be a certain frequency difference between them. For the effectiveness of the interference implementation, the code phase deviation between the real signal and the spoofing signal usually will not be particularly large.

[0184] (a) Generative spoofing.

[0185] Generative spoofing interference generates false positioning results by simulating the real signals of satellites and fabricating false navigation information for the target receiver. Generative spoofing interference, on the premise of knowing the signal code structure, independently emits navigation signals similar to the real satellite signals. The generative spoofing interferer consists of a signal receiving unit, a signal generating unit, and a signal transmitting unit, such asFigure 16 As shown. The signal receiving unit completes the reception and processing of navigation signals, stores the information such as the code phase, Doppler frequency, carrier phase, tropospheric ionospheric delay, and navigation message of the received satellites that have been calculated, and inputs it into the signal generating unit. The signal generating unit, based on the parameter information of each satellite received and knowing the signal structure according to its spoofing requirements, adds the parameter adjustment amount to the generated spoofing signal, and finally the transmitting unit transmits it to the target receiver.

[0186] The spoofing signals generated by the generative spoofing jammer correspond one-to-one with satellite signals. Therefore, for different satellites, the generative spoofing jammer can simulate and generate the signals of each satellite through a single generating device and transmit them. Because it is single-generation, the delay for each satellite can be different. At the same time, it can be seen from the positioning equation that the generative spoofing jammer can spoof the target receiver to any required position. To constitute a generative spoofing threat, it is first necessary to fully understand the satellite navigation message structure, pseudocode structure, and signal generation method, which results in great limitations for generative spoofing jamming:

[0187] (1) It is only applicable to civilian devices using pseudocode as the ranging code because the pseudocode structure is public.

[0188] (2) Due to the confidentiality of military codes, it cannot pose a threat to military navigation equipment without knowing the military code structure.

[0189] Due to the special spoofing mechanism, the generative spoofing jammer requires more hardware devices during implementation, and poses higher requirements for signal processing, and the cost of the jammer will also increase a lot. Although the generative spoofing jammer can induce users to any specified position, the premise is that it needs to be able to crack the navigation signal structure, which has great limitations for encrypted military equipment and low feasibility.

[0190] (b) Analysis of the generative spoofing principle.

[0191] The basic principle of generative spoofing is to detect the position and speed information of the target carrier through monitoring methods such as radar, design a spoofing strategy to make the GNSS receiver capture the spoofing signal, and calculate the wrong position and speed, and gradually induce the carrier to deviate from the predetermined trajectory with a small positioning offset. Position spoofing is based on the spoofing position set in the spoofing strategy, and changes the pseudorange information required for position calculation by the method of delaying and forwarding the satellite signal. Therefore, at time t k the spoofing and the true pseudorange for satellite j have the following relationship:

[0192]

[0193] where Δρ j is the additional pseudorange of the spoofing pseudorange based on the true pseudorange, and velocity spoofing is to achieve the spoofing purpose by adjusting the Doppler frequency required for velocity calculation according to the spoofing velocity set in the spoofing strategy. The general calculation method of the pseudorange rate is

[0194]

[0195] where are the wavelength and Doppler shift of satellite signal j respectively. Then the spoofing pseudorange rate k at time t for satellite signal j and the true pseudorange rate are related as

[0196]

[0197] where is the adjusted Doppler frequency for satellite signal j.

[0198] (c) Repeater spoofing.

[0199] Different from the generative spoofing jamming, the repeater spoofing jamming makes the target receiver capture and track the spoofing signal by delaying and forwarding the real satellite signal, thus obtaining an incorrect positioning result. The repeater spoofing jamming does not require too much power compared with the suppression jamming, and has good concealment performance and is not easy to be detected. At the same time, compared with the generative spoofing jamming, it does not need to know the specific structure of the satellite navigation signal. Especially in the aspect of spoofing jamming against military navigation receivers, the repeater spoofing jamming has higher feasibility. Its core is to control the delay and power of the forwarded signal, so that the target receiver uses the forwarded signal for positioning and calculates incorrect coordinates, thus achieving the purpose of spoofing jamming.

[0200] The repeater spoofing jamming device usually consists of a receiving antenna part, a delay module, an amplifier module, and a transmitting antenna part, as Figure 17 shown.

[0201] The jamming source device first receives the real satellite signal through the receiving antenna part. In order to ensure receiving satellite signals from all directions, omnidirectional antennas are usually selected. According to its own spoofing requirements, the received real signal is delayed by the delay module, and then the required power amplification factor is obtained through the power amplifier, and finally it is transmitted to the target receiver through the antenna. The purpose of using the power amplifier is, on the one hand, that the signal processing process in the early stage will be attenuated; on the other hand, it is to enable the target receiver to better capture and track the spoofing signal.

[0202] The hardware cost required for repeat-back spoofing jamming is low, the jamming range of the jammer is large and it is easy to implement. Although repeat-back spoofing jamming cannot use the signal delay to spoof the user coordinates to any given position, in fields with high requirements for navigation positioning and timing, such as ships, missiles, and aircraft at sea, even inaccurate repeat-back spoofing jamming will still cause fatal harm to our civilian and military equipment. Therefore, repeat-back spoofing jamming has important research significance.

[0203] (d) Analysis of the principle of repeat-back spoofing.

[0204] The repeat-back jammer receives the normal navigation signal transmitted by the satellite, amplifies it after a certain delay and then transmits it through the antenna, so that the target receiver within a certain area receives the spoofing signal forwarded by the jammer.

[0205] Analyze the interference principle of the repeat-back spoofing signal to provide a theoretical basis for subsequent interference detection. The interference principle is as Figure 18 shown.

[0206] Figure 18 Parameter description in i : A: Position of the target receiver; A1: Position of the receiver after being spoofed; S

[0207] When the target receiver is not affected by spoofing jamming, assume that the coordinates of point A are The receiver clock error is t u , and pseudo-range measurements are performed on four satellites to obtain the following equations:

[0208] ρ i =||S i -A||+ct u (8)

[0209] In the formula, S i are four different satellites, ρ i is the pseudo-range value from each satellite to the target receiver, A is the target receiver coordinate, c is the speed of light, and the positioning equation of point A is obtained according to the pseudo-range measurement equation:

[0210]

[0211] It can also be written as:

[0212]

[0213] x i 、y i 、z i are the three-dimensional coordinates of the i-th satellite, and their coordinate values can be calculated using the navigation message in the received signal. The pseudo-range ip can be measured by the receiver. For the receiver clock error t uand the three coordinate components of the receiver position

[0214] x A 、y A 、z A can be solved by a system of simultaneous equations. By solving the equations, the positioning information of the navigation receiver can be obtained, which is the basic principle of pseudorange positioning.

[0215] When the target receiver is subjected to repeater spoofing interference, the receiver is within the effective interference range of the jammer. At this time, the satellite signals received by the receiver are no longer direct signals, but spoofing signals forwarded by the jammer.

[0216] Assume that the transmission delay of the jammer's receiving antenna and transmitting antenna is t1, the path delay from the transmitting antenna to the receiver is t2, and the artificial delay added by the jammer is t3. At this time, for the target receiver A, the positioning expression becomes:

[0217]

[0218] Assume that the forwarding delay of each satellite is the same, t u -t1 - t2 - t3 = t x The above equation can also be written as:

[0219]

[0220] Comparing the positioning equations (9) and (11), the spoofed target receiver is very likely to locate the coordinates to the point and obtain incorrect navigation positioning information.

[0221] The repeater jammer receives the real signal transmitted by the satellite, delays and amplifies it, and then transmits it, so that the target receiver within the effective interference area receives the forwarded signal. Since the power of the spoofing signal is usually higher than that of the normal navigation signal, it is entirely possible for the target receiver to capture the spoofing signal when capturing the signal. The spoofing signal adds delay to the normal navigation signal, thus changing the pseudorange measurement value of the target receiver and giving an incorrect navigation positioning result, achieving the spoofing purpose.

[0222] (203) Design of spoofing interference detection scheme.

[0223] Through the research on the GNSS signal structure, vulnerability, and the principle of GNSS signal repeater spoofing interference, the overall spoofing interference detection scheme of this paper is proposed. Most of the existing receiver spoofing interference detection methods use inertial navigation assistance technology and multi-antenna technology, which require a lot of hardware resources and high costs. To reduce the hardware cost of receiver spoofing interference detection and improve the detection performance of the receiver for spoofing signals, the overall spoofing interference detection scheme of this embodiment is designed, and the joint detection scheme is as Figure 19as shown

[0224] For the forwarding spoofing jamming to achieve the spoofing purpose, there will be a certain delay between the spoofing signal and the real navigation signal, and the spoofing signal is forwarded from the normal navigation signal to the target receiver through the jamming device. The Doppler frequency of the spoofing signal received by the receiver will have a certain deviation relative to the normal navigation signal. According to the differences in time delay and Doppler frequency between the spoofing signal and the navigation signal, this embodiment designs a detection scheme for forwarding spoofing jamming based on the signal acquisition and tracking stages of the receiver.

[0225] In the signal acquisition stage, for the spoofing signal with a large forwarding delay, a multi-peak detection algorithm is proposed to detect the jamming by judging the number of acquisition correlation peaks. For the small-time-delay spoofing signal with high detection difficulty, this embodiment focuses on studying the FWHM detection algorithm, using the full width at half maximum of the acquisition correlation peak to detect whether the received signal is spoofed, and at the same time studies the selection of the fitting function to improve its detection accuracy.

[0226] In the signal tracking stage, since the spoofing signal is forwarded from the normal navigation signal to the target receiver through the jammer, the Doppler shift of the spoofing signal often differs from that of the real signal. By monitoring the change of the Doppler shift of the signal, spoofing jamming can be effectively detected. Therefore, the Doppler offset detection algorithm and the Doppler change rate consistency detection algorithm are studied. Through the joint detection in two stages, the spoofing signal is detected before the navigation information is decoded.

[0227] Specifically, the steps of the joint detection in two stages include:

[0228] Step 1: GNSS navigation signal Doppler offset detection algorithm.

[0229] Step 101: Correlation preprocessing.

[0230] (1) Signal filtering: Use a band-pass filter to filter the received GNSS signal (i.e., BDS satellite signal), filter out out-of-band noise and interference, and retain the useful signal in the frequency band of the GNSS signal.

[0231] (2) Down-conversion: Down-convert the received RF signal to intermediate frequency or baseband for subsequent digital signal processing. By mixing with the sine wave generated by the local oscillator, the high-frequency signal is converted into a lower-frequency signal while retaining the Doppler shift information of the signal.

[0232] (3) Sampling: Sample the down-converted signal to convert the analog signal into a digital signal for computer processing. The sampling frequency should satisfy the Nyquist sampling theorem to avoid signal spectrum aliasing.

[0233] Step 102: Detection of Doppler offset based on a Phase-Locked Loop (PLL).

[0234] The PLL is used to track the carrier phase and frequency of the GNSS signal. By adjusting the parameters of the PLL, its output signal is synchronized with the received GNSS signal in terms of phase and frequency. When the PLL reaches a stable state, the output frequency control signal is the estimated value of the Doppler offset.

[0235] The received GNSS signal is input into the PLL. The PLL compares the phase difference between the input signal and the locally generated reference signal through a phase detector, and adjusts the output frequency of the Voltage-Controlled Oscillator (VCO) according to the phase difference, so that the frequency and phase of the local reference signal gradually approach the input signal. When the PLL locks, the output frequency of the VCO is equal to the Doppler offset frequency of the GNSS signal.

[0236] Step 2: GNSS navigation signal Doppler change rate consistency detection algorithm.

[0237] Step 201: Signal acquisition: The receiver is used to acquire multiple navigation signals, which can come from different satellites or different frequency bands of the same satellite.

[0238] Step 202: Doppler frequency shift estimation: For each acquired navigation signal, the relevant Doppler offset detection algorithm is used to estimate its Doppler frequency shift. Multiple estimations are performed at different times to obtain multiple sequences of Doppler frequency shift values.

[0239] Step 203: Doppler change rate calculation: According to the estimated Doppler frequency shift sequence, the Doppler change rate of each signal is calculated by methods such as numerical differentiation. For example, the approximate value of the Doppler change rate can be obtained by dividing the difference in Doppler frequency shift between adjacent times by the time interval.

[0240] Step 204: Consistency detection: The calculated Doppler change rates of each signal are compared. A threshold can be set. If the difference between the Doppler change rates of two or more signals is less than the threshold, it is considered that they are consistent to a certain extent; otherwise, it is considered inconsistent, and interference is considered to exist when they are inconsistent.

[0241] In this embodiment, the research method for selecting the fitting function is as follows:

[0242] (1) Theoretical analysis and model comparison.

[0243] First, conduct a theoretical analysis of common signal peak shape fitting functions, including the Gaussian function, Lorentz function, Voigt function (the convolution of Gaussian and Lorentz), etc. By comparing the mathematical properties (such as symmetry, tail decay rate) and physical meanings (such as robustness to noise, adaptability to peak shape distortion) of these functions, initially screen out candidate functions. For example:

[0244] Gaussian function: Suitable for describing signals with a single peak and good symmetry, but sensitive to the tailing phenomenon.

[0245] Lorentz function: Has a better fitting effect on long-tailed signals, but may overfit near the peak.

[0246] Voigt function: Combines the characteristics of Gaussian and Lorentz, suitable for complex peak shapes (such as mixed noise or multi-component signals), but has a higher computational complexity.

[0247] (2) Simulation experiments and parameter optimization.

[0248] Generate spoofing signals with different forwarding delays and superimpose Gaussian white noise to simulate the actual receiving environment. Optimize the parameters of each candidate function (such as the mean μ and standard deviation σ of the Gaussian function), and compare the FWHM estimation errors at different signal-to-noise ratios (SNR). For example, in a low SNR scenario, the Gaussian function may cause peak width estimation deviation due to noise interference, while the Voigt function can improve robustness by introducing a mixing parameter θ (the ratio of Gaussian to Lorentz).

[0249] (3) Goodness-of-fit test and model selection.

[0250] Use statistical methods to evaluate the fitting effect, such as the chi-square test (χ 2 ), K-S test (Kolmogorov-Smirnov), and information criteria (AIC, BIC). For example:

[0251] Chi-square test: Calculate the sum of squared deviations between the observed values and the fitted values to judge whether the fitted distribution is consistent with the true signal distribution.

[0252] AIC / BIC criterion: Weigh between the goodness-of-fit and the model complexity, and select the function with the smallest AIC / BIC value. For example, although the Voigt function has more parameters (higher complexity), it may obtain a lower AIC value in the case of complex peak shapes.

[0253] (4) Validation with actual data and adaptability analysis.

[0254] Use the measured signal data to verify the effectiveness of the fitting function. For example, in the scenario of forwarded spoofing signals, the superposition of the real signal and the spoofing signal may cause the correlation peak to broaden. By comparing the fitting results of different functions, select the function that is most sensitive to the time delay change.

[0255] (5) Algorithm optimization and experimental results.

[0256] 1) Parameter initialization strategy.

[0257] To improve the fitting efficiency, a heuristic initialization method is adopted, for example:

[0258] Peak position: Determine the approximate position of the relevant peak through rough search.

[0259] Peak width estimation: Use a sliding window to calculate the local variance of the signal and initially estimate σ or γ.

[0260] 2) Multi-function hybrid model.

[0261] In complex scenarios, the superposition of multiple Gaussian or Lorentz functions (such as the Gaussian mixture model GMM) may be adopted to capture the characteristics of multi-component signals.

[0262] 3) Experimental verification.

[0263] Through the comparison of simulation and measured data, it is found that:

[0264] Gaussian function: It has high estimation accuracy at high SNR, but is sensitive to time delay changes.

[0265] Voigt function: It performs better under low SNR or complex peak shapes, and the FWHM estimation error is reduced by about 30%.

[0266] Multi-peak fitting: Select the optimal model through the AIC / BIC criterion, and the detection sensitivity is increased by 20%-40%.

[0267] The research on the selection of fitting functions combines theoretical analysis, simulation verification and actual data testing. By comparing the mathematical characteristics, statistical tests and model selection criteria of different functions, the optimal fitting model is finally determined. The Gaussian function becomes the basic choice due to its simple calculation and high accuracy at high SNR, while the Voigt function or hybrid model is used for complex scenarios. This research provides a theoretical basis and practical guidance for improving the robustness and accuracy of the FWHM detection algorithm.

[0268] Embodiment 2

[0269] This embodiment provides a satellite timing method against spoofing and jamming.

[0270] A satellite timing method against spoofing and jamming provided by this embodiment adopts a satellite timing system against spoofing and jamming as described in Embodiment 1, including:

[0271] Each GNSS RF module in the GNSS RF board receives a BDS satellite signal;

[0272] The dual BDS signal spoofing interference recognition module integrated in the satellite receiving board performs interference detection on one BDS satellite signal respectively through the GNSS signal suppression interference detection method and the GNSS signal spoofing interference detection method to obtain the satellite signal interference state;

[0273] The CPU reads the serial port message data of the two satellite signal spoofing interference recognition modules and parses out the UTC time; at the same time, according to the satellite signal interference state, it determines the RF switch command;

[0274] The FPGA controls the two GNSS RF modules to output or reject the BDS satellite signal according to the RF switch command.

[0275] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A satellite time service system for anti-deception and suppression jamming, characterized in that Including: A satellite receiving board, a CPU, an FPGA, and a GNSS RF board connected in sequence, and the GNSS RF board is also connected to the satellite receiving board; A dual GNSS RF module is integrated in the GNSS RF board, and each GNSS RF module is responsible for receiving one path of BDS satellite signals; A dual BDS signal spoofing interference recognition module is integrated in the satellite receiving board, and each BDS signal spoofing interference recognition module is configured with a GNSS signal suppression interference detection method and a GNSS signal spoofing interference detection method to perform interference detection on one path of BDS satellite signals to obtain the satellite signal interference status; The CPU is used to read the serial port message data for the two satellite signal spoofing interference recognition modules and parse out the UTC time; at the same time, according to the satellite signal interference status, determine the RF switch command; The FPGA is used to control the two GNSS RF modules to output or reject BDS satellite signals according to the RF switch command.

2. The satellite time service system for anti-deception and suppression interference according to claim 1, characterized in that It also includes a crystal oscillator; The FPGA and the crystal oscillator jointly establish a counter with accurate 64-bit second counting and 27-bit nanosecond counting to timestamp the PPS of each input time.

3. The satellite time service system for anti-deception and suppression interference according to claim 1, characterized in that, The RF board has two RF input interfaces and four RF output interfaces. Each RF input interface is connected to a BDS antenna feeder. The two RF output interfaces are correspondingly output to the satellite receiving board, and the two RF output interfaces are used as BDS satellite signal outputs.

4. A satellite timekeeping system for anti-deception and suppression jamming, as claimed in claim 1, wherein The CPU sends out the expected second interval count value, and the FPGA judges the arrival to generate the LC_PPS time pulse.

5. The satellite time service system for anti-deception and suppression interference according to claim 1, characterized in that, The message includes the satellite signal interference status, positioning time, latitude, and longitude information.

6. The satellite time service system for anti-deception and suppression interference according to claim 1, characterized in that, The GNSS signal suppression interference detection method is: monitor the output related value of the AGC in the GNSS RF board and compare it with the interference detection threshold. If the output related value of the AGC is greater than or equal to the interference detection threshold, it is judged that there is interference.

7. The satellite time service system for anti-deception and suppression interference according to claim 6, characterized in that, The interference detection threshold is set by measuring the distance between the interference transmitter and the GNSS RF board and the change of the output related value of the AGC.

8. The satellite time service system for anti-deception and suppression interference according to claim 1, characterized in that The GNSS signal spoofing interference detection method is: for the BDS satellite signal, use the Doppler offset detection algorithm to estimate the Doppler frequency shift, make multiple estimations at different times to obtain multiple Doppler frequency shift sequences; according to the estimated Doppler frequency shift sequences, calculate the Doppler change rate of each BDS satellite signal; Compare the calculated Doppler change rates of each BDS satellite signal; if the difference between the Doppler change rates is less than the threshold, it is considered consistent.

9. The satellite time service system for anti-deception and suppression interference according to claim 8, characterized in that, The steps of the Doppler offset detection algorithm include: Use a phase-locked loop to track the carrier phase and frequency of the BDS satellite signal. By adjusting the parameters of the phase-locked loop, make its output signal reach phase and frequency synchronization with the received BDS satellite signal. When the phase-locked loop reaches a stable state, the output frequency control signal is the estimated value of the Doppler offset; The received BDS satellite signal is input into a phase-locked loop (PLL). The PLL compares the phase difference between the input signal and the locally generated reference signal through a phase detector, and adjusts the output frequency of the voltage-controlled oscillator according to the phase difference, so that the frequency and phase of the local reference signal gradually approach the input signal. When the PLL is locked, the output frequency of the voltage-controlled oscillator is equal to the Doppler shift frequency of the BDS satellite signal.

10. A satellite timekeeping method for anti-deception and suppression interference, characterized in that, Adopt a satellite time synchronization system for anti-spoofing and jamming suppression as described in any one of claims 1-9, including: Each GNSS RF module in the GNSS RF board receives a BDS satellite signal. The dual BDS signal spoofing interference identification module integrated in the satellite receiving board performs interference detection on a BDS satellite signal respectively through the GNSS signal jamming suppression detection method and the GNSS signal spoofing interference detection method to obtain the satellite signal interference state. The CPU reads the serial port message data of the two satellite signal spoofing interference identification modules and parses out the UTC time. At the same time, according to the satellite signal interference state, it determines the RF switch command. The FPGA controls the two GNSS RF modules to output or reject the BDS satellite signal according to the RF switch command.

Citation Information

Cited By

  • Power system time synchronization protection method, device and equipment, and storage medium

    CN121187101A

  • A method and system for detecting anti-interference of a power grid edge device beidou timing

    CN122525592A