Determining the correct position in the presence of GNSS spoofing
By using non-GNSS positioning information and prediction frequency and code phase differences in the GNSS positioning system to set the search window, the fraud signal is eliminated, and the position inaccurate caused by the fraud signal is solved, and more accurate positioning is achieved.
Patent Information
- Application Number
- CN202180029102.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-04-22
- Filing Date
- 2021-04-21
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2041-04-21
AI Technical Summary
In the presence of spoofing signals, existing GNSS positioning systems have difficulty accurately determining the location of the mobile device, resulting in incorrect or inaccurate location information.
By determining the initial position of the mobile device based on non-GNSS positioning information, setting a search window using predicted frequency and code phase differences, excluding spoofed signals, receiving and measuring a legitimate GNSS signal to determine the updated location.
Effectively identifying and eliminating spoofing signals improves the accuracy and reliability of GNSS positioning and ensures that the location information of mobile devices is more accurate.
Smart Images

Figure CN115398273B_ABST
Abstract
Description
Background Art
[0001] Obtaining a reliable and accurate location of a mobile device or system is useful for many applications such as emergency handling, personal navigation, autonomous driving, asset tracking, locating friends or family members, etc. Existing location methods include methods based on measuring radio signals transmitted from various devices or entities, including satellite vehicles (SVs) and terrestrial wireless power sources in a wireless network, such as base stations and access points. For example, modern electronic devices often include systems that can receive signals from satellite navigation systems, which are commonly referred to as global navigation satellite systems (each referred to as a “GNSS”), and use satellite signals to determine the location of the device and other information such as speed, heading, altitude, etc. GNSS receivers can be integrated into consumer electronic devices (such as smartphones or smartwatches), as well as into navigation systems integrated into various types of transportation vehicles (such as cars, trucks, ships, airplanes, and drones). Signals from multiple satellites orbiting the Earth can be received and processed by the GNSS receiver to determine the location of the GNSS receiver, and by proxy, the location of the device, vehicle, etc. Summary of the Invention
[0002] Various inventive embodiments for determining the location of a mobile device or mobile system using GNSS signals are described herein, including devices, systems, components, apparatuses, methods, processes, instructions, code, computer storage media, etc.
[0003] According to the present disclosure, an example method of determining the location of a mobile device resistant to global navigation satellite system (GNSS) spoofing includes determining a non-GNSS location of the mobile device based on location information from one or more non-GNSS data sources that receive a first GNSS signal at the mobile device. The method further includes determining that the first GNSS signal includes: a frequency that differs from a predicted frequency by more than a threshold frequency difference, a code phase that differs from a predicted code phase by more than a threshold code phase difference, or both, for a predicted frequency and a predicted code phase based on the non-GNSS location. The method further includes receiving a second GNSS signal within a search window based on the non-GNSS location, the threshold frequency difference, and the threshold code phase difference. The method further includes determining a measurement for the second GNSS signal.
[0004] According to the present disclosure, an example mobile device for determining a location resistant to Global Navigation Satellite System (GNSS) spoofing includes an antenna configured to receive GNSS signals, a memory, and one or more processing units communicatively coupled to the antenna and the memory. The one or more processing units are configured to: determine a non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources. The one or more processing units are further configured to receive a first GNSS signal via the antenna. The one or more processing units are further configured to determine that the first GNSS signal includes: a frequency that differs from a predicted frequency by more than a threshold frequency difference, a code phase that differs from a predicted code phase by more than a threshold code phase difference, or both, for a predicted frequency and a predicted code phase based on the non-GNSS location. The one or more processing units are further configured to receive a second GNSS signal via the antenna within a search window based on the non-GNSS location, the threshold frequency difference, and the threshold code phase difference. The one or more processing units are further configured to determine a measurement for the second GNSS signal.
[0005] According to the present disclosure, an example apparatus for determining a location of a mobile device resistant to Global Navigation Satellite System (GNSS) spoofing includes means for determining a non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources. The apparatus further includes means for receiving a first GNSS signal at the mobile device. The apparatus further includes means for determining that the first GNSS signal includes a frequency that differs from a predicted frequency by more than a threshold frequency difference, a code phase that differs from a predicted code phase by more than a threshold code phase difference, or both, for a predicted frequency and a predicted code phase based on the non-GNSS location. The apparatus further includes means for receiving a second GNSS signal within a search window based on the non-GNSS location, the threshold frequency difference, and the threshold code phase difference. The apparatus further includes means for determining a measurement for the second GNSS signal.
[0006] According to the present disclosure, an example non-transitory computer-readable medium stores instructions for determining a location of a mobile device resistant to Global Navigation Satellite System (GNSS) spoofing. The instructions include code for determining a non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources. The instructions further include code for receiving a first GNSS signal. The instructions further include code for determining that the first GNSS signal includes a frequency that differs from a predicted frequency by more than a threshold frequency difference, a code phase that differs from a predicted code phase by more than a threshold code phase difference, or both, for a predicted frequency and a predicted code phase based on the non-GNSS location. The instructions further include code for receiving a second GNSS signal within a search window based on the non-GNSS location, the threshold frequency difference, and the threshold code phase difference. The instructions further include code for determining a measurement for the second GNSS signal.
[0007] This invention content is neither intended to identify the key or essential features of the claimed subject matter nor to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to the appropriate portions of the entire specification of this disclosure, any or all of the drawings, and each claim. The foregoing and other features and examples will be described in more detail in the following specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Aspects of the present disclosure are shown by way of example. The non-limiting and non-exhaustive aspects are described with reference to the following drawings.
[0009] Figure 1 is a simplified diagram of an example of a positioning system according to certain embodiments.
[0010] Figure 2A shows a simplified block diagram of an example GNSS receiver according to an embodiment.
[0011] Figure 2B shows an example of a search grid 210 for satellite signal acquisition.
[0012] Figure 3 shows a grid-based search window according to an embodiment.
[0013] Figure 4 and Figure 5 is an example energy distribution diagram used in grid-based acquisition and tracking techniques according to an embodiment.
[0014] Figure 6 is a diagram showing an example of an abnormal GNSS signal in an example of a positioning system.
[0015] Figure 7 is a diagram showing an example of spoofing by a spoofing device.
[0016] Figure 8 is a diagram showing an example of tracking a GNSS signal using a propagation search window according to certain embodiments.
[0017] Figures 9A to 9B is a flowchart showing an example method for determining the location of a mobile device in the presence of spoofing signals according to certain embodiments.
[0018] Figure 10 is an illustration of a grid according to one embodiment, showing a type of spoofing detection that can be performed in a grid-based method.
[0019] Figure 11 and Figure 12 is a block diagram of an example mobile device according to certain embodiments.
[0020] Figure 13 FIG. is a flow chart of an example method of how to subtract a spoofing signal from a received signal according to one embodiment.
[0021] In the drawings, unless otherwise noted, like reference numerals refer to like parts throughout the various figures. Additionally, multiple instances of a component may be distinguished by adding a second label (e.g., a letter or number) after the reference numeral, or a dash and a second label. If only the first reference numeral is used in the specification, the description applies to any one of the like components having the same first reference numeral, regardless of the second label. DETAILED DESCRIPTION
[0022] The techniques disclosed herein generally relate to determining the location of a mobile device or mobile system, and more particularly, to using Global Navigation Satellite System (GNSS) signals to determine the location of a mobile device or mobile system in the presence of spoofing signals. Various inventive embodiments are described herein, including devices, systems, components, apparatuses, methods, processes, instructions, code, computer-readable storage media, etc.
[0023] An increasing number of users worldwide rely on mobile navigation services because knowing the location of a mobile object such as a mobile device or system is very useful for many applications and / or in many situations, such as emergency calls, personal navigation, autonomous driving, asset tracking, locating people, and so on. Determining an incorrect location of a mobile device is very important. The incorrect location of a mobile device may be determined erroneously based on incorrect or inaccurate input information, such as GNSS or satellite positioning system (SPS) signals that may be incorrect or inaccurate either unintentionally (e.g., due to SV errors) or intentionally (e.g., due to an entity providing one or more spoofing signals). A spoofing signal is a signal that appears to come from a particular source (e.g., a known trusted source) but actually comes from a different source. For example, the Global Positioning System (GPS) is a GNSS system in which the signals include open signals without any encryption and are thus vulnerable to spoofing attacks, where an adversary can inject forged GPS signals to control the victim's GPS device. For example, a spoofing signal may have the characteristics of a signal from a GPS SV but may actually originate from a GLONASS (or GLO) SV or an SPS simulator (e.g., a ground-based SPS signal generator). A spoofing device or system (referred to herein as a "spoofing device") may rebroadcast GNSS signals recorded at another location or time (referred to as meaconing), or may generate and transmit modified satellite signals. Since most navigation systems are designed to use the strongest GNSS signals for positioning, spoofing signals may typically be strong signals that can override weaker but legitimate satellite signals. Identifying spoofing signals or other abnormal signals (i.e., undesired, spoofed, or inaccurate or incorrect signals) can help GNSS receivers mitigate the consequences of receiving such signals.
[0024] According to certain embodiments, a GNSS receiver and / or a processing unit may: use various techniques to identify spoofing signals; obtain current positioning information associated with the mobile device; and determine a GNSS signal search window (e.g., narrower or tighter) for acquiring and / or tracking GNSS signals associated with satellites based on the current positioning information such that spoofing signals can be excluded from the search window. The current positioning may include non-GNSS positioning based on positioning information from one or more non-GNSS data sources. The search window may define the frequency and code phase range of GNSS signals and may be implemented using different types of GNSS signal tracking techniques as described in more detail herein, such as grid-based tracking and / or loop-based tracking as described in more detail herein. Then, the GNSS receiver may search for GNSS signals associated with satellites using the GNSS signal search window to determine updated positioning information of the mobile device based at least on information (e.g., frequency and code phase offset) of the GNSS signals associated with the satellites.
[0025] As used herein, when the term "tracking" is used in the context of a GNSS receiver (and / or its components), "tracking" a signal can refer to a mode (e.g., "tracking mode") in which, after identifying a GNSS signal, the GNSS receiver tracks the changes in the signal over time (e.g., changes in frequency and / or code phase). This enables the GNSS receiver to continue receiving the tracked signal over time (e.g., for position estimation using non-spoofed signals). A GNSS receiver that is tracking a signal may also be referred to herein as being "locked" to the signal. Before tracking a signal, the GNSS receiver may first search for and acquire the signal. Details regarding signal acquisition and tracking are provided herein, but the embodiments are not limited to these disclosed techniques.
[0026] As used herein, unless otherwise specified, the terms "user equipment" (UE) and "base station" are not intended to be specific to or otherwise limited to any particular radio access technology (RAT). Generally, a mobile device and / or UE can be any wireless communication device that a user uses to communicate over a wireless communication network (e.g., a mobile phone, router, tablet computer, laptop computer, tracking device, wearable device (e.g., smartwatch, glasses, augmented reality (AR) / virtual reality (VR) headset, etc.), vehicle (e.g., car, motorcycle, bicycle, etc.), Internet of Things (IoT) device, etc.). A UE can be mobile or can be (e.g., at certain times) stationary and can communicate with a radio access network (RAN). As used herein, the term "UE" can be interchangeably referred to as "access terminal" or "AT", "client device", "wireless device", "user equipment", "user terminal", "user station", "user terminal" (or UT), "mobile device", "mobile terminal", "mobile station", or variants thereof. Generally, a UE can communicate with a core network via the RAN, and through the core network, the UE can connect to external networks (such as the Internet) and other UEs. Other mechanisms for a UE to connect to the core network and / or the Internet are also possible, such as via a wired access network, a wireless local area network (WLAN) network (such as based on IEEE 802.11, etc.).
[0027] The base station can operate according to one of several RATs for communicating with the UE, depending on the network in which it is deployed, and can alternatively be referred to as an access point (AP), network node, NodeB, evolved NodeB (eNB), next-generation eNB (ng-eNB), New Radio (NR) Node B (which can also be referred to as gNB or gNodeB), etc. In the NR system, the terms "cell" and next-generation NodeB (gNB), New Radio base station (NR BS), 5G NB, access point (AP), or transmit-receive point (TRP) can be used interchangeably. The base station can be mainly used to support the wireless access of the UE, including supporting the data, voice, and / or signaling connections of the supported UE. In some systems, the base station can provide a pure edge node signaling function, while in other systems, the base station can provide additional control and / or network management functions. The communication link through which the UE sends signals to the base station is called the uplink (UL) channel (e.g., reverse traffic channel, reverse control channel, access channel, etc.). The communication link through which the base station sends signals to the UE is called the downlink (DL) or forward link channel (e.g., paging channel, control channel, broadcast channel, forward traffic channel, etc.). As used herein, the term traffic channel (TCH) can refer to the uplink / reverse or downlink / forward traffic channel.
[0028] In some embodiments, the term "base station" can refer to a single physical transmit-receive point (TRP) or multiple physical TRPs, which can be co-located or not co-located. For example, in the case where the term "base station" refers to a single physical TRP, the physical TRP can be the antenna of the base station corresponding to the cell (or several cell sectors) where the base station is located. In the case where the term "base station" refers to multiple co-located physical TRPs, the TRPs can be an antenna array of the base station (e.g., in a multiple-input multiple-output (MIMO) system or when the base station employs beamforming). In the case where the term "base station" refers to multiple non-co-located physical TRPs, the physical TRPs can be a distributed antenna system (DAS) (a spatially separated antenna network connected to a common source via a transmission medium) or a remote radio head (RRH) (a remote base station connected to the serving base station). Alternatively, the non-co-located physical TRPs can be the serving base station that receives the measurement report from the UE and an adjacent base station whose reference RF signal (or simply "reference signal") the UE is measuring. As used herein, since the TRP is the point where the base station sends and receives wireless signals, a reference to a transmission from the base station or a reception at the base station should be understood to refer to a specific TRP of the base station.
[0029] In some embodiments that support UE positioning, the base station may not support the wireless access of the UE (e.g., may not support the data, voice, and / or signaling connections of the UE), but may send a reference signal to the UE for the UE to measure, and / or may receive and measure the signal sent by the UE. Such a base station may be referred to as a positioning beacon (e.g., when sending a signal to the UE) and / or a position measurement unit (e.g., when receiving and measuring the signal from the UE).
[0030] An "RF signal" includes electromagnetic waves in a given frequency range that transmit information through the space between a transmitter and a receiver. As used herein, a transmitter may send a single "RF signal" or multiple "RF signals" to a receiver. However, due to the propagation characteristics of RF signals through a multipath channel, a receiver may receive multiple "RF signals" corresponding to each transmitted RF signal. The same transmitted RF signal on different paths between the transmitter and the receiver may be referred to as a "multipath" RF signal. As used herein, an RF signal may also be referred to as a "wireless signal" or simply a "signal", where it is clear from the context that the term "signal" refers to a wireless signal or an RF signal.
[0031] As used herein, a "space vehicle" or "SV" refers to an object capable of sending a signal to a receiver on the Earth's surface. In one particular example, such an SV may include a geostationary satellite. Alternatively, the SV may include a satellite that orbits and moves relative to a stationary location on the Earth. However, these are merely examples of SVs, and the claimed subject matter is not limited in these respects.
[0032] As used herein, a "location" refers to information associated with the whereabouts of an object or thing relative to a reference point. For example, such a location may be represented as geographical coordinates, such as latitude and longitude. In another example, such a location may be represented as geocentric XYZ coordinates. In yet another example, such a location may be represented as a street address, a municipality or other government jurisdiction, a postal code, etc. However, these are merely examples of how a location may be represented according to specific examples, and the claimed subject matter is not limited in these respects. "Positioning" is also referred to as "position estimation", "estimated position", "location", "determining positioning", "positioning estimation", "position location", "estimation positioning" herein.
[0033] Certain illustrative embodiments will now be described with reference to the accompanying drawings, which form a part of this specification. The following description provides only examples and is not intended to limit the scope, applicability, or configuration of the present disclosure. Instead, the following description of the embodiments will provide those skilled in the art with an enabling description for implementing one or more embodiments. It should be understood that various changes can be made to the functions and arrangements of the elements without departing from the spirit and scope of the present disclosure. In some cases, devices, systems, structures, components, methods, and other components may be shown as components in block diagram form to avoid obscuring these examples with unnecessary details. In other cases, well-known devices, processes, systems, structures, and technologies may be shown without unnecessary details to avoid confusing these examples. The terms and expressions employed in this disclosure have been used in a descriptive rather than a restrictive sense, and there is no intention of excluding any equivalents of the features shown and described or portions thereof when using such terms and expressions. The word "example" as used herein means "serving as an example, instance, or illustration." Any embodiment or design described herein as an "example" is not necessarily to be construed as preferred or advantageous over other embodiments or designs.
[0034] Figure 1 FIG. 4 is a simplified diagram of an example of a positioning system 100 according to certain embodiments, where spoofing may occur and the techniques provided herein for determining the correct location may be performed. In positioning system 100, UE 105, location server 160, and / or other components of positioning system 100 may use the techniques provided herein to determine the estimated location of UE 105. The estimated location of UE 105 may be used in various applications to, for example, assist the user of UE 105 with direction finding or navigation, or to assist another user (such as a user associated with external client 180) in locating UE 105. The location of UE 105 may include the absolute location of UE 105 (e.g., latitude and longitude and possibly altitude) or the relative location of UE 105 (e.g., a location expressed as a certain distance north or south, east or west, and possibly above or below some other known fixed location or some other location (such as the location of UE 105 at some known previous time)). The location may also be specified as a geodetic location (such as latitude and longitude) or an urban location (e.g., a street address or using other location-related names and labels). The location may also include an indication of uncertainty or error, such as the level of error in the expected location and possibly the vertical distance, or an indication of the area or volume (e.g., circular or elliptical) within which UE 105 is expected to be located with a certain confidence (e.g., 95% confidence).
[0035] In this example, Figure 1UE 105 is shown as a smartphone device. However, the UE can be any suitable device that includes GNSS capabilities, or can be a device or machine that has such GNSS functionality integrated. For example, UE 105 can include personal devices such as smartphones, smartwatches, tablets, laptops, etc. However, the UE can also include a larger category of devices and can include vehicles such as boats, ships, cars, trucks, airplanes, drones, etc. that have an integrated GNSS receiver and positioning system.
[0036] The techniques described herein can be implemented by one or more components of positioning system 100. Positioning system 100 can include vehicle 102, UE 105, one or more satellites 110 (also referred to as SVs) of a GNSS constellation such as GPS, base station 120, access point (AP) 130, location server 160, network 170, and external client 180. UE 105 can be connected to vehicle 102 or integrated into vehicle 102. Generally, positioning system 100 can estimate the location of mobile device 105 based on RF signals received and / or transmitted by UE 105 and the known locations of other components that transmit and / or receive RF signals (e.g., GNSS satellites 110, base station 120, AP 130). Additional details regarding specific location estimation techniques will be discussed in more detail below.
[0037] Figure 1 A general description of the various components is provided, any one or all of which can be used as appropriate, and each component can be replicated as needed. Specifically, although only one UE 105 is shown, it should be understood that many UEs (e.g., hundreds, thousands, millions, etc.) can use positioning system 100. Similarly, positioning system 100 can include more or fewer base stations 120 and / or APs 130 than Figure 1 shown. The connections shown connecting the various components in positioning system 100 include data and signaling connections, which can include additional (intermediate) components, direct or indirect physical and / or wireless connections, and / or additional networks. Additionally, components can be rearranged, combined, separated, replaced, and / or omitted according to the desired functionality. In some embodiments, for example, external client 180 can be directly connected to location server 160. Those of ordinary skill in the art will recognize many modifications to the components shown.
[0038] Depending on the desired functionality, network 170 can include any one of a variety of wireless and / or wired networks. For example, network 170 can include any combination of public and / or private networks, local area networks and / or wide area networks, etc. Additionally, network 170 can utilize one or more wired and / or wireless communication technologies. In some embodiments, for example, network 170 can include a cellular or other mobile network, a wireless local area network (WLAN), a wireless wide area network (WWAN), and / or the Internet. Examples of network 170 include an LTE wireless network, a 5G NR wireless network, a Wi-Fi WLAN, and the Internet. LTE, 5G, and NR are wireless technologies defined or being defined by the Third Generation Partnership Project (3GPP). As used herein, the terms “5G NR,” “5G,” and “NR” can be used interchangeably to refer to these wireless technologies. Network 170 can also include more than one network and / or more than one type of network.
[0039] Base station 120 and access point (AP) 130 are communicatively coupled to network 170. In some embodiments, base station 120 can be owned, maintained, and / or operated by a cellular network provider and can employ any one of a variety of wireless technologies, as described below. Depending on the technology of network 170, base station 120 can include a Node B, an evolved Node B (eNodeB or eNB), a base transceiver station (BTS), a radio base station (RBS), an NR NodeB (gNB), a next-generation eNB (ng-eNB), etc. Base station 120 as a gNB or ng-eNB can be part of a next-generation radio access network (NG-RAN), which can be connected to a 5G core network (5G CN) in the case where network 170 is a 5G network. For example, AP 130 can include a Wi-Fi AP or a Bluetooth AP. Thus, by accessing network 170 via base station 120 using the first communication link 133, UE 105 can send and receive information with network-connected devices such as location server 160. Additionally or alternatively, since AP 130 can also be communicatively coupled to network 170, UE 105 can communicate with Internet-connected devices including location server 160 using the second communication link 135.
[0040] The location server 160 may include a server and / or another computing device configured to determine the estimated location of the UE 105 and / or provide data (e.g., "assistance data") to the UE 105 to facilitate location determination. According to some embodiments, the location server 160 may include a Home Subscriber Plane Location (SUPL) Location Platform (H-SLP), which may support the SUPL User Plane (UP) positioning scheme defined by the Open Mobile Alliance (OMA) and may support the location services of the UE 105 based on the subscription information of the UE 105 stored in the location server 160. In some embodiments, the location server 160 may include a Discovered SLP (D-SLP) or an Emergency SLP (E-SLP). The location server 160 may alternatively include an Enhanced Serving Mobile Location Center (E-SMLC), which supports the positioning of the UE 105 using a Control Plane (CP) positioning scheme for the LTE radio access of the UE 105. The location server 160 may also include a Location Management Function (LMF), which supports the positioning of the UE 105 using a Control Plane (CP) positioning scheme for the NR radio access of the UE 105. In the CP positioning scheme, the signaling for controlling and managing the positioning of the UE 105 may use existing network interfaces and protocols and be exchanged between the elements of the network 170 and with the UE 105 as signaling from the network 170. In the UP positioning scheme, from the perspective of the network 170, the signaling for controlling and managing the location of the UE 105 may be exchanged between the location server 160 and the UE 105 as data (e.g., data transmitted using the Internet Protocol (IP) and / or the Transmission Control Protocol (TCP)).
[0041] As described above (and discussed in more detail below), the estimated location of the UE 105 may be based on measurements of RF signals transmitted from the UE 105 and / or measurements of RF signals received by the UE 105. Specifically, these measurements may provide information about the relative distance and / or angle between the UE 105 and one or more components in the positioning system 100 (e.g., GNSS satellites 110, APs 130, and base stations 120). The location of the UE 105 may be geometrically estimated based on the distance and / or angle measurements and the known locations of one or more components (e.g., using multi-angle and / or multilateration techniques).
[0042] Although terrestrial components such as APs 130 and base stations 120 may be fixed, embodiments are not limited thereto. In some embodiments, mobile components may be used. Additionally, in some embodiments, the location of the UE 105 may be at least partially based on the relative distance and / or angle between the UE 105 and one or more other UEs Figure 1estimated by measurements of RF signals transmitted between (which may be mobile or stationary and are not shown). Direct communication between UEs in this way may include sidelink and / or similar device-to-device (D2D) communication techniques. The sidelink defined by 3GPP is a form of D2D communication under the cellular-based LTE and NR standards.
[0043] The external client 180 may be a network server or a remote application that may have some association with the mobile device 105 (e.g., may be accessed by the user of the UE 105), or may be a server, application, or computer system that provides location services to some other user, which may include obtaining and providing the location of the UE 105 (e.g., enabling services such as friend or relative finder, asset tracking, or location of children or pets). Additionally or alternatively, the external client 180 may obtain the location of the UE 105 and provide it to emergency service providers, government agencies, etc.
[0044] As used herein, GNSS refers to SPS, which includes SVs that transmit synchronized navigation signals according to a common signaling format. For example, such GNSS may include a constellation of SVs in a synchronous orbit to transmit navigation signals to locations over most of the Earth's surface simultaneously from multiple SVs in the constellation. The SVs that are members of a particular GNSS constellation typically transmit navigation signals in a format specific to that GNSS constellation. A GNSS receiver (e.g., in the UE 105) may be used to determine the absolute and relative positions of the UE 105. For example, a GNSS receiver may include a receiver that can receive broadcast signals from GNSS satellites such as GPS (USA), Galileo (EU), GLONASS (Russia), Compass, the Quasi-Zenith Satellite System (QZSS) over Japan, the Indian Regional Navigation Satellite System (IRNSS) over India, Beidou (or BDS) over China, etc. The GNSS receiver can determine the absolute positioning and speed of the UE 105 by processing the signals broadcast by the satellites. Since the satellites are always in motion, the GNSS receiver can continuously acquire and track signals from visible satellites and calculate its distance to a set of satellites based on the speed of electromagnetic waves (e.g., the speed of light) and the propagation time of the input signals propagating through space (e.g., the time of flight), and the propagation time can be determined using the local clocks of the satellites and the receiver.
[0045] A GNSS receiver can receive GNSS signals broadcast by three or more GNSS satellites 110. For example, GNSS satellites 110 can operate at an altitude of approximately 20,000 km to approximately 23,000 km and can have a very precise known time and ephemeris. GNSS satellites 110 can broadcast GNSS signals including a pseudo-random code. The GNSS signals can include carrier frequencies in the L band, such as 1575.42 MHz (L1), 1227.6 MHz (L2), or 1176.45 MHz (L5) modulated at approximately 1 MHz and / or approximately 10 MHz. For example, the L1 GPS signal can include a navigation message, a coarse acquisition (C / A) code that is freely available to the public, and an encrypted precise positioning (P) code or P(Y) code (restricted access). The P(Y) code is only used by authorized U.S. military receivers, and the C / A code is not encrypted for general civilian access. The navigation message can be a low bit rate (e.g., approximately 50 bps) message that includes GPS date and time, satellite status and health, satellite ephemeris data (which allows the receiver to calculate the positioning of the satellite), and an almanac including information and status of all GPS satellites (e.g., approximate orbit and status information), such that the GPS receiver knows which satellites are available for tracking. The GNSS signals can travel through near-vacuum space and various atmospheres to reach the Earth and are received by the GNSS receiver. In some embodiments, satellite assistance information can be downloaded from a server for use in determining the position of the GNSS receiver relative to the satellites in combination with the received signals, and based on the known positions of each satellite, determining the position of the GNSS receiver (and UE 105) on the Earth.
[0046] GNSS receivers can typically track three or more (e.g., four or more) satellites within the line of sight of the GNSS receiver antenna and have a small Dilution of Precision (DOP) to receive GNSS signals from the satellites. For each tracked satellite, the GNSS receiver can determine the propagation time of a pseudo-random code that includes, for example, 1023 or more bits. A GNSS receiver using code-based techniques can correlate or align with the pseudo-random noise (PRN) code broadcast by the satellite to determine its time and location. The GNSS receiver can know the PRN code of each satellite and can thus determine the time at which it receives the code from a particular satellite to determine the propagation time. The propagation time can be multiplied by the speed of light in free space to calculate the distance between the GNSS receiver and the particular satellite, which can be referred to as a "pseudo-range" because the calculated distance can include errors (e.g., clock errors of the GNSS receiver and other errors) and may not exactly equal the actual distance. Using positioning techniques such as trilateration techniques, satellite ephemeris data, and the calculated distances between the GNSS receiver and each of three or more satellites, the GNSS receiver can determine the position of the GNSS receiver as the intersection of three or more spheres. Due to the relatively large clock error of the GNSS receiver, the three or more spheres may not intersect at a single point. The GNSS receiver can adjust its own clock to determine the time of flight and pseudo-range until the three or more spheres approximately intersect at a point, which indicates the measured position of the GNSS receiver.
[0047] There can be many errors in GNSS-based positioning systems. For example, the atomic clocks in GNSS satellites are very precise, but they can still drift by a small amount and can thus cause errors of, for example, about ±2 meters. Like satellite clocks, satellite orbits can also have small variations and can thus cause errors of, for example, about ±2.5 meters. To obtain better accuracy, GNSS receivers may need to compensate for the clock errors and orbit errors of the satellites. For example, some GNSS receivers can use carrier-based techniques (such as Real-Time Kinematic (RTK) and Precise Point Positioning (PPP) techniques) to measure the phase of the carrier. Since the carrier of the GNSS signal is a sine wave with a period less than 1 meter (e.g., the period of the L1 carrier signal is approximately 19 cm), more precise time-of-flight measurements can be achieved using carrier-based techniques. In some positioning systems, for example, the GNSS receiver can download correction data from a satellite-based augmentation system (SBAS) or PPP service satellite, or differential GNSS or RTK base stations to further improve the accuracy of positioning.
[0048] For example, in an SBAS system, reference stations geographically distributed throughout the SBAS service area can receive GNSS signals and forward them to a master station. Since the positions of the reference stations are precisely known, the master station can accurately calculate wide-area correction data. The calculated correction data can be uploaded to an SBAS satellite, which can broadcast the correction data to GNSS receivers within the SBAS coverage area. The PPP technique also uses correction data broadcast from satellites. In addition, the PPP technique uses carrier ranging to achieve high precision.
[0049] In a differential GNSS (DGNSS) system, the positioning of a fixed GNSS receiver (referred to as a base station) can be determined with high precision, and the base station can compare the known high-precision positioning with the positioning calculated using GNSS signals. The difference between these two positionings can be attributed to satellite ephemeris and clock errors, as well as errors associated with atmospheric delays. The base station can send these calculated errors to other GNSS receivers (e.g., rovers or vehicle-mounted GNSS receivers), which can use the calculated errors to correct the positioning calculations. The RTK technique also eliminates errors common to base stations and rovers. In addition, the RTK technique uses carrier ranging to achieve high precision.
[0050] GNSS signals can travel in a straight line only in a vacuum or through a completely uniform medium, and they bend when passing through the Earth's atmosphere. The Earth's atmosphere that has the greatest impact on the transmission of GPS (and other GNSS) signals is the ionosphere, which is located approximately 70 km to approximately 1000 km above the Earth's surface and includes ionized gas molecules and free electrons generated by, for example, ultraviolet rays from the sun. The ionosphere can delay satellite signals and can cause a large number of satellite positioning errors, such as ±5 meters. Ionospheric delays can vary with solar activity, time of year, season, time of day, location, etc., and are therefore difficult to predict. Ionospheric delays can also be frequency-dependent and can thus be determined and eliminated by calculating distances using L1 and L2 signals. The ionospheric conditions within a local area can be similar, such that base station and rover receivers can experience similar ionospheric delays. In this way, ionospheric delays can be compensated for using, for example, differential GNSS or RTK systems.
[0051] Another layer of the Earth's atmosphere that can affect GNSS signal transmission is the troposphere, which is the lowest layer of the Earth's atmosphere. The delay caused by the troposphere can be a function of local temperature, pressure, relative humidity, etc. The L1 signal and the L2 signal may be equally affected by tropospheric delay, and thus the effect of tropospheric delay may not be eliminated using GNSS signals of multiple frequencies. The troposphere can be modeled to predict and compensate for most of the tropospheric delay. Since tropospheric conditions are usually similar within a local area, a base station and nearby rover receivers may experience similar tropospheric delays, which can be compensated for in a differential GNSS or RTK system.
[0052] Some of the GNSS signals transmitted by the satellite may be reflected on their way to the GNSS receiver, such as being reflected by buildings. This phenomenon is called multipath propagation. The reflected signal travels a longer distance and is thus delayed relative to the direct signal; and if the reflected signal is strong enough, it may interfere with the direct signal. The delayed signal can cause the receiver to calculate an incorrect location. Multipath errors can be difficult to handle because they are usually local errors that a base station may not experience similarly. Some techniques have been developed where the receiver can consider only the earliest-arriving (or strongest) signal and ignore later-arriving multipath signals. In some cases, expensive high-end GNSS receivers and antennas may be required to reduce long-delay multipath errors and short-delay multipath errors.
[0053] The position of vehicle 102 can also be determined in a similar manner to UE 105. In addition, vehicle 102 and / or UE 105 may include other devices and sensors for positioning. For example, these sensors can include cameras, ultrasonic sensors, radar sensors (e.g., short-range and long-range radar), one or more light detection and ranging (LIDAR) sensors, motion sensors or inertial measurement units (IMUs) (e.g., accelerometers and / or gyroscopes), wheel sensors (e.g., steering angle sensors or rotational sensors), etc. Each of these sensors can generate signals that provide information related to vehicle 102 (or UE 105) and / or the surrounding environment. Each of these sensors can send and / or receive signals (e.g., signals broadcast into the surrounding environment and signals returned from the surrounding environment), which can be processed to determine the attributes of features (e.g., objects) in the surrounding environment.
[0054] The camera can be used to provide visual information related to the vehicle 102 and / or its surrounding environment, for example, for parking assistance, street sign and / or traffic sign recognition, pedestrian detection, lane sign detection and lane departure warning, surround view, etc. Two or more cameras can also be used to determine the distance of environmental features (such as buildings or landmarks) based on the positioning of the two or more cameras and their perspectives on the environmental features. The camera can include a wide-angle lens, such as a fish-eye lens that can provide a large viewing angle (e.g., greater than 150°). Multiple cameras can provide multiple views, and these views can be stitched together to form an aggregated view. For example, images from cameras located on each side of the vehicle 102 can be stitched together to form a 360-degree view of the vehicle and / or its surrounding environment. In some embodiments, the 360-degree view can be provided from an overhead perspective, such as a perspective looking down on the vehicle at a 45-degree angle.
[0055] The ultrasonic sensor array can be located on the front bumper of the vehicle 102. In some embodiments, the vehicle 102 can include ultrasonic sensors on the driver side, passenger side, and / or rear bumper of the vehicle 102. The ultrasonic sensors can emit ultrasonic waves, and the vehicle control system can use the ultrasonic waves to detect objects (such as people, structures, and / or other vehicles) in the surrounding environment. In some embodiments, the vehicle control system can also use the ultrasonic waves to determine the speed, positioning (including distance), and / or other attributes of the object relative to the vehicle 102. For example, the ultrasonic sensors can also be used for parking assistance.
[0056] The radar sensor can emit radio frequency waves, and the vehicle control system can use the radio frequency waves to detect objects (such as people, structures, and / or other vehicles) in the surrounding environment. In some embodiments, the vehicle control system can use the radio frequency waves to determine the speed, positioning (including distance), and / or other attributes of the object. The radar sensor can be located at the corner of the front bumper of the vehicle or on the front dashboard. Some radar sensors can be installed at the rear of the vehicle 102. The radar sensors can include long-range radar, mid-range radar, and / or short-range radar, and can be used for, for example, blind spot detection, rear collision warning, cross-traffic alert, adaptive cruise control, etc.
[0057] The LIDAR sensor can emit infrared lasers, and the vehicle control system can use the infrared lasers to detect objects (such as people, structures, and / or other vehicles) in the surrounding environment, for example, for emergency braking, pedestrian detection, or collision avoidance. In some embodiments, the vehicle control system can use the infrared lasers to determine the speed, positioning (including distance), and / or other attributes of the object. For example, the LIDAR sensor can be located on the top or bottom of the vehicle 102.
[0058] The IMU can measure speed, linear acceleration or deceleration, angular acceleration or deceleration, or other parameters related to the movement of vehicle 102. For example, the wheel sensors can include a steering angle sensor that measures the steering wheel positioning angle and the rotation rate, a rotational speed sensor that measures the rotational speed of the wheel, or another wheel speed sensor.
[0059] In some embodiments, such as during GNSS signal interruption or weakening, or in an environment with spoofing or other abnormal signals, vehicle data (such as wheel ticks, forward / backward signals, steering wheel angles, and other data generated by the sensors described above) can be used to improve the accuracy of GNSS-based positioning systems. For example, when the GNSS signal is weak, unavailable, or noisy (due to noise and interference), the sensor fusion module of the vehicle can use dead reckoning techniques to fuse IMU data, vehicle data, or other sensor data, as well as the previously determined position of the vehicle (e.g., corrected positioning data), to estimate the positioning information of the vehicle. IMU data can include the speed and / or acceleration information of the vehicle, and thus can be used to determine the displacement of the vehicle at a specific moment based on the laws and equations of motion.
[0060] Dead reckoning is a process of using a previously determined position (or position fix) to calculate the current position and advancing (propagating) that position based on the known or estimated elapsed time and the speed along the route. To overcome the limitations of GNSS technology, dead reckoning can be implemented in some high-end navigation systems. For example, satellite signals may be unavailable in buildings, parking lots, and tunnels, and are often severely degraded near urban canyons and trees due to blocked line-of-sight to the satellites or multipath propagation. In a dead reckoning navigation system, the vehicle can be equipped with sensors, etc., that know the wheel circumference and can record the wheel rotation and the steering direction. These sensors typically already exist in the vehicle for other purposes (e.g., anti-lock braking system, electronic stability control, etc.) and can be read by the navigation system from the controller area network (CAN) bus. Then, the navigation system uses, for example, a Kalman filter to integrate the sensor data with the more accurate but occasionally unavailable positioning information from the GNSS receiver into a combined positioning. The Kalman filter can perform a recursive two-stage process including a prediction stage and an update (or correction) stage. The prediction stage can estimate the current state and uncertainty by projecting the previous state and uncertainty forward to obtain a prior estimate of the current state and uncertainty, and the update stage can update the prior estimate based on the current measurement to obtain an improved posterior estimate.
[0061] As described above, each satellite in a GPS system can transmit a PRN code that includes, for example, 1023 or more bits. The PRN code can be unique for each satellite. For each satellite being tracked, a GNSS receiver can determine the propagation time of the PRN code. The GNSS receiver can know the PRN code of each satellite at a given time and can generate an electronic copy using its own clock. Then, the GNSS receiver can compare the copy signal with the received GNSS signal. Since the GNSS signal was actually created in the satellite some time ago (e.g., about 0.07 seconds ago due to the speed of light), the receiver's copy signal needs to be delayed so that the input signal matches the copy signal. This time delay represents the time it takes for the signal to travel from the satellite to the receiver and the error between the satellite clock and the receiver clock.
[0062] In some embodiments, the time delay can be determined by autocorrelation. In autocorrelation, the first bit from the input signal is multiplied by the first bit of the copy signal. For example, if the values of the first two bits of both signals are -1, the result is (-1) × (-1) = +1. Similarly, if the values of both bits are +1, the result is +1. On the other hand, if the two bits do not match, the result is (+1) × (-1) = -1. This process is repeated for the second pair of bits, and so on. The results can be written as a sequence of +1 (bits match) and -1 (bits do not match). Then, this sequence is summed and divided by the total number of bits in each signal. For example, if signal A includes (+1, -1, -1, +1, -1) and signal B includes (+1, +1, -1, -1, +1), then the multiplication results in (+1, -1, +1, -1, -1), the sum of which is -1, and dividing the sum by the number of bits (5) gives -0.2. If the two signals match exactly, the result will be +1. When the two signals include a pseudo-random pattern and are not properly matched in time, the result of the autocorrelation may be close to zero. If the two signals are aligned in time, the result is close to +1 (but not exact because real signals also have noise and thus some bits are incorrect). Generally, the more bits that are compared, the higher the resolution. The autocorrelation function can have the shape of an equilateral triangle with a peak of 1 (if there is no noise), which can be used to find the time displacement that maximizes the autocorrelation.
[0063] During the GPS signal acquisition process, a GNSS receiver can identify the satellites visible to the receiver and provide measurements of the carrier frequency Doppler shift and C / A code delay of the input GPS signal. The Doppler shift in the GPS signal carrier frequency may be caused by the relative velocity of the satellite with respect to the receiver. Satellites in a GNSS system move in fast orbits around the Earth, where the orbits can be different for different constellations (low Earth orbit, medium Earth orbit, coverage, etc.). Thus, although a satellite may transmit at an initial frequency f0, there is a Doppler shift associated with the satellite signal received at the GNSS receiver. This shift is largely due to the motion of the satellite (Δf sat ), and can also be due to the movement of the receiver (Δf receiver ). Therefore, the GNSS receiver can detect the satellite signal at f0 + Δf sat + Δf receiver . The C / A code phase offset is caused by the transmission time of the satellite signal from the satellite to the GNSS receiver. Within a given satellite band, such as L1 for GPS, each satellite typically transmits at the same frequency but uses orthogonal coding so that different satellite signals can be detected and the corresponding pseudorange can be determined at baseband. In contrast, GLONASS satellites share the same coding but use different subbands for satellite signals.
[0064] Acquisition is typically performed by synchronizing a locally generated C / A code and carrier with the received signal. Acquisition is typically performed on data blocks received from the satellite signal, such as a period of the C / A code (e.g., 1 ms). The GNSS receiver can find satellite signals from different satellites in the search space by estimating the Doppler frequency and code delay of each signal. After identifying the available satellites and acquiring the parameters, parallel channels can be used to track the identified satellites. In some embodiments, in each channel, a tracking loop is used to extract navigation data. In the tracking loop, the C / A code and carrier are removed by refining the code phase and Doppler frequency.
[0065] Figure 2A FIG. shows a simplified block diagram of an example signal processing architecture 200 that can be used in a GNSS receiver to implement GNSS signal acquisition and tracking (including grid-based tracking and loop-based tracking, described in further detail below). The signal processing architecture 200 can be implemented in the hardware and / or software components of a GNSS receiver, such as Figure 11 GNSS receiver 1180 and / or Figure 12 GNSS receiver 1280, which will be described in more detail below. The signal processing architecture 200 processes the received signal by comparing it with a frequency F determined at least in part based on a first carrier frequency f1 and a second carrier frequency f2LO is mixed with a local oscillator (LO) signal to process two GNSS signals GNSS1 and GNSS2. As Figure 2A shown, according to a particular embodiment, the signal processing architecture 200 may receive signals GNSS1 and GNSS2 at a single radio frequency (RF) antenna 202, a bandpass RF filter such as a surface acoustic wave (SAW) filter 204, and a low noise amplifier 206. As shown, then, by mixing the received signals with the LO signal, the received GNSS signals may be complex downconverted to an intermediate frequency.
[0066] In this case, "downconversion" may involve transforming an input signal having a first frequency characteristic into an output signal having a second frequency characteristic. In a particular embodiment, although the claimed subject matter is not limited to this aspect, such downconversion may include transforming a first signal into a second signal, where the second signal has a frequency characteristic lower than that of the first signal. Here, in a particular example, such downconversion may include transforming a radio frequency (RF) signal into an intermediate frequency (IF) signal, or transforming an IF signal into a baseband signal and / or baseband information. However, these are merely examples of downconversion, and the claimed subject matter is not limited in this regard.
[0067] In a particular embodiment, by selecting F at approximately the midpoint between f1 and f2 LO , the signal portions downconverted from spectra 202 and 204 may be substantially covered by bandpass filters 208 and 210. Here, for example, the selection of a particular frequency of F LO may result in the image frequency components of one downconverted GNSS signal being substantially overlapped with the desired signal components of another downconverted GNSS signal. In a particular embodiment, the effects of such overlap may be avoided without attenuating the image frequency components prior to mixing with the LO. However, it should be understood that in other embodiments, F LO may be selected at a location other than approximately the midpoint between f1 and f2, and the claimed subject matter is not limited in this regard.
[0068] Then, the in-phase (I) and quadrature (Q) components filtered by the associated BPFs 208 and 210 can be digitally sampled at the analog-to-digital conversion circuits (ADCs) 212 and 214 to provide the digitally sampled in-phase and quadrature components for further processing (e.g., acquisition and / or tracking as described herein). Here, the ADCs 212 and 214 can be adapted to sample the output signals of the BPFs 208 and 210 at the Nyquist rate of the combined signal or higher. Additionally, the presently illustrated embodiments include the ADCs 212 and 214 between the first down-conversion stage and the second down-conversion stage. However, it should be understood that other architectures can be implemented without departing from the claimed subject matter. For example, in other embodiments, the analog-to-digital conversion can occur after the second down-conversion. Similarly, these are merely example embodiments, and the claimed subject matter is not limited in these respects.
[0069] Additionally, in alternative embodiments, the ADCs 212 and 214 can be replaced with a single combined ADC or with a single time-shared and / or multiplexed ADC, where appropriate delays are shared between the in-phase signal path and the quadrature signal path.
[0070] In a particular embodiment, GNSS1 and / or GNSS2 can include any one of several pairs of different GNSS signals. In one particular example, although the claimed subject matter is not limited in this respect, GNSS1 and GNSS2 can be selected such that f1 and f2 are close in frequency to enable low-cost fabrication of the SAW 204 and / or the LNA 206 by restricting the operating frequency band. Although, as shown in the above particular example, GNSS1 and GNSS2 can be selected such that f1 and f2 are close in frequency (e.g., both in the L1 band or both in the L2 band), the claimed subject matter is not limited in this respect. In alternative examples, as shown above, GNSS signals transmitted at more widely separated carrier frequencies can be down-converted to a common intermediate frequency in a single receiver channel. In one particular example, SVs in a GNSS constellation can transmit multiple GNSS signals at different carrier frequencies and / or frequency bands (such as the L1 band and the L2 band).
[0071] In a particular example, the bandwidths of the BPFs 208 and 210 can be centered at a common intermediate frequency IF oNearby to process the GNSS signal portions received from GNSS1 and GNSS2. Additionally, the bandwidths of BPF 208 and 210 can be implemented wide enough to capture sufficient information of the GNSS signals received from GNSS1 and GNSS2 without introducing significant noise outside the frequency bands of spectra 202 and 204. Additionally, BPF 208 and 210 narrow enough can be selected to enable ADC 212 and 214 to sample at a given sampling rate (e.g., approximately at the Nyquist rate) without significant distortion.
[0072] According to a particular embodiment, the sampled in-phase and quadrature components provided by ADC 212 and 214 can be further processed according to complex downconversion and digital baseband 216, which can be used to generate the in-phase and quadrature components and output the pseudorange derived from the GNSS signal. According to some embodiments, the output of complex downconversion and digital baseband 216 can be more broadly referred to as a measurement, where the measurement can include the pseudorange or the pseudorange and carrier phase.
[0073] Figure 2B An example of a two-dimensional search grid 250 that can be used for satellite signal acquisition according to some embodiments is shown. One axis of the search grid 250 is the carrier frequency hypothesis with different Doppler shifts, and the other axis of the search grid 250 is the code phase hypothesis (or code / time delay). The search grid 250 is generally referred to as a search window, although as described below, the dimensions of this search window can be narrowed to reduce the search space. In each search step, the Doppler shift (and thus the frequency of the locally generated carrier) and the delay of the locally generated PRN code can be set according to the date point of the search grid. Then, the received signal from the RF front end can be processed using the Doppler shift and code phase offset, as described above with reference to Figure 2A as described. In many embodiments, if the integration result is greater than the threshold, the frequency of the locally generated carrier signal and the code phase offset can be handed over to the tracking unit / algorithm for further processing. (However, as described below, embodiments can perform verification to determine whether this is a spoofing signal.) When the GNSS receiver is in the tracking mode, the time-frequency search window can be known quite precisely, and when the satellite moves, the satellite can be tracked by moving the search window accordingly, resulting in a corresponding change in the Doppler shift. If the integration result is less than the threshold, the frequency of the locally generated carrier and / or the delay of the locally generated PRN code can be adjusted based on another data point in the search grid until they match the frequency and code phase offset of the received signal, resulting in an integration result greater than the threshold.
[0074] GNSS receivers typically store some information that helps to speed up the process of acquiring satellite signals. When the GNSS receiver is turned on, the last calculated position, time, almanac, etc. can be retrieved. If this information is accurate enough, the receiver can calculate the approximate Doppler frequencies of all visible satellites, such that the receiver does not need to search the entire frequency plane of the search space, or can quickly find the carrier (referred to as a hot start). For example, if the mobile device has the time and approximate location, the positions of the GNSS satellites can be determined relative to the mobile device. Additionally, since the position, heading, and velocity of each GNSS satellite can be determined based on, for example, an ephemeris and / or almanac, the Doppler shift of each satellite can be determined based on the motion of the satellite. Similarly, the motion of the receiver relative to the satellite can be taken into account when determining the Doppler frequency shift experienced by each satellite signal and thus the time and frequency window for finding a given satellite signal.
[0075] In a cold start or non-tracking mode, the GNSS receiver may need to search a larger time-frequency search space for Doppler frequencies and satellites to correlate with the known codes of satellites that are expected to be visible within a frequency range determined based on satellite assistance information and the predicted orbits of visible satellites. The receiver can then select the strongest integration peak, etc., based on the integration of the signal over time relative to the known satellite codes.
[0076] Figure 3 An example of a grid-based search window 300 is shown, which extends across twenty hypotheses in the frequency dimension and 32 code-phase hypotheses or bins in the code-phase dimension. Also, the selection of the specific positions and / or spacings of the hypotheses for each dimension of the search window 300 can be guided by information obtained from an external (also referred to herein as an "injected" position) and / or from one or more previous searches. For example, it may be known or estimated that the desired signal lies within a specific number of chips from a given code phase, and / or that the signal can be found within a specific bandwidth around a given frequency, such that the code-phase search window can be defined accordingly. In the case of searching for more than one code, the associated search windows do not need to have the same dimensions.
[0077] A search can be performed (e.g., a search window of D frequency hypotheses multiplied by C code hypotheses) to obtain a grid of D×C energy results, each corresponding to one of the D frequency hypotheses and one of the C code hypotheses. The set of energy results for the code-phase hypotheses corresponding to a specific frequency hypothesis can be referred to herein as a "Doppler bin".
[0078] Figure 4An example of the energy distribution of twenty Doppler bins or the peaks within a grid is shown, where each bin has 64 code phase hypotheses. In this example, adjacent code phase hypotheses are separated by 1 / 2 chip, such that the grid spans 32 chips in code space. The energy peak in this figure indicates the presence of a selected SV signal at code phase hypothesis 16 in Doppler bin 10. A receiver (or a searcher in such a device) can generate energy grids for several different corresponding SVs from the same portion of the received signal, and these grids may have different dimensions.
[0079] The received signal may include versions of the same transmitted signal that have propagated along different paths and arrived at the receiver at different times. Correlation of such a received signal with a corresponding reference code may produce several peaks at different grid points, each peak being due to a different instance of the transmitted signal (also known as multipath). These multipath peaks may fall within the same Doppler bin. In addition to multipath, spoofing may produce one or more additional peaks. Figure 5 An example of an energy distribution with multiple peaks is shown.
[0080] As described above, in a GPS system, each satellite continuously broadcasts GPS information using a coarse acquisition (C / A) code (e.g., repeated every 1 ms) in the L1 band (e.g., at 1575.42 MHz) and a encrypted precise positioning (P / Y) code in the L2 band (e.g., at 1227.60 MHz) at a data rate of approximately 50 bps. The P(Y) code is encrypted and is used only by authorized U.S. military receivers. The C / A code is not encrypted for general civilian access. In addition, the signals transmitted by GNSS SVs typically have a very low signal strength (e.g., less than approximately -120 dBm) when they reach a GNSS receiver. Thus, radio interference can suppress weak GNSS signals, causing satellite signal loss and potentially resulting in positioning loss. Therefore, civilian GPS can be very vulnerable to spoofing attacks. Malicious actors may exploit this vulnerability and may transmit incorrect information in a competing signal (referred to as a spoofing signal). As described above, this can result in additional energy peaks in the Doppler bins, which the GNSS receiver can then use to determine navigation data or time data that is different from the navigation data or time data determined based on the true GNSS signals. This can cause vehicles relying on GNSS navigation signals to deviate from their routes, or in extreme cases, a GNSS spoofing system can take control of the navigation system and divert the vehicle to an unintended location. Thus, spoofing signals can cause accidents or other damages.
[0081] For example, by having a format similar to or the same as the format of the signal sent by the claimed source, the spoofing signal can have the corresponding claimed source. For example, the spoofing signal can include the same PRN code associated with the claimed satellite. However, the spoofing signal can have some modified parameters, such as time and / or date information, identification, encoded ephemeris or other encoded information, which will cause the mobile device to calculate an incorrect position or be unable to calculate the position. For example, the spoofing signal can simulate the signal of a specific GNSS constellation on a specific frequency band, such as the GPS signal on the L1 frequency band, or can include an analog signal corresponding to multiple GNSS constellations and / or multiple frequency bands. The more complex the spoofing scenario becomes, the greater the technical difficulty in creating / simulating the scenario, and the higher the cost of deploying the spoofing scenario. The spoofing signal can be GNSS-based (e.g., from an SV) or can be ground-based (e.g., from a false base station and / or access point).
[0082] A GPS spoofing attack can include two steps. In the first step (takeover), the spoofing device can lure the victim GPS receiver to migrate from the legitimate signal to the spoofing signal. In some cases, the spoofing device can transmit a forged GPS signal at a high power, causing the victim to lose track of the satellite and lock onto the stronger spoofing signal. In some cases, the spoofing device can transmit a signal synchronized with the authenticated GPS signal and then gradually suppress the authenticated GPS signal to cause the migration. In the latter case, the spoofing signal may not generate abnormal jumps in received signal strength, frequency, or time, but the spoofing device may need to use specialized hardware to track the original signal in real time at the victim's location and synchronize with it. In the second step, the spoofing device can manipulate the GPS receiver by changing the time of arrival of the signal or modifying the navigation message.
[0083] During the time-frequency search for GNSS signal acquisition, the GNSS receiver is most vulnerable to spoofing signals. Spoofing signals can generally be emulated in a coordinated manner and broadcast at a high signal level such that the emulated signal and associated offsets and other characteristics can cause the receiver to calculate an incorrect position or a series of incorrect positions. The spoofing signals can be coordinated by managing the frequency offset of each satellite to make it consistent with a false position or a series of false positions.
[0084] The goal of a spoofing system is to appear as consistent as possible with real GNSS signals, but to give Doppler frequency shifts and / or timing delay shifts consistent with different locations rather than the actual location of the GNSS receiver. To make the spoofing signal reasonably convincing, the time information in the spoofing signal may need to be fairly consistent with the current satellite time of each simulated constellation. For example, the spoofing system may include a GNSS receiver to obtain the current GNSS time and visible satellites. The messages in the spoofing signal may need to be fairly consistent with the messages from actual satellites. The spoofing signal may need to include Doppler shifts consistent with a single but different location. The spoofing system may need to be close to the GNSS receiver such that the signal strength of the spoofing signal can be significantly greater than the actual GNSS signal (e.g., GNSS signal levels in an outdoor environment).
[0085] Since the detection and ranging of GNSS signals are done in the baseband by correlation, changing the frequency shift to be consistent with different locations on all visible satellites may be sufficient to change the location calculated by the GNSS receiver. In one example, the spoofing system may receive existing GNSS signals, change the frequency of each satellite signal to be consistent with the Doppler shift of the spoofing location, and rebroadcast the changed signals at a stronger signal strength based on known satellite positions (via downloaded or demodulated assistance data), the speed and direction of each satellite, and the spoofing location. In some embodiments, the coded time of day may also be changed, which may not be necessary for relatively short distances.
[0086] Figure 6Shows an example of an abnormal GNSS signal in an example of a positioning system 600. The positioning system 600 may be similar to the positioning system 100 and may include, for example, a vehicle 102, a UE 105, a satellite 110, a base station 120, an AP 130, a location server 160, a network 170, and an external client 180. The positioning system 600 may also include an SV 610 and a satellite signal emulator 620, which may send abnormal GNSS signals. For example, the SV 610 may send an abnormal GNSS signal 612 to the UE 105. The abnormal GNSS signal 612 has a carrier frequency, where the carrier frequency may be the frequency used by the UE to determine its position using GNSS signals, such as the L1 frequency (1575.42 MHz) of the GPS system. The abnormal GNSS signal 612 may be abnormal in one or more aspects. For example, the abnormal GNSS signal 612 may be a spoofing signal, generated in the format associated with the SV 610 but inaccurate, such as having incorrect timing, which may lead to an inaccurate determination of the distance from the UE 105 to the SV 610. As another example, the abnormal GNSS signal 612 may be a spoofing signal with a format associated with another SV, such as another SV in the same constellation as the SV 610 or another SV in a different constellation. In this case, the pseudorange determined for the abnormal GNSS signal 612 may correspond to the distance from the UE 105 to the SV 610, but the UE 105 may use this distance as the distance to the expected position of another SV from the UE 105 (e.g., as indicated by ephemeris data). In either of these scenarios, if the UE 105 does not recognize the abnormal GNSS signal 612 as abnormal and thus does not take appropriate actions, such as not using the abnormal GNSS signal 612 and / or determining the position of the UE 105 based on the pseudorange determined from the abnormal GNSS signal 612, the UE 105 may receive inaccurate information in the signal in the format of the SV 610 or a signal simulating the format of another SV, and the UE 105 may calculate an incorrect position of the UE 105.
[0087] In another example, the UE 105 may receive an anomalous GNSS signal 622 from a satellite signal simulator 620 (e.g., a spoofing device). The satellite signal simulator 620 may be a GNSS signal simulator configured to generate and transmit signals that simulate GNSS signals. The anomalous GNSS signal 622 may thus simulate a signal from an SV such as satellite 110 (e.g., having a format corresponding to the SV (e.g., a pseudorandom code)). When received by the UE 105, the anomalous GNSS signal 622 may have a much higher power (and corresponding Doppler bin peak) than a non-anomalous GNSS signal from satellite 110, which may cause the UE 105 to acquire and track the anomalous GNSS signal 622 instead of the non-anomalous GNSS signal actually transmitted by satellite 110 as described above.
[0088] Figure 7 An example is shown of how spoofing by a spoofing device 724 can affect the estimated location of a vehicle using GNSS-based positioning. The spoofing device 724 (which may be mobile or stationary) may be an example of the satellite signal simulator 620. The spoofing device 724 may include an antenna 728 and a transmitter 732. The spoofing device 724 may generate a spoofing signal 726 received by the vehicle antenna 720. The spoofing signal 726 may be a composite signal that includes multiple false GNSS satellite signals. The spoofing signal 726 may be generated to mimic a real GNSS satellite signal.
[0089] In some embodiments, the spoofing device 724 may be located at a fixed geographic location. In some embodiments, the spoofing device 724 may be mobile (e.g., attached to a vehicle, drone, or boat). For example, the spoofing device 724 may be on a tower or other broadcast point, or may be in a car or other moving vehicle (e.g., vehicle 700) following a target. It may be more difficult to detect a situation where a mobile spoofing device 724 provides a spoofing signal that is only slightly different from an actual GNSS signal, and in such a case, according to some embodiments, the positioning engine of a GNSS receiver at a mobile device may be more reliant on non-GNSS data sources for positioning. For example, a Bluetooth transceiver located at an ATM may be used to verify that a GNSS position matches a location near the ATM via a secure (handshake, public-private key exchange, etc.) short-range signal from the ATM (e.g., the distance can be determined using round-trip time (RTT) or signal strength ranging techniques), thereby verifying that the mobile device is near the ATM.
[0090] The spoofing device 724 can be designed to create false GNSS satellite signals in several ways. In some embodiments, the spoofing device 724 can create a spoofing signal 726 by simulating a real GNSS satellite signal programmed with desired false satellite data. For example, the spoofing device 724 can capture real GNSS signals 702, 704, 706, and 708 at the antenna 728 and then modify and retransmit these signals with the transmitter 732. The spoofing device 724 can create a spoofing signal 726 by retransmitting a live GNSS signal that includes false GNSS data (e.g., for a first location) to be accepted as a real GNSS signal by a GNSS receiver (e.g., at a second location). The spoofing device 724 can also simulate a stationary or moving position. For example, the spoofing device 724 can simulate a position that forms a circle around a geographical area.
[0091] The spoofing signal 726 can be a composite signal of multiple GNSS signals 702, 704, 706, and 708 received by the antenna 720. When the GNSS signals 702, 704, 706, and 708 are retransmitted from the spoofing transmitter, they become false GNSS satellite signals because they contain data received by the spoofing antenna 728 at a location different from the true location, resulting in a spoofed location 730. The spoofing signal 726 can contain any number of false GNSS satellite signals.
[0092] The power level of the spoofing signal 726 can be set such that when the spoofing signal 726 is received by the antenna 720, the spoofing signal 726 suppresses the real GNSS signals 702, 704, 706, and 708. Thus, based on the false GNSS satellite signal, the receiver 722 can use the spoofing signal 726 to calculate a GNSS position. Specifically, the receiver 722 can measure the GNSS satellite signal phase (code phase and / or carrier phase) values of the spoofing signal 726, use the code phase and / or carrier phase values to calculate the GNSS position coordinates of a position different from the true position, and report that the vehicle is at a different position than its true position. It may be the intention of the spoofing device 724 to make the receiver 722 believe and report that the vehicle 700 is at a false position different from the true location (e.g., the spoofed location 730). The navigation system can also be spoofed to cause the navigation device to provide incorrect timing data.
[0093] To address spoofing attacks, the systems and methods according to the present disclosure can use various techniques to detect potential GNSS spoofing and reduce or minimize the impact of spoofing signals on the positioning and navigation of a mobile device. These techniques can be performed by software and / or hardware components of a UE, such as a mobile device or a vehicle. This can include circuitry and / or software that is included in the GNSS receiver and / or the application processor, and the software is executed by the GNSS receiver and / or the application processor.
[0094] In some embodiments, the GNSS receiver can detect spoofing signals based on signal strength. As described above, at the GNSS receiver, spoofing signals generated by a spoofing device (e.g., satellite signal simulator 620 or spoofing device 724) typically have a signal strength greater than that of the true GNSS signals transmitted by GNSS SVs in order to lure the GNSS receiver to lock onto the stronger spoofing signal. Thus, a sudden increase in signal strength or a signal strength above a threshold will indicate that the detected signal may be a spoofing signal. For example, the threshold can be the typical GNSS signal strength in open sky conditions or another signal environment. When the signal strength remains above the threshold, the signal may be a spoofing signal. In some embodiments, the threshold can be determined through crowdsourcing. In some embodiments, the programmable gain amplifier (PGA) of the GNSS receiver can be monitored, and a PGA output reaching the positive or negative rail can indicate the presence of a strong spoofing signal. In some embodiments, an increase in the signal-to-noise ratio or carrier-to-noise ratio can indicate that the received signal is a potential spoofing signal. In some embodiments, an increase in the noise floor can also indicate that the received signal is a potential spoofing signal.
[0095] In some embodiments, the GNSS receiver can detect spoofing signals by detecting a time discontinuity at the GNSS receiver. A time discontinuity can occur when the spoofing device is not synchronized with GNSS time or when there is a significant delay in the spoofing signal transmitted by the spoofing device. As described above, the spoofing device may take time to acquire the true GNSS signals and generate spoofing signals, and thus there may be a significant delay in generating spoofing signals at the spoofing device. Therefore, when a GNSS receiver that has been synchronized with GNSS time acquires and uses spoofing signals to determine location and time (e.g., in the hot mode), the GNSS receiver can detect a time change that may be approximately equal to the time delay associated with the processing time at the spoofing device.
[0096] In some embodiments, a GNSS receiver can detect spoofing signals by detecting a sudden change in the signal frequency of GNSS signals at the GNSS receiver, specifically when all signals are coherently affected to indicate a new location. In some embodiments, the Doppler shift and / or phase delay of the received GNSS signals can be compared to determine whether a signal with a higher intensity is abnormal (signals outside the expected time window and / or Doppler window are identified as abnormal). Additionally or alternatively, the approximate location of the mobile device (e.g., determined based on wide area network (WAN) and / or WLAN signals or other sensor data as described above) can be used to determine the expected Doppler shift and phase shift, and GNSS signals that are significantly different from the expected Doppler shift and / or phase shift can be identified as potential spoofing signals.
[0097] In some embodiments, a GNSS receiver can detect spoofing signals by detecting a sudden change in the calculated location. As described above, the GNSS receiver can be in a tracking mode, where the determined GNSS pseudorange can be fed into a Kalman filter or another position propagation filter. The position propagation filter can determine the propagated location, and the GNSS receiver can also predict the location based on the pseudorange determined using GNSS signals. If the difference between the propagated location and the predicted location is greater than a threshold, a positioning jump may occur when the GNSS pseudorange is used. Therefore, the system may have locked onto a spoofing signal rather than a genuine GNSS signal. In some embodiments, as described above, other sensors such as motion sensors, ultrasonic sensors, radar sensors, LIDAR sensors, wheel sensors, etc. can be used to predict the location of the vehicle, such as in positioning using dead reckoning techniques (e.g., pedestrian dead reckoning or automotive dead reckoning), and then the predicted location can be compared with the predicted location using the GNSS pseudorange. If the difference is greater than the threshold, the GNSS signal used to determine the pseudorange may be a spoofing signal. In some embodiments, the location predicted based on GNSS signals can be compared with the location determined based on, for example, Wi-Fi and / or WAN-based trilateration and / or dead reckoning. If the difference is greater than the threshold, the GNSS signal used to determine the pseudorange may be a spoofing signal. In some embodiments, if the location predicted based on GNSS signals (and / or the history of the location) does not match certain features on a map or the surrounding environment (e.g., on land rather than on water, as determined using a camera) (e.g., a straight street indicated by the GNSS signal rather than a circle), the GNSS signal may include a spoofing signal. For example, if the GNSS receiver is on a street, but the GNSS signal indicates that the GNSS receiver is in a different environment (e.g., on a boat), the GNSS signal may include a spoofing signal.
[0098] In some embodiments, inconsistencies between GNSS signals received from different constellations or different frequency bands (e.g., the difference in pseudorange and / or the resulting position estimate of the GNSS receiver exceeds a threshold distance) may indicate that some signals may be spoofing signals. If the signals remain inconsistent by more than a threshold amount, such as an amount that cannot be explained by GNSS multipath, then some signals may be spoofing signals. The threshold amount may be a fixed threshold or may be determined by measuring GNSS multipath on the received signals.
[0099] As described above, GNSS signals can be received by a GNSS receiver from satellites via multipath propagation. Thus, a GNSS receiver may find multiple peaks during GNSS signal acquisition. Multipath propagation may cause the determined position to deviate by several hundred meters, but generally may not cause the calculated position to deviate from the true position by more than several hundred meters, such as in another city or another country. Additionally, the multiple peaks caused by multipath propagation may be inconsistent in time and / or position. Thus, the multiple peaks caused by multipath propagation can be distinguished from the multiple peaks caused by spoofing signals. In some embodiments, the GNSS receiver may track two or more sets of self-consistent GNSS signals by using a least squares fitting technique and solving for the position (e.g., x, y, and z coordinates) of the mobile device and the coarse and fine time for each corresponding set of self-consistent GNSS signals. If the positions determined using two or more sets of self-consistent GNSS signals are inconsistently different in a consistent manner, then at least one set of GNSS signals may be a spoofing signal. In one example, the measurement of a first set of GNSS signals may result in a position, while the measurement of signals in a second set of GNSS signals, although having a stronger received power, may converge around a different position that may be far from the first position, then the second set of GNSS signals may be identified as a potential spoofing signal. In such a scenario, there may be two clusters of positions, one cluster close to the position based on historical data and / or other input data, and the other cluster clustering around a simulated position that may not be the actual position. In some embodiments, two or more sets of GNSS signals may be tracked in parallel. In some other embodiments, the GNSS signals may be saved to memory and may be processed or reprocessed to separately track two or more sets of GNSS signals.
[0100] In some embodiments, if the received signals are inconsistent with the surrounding environment, the GNSS receiver may identify spoofing signals based on knowledge of the surrounding environment. For example, if the GNSS receiver is in a noisy environment or an environment that should have multipath signals, but the received signals are abnormally clean or have very low multipath peaks and / or are consistent, then the received signals may include spoofing signals.
[0101] In some embodiments, signals identified as potential spoofing signals can be reexamined to determine if the signal is indeed a spoofing signal. For example, one or more of the techniques described above for identifying potential spoofing signals can be repeated or combined at different times to determine and / or cross-check if the signal is a spoofing signal.
[0102] In some embodiments, a mobile device (e.g., a vehicle or a mobile device) can use any of the methods or any combination of methods described above to detect potential spoofing signals, and can mitigate the effects of potential spoofing signals by, for example, ignoring the identified spoofing signals to support non-spoofed and / or more reliable data sources. The mobile device can also flag spoofing signals to other devices, such as via a location server or base-station-based alerts, or by marking the signal source in the auxiliary data as unreliable.
[0103] In some embodiments, a set of strong signals (especially if the strong signals are from the same GNSS constellation and the same frequency band) can be used to determine a location, and then the location can be verified against ground position signals, the output of a position propagation filter (e.g., a Kalman filter), and / or a recently stored location (e.g., less than an hour ago). If there is a significant inconsistency, the weaker GNSS signals stored in memory can be used to determine the location, while the stronger signals can be ignored. Additionally or alternatively, an assisted GNSS signal search can be performed to identify secondary or lower-intensity correlation peaks to calculate the true location. For example, specifically, if the weaker peaks are approximately consistent with a predicted or known location, additional correlation peaks (including those further away from the strong detected correlation peaks) can be reported to and utilized by the location engine. In some embodiments, the search window can be set based on the weaker GNSS signal source, historical data, ground signal sources, and / or time information such that anomalous signal sources can be excluded from the search window.
[0104] In one example, after a spoofing signal is detected, the GNSS receiver associated with the mobile device can ignore all GNSS signals and rely on other location information sources, such as Wi-Fi and WAN signals, other sensor inputs, dead reckoning outputs, etc. For example, if the mobile device includes a mobile phone, Wi-Fi-based, WAN-based, or hybrid trilateration or transceiver ID-based positioning techniques can be used (possibly in combination with dead reckoning and sensor results) to determine the actual location of the mobile phone. If the mobile device includes a vehicle, positioning, map matching, or other positioning techniques based on the output of other sensors (e.g., cameras, LIDAR, IMU, etc.) can be used to determine the actual location of the vehicle.
[0105] In some embodiments, since the true GNSS signals are still present (even when the GNSS receiver may acquire the spoofing signal due to the higher signal strength of the spoofing signal), the GNSS receiver in the tracking mode can narrow, tighten, or only maintain the current search window for each satellite to exclude the stronger spoofing signal. In some embodiments, based on the output from a position propagation filter (e.g., a Kalman filter using non-GNSS sources or historical propagated positions) and satellite assistance data, if the GNSS receiver is not already in the tracking mode, the GNSS receiver can predict the correct search window.
[0106] Figure 8 An example of grid-based tracking of GNSS signals (or more precisely, the energy peaks corresponding to the GNSS signals) using a propagated search window in accordance with certain embodiments is shown. As described above, to acquire a GNSS signal, the GNSS receiver can vary the carrier frequency and code phase offset to search for the correlation peak between the GNSS signal received from a satellite by the GNSS receiver and the locally generated PRN signal. The search can be performed within a search window in a grid 800 (similar to Figures 2B to 5 the grid shown), where the GNSS receiver can vary the carrier frequency and code phase offset based on the corresponding carrier frequency hypotheses and code phase hypotheses associated with each grid point in the search window.
[0107] In Figure 8In the example shown, a previous search may obtain GNSS signal 810 with an associated code phase (or code phase offset) and a corresponding frequency (due to Doppler shift). For example, based on the code phase and frequency of the previously obtained GNSS signal 810, information such as the position and / or velocity of the satellite and / or the position and / or velocity of the mobile device, and / or previous search window and / or time and / or satellite ephemeris information, search window 805 may be determined. Search window 805 may be a narrow or tight window because the distance and relative velocity between the mobile device and the satellite do not change suddenly, and thus the code phase offset and Doppler shift of the new GNSS signal 812 do not change drastically either. On the other hand, in order for the GNSS receiver to determine a position very different from the true position, spoofing signals may have very different code phase offsets and / or frequency offsets, as shown by spoofing signals 820, 822, or 824, which may be outside search window 805 and thus may not be acquired or locked by the GNSS receiver. Therefore, spoofing signals may not have an obvious impact on positioning. The search window for subsequent GNSS signal acquisition may be determined similarly to acquire true GNSS signals 814, 816, etc. in subsequent sampling periods (e.g., every millisecond or every second). That is, during a cold start, when a wider window can be used, the search may still pick up spoofing signals (or for any other reason when a wider window is used, such as when the GNSS receiver loses lock on the signal), and at this time the conventional algorithm using the strongest peak will be hijacked by the spoofing signal.
[0108] It can be noted that, according to some embodiments, in a multipath environment, due to signal bounce, GNSS signals (e.g., GNSS signal 810) may occasionally jump out of search window 805 (e.g., for a relatively small number of sampling periods). However, in such an embodiment, there may be a second larger window (not shown) that includes search window 805 representing the limits of such multipath jumps. The size of this larger window may be based on the maximum possible multipath expected in a typical dense urban environment (e.g., resulting in a positioning error of up to one city block or an error of several hundred meters). In such a multipath environment, when there is a direct line of sight / if there is a direct line of sight, GNSS signals may sporadically return to the window. Further, each satellite may have different multipath because they all transmit signals from different regions of the sky and have different velocity vectors (which affect frequency / Doppler differently). It can also be noted that the search window may be static or may be enlarged for a high multipath environment so as not to lose track of the satellite signal in a high multipath environment.
[0109] In some embodiments, as described above, two or more search / tracking windows, such as search windows 805 and 830, may be used to track two or more sets of signals, such as true GNSS signals 812 and spoofing signals 822. In some embodiments, the spoofing signal (e.g., a stronger signal and / or a signal having a larger jump compared to a previous signal) may be subtracted from the digital signal data in the baseband to enhance the reception of the true GNSS signal. For example, the GNSS signal may first be saved to a memory. After the spoofing signal is identified, the spoofing signal may be subtracted from the saved GNSS signal. In some embodiments, active poles having the frequency and code phase offset of the spoofing signal may be inserted to attempt to remove the spoofing component.
[0110] In some embodiments, a wider search window may be used, where the GNSS receiver may not discard weaker correlation peaks, but instead may identify a cluster of peaks consistent with the current position predicted based on other sources and ignore stronger peaks inconsistent with the position continuity prediction (since a mobile device does not suddenly jump to a far-away location) and / or peaks inconsistent with other sources. This technique may be used all the time for spoofing mitigation, or may be used only when a potential spoofing signal is detected using the techniques described above.
[0111] As described above, spoofing signals may also be generated by enemy-launched satellites, where the spoofing signals may cause interference in the GNSS band or may include pseudo GNSS signals. Depending on the signal energy utilized, the techniques described above and, in some embodiments, longer integration periods, active isolation and cancellation of the pseudo signals in the baseband, and / or active window management (e.g., based on different Doppler profiles of non-co-located satellites) may be used to mitigate the impact of the spoofing signal on positioning. In some embodiments, by depicting the Doppler frequency shift relative to the orbit, the source of the spoofing signal, such as the satellite and satellite constellation generating the spoofing signal, may also be determined.
[0112] In some embodiments, information about spoofing signals, such as the area in which the spoofing signal is detected, the characteristics of the mobile spoofing device (e.g., the license plate or digital identifier or other identifying characteristics of the vehicle transmitting the spoofing signal), etc., may be crowdsourced from various GNSS receivers or mobile devices. For example, this information may be sent to other GNSS receivers or a location server, which may collate the received information to generate specific assistance data including information such as the spoofing area. Then, the location server may broadcast the assistance data to the GNSS receivers.
[0113] Figure 9Ais a flowchart showing an example of method 900-A for determining the correct location of a mobile device in the presence of GNSS spoofing according to certain embodiments. For example, the mobile device may include a mobile phone, a vehicle, and / or other types of UEs or electronic devices. It should be noted that Figure 9A the operations shown and described herein provide specific positioning techniques to detect and mitigate the impact of spoofing signals on positioning. According to alternative embodiments, other sequences of operations may also be performed. For example, alternative embodiments may perform the operations in a different order. Additionally, Figure 9A each of the operations shown may include multiple sub-operations, which may be performed in various orders suitable for each operation. Additionally, depending on the specific application, some operations may be added or removed. In some implementations, two or more operations may be performed in parallel. Those of ordinary skill in the art will recognize many variations, modifications, and substitutions. In various embodiments, for example, the components for performing the functions shown in method 900-A may include the GNSS receiver and / or processing unit of the mobile device, and the GNSS receiver and / or processing unit may include hardware and / or software components for performing the described functions. For example, the components for performing the operations in method 900-A may include various components of the mobile device, such as the wireless communication interface 1130, the wireless communication antenna 1132, the bus 1105, the digital signal processor (DSP) 1120, the processing unit 1110, the memory 1160, the GNSS receiver 1180, and / or other components of the mobile device 1100, as follows Figure 11 shown; and / or the wireless communication interface 1230, the wireless communication antenna 1232, the bus 1205, the digital signal processor (DSP) 1220, the processing unit 1210, the memory 1260, the GNSS receiver 1280, and / or other components of the mobile device 1200, as follows Figure 12 shown.
[0114] The functionality at block 905 includes determining a non-GNSS location of the mobile device based on location information from one or more non-GNSS data sources. Here, the location information from one or more non-GNSS data sources can include any one of a variety of information indicating the location of the mobile device from the data source (other than current GNSS information). Thus, the location information can include multilateration of the mobile device based at least in part on signals from ground transceivers (e.g., RAT-based positioning, WLAN-based positioning, etc.), WAN cell sector centers, access point (AP) locations (e.g., based on the location of the nearest AP), map data, sensor data, or dead reckoning location information or a combination thereof. The sensor data can also vary depending on the sensors available to the mobile device. For example, the sensor data can include data from motion sensors, magnetometers, wheel sensors, cameras, radars, LIDARs, or sonar sensors or a combination thereof.
[0115] It can be noted that while non-GNSS positioning may not be based on the current GNSS signal, it may be at least partially based on previous GNSS information. For example, non-GNSS positioning can be provided by a positioning engine (e.g., a Kalman filter) that can use information from various data sources (including the aforementioned ground transceivers, sensors, etc.), as well as historical location / previous positioning that may have used GNSS information (e.g., previous GNSS location information).
[0116] As described in more detail below (e.g., with reference to Figure 12 ), in view of data from one or more location data sources, the application processor can determine and / or obtain the non-GNSS location of the mobile device (e.g., using a positioning engine). The application processor can then provide the location and / or provide data to the GNSS receiver such that the GNSS receiver can define a search window in view of the non-GNSS location. In such an embodiment, method 900-A can also include receiving the non-GNSS location at the GNSS receiver of the mobile device from the application processor of the mobile device.
[0117] At block 910, the functionality includes receiving a first GNSS signal at the mobile device. For example, this can include obtaining the first GNSS signal from a cold start receiver. Starting from a cold start, the GNSS receiver can search a very large search space. For example, the search window can include up to an entire country or more, or as small as the maximum antenna range of a ground transceiver. However, with location information, this search basis may be narrowed somewhat. For example, if the mobile device has access to the most recent previous location or infrastructure-based (e.g., RAT-based or WLAN-based) location, the search space can be narrowed around the current location and current time (if available). (However, it can be assumed that the search window is wide enough and / or that spoofed GNSS signals are close enough in frequency and phase offset such that the spoofed GNSS signals are captured by the current search window parameters.) Additionally, according to some embodiments, the GNSS receiver can save processing power by searching for a single satellite and then using ephemeris and time to determine the positions of other satellites.
[0118] At block 920, the functionality includes determining that the first GNSS signal includes a frequency that differs from a predicted frequency by more than a threshold frequency difference, a code phase that differs from a predicted code phase by more than a threshold code phase difference, or both, for a predicted frequency and predicted code phase based on non-GNSS positioning. As described herein, an approximate position of a satellite relative to the mobile device can be determined based on an approximate location of the mobile device (e.g., non-GNSS positioning of the mobile device), time, and / or time uncertainty and / or ephemeris data of the satellite. In some embodiments, ephemeris information can be used to detect spoofing. Ephemeris information can include long-term ephemeris, regular ephemeris sent from a location server, and / or demodulated ephemeris for each satellite, and can be used to determine an approximate position of a given satellite at a particular time. Using this information, the GNSS receiver can determine the predicted frequency and code phase of the GNSS signal from the satellite. Using the confidence and / or accuracy of the non-GNSS positioning, historical information, and / or other relevant data, the mobile device can determine the thresholds for the frequency difference and phase difference within which GNSS signals from the satellite are expected.
[0119] At block 930, the frequency includes receiving a second GNSS signal within a search window based on non-GNSS positioning, a threshold frequency difference, and a threshold code phase difference. Here, for example, the frequency window may be centered on non-GNSS positioning and sized according to the threshold frequency difference and the threshold code phase difference. Specifically, according to some embodiments, the search window may be selected such that the first GNSS is outside the search window. Additionally, the search window may be implemented using one or more tracking loops (e.g., implementing loop-based acquisition / tracking). Additionally or alternatively, the search window may be part of a two-dimensional tracking grid that includes different combinations of code phase offsets and signal frequencies (e.g., grid-based acquisition / tracking). Conventional loop-based and grid-based acquisition / tracking typically acquire and track the strongest signal (which may often be a spoofing signal). Thus, establishing the search window in the manner provided at block 930 may enable a GNSS receiver to acquire and track a legitimate GNSS signal (within the expected or predicted search space) in the presence of a spoofing signal with stronger power.
[0120] At block 940, method 900-A includes determining a measurement for the second GNSS signal. For example, the measurement may include pseudorange or pseudorange and carrier phase. According to some embodiments, if the measurement of the second GNSS signal results in an estimated position that is consistent within a threshold amount with the non-GNSS positioning (e.g., estimated by a positioning engine), then the second GNSS signal may be determined to be a legitimate GNSS signal and the first GNSS signal may be determined to be a spoofing signal. (It may be noted that, to determine the estimated position, multiple satellites (e.g., three or more) may be used to determine the estimated position. And thus, the second GNSS signal may be one of many signals used to determine the estimated position of the mobile device.) Thus, some embodiments of method 900-A may also include determining an updated position of the mobile device based on the measurement (e.g., pseudorange) of the second GNSS signal and / or determining the first GNSS signal as a spoofing signal. As described elsewhere herein, determining whether a pseudorange results in an estimated position that is "consistent" with non-GNSS positioning may involve determining a least squares fit or other position calculation, where the fit / error terms may be analyzed (e.g., relative to a threshold) when the position is determined using the first GNSS signals of multiple satellites.
[0121] According to some embodiments, method 900-A may further include subtracting a spoofing signal from a plurality of received signals to receive a second GNSS signal. According to some embodiments, the first GNSS signal is received by the mobile device via a first frequency or GNSS constellation, and the second GNSS signal is received by the mobile device via a second frequency or GNSS constellation. Additionally or alternatively, determining the first GNSS signal as a spoofing signal may be at least partially based on determining that the first signal is from a first constellation and is inconsistent with the position of the mobile device determined using a second constellation.
[0122] Determining the first GNSS signal as a spoofing signal may be performed in any of a variety of ways depending on the desired functionality. For example, according to some embodiments, determining the first GNSS signal as a spoofing signal may be at least partially based on the signal strength of the spoofing signal being greater than a threshold. According to some embodiments, the threshold may be determined based on the GNSS signal strength level under open sky conditions.
[0123] According to some embodiments, determining the first GNSS signal as a spoofing signal may include: determining the location of the mobile device based on the received signals including the first GNSS signal, and identifying the received signals as including a spoofing signal based on determining that the determined location is inconsistent with a non-GNSS location. Additionally or alternatively, determining the first GNSS signal as a spoofing signal may include obtaining the first GNSS signal and identifying the first GNSS signal as a spoofing signal based on determining that one or more positions determined from the pseudorange of the first GNSS are inconsistent with map data. Here, as described in further detail below, such an inconsistency may include the mobile device being located at a position that is not possible from the perspective of the map data.
[0124] According to some embodiments, determining the first GNSS signal as a spoofing signal may include determining that the difference between the signal frequency of the first GNSS signal and the signal frequency of a previously captured GNSS signal is greater than a threshold. That is, the first GNSS signal frequency may be inconsistent with historical data regarding the corresponding GNSS signal frequency.
[0125] According to some embodiments, determining that a first GNSS signal is a spoofing signal may include obtaining two sets of self-consistent signals, where one set of self-consistent signals includes the first GNSS signal. In such an embodiment, determining the corresponding location of the mobile device may be based on the set of self-consistent signals that does not include the first GNSS signal. Such an embodiment may also include identifying the set of self-consistent signals that includes the first GNSS signal as including a spoofing signal based on the difference between two corresponding locations. If two sets of self-consistent signals are detected, the set of signals closest to the non-GNSS location may be determined to be legitimate GNSS signals, and the other set of signals may be determined to be spoofing signals. Here, the self-consistent signals indicate that the error estimate of the least squares fit is rather small. If there is a tight fit / small error in a set of self-consistent signals that is inconsistent with the non-GNSS location, it may indicate spoofing (e.g., rather than multipath). Multipath affects different satellites differently (e.g., satellites of the same or distant constellations), which may result in larger errors.
[0126] According to some embodiments, determining that a first GNSS signal is a spoofing signal includes obtaining the first GNSS signal and identifying the first GNSS signal as a spoofing signal based on (i) determining that the change in the code phase of the first GNSS signal exceeds a threshold code phase change, (ii) determining that the change in the frequency of the first GNSS signal exceeds a threshold frequency change, or (iii) both. As described above, these changes may occur between sampling periods. Exceptions for multipath may be provided, where (as described above) a larger search window may be used to account for frequency and / or code phase jumps based on multipath.
[0127] According to some embodiments, detecting a spoofing signal may include obtaining the first GNSS signal and identifying the first GNSS signal as a spoofing signal based on determining that the rate of change of the code phase, frequency, or both of the first GNSS signal is different from a previously determined or predicted rate of change that exceeds a threshold. For example, if spoofed, the determined location of the mobile device may change more than has been observed (historical data) or expected (e.g., based on motivated movement). For example, a vehicle rarely travels at speeds exceeding 100 mph on a highway and may only be 30 - 50 mph in the city. A pedestrian's movement speed generally does not exceed 10 mph. Therefore, if the mobile device knows the type of movement (driving, walking, etc.), the type of movement may be used to determine the maximum thresholds for code phase change and frequency change. The type of movement may be determined by the application processor based on, for example, sensor inputs and / or other data.
[0128] Figure 9B is a method 900-B of an example embodiment showing the use of information about spoofing signals to process and / or classify GNSS signals. Additionally, Figure 9BThe operations shown and described herein provide specific techniques for detecting and mitigating the effects of spoofing signals on the positioning of a mobile device. Figure 9B Some or all of the functions shown in the block of Figure 9A can be performed in combination with some or all of the functions shown in the block of Figure 9B According to alternative embodiments, other sequences of operations may also be performed. For example, alternative embodiments may perform the operations in a different order. Additionally, Figure 11 each of the operations shown may include multiple sub-operations, which may be performed in various orders suitable for each operation. Additionally, depending on the specific application, some operations may be added or removed. In some implementations, two or more operations may be performed in parallel. Those of ordinary skill in the art will recognize many variations, modifications, and substitutions. In various embodiments, for example, the components for performing the functions shown in flowchart 900-B may include the GNSS receiver and / or processing unit of the mobile device, and the GNSS receiver and / or processing unit may include hardware and / or software components for performing the described functions. For example, the components for performing the operations in flowchart 900 may include various components of the mobile device, such as wireless communication interface 1130, wireless communication antenna 1132, bus 1105, digital signal processor (DSP) 1120, processing unit 1110, memory 1160, GNSS receiver 1180, and / or other components of mobile device 1100, as shown Figure 11 below; and / or wireless communication interface 1230, wireless communication antenna 1232, bus 1205, digital signal processor (DSP) 1220, processing unit 1210, memory 1260, GNSS receiver 1280, and / or other components of mobile device 1200, as shown Figure 12 below.
[0129] At block 960, the function includes determining that a first GNSS signal received at the mobile device is a spoofing signal. The determination that the first GNSS signal is a spoofing signal can be made using any of the techniques described herein (e.g., comparison of frequency and / or code phase with predicted frequency and / or code phase based on non-GNSS position, exceeding a signal strength threshold, inconsistency with map data, etc.).
[0130] At block 970, the function includes receiving a second GNSS signal at the mobile device. The second GNSS signal may be in the same or a different constellation as the first GNSS signal, may be received within a search window established by the mobile device (e.g., using the techniques described herein), and so on.
[0131] At block 980, the functionality includes determining whether a second GNSS signal is also a spoofed signal based at least in part on information regarding a first received GNSS signal. Here, the mobile device can utilize the information regarding the first GNSS signal in any of a variety of ways. For example, the mobile device can reduce the size of a search window based on characteristics (frequency and / or code phase offset) of the first GNSS signal. As described elsewhere herein, a spoofed signal can be tracked (e.g., using a grid-based or loop-based tracking method where the search window is centered on the spoofed signal), and real-time information regarding the tracked spoofed signal can also be used for any newly detected GNSS signals. For example, a code window can be predicted by the tracked spoofed signal in order to enable detection of a similar spoofed signal. For example, time, frequency offset, and code phase offset derived from a spoofed signal of one satellite can be used with an ephemeris to determine spoofed signal code phase offset and frequency offset of other satellite signals spoofed within the same constellation. Additionally or alternatively, any newly detected GNSS signal that falls within the window of the tracked spoofed signal can be identified as a spoofed signal and, if desired, also tracked. Any spoofed signal identified by the mobile device can be communicated to other mobile devices, servers, etc. to assist in identifying and mitigating the effects of spoofing.
[0132] Figure 10 is an illustration of a grid 1000 that shows how this type of spoofing detection can be performed in a grid-based method. The method can vary depending on whether the GNSS receiver has acquired and is tracking GNSS signals or whether the GNSS receiver has not yet acquired GNSS signals. Referring Figure 10 to the spoofing detection techniques described can reflect one or more of the techniques described above with reference to FIG. 9.
[0133] If the GNSS receiver has locked (e.g., is tracking) GNSS signal 1010, then the GNSS receiver will likely have valid time and ephemeris, and can establish window 1020 based on the relative positioning of the satellite to the GNSS receiver (derived from the time and ephemeris), within which the GNSS receiver tracks GNSS signal 1010 (e.g., in the manner described above). Then, window 1020 can be used as a threshold as to how far GNSS signal 1010 is allowed to "jump" to other grid points of grid 1000 for continuous measurement. The size of window 1020 can also be based on the expected variation of the actual signal based on multipath. For example, in some embodiments, the size of window 1020 can be determined such that GNSS signal 1010 is not allowed to jump in frequency and / or code phase in a way that would cause the estimated positioning of the GNSS receiver to change by 100 m or more. (As needed, other embodiments can implement larger or smaller windows 1020.) In this way, when spoofing signal 1030 (and some multipath signals with very large errors) is not helpful to the navigation scheme of the GNSS receiver, the signal can be ignored. Other location constraints can also be used to inform the size and location of window 1020. For example, in the case of a vehicle, these location limits can include lane or road boundaries; buildings, obstacles, or other objects where the vehicle cannot (or is extremely unlikely to) be located; and so on. As another example, if the GNSS receiver loses track of a satellite, the search window for one or more satellites can be expanded. In such a case, the spoofing signal can be captured, and the techniques provided herein can be used to identify the actual GNSS signal (e.g., based on non-GNSS positioning). In this case, the GNSS signals from the lost satellite may become visible again in the search window, which is consistent with the signals from the satellites with corresponding GNSS signals that are still being tracked. (Then, if needed, separate search windows across all satellites can be used to verify the presence of a spoofing signal.)
[0134] According to some embodiments, historical tracking data can be used to identify patterns and ensure the consistency of the tracked GNSS signal 1010. For example, when a satellite is visible, the movement of GNSS signal 1010 on grid 1000 over a period of time can be tracked. In such an embodiment, the GNSS receiver can apply a rate-of-change threshold such that the GNSS signal 1010 used for positioning / navigation is not allowed to move more than is consistent with the previous movement of GNSS signal 1010 on grid 1000. This rate of change can also be based on the historical or real-time movement data of the GNSS receiver. According to some embodiments, different rate-of-change thresholds can be used for frequency and code phase.
[0135] If the GNSS receiver has not yet acquired the GNSS signal 1010, some modifications can be made to the functions described previously. If the GNSS receiver does not have a valid time, it can obtain a reasonable time from a network (e.g., a wide area network (WAN) system that provides time, an Internet time server that provides time, or other servers). A valid ephemeris can be used or obtained (e.g., demodulated or received from a network), and an approximate location can also be obtained as described above (e.g., from the nearest location estimate, from other positioning techniques, etc.). Then, the time, ephemeris, and approximate location can be used to predict the boundaries of the window 1020 in which the GNSS signal 1010 is expected to be received. The size of the window 1020 can be based on the uncertainty of the time and / or approximate location.
[0136] Spoofing signals 1030 located outside the established window 1020 may be relatively strong. However, for the purpose of location estimation, the spoofing signal can be ignored to support the weaker GNSS signal 1010 satellite signals within the predicted boundaries. As the approximate location (using non-GNSS means) changes, the position of the window 1020 can change correspondingly, so as to maintain the threshold that the GNSS receiver can use to identify the spoofing signal 1030. Further, as described above, once the GNSS signal 1010 is acquired within the window 1020, additional constraints can be used to track the acquired GNSS signal 1010.
[0137] According to some embodiments, an energy threshold can be established and used additionally or alternatively to detect the spoofing signal 1030. For example, the GNSS receiver can use the tracked GNSS signal 1010 and / or historical data from the GNSS signal to determine the expected energy level and establish a maximum energy threshold. If the GNSS receiver receives a spoofing signal 1030 with an energy level exceeding this threshold (even if the spoofing signal 1030 is within the window 1020), the GNSS receiver can ignore the spoofing signal 1030.
[0138] The embodiments are not limited to the grid-based acquisition or tracking methods described in the above embodiments. For example, the embodiments can utilize loop-based tracking (e.g., frequency and / or code loops) that are often used by GNSS receivers. In fact, various types of GNSS receivers can implement various types of frequency and code tracking techniques. Regardless of the type of tracking used (e.g., grid-based tracking, loop-based tracking, or others), embodiments for determining the correct position of the GNSS receiver in the presence of GNSS spoofing can be implemented. Referring again to Figure 2A, for example, the complex down-conversion and digital baseband processing at block 216 can be used to implement a frequency and / or code phase loop that provides loop-based acquisition / tracking (as a supplement or alternative to providing grid-based acquisition / tracking). In this example, both the I and Q components provided as inputs to block 216 can be provided to the code and carrier loops, which can be tuned to track the acquired code and carrier signals, respectively. Similar to the grid-based method described above, this tuning can be modified to provide a search window to provide reliable positioning of the mobile device in the presence of spoofing.
[0139] For example, if a GNSS receiver has acquired a GNSS signal when it encounters a spoofing signal, the spoofing signal may cause a jump in the code phase and / or frequency to account for the spoofing scenario. Additionally, using the time of validity and ephemeris, the GNSS receiver can establish a search window that sets thresholds for the maximum frequency change and maximum code phase change allowed by the frequency and code tracking loops (e.g., these loops can be tuned as described above to only accept frequency and / or code phase changes below these maximum values). Further, by integrating for a longer period of time using the center frequency and code phase (predicted using the time and ephemeris), for example, propagated using a Kalman or other filter, the original GNSS signal can still be tracked. Also, when determining the thresholds, embodiments can allow for real signal variations based on multipath and other signal anomalies such that the signal variations do not cause the position to move by more than a threshold amount. (This can be based on a threshold change in the pseudorange rather than the actual position of the GNSS receiver.) Thus, signals that cause such changes to exceed the established thresholds can be ignored.
[0140] As with the previously described embodiments, the frequency and code phase changes can be tracked over time to establish a rate of change threshold. In other words, when the satellite of the tracked GNSS signal is in the line of sight, a rate of change threshold for the frequency and / or code phase can be established such that an accepted jump in the tracked GNSS signal does not move the signal in frequency and / or code phase more than is consistent with previous movements.
[0141] If, when encountering a spoofing signal, the GNSS receiver has not yet acquired a GNSS signal, the time, ephemeris, and approximate location can be obtained in the manner described above and used to set the size of the search window (e.g., predicting the maximum and minimum frequency thresholds, and the maximum and minimum code phase thresholds). The frequency and code phase loops can be tuned accordingly to implement the search window, allowing the GNSS receiver to identify the true GNSS signal within the specified thresholds. Similar to the grid-based method of moving window 1020 based on changes in the approximate location of the GNSS receiver, embodiments using tracking loops can modify the threshold boundaries of the frequency and code phase loops when there are changes in the approximate location based on non-GNSS sources. Further, once the signal is acquired within the search window (established thresholds), the constraints described above for a receiver that has acquired a GNSS signal can be used.
[0142] Figure 11 An embodiment of a mobile device 1100 is shown, and the mobile device 1100 can be used as described above (e.g., in conjunction with Figures 1 to 11 ). For example, the mobile device 1100 can correspond to the UE 105 of Figure 1 and Figure 6 , and / or can perform one or more of the functions of the method shown in Figure 9A and Figure 9B . It should be noted that Figure 11 is only intended to provide a general description of the various components, and any one or all of them can be used appropriately. It can be noted that in some cases, Figure 11 the components shown can be located in a single physical device and / or distributed among various networked devices, which can be set at different physical locations. Additionally, as described above, the functions of the UE discussed in the previous embodiments can be performed by Figure 11 one or more of the hardware and / or software components shown.
[0143] The mobile device 1100 is shown as including hardware elements (or can communicate in other ways as appropriate) that can be electrically coupled via a bus 1105. The hardware elements can include a processing unit 1110, and the processing unit 1110 can include, but is not limited to, one or more general-purpose processors, one or more dedicated processors (such as DSP chips, graphics acceleration processors, application-specific integrated circuits (ASICs), etc.) and / or other processing structures or components. As Figure 11As shown, some embodiments may have a separate DSP 1120 according to the desired functionality. Location determination based on wireless communication and / or other determinations may be provided in the processing unit 1110 and / or the wireless communication interface 1130 (discussed below). The mobile device 1100 may also include one or more input devices 1170, which may include but are not limited to one or more keyboards, touchscreens, touchpads, microphones, buttons, dials, switches, etc.; and one or more output devices 1115, which may include but are not limited to one or more displays (e.g., touchscreens), light-emitting diodes (LEDs), speakers, etc.
[0144] The mobile device 1100 may also include a wireless communication interface 1130, which may include but is not limited to a modem, network card, infrared communication device, wireless communication device, and / or chipset (such as a Bluetooth device, IEEE 802.11 device, IEEE 802.15.4 device, Wi-Fi device, WiMAX device, WAN device, and / or various cellular devices, etc.), and / or similar devices, which may enable the mobile device 1100 to communicate with other devices described in the above embodiments. As described herein, for example, the wireless communication interface 1130 may allow data and signaling to communicate (e.g., transmit and receive) with the TRP of the network via an eNB, gNB, ng-eNB, access point, various base stations, and / or other access node types and / or other network components, computer systems, and / or any other electronic device communicatively coupled to the TRP. The communication may be performed via one or more wireless communication antennas 1132 that transmit and / or receive wireless signals 1134. According to some embodiments, the wireless communication antennas 1132 may include multiple discrete antennas, antenna arrays, or any combination thereof.
[0145] Depending on the desired functionality, the wireless communication interface 1130 may include separate receivers and transmitters, or any combination of transceivers, transmitters, and / or receivers to communicate with base stations (e.g., ng-eNBs and gNBs) and other terrestrial transceivers such as wireless devices and access points. The mobile device 1100 may communicate with different data networks including various network types. For example, a wireless wide area network (WWAN) may be a CDMA network, a time division multiple access (TDMA) network, a frequency division multiple access (FDMA) network, an orthogonal frequency division multiple access (OFDMA) network, a single-carrier frequency division multiple access (SC-FDMA) network, a WiMAX (IEEE 802.16) network, etc. A CDMA network may implement one or more radio access technologies (RATs) such as CDMA2000, WCDMA, etc. CDMA2000 includes the IS-95 standard, the IS-2000 standard, and / or the IS-856 standard. A TDMA network may implement GSM, digital advanced mobile phone system (D-AMPS), or some other RAT. An OFDMA network may employ LTE, LTE-Advanced, 5G NR, etc. 5G NR, LTE, LTE-Advanced, GSM, and WCDMA are described in the documents of the 3rd Generation Partnership Project (3GPP). Cdma2000 is described in the documents of the consortium named "3rd Generation Partnership Project 2" (3GPP2). The 3GPP documents and 3GPP2 documents are publicly available. A WLAN may also be an IEEE 802.11x network, and a wireless personal area network (WPAN) may be a Bluetooth network, IEEE 802.15x, or some other type of network. The techniques described herein may also be used for any combination of WWAN, WLAN, and / or WPAN.
[0146] The mobile device 1100 may also include a sensor 1140. The sensor 1140 may include, but is not limited to, one or more inertial sensors and / or other sensors (e.g., accelerometers, gyroscopes, cameras, magnetometers, altimeters, microphones, proximity sensors, light sensors, barometers, etc.), some of which may be used to obtain location-related measurements and / or other information.
[0147] An embodiment of the mobile device 1100 may also include a GNSS receiver 1180 that is capable of receiving and processing signals 1184 from one or more GNSS satellites (e.g., in the manner described herein) using an antenna 1182 (which may be the same as the wireless communication antenna 1132). The positioning measured based on the GNSS signals may be used to supplement and / or combine with the techniques described herein. The GNSS receiver 1180 may use conventional techniques to extract the positioning of the mobile device 1100 from GNSS satellites 110 of GNSS systems such as the Global Positioning System (GPS), Galileo, GLONASS, the Quasi-Zenith Satellite System (QZSS) over Japan, the Indian Regional Navigation Satellite System (IRNSS) over India, the BeiDou Navigation Satellite System (BDS) over China, etc. Additionally, the GNSS receiver 1180 may be used in conjunction with various augmentation systems (e.g., satellite-based augmentation systems (SBAS)) that may be associated with or capable of being used with one or more global and / or regional navigation satellite systems, such as the Wide Area Augmentation System (WAAS), the European Geostationary Navigation Overlay Service (EGNOS), the Multi-functional Satellite Augmentation System (MSAS), and the GPS Aided Geo Augmented Navigation (GAGAN), etc.
[0148] It should be noted that although the GNSS receiver 1180 is shown as a different component in Figure 11 the embodiments are not limited thereto. As used herein, the term "GNSS receiver" may include hardware and / or software components configured to obtain GNSS system measurements (measurements from GNSS satellites). Thus, in some embodiments, the GNSS receiver may include a measurement engine executed (as software) by one or more processing units, such as the processing unit 1110, the DSP 1120, and / or the processing unit within the wireless communication interface 1130 (e.g., in the modem). Other details regarding such embodiments are described below with reference to Figure 12 Optionally, the GNSS receiver may also include a positioning engine that may use the GNSS measurements from the measurement engine to determine the positioning of the GNSS receiver using an Extended Kalman Filter (EKF), a Weighted Least Squares (WLS), a hatch filter, a particle filter, etc. The positioning engine may also be executed by one or more processing units (such as the processing unit 1110 or the DSP 1120).
[0149] The mobile device 1100 may also include a memory 1160 and / or communicate with the memory 1160. The memory 1160 may include, but is not limited to, local and / or network-accessible storage devices, disk drives, drive arrays, optical storage devices, solid-state storage devices such as random access memory (RAM) and / or read-only memory (ROM), which may be programmable, flash-updateable, etc. Such storage devices may be configured to implement any suitable data storage, including but not limited to various file systems, database structures, etc.
[0150] The memory 1160 of the mobile device 1100 may also include software elements ( Figure 11 not shown), including an operating system, device drivers, executable libraries, and / or other code, such as one or more application programs, which may include computer programs provided by various embodiments, and / or may be designed to implement methods provided by other embodiments, and / or configure systems provided by other embodiments, as described herein. By way of example only, one or more of the processes described with respect to the above methods may be implemented as code and / or instructions in the memory 1160, which may be executed by the mobile device 1100 (and / or the processing unit 1110 or DSP 1120 within the mobile device 1100). In one aspect, then, such code and / or instructions may be used to configure and / or adapt a general-purpose computer (or other device) to perform one or more operations in accordance with the described methods.
[0151] As described above, the foregoing embodiments (including those with respect to Figures 8 to 10 the functions described and Figure 11 the architectures in
[0152] Figure 12 may be implemented, in whole or in part, by the GNSS receiver 1180, which may include hardware and / or software components separate from the DSP 1120 and the processing unit 1110 to implement such functions. That is, some embodiments may use the processing unit 1110 (e.g., an application processor or other processing unit / hardware component external to the physical GNSS receiver 1180) to implement at least some of the functions. Figure 12 The mobile device 1200 of Figure 11 shows a variant of the mobile device 1100 of
[0153] Figure 12 in which additional sub-components are shown to help illustrate embodiments in which the positioning engine 1215 may be executed by the processing unit 1210, such as an application processor, which may be separate from the physical GNSS receiver 1280. Figure 11 The components similar to those shown inFigure 11 The described functionality. However, in Figure 12 , the positioning engine 1215 executed by the processing unit 1210 can receive information from various sub-components such as LIDAR 1242, radar 1244, and / or camera 1246 of the sensor 1240. Based on this information, the positioning of the mobile device 1200 can be calculated. (This can include raw sensor data and / or sensor data that has been pre-processed to some extent by the sensor core 1248.) Additional data sources for the positioning engine 1215 include map data 1265 (which can be stored in the memory 1260) and GNSS baseband / combined baseband 1285 (which can be a component of the GNSS receiver 1280).
[0154] The positioning engine 1215 can determine the positioning of the mobile device 1200 by using an EKF, WLS, shadow filter, particle filter, etc. to determine a positioning solution by integrating data from one or more of the various position data sources (identified in the previous paragraph). To determine the solution, the positioning engine 1250 can obtain inputs from various data sources and de-weight the outlier data. During GNSS acquisition, the processing unit 1210 can send a position request to the GNSS receiver. The processing unit 1210 can also provide information to the GNSS receiver 1280 by "injecting" an approximate position (seed position), ephemeris data (if available), and time (if available). If the GNSS receiver 1280 locks onto a spoofing signal, the output of the GNSS receiver 1280 (e.g., the pseudorange from the GNSS baseband / combined baseband 1285) may no longer be consistent with the other inputs to the positioning engine 1215, and the positioning engine 1215 can de-weight or potentially ignore these GNSS pseudorange outputs from the GNSS receiver / baseband.
[0155] According to some embodiments, if the positioning engine 1215 detects an erroneous input from the GNSS receiver 1280, the positioning engine 1215 may inject an approximate (seed) position based on inputs from other position data sources and time and ephemeris (if needed) to reset the GNSS receiver 1280 to the correct time / code phase for each satellite. According to some embodiments, the positioning engine 1215 may also send an indication of potential spoofing and / or maximum frequency and / or code phase thresholds based on the current position uncertainty to enable the GNSS receiver 1280 to operate in an anti-spoofing mode. In the anti-spoofing mode, the GNSS receiver 1280 may ignore stronger signals in favor of signals detected within appropriate thresholds as described above. Similarly, according to some embodiments, the GNSS receiver 1280 may notify the positioning engine 1215 of frequency and code phase jumps (e.g., using a grid-based or tracking loop-based method) and request the positioning engine 1215 to re-inject the correct parameters. Additionally or alternatively, the GNSS receiver 1280 may provide an indication to the positioning engine 1215 to de-weight or ignore GNSS signals until the detected spoofing signal no longer exists, or use re-injection of parameters to verify the output of the GNSS receiver 1280 such that the GNSS receiver 1280 can determine whether to track or ignore certain received GNSS signals.
[0156] According to some embodiments, multiple frequencies of GNSS signals transmitted by satellites may be monitored to determine whether one frequency is being spoofed. For example, in GPS, a multi-band GNSS receiver may monitor at least two of the L1, L2, and L5 bands. If only one band is being spoofed, the positioning engine (e.g., implemented by the GNSS receiver and / or application processor) may prioritize pseudorange measurements determined from GNSS signals that do not result in frequency and / or phase jumps greater than a threshold and / or result in a positioning solution consistent with the historical position and travel speed and heading. According to some embodiments, the GNSS signal having the most stable C / No (carrier-to-noise density ratio) characteristics may be selected. The C / No difference between the various frequency bands (L1, L2, and L5) should be stable, and the antenna gain difference across the antenna should be small. This can be modeled, but assuming the same antenna gain pattern or stable orientation of the antenna, the C / No difference should be stable. Further, if the temperature is stable and there are no other RF delays changing, a step change in the in-system signal bias or inter-signal systematic bias indicates a spoofing device. Regarding the spoofed band, the GNSS receiver may wait for the spoofing to stop and then use the corresponding GNSS signal again and / or combine it with GNSS signals on the band being used (e.g., for increased accuracy). When the GNSS receiver again determines that a tracked GNSS signal is being acquired from the (previous) spoofed band, GNSS signals from non-spoofed bands may be used for signal acquisition.
[0157] According to some embodiments, the use of multiple constellations can be similar to the use of multiple frequency bands in the previous paragraph. That is, for a GNSS receiver capable of receiving GNSS signals from multiple constellations, if the GNSS signals from the first constellation are determined to be spoofed, the GNSS receiver can continue to use the GNSS signals from the second constellation determined not to be spoofed (e.g., consistent with historical position / velocity / course, consistent with other data, etc.). The GNSS signals from the first constellation can be periodically checked to determine whether they are still being spoofed. The GNSS signals from the second constellation can be used as a data source to verify whether spoofing is still occurring. Additionally or alternatively, the spoofed GNSS signals from the first constellation can be tracked (e.g., in the manner described herein). If such a spoofed signal undergoes a frequency and / or code phase jump (e.g., similar to the jump made at the start of spoofing), it can indicate that the signal is no longer being spoofed. Thus, such a jump can trigger a check (e.g., against a reliable position data source) to determine whether the signal may still be spoofed.
[0158] Regarding the embodiments described above for monitoring multiple frequencies and / or multiple constellations, a weighted least squares solution for each constellation / frequency combination can be calculated (e.g., continuously), and the position, velocity, and time (PVT) can be compared to determine whether any frequency or constellation becomes inconsistent with other solutions. As an example of using constellations, assume that GPS and GLO are spoofing-consistent with each other, and GLO and BDS are real. If GNSS-based inconsistencies are detected only on GPS or GLO, they can be applied to the constellation and / or frequency on which they are found and then propagated to the spoofed consistent solutions, so that they are all removed. According to some embodiments, independent inputs can be used to identify the spoofed PVT and remove it. For example, the spoofed PVT can be identified based on the difference (exceeding a threshold amount) from a positioning scheme based on 5G, test-specified positioning (TDP), or WLAN or microelectromechanical systems (MEMS).
[0159] According to available resources, some embodiments can track spoofed signals and subtract the spoofed signals to better obtain the actual GNSS signals. Figure 13 FIG. 1300 is a flowchart of an example method for how this is done. For example, the components for performing method 1300 can include the hardware and / or software components of a GNSS receiver. For example, the specific implementation can vary depending on whether a tracking grid or a tracking loop is used. Generally speaking, if a spoofed signal is detected and a search window is established to detect legitimate GNSS signals, poles can be created, for example, at the center of the spoofed signal frequency and code phase, and all or part of the spoofed signal can be removed so that the spoofed signal can be correlated within the search window.
[0160] At block 1305, method 1300 includes identifying and tracking spoofing signals. This can be done using any of the techniques described herein. For example, spoofing signals can be detected by comparing the corresponding pseudorange or position derived from the signal with data from other position data sources. The spoofing signals can then be tracked using, for example, a tracking loop and / or a grid-based tracking scheme.
[0161] At block 1310, the position of the GNSS receiver can be determined from one or more other position data sources. This can be determined using a positioning engine (e.g., a Kalman filter) using, for example, one or more position data sources such as LIDAR, RADAR, cameras, map data, sensors, and / or positioning schemes from other positioning systems such as 5G / WAN, WLAN (e.g., Wi-Fi), etc.
[0162] At block 1320, the functionality includes setting a search window (for grid-based tracking) and / or tracking parameters (for loop-based tracking) for the actual GNSS signals based on the position determined at block 1310. As described herein, the size of the search window and / or the parameters for the tracking loop can be set based on the accuracy and / or confidence of the positioning determination. As described in other embodiments, spoofing signals can be tracked separately from the acquisition and / or tracking of the actual GNSS signals. Further, using the techniques provided herein, the search window and / or tracking parameters for the actual GNSS signals can be set to exclude spoofing signals. However, in the case where the spoofing signals still fall within the search window and / or tracking parameters of the actual GNSS signals, the spoofing signals can be subtracted, as further shown in method 1300.
[0163] At block 1330, the spoofing signals are subtracted from the baseband. For example, this can be done at the GNSS receiver where the spoofing signals have been identified. In this way, the GNSS receiver can effectively "ignore" the spoofing signals and more easily identify the actual GNSS signals. (However, it can be noted that some embodiments may not perform a true subtraction of the signals. In some embodiments, the signals are buffered and the poles can be used in cases where the spoofing is minimized or reduced in the baseband.) In this way, at block 1340, the functionality includes searching for GNSS signals (after subtracting the spoofing signals).
[0164] It will be apparent to those skilled in the art that substantial variations can be made in accordance with specific requirements. For example, custom hardware can also be used, and / or specific elements can be implemented in hardware, software (including portable software such as applets, etc.), or both. Further, connections to other computing devices such as network input / output devices can be used.
[0165] Referring to the accompanying drawings, components that may include a memory may include a non-transitory machine-readable medium. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any storage medium that participates in providing data that causes a machine to operate in a particular manner. In the embodiments provided above, various machine-readable media may be involved in providing instructions / code to a processing unit and / or other devices for execution. Additionally or alternatively, the machine-readable medium may be used to store and / or carry such instructions / code. In many implementations, the computer-readable medium is a physical and / or tangible storage medium. Such media may take many forms, including but not limited to non-volatile media, volatile media, and transmission media. Common forms of computer-readable media include, for example, magnetic and / or optical media, any other physical media with a hole pattern, RAM, programmable ROM (PROM), erasable PROM (EPROM), FLASH-EPROM, any other storage chip or cartridge memory, subcarriers described below, or any other medium from which a computer can read instructions and / or code.
[0166] The methods, systems, and devices discussed herein are examples. Various embodiments may appropriately omit, substitute, or add various processes or components. For example, features described with respect to certain embodiments may be combined in various other embodiments. Different aspects and elements of embodiments may be combined in a similar manner. The various components of the drawings provided herein may be implemented in hardware and / or software. Additionally, technology is evolving, and thus, many elements are examples and do not limit the scope of the present disclosure to those specific examples.
[0167] Primarily for general reasons, it has sometimes proven convenient to refer to such signals as bits, information, values, elements, symbols, characters, variables, terms, numbers, digits, etc. However, it should be understood that all of these or similar terms are associated with appropriate physical quantities and are merely convenient labels. Unless otherwise specified, it is apparent from the above discussion that throughout the specification discussion, the use of terms such as "processing," "computing," "calculating," "determining," "ascertaining," "identifying," "associating," "measuring," "executing," etc. refers to the actions or processes of a particular apparatus (such as a special-purpose computer or similar special-purpose electronic computing device). Thus, in the context of this specification, a special-purpose computer or similar special-purpose electronic computing device is capable of manipulating or transforming signals, typically represented as physical electrical, electronic, or magnetic quantities in the memory, registers, or other information storage devices, transmission devices, or display devices of the special-purpose computer or similar special-purpose electronic computing device.
[0168] As used herein, the terms "and" and "or" may include a variety of meanings that also depend, at least in part, upon the context in which such terms are used. Generally, "or" if used to associate a list, such as A, B, or C, is intended to mean A, B, and C, used in an inclusive sense herein, as well as A, B, or C, used in an exclusive sense herein. In addition, the term "one or more" as used herein may be used in the singular to describe any feature, structure, or characteristic, or may be used to describe some combination of features, structures, or characteristics. However, it should be noted that this is merely an illustrative example and the claimed subject matter is not limited to this example. In addition, the term "at least one" if used to associate a list, such as A, B, or C, may be interpreted to represent any combination of A, B, and / or C, such as A, AB, AA, AAB, AABBCCC, etc.
[0169] A number of embodiments have been described and various modifications, alternative constructions, and equivalents may be used without departing from the spirit of the disclosure. For example, the above elements may merely be components of a larger system, where other rules may take precedence over or otherwise modify the application of the various embodiments. In addition, many steps may be taken before, during, or after considering the above factors. Accordingly, the above description does not limit the scope of the disclosure.
[0170] In view of this description, embodiments may include different combinations of features. The following numbered clauses describe example embodiments:
[0171] Clause 1: A method for determining the location of a mobile device resistant to GNSS spoofing, the method comprising: determining a non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources; receiving a first GNSS signal at the mobile device; for a predicted frequency and a predicted code phase based on the non-GNSS location, determining that the first GNSS signal includes: a frequency that differs from the predicted frequency by more than a threshold frequency difference, a code phase that differs from the predicted code phase by more than a threshold code phase difference, or both; receiving a second GNSS signal within a search window based on the non-GNSS location, the threshold frequency difference, and the threshold code phase difference; and determining a measurement for the second GNSS signal.
[0172] Clause 2: The method according to Clause 1, wherein the positioning information from one or more non-GNSS data sources includes: multilateration of the mobile device based at least in part on signals from terrestrial transceivers, wide area network (WAN) cell sector centers, access point (AP) locations, map data, sensor data, or dead reckoning positioning information, or a combination thereof.
[0173] Clause 3: The method according to Clause 2, wherein the sensor data includes data from the following: motion sensors, magnetometers, wheel sensors, cameras, radars, LIDARs, or sonar sensors, or combinations thereof.
[0174] Clause 4: The method according to any one of Clauses 1 to 3, further comprising receiving, at a GNSS receiver of the mobile device, a non-GNSS positioning from an application processor of the mobile device.
[0175] Clause 5: The method according to any one of Clauses 1 to 4, wherein the non-GNSS positioning is based on a previous positioning estimate of the mobile device.
[0176] Clause 6: The method according to any one of Clauses 1 to 5, further comprising selecting a search window such that a first GNSS signal is outside the search window.
[0177] Clause 7: The method according to any one of Clauses 1 to 6, wherein the search window is implemented using one or more tracking loops.
[0178] Clause 8: The method according to any one of Clauses 1 to 6, wherein the search window is part of a two-dimensional tracking grid that includes different combinations of code phase offsets and signal frequencies.
[0179] Clause 9: The method according to any one of Clauses 1 to 8, further comprising: determining an updated positioning of the mobile device based on measurements of a second GNSS signal.
[0180] Clause 10: The method according to any one of Clauses 1 to 9, further comprising determining that the first GNSS signal is a spoofing signal.
[0181] Clause 11: The method according to Clause 10, wherein determining that the first GNSS signal is a spoofing signal is at least partially based on the signal strength of the spoofing signal being greater than a threshold.
[0182] Clause 12: The method according to Clause 11, wherein the threshold is determined based on the GNSS signal strength level under open sky conditions.
[0183] Clause 13: The method according to any one of Clauses 10 to 12, wherein it further comprises subtracting the spoofing signal from a plurality of received signals to receive a second GNSS signal.
[0184] Clause 14: The method according to Clause 10, wherein determining that the first GNSS signal is a spoofing signal includes: determining the positioning of the mobile device based on received signals from a plurality of GNSS satellites, including the first GNSS signal and additional GNSS signals; and identifying the received signals as including a spoofing signal based on determining that the positioning is inconsistent with the non-GNSS positioning.
[0185] Clause 15: The method according to Clause 10, wherein determining that the first GNSS signal is a spoofing signal includes: identifying the first GNSS signal as a spoofing signal based on determining that a position determined from a pseudorange of the first GNSS signal is inconsistent with map data.
[0186] Clause 16: The method according to Clause 10, wherein determining that the first GNSS signal is a spoofing signal includes: determining that a difference between a signal frequency of the first GNSS signal and a signal frequency of a previously captured GNSS signal is greater than a threshold.
[0187] Clause 17: The method according to Clause 10, wherein determining that the first GNSS signal is a spoofing signal includes: obtaining two sets of self - consistent signals, wherein one set of self - consistent signals includes the first GNSS signal; determining a corresponding positioning of the mobile device based on each set of self - consistent signals of the two sets of self - consistent signals; and identifying the set of self - consistent signals including the first GNSS signal as including a spoofing signal based on a difference between the two corresponding positionings.
[0188] Clause 18: The method according to Clause 10, wherein determining that the first GNSS signal is a spoofing signal includes: identifying the first GNSS signal as a spoofing signal based on any of the following: determining that a change in a code phase of the first GNSS signal exceeds a threshold code phase change, determining that a change in a frequency of the first GNSS signal exceeds a threshold frequency change, or both.
[0189] Clause 19: The method according to Clause 10, determining that the first GNSS signal is a spoofing signal includes: acquiring the first GNSS signal; and identifying the first GNSS signal as a spoofing signal based on determining that a rate of change of a code phase, a frequency, or both of the first GNSS signal is different from a previously determined or predicted rate of change exceeding a threshold.
[0190] Clause 20: The method according to any one of Clauses 1 to 19, wherein the first GNSS signal is received by the mobile device via a first frequency or GNSS constellation, and the second GNSS signal is received by the mobile device via a second frequency or GNSS constellation.
[0191] Clause 21: The method according to Clause 10, wherein determining that the first GNSS signal is a spoofing signal is at least partially based on determining that the first GNSS signal is from a first constellation and is inconsistent with a position of the mobile device determined using a second constellation.
[0192] Clause 22: A mobile device for determining a location resistant to Global Navigation Satellite System (GNSS) spoofing, the mobile device comprising: an antenna configured to receive GNSS signals; a memory; and one or more processing units communicatively coupled to the antenna and the memory, wherein the one or more processing units are configured to: determine a non-GNSS location of the mobile device based on location information from one or more non-GNSS data sources; receive a first GNSS signal via the antenna; for a predicted frequency and a predicted code phase based on the non-GNSS location, determine that the first GNSS signal comprises: a frequency that differs from the predicted frequency by more than a threshold frequency difference, a code phase that differs from the predicted code phase by more than a threshold code phase difference, or both; based on the non-GNSS location, the threshold frequency difference, and the threshold code phase difference, receive a second GNSS signal via the antenna within a search window; and determine a measurement for the second GNSS signal.
[0193] Clause 23: The mobile device according to Clause 22, wherein the location information from one or more non-GNSS data sources comprises: multilateration of the mobile device based at least in part on signals from ground transceivers, a wide area network (WAN) cell sector center, an access point (AP) location, map data, sensor data, or dead reckoning location information, or a combination thereof.
[0194] Clause 24: The mobile device according to Clause 23, wherein the sensor data comprises data from: motion sensors, magnetometers, wheel sensors, cameras, radars, LIDARs, or sonar sensors, or a combination thereof.
[0195] Clause 25: The mobile device according to any one of Clauses 22 to 24, wherein: the one or more processing units comprise an application processor and a processor within a GNSS receiver of the mobile device; and the processor within the GNSS receiver of the mobile device is configured to receive the non-GNSS location from the application processor.
[0196] Clause 26: The mobile device according to any one of Clauses 22 to 25, wherein the application processor is configured to execute a positioning engine, and wherein the non-GNSS location is determined using the positioning engine.
[0197] Clause 27: The mobile device according to any one of Clauses 22 to 26, wherein the one or more processing units are further configured to select the search window such that the first GNSS signal is outside the search window.
[0198] Clause 28: The mobile device according to any one of Clauses 22 to 27, wherein the search window is implemented using one or more tracking loops.
[0199] Clause 29: A mobile device according to any one of Clauses 22 to 27, wherein the search window is part of a two-dimensional tracking grid that includes different combinations of code phase offsets and signal frequencies.
[0200] Clause 30: A mobile device according to any one of Clauses 22 to 29, wherein one or more processing units are further configured to determine an updated location of the mobile device based on measurements of a second GNSS signal.
[0201] Clause 31: A mobile device according to any one of Clauses 22 to 30, wherein one or more processing units are further configured to determine that the first GNSS signal is a spoofing signal.
[0202] Clause 32: The mobile device according to Clause 31, wherein one or more processing units are configured to determine that the first GNSS signal is a spoofing signal based at least in part on the signal strength of the spoofing signal being greater than a threshold.
[0203] Clause 33: The mobile device according to Clause 32, wherein one or more processing units are further configured to subtract the spoofing signal from a plurality of received signals to receive a second GNSS signal.
[0204] Clause 34: The mobile device according to Clause 31, wherein when it is determined that the first GNSS signal is a spoofing signal, one or more processing units are configured to: determine the location of the mobile device based on received signals from a plurality of GNSS satellites, including the first GNSS signal and additional GNSS signals; and identify the received signals as including a spoofing signal based on determining that the determined location is inconsistent with a non-GNSS location.
[0205] Clause 35: The mobile device according to Clause 34, wherein one or more processing units include an application processor and a processor within the GNSS receiver of the mobile device; and the application processor is configured to: determine that the determined location is inconsistent with a non-GNSS location; and provide information about the non-GNSS location, the search window, or both to the processor within the GNSS receiver based on determining that the determined location is inconsistent with a non-GNSS location.
[0206] Clause 36: The mobile device according to Clause 31, wherein when it is determined that the first GNSS signal is a spoofing signal, one or more processing units are configured to: identify the first GNSS signal as a spoofing signal based on determining that a location determined from the pseudorange of the first GNSS signal is inconsistent with map data.
[0207] Clause 37: The mobile device according to Clause 31, wherein when the first GNSS signal is determined to be a spoofing signal, one or more processing units are configured to determine that the difference between the signal frequency of the first GNSS signal and the signal frequency of a previously captured GNSS signal is greater than a threshold.
[0208] Clause 38: The mobile device according to Clause 31, wherein when the first GNSS signal is determined to be a spoofing signal, one or more processing units are configured to: obtain two sets of self-consistent signals, wherein one set of self-consistent signals includes the first GNSS signal; determine a corresponding location of the mobile device based on each set of self-consistent signals in the two sets of self-consistent signals; and identify the set of self-consistent signals including the first GNSS signal as including a spoofing signal based on the difference between the two corresponding locations.
[0209] Clause 39: The mobile device according to Clause 31, wherein when the first GNSS signal is determined to be a spoofing signal, one or more processing units are configured to identify the first GNSS signal as a spoofing signal based on: determining that the change in the code phase of the first GNSS signal exceeds a threshold code phase change, determining that the change in the frequency of the first GNSS signal exceeds a threshold frequency change, or both.
[0210] Clause 40: The mobile device according to Clause 31, wherein when the first GNSS signal is determined to be a spoofing signal, one or more processing units are configured to identify the first GNSS signal as a spoofing signal based on determining that the rate of change of the code phase, frequency, or both of the first GNSS signal is different from a previously determined or predicted rate of change that exceeds a threshold.
[0211] Clause 41: The mobile device according to any one of Clauses 22 to 40, wherein the first GNSS signal is received by the mobile device via a first frequency or GNSS constellation, and the second GNSS signal is received by the mobile device via a second frequency or GNSS constellation.
[0212] Clause 42: The mobile device according to Clause 31, wherein one or more processing units are configured to determine that the first GNSS signal is a spoofing signal based at least in part on determining that the first GNSS signal is from a first constellation and is inconsistent with the location of the mobile device determined using a second constellation.
[0213] Clause 43: A device for determining the location of a mobile device against Global Navigation Satellite System (GNSS) spoofing, comprising: components for determining the non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources; components for receiving a first GNSS signal at the mobile device; components for determining, for a predicted frequency and a predicted code phase based on the non-GNSS location, that the first GNSS signal includes: a frequency that differs from the predicted frequency by more than a threshold frequency difference, a code phase that differs from the predicted code phase by more than a threshold code phase difference, or both; components for receiving a second GNSS signal within a search window based on the non-GNSS location, the threshold frequency difference, and the threshold code phase difference; and components for determining measurements for the second GNSS signal.
[0214] Clause 44: The device according to Clause 43, further comprising components for selecting a search window such that the first GNSS signal is outside the search window.
[0215] Clause 45: The device according to any one of Clauses 43 to 44, wherein the search window is implemented using one or more tracking loops.
[0216] Clause 46: The device according to any one of Clauses 43 to 44, wherein the search window is part of a two-dimensional tracking grid that includes different combinations of code phase offsets and signal frequencies.
[0217] Clause 47: A non-transitory computer-readable medium storing instructions for determining the location of a mobile device against Global Navigation Satellite System (GNSS) spoofing, the instructions including code for: determining the non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources; receiving a first GNSS signal; determining, for a predicted frequency and a predicted code phase based on the non-GNSS location, that the first GNSS signal includes: a frequency that differs from the predicted frequency by more than a threshold frequency difference, a code phase that differs from the predicted code phase by more than a threshold code phase difference, or both; receiving a second GNSS signal within a search window based on the non-GNSS location, the threshold frequency difference, and the threshold code phase difference; and determining measurements for the second GNSS signal.
Claims
1. A method for determining the location of a mobile device against global navigation satellite system (GNSS) spoofing, the method comprising: Determining a non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources; Receiving, at the mobile device, a first version of a GNSS signal at a first location within a capture search window, the first version of the GNSS signal including a stronger signal than a second version of the GNSS signal at a second location outside the first location within the capture search window, the first version and the second version being associated with a first GNSS signal source; Determining boundaries of a window for capturing a valid GNSS signal associated with the first GNSS signal source, the boundaries being based on: a predicted frequency based on the non-GNSS location and a predicted code phase based on the non-GNSS location; Determining that the first version of the GNSS signal is outside the boundaries of the window for capturing a valid GNSS signal from the first GNSS signal source, the determining including determining: The frequency of the first version of the GNSS signal differs from the predicted frequency by more than a threshold frequency difference, The code phase of the first version of the GNSS signal differs from the predicted code phase by more than a threshold code phase difference, or Both of the above; Determining measurements for the second version of the GNSS signal; and Determining the location of the mobile device at least in part based on the measurements for the second version of the GNSS signal.
2. The method according to claim 1, wherein The positioning information from one or more non-GNSS data sources includes: Multilateration of the mobile device at least in part based on signals from ground transceivers, Wide area network (WAN) cell sector centers, Access point (AP) locations, Map data, Sensor data, or Dead reckoning positioning information, or A combination thereof.
3. The method according to claim 2, wherein The sensor data includes data from: Motion sensors, Magnetometers, Wheel sensors, Cameras, Radar, LIDAR, or Sonar sensors, Or a combination thereof.
4. The method according to claim 1, further comprising receiving the non-GNSS location at a GNSS receiver of the mobile device from an application processor of the mobile device.
5. The method according to claim 4, wherein, The non-GNSS location is based on a previous positioning estimate of the mobile device.
6. The method according to claim 1, wherein The boundaries for capturing a valid GNSS signal associated with the first GNSS signal source are part of a two-dimensional grid that includes different combinations of code phase offsets and signal frequencies.
7. The method according to claim 1, further comprising determining that the first version of the GNSS signal is a spoofing signal.
8. The method according to claim 7, wherein, Determining that the first version of the GNSS signal is a spoofing signal is at least in part based on the signal strength of the spoofing signal being greater than a threshold.
9. The method according to claim 8, wherein The threshold is determined based on GNSS signal strength levels under open sky conditions.
10. The method according to claim 7, wherein Further comprising subtracting the spoofing signal from a plurality of received signals to receive the second version of the GNSS signal.
11. The method according to claim 7, wherein, Determining that the first version of the GNSS signal is a spoofing signal includes: Determine the location of the mobile device based on the received signals from multiple GNSS satellites, including a first version of the GNSS signal and additional GNSS signals; and Based on determining that the location is inconsistent with the non-GNSS location, identify the received signals as including spoofing signals.
12. The method according to claim 7, wherein Determining that the first version of the GNSS signal is a spoofing signal includes:[[]] Based on determining that the position determined from the pseudorange of the first version of the GNSS signal is inconsistent with the map data, identify the first version of the GNSS signal as the spoofing signal.
13. The method according to claim 7, wherein, Determining that the first version of the GNSS signal is a spoofing signal includes:[[]] Determine that the difference between the signal frequency of the first version of the GNSS signal and the signal frequency of a previously captured GNSS signal is greater than a threshold.
14. The method according to claim 7, wherein Determining that the first version of the GNSS signal is a spoofing signal includes:[[]] Obtain two sets of self-consistent signals, where one set of self-consistent signals includes the first version of the GNSS signal; Based on each set of self-consistent signals in the two sets of self-consistent signals, determine the corresponding location of the mobile device; and Based on the difference between the two corresponding locations, identify the set of self-consistent signals including the first version of the GNSS signal as including the spoofing signal.
15. The method according to claim 7, wherein, Determining that the first version of the GNSS signal is a spoofing signal includes:[[]] Based on the following, identify the first version of the GNSS signal as the spoofing signal:[[]] Determine that the change in the code phase of the first version of the GNSS signal exceeds a threshold code phase change, Determine that the change in the frequency of the first version of the GNSS signal exceeds a threshold frequency change, or both of the above.
16. The method according to claim 7, wherein, Determining that the first version of the GNSS signal is a spoofing signal includes:[[]] Capture the first version of the GNSS signal; and Based on determining that the rate of change of the code phase, frequency, or both of the first version of the GNSS signal is different from a previously determined or predicted rate of change that exceeds a threshold, identify the first version of the GNSS signal as the spoofing signal.
17. The method according to claim 7, wherein Determine that the first version of the GNSS signal is a spoofing signal at least in part based on determining that the first version of the GNSS signal is from a first constellation and is inconsistent with the location of the mobile device determined using a second constellation.
18. The method according to claim 1, wherein The first version of the GNSS signal is received by the mobile device via a first frequency or GNSS constellation, and the second version of the GNSS signal is received by the mobile device via a second frequency or GNSS constellation.
19. A mobile device for determining a location resistant to Global Navigation Satellite System (GNSS) spoofing, the mobile device including:[[]] An antenna configured to receive GNSS signals; A memory; And One or more processing units communicatively coupled to the antenna and the memory, where the one or more processing units are configured to:[[]] Determine the non-GNSS location of the mobile device based on location information from one or more non-GNSS data sources; Receiving, via an antenna, a first version of a GNSS signal located at a first position of a capture search window, the first version of the GNSS signal including a stronger signal than a second version of a GNSS signal located at a second position outside the first position of the capture search window, the first version and the second version being associated with a first GNSS signal source; Determining boundaries of a window for capturing a valid GNSS signal associated with the first GNSS signal source, the boundaries being based on: a predicted frequency based on the non-GNSS positioning and a predicted code phase based on the non-GNSS positioning; Determining that the first version of the GNSS signal is outside the boundaries of the window for capturing a valid GNSS signal from the first GNSS signal source, the determining including determining: The frequency of the first version of the GNSS signal differs from the predicted frequency by more than a threshold frequency difference, The code phase of the first version of the GNSS signal differs from the predicted code phase by more than a threshold code phase difference, or Both of the above; Determining measurements for the second version of the GNSS signal; and determining the position of the mobile device at least in part based on the measurements for the second version of the GNSS signal.
20. The mobile device according to claim 19, wherein, The positioning information from one or more non-GNSS data sources includes: Multilateration of the mobile device at least in part based on signals from ground transceivers, Wide area network (WAN) cell sector centers, Access point (AP) locations, Map data, Sensor data, or Dead reckoning positioning information, or A combination thereof.
21. The mobile device according to claim 20, wherein, The sensor data includes data from: Motion sensors, Magnetometers, Wheel sensors, Cameras, Radar, LIDAR, or Sonar sensors, Or a combination thereof.
22. The mobile device according to claim 19, wherein: The one or more processing units include an application processor and a processor within a GNSS receiver of the mobile device; And The processor within the GNSS receiver of the mobile device is configured to receive the non-GNSS positioning from the application processor.
23. The mobile device according to claim 22, wherein, The application processor is configured to execute a positioning engine, and wherein the non-GNSS positioning is determined using the positioning engine.
24. The mobile device according to claim 19, wherein, The boundaries for capturing a valid GNSS signal associated with the first GNSS signal source are part of a two-dimensional grid that includes different combinations of code phase offsets and signal frequencies.
25. The mobile device according to claim 19, wherein, The one or more processing units are further configured to determine that the first version of the GNSS signal is a spoofing signal.
26. The mobile device according to claim 25, wherein, The one or more processing units are configured to determine that the first version of the GNSS signal is a spoofing signal at least in part based on the signal strength of the spoofing signal being greater than a threshold.
27. The mobile device according to claim 25, wherein, The one or more processing units are further configured to subtract the spoofing signal from a plurality of received signals to receive the second version of the GNSS signal.
28. The mobile device according to claim 25, wherein, When determining that the first version of the GNSS signal is a spoofing signal, the one or more processing units are configured to: Determining the location of the mobile device based on the received signals from multiple GNSS satellites, including the first version of the GNSS signal and additional GNSS signals; And Based on determining that the location is inconsistent with the non-GNSS location, identifying the received signals as including the spoofing signal.
29. The mobile device according to claim 28, wherein: The one or more processing units include an application processor and a processor within the GNSS receiver of the mobile device; And The application processor is configured to: Determine that the location is inconsistent with the non-GNSS location; and Based on determining that the location is inconsistent with the non-GNSS location, provide information about the non-GNSS location, the search window, or both to the processor within the GNSS receiver.
30. The mobile device according to claim 25, wherein, When it is determined that the first version of the GNSS signal is a spoofing signal, the one or more processing units are configured to: Based on determining that the position determined from the pseudorange of the first version of the GNSS signal is inconsistent with the map data, identify the first version of the GNSS signal as the spoofing signal.
31. The mobile device according to claim 25, wherein, When it is determined that the first version of the GNSS signal is a spoofing signal, the one or more processing units are configured to determine that the difference between the signal frequency of the first version of the GNSS signal and the signal frequency of a previously captured GNSS signal is greater than a threshold.
32. The mobile device according to claim 25, wherein, When it is determined that the first version of the GNSS signal is a spoofing signal, the one or more processing units are configured to: Obtain two sets of self-consistent signals, where one set of self-consistent signals includes the first version of the GNSS signal; Determine the corresponding location of the mobile device based on each set of self-consistent signals in the two sets of self-consistent signals; and Based on the difference between the two corresponding locations, identify the set of self-consistent signals including the first version of the GNSS signal as including the spoofing signal.
33. The mobile device according to claim 25, wherein, When it is determined that the first version of the GNSS signal is a spoofing signal, the one or more processing units are configured to: Based on the following, identify the first version of the GNSS signal as the spoofing signal: Determine that the change in the code phase of the first version of the GNSS signal exceeds a threshold code phase change, Determine that the change in the frequency of the first version of the GNSS signal exceeds a threshold frequency change, Or both.
34. The mobile device according to claim 25, wherein, When it is determined that the first version of the GNSS signal is a spoofing signal, the one or more processing units are configured to: Based on determining that the rate of change of the code phase, frequency, or both of the first version of the GNSS signal is different from a previously determined or predicted rate of change that exceeds a threshold, identify the first version of the GNSS signal as the spoofing signal.
35. The mobile device according to claim 25, wherein, The one or more processing units are configured to determine that the first version of the GNSS signal is a spoofing signal at least in part based on determining that the first version of the GNSS signal is from a first constellation and is inconsistent with the location of the mobile device determined using a second constellation.
36. The mobile device according to claim 19, wherein, The first version of the GNSS signal is received by the mobile device via a first frequency or GNSS constellation, and the second version of the GNSS signal is received by the mobile device via a second frequency or GNSS constellation.
37. An apparatus for determining the location of a mobile device resistant to Global Navigation Satellite System (GNSS) spoofing, the apparatus comprising: means for determining a non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources; means for receiving, at the mobile device, a first version of a GNSS signal located at a first position of a capture search window, the first version of the GNSS signal comprising a stronger signal than a second version of the GNSS signal located at a second position outside the first position of the capture search window, the first version and the second version being associated with a first GNSS signal source; means for determining boundaries of a window for capturing a valid GNSS signal associated with the first GNSS signal source, the boundaries being based on: a predicted frequency based on the non-GNSS location and a predicted code phase based on the non-GNSS location; means for determining that the first version of the GNSS signal is outside the boundaries of a window for capturing a valid GNSS signal from the first GNSS signal source based on: the frequency of the first version of the GNSS signal differing from the predicted frequency by more than a threshold frequency difference, the code phase of the first version of the GNSS signal differing from the predicted code phase by more than a threshold code phase difference, or both of the above; means for determining measurements for the second version of the GNSS signal; and means for determining the location of the mobile device based at least in part on the measurements for the second version of the GNSS signal.
38. The apparatus of claim 37, further comprising means for determining that the first version of the GNSS signal is a spoofing signal.
39. The apparatus according to claim 37, wherein, Determining the first version of the GNSS signal as a spoofing signal is at least in part based on the spoofing signal having a signal strength above a threshold.
40. The apparatus according to claim 37, wherein, The boundaries for capturing a valid GNSS signal associated with the first GNSS signal source are part of a two-dimensional grid that includes different combinations of code phase offsets and signal frequencies.
41. A non-transitory computer-readable medium storing instructions for determining the location of a mobile device resistant to Global Navigation Satellite System (GNSS) spoofing, the instructions comprising code for: determining a non-GNSS location of the mobile device based on positioning information from one or more non-GNSS data sources; receiving a first version of a GNSS signal located at a first position of a capture search window, the first version of the GNSS signal comprising a stronger signal than a second version of the GNSS signal located at a second position outside the first position of the capture search window, the first version and the second version being associated with a first GNSS signal source; Determine the boundaries of a window for capturing a valid GNSS signal associated with the first GNSS signal source, the boundaries being based on: a predicted frequency based on the non-GNSS positioning and a predicted code phase based on the non-GNSS positioning; Determine that a first version of the GNSS signal is outside the boundaries of a window for capturing a valid GNSS signal from the first GNSS signal source, based on: the frequency of the first version of the GNSS signal differing from the predicted frequency by more than a threshold frequency difference, the code phase of the first version of the GNSS signal differing from the predicted code phase by more than a threshold code phase difference, or both of the above; Determine measurements for a second version of the GNSS signal; and Determine the location of the mobile device, at least in part based on the measurements for the second version of the GNSS signal.
Citation Information
Patent Citations
Improving vehicle location services
CN106990415A
Methods and systems for collaborative global navigation satellite system (GNSS) diagnostics
CN107949795A
System and method for server side detection of falsified satellite measurements
US20120026037A1
Method and device for deriving location information by means of receiving GPS signal in wireless communication system
US20190265364A1
Method and system to mitigate emulator spoofer signals
US7697919B1