A time spoofing method for GNSS timekeeping receivers

By adjusting the satellite signal parameters of the GNSS timing receiver and employing a pseudorange and satellite position time deception algorithm, the problem of GNSS timing receivers being susceptible to time deception interference was solved. This achieved the effect of introducing timing deviation without changing the positioning results.

CN115616617BActive Publication Date: 2026-03-31Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-16
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing technologies, GNSS timing receivers are susceptible to time spoofing interference, which leads to timing distortion, deviation and delay, affecting the stability and security of time-dependent systems. Moreover, existing defense measures are difficult to effectively detect and defend against time spoofing.

Method used

By acquiring real satellite signals and employing time spoofing algorithms that modify pseudorange, satellite position, or both pseudorange and satellite position simultaneously, satellite signal parameters are adjusted to change the receiver's timing results without altering its positioning results. This includes modifying pseudorange bias, satellite position bias, or both pseudorange and satellite position simultaneously, and the bias is calculated using the Jacobian matrix and Taylor expansion formula.

Benefits of technology

The method successfully introduced timing bias without altering the receiver positioning results, achieving the goal of time deception. Simulation and field experiments show that the effect is significant, with receiver clock bias and spatial coordinate deviation meeting expectations, thus achieving the desired time deception effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115616617B_ABST
    Figure CN115616617B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of time deception methods for GNSS time service receiver, belong to navigation time deception interference control technical field.The present application is by adjusting the parameter in real signal, so that each satellite signal is added equal pseudorange deviation, or each satellite position is added corresponding position deviation, or equal pseudorange deviation and corresponding satellite position deviation are added simultaneously, so that receiver is solved according to processed satellite signal, when achieving time deception purpose when receiver is solved epoch pseudorange positioning timing.The simulation experiment and actual measurement experiment further verify that the present application can better achieve the purpose of time deception.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a time deception method for GNSS timing receivers, belonging to the field of navigation time deception interference control technology. Background Technology

[0002] Global Navigation Satellite System (GNSS) is widely used for timing and frequency calibration of power, telecommunications, and other network systems. Satellite navigation deception jamming is an emerging navigation jamming technique. Due to its strong concealment and high threat level, it has gradually become one of the hot topics in navigation jamming technology research. Deception jamming targeting GNSS timing receivers configured in infrastructure introduces time errors to disrupt the system's time, thereby paralyzing its power and communication systems, achieving the purpose of a soft strike against the enemy. It is generally believed that deception jamming mostly deceives the target's positioning results, therefore less attention is paid to deceiving the target's timing results. However, deceiving the timing results is highly harmful to the target and extremely covert.

[0003] A series of experiments have demonstrated that time spoofing can significantly impact various time-dependent systems. Northrop Grumman Information Systems (NGIS) and the University of Texas (UT) have tested and proven that GPS spoofers can broadcast spoofing signals to cause GNSS timing receivers used for timing in Phase Measurement Units (PMUs) to track the spoofing signals, thereby controlling the timing of the PMUs. The time offset caused by the spoofing signal will produce corresponding changes in the phase angle measured by the PMUs (approximately 11 minutes after the spoofing occurs, causing the PMUs to violate the IEEE C37.118 standard for phase synchronization). Zhenghao Zhang et al. proposed a novel Time Synchronization Attack (TSA) method to attack time information in smart grids and verified its effectiveness using numerical simulations. Qian Bin et al. found that time synchronization disruptions caused by GPS spoofing-based TSAs can disable the head-end system (HES) of Advanced Metering Infrastructure (AMI) and proposed a time jitter-based detection algorithm to identify and defend against GPS time spoofing. However, Daniele Borio et al. pointed out that although interference suppression techniques can significantly improve the performance of GNSS receivers when subjected to interference, they can also cause distortion, deviation, and delay in GNSS timing results. Gao Yangjun et al., based on data from the Texas Spoofing Test Battery (TEXBAT) at the University of Texas, analyzed the impact of time deception on receivers in different scenarios. The results showed that receiver timing results are susceptible to deception interference, and the power of the deception signal and the frequency locking mode are important factors affecting the effectiveness of time deception.

[0004] Time deception can be achieved by altering pseudorange observations. Huang Long proposed a design algorithm for a repeater-based deception jamming system targeting GNSS timing receivers. Theoretical analysis and simulation results show that by precisely controlling the repeater system's delay and accurately calibrating the target receiver's antenna position, the GNSS timing receiver's time can be effectively controlled with a 94.9% probability, exhibiting strong concealment. Peng Chenxi made the pseudorange modification amount the same for different satellites in the deception signal, modifying the calculated time information without changing the receiver's position. In experiments deceiving commercial timing receivers, it was found that when the deception signal's code phase is close to the real signal, the receiver clock bias exhibits a μs-level jump. Continuing to adjust the deception signal's code phase can pull the receiver clock bias off. If the code phase change rate is too fast, the clock bias will also jump. It is speculated that because only the code phase is modified to change the clock bias without modifying the carrier Doppler to change the clock drift, the receiver clock bias and clock drift results are inconsistent. Hu Yanfeng et al. proposed a clock bias compensation algorithm for forwarding-based spoofing interference. Simulation results show that this algorithm can effectively reduce the impact on the clock bias of the target receiver when performing position spoofing. It is noteworthy that in the forwarding model of the algorithm, the processing delay of the spoofer and the propagation delay of the spoofing signal from the spoofer to the target receiver are completely absorbed by the target receiver's clock bias. Before adopting the clock bias compensation algorithm, the active delay of the spoofer's forwarded signal was completely absorbed by the target receiver's coordinates. However, after adopting the clock bias compensation algorithm, the original active delay of the spoofer's forwarded signal is still absorbed by the target receiver's coordinates, while the active delay adjustment part is absorbed by the target receiver's clock bias. Zhao Xiangxiang demonstrated through simulation experiments that, for multi-peak spoofing detection algorithms, the spoofer can effectively deceive the clock of a static receiver by making the delay of the spoofing signal received by the target an integer multiple of the pseudo-code period and dynamically adjusting the forwarding delay over time. He Ting proposed deploying the deception devices in a regular hexagonal grid pattern. For target receivers with robust adaptive clock bias detection function, the optimal coverage radius of a single deception device was determined to be 10km, and the optimal distance between adjacent deception devices was determined to be 17km.

[0005] Time spoofing can be achieved through two algorithms: modifying GNSS timestamps and altering signal propagation time. Xiao Wei's experiments show that by modifying GPS timestamps, severe GPS time spoofing can be performed with relatively small pseudorange errors (248.6m) and positioning errors (53.2m). Spoofing can also be achieved by inserting the same delay into all GPS signals, with pseudorange errors less than 5nm and positioning errors of 283.6m. Compared to GPS positioning accuracy, these low-error attacks are difficult to detect solely from positioning errors or pseudorange calculations. Conversely, when random delays are inserted into each signal to control propagation time, pseudorange errors and receiver positioning errors can reach several kilometers, making detection highly probable. Summary of the Invention

[0006] The purpose of this invention is to provide a time deception method for GNSS timing receivers, which is used to achieve time deception when the receiver performs epoch pseudorange positioning timing calculations.

[0007] To solve the above-mentioned technical problems, this invention provides a time spoofing method for GNSS timing receivers, the method comprising the following steps:

[0008] 1) Acquire real satellite signals, which include satellite signals from each channel used by the receiver for pseudorange positioning timing calculation;

[0009] 2) The pseudorange time deception algorithm, the satellite position time deception algorithm, or the pseudorange and satellite position time deception algorithm are used to process each satellite signal so that the receiver can perform the calculation according to the processed satellite signal;

[0010] The pseudorange modification time deception algorithm refers to adding an equal pseudorange deviation to each of the satellite signals;

[0011] The time spoofing algorithm for modifying satellite positions refers to adding a corresponding position deviation to the satellite position signals in each of the satellite signals;

[0012] The time-spoofing algorithm that simultaneously modifies pseudorange and satellite position refers to simultaneously modifying the pseudorange and satellite position of each satellite signal.

[0013] This invention adjusts the parameters in the real signal so that each satellite signal is given an equal pseudorange deviation, or each satellite position is given a corresponding position deviation, or both equal pseudorange deviation and corresponding position deviation are given simultaneously. This allows the receiver to perform calculations based on the processed satellite signal, achieving time deception when the receiver performs epoch pseudorange positioning timing calculations.

[0014] Furthermore, when using a time-spoofing algorithm that modifies pseudorange, this can be achieved by adding a time delay to the navigation signal.

[0015] Furthermore, when using a time spoofing algorithm that modifies satellite positions, this can be achieved by modifying the ephemeris parameters i0, Ω0, ω, ... C uc C us C rc C rs C ic C is To change the satellite's position, i0 is the ephemeris reference time t. oe The orbital inclination is given by Ω0, where Ω0 is the right ascension of the ascending node at time 0 during the cycle, and ω is the orbital perigee. The rate of change of the orbital inclination with respect to time. C is the rate of change of the right ascension of the ascending node of the orbit with respect to time. uc To correct the amplitude for the cosine harmonic correction of the rising node angle distance, C us To correct the amplitude of the sinusoidal harmonic correction at the rising node angle, C rc For the cosine harmonic correction amplitude of the orbital radius, C rs For the sinusoidal harmonic correction amplitude of the orbital radius, C ic To adjust the amplitude for the cosine harmonic correction of the track inclination angle, C is The amplitude is corrected by sinusoidal tuning to the orbital radius.

[0016] Furthermore, when employing a time-spoofing algorithm that simultaneously modifies the pseudorange and satellite position, this can be achieved by modifying the satellite's semi-major axis 'a'. s square root Mean angular velocity correction value Δn, ephemeris reference time t oe The mean anterior angle M0 and the orbital eccentricity e s This allows for simultaneous changes to both the pseudorange observation and the satellite position.

[0017] Furthermore, when employing a time-spoofing algorithm that simultaneously modifies pseudorange and satellite position, the ephemeris reference time t can be modified. oe This allows for simultaneous changes to both the pseudorange observation and the satellite position.

[0018] Furthermore, when employing a time spoofing algorithm that simultaneously modifies pseudorange and satellite position, the three coefficients 'a' in the satellite clock correction model equation can be modified. f0 a f1 a f2 The deviation ΔT of the group delay correction value in a single-frequency receiver GD This allows for simultaneous changes to both the pseudorange observation and the satellite position.

[0019] Furthermore, when using the time-deception algorithm with modified pseudorange, the increased pseudorange bias Δρ is:

[0020] Gδ≈Δρ

[0021] δ=[Δx u ,Δy u ,Δz u ,Δδ u ] T

[0022] Δρ1=Δρ2=…=Δρ N

[0023] Where N is the number of satellites; G is the Jacobian matrix, which depends only on the geometric position of each satellite relative to the user; δ represents the desired deviation of the receiver's spatial rectangular coordinates and the receiver clock bias; R iΔδ represents the geometric distance between the satellite with PRN number i and the receiver. u The desired receiver clock bias; (Δx) u ,Δy u ,Δz u ) represents the desired spatial rectangular coordinate deviation of the receiver; Δρ i This represents the pseudorange deviation of satellite with PRN number i.

[0024] Furthermore, when using a time-spoofing algorithm to modify satellite positions, the satellite position deviation is calculated using the following formula:

[0025]

[0026]

[0027] Where [Δx] i ,Δy i ,Δz i ] represents the positional deviation of satellite with PRN number i; R i This represents the geometric distance between the satellite with PRN number i and the receiver; (Δx) u ,Δy u ,Δz u ) represents the desired spatial rectangular coordinate deviation of the receiver, and b is a real number.

[0028] Furthermore, when using a time-spoofing algorithm that simultaneously modifies pseudorange and satellite position, the formulas used to calculate the pseudorange observations and satellite position deviations are as follows:

[0029]

[0030] Δρ1=Δρ2=…=Δρ N =d

[0031]

[0032] Where [Δx] i ,Δy i ,Δz i ] represents the positional deviation of satellite with PRN number i; R i This represents the geometric distance between the satellite with PRN number i and the receiver; (Δx) u ,Δy u ,Δz u Let ρ be the desired receiver spatial rectangular coordinate deviation, b be a real number, and Δρ be the deviation. i Let b be the pseudorange deviation of satellite with PRN number i, and b be a real number. Attached Figure Description

[0033] Figure 1This is a flowchart of a time spoofing method for GNSS time receivers;

[0034] Figure 2 This is a schematic diagram of the receiver clock error before and after adding pseudorange bias in the simulation experiment of this invention;

[0035] Figure 3 This is a schematic diagram of the receiver's spatial rectangular coordinates before and after adding pseudorange bias in the simulation experiment of this invention;

[0036] Figure 4 This is a schematic diagram of the receiver clock error deviation before and after adding pseudorange bias in the simulation experiment of this invention;

[0037] Figure 5 This is a schematic diagram of the receiver's spatial rectangular coordinate deviation before and after adding pseudorange bias in the simulation experiment of this invention;

[0038] Figure 6 This is a schematic diagram of the receiver clock difference before and after modifying the satellite position in the simulation experiment of this invention;

[0039] Figure 7 This is a schematic diagram of the receiver's spatial rectangular coordinates before and after modifying the satellite position in the simulation experiment of this invention;

[0040] Figure 8 This is a schematic diagram of the receiver clock bias deviation before and after modifying the satellite position in the simulation experiment of this invention;

[0041] Figure 9 This is a schematic diagram of the spatial rectangular coordinate deviation of the receiver before and after modifying the satellite position in the simulation experiment of this invention;

[0042] Figure 10 This is a schematic diagram of the receiver clock error before and after adding pseudorange bias and modifying satellite position in the simulation experiment of this invention;

[0043] Figure 11 This is a schematic diagram of the receiver's spatial rectangular coordinates before and after simultaneously adding pseudorange bias and modifying the satellite position in the simulation experiment of this invention;

[0044] Figure 12 This is a schematic diagram of the receiver clock error before and after adding pseudorange bias and modifying satellite position in the simulation experiment of this invention;

[0045] Figure 13 This is a schematic diagram of the receiver's spatial rectangular coordinate deviation before and after adding pseudorange bias and modifying satellite position in the simulation experiment of this invention;

[0046] Figure 14 This is a schematic diagram of the receiver clock error before and after adding pseudorange bias in the actual test of this invention;

[0047] Figure 15This is a schematic diagram of the receiver's spatial rectangular coordinates before and after adding pseudorange bias in the actual test of this invention;

[0048] Figure 16 This is a schematic diagram of the receiver clock error deviation before and after adding pseudorange bias in the actual test of this invention;

[0049] Figure 17 This is a schematic diagram of the spatial rectangular coordinate deviation of the receiver before and after adding pseudorange bias in the actual test of this invention;

[0050] Figure 18 This is a schematic diagram of the receiver clock error before and after modifying the satellite position in the actual test experiment of this invention;

[0051] Figure 19 This is a schematic diagram of the receiver's spatial rectangular coordinates before and after modifying the satellite position in the actual test experiment of this invention;

[0052] Figure 20 This is a schematic diagram of the receiver clock bias deviation before and after modifying the satellite position in the actual test experiment of this invention;

[0053] Figure 21 This is a schematic diagram of the spatial rectangular coordinate deviation of the receiver before and after modifying the satellite position in the actual test experiment of this invention;

[0054] Figure 22 This is a schematic diagram of the receiver clock error before and after adding pseudorange bias and modifying satellite position in the actual test of this invention;

[0055] Figure 23 This is a schematic diagram of the receiver's spatial rectangular coordinates before and after simultaneously adding pseudorange bias and modifying the satellite position in the actual test of this invention;

[0056] Figure 24 This is a schematic diagram of the receiver clock bias before and after adding pseudorange bias and modifying satellite position in the actual test of this invention;

[0057] Figure 25 This is a schematic diagram of the receiver's spatial rectangular coordinate deviation before and after adding pseudorange bias and modifying the satellite position in the actual test of this invention. Detailed Implementation

[0058] The specific embodiments of the present invention will be further described below with reference to the accompanying drawings.

[0059] This invention acquires real satellite signals, including various satellite signals used by the receiver for pseudorange positioning and timing calculations. Then, it processes each satellite signal using a pseudorange-modifying time deception algorithm, a satellite position-modifying time deception algorithm, or a simultaneous pseudorange and satellite position-modifying time deception algorithm. This process controls the receiver clock deviation, causing the receiver to perform calculations according to the processed satellite signals, thereby achieving the purpose of time deception. The implementation flow of this method is as follows: Figure 1 As shown.

[0060] Before providing a detailed explanation of each time spoofing algorithm, we will first explain the working principle of the GNSS time receiver and the corresponding time spoofing methods.

[0061] A GNSS timing receiver consists of four parts: an antenna, an RF front-end, baseband processing, and time generation. When operating in timing mode, it selects the optimal combination of satellite signals and timing methods, processes them to obtain clock bias information, and controls the local frequency standard through a discipline filter module, thereby driving the generation of time-frequency signals and time information. After taking over the target GNSS timing receiver, a GNSS deception signal broadcast by the deceiving party can alter pseudorange observations or navigation message information, causing the GNSS timing receiver to change its timing results without changing its positioning results, thus achieving the purpose of time deception.

[0062] Of the 16 satellite ephemeris parameters in the navigation message, if the following 4 ephemeris parameters are modified (one or more of the 4 parameters may be modified): satellite orbit semi-major axis a s square root Mean angular velocity correction value Δn, ephemeris reference time t oe The mean anterior angle M0 and the orbital eccentricity e s The relativistic effect correction amount Δt of satellite clock bias r If the satellite signal transmission time is changed, then both the pseudorange observation and the satellite position will be altered. Modifying the ephemeris parameters will also change the satellite position. Therefore, modifying the above four satellite parameters will simultaneously change the pseudorange observation and the satellite position. If the ephemeris reference time t among the 16 satellite ephemeris parameters is modified... oe If the satellite clock bias is changed, then the pseudorange observations and the satellite position will be altered because the satellite signal transmission time is changed. Simultaneously, modifying the ephemeris parameters will also change the satellite position. Therefore, modifying t... oe This will simultaneously change both the pseudorange observation and the satellite position. If the remaining 11 ephemeris parameters out of the 16 ephemeris parameters are modified (t...),... oe The orbital inclination i0, the right ascension of the ascending node Ω0 when the orbital time is equal to 0 during the cycle, the orbital perigee ω, and the rate of change of the orbital inclination with respect to time. Rate of change of right ascension of the ascending node of the orbit with respect to time The amplitude C of the ascending node angle distance cosine harmonic correction uc , rising node angle distance, sinusoidal harmonic correction amplitude C us Orbit radius cosine harmonic correction amplitude C rc Orbit radius sinusoidal tuning correction amplitude C rs Track inclination cosine harmonic correction amplitude C ic Orbit radius sinusoidal harmonic correction amplitude C is If the satellite position is changed, then only the pseudorange observation will be changed.

[0063] If the following four time message parameters in the navigation message are modified: the three coefficients a in the satellite clock correction model equation f0 a f1 a f2 The deviation ΔT of the group delay correction value in a single-frequency receiver GD Changing the satellite clock bias alters the pseudorange observations and satellite position because the satellite signal transmission time is changed. Modifying the handover word (HOW) will also change the pseudorange observations and satellite position.

[0064] Therefore, modifying the above navigation message parameters will at least change the satellite position. If only the pseudorange observation is changed without changing the satellite position, it should be achieved by adding a time delay to the navigation signal.

[0065] 1. Obtain the actual satellite signal from the GNSS timing receiver.

[0066] The acquired real satellite signals include the satellite signals from each satellite that the receiver uses for pseudorange positioning timing calculations.

[0067] 2. The satellite signals are processed using a pseudorange-modification time spoofing algorithm, a satellite position-modification time spoofing algorithm, or a simultaneous pseudorange and satellite position-modification time spoofing algorithm to control the receiver clock deviation and enable the receiver to perform calculations according to the processed satellite signals.

[0068] 1) Modify the pseudorange time spoofing algorithm

[0069] By reasonably modifying the pseudorange variation of each deception signal, the timing result of the target receiver can be altered without changing its positioning result. Assume that at time k, the pseudorange ρ of the target receiver corresponds to the satellite with PRN number i. i There is a deviation Δρ i The observation equation is:

[0070] R i +δt u +Δδt u =ρ i +Δρ i (1)

[0071] Where, δt u Δδt represents the receiver clock bias (equivalent to m). u R represents the receiver clock bias caused by pseudorange modification (equivalent to meters). i Represented as:

[0072]

[0073] Δx u =[Δx u ,Δy u ,Δz u ] T This represents the receiver's spatial rectangular coordinate deviation caused by the pseudorange modification. The above observation equations are then plotted in receiver spatial rectangular coordinates x... u =[x u ,y u ,z u ] T Receiver clock bias δt u Performing a first-order Taylor expansion, we get:

[0074]

[0075] Among them, R i Let represent the geometric distance between the satellite with PRN number i and the receiver. If a receiver uses pseudorange positioning with N satellites, the above formula can be expressed as:

[0076] Gδ≈Δρ (4)

[0077] Let G denote the Jacobian matrix, which depends only on the geometric position of each satellite relative to the user; δ denote the desired receiver spatial rectangular coordinate bias and receiver clock bias (set according to actual requirements); and Δρ denote the pseudorange bias vector of N satellites. The expressions for G, Δρ, and δ are:

[0078] δ=[Δx u ,Δy u ,Δz u ,Δδ u ] T (5)

[0079] According to the pseudorange positioning principle, equation (4) can be solved as follows:

[0080] δ≈(G T G) -1 G T Δρ (6)

[0081] To change the receiver clock bias while keeping the receiver's spatial rectangular coordinates constant, the pseudorange bias of the N satellites in Δρ must be equal, i.e.:

[0082] Δρ1=Δρ2=…=Δρ N (7)

[0083] By using the Jacobian matrix, the deviations of the desired receiver spatial rectangular coordinates and the receiver clock error are input into formula (4) to obtain the pseudorange deviation values ​​of each satellite.

[0084] 2) Modify the time spoofing algorithm for satellite position

[0085] Without altering the pseudorange observations, the receiver timing results can be changed by appropriately modifying the satellite's position. Assume the satellite with PRN number i has the following spatial rectangular coordinates x at time k. i =[x i ,y i ,z i ] T The deviation is Δx i =[Δx i ,Δy i ,Δz i ] T The observation equation for the target receiver corresponding to the satellite with PRN number i is:

[0086]

[0087] Where, Δδt u ρ represents the receiver clock bias caused by changes in satellite position (equivalent to in meters). i The pseudorange remains unchanged compared to before the satellite position was modified. Represented as:

[0088]

[0089] Δx u =[Δx u ,Δy u ,Δz u ] T This represents the spatial rectangular coordinate deviation of the receiver caused by changes in satellite position. The above observation equation is then plotted in satellite spatial rectangular coordinates x... i =[x i ,y i ,z i ] T Receiver spatial rectangular coordinates x u =[x u ,y u ,z u ] T Receiver clock bias δt u Performing a first-order Taylor expansion, we get:

[0090]

[0091] R i Let x represent the geometric distance between the satellite with PRN number i and the receiver. The satellite's spatial rectangular coordinates x in observation equation (8) are... i =[x i ,y i ,z i ] T Receiver spatial rectangular coordinates x u =[x u ,y u ,z u ] T Taking the partial derivatives separately, we get:

[0092]

[0093] Substituting equations (8) and (11) into equation (10), we get:

[0094]

[0095] If a receiver uses pseudorange from N satellites for positioning, the above formula can be expressed as:

[0096] Gδ≈Δs (13)

[0097] Let G denote the Jacobian matrix, which depends only on the geometric position of each satellite relative to the user. The expressions for G, δ, and Δs are:

[0098] δ=[Δx u ,Δy u ,Δz u ,Δδ u ] T

[0099]

[0100] According to the pseudorange positioning principle, equation (13) can be solved as follows:

[0101] δ≈(G T G) -1 G T Δs (15)

[0102] Based on equation (15), the positioning timing deviation caused by the satellite spatial rectangular coordinate deviation can be calculated. To ensure that the target receiver only changes the timing result while the positioning result remains unchanged, each row of elements in Δs must be equal, i.e.:

[0103]

[0104] Where b is a real number, i.e., equation (16) serves as the constraint condition for solving (15). The deviation vector Δx of the spatial rectangular coordinates of satellite i at time k... i =[Δx i ,Δy i ,Δz i ] T The geometric distance vector R between satellite i and receiver i When the two vectors above are parallel, that is, when the deviation vector of the modified spatial rectangular coordinates of satellite i is at the extension of the geometric distance vector between satellite i and the receiver, it is equivalent to making the pseudorange ρ i Extend it, as shown in equation (17).

[0105]

[0106] Substituting equation (17) into equation (16), we obtain equation (18):

[0107]

[0108] According to equations (13) and (18), the required Δδ can be obtained. u Calculate Δx i Then, from equation (17), the deviation Δx of the spatial rectangular coordinates of satellite i at time k can be obtained. i =[Δx i ,Δy i ,Δz i ] T .

[0109] 3) Simultaneously modify the pseudorange and satellite position time spoofing algorithm

[0110] The receiver timing results can be altered by appropriately modifying the satellite's position and pseudorange observations. Assume the spatial rectangular coordinates of the i-th satellite are x... i =[x i ,y i ,z i ] T The deviation is Δx i =[Δx i ,Δy i ,Δz i ] T The pseudorange ρ of this satellite i There is a deviation Δρ i Then the observation equation for the target receiver corresponding to the i-th satellite is:

[0111]

[0112] Represent the above observation equation in satellite space rectangular coordinates x i =[x i ,yi , z i T , the receiver's rectangular coordinates in space x u = [x u , y u , z u T , the receiver clock offset δt u Perform a first-order Taylor expansion. According to the derivations in steps 1) and 2), if a receiver uses N satellite pseudorange positionings, we can obtain:

[0113] Gδ ≈ Δρ + Δs (20)

[0114] According to the pseudorange positioning principle, equation (20) can be solved as:

[0115] δ ≈ (G T G) -1 G T (Δs + Δρ) (21)

[0116] Based on equation (21), the positioning and timing deviation caused by the satellite's rectangular coordinate deviation in space can be calculated. To make the target receiver only change the timing result while keeping the positioning result unchanged, the elements in each row of Δs + Δρ should be equal, that is:

[0117]

[0118] where b is a real number, that is, equation (22) is used as the constraint condition for solving (21).

[0119] To change the receiver clock offset while keeping the receiver's rectangular coordinates in space unchanged, here let the pseudorange deviation of N satellites in Δ ρ be d, and d satisfies 0 < d < b, that is:

[0120] Δρ1 = Δρ2 = … = Δρ N = d (23)

[0121] In addition, when the deviation vector Δx i of the satellite i's rectangular coordinates in space at time k and the geometric distance vector R i , between the satellite i and the receiver are parallel, it is equivalent to extending the pseudorange ρ i , and the expression is as in equation (17). Substituting equation (17) into equation (22), we can obtain equation (24): i T , the geometric distance vector between satellite i and the receiver i , when the above two vectors are parallel, it is equivalent to extending the pseudorange ρ i , and the expression is as in equation (17). Substituting equation (17) into equation (22), we can obtain equation (24):

[0122]

[0123] ​​​According to equations (20), (23), and (24), the required Δδ can be obtained. u Calculate Δx i Then, from equation (17), the deviation Δx of the spatial rectangular coordinates of satellite i at time k can be obtained. i =[Δx i ,Δy i ,Δz i ] T .

[0124] Simulation experiment verification

[0125] The following simulation experiments verify the time deception methods for modifying pseudorange, satellite position, and both pseudorange and satellite position. The purpose of the deception is to introduce a 10μs timing error (equivalent to a 3000m distance error) into the target receiver's single-epoch pseudorange positioning timing calculation, while not introducing a positioning error.

[0126] Experiment 1: Using a time-spoofing algorithm with modified pseudorange, at epoch k, the receiver uses 6 satellites for pseudorange positioning timing calculation, incorporating equal pseudorange bias into all 6 satellite signals. During the pseudorange positioning timing calculation, the receiver uses the least squares method to solve for each Newton iteration loop, with the number of iterations at epoch k being 3-6. Figure 2 The dashed and solid lines represent the receiver clock errors when no pseudorange bias is added and when pseudorange bias is added, respectively. Figure 2 The dashed and solid lines represent the receiver's spatial rectangular coordinates without pseudorange bias and with pseudorange bias, respectively. Figure 4 This indicates the receiver clock bias with and without pseudorange bias. Figure 5 This indicates the spatial rectangular coordinate deviation of the receiver with and without pseudorange bias.

[0127] according to Figure 2 and Figure 4 (For ease of representation, Figure 4 For receiver clock bias δt u The difference from 3000, after modifying the pseudorange, the receiver clock error causes a change of 3000m; according to Figure 3 and Figure 5 After modifying the pseudorange, the receiver's spatial rectangular coordinates hardly changed, indicating that the time deception algorithm for modifying the pseudorange can achieve the purpose of time deception for the single-epoch pseudorange positioning timing calculation of the target receiver.

[0128] Experiment 2: Using a time spoofing algorithm that modifies satellite positions, at epoch k, the receiver uses 6 satellites for pseudorange positioning timing calculation. Following the calculation algorithm in step 2), the positions of all 6 satellites are adjusted to include the corresponding positional deviation. During the pseudorange positioning timing calculation, the receiver uses the least squares method to solve for each Newton iteration loop. The number of iterations at epoch k is taken as 3-6. Figure 6 The dashed and solid lines represent the receiver clock bias when the satellite position is not modified and when the satellite position is modified, respectively. Figure 7 The dashed and solid lines represent the receiver's spatial rectangular coordinates when the satellite position is not modified and when the satellite position is modified, respectively. Figure 8 This indicates the receiver clock bias when the satellite position is modified and when the satellite position is not modified. Figure 9 This indicates the spatial rectangular coordinate deviation of the receiver when the satellite position is modified and when the satellite position is not modified.

[0129] according to Figure 6 and Figure 8 After the satellite position was modified, the receiver's spatial rectangular coordinates changed by 124.74m; according to Figure 7 and Figure 9 After modifying the satellite position, the receiver clock bias deviation differed from 3000m by -128.71m. This demonstrates that for single-epoch pseudorange positioning timing calculations of the target receiver, the time deception algorithm by modifying the satellite position can essentially achieve the purpose of time deception.

[0130] Experiment 3: Using a time deception method that simultaneously modifies pseudorange and satellite positions, at epoch k, the receiver uses 6 satellites for pseudorange positioning timing calculation. According to the calculation algorithm in step 3), the positions of all 6 satellites are given the corresponding positional deviation, and the pseudorange deviation d = 1500m is given for all 6 satellite signals. Then, in equation (24), bd = 1500m. During the pseudorange positioning timing calculation, the receiver uses the least squares method to solve each Newton iteration loop. The number of iterations at epoch k is taken as 3-6. Figure 10 The dashed and solid lines represent the receiver clock biases when no pseudorange bias is added and the satellite position is not modified, and when pseudorange bias is added and the satellite position is modified, respectively. Figure 11 The dashed and solid lines represent the receiver's spatial rectangular coordinates when no pseudorange bias is added and the satellite position is not modified, and when pseudorange bias is added and the satellite position is modified, respectively. Figure 12 This indicates the receiver clock bias with pseudorange bias and satellite position modification added, and without pseudorange bias and satellite position modification. Figure 13 This indicates the receiver's spatial rectangular coordinate deviation when pseudorange bias is added and satellite position is modified, and when pseudorange bias is not added and satellite position is not modified.

[0131] according to Figure 10 and Figure 12After simultaneously modifying the pseudorange and satellite position, the receiver clock bias deviation differed from 3000m by -64.35m; according to Figure 11 and Figure 13 After simultaneously modifying the pseudorange and satellite position, the receiver's spatial rectangular coordinates changed by 62.37m. This demonstrates that for the single-epoch pseudorange positioning timing calculation of the target receiver, the time deception algorithm that simultaneously modifies the pseudorange and satellite position effectively achieves the time deception objective.

[0132] Table 1 presents the statistical results of the three experiments, where ΔR represents the receiver's spatial rectangular coordinate deviation. As shown in Table 1, the time spoofing algorithm with modified pseudorange exhibits the best performance, with an average difference between the receiver clock error deviation and 3000m of -1.16 × 10⁻⁶. -8 m, the average change in the receiver's spatial rectangular coordinates is -1.56 × 10 m. -8 The algorithm that modifies both pseudorange and satellite position achieves a time deception objective completely. The algorithm that modifies satellite position is slightly less effective, with a receiver clock error difference of -128.71m from 3000m and a change in the receiver's spatial rectangular coordinates of 124.74m. This can be considered to have basically achieved the time deception objective. The algorithm that modifies both pseudorange and satellite position simultaneously achieves a time deception objective between the two algorithms mentioned above, with a receiver clock error difference of -64.35m from 3000m and a change in the receiver's spatial rectangular coordinates of 62.37m. This can be considered to have achieved the time deception objective relatively well.

[0133] Table 1

[0134]

[0135] Actual measurement experiments verified

[0136] The following experiments verify the time deception algorithms for modifying pseudorange, modifying satellite position, and simultaneously modifying both pseudorange and satellite position. The purpose of the deception is to introduce a timing error of 10 μs (equivalent to a distance error of 3000 m) into the pseudorange positioning timing calculation of the target receiver at each epoch, while not introducing a positioning error.

[0137] The experiment used open-source GNSS observation data provided by Curin GNSS-SPAN Group. Continuously Operating Reference Stations (CORS) CUTA0 was selected, with a TRM59800.00SCIS receiver antenna and a JAVAD TRE_G3TH_8 receiver. The observation period was from 00:00:00 on January 4, 2018 to 03:00:00 on January 4, 2018, for a total observation duration of 3 hours. The data update interval was 30 seconds.

[0138] Experiment 4: Using a time deception algorithm that modifies pseudorange, at epoch k, the receiver uses more than 4 satellites for pseudorange positioning timing calculation. Following the calculation algorithm in step 1), equal pseudorange bias is added to each satellite signal. Figure 14 The dashed and solid lines represent the receiver clock errors when no pseudorange bias is added and when pseudorange bias is added, respectively. Figure 15 The dashed and solid lines represent the receiver's spatial rectangular coordinates without pseudorange bias and with pseudorange bias, respectively. Figure 16 This indicates the receiver clock bias with and without pseudorange bias. Figure 17 This indicates the spatial rectangular coordinate deviation of the receiver with and without pseudorange bias.

[0139] according to Figure 14 and Figure 16 (For ease of representation, Figure 16 For receiver clock bias δt u The difference from 3000, after modifying the pseudorange, the receiver clock error causes a change of 3000m; according to Figure 15 and Figure 17 After modifying the pseudorange, the receiver's spatial rectangular coordinates remained almost unchanged. This demonstrates that the pseudorange-modified time deception algorithm can achieve time deception for pseudorange positioning timing calculations of the target receiver.

[0140] Experiment 5: Using a time spoofing algorithm that modifies satellite positions, at epoch k, the receiver uses more than 4 satellites for pseudorange positioning timing calculation. Following the calculation algorithm in section 2), the positions of each satellite are adjusted to include the corresponding positional deviation. Figure 18 The dashed and solid lines represent the receiver clock bias when the satellite position is not modified and when the satellite position is modified, respectively. Figure 19 The dashed and solid lines represent the receiver's spatial rectangular coordinates when the satellite position is not modified and when the satellite position is modified, respectively. Figure 20 This indicates the receiver clock bias when the satellite position is modified and when the satellite position is not modified. Figure 21 This indicates the spatial rectangular coordinate deviation of the receiver when the satellite position is modified and when the satellite position is not modified.

[0141] according to Figure 18 and Figure 20 After modifying the satellite position, the average difference between the receiver clock bias and 3000m was -117.80m; according to Figure 19 and Figure 21 After modifying the satellite position, the receiver's spatial rectangular coordinates changed by an average of 109.08m. This demonstrates that for single-epoch pseudorange positioning timing calculations of the target receiver, the time deception algorithm involving modifying the satellite position can essentially achieve the purpose of time deception.

[0142] Experiment 6: Using a time deception algorithm that simultaneously modifies pseudorange and satellite position, at epoch k, the receiver uses more than 4 satellites for pseudorange positioning timing calculation. According to the calculation algorithm in step 3), the position of each satellite is increased by the corresponding position deviation, and the pseudorange deviation of each satellite signal is increased by the corresponding pseudorange deviation d = 1500m. Then, in equation (24), bd = 1500m. Figure 22 The dashed and solid lines represent the receiver clock biases when no pseudorange bias is added and the satellite position is not modified, and when pseudorange bias is added and the satellite position is modified, respectively. Figure 23 The dashed and solid lines represent the receiver's spatial rectangular coordinates when no pseudorange bias is added and the satellite position is not modified, and when pseudorange bias is added and the satellite position is modified, respectively. Figure 24 This indicates the receiver clock bias with pseudorange bias and satellite position modification added, and without pseudorange bias and satellite position modification. Figure 25 This indicates the receiver's spatial rectangular coordinate deviation when pseudorange bias is added and satellite position is modified, and when pseudorange bias is not added and satellite position is not modified.

[0143] according to Figure 22 and Figure 24 After simultaneously modifying the pseudorange and satellite position, the average difference between the receiver clock bias and 3000m was -58.90m; according to Figure 23 and Figure 25 After simultaneously modifying the pseudorange and satellite position, the average change in the receiver's spatial rectangular coordinates was 54.55m. This demonstrates that for the single-epoch pseudorange positioning timing calculation of the target receiver, the time deception algorithm that simultaneously modifies the pseudorange and satellite position effectively achieves the time deception objective.

[0144] Table 2 presents the statistical results of the three experiments, where ΔR represents the receiver's spatial rectangular coordinate deviation. As shown in Table 2, the pseudorange modification time deception algorithm is the most effective, and can be considered to have completely achieved the purpose of time deception. The satellite position modification time deception algorithm is slightly less effective, with an average change in receiver spatial rectangular coordinates of 109.08m and an average difference between the receiver clock bias and 3000m of -117.80m, which can be considered to have basically achieved the purpose of time deception. The simultaneous pseudorange and satellite position modification time deception algorithms fall between the two algorithms mentioned above, with an average change in receiver spatial rectangular coordinates of 54.55m and an average difference between the receiver clock bias and 3000m of -58.90m, which can be considered to have achieved the purpose of time deception quite well.

[0145] Table 2

[0146]

[0147] Although the time deception algorithm for modifying satellite position is slightly less effective than the time deception algorithm for modifying pseudorange, the latter does not require adding pseudorange delay and can be achieved by modifying navigation message parameters. Therefore, it is not easy for the target receiver to detect pseudorange delay and thus detect the deception. In fact, the time deception algorithm for modifying satellite position has basically achieved the purpose of time deception.

Claims

1. A method of time spoofing against a GNSS time receiver, characterized in that, The method comprises the following steps: 1) obtaining real satellite signals, wherein the real satellite signals comprise satellite signals for pseudo-range positioning and timing solution of a receiver; 2) processing the satellite signals by using a time deception algorithm for modifying pseudo-range, a time deception algorithm for modifying satellite position or a time deception algorithm for simultaneously modifying pseudo-range and satellite position, so that the receiver solves according to the processed satellite signals; the time deception algorithm for modifying pseudo-range refers to adding equal pseudo-range deviation in the satellite signals; the time deception algorithm for modifying satellite position refers to adding corresponding position deviation in the satellite position signals in the satellite signals; the time deception algorithm for simultaneously modifying pseudo-range and satellite position refers to simultaneously modifying the pseudo-range and satellite position of the satellite signals; when the time deception algorithm for modifying pseudo-range is used, the time delay can be added to the navigation signal.

2. The method of time spoofing against a GNSS time receiver according to claim 1, characterized in that, When a time deception algorithm of modifying satellite position is adopted, the satellite position can be changed by modifying i0, Ω0, ω, C uc , C us , C rc , C rs , C ic , C is in ephemeris parameters, i0 is the orbit inclination at the ephemeris reference time t oe , Ω0 is the orbit longitude of ascending node when the mean anomaly is equal to 0, ω is the orbit angle of perigee, is the change rate of orbit inclination to time, is the change rate of orbit longitude of ascending node to time, C uc is the amplitude of cosine harmonic correction of the angle of ascending node, C us is the amplitude of sine harmonic correction of the angle of ascending node, C rc is the amplitude of cosine harmonic correction of the orbit radius, C rs is the amplitude of sine harmonic correction of the orbit radius, C ic is the amplitude of cosine harmonic correction of the orbit inclination, C is is the amplitude of sine harmonic correction of the orbit radius.

3. The method of claim 1, wherein, When a time deception algorithm that modifies both the pseudorange and the satellite position is used, the pseudorange observation and the satellite position can be changed simultaneously by modifying the square root of the semi-major axis a s of the satellite orbit The mean motion angular velocity correction value Δn, the ephemeris reference time t oe The mean anomaly M0, the orbital eccentricity e s at the time when the mean motion angular velocity correction value Δn, the ephemeris reference time t 4. The method of claim 1, wherein, When the time spoofing algorithm that modifies both pseudorange and satellite position is employed, the pseudorange observation and satellite position can be changed simultaneously by modifying the reference time t oe of the ephemeris.

5. The method of claim 1, wherein, When a time spoofing algorithm that modifies both pseudorange and satellite position is employed, the three coefficients a f0 、a f1 、a f2 of the satellite clock correction model equation can be simultaneously changed to alter both the pseudorange observation and the satellite position by modifying the group delay correction value existing in single frequency receivers, ΔT GD .

6. The method of claim 1, wherein, when the time deception algorithm for modifying pseudo-range is used, the added pseudo-range deviation Δρ is: Gδ≈Δρ delta = [delta x u , delta y u , delta z u , delta delta u ] T Δρ1= Δρ2=... = Δρ N where N is the number of satellites; G is the Jacobian matrix, which is only related to the geometric positions of each satellite relative to the user; δ represents the expected receiver spatial rectangular coordinate bias and the receiver clock bias bias; R i represents the geometric distance between the satellite with PRN number i and the receiver; Δδ u is the expected receiver clock bias bias; (Δx u , Δy u , Δz u ) is the expected receiver spatial rectangular coordinate bias; Δρ i is the pseudo-range bias quantity of the satellite with PRN number i.

7. The method of claim 2, wherein, when the time deception algorithm for modifying satellite position is used, the satellite position deviation is calculated by using the following formula: where [Δx i ,Δy i ,Δz i ] is the position bias of the satellite with PRN number i; R i represents the geometric distance between the satellite with PRN number i and the receiver; (Δx u ,Δy u ,Δz u ) is the expected spatial rectangular coordinate bias of the receiver, and b is a real number.

8. The method of time spoofing against a GNSS time receiver according to any of claims 3-5, characterized in that, when the time deception algorithm for simultaneously modifying pseudo-range and satellite position is used, the calculation formula of the pseudo-range observation and the satellite position deviation is: Δρ1= Δρ2=... = Δρ N = d where [Δx i ,Δy i ,Δz i ] is the position bias of the satellite with PRN number i; R i represents the geometric distance between the satellite with PRN number i and the receiver; (Δx u ,Δy u ,Δz u ) is the expected spatial rectangular coordinate bias of the receiver, b is a real number, and Δρ i is the pseudo-range bias of the satellite with PRN number i, and d is a real number.

Citation Information

Patent Citations

  • Method for detecting Beidou deception jamming based on receiver relative distance

    CN110161537A