Method for navigating a vehicle by tracking GNSS signals with spoofing detection

The method uses a GNSS receiver with multiple channels to verify GNSS signals by comparing pseudo random noise codes and physical properties, effectively detecting and mitigating spoofing attacks in autonomous driving systems, ensuring reliable navigation.

WO2025195730A1PCT designated stage Publication Date: 2025-09-25ROBERT BOSCH GMBH

Patent Information

Application Number
PCT/EP2025/055091
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-22
Filing Date
2025-02-26
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

GNSS signals can be easily falsified using inexpensive hardware and software, posing a significant threat to the security and integrity of autonomous driving systems, necessitating effective spoofing detection methods.

Method used

A method for navigating vehicles using a GNSS receiver with multiple channels to track and verify GNSS signals by comparing pseudo random noise codes and physical properties, such as receive power and Doppler frequency, to distinguish between authentic and spoofed signals.

Benefits of technology

This method effectively detects and mitigates GNSS spoofing attacks without hardware changes, ensuring reliable navigation by identifying and isolating spoofed signals, thus protecting autonomous vehicles from manipulation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025055091_25092025_PF_FP_ABST
    Figure EP2025055091_25092025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for navigating a vehicle (6) by tracking GNSS signals with spoofing detection by means of a GNSS receiver having a plurality of channels, wherein a first GNSS signal is tracked on a first channel and then checked for plausibility on a second channel, comprising the following steps: a) searching for a second GNSS signal which should contain the identical pseudo random noise code as the first GNSS signal, b) checking the plausibility of the first GNSS signal as an authentic GNSS signal if no second GNSS signal has been found, or carrying out the following sub-steps if a second GNSS signal has been found: i) comparing the first and the second GNSS signal with one another, and ii) checking the plausibility of the first or the second GNSS signal as the authentic GNSS signal on the basis of the comparison result.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] title

[0003] Method for navigating a vehicle by tracking GNSS signals with spoofing detection

[0004] State of the art

[0005] The present invention relates to a method for navigating a vehicle by tracking GNSS signals with spoofing detection using a GNSS receiver with a plurality of channels. Furthermore, a control unit, a computer program, a machine-readable storage medium, and a localization system for a vehicle are specified. The invention can be applied in particular to GNSS- and INS-supported localization systems for autonomous or semi-autonomous driving.

[0006] A global navigation satellite system (GNSS) is a system for determining position and navigating on Earth and in the air by receiving GNSS signals. A positioning system with a GNSS receiver allows an object equipped with the positioning system to be positioned and navigated.

[0007] Today, however, GNSS signals can be easily falsified using inexpensive hardware and software, such as open source software, so that an object to be navigated can be manipulated using the falsified GNSS signals. This is known as GNSS spoofing and is particularly important for autonomous driving. Autonomous driving places particularly high demands on security and integrity (or the correctness of the position information, e.g., the correctness of the accuracy specification) in addition to position accuracy. The security of GNSS-based positioning is particularly relevant in the context of safety-critical automated driving functions in order to protect the positioning from manipulation by falsified GNSS signals. Detection of GNSS spoofing is therefore considered necessary, especially for autonomous driving.

[0008] The present invention offers new possibilities for detecting and defending against the above-mentioned GNSS spoofing attack and thus for detecting an unsafe state in the context of automated driving.

[0009] Disclosure of the invention

[0010] A method for navigating a vehicle by tracking GNSS signals with spoofing detection by means of a GNSS receiver with a plurality of channels contributes to this, wherein a first GNSS signal is tracked on a first channel and then plausibility checked on a second channel with the following steps: a) searching for a second GNSS signal which should contain the identical pseudo random noise code as the first GNSS signal, b) plausibility checking of the first GNSS signal as an authentic GNSS signal if no second GNSS signal was found, or carrying out the following sub-steps if a second GNSS signal was found: i) comparing the first and the second GNSS signal with each other, and ii) plausibility checking of the first or the second GNSS signal as the authentic GNSS signal based on the comparison result.

[0011] The described method is particularly suitable for autonomous driving. Autonomous driving is understood here, in particular, to mean the movement of vehicles that behave largely autonomously using a GNSS receiver and based on global navigation satellite systems (GNSS). The vehicles can be a motor vehicle, for example a passenger car, a truck or other commercial vehicle, a robot, or the like. It is particularly advantageous if a self-driving motor vehicle is equipped with a localization system, in particular a GNSS- and INS-supported localization system, for implementing the described method.

[0012] GNSS is the abbreviation for Global Navigation Satellite Systems, including GPS, GLONASS, Galileo, and Beidou. A GNSS system comprises a multitude of GNSS satellites distributed across the sky. A GNSS signal, in this context, refers specifically to the signal emitted by a GNSS satellite. By tracking at least four GNSS satellites of the same GNSS system, it is possible to position and navigate a vehicle in three dimensions.

[0013] A GNSS receiver can track GNSS satellites by receiving and tracking the GNSS signals broadcast by the corresponding GNSS satellites to decode navigation data from the tracked GNSS signals and calculate a navigation solution based on the decoded navigation data.

[0014] In the GNSS receiver, each received GNSS signal can be tracked on a single channel. A GNSS receiver typically has a large number of channels, e.g., eight, twelve, or more. A channel here is specifically a GNSS signal processing unit configured to determine the information contained in a GNSS signal, such as the pseudorandom noise code and the navigation message.

[0015] GNSS spoofing refers specifically to the transmission of deliberately manipulated GNSS signals in order to manipulate the navigation solutions calculated in a GNSS receiver, such as time and position. A GNSS spoofing signal is a simulated deceptive signal based on an authentic GNSS signal, whose identity is concealed by a deceptive method. The evaluation of the GNSS spoofing signal thus yields a false positioning. An authentic GNSS signal is therefore understood here to be the signal actually transmitted by a GNSS satellite.

[0016] To detect a spoofing attack, the pseudo random noise code of a targeted GNSS signal is used in particular, as the pseudo random noise code uniquely identifies the GNSS satellite that transmitted the GNSS signal containing this pseudo random noise code. Furthermore, a spoofing attack uses a spoofer, which typically transmits a GNSS spoofing signal that is similar to an authentic GNSS signal but is manipulated. This means that the GNSS spoofing signal must also contain the identical pseudo random noise code as the authentic GNSS signal. If a GNSS receiver is located near the spoofer, it typically receives both the authentic GNSS signal and the GNSS spoofing signal, with both signals containing the identical random noise code.On this basis, it is possible to detect a spoofing attack by checking whether (at least) two signals with the identical pseudo random noise code can be acquired by the GNSS receiver at the same time.

[0017] According to the described method, a GNSS signal can first be acquired and tracked in a known manner on one channel, allowing the pseudorandom noise code of this GNSS signal to be detected. To verify whether this GNSS signal is a GNSS spoofing signal, another channel is used according to step a). Based on the pseudorandom noise code of this already tracked GNSS signal, this channel performs a parallel, rough search for a signal that also contains the identical pseudorandom noise code as this already tracked GNSS signal.

[0018] In this context, the first acquired and tracked GNSS signal is referred to as the first GNSS signal, and the GNSS signal to be searched for based on the pseudorandom noise code of the first GNSS signal is referred to as the second GNSS signal. Accordingly, the channel for acquiring and tracking the first GNSS signal is referred to as the first channel, and the channel for searching for the second GNSS signal is referred to as the second channel. In particular, the second channel can be an unoccupied channel or a channel that is not necessarily used for tracking other GNSS signals (e.g., the other GNSS signals are of poor quality and not worth tracking).

[0019] The search for the second GNSS signal on the second channel can be carried out, for example, using correlator accumulations. In the event of a spoofing attack, the GNSS signal in question is typically detected twice during the acquisition phase by forming two correlation peaks in the so-called correlator accumulations. The correlator accumulations provide the correlation value between the received GNSS signal and the PRN code as a function of the code delay (i.e., the signal propagation time) and the Doppler frequency of the received GNSS signal. One of the two peaks represents the authentic signal, while the other peak represents the inauthentic and thus the GNSS spoofing signal. The presence of at least two significant peaks in the correlator accumulations is therefore an indication of a spoofing attack. A significant peak is a correlation value that is clearly different from the noise (e.g.,by a factor of 20) and is visible for a longer period of time (e.g. more than 5 seconds).

[0020] If fewer than two peaks are formed in the correlator accumulations, this means that no second GNSS signal was detected. In this case, the first GNSS signal is validated as an authentic GNSS signal according to step b), so that the first GNSS signal can be further tracked on the first channel to decode navigation data from the first GNSS signal, which is used to calculate navigation solutions.

[0021] If at least two peaks occur in the correlator accumulations, this indicates a possible spoofing attack. In this case, the first and second GNSS signals can be compared according to substep i), and an authentic GNSS signal can be identified from the two signals based on the comparison result according to substep ii).

[0022] The comparison between the first and the second GNSS signal can exploit at least two typical phenomena of GNSS spoofing.

[0023] First, in order for the spoofer to "catch" the GNSS receiver, the GNSS spoofing signal can be stronger than the authentic GNSS signal, i.e., the GNSS spoofing signal can be received with a higher signal power. Based on this, the first and second GNSS signals can be compared in terms of received power according to sub-step i). This has the advantage that a possible spoofing attack can be quickly detected and appropriate security measures can be taken, especially if an atypical received power is present at the receiving antenna.

[0024] Second, GNSS spoofing signals are usually transmitted from one antenna. Typically, spoofers use a common antenna for all spoofing signals to generate GNSS spoofing signals. In contrast, authentic GNSS signals are transmitted from GNSS satellites in the sky. Therefore, an authentic GNSS signal and a GNSS spoofing signal that imitates this authentic GNSS signal are received at different Doppler frequencies. On this basis, in sub-step i), the first and second GNSS signals can be compared with regard to the Doppler change. For this purpose, the measured

[0025] The Doppler change of the first and second GNSS signals is compared with a Doppler change estimated based on the vehicle movement data and the satellite movement data. Thus, according to substep ii), the authentic GNSS signal whose measured Doppler change is closest to the estimated Doppler change can be selected. This has the advantage of achieving more reliable plausibility checks.

[0026] As described above, the method proposed here offers new possibilities for spoofing detection based on the pseudo random noise codes of GNSS signals and using currently unoccupied channels of a GNSS receiver to search in parallel for signals with identical pseudo random noise codes as the GNSS signals already tracked, whereby a spoofing attack can be detected if at least two signals with identical pseudo random noise codes have been found.

[0027] The described method also makes it possible to select authentic GNSS signals from spoofed GNSS signals based on the different physical properties between the authentic and spoofed GNSS signals, such as receive power and / or Doppler frequency. This allows the vehicle to navigate without interference despite a spoofing attack. In particular, the described method can be implemented with existing GNSS receivers without any hardware changes. Only a software update is required. The described method thus offers cost-effective yet effective protection against GNSS spoofing.

[0028] It is preferred if, in step a), a second GNSS signal is searched for in such a way that the pseudo random noise code of the first GNSS signal is correlated with a signal arriving on the second channel to form correlation values, wherein a second GNSS signal is found if the correlation values ​​have at least two correlation peaks.

[0029] The pseudo random noise code can be correlated with the incoming signal depending on the code delay (i.e. the signal propagation time) and the Doppler frequency of the incoming signal.

[0030] A significant correlation peak is a correlation value that differs significantly from the noise (e.g., by a factor of 20) and is visible over a longer period of time (e.g., more than 5 seconds). To increase robustness against noise, the correlations can be averaged over time (e.g., over 10 calculations). Suspicion of spoofing can be confirmed if, for example, at least two significant peaks are observed in the correlator accumulations for several (e.g., more than 5) GN SS signals (or PRN codes).

[0031] It is preferred if, in step a), the second GNSS signal is additionally searched for taking into account the reception power.

[0032] Automatic gain control can be used for this purpose, which typically provides an estimate of the received power at the GNSS receiver's antenna. If the GNSS receiver is located in close proximity to a spoofer, the received power is increased compared to typical reception conditions. This means that, in addition to the otherwise dominant thermal noise and the authentic GNSS signals, an additional signal is received in the sensitive frequency range.

[0033] The received power of the GNSS signals is typically below the thermal noise. Thermal noise is temperature-dependent and delivers a received power of -174 dBm / Hz at 20 °C, or -111 dBm at the typical GPS signal bandwidth of 2 MHz. If the received power is significantly higher than this value (e.g., more than 10 dB higher, resulting in an atypically high received power at the receiving antenna), and if, in this case, a good signal-to-noise ratio of the decoded signal is nevertheless determined in the GNSS receiver (e.g., C / NO greater than 35 dB / Hz), this is also an indication of a spoofing attack.

[0034] It is preferred if, in sub-step i), the correlation peak of the first GNSS signal is compared with the correlation peak of the second GNSS signal, and wherein, in sub-step ii), the first GNSS signal is verified as the authentic GNSS signal if the correlation peak of the first GNSS signal is smaller than the correlation peak of the second GNSS signal, or the second GNSS signal is verified as the authentic GNSS signal if the correlation peak of the first GNSS signal is larger than the correlation peak of the second GNSS signal, if the case of an atypically high reception power at the reception antenna exists.

[0035] It is preferred if, in sub-step i), the first and second GNSS signals are compared with each other with regard to the Doppler change, comprising the following sub-steps:

[0036] 1) Estimating a Doppler change using at least vehicle movement data in a journal,

[0037] 2) Measuring the Doppler change of the first and second GNSS signals,

[0038] 3) comparing the estimated Doppler change with the measured Doppler change of the first and second GNSS signals, and

[0039] 4) Determining a first deviation between the estimated and the measured Doppler change of the first GNSS signal and a second deviation between the estimated and the measured Doppler change of the second GNSS signal.

[0040] It is also preferred if, in sub-step 2), the Doppler change is measured using a code-based and / or a phase-based tracking loop. The measured Doppler change of the first GNSS signal can be obtained by tracking the first GNSS signal on the first channel using a delay-lock loop (DLL) and / or a phase-lock loop (PLL). Similarly, the measured Doppler change of the second GNSS signal can be obtained by tracking the second GNSS signal on the second channel using a delay-lock loop and / or a phase-lock loop.

[0041] When tracking the first and second GNSS signals, the ephemeris data are decoded and the corresponding elevation angles el sv and azimuth angle cr sl / to the GNSS satellite identified using the pseudo random noise code of the first and second GNSS signals.

[0042] The estimated Doppler change Pred&D can be calculated using the following formulas:

[0043] When the vehicle speed changes

[0044] When the vehicle changes direction

[0045] When the vehicle changes speed and direction

[0046] Where V^ represents the speed of the vehicle movement and aheading, 2 the heading of the vehicle movement at the observation time b and V1 the speed of the vehicle movement and aheading, 1 the heading of the vehicle movement at the observation time ti. Here, federates the observation time after the speed and / or

[0047] Change of direction, and ti the observation time before the change in speed and / or direction. Here, fo denotes the carrier frequency of GNSS signals (e.g., 1575.42 MHz for GPS L1) and Co denotes the speed of light. The speed and heading can be determined using vehicle sensors. The change in elevation angle and azimuth angle can be neglected compared to the change in speed and the change in direction of the vehicle.

[0048] It is preferred if, in sub-step ii), the first GNSS signal is verified as the authentic GNSS signal if the first deviation is smaller than the second deviation, or the second GNSS signal is verified as the authentic GNSS signal if the first deviation is greater than the second deviation.

[0049] It is preferred if the sub-steps 1) to 4) are repeated journal by journal, so that the first deviations determined over time in sub-step 4) are accumulated to a first accumulated deviation and the second deviations determined over time in sub-step 4) are accumulated to a second accumulated deviation, so that a first probability that the first GNSS signal is the authentic GNSS signal and / or a second probability that the second GNSS signal is the authentic GNSS signal is determined based on the first and the second accumulated deviation.

[0050] It is preferred if, in sub-step ii), the first or the second GNSS signal is verified as the authentic GNSS signal based on the determined first and / or second probability.

[0051] The comparison of the measured Doppler change with the estimated Doppler change can be performed using a specific journal. The following formulas can be used for this purpose

[0052] Ei (n) is the nth error term for the i-th tracked GNSS signal with the identical pseudorandom noise code for the n-th plausibility check or for the n-th observation time step. PredäDi(n) is the estimated Doppler change and MüDi(n) is the measured Doppler change for the i-th tracked GNSS signal with the identical pseudorandom noise code associated with the n-th observation time step or the n-th plausibility check, respectively. The error terms Ei (n) and E2 (n) are summed to EACCI = En F(n) and FACCZ = Zn Fi(n), respectively. The probability that the i-th tracked signal is a GNSS spoofing signal can then be estimated as follows: P s / g / .spoofed = EACCI / El EACCI

[0053] The traced signal for which the lowest spoofing probability is determined can be considered an authentic signal. The probability that the i-th traced signal is an authentic signal can be equivalently estimated using the following formula:

[0054] P sigi. authentic = El EACCI - EACCI / El EACCI

[0055] In one variant, plausibility checks can be used to determine the probability until the signal assumed to be authentic falls below a desired spoofing probability. In another variant, the channels can be re-enabled for tracking signals classified as spoofing, for example, as soon as the signal assumed to be authentic falls below a certain spoofing probability.

[0056] In the case where more than two signals with the identical pseudorandom noise code are tracked (i.e., the GNSS receiver is affected by multiple spoofers in this case), an alternative calculation of the spoofing probability of a tracked GNSS signal can be used, where the probability is normalized to the presence of only two tracked signals with the identical pseudorandom noise code. With this normalization, a probability of 50% is output for the case where all tracked signals with the identical pseudorandom noise code are equally likely. The normalized probability for a GNSS spoofing signal can be calculated using the following formula:

[0057] P sigi.spoofed_norm = P sigi.spoofed_ * 2

[0058] Here, L represents the number of traced signals. Analogously, the probability of an authentic signal can be calculated as follows: P sigi.authentic_norm = P sigi.authentic_ * L / 2 (L- 1)

[0059] It is preferred if the vehicle movement data

[0060] Changes in speed and / or direction are preferred. It is preferred if the vehicle movement data is determined using vehicle sensors. The vehicle sensors are located in the vehicle to be navigated.

[0061] It is preferred if a control device is configured to carry out the described method.

[0062] It is also preferred if a computer program is used to carry out a method described here. In other words, this particularly relates to a computer program (product) comprising instructions that, when executed by a computer, cause the computer to carry out a method described here.

[0063] It is also preferred if a machine-readable storage medium is used on which the computer program proposed here is stored. The machine-readable storage medium is usually a computer-readable data carrier.

[0064] It is particularly preferred if the localization system for a vehicle is set up to carry out a method described here.

[0065] The solution presented here and its technical environment are explained in more detail below with reference to the figures. It should be noted that the invention is not intended to be limited by the exemplary embodiments shown. In particular, unless explicitly stated otherwise, it is also possible to extract partial aspects of the facts explained in the figures and combine them with other components and / or findings from other figures and / or the present description. It shows schematically and by way of example:

[0066] Fig. 1 shows a first variant for selecting an authentic signal in a spoofing attack, and

[0067] Fig. 2 shows a second variant for selecting an authentic signal in a spoofing attack. Fig. 1 shows a first variant, and Fig. 2 shows a second variant for selecting an authentic GNSS signal in a spoofing attack. The first and second variants can be implemented independently or in mutual support.

[0068] What both variants have in common is that after tracking a first GNSS signal on a first channel in the background, a second channel is used to acquire the already tracked first GNSS signal in parallel to perform a rough search for a second GNSS signal based on the pseudo random noise code of the first GNSS signal, whereby the second GNSS signal to be searched for should contain the identical pseudo random noise code as the already tracked first GNSS signal. In the case of a spoofing attack, the affected GNSS signal is typically found twice during the acquisition phase. Therefore, if no second GNSS signal is found, the first GNSS signal is the authentic GNSS signal, whereas if a second GNSS signal is found, an authentic signal can be selected between the first and the second GNSS signal according to the variant shown in Fig. 1 and / or Fig. 2.The second channel can, in particular, be a currently freely available channel. It is possible for multiple second channels to be used in parallel for several different, already tracked, first GNSS signals.

[0069] The first variant in Fig. 1 uses correlator accumulation, in which the pseudorandom noise code of the first GNSS signal and the signal arriving on the second channel are correlated to form correlation values ​​1 depending on the code delay 3 and the Doppler frequency 2. This results in two correlation peaks 5 being formed against noise 4 during a spoofing attack. One correlation peak 5 corresponds to the authentic GNSS signal and the other correlation peak 5 to the GNSS spoofing signal. Since the GNSS spoofing signal was typically received with a higher reception power, the authentic GNSS signal with the smaller correlation peak 5 can be selected.

[0070] Alternatively or additionally, the second variant in Fig. 2 for selecting an authentic GNSS signal based on the Doppler change can be performed by comparing the measured Doppler change of the first and the detected second GNSS signal with a Doppler change estimated based on the vehicle movement data and the satellite movement data. Thus, the authentic GNSS signal whose measured Doppler change is closest to the estimated Doppler change can be selected.

[0071] The measured Doppler change of the first and second GNSS signals can be obtained using a delay-lock loop (DLL) and / or a phase-lock loop (PLL).

[0072] The estimated Doppler change Pred^D can be calculated using the following formulas:

[0073] When the vehicle speed changes 6

[0074] When the vehicle changes direction 6

[0075] When the vehicle changes speed and direction 6

[0076] Where V^ represents the speed of the vehicle movement and ahead, 2 the heading 10 of the vehicle movement at the observation time b and V1 the speed of the vehicle movement and ahead, 1 the heading 10 of the vehicle movement at the observation time ti. Here, federates the observation time after the change in speed and / or direction and ti the observation time before the change in speed and / or direction. fo denotes the carrier frequency of GNSS signals (e.g., for GPS L1 1575.42 MHz) and Co denotes the speed of light. The speed and heading 10 can be determined using vehicle sensors and elevation angle el sv 8 and azimuth angle cr sl / 9 can be determined from the decoded ephemeris data of the corresponding GNSS satellite 7.

[0077] The comparison of the measured Doppler change with the estimated Doppler change can be performed using a specific journal. The following formulas can be used for this purpose

[0078] Ei (n) is the nth error term for the i-th tracked GNSS signal with the identical pseudo random noise code for the n-th plausibility check or for the n-th observation time step. PredüDi(n) is the estimated Doppler change and MüDi(n) is the measured Doppler change for the i-th tracked GNSS signal with the identical pseudo random noise code associated with the n-th observation time step or the n-th plausibility check.

[0079] The error terms Ei (n) and E2 (n) are summed to EACCI = En F(n) and FACCZ = Zn Fi(n) respectively. The probability that the i-th tracked signal is a GNSS spoofing signal can then be estimated as follows: P s / g / .spoofed = EACCI / El EACCI

[0080] The traced signal for which the lowest spoofing probability is determined can be considered an authentic signal. The probability that the i-th traced signal is an authentic signal can be equivalently estimated using the following formula:

[0081] P sigi. authentic = El EACCI - EACCI / El EACCI

[0082] In one variant, plausibility checks can be used to determine the probability until the signal assumed to be authentic falls below a desired spoofing probability. In another variant, the channels can be re-enabled for tracking signals classified as spoofing, for example, as soon as the signal assumed to be authentic falls below a certain spoofing probability.

[0083] In the case where more than two signals with the identical pseudorandom noise code are tracked (i.e., the GNSS receiver is affected by multiple spoofers in this case), an alternative calculation of the spoofing probability of a tracked GNSS signal can be used, where the probability is normalized to the presence of only two tracked signals with the identical pseudorandom noise code. With this normalization, a probability of 50% is output for the case where all tracked signals with the identical pseudorandom noise code are equally likely. The normalized probability for a GNSS spoofing signal can be calculated using the following formula:

[0084] P sigi.spoofed_norm = P sigi.spoofed_ * L 2.

[0085] Here, L represents the number of traced signals. Analogously, the probability of an authentic signal can be calculated as follows: P sigi.authentic_norm = P sigi.authentic_ * L / 2 (L- 1).

Claims

Claims 1. Method for navigating a vehicle (6) by tracking GNSS signals with spoofing detection by means of a GNSS receiver with a plurality of channels, wherein a first GNSS signal is tracked on a first channel and then plausibilized on a second channel with the following steps: a) searching for a second GNSS signal which should contain the identical pseudo random noise code as the first GNSS signal, b) plausibilizing the first GNSS signal as an authentic GNSS signal if no second GNSS signal was found, or performing the following sub-steps if a second GNSS signal was found: i) comparing the first and the second GNSS signal with each other, and ii) plausibilizing the first or the second GNSS signal as the authentic GNSS signal based on the comparison result.

2. The method according to claim 1, wherein in step a) a second GNSS signal is searched for in such a way that the pseudo random noise code of the first GNSS signal is correlated with a signal arriving on the second channel to form correlation values ​​(1), wherein a second GNSS signal is found if the correlation values ​​(1) have at least two correlation peaks (5).

3. The method according to claim 2, wherein in step a) the second GNSS signal is searched taking into account the reception power.

4. The method according to claim 3, wherein in sub-step i) the correlation peak (5) of the first GNSS signal is compared with the correlation peak (5) of the second GNSS signal, and wherein in sub-step ii) the first GNSS signal is verified as the authentic GNSS signal if the correlation peak (5) of the first GNSS signal is smaller than the correlation peak (5) of the second GNSS signal, or the second GNSS signal is verified as the authentic GNSS Signal is verified if the correlation peak (5) of the first GNSS signal is greater than the correlation peak (5) of the second GNSS signal.

5. Method according to one of the preceding claims, if in sub-step i) the first and the second GNSS signal are compared with each other with regard to the Doppler change, comprising the following sub-steps: 1) Estimating a Doppler change using at least vehicle movement data in a journal, 2) Measuring the Doppler change of the first and second GNSS signals, 3) comparing the estimated Doppler change with the measured Doppler change of the first and second GNSS signals, and 4) Determining a first deviation between the estimated and the measured Doppler change of the first GNSS signal and a second deviation between the estimated and the measured Doppler change of the second GNSS signal.

6. The method according to claim 5, wherein in sub-step ii) the first GNSS signal is verified as the authentic GNSS signal if the first deviation is smaller than the second deviation, or the second GNSS signal is verified as the authentic GNSS signal if the first deviation is greater than the second deviation.

7. The method according to claim 5, wherein sub-steps 1) to 4) are repeated journal by journal, so that the first deviations determined over time in sub-step 4) are accumulated to a first accumulated deviation and the second deviations determined over time in sub-step 4) are accumulated to a second accumulated deviation, so that a first probability that the first GNSS signal is the authentic GNSS signal and / or a second probability that the second GNSS signal is the authentic GNSS signal is determined based on the first and the second accumulated deviation.

8. The method according to claim 7, wherein in sub-step ii) the first or the second GNSS signal is verified as the authentic GNSS signal based on the determined first and / or second probability.

9. Method according to one of claims 5 to 8, wherein the vehicle movement data are changes in speed and / or changes in direction.

10. Method according to one of claims 5 to 9, wherein the vehicle movement data are determined with the aid of vehicle sensors.

11. Method according to one of claims 5 to 10, wherein in sub-step 2) the Doppler change is measured using a code-based and / or a phase-based tracking loop.

12. Control device which is configured to carry out a method according to one of the preceding claims.

13. Computer program for carrying out a method according to one of the preceding claims 1 to 9.

14. A machine-readable storage medium on which the computer program according to claim 13 is stored.

15. Localization system for a vehicle, configured to carry out a method according to one of claims 1 to 10.

Citation Information

Patent Citations

  • Method for detecting spoofing in a global navigation satellite system receiver, corresponding receiver apparatus and computer program product

    US11640003B2

  • GNSS Spoofing Detection and Mitigation Using Peak Suppression Monitor

    US20220390616A1

Cited By

  • Navigation deception detection method and device based on multiple correlators and variance filtering, equipment and storage medium

    CN121559551A