Iq branch-based sqm satellite navigation spoofing detection method
By using the IQ branch-based SQM satellite navigation spoofing detection method, detection indicators are established by utilizing the energy changes of the IQ branch, and actual and theoretical threshold values are derived. This solves the problems of insufficient detection accuracy and robustness in existing technologies and achieves higher spoofing interference detection performance and robustness.
Patent Information
- Application Number
- CN202211432865.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-16
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2042-11-16
AI Technical Summary
Existing SQM detection methods lack accuracy and robustness when detecting satellite navigation spoofing signals, especially when there are phase changes between the real and spoofing signals, the detection quantity fluctuates drastically, leading to a decrease in detection accuracy and robustness.
A SQM satellite navigation spoofing detection method based on IQ branch is adopted. By establishing a detection index based on IQ branch energy change, deriving actual and theoretical threshold values, and using multiple detection thresholds for judgment, the detection performance and robustness are improved.
Without changing the basic receiver architecture or increasing the number of correlators, the detection probability and robustness are improved, achieving higher performance in detecting deception interference.
Smart Images

Figure CN115755108B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of satellite navigation signal processing technology, and more specifically to an SQM satellite navigation spoofing detection method based on the IQ branch. Background Technology
[0002] Global Navigation Satellite Systems (GNSS) are now widely used in civilian and military navigation and positioning infrastructures, providing them with all-weather, high-precision, and high-efficiency position, velocity, and time (PVT) information services. However, due to the inherent vulnerabilities of GNSS's open signal structure and low power, it is susceptible to interference and spoofing. Interference reduces the carrier-to-noise ratio of the received signal by transmitting suppressive signals, while spoofing generates deceptive signals that resemble the real signal or produces a real signal with forwarding delays and power amplification, causing the receiver to obtain incorrect navigation and timing information. Compared to interference signals, spoofing signals are more concealed and destructive, making them one of the most favored spoofing attack methods. In recent years, the continuous updates to GNSS spoofing technology have posed a significant threat to the accuracy, availability, continuity, and integrity of GNSS. Therefore, detection and identification technologies for spoofing and interference signals are of great importance to the safe use of GNSS signals.
[0003] Deception interference detection technology based on signal characteristics is the mainstream technology for GNSS interference and anti-interference in modern times. When deception interference exists, the deception signal and the real signal will produce different values or specific characteristics after being processed by radio frequency front-end, digital signal, etc. Deception interference can be detected based on different antenna design methods, automatic gain control (AGC), signal strength, signal quality monitoring (SQM), Doppler consistency, signal arrival time and signal arrival angle, etc.
[0004] SQM (Signal Quality Management) technology detects spoofing attacks by monitoring the correlation peak distortion caused by the interaction between genuine navigation satellite signals and spoofing jamming signals. When a spoofing jamming signal successfully enters the tracking loop, it causes the correlation peak to become abnormally sharp, flat, or asymmetrical. Various SQM metrics have been designed based on the correlator output values at different times, with Delta and Ratio being common. The detection values used in SQM can be calculated using only the outputs of the early correlator, immediate correlator, and late correlator without any other external dependencies. Detecting spoofing attacks by setting thresholds is effective. Due to its simplicity and efficiency, SQM is highly favored in multipath detection and spoofing detection.
[0005] Traditional SQM metrics (such as Delta and Ratio metrics) use the output of a single in-phase branch correlator in the tracking loop to determine whether the receiver has been spoofed. However, the fluctuation between the in-phase and quadrature branches caused by the change in the relative phase of the real signal and the spoofed signal with respect to the carrier can cause drastic fluctuations in the SQM detection, resulting in a decrease in the overall accuracy and robustness of spoofing interference detection. Summary of the Invention
[0006] The technical problem to be solved by this invention is: This invention provides an SQM satellite navigation spoofing detection method based on IQ branch, which uses multiple detection thresholds for judgment, thereby improving detection performance and robustness.
[0007] To solve the above-mentioned technical problems, the technical solution proposed by this invention is as follows:
[0008] A satellite navigation spoofing detection method based on IQ branch is proposed. The spoofing detection method first establishes SQM detection index based on the energy change of IQ dual branch, then derives the actual application measurement threshold and the theoretical calculation threshold, and then compares the SQM detection quantity with the measurement threshold and the theoretical calculation threshold to detect whether it is subject to spoofing interference.
[0009] A further improvement to the above technical solution is as follows:
[0010] Preferably, the deception detection method includes the following steps:
[0011] S1. When only real signals exist, the satellite receiver searches for and tracks M satellite signals.
[0012] S2. During the tracking phase, the I and Q branches are respectively operated with the locally copied C / A code to obtain the outputs of the in-phase I and quadrature Q branch correlators;
[0013] S3. Based on the output values of the early, immediate, and late correlators of the I and Q branches, establish the SQM detection metric M. value ;
[0014] S4. Set the maximum false alarm probability that the detection must meet, based on the calculated actual detection metric M. value The measurement threshold value Thresold is derived. mea ;
[0015] S5. Utilize a smooth moving window to process the detection metric M. value ;
[0016] S6. Calculate the detection metric value M value The mean M value-mean and variance M value-varBased on the Neyman-Pearson criterion, and with the same false alarm probability as S4, the threshold value Thresold is derived for calculation. cal ;
[0017] S7. During the deception interference detection phase, the SQM detection quantity M is calculated using the early, immediate, and late correlator output values of the IQ branch. act-val For the detection quantity M act-val Perform smooth movement processing;
[0018] S8. The detection quantity M obtained in step S7 act-val The value is the same as the measurement threshold value Thresold obtained in step S4. mea The calculated threshold value Thresold obtained in step S6 cal For comparison, if the detection quantity M act-val If the value is greater than the measurement threshold and the calculation threshold, then deceptive interference is considered to exist.
[0019] Preferably, in step S1, the received satellite signal is:
[0020]
[0021] In the formula, n is the sampling sequence number; T s It is the sampling period of the intermediate frequency signal; the subscript l is the pseudo-random code number of the satellite, and M is the number of real satellite signals received; It's a real signal. The deception signal sent by the deception device to the target receiver is represented by the superscripts a and s, which indicate the real signal and the deception signal, respectively; η(nT) s This is band-limited additive white Gaussian noise;
[0022] The l-th channel signal model is represented as:
[0023]
[0024] In the formula, the relative amplitude α of the real signal A =1, the relative amplitude α of the deception signal S >1; P l C is the received power of channel l received by the antenna; l (·), D l (·) represent the pseudo-random spreading code and navigation data bits, respectively; f IF The center frequency; f l τ is the Doppler frequency; l For code propagation delay; This is the initial carrier phase.
[0025] Preferably, in step S2, the signal from step S1 is demodulated using I / Q modulation, and after coherent integration, the autocorrelation function of the in-phase I and quadrature Q branch correlators is:
[0026]
[0027] In the formula, R(·) represents the C / A code autocorrelation function with a maximum value of 1, and τ A τ S To instantly replicate the phase difference between the C / A code and the real and deceptive signal codes, τ A / S =dT s Where d is the interval between the early or late correlator and the immediate correlator, and T s It is the sampling period of the intermediate frequency signal.
[0028] Preferably, in step S3, an SQM detection metric M is established based on the early, immediate, and late correlator output values of the I and Q branches. value The formula is:
[0029]
[0030] In the formula, I Ed (n), I P (n) and I Ld (n) represent the early, immediate, and late correlator outputs of the in-phase channel within the nth coherent integral, respectively, Q. Ed (n) and Q Ld (n) are the early and late correlator outputs of the positive traffic channel within the nth coherent integral, respectively.
[0031] Preferably, in step S4, the maximum false alarm probability P that the detection must satisfy is set. fa-mea P fa-mea satisfy:
[0032]
[0033] In the formula, M value (n) is the real signal M value The value of the nth sample in the dataset, count(M) Value (n)>Thresold mea ) represents the detection metric M Value Greater than the measurement threshold Thresold mea The total count value;
[0034] Measurement threshold Thresold mea The expression is:
[0035] Thresold mea =M Value([N m ×(1-P fa-mea (9)
[0036] Where [·] is the floor function; N m The length of the actual signal dataset.
[0037] Preferably, in step S6, the false alarm probability P is derived when calculating the threshold value. fa-cal for:
[0038]
[0039] In the formula, f M (x) represents the SQM detection metric M when there is no deception attack. value The probability density function is given, and erfc(·) is the complementary error function; the threshold value Thresold is obtained. cal The expression is
[0040]
[0041] The SQM satellite navigation spoofing detection method based on IQ branch provided by this invention has the following advantages compared with the prior art:
[0042] (1) The SQM satellite navigation spoofing detection method based on the IQ branch of the present invention saves hardware resources and is easy to implement without changing the basic architecture of the traditional receiver or increasing the number of correlators. Compared with the traditional SQM algorithm which only considers the energy change of the in-phase I branch and some improved SQM detection metrics, it has a higher detection probability under the same false alarm probability.
[0043] (2) The present invention proposes a measurement threshold Thresold for the SQM satellite navigation spoofing detection method based on the IQ branch. mea It is the actual threshold value derived from current real GNSS data, while the calculated threshold value is Thresold. cal It is based on the detection metric M value The theoretical threshold value is calculated from the probability distribution. Using the two threshold values together is more practical and has higher detection performance compared to the single theoretical threshold value of the existing SQM algorithm. Attached Figure Description
[0044] Fig. 1 This is a schematic flowchart of the detection method of the present invention.
[0045] Fig. 2 This invention is applied in the TeXBAT dataset Clean Static and DS2 under M... value A graph showing the measurement of the detected quantity.
[0046] Fig. 3 When this invention is applied, the false alarm probability is 10. -3 Measurement threshold under the DS2 dataset of the TEXBAT dataset. Detailed Implementation
[0047] The following provides a detailed description of specific embodiments of the present invention. It should be understood that the specific embodiments described herein are for illustrative and explanatory purposes only and are not intended to limit the scope of the invention.
[0048] Figs. 1 to 3 This paper illustrates one implementation of the SQM satellite navigation spoofing detection method based on the IQ branch of the present invention. When only the real signal is present, the in-phase I branch contains energy and some noise, while the quadrature Q branch is essentially just noise. When a spoofing signal is present, the carrier phase difference between the real signal and the spoofing signal causes a slight energy change in the quadrature Q branch. For the receiver to successfully lock onto the spoofing signal, the spoofing signal energy must be slightly greater than the real signal. Simultaneously, the movement of the spoofing signal transmitting antenna relative to the receiver also causes an increase in the noise floor. Based on the energy changes of the IQ dual branches, an SQM detection index is established, and the practical application measurement threshold Thresold is derived. mea and theoretically calculated threshold value Thresold cal The SQM detection quantity is compared with the dual-threshold method to detect whether it is subject to deceptive interference. The SQM detection index based on the energy change of the IQ dual-branch has higher detection performance than the traditional SQM index of a single in-phase branch.
[0049] Specifically, the following steps are included:
[0050] Step S1: When only real signals exist, the satellite receiver searches for and tracks M satellite signals.
[0051] The received GNSS intermediate frequency signal can be represented as:
[0052]
[0053] In the formula, n is the sampling sequence number; T s It is the sampling period of the intermediate frequency signal; the subscript l is the pseudo-random code number of the satellite, and M is the number of real satellite signals received; It's a real signal. The deception signal sent by the deception device to the target receiver is represented by the superscripts A and S, which indicate the real signal and the deception signal, respectively; η(nT) s ) is band-limited additive Gaussian white noise.
[0054] The number of spoofing signals and real satellite signals is the same, and the pseudo-random noise codes (PRN numbers) correspond one-to-one, having the same signal structure. The l-th channel signal model is represented as:
[0055]
[0056] In the formula, the relative amplitude α of the real signal A =1, the relative amplitude α of the deception signal S >1; P l C is the received power of channel l received by the antenna; l (·), D l (·) represent the pseudo-random spreading code and navigation data bits, respectively; f IF The center frequency; f l τ is the Doppler frequency; l Code propagation delay (code phase); This is the initial carrier phase.
[0057] Step S2: During the tracking phase, the I and Q branches are correlated with the locally copied C / A code to obtain the outputs of the in-phase I and quadrature Q branch correlators.
[0058] After the intermediate frequency signal received by the antenna is demodulated by I / Q, the I and Q branches are correlated with the locally copied C / A code, respectively. After coherent integration, the coherent integral values I(n) and Q(n) of the IQ branches can be expressed as:
[0059]
[0060]
[0061] In the formula, P represents the amplitude of the actual signal; τ A τ S To instantly replicate the phase difference between the C / A code and the real and deceptive signal codes, τ A / S =dT s Where d is the interval between the early or late correlator and the instantaneous correlator; for a typical receiver, the correlator interval d ranges from 0.1 to 0.5 chips, and the correlator interval used in this embodiment is uniformly defined as 0.5 chips; and These represent the Doppler differences between the local code and the real satellite signal, and between the local code and the spoofed signal, respectively. and T represents the carrier phase difference between the local code and the real satellite signal, and between the local code and the spoofed signal, respectively; coh For coherent integration time; η I and η QFor the Gaussian noise of the I and Q branches; sinc(x) = [sin(πx)] / πx; R(·) represents the C / A code autocorrelation function with a maximum value of 1.
[0062] Taking the C / A code of GPS L1 signal as an example, it can be represented as:
[0063]
[0064] Step S3: Based on the early, immediate, and late correlator output values of the I and Q branches, establish the SQM detection metric M. value The formula is as follows:
[0065]
[0066] In the formula, I Ed (n), I P (n) and I Ld (n) represent the early, immediate, and late correlator outputs of the in-phase channel within the nth coherent integral, respectively, Q. Ed (n) and Q Ld (n) are the early and late correlator outputs of the positive traffic channel within the nth coherent integral, respectively.
[0067] Step S4: Set the maximum false alarm probability that the detection must meet, based on the calculated true detection metric M. value The measurement threshold value Thresold is derived. mea .
[0068] Measurement threshold Thresold mea The novel detection metric M, calculated from real GNSS data, is determined based on available datasets under non-deceptive interference conditions. Value Sort in ascending order as follows:
[0069] M Value (1)≤M Value (2)≤…M Value (n)≤…≤M Value (N m -1)≤M Value (N m (7)
[0070] Where, N m The length of the actual signal dataset.
[0071] The false alarm probability represents the probability that a signal is mistakenly detected even when it does not actually exist. The maximum false alarm probability P that the detection must satisfy is defined as follows. fa-mea Below, P fa-mea satisfy:
[0072]
[0073] In the formula, M value (n) is the real signal M value The value of the nth sample in the dataset, count(M) Value (n)>Thresold mea ) represents the detection metric M Value Greater than the measurement threshold Thresold mea The total count value. The measurement threshold value Thresold can be obtained according to formula (8). mea The expression is:
[0074] Thresold mea =M Value ([N m ×(1-P fa-mea (9)
[0075] Where [·] is the floor function.
[0076] Step S5: Detect the measurement value M value A moving average is applied to reduce the probability of false alarms caused by abnormal fluctuations.
[0077] In all detection metrics M value Select a subset of length L and calculate its mean. Form a sliding window with a fixed sliding interval W. Move the sliding window forward to select a new subset and calculate its mean. Repeat this process until the sliding window reaches the end of the dataset. The total number of slides is the ratio of the total dataset length to the window length. The mean SQM detections of the k-th sliding window can be expressed as:
[0078]
[0079] In the formula M value (i) is M value The value of the i-th sample in the dataset.
[0080] Step S6: Calculate the detection metric M value Mean M of data values value-mean and variance M value-var Based on the Neyman-Pearson criterion, and with the same false alarm probability as in step S4, the threshold value Thresold is derived. cal The specific derivation process is as follows:
[0081] Under the premise of only real satellite signals and without loss of generality, according to formulas (3), (4), and (5), the coherent integral result of the IQ branch can be expressed as:
[0082]
[0083]
[0084] Assuming the residual Doppler frequency shift error is negligible, η I and η Q Uncorrelated, I(n) and Q(n) follow a normal distribution. The theoretical statistics of I(n) and Q(n) without deception are as follows:
[0085]
[0086] Where, μ I(n) and μ Q(n) These are the average values of the outputs of the correlators in the same phase branch; and Let be the variances of the outputs of the orthogonal branch correlators, assuming...
[0087] M value See as different The absolute value of the sum of the products is expressed by the formula:
[0088]
[0089] Equation (13) provides the theoretical distribution of the output values of the in-phase quadrature correlator in the early, immediate, and late stages. Equation (14) can be expanded to obtain:
[0090]
[0091] Given that the variance of f(x,y) = x / y after Taylor expansion is Will and Substituting these values, we can obtain the corresponding mean and variance, which can be expressed as:
[0092]
[0093]
[0094] It is deduced that z1 and z3 follow a Gaussian distribution with the same mean and variance, and z2 and z4 follow a Gaussian distribution with the same mean and variance. When two independent Gaussian distributions are multiplied, they still result in a single Gaussian distribution. That is, z1×z2 and z3×z4 each follow a Gaussian distribution with the same mean and variance. When two independent Gaussian distributions are added, they still result in a single Gaussian distribution. That is, z1×z2 + z3×z4 is a normal distribution, which can be expressed as:
[0095]
[0096] Given the mean and variance of z1×z2+z3×z4, the mean and variance of |z1×z2+z3×z4| can be derived using the probability density function, thus revealing M. value Let be a Gaussian distributed variable, which can be represented as:
[0097]
[0098]
[0099] At this time M value ~(M) value-mean M value-var The detection threshold can be calculated based on the Neyman-Pearson criterion.
[0100] For a given calculation threshold Thresold cal False alarm probability P fa-cal The calculation is as follows:
[0101]
[0102] In the formula, f M (x) represents the SQM detection metric M when there is no deception attack. value The probability density function is erfc(·), which is the complementary error function. The threshold value Thresold can be calculated according to formula (21). cal The expression is
[0103]
[0104] It is evident that the threshold value Thresold can be calculated. cal It is determined by the false alarm probability P fa-cal and detection metric M value The statistics are determined.
[0105] Step S7: In the deception interference detection phase, calculate the SQM detection quantity M using the early, immediate, and late correlator output values of the IQ branch. act-val Perform smooth movement processing.
[0106] Step S8: Calculate the detection quantity M obtained in step S7. act-val The value is the same as the measurement threshold value Thresold obtained in step S4. mea The calculated threshold value Thresold obtained in step S6 cal Compare, if M act-val If the value is greater than the measurement threshold and the calculation threshold, then deceptive interference is considered to exist.
[0107] The satellite navigation signal spoofing detection method proposed in this invention uses the output value of the IQ branch correlator to establish the SQM detection quantity for spoofing interference detection. Multiple detection thresholds are used for judgment. Compared with the traditional SQM detection quantity, it has a higher detection probability under the same false alarm probability, and the detection performance and robustness are improved.
[0108] The above embodiments are merely preferred examples of the present invention and are not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Therefore, any simple modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention should fall within the protection scope of the present invention.
Claims
1. A SQM satellite navigation spoofing detection method based on IQ branches, characterized in that, The deception detection method first establishes the SQM detection index based on the energy change of the IQ dual-branch, then derives the actual application measurement threshold and the theoretical calculation threshold, and then compares the SQM detection quantity with the measurement threshold and the theoretical calculation threshold to detect whether it is affected by deception interference. The deception detection method includes the following steps: S1. When only real signals exist, the satellite receiver searches for and tracks M satellite signals. S2. During the tracking phase, the I and Q branches are respectively operated with the locally copied C / A code to obtain the outputs of the in-phase I and quadrature Q branch correlators; S3. Based on the output values of the early, immediate, and late correlators of the I and Q branches, establish the SQM detection metric M. value ; S4. Set the maximum false alarm probability that the detection must meet, based on the calculated actual detection metric M. value The measurement threshold value Thresold is derived. mea ; S5. Utilize a smooth moving window to process the detection metric M. value ; S6. Calculate the detection metric value M value The mean M value-mean and variance M value-var Based on the Neyman-Pearson criterion, and with the same false alarm probability as S4, the threshold value Thresold is derived for calculation. cal ; S7. During the deception interference detection phase, the SQM detection quantity M is calculated using the early, immediate, and late correlator output values of the IQ branch. act-val For the detection quantity M act-val Perform smooth movement processing; S8. The detection quantity M obtained in step S7 act-val The value is the same as the measurement threshold value Thresold obtained in step S4. mea The calculated threshold value Thresold obtained in step S6 cal For comparison, if the detection quantity M act-val If the value is greater than the measurement threshold and the calculation threshold, then deceptive interference is considered to exist.
2. The SQM satellite navigation spoofing detection method based on IQ branch according to claim 1, characterized in that, In step S1, the received satellite signal is: In the formula, n is the sampling sequence number; T s It is the sampling period of the intermediate frequency signal; the subscript l is the pseudo-random code number of the satellite, and M is the number of real satellite signals received; It's a real signal. The deception signal sent by the deception device to the target receiver is represented by the superscripts A and S, which indicate the real signal and the deception signal, respectively; η(nT) s This is band-limited additive white Gaussian noise; The l-th channel signal model is represented as: In the formula, the relative amplitude α of the real signal A =1, the relative amplitude α of the deception signal S >1; P l C is the received power of channel l received by the antenna; l (·), D l (·) represent the pseudo-random spreading code and navigation data bits, respectively; f IF The center frequency; f l τ is the Doppler frequency; l For code propagation delay; This is the initial carrier phase.
3. The SQM satellite navigation spoofing detection method based on IQ branch according to claim 2, characterized in that, In step S2, the signal from step S1 is demodulated using I / Q modulation, and after coherent integration, the autocorrelation function of the in-phase I and quadrature Q branch correlators is: In the formula, R(·) represents the C / A code autocorrelation function with a maximum value of 1, and τ A τ S To instantly replicate the phase difference between the C / A code and the real and deceptive signal codes, τ A / S =dT s Where d is the interval between the early or late correlator and the immediate correlator, and T s It is the sampling period of the intermediate frequency signal.
4. The SQM satellite navigation spoofing detection method based on IQ branch according to claim 2, characterized in that, In step S3, based on the early, immediate, and late correlator output values of the I and Q branches, the SQM detection metric M is established. value The formula is: In the formula, I Ed (n), I P (n) and I Ld (n) represent the early, immediate, and late correlator outputs of the in-phase channel within the nth coherent integral, respectively, Q. Ed (n) and Q Ld (n) are the early and late correlator outputs of the positive traffic channel within the nth coherent integral, respectively.
5. The SQM satellite navigation spoofing detection method based on IQ branch according to claim 1, characterized in that, In step S4, the maximum false alarm probability P that the detection must satisfy is set. fa-mea P fa-mea satisfy: In the formula, M value (n) is the real signal M value The value of the nth sample in the dataset, count(M) Value (n)>Thresold mea ) represents the detection metric M Value Greater than the measurement threshold Thresold mea The total count value; Measurement threshold Thresold mea The expression is: Thresold mea =M Value ([N m ×(1-P fa-mea )]) (6) Where [·] is the floor function; N m The length of the actual signal dataset.
6. The SQM satellite navigation spoofing detection method based on IQ branch according to claim 5, characterized in that, In step S6, the false alarm probability P when calculating the threshold value is derived. fa-cal for: In the formula, f M (x) represents the SQM detection metric M when there is no deception attack. value The probability density function is given, and erfc(·) is the complementary error function; the threshold value Thresold is obtained. cal The expression is .
Citation Information
Patent Citations
GNSS deception jamming detection method based on combined SQM square
CN115236701A