Method of reporting spoofing / jamming attack in wireless communication system and related wireless communication system
By integrating spoofing and jamming detection with a normalized probability metric in UE reporting, the method addresses the lack of effective attack reporting in wireless communication systems, enhancing system resilience against GNSS threats and improving positioning accuracy.
Patent Information
- Application Number
- PCT/CN2025/126090
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-10-08
- Filing Date
- 2025-09-30
- Publication Date
- 2026-04-16
Smart Images

Figure CN2025126090_16042026_PF_FP_ABST
Abstract
Description
METHOD OF REPORTING SPOOFING / JAMMING ATTACK IN WIRELESS COMMUNICATION SYSTEM AND RELATED WIRELESS COMMUNICATION SYSTEM
[0001] CROSS REFERENCE TO RELATED APPLICATION
[0002] This application claims the benefit of PCT / CN2024 / 123370 filed on 2024 / 10 / 08. The content of the application is incorporated herein by reference.BACKGROUND OF THE INVENTION1. FIELD OF THE INVENTION
[0003] The present invention is related to a method of reporting spoofing / jamming attack in wireless communication system and related wireless communication system, and more particularly, to a method of reporting spoofing / jamming attack in wireless communication system using an extended LPP GNSS error reporting format with an additional error cause and an attack probability metric and related wireless communication system.
[0004] 2. DESCRIPTION OF THE PRIOR ART
[0005] Stable and precise synchronization is of key importance in mobile networks for the successful connection of base stations and real-time data transmission, as well as for navigation and positioning services. Mobile networks must be synchronized so that base stations whose coverage overlaps do not interfere with each other and cause call drops or service degradation. One of the important sources of reference signals for synchronization and provision of navigation and positioning services is Global Navigation Satellite System (GNSS) . With constant improvement of existing systems to ensure better precision, there are an increasing number of threats and risks such as malicious attacks targeting these systems.
[0006] The basic tasks of GNSS receivers are to receive and separate signals from satellites, calculate pseudo-ranges for each satellite based on signal reception time, demodulate the navigation message to obtain ephemeris data, and estimate the Position, Velocity, and Time (PVT) solution. GNSS spoofing attack refers to the intentional transmission of fake GNSS signals to deceive the receiver to misinterpret fake signals as authentic ones, and to falsify the receiver’s location. GNSS jamming attack refers to an intentional transmission of a high-power radio frequency signal equal to or very close to the frequency of the device whose operation is to be prevented, with the intention to overload the receivers to the point that the receivers lose lock on the satellites and is thus rendered ineffective or degraded for users in the jammed area. Spoofing / jamming of GNSS signals is an increasing problem in the field, especially significantly impacting commercial aviation, with the expectation that Unmanned Aerial Vehicle (UAS) and ground receivers relying on 3GPP support for GNSS positioning would also be affected. A bad baseline location can propagate to affect subsequent location estimates even after the spoofed signal is no longer present. Because many devices transmit on frequencies close to GNSS receivers, it is possible that some of these devices unintentionally interfere with GNSS signals. Even small jammers that fit in the palm of a hand can have a range of several meters.
[0007] While a receiver may be able to detect spoofing / jamming of GNSS signals, but in general it cannot defend itself. In the presence of a degraded GNSS signal of which the receiver is aware, the confidence of the result could be indicated as poor, but the current Long Term Evolution Positioning Protocol (LPP) does not support a suitable cause for indicating such degradation. Therefore, there is a need for a method of reporting spoofing / jamming attack in a wireless communication system.SUMMARY OF THE INVENTION
[0008] The present disclosure provides a method of reporting spoofing / jamming attack in a wireless communication system. The method includes performing, by at least one UE in the wireless communication system, spoofing detection and / or jamming detection; and reporting, by the at least one UE, a detected spoofing attack and / or a detected jamming attack in a normalized probability metric to a server in the wireless communication system.
[0009] The present disclosure also provides a computer program product comprising at least one non-transitory computer-readable storage medium having computer-readable program instruction portions stored therein, the computer-readable program instruction portions comprise executable portions configured, when executed by a processor of an apparatus, to cause the apparatus to perform a method of reporting spoofing / jamming attack in a wireless communication system. The method includes performing, by at least one UE in the wireless communication system, spoofing detection and / or jamming detection; and reporting, by the at least one UE, a detected spoofing attack and / or a detected jamming attack in a normalized probability metric to a server in the wireless communication system.
[0010] The present disclosure also provides a wireless communication system for reporting spoofing / jamming attack. The wireless communication system includes at least one UE configured to perform spoofing detection and / or jamming detection and report a detected spoofing attack and / or a jamming spoofing attack in a normalized probability metric; and a server configured to receive the detected spoofing / jamming attack from the at least one UE.
[0011] These and other objectives of the present invention will no doubt become obvious to those of ordinary skill in the art after reading the following detailed description of the preferred embodiment that is illustrated in the various figures and drawings.BRIEF DESCRIPTION OF THE DRAWINGS
[0012] FIG. 1 is a diagram illustrating an example wireless communications system according to aspects of the present disclosure.
[0013] FIG. 2 is a diagram illustrating an example network apparatus in the wireless communication system according to aspects of the present disclosure.
[0014] FIG. 3 is a diagram illustrating an example UE in the wireless communications system according to aspects of the present disclosure.
[0015] FIG. 4 is a flowchart illustrating an example method for reporting spoofing / jamming attack according to aspects of the present disclosure.
[0016] FIG. 5 is a diagram illustrating a 3GPP-based LPP GNSS error reporting format for sending an error code along with measurements or a location estimate according to aspects of the present disclosure.
[0017] FIG. 6 is a diagram illustrating a 3GPP-based LPP GNSS error reporting format for sending an error code along with measurements or a location estimate according to aspects of the present disclosure.
[0018] FIG. 7 is a diagram illustrating a 3GPP-based LPP GNSS error reporting format for sending an error code along with measurements or a location estimate according to aspects of the present disclosure.DETAILED DESCRIPTION
[0019] Aspects of the disclosure are provided in the following description and related drawings directed to various examples provided for illustration purposes. Alternate aspects may be devised without departing from the scope of the disclosure. Additionally, well-known elements of the disclosure will not be described in detail or will be omitted so as not to obscure the relevant details of the disclosure.
[0020] The words “exemplary” and / or “example” are used herein to mean “serving as an example, instance, or illustration. ” Any aspect described herein as “exemplary” and / or “example” is not necessarily to be construed as preferred or advantageous over other aspects. Likewise, the term “aspects of the disclosure” does not require that all aspects of the disclosure include the discussed feature, advantage or mode of operation.
[0021] Those of skill in the art will appreciate that the information and signals described below may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the description below may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof, depending in part on the particular application, in part on the desired design, in part on the corresponding technology, etc.
[0022] Further, many aspects are described in terms of sequences of actions to be performed by, for example, elements of a computing device. It will be recognized that various actions described herein can be performed by specific circuits (e.g., application specific integrated circuits (ASICs) ) , by program instructions being executed by one or more processors, or by a combination of both. Additionally, the sequence (s) of actions described herein can be considered to be embodied entirely within any form of non-transitory computer-readable storage medium having stored therein a corresponding set of computer instructions that, upon execution, would cause or instruct an associated processor of a device to perform the functionality described herein. Thus, the various aspects of the disclosure may be embodied in a number of different forms, all of which have been contemplated to be within the scope of the claimed subject matter. In addition, for each of the aspects described herein, the corresponding form of any such aspects may be described herein as, for example, “logic configured to” perform the described action.
[0023] As used herein, the terms “user equipment” (UE) and “base station (BS) ” are not intended to be specific or otherwise limited to any particular radio access technology (RAT) , unless otherwise noted. In general, a UE may be any wireless communication device (e.g., a mobile phone, router, tablet computer, laptop computer, consumer asset locating device, wearable (e.g., smart watch, glasses, augmented reality (AR) / virtual reality (VR) headset, etc. ) , vehicle (e.g., automobile, motorcycle, bicycle, etc. ) , Internet of Things (IoT) device, etc. ) used by a user to communicate over a wireless communications network. A UE may be mobile or may be stationary, and may communicate with a radio access network (RAN) . As used herein, the term “UE” may be referred to interchangeably as an “access terminal” or “AT, ” a “client device, ” a “wireless device, ” a “subscriber device, ” a “subscriber terminal, ” a “subscriber station, ” a “user terminal” or “UT, ” a “mobile device, ” a “mobile terminal, ” a “mobile station. ” or variations thereof. Generally, UEs can communicate with a core network via a RAN, and through the core network the UEs can be connected with external networks such as the Internet and with other UEs. Of course, other mechanisms of connecting to the core network and / or the Internet are also possible for the UEs, such as over wired access networks, wireless local area network (WLAN) networks and so on.
[0024] A base station may operate according to one of several RATs in communication with UEs depending on the network in which it is deployed, and may be alternatively referred to as an access point (AP) , a network node, a NodeB, an evolved NodeB (eNB) , a next generation eNB (ng-eNB) , a New Radio (NR) Node B (also referred to as a gNB or gNodeB) , etc. A base station may be used primarily to support wireless access by UEs, including supporting data, voice, and / or signaling connections for the supported UEs. In some systems a base station may provide purely edge node signaling functions while in other systems it may provide additional control and / or network management functions. A communication link through which UEs can send signals to a base station is called an uplink (UL) channel (e.g., a reverse traffic channel, a reverse control channel, an access channel, etc. ) . A communication link through which the base station can send signals to UEs is called a downlink (DL) or forward link channel (e.g., a paging channel, a control channel, a broadcast channel, a forward traffic channel, etc. ) . As used herein the term traffic channel (TCH) can refer to either an uplink / reverse or downlink / forward traffic channel.
[0025] In some implementations that support positioning of UEs, a base station may not support wireless access by UEs (e.g., may not support data, voice, and / or signaling connections for UEs) , but may instead transmit reference signals to UEs to be measured by the UEs, and / or may receive and measure signals transmitted by the UEs. Such a base station may be referred to as a positioning beacon (e.g., when transmitting signals to UEs) and / or as a location measurement unit (e.g., when receiving and measuring signals from UEs) .
[0026] An “RF signal” comprises an electromagnetic wave of a given frequency that transports information through the space between a transmitter and a receiver. As used herein, a transmitter may transmit a single “RF signal” or multiple “RF signals” to a receiver. However, the receiver may receive multiple “RF signals” corresponding to each transmitted RF signal due to the propagation characteristics of RF signals through multipath channels. The same transmitted RF signal on different paths between the transmitter and receiver may be referred to as a “multipath” RF signal. As used herein, an RF signal may also be referred to as a “wireless signal” or simply a “signal” where it is clear from the context that the term “signal” refers to a wireless signal or an RF signal.
[0027] FIG. 1 is a diagram illustrating an example wireless communications system 100 according to aspects of the present disclosure. The wireless communications system 100 includes one or more network apparatuses 10, one or more UEs 20, one or more GNSS satellites 30, one or more base stations 40, one or more networks 60, and / or the like. For illustrative purpose, FIG. 1 only depicts one network apparatus 10, one UE 20, one GNSS satellite 30, and one base station, but the quantity of the above-mentioned devices does not limit the scope of the present disclosure.
[0028] In various embodiments, the network apparatus 10 may be a server, group of servers, distributed computing system, part of a cloud-based computing system, and / or other computing systems. In various embodiments, the UE 20 may be a smart phone, tablet, laptop, personal digital assistant (PDA) , mobile computing device, navigation system, automated vehicle control system (ADAS) , mobile data gathering platform, IoT devices or any device capable of performing one or more positioning and / or navigation-related functions. However, the type of the network apparatus 10 or the UE 20 does not limit the scope of the present disclosure.
[0029] In various embodiments, the one or more GNSS satellites 30 are configured to provide signals that may be used by the mobile apparatuses 20 and / or other devices containing a GNSS sensor / receiver to determine position estimates accordingly. In various embodiments, devices configured to spoof / jam GNSS signals are located and / or operating within an area within which one or more UEs 20 are located.
[0030] In various embodiments, the one or more base stations 40 may be radio nodes or access points. In various embodiments, the base stations 40 may be wireless network access points and / or gateways such as Wi-Fi network access points, cellular network access points, Bluetooth centrals, and / or other radio frequency-based network access points. However, the type of the base stations 40 does not limit the scope of the present disclosure.
[0031] Each of the components of the wireless communication system 100 may be in electronic communication with, for example, one another over the same or different wireless or wired networks 60 including, for example, a wired or wireless Personal Area Network (PAN) , Local Area Network (LAN) , Metropolitan Area Network (MAN) , Wide Area Network (WAN) , cellular network, and / or the like. In an example embodiment, a network 60 comprises the automotive cloud, digital transportation infrastructure (DTI) , radio data system (RDS) / high definition (HD) radio or other digital radio system, and / or the like. However, the type of the network 60 does not limit the scope of the present disclosure.
[0032] FIG. 2 is a diagram illustrating an example network apparatus 10 in the wireless communication system 100 according to aspects of the present disclosure. The network apparatus 10 may include a core network 110, a Next Generation RAN (NG-RAN) 120, a location server 130 and a user interface 140. The core network 110 may be a 5GC, also referred to as a Next Generation Core (NGC) , which can be viewed functionally as control plane (C-plane) functions 114 (e.g., UE registration, authentication, network access, gateway selection) and user plane (U-plane) functions 112 (e.g., UE gateway function, access to data networks, IP routing) operating cooperatively to form the core network 110.
[0033] In an example embodiment, the NG-RAN 120 includes one or more gNBs 122, which may communicate with one or more UEs 20 via the user interface 140. Each gNB 122 may be connected to the U-plane functions 112 and the C-plane functions 114 via a U-plane interface 113 and a C-plane interface 115, respectively.
[0034] In another example embodiment, the NG-RAN 120 includes one or more gNBs 122 and one or more ng-eNBs 124, either or both of which may communicate with one or more UEs 20 via the user interface 140. Meanwhile, the ng-eNB 124 may directly communicate with the gNB 122 via a backhaul connection 123. Each gNB 122 may be connected to the U-plane functions 112 and the C-plane functions 114 via a U-plane interface 113 and a C-plane interface 115, respectively. Each ng-eNB 124 may be connected to the U-plane functions 112 and the C-plane functions 114 via a U-plane interface 113 and a C-plane interface 115, respectively.
[0035] In an example embodiment, the location server 130 may be in communication with the core network 110 to provide location assistance for the one or more UEs 20. The location server 130 may be implemented as a plurality of separate servers (e.g., physically separate servers, different software modules on a single server, different software modules spread across multiple physical servers, etc. ) , or alternately may each correspond to a single server. The location server 130 may be configured to support one or more location services for the one or more UEs 20 that can connect to the location server 130 via the core network 110, and / or via the Internet (not shown in FIG. 2) . Further, the location server 130 may be integrated into a component of the core network 110, or alternatively may be external to the core network 110 as a third party server, such as an original equipment manufacturer (OEM) server or service server.
[0036] FIG. 3 is a diagram illustrating an example UE 20 in the wireless communications system 100 according to aspects of the present disclosure. The UE 20 may include a processor 22, memory 24, a communication interface 26, a user interface 28, one or more sensors 29 and / or other components configured to perform various operations, procedures, functions or the like described herein.
[0037] In an example embodiment, the processors 22 may include one or more general purpose processors, multi-core processors, central processing units (CPUs) , ASICs, digital signal processors (DSPs) , field programmable gate arrays (FPGAs) , other programmable logic devices or processing circuitry, or various combinations thereof. The processor 22 is configured to provide functionality relating to wireless communication, and provide other processing functionality, such as means for determining, means for calculating, means for receiving, means for transmitting, means for indicating, etc.
[0038] In an example embodiment, the memory 24 may include random access memory (RAM) , flash memory, read-only memory (ROM) , erasable programmable ROM (EPROM) , electrically erasable programmable ROM (EEPROM) , registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. In various embodiments, the memory 24 may be integral to the processor 22, or the memory 24 and the processor 22 may reside as discrete components in the UE 20. The memory 24 is configured to store information or executable code used by the wireless communication system 100 to provide its functionality.
[0039] In various embodiments, the sensors 29 may include one or more inertial measurement unit (IMU) sensors, one or more GNSS sensors, one or more radio sensors, one or more image sensors, and / or other sensors capable of capturing data corresponding to observations of features within the UE’s environment. In an example embodiment, the one or more IMU sensors comprise one or more accelerometers (e.g., a micro-electrical mechanical systems (MEMS) device) , geomagnetic sensors (e.g., compass) , altimeters (e.g., a barometric pressure altimeter) , magnetometers, and / or the like. In an example embodiment, the one or more GNSS sensors are configured to communicate with one or more GNSS satellites 30 and determine GNSS-based position estimates and / or other information based on the communication with the GNSS satellites 30. In an example embodiment, the one or more radio sensors comprise one or more radio interfaces configured to observe and / or receive signals generated and / or transmitted by one or more base stations 40. In an example embodiment, the one or more image sensors may include digital cameras, 3D cameras, 360° cameras, and / or any image sensor capable of capturing visual samples.
[0040] In various embodiments, the communication interface 26 may transmit one or more types of signals generated and / or transmitted in accordance with one or more protocols such as 5G, general packet radio service (GPRS) , Universal Mobile Telecommunications System (UMTS) , Code Division Multiple Access 2000 (CDMA2000) , Wideband Code Division Multiple Access (WCDMA) , Global System for Mobile Communications (GSM) , Enhanced Data rates for GSM Evolution (EDGE) , Time Division-Synchronous Code Division Multiple Access (TD-SCDMA) , Long Term Evolution (LTE) , Evolved Universal Terrestrial Radio Access Network (E-UTRAN) , Evolution-Data Optimized (EVDO) , High Speed Packet Access (HSPA) , High-Speed Downlink Packet Access (HSDPA) , IEEE 802.11 (Wi-Fi) , Wi-Fi Direct, 802.16 (WiMAX) , ultra-wideband (UWB) , infrared (IR) protocols, near field communication (NFC) protocols, Wibree, Bluetooth protocols, wireless universal serial bus (USB) protocols, and / or any other wireless protocol.
[0041] FIG. 4 is a flowchart illustrating an example method 400 for reporting spoofing / jamming attack according to aspects of the present disclosure. In an aspect, the method 400 may be performed by the wireless communication system 100. In another aspect, the method 400 may be performed by a computer program product which comprises at least one non-transitory computer-readable storage medium having computer-readable program instruction portions stored therein, the computer-readable program instruction portions comprise executable portions configured, when executed by a processor of an apparatus. The method 400 depicted in FIG. 4 includes the following steps:
[0042] Step 410: the UE 10 performs spoofing / jamming detection.
[0043] Step 420: the UE 10 reports a detected spoofing / jamming attack in a normalized probability metric to a server in the network apparatus 20.
[0044] Step 430: the network apparatus 20 acts on crowd-sourced information of one or more spoofing / jamming attack reports received from one or more UEs.
[0045] At step 410, the UE 10 may be implemented with a GNSS signal spoofing / jamming detection method for detecting fake signals. Alternatively, the one or more GNSS satellites 30 may provide authentication in the signals, allowing the UE 10 to identify fake signals.
[0046] In an example embodiment, the GNSS signal spoofing detection method adopted by the UE 10 may be a signal processing method based on correlation peak monitoring, power-based, and antenna array processing techniques. For example, a correlation peak monitoring method performs spoofing / jamming detection by monitoring the distribution of correlation peaks and phase difference between fake / jammed signals and authentic signals. A power-based monitoring method performs spoofing / jamming detection by monitoring the difference between the signal strength, such as power, automatic gain control (AGC) or signal-to-noise ratio (SNR) , between fake and authentic signals. An antenna array processing method performs spoofing / jamming detection by estimating the direction of arrival (DoA) of real and spoofed / jammed signals.
[0047] In an example embodiment, the GNSS signal spoofing / jamming detection method adopted by the UE 10 may be a data bit method based on time of arrival (ToA) , DoA, and NMEA messages analysis techniques. For example, a ToA-based data bit method performs spoofing / jamming detection by detecting the difference between fake and authentic signals in accordance with the ToA. A DoA-based data bit method performs spoofing / jamming detection by detecting the difference between fake / jammed signals and authentic signals in accordance with the DoA. A data bit method based on NMEA messages analysis detects and identifies suspected potentially fake / jammed signals by checking the consistency of NMEA messages from GNSS receivers.
[0048] In an example embodiment, the GNSS signal spoofing detection method adopted by the UE 10 may be a positing method based on pseudo-range measurements. This approach detects spoofing signals by analyzing the differences between pseudo-range double-differences (PRDD) measurements and expected PRDD estimations.
[0049] In an example embodiment, the GNSS signal spoofing / jamming detection method adopted by the UE 10 may be a machine and deep learning method which combines classical observation parameters and uses a software-defined radio. This approach detects spoofing / jamming signals by using a support vector machine (SVM) learning method with the combination of real and simulated datasets to verify and validate the machine learning algorithms.
[0050] In an example embodiment, the UE 10 may be implemented with a GNSS signal spoofing detection method for detecting fake signals and a GNSS signal jamming detection method for detecting jammed signals. Alternatively, the UE 10 may be implemented with a GNSS signal spoofing and jamming combination detection method for detecting fake signals and jammed signals.
[0051] At step 420, the UE 10 is configured to report a detected spoofing / jamming attack in a normalized probability metric to a server in the network apparatuses 20. In an example embodiment, the UE 10 may modify a current LPP GNSS error reporting format for reporting a detected spoofing attack to the server. According to related 3GPP standards, the IE GNSS-TargetDeviceErrorCauses is used by the target device (i.e., UE 10) to provide GNSS error reasons the location server 130 in the network apparatuses 20.
[0052] FIG. 5 is a diagram illustrating a 3GPP-based LPP GNSS error reporting format 500 for sending an error code along with measurements or a location estimate according to aspects of the present disclosure. In addition to the existing "fineTimeAssistanceMeasurementsNotPossible" , "adrMeasurementsNotPossible" and "multiFrequenceMeasurementsNotPossible” error types, the present LPP GNSS error reporting format 500 further introduces a new error type “spoofError” and a new field “attack-Porbability-Metric-r18” . If the cause value is "notAllRequestedMeasurementsPossible" and the UE 10 detects a spoofing attack in step 410, the UE 10 is configured to include the "spoofError" field when reporting error codes.
[0053] The field “attack-Porbability-Metric-r18” indicates the probability of the UE 10 under spoofing attack. The range is from 0 (least likely) to 6 (most likely) . This metric can be calculated with the number of server-UE authentication errors in a time window (such as 6 periodic updates) . However, the method of calculating the probability metric of spoofing attack does not limit the scope of the present disclosure.
[0054] FIG. 6 is a diagram illustrating a 3GPP-based LPP GNSS error reporting format 600 for sending an error code along with measurements or a location estimate according to aspects of the present disclosure. In addition to the existing "fineTimeAssistanceMeasurementsNotPossible" , "adrMeasurementsNotPossible" and "multiFrequenceMeasurementsNotPossible” error types, the present LPP GNSS error reporting format 600 further introduces a new error type “jammingError” and a new field “attack-Porbability-Metric-r18” . If the cause value is "notAllRequestedMeasurementsPossible" and the UE 10 detects a jamming attack in step 410, the UE 10 is configured to include the "jammingError" field when reporting error codes.
[0055] The field “attack-Porbability-Metric-r18” indicates the probability of the UE 10 under jamming attack. The range is from 0 (least likely) to 6 (most likely) . This metric can be calculated with the number of server-UE authentication errors in a time window (such as 6 periodic updates) . However, the method of calculating the probability metric of jamming attack does not limit the scope of the present disclosure.
[0056] FIG. 7 is a diagram illustrating a 3GPP-based LPP GNSS error reporting format 7600 for sending an error code along with measurements or a location estimate according to aspects of the present disclosure. In addition to the existing "fineTimeAssistanceMeasurementsNotPossible" , "adrMeasurementsNotPossible" and "multiFrequenceMeasurementsNotPossible” error types, the present LPP GNSS error reporting format 700 further introduces a new error type “spoofjammingError” and a new field “attack-Porbability-Metric-r18” . If the cause value is "notAllRequestedMeasurementsPossible" and the UE 10 detects a spoofing attack and / or a jamming attack in step 410, the UE 10 is configured to include the "spoofjammingError" field when reporting error codes.
[0057] The field “attack-Porbability-Metric-r18” indicates the probability of the UE 10 under spoofing / jamming attack. The range is from 0 (least likely) to 6 (most likely) . This metric can be calculated with the number of server-UE authentication errors in a time window (such as 6 periodic updates) . However, the method of calculating the probability metric of spoofing / jamming attack does not limit the scope of the present disclosure.
[0058] At step 430, the network apparatus 20 is configured to act on crowd-sourced information of one or more spoofing / jamming attack reports received from one or more UEs. By acting on crowd-sourced information rather than individual reports from a single source, the server may avoid taking unnecessary measures in response to false spoofing / jamming attack report of an individual UE. In an example embodiment, after determining that an spoofing / jamming attack report is valid, the server may take an implementation-dependent decision on how to handle the situation, such as falling back to another positioning method (or a different constellation where applicable) .
[0059] In conclusion, the present UE detects GNSS signal spoofing / jamming and reports a detected spoofing / jamming attack to a server in the network apparatuses using an extended LPP GNSS error reporting format with an additional error cause and an attack probability metric. Further, the network apparatuses may take an implementation-dependent decision depending on crowd-sourced information of one or more spoofing / jamming attack reports received from one or more UEs.
[0060] Those skilled in the art will readily observe that numerous modifications and alterations of the device and method may be made while retaining the teachings of the invention. Accordingly, the above disclosure should be construed as limited only by the metes and bounds of the appended claims.
Claims
1.A method of reporting spoofing / jamming attack in a wireless communication system, comprising:performing, by at least one user equipment (UE) in the wireless communication system, spoofing / jamming detection; andreporting, by the at least one UE, a detected spoofing attack and / or a detected jamming attack in a normalized probability metric to a server in the wireless communication system.2.The method of claim 1, further comprising:reporting, by the at least one UE, the detected spoofing attack and / or the detected jamming attack in the normalized probability metric to the server using a 3GPP-based Long Term Evolution Positioning Protocol (LPP) Global Navigation Satellite System (GNSS) error reporting format.3.The method of claim 2, further comprising:introducing a spoofing-related error type and / or a jamming-related error type in the 3GPP-based LPP GNSS error reporting format and a field associated with the normalized probability metric.4.The method of claim 3, further comprising:calculating, by the at least one UE, the normalized probability metric with a number of server-UE authentication errors in a time window.5.The method of claim 1, further comprising:performing, by the at least one UE, spoofing / jamming detection using at least one of a correlation peak monitoring method, a power-based monitoring method and an antenna array processing method.6.The method of claim 1, further comprising:performing, by the at least one UE, spoofing / jamming detection using at least one of a data bit method based on time of arrival (ToA) , a data bit method based on direction of arrival (DoA) , and a data bit method based on NMEA messages analysis.7.The method of claim 1, further comprising:performing, by the at least one UE, spoofing detection using a positing method based on pseudo-range measurements.8.The method of claim 1, further comprising:performing, by the at least one UE, spoofing / jamming detection using a machine and deep learning method.9.The method of claim 1, further comprising:obtaining, by the server, crowd-sourced data of one or more spoofing attack reports and / or one or more jamming attack reports received from one or more UEs; andtaking an action when determining that the detected spoofing attack and / or the detected jamming attack reported by the at least one UE is valid based on the crowd-sourced data.10.The method of claim 1, further comprising:falling back to a different positioning method or a different constellation, by the server, when determining that the detected spoofing attack and / or the detected jamming attack reported by the at least one UE is valid.11.A computer program product comprising at least one non-transitory computer-readable storage medium having computer-readable program instruction portions stored therein, the computer-readable program instruction portions comprise executable portions configured, when executed by a processor of an apparatus, to cause the apparatus to perform claim 1.12.A wireless communication system for reporting spoofing / jamming attack, comprising:at least one user equipment (UE) configured to perform spoofing detection and / or jamming detection and report a detected spoofing attack and / or a detected jamming attack in a normalized probability metric; anda server configured to receive the detected spoofing attack and / or the detected jamming attack from the at least one UE.13.The wireless communication system of claim 12, wherein:the at least one UE is further configured to report the detected spoofing attack and / or the detected jamming attack in the normalized probability metric to the server using a 3GPP-based Long Term Evolution Positioning Protocol (LPP) Global Navigation Satellite System (GNSS) error reporting format.14.The wireless communication system of claim 13, wherein:a spoofing-related error type and / or a jamming-related error type and a field associated with the normalized probability metric are introduced in the 3GPP-based LPP GNSS error reporting format.15.The wireless communication system of claim 14, wherein:the at least one UE is further configured to calculate the normalized probability metric with a number of server-UE authentication errors in a time window.16.The wireless communication system of claim 12, wherein:the at least one UE is further configured to perform spoofing detection and / or jamming detection using at least one of a correlation peak monitoring method, a power-based monitoring method, an antenna array processing method, a data bit method based on time of arrival (ToA) , a data bit method based on direction of arrival (DoA) , a data bit method based on NMEA messages analysis, a positing method based on pseudo-range measurements, and a machine and deep learning method.17.The wireless communication system of claim 12, wherein the server is further configured to:obtain crowd-sourced data of one or more spoofing attack reports and / or one or more jamming attack reports received from one or more UEs; andtake an action when determining that the detected spoofing attack and / or the detected jamming attack reported by the at least one UE is valid based on the crowd-sourced data.18.The wireless communication system of claim 12, wherein the server is further configured to:fall back to a different positioning method or a different constellation when determining that the detected spoofing attack and / or the detected jamming attack reported by the at least one UE is valid.
Citation Information
Patent Citations
Computer-implemented method, data processing device, computer program product and computer-readable storage medium for detecting global navigation satellite system signal spoofing
CN116075746A
Methods and systems for collaborative global navigation satellite system (GNSS) diagnostics
US20170070971A1
Systems and methods for detecting and mitigating spoofed satellite navigation signals
US20220221587A1
Techniques for detecting an intranet spoofing attack
US9578057B1
Method and apparatus for acquisition of reliable time in a wireless network
WO2023009218A1