Computer-implemented method, data processing device, computer program product and computer-readable storage medium for detecting global navigation satellite system signal spoofing

By calculating the partial correlation of GNSS signals and defining multiple predefined metrics, the detection challenge of zero-latency SCER attacks is solved, achieving more efficient GNSS signal spoofing identification and improving detection accuracy and robustness.

CN116075746BActive Publication Date: 2026-05-08欧盟由欧盟委员会为代表
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
欧盟由欧盟委员会为代表
Filing Date
2021-07-12
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing GNSS signal spoofing detection methods are difficult to effectively detect zero-delay SCER attacks, especially when the spoofer cannot know the unpredictable bit values ​​in advance, making signal synchronization difficult and thus hindering detection.

Method used

By calculating the partial correlation between unpredictable and predictable sample sequences, several predefined metrics R1-R5 are defined, and these metrics are compared with predefined thresholds to detect GNSS signal spoofing, especially zero-delay SCER attacks.

Benefits of technology

It improves the accuracy and robustness of GNSS signal spoofing detection, and can effectively identify signal spoofing when the power of the spoofer and receiver is asymmetrical, thus reducing the probability of false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116075746B_ABST
    Figure CN116075746B_ABST
Patent Text Reader

Abstract

A computer-implemented method for detecting spoofing of global navigation satellite system (GNSS) signals. The method comprises storing (120), at a GNSS receiver, a sequence of samples of a predictable part and an unpredictable part of a GNSS signal, wherein the predictable part comprises predictable bits and the unpredictable part comprises unpredictable bits; verifying (125) values of the unpredictable bits from which the sequence of unpredictable samples is extracted; computing (130) first and second partial correlations between the unpredictable, respectively predictable, sequence of samples and a locally stored copy of the GNSS signal; computing (140) a predefined metric from the composite-valued partial correlations; and comparing (150) the predefined metric to a predefined threshold. In a zero-delay replay attack, a spoofing device has to estimate the unpredictable bits introduced by a GNSS authentication protocol and thereby introduce distortions into the signal. The method detects such distortions to indicate whether the signal under analysis is spoofed or genuine.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a computer-implemented method for detecting Global Navigation Satellite System (GNSS) signal spoofing. The invention also relates to a data processing apparatus for performing the method, a computer program product, and a computer-readable storage medium, both of which include instructions for the method. Background Technology

[0002] Global Navigation Satellite System (GNSS) spoofing attacks are deliberate interference aimed at manipulating the position, velocity, and time (PVT) of a target GNSS receiver. Galileo recently adopted the Open Services Navigation Message Authentication (OSNMA) function (Fernandez-Hernandez, I., Rijmen, V., Seco-Granados, G., Simon, J., Rodriguez, I., & Calle, JD (2016)). [Galileo Open Services Navigation Message Authentication Recommendation. Journal of the Navigation Academy (Spring), pp. 85-102]. In this function, the E1B signal components transmitted from Galileo satellites include unpredictable bits to allow the GNSS receiver to detect spoofing attacks.

[0003] A spoofing attack is disclosed in Humphreys, Todd E. "Detection strategies for anti-spoofing of encrypted GNSS," IEEE Transactions on Aerospace and Electronic Systems 49, Vol. 2 (2013): 1073-1090. More specifically, a Secure Code Estimation and Reproducibility (SCER) attack is disclosed, which comprises two steps. First, the spoofer tracks signals received from GNSS satellites and estimates the value of unpredictable bits for each satellite in the field of view. Second, the spoofer generates a set of GNSS signals that are sent to the target GNSS receiver to control the tracking loop and ultimately control the user's position.

[0004] Generating a SCER attack is far from a simple task for a spoofer, as the spoofed signal must be synchronized with the real signal. If the two signals are not aligned in the time domain when the spoofer initiates the attack, the problem can be detected at the receiver using the target receiver's clock. This is because the stability of the receiver clock is well-known, and high variations in clock offset over short periods during the PVT phase are known side effects that can be caused by a spoofer. Therefore, to execute a SCER attack without being detected by the receiver clock, a spoofer can perform a zero-latency attack, which is based on sending a signal that is actually synchronized with the real signal received by the target receiver. By doing so, the spoofer can control the target receiver.

[0005] Fernández-Hernández, Ignacio, and Gonzalo Seco-Granados, in their presentation "Unpredictability and Reproducibility Protection of Galileo NMA Signals" at the International Conference on Positioning and GNSS (ICL-GNSS), IEEE, June 28, 2016, proposed using Navigation Message Authentication (NMA) to prevent reproducibility attacks. In this method, the receiver stores the first sample of each unpredictable bit, creating a sequence whose correlation gain will be lower if the tracked signal is reproduced by a spoofer. In other words, this method measures the gain decrease when tracking unpredictable bits. A brief suggestion in this disclosure is to compare the gain based on unpredictable sequences with the gain based on predictable sequences as a test statistic for detecting zero-latency attacks, but the detection probability of such test statistics is not disclosed.

[0006] US 2011 / 102259 A1 discloses a method for combating GNSS spoofing, which triggers an indicator when an anomaly (such as a GNSS bit flip or an unexpected signal correlation curve) is detected.

[0007] Other methods for detecting GNSS signal spoofing are also known in the art, such as those disclosed in US 7,956,803 and EP 3495848A1, which rely on comparing the GNSS signal with information obtained from an alternative source.

[0008] US 7,956,803 discloses a method for detecting GNSS signal spoofing. The method includes providing information to a wireless device that allows the wireless device to determine navigation data messages from a reference network. The method also includes receiving navigation data from a GNSS network and comparing the navigation data from the GNSS network with navigation data derived from the reference network to determine whether one or more GNSS signals have been spoofed.

[0009] EP 3495848A1 discloses a method for detecting GNSS signal spoofing by comparing a first GNSS signal with a second non-GNSS signal and using a threshold. Summary of the Invention

[0010] One object of the present invention is to provide an improved method for detecting GNSS signal spoofing (especially zero-delay SCER attacks).

[0011] According to the present invention, this objective is achieved by a computer-implemented method for detecting Global Navigation Satellite System (GNSS) signal spoofing, the method comprising: a) digitizing, acquiring, and tracking GNSS signals from at least one GNSS satellite at a receiver, the GNSS signals comprising a predictable portion and an unpredictable portion, wherein the predictable portion comprises predictable bits and the unpredictable portion comprises unpredictable bits; b) storing a sample sequence of the predictable portion of the GNSS signals by the receiver. and unpredictable parts of the sample sequence c) The receiver verifies the value of the unpredictable bits extracted from the unpredictable sample sequence; d) The receiver calculates the first partial correlation B′ between the unpredictable sample sequence and the locally stored GNSS signal copy x(n) using the following formula. unpred The second partial correlation B′ between (k) and the predictable sample sequence and the locally stored GNSS signal copy x(n) pred (k)

[0012] as well as

[0013]

[0014] And through B unpred,pred (k)=b(k)B′ unpred,pred (k) Remove the sign of the first and second part correlations, where b(k) is the value of the bit; e) Calculate a predefined metric R by the receiver based on the first and second part correlations, where the predefined metric R is any of the following:

[0015]

[0016]

[0017] as well as

[0018]

[0019] Where, N b It is the number of unpredictable bits of its sample sequence that have been stored in step b), where T coh of It is the coherent integral time for calculating partial correlation, where and And among them B x (k) is the partial correlation of any part of the bit; and f) compares a predefined metric with a predefined threshold to detect GNSS signal spoofing.

[0020] In one embodiment of the invention, step b) includes: taking a sample sequence of the start portion of the unpredictable bits. Stored as an unpredictable sample sequence, and the sample sequence after the unpredictable bits (i.e., any part other than the initial part, such as the end part). Store as a predictable sample sequence; or store the sample sequence of the beginning portion of the unpredictable bits. Store as an unpredictable sample sequence, and store as a sample sequence with predictable bits. Store as a predictable sample sequence.

[0021] In one embodiment of the present invention, W u,d W is the duration of a single sequence in the stored unpredictable sample sequence (i.e., the duration of the sample taken at the beginning of the unpredictable position), and W p,d It is the duration of a single sequence in the stored unpredictable sample sequence (i.e., the duration of a sample taken at the end of an unpredictable bit, or the duration of a sample from any other part of an unpredictable or predictable bit). Preferably, W u,d and / or W p,d The duration is greater than 0.05 ms, preferably greater than 0.1 ms, more preferably greater than 0.12 ms and less than 1 ms, preferably less than 0.75 ms, and more preferably less than 0.6 ms. The optimal duration of the stored sample is between 0.125 and 0.5 ms.

[0022] In one embodiment of the invention, step b) includes storing a sample sequence representing at least a portion of at least 50 bits, preferably at least 100 bits, more preferably at least 150 bits, and most preferably at least 200 bits, of unpredictable and / or predictable samples.

[0023] In one embodiment of the invention, the predefined threshold is based on the cumulative density function of R under the assumption that the GNSS signal is real. Preferably, the predefined threshold is set to a value that results in a false alarm probability of 0.02.

[0024] In one embodiment of the invention, step f) includes authenticating the GNSS signal when no signal spoofing is detected, preferably by: authenticating the GNSS signal when the predefined metric of the GNSS signal is below a predefined threshold; and detecting GNSS signal spoofing when the predefined metric of the GNSS signal is above the predefined threshold.

[0025] In one embodiment of the invention, step a) includes receiving GNSS signals from at least four different GNSS satellites, the GNSS signals including spreading codes and satellite data including unpredictable portions, and wherein the method further includes: g) calculating the arrival time of the GNSS signals from the spreading codes by a receiver; and h) calculating the position, velocity, and time of the satellite signals by the receiver by demodulating the satellite data.

[0026] In an embodiment of the invention, step f) includes authenticating the GNSS signal when no signal spoofing is detected, preferably by authenticating the GNSS signal when a predefined metric of the GNSS signal is below a predefined threshold; and detecting GNSS signal spoofing when the predefined metric of the GNSS signal is above the predefined threshold, wherein steps g) and h) are performed only if at least four GNSS signals from at least four different GNSS satellites have been authenticated.

[0027] In one embodiment of the invention, step b) includes storing a sample sequence of the unpredictable portion of the GNSS signal based on randomly selected unpredictable bits. Alternatively, step d) may involve calculating the first partial correlation B′ between the unpredictable sample sequence and the locally stored GNSS signal copy x(n) based on a randomly selected subset of the unpredictable sample sequence. unpred (k).

[0028] According to the present invention, this objective is achieved by a data processing device, particularly a GNSS signal receiver, that includes means for performing the above-described method.

[0029] According to the present invention, this object is achieved by a computer program product comprising instructions that, when executed by a computer, cause the computer to perform the above-described method.

[0030] According to the present invention, this object is achieved by a computer-readable storage medium comprising instructions that, when executed by a computer, cause the computer to perform the above-described method.

[0031] It is readily understood that one or more of the above embodiments can be easily combined with each other.

[0032] The inventors have recognized that in zero-latency SCER attacks, the spoofer needs to estimate unpredictable bits introduced by OSNMA with near-zero latency. For this reason, the spoofer introduces a slight distortion into the signal, which forms the basis of current GNSS signal spoofing detection methods.

[0033] More specifically, because the spoofer cannot know the value of the unpredictable bits beforehand, the signal sent by the spoofer contains some errors, especially in the first microsecond of the unpredictable bits. The inventors have realized that they can detect this error by calculating a first partial correlation between the unpredictable sample sequence (especially the beginning portion of the unpredictable bits) and the corresponding local copy, and a second partial correlation between the predictable sample sequence (especially the end portion of the unpredictable bits) and the corresponding local copy. In particular, various measures have been defined to compare the first and second correlations, and these measures indicate (when compared with a threshold) whether the signal being analyzed is being reproduced (i.e., spoofed) or is genuine.

[0034] It has been found (as described in more detail below) that the metric according to the invention (i.e., based on partial correlation) yields better results than the gain-based test metric proposed by Fernandez-Hernandez, Ignacio, and Gonzalo Secco-Granados. "Unpredictability and Reproducibility Protection of Galileo NMA Signals," International Conference on Positioning and GNSS (ICL-GNSS), 2016, IEEE, June 28, 2016. One possible reason for the better performance is that partial correlation is a composite value, while gain (although derived from partial correlation) is a true value, and therefore includes less information about the received signal.

[0035] Using the end portion of unpredictable bits as a predictable sample sequence is beneficial because it minimizes time-dependent signal impairment variations (e.g., multipath or unintentional interference) in this way.

[0036] Furthermore, using only randomly selected unpredictable bits or randomly selected stored unpredictable sample sequences improves the robustness of the detection capability of GNSS signal spoofing methods and avoids the spoofer exploiting the knowledge of which unpredictable bits are used in the detection method. Attached Figure Description

[0037] The present invention will be further explained by the following description and the accompanying drawings.

[0038] Figure 1 This illustrates a representative example of a spoofing attack targeting a satellite.

[0039] Figure 2 A flowchart of the GNNS signal deception detection method according to the present invention is shown.

[0040] Figures 3A to 3C This section describes three different types of zero-latency SCER attacks.

[0041] Figure 4The graph shows the relationship between the detection probability and the number of unpredictable bits when the false alarm probability is 0.02. In the top curve, both the user and the spoofer receive the signal at the same power. In the bottom curve, the spoofer has a 3-dB advantage.

[0042] Figure 5 The diagram shows the relationship between the detection probability and the number of unpredictable bits when the false alarm probability is 0.02. The spoof signal is received at a power 3 dB higher than the real signal.

[0043] Figure 6 The diagram shows the relationship between the detection probability and the number of unpredictable bits for a false alarm probability of 0.02 and different window lengths (0.125 ms for the top curve and 0.500 ms for the bottom curve). The spoofer has a 3-dB advantage over the user.

[0044] Figure 7 The diagram shows a comparison between the probability density function (top curve) and the probability of a false alarm (bottom curve) under the null hypothesis of R3, as well as the false alarm probability P obtained from Monte Carlo simulations and theory based on the Rayleigh expression. fa . Detailed Implementation

[0045] The invention will be described with reference to specific embodiments and certain accompanying drawings, but is not limited thereto; rather, it is defined solely by the claims. The described drawings are merely illustrative and not restrictive. In the drawings, for illustrative purposes, the dimensions of some elements may be exaggerated and not drawn to scale. Scale and relative scale do not necessarily correspond to an actual simplification of the practice of the invention.

[0046] Furthermore, the terms first, second, third, etc., used in the specification and claims are used to distinguish between similar elements and are not necessarily used to describe order or chronological sequence. These terms may be interchanged where appropriate, and embodiments of the invention may operate in a different order than that described or explained herein.

[0047] Furthermore, the terms top, bottom, above, below, etc., used in the specification and claims are for descriptive purposes. These terms are interchangeable where appropriate, and the various embodiments of the invention described herein may operate in other orientations than those described or explained herein.

[0048] Furthermore, although referred to as "preferred", the embodiments are to be interpreted as exemplary ways of implementing the invention, and not as limiting the scope of the invention.

[0049] Figure 1A representative example of a spoofing attack against a single satellite 10 is shown, and Table 1 below provides... Figure 1 The definition of each parameter indicated in the text. Global Navigation Satellite System (GNSS) satellite 10 broadcasts its GNSS signal, which is received by spoofer 20 and GNSS receiver 30. Spoofer 20 then generates and broadcasts its own GNSS signal in order to control GNSS receiver 30.

[0050]

[0051]

[0052] Table 1: Parameter definitions for zero-delay deception attacks on GNSS signals containing unpredictable symbols

[0053] Typically, spoofing detection is a binary hypothesis testing problem, which can be modeled under two assumptions: the spoofer exists (H1) or does not exist (H0), as follows:

[0054]

[0055] Where y(n) is the received signal, N sat It refers to the number of satellites, A. p It is the signal amplitude, β l It is the amplitude of the deception signal, b(n-τ) p ) is an unpredictable bit, c(n-τ) p ) is a pseudo-random noise code, f d,p It is the Doppler frequency. It is phase, N spof It is the number of satellites used to carry out deception attacks. ω(n) is the unpredictable bit sent by the cheat device, and ω(n) is additive white Gaussian noise.

[0056] Since this invention primarily focuses on Zero-Delay Secure Code Estimation and Reproducibility (SCER) attacks, we assume that the spoofer uses f d,l =f d,p and τ l =τ p But A p and It can be different from β l and We assume that our deception device can control the amplitude β of the deception signal. l And in some cases make it equal to A pHowever, it cannot align carrier phase measurements with the true value because aligning carrier phase measurements requires a very high level of accuracy. There are two further modeling assumptions. First, we assume the receiver tracks the true signal at the start of the attack, i.e., the receiver initiates and performs acquisition in a controlled environment. While deception at acquisition is a relevant scenario, most of the time the GNSS receiver is in the tracking phase. Second, we assume that in a zero-delay SCER attack, the deceitful device will not force a signal reacquisition. A deceitful device that forces a reacquisition to gain loop control would need to lose signal for more than a minute to correctly estimate unpredictable bits from the outset. Furthermore, under these conditions, gaining loop control would result in cycle slips, which can be detected by the GNSS receiver.

[0057] As mentioned above, the inventors recognized that the weakness of zero-latency attacks lies in the inclusion of errors in the first part of the unpredictable bit of the signal sent by the spoofer. To make it difficult for the target receiver to detect, the spoofer can primarily perform three types of attacks: estimation attacks, random value attacks, and zero-value attacks, such as... Figures 3A to 3C As shown.

[0058] exist Figure 3A The image illustrates an estimation attack. The spoofer attempts to estimate the unpredictable bit sample by sample and introduces this estimate into the spoofed signal. By doing so, the first part of the bit will contain several sign variations because obtaining a reliable estimate of the bit is infeasible, but after a reasonable number of samples, the spoofer provides the true value of the unpredictable bit.

[0059] Random value attacks such as Figure 3B As shown. The cheat introduces a random value of 1 or -1 at the beginning of the bit for a short period of time, and when the cheat has a reliable estimate of the unpredictable bit value, it is included in the remainder of the bit.

[0060] Zero-value attacks, such as Figure 3C As shown. The cheat introduces the value 0 at the beginning of the bit for a short period of time, and when the cheat has estimated an unpredictable bit value, it is included in the remainder of the bit.

[0061] Note that in Figure 3A , 3B In 3C, the period during which the cheat generates random values ​​or zero is the parameter Ws defined in Table 1.

[0062] Figure 2A flowchart illustrating a GNSS signal spoofing detection method 100 according to the present invention is shown. In step 110, a GNSS receiver digitizes, acquires, and tracks a GNSS signal from at least one GNSS satellite, the GNSS signal comprising a predictable portion and an unpredictable portion, wherein the predictable portion comprises predictable bits and the unpredictable portion comprises unpredictable bits. Methods for digitizing, acquiring, and tracking GNSS signals are known in the art and will not be described further.

[0063] In step 120, the receiver stores a sample sequence of the predictable portion of one or more tracked GNSS signals. and unpredictable parts of the sample sequence In the embodiments described below, the stored sequence is a portion of the same unpredictable bit. In other words, the beginning portion of the unpredictable bit is stored as an unpredictable sample sequence. The unpredictable part at the end is stored as a predictable sample sequence. As mentioned above, although the predictable sample sequence is obtained from the unpredictable bits, the non-initial parts of the unpredictable bits (i.e., not the start parts) are usually correctly estimated by the cheater and are therefore considered predictable.

[0064] In step 125, the receiver verifies the values ​​(i.e., bit values) of the unpredictable portion of the signal, specifically the values ​​of the unpredictable bits extracted from the unpredictable sample sequence. More specifically, although typically all unpredictable bit values ​​would be verified, it is readily understood that the method according to the invention requires only the verification of at least the unpredictable bit values ​​of the stored sample sequence. This saves computational resources in the receiver. This verification of the unpredictable portion can be performed by a GNSS authentication protocol, such as the OSNMA function in Galileo.

[0065] In step 130, the receiver calculates a first partial correlation between the unpredictable sample sequence and the locally stored copy of the GNSS signal, and a second partial correlation between the predictable sample sequence and the locally stored copy of the GNSS signal. Preferably, step 130 occurs only after the unpredictable bits have been verified in step 125.

[0066] In step 132, the following formula is used to calculate the partial correlation:

[0067] as well as

[0068]

[0069] in and W of the signal received within one code period u,d and Wp,d Unpredictable and predictable samples during the period, x unpred (n) and x pred (n) is the corresponding local copy, while samples_u and samples_p represent the total number of unpredictable and predictable stored samples, respectively. Note that samples_u and samples_p do not have to be the same. Thus, partial correlation represents the initial and final portions of the unpredictable bits.

[0070] In the subsequent step 134, B is defined. unpred (k) and B pred (k), which correspond to partial cross-correlation after removing the sign of unpredictable bits.

[0071] B unpred (k)=b(k)B′ unpred (k); and

[0072] B pred (k)=b(k)B′ pred (k),

[0073] Where b(k) is the value of the unpredictable bit (1, -1).

[0074] In step 140, the receiver uses the partial correlation after sign removal to compute one or more of a plurality of predefined metrics R. Several metrics are described below.

[0075] An intuitive method for detecting spoofing is to compare the satellite code gain based on several unpredictable bits with the satellite code gain obtained from various predictable bits suggested by Fernandez-Hernandez, Ignacio, and Gonzalo Secco-Granados. "Unpredictability and Reproducibility Protection of Galileo NMA Signals," International Conference on Positioning and GNSS (ICL-GNSS), 2016, IEEE, June 28, 2016. One way to perform this comparison (i.e., gain comparison) is to calculate N... b The ratio of the sum of the partial correlations. Then, calculate the absolute value of the ratio between the two measures:

[0076]

[0077] If a spoofer is present, R1 should be close to 0; but if a spoofer is not present, it should be close to 1. However, a drawback of this metric R1 is that if the received signal includes spoofed and real signals with different phase values, it can provide any value of H1, in which the behavior of the different phase values ​​is best represented in the composite part of the correlation of the composite value part.

[0078] To address this issue, the present invention relies on four additional metrics R2-R5, which are based on comparing the partial correlation of composite values ​​rather than the gain of true values. The first metric R2 is:

[0079]

[0080] The idea behind R² is that if the cheater is not present, R² is close to 0, but if the cheater is present, R² is larger. This helps in defining the detection threshold.

[0081] An additional metric is R3, which involves calculating the average difference between the initial and final partial correlations:

[0082]

[0083] If R3 is a large value, then a cheat exists. However, if R3 is a small value, then no cheat exists.

[0084] Another interesting metric is the comparison of the carrier-to-noise ratio (C / N0) estimate for the initial portion of the signal that is considered unpredictable with the estimates for the other portions that are considered predictable. To estimate C / N0, the well-known narrow-bandwidth power ratio (NWPR) estimator can be used. Essentially, it requires evaluating the ratio of the signal's wideband power (WBP) to its narrowband power (NBP):

[0085]

[0086] Among them, B x (k) and This refers to the partial correlation of any part of the bit, such as the unpredictable start and end portions of a bit. Finally, the carrier-to-noise ratio (C / N0) estimate can be obtained as:

[0087]

[0088] Where T coh This is the coherent integral time for calculating partial correlation. The predefined metric R4 is based on the difference between the C / N0 estimates of the predictable and unpredictable parts of the bit:

[0089]

[0090] This metric can be used to detect spoofing attacks because if there is no spoofing attack, the metric will be close to 0, while if a spoofing attack exists, the metric will provide a larger value.

[0091] The final metric R5 uses only the phases of the initial and final partial correlations:

[0092]

[0093] If the presence of a spoofing signal alters the phase of the received signal, this metric can be used to detect the spoofer.

[0094] In step 150, the receiver compares a predefined metric R with a predefined threshold to detect GNSS signal spoofing. In practice, the threshold is set in such a way that a predetermined false alarm probability is obtained, for example, a false alarm probability of 0.02 or any other desired value. It is readily understood that the threshold (and the corresponding false alarm probability) can be different for each of the aforementioned metric R. For example, for metric R3, the threshold can be set to a value that results in a false alarm probability of 0.02, and when metric R3 is below the threshold, the signal can be authenticated in step 152, while when metric R3 is above the threshold, the signal can be considered a spoofed signal in step 154.

[0095] Generally speaking, a predefined threshold and the false alarm probability P fa =0,02 are associated, and this predefined threshold can be determined for each metric R by deriving the cumulative density function of the metric R under the null hypothesis (i.e., no cheater exists). A more detailed example is described below.

[0096] Figure 2 The method shown also includes steps 160 and 170, in which the receiver calculates the time of arrival of the GNSS signal based on the spreading code, and in step 170, the receiver calculates its position, velocity, and time by demodulating the satellite data. This is typically accomplished using GNSS signals from at least four different GNSS satellites, each including a spreading code and satellite data, which may contain unpredictable components. Preferably, steps 160 and 170 are performed only after the GNSS signals from at least four satellites have been authenticated in step 150.

[0097] It is readily understood that in other embodiments, the predictable sample sequence may be obtained from other parts of the signal, such as from predictable bits (parts) and / or from other parts of unpredictable bits (i.e., not the initial or end parts).

[0098] Knowing in advance which unpredictable bits and which parts of them will be correlated allows a spoofer to exploit this advantage. First, it can launch random value attacks with variable power based on the success or failure of previous guesses; second, it can alter predictable correlations to deceive the detector. Both of these advantages are diminished by the randomization of correlations. In other words, in some embodiments, not all stored sample sequences need to be used in the calculation of the metric R. For example, a random number of unpredictable bits are not used. This improves the robustness of GNSS signal spoofing methods, especially when the spoofer expects this type of defense.

[0099] It should be understood that the above description focuses on a single spoofing signal targeting only one satellite. However, this method can be readily used to detect multiple spoofing signals simultaneously. In fact, as described below, because the method according to the invention can detect a single spoofing signal, it will be better suited for detecting spoofing when the spoofer wants to continuously spoof the entire PVT solution, as this would require successfully spoofing multiple satellite signals simultaneously.

[0100] The following section presents performance analyses of different metrics in the presence of zero-latency attacks, where R1 is used as a baseline comparison representing the prior art, and R2-R5 represent the present invention. The following are simulation results of the spoofing detection capabilities of the proposed R2-R5 metrics under the most relevant attack scenarios. The presented results constitute the most difficult spoofing scenario to detect, in terms of spoofing power advantage and attack type. The spoofing simulation parameters are given in Table 2 below. Regarding attack type, among the three attacks described above, we focus on the estimation attack to perform the presented simulation because it provides an upper limit on the required number of unpredictable bits compared to the other two attacks. This attack involves estimating the unpredictable bits sample by sample and introducing this estimation into the spoofing signal. The estimation of unpredictable bits performed by the spoofer can be easily performed during the tracking phase using the following expression.

[0101]

[0102] By doing so, the cheater obtains an estimate of the bits for each m.

[0103] One variant of this attack involves estimating the bit sample by sample, and then transmitting the bit estimate using a scalar factor, depending on the attacker's confidence level. This subcase has also been analyzed, and it is not significantly different from the standard estimation attack.

[0104] We also evaluated the case where the spoofer has a C / N0 advantage over the receiver by up to 5 dB. Regarding the relative power between the spoofed and genuine signals, we evaluated the case with the same power as well as the case where the spoofed signal has +3 dB power. The results were tested on the AWGN channel using a real number of visible GPS and Galileo satellites. In the simulation, we used a threshold that resulted in a false alarm probability of 0.02, as it provides a good benchmark for comparing various metrics.

[0105]

[0106] Table 2 Parameterization of Deception Simulation

[0107] In all cases, under different combinations of these parameters, for different numbers of bits N b Measuring the probability of deception detection P d .

[0108] Figure 4 The graph shows the relationship between the probability of detecting a spoofing attack and the number of unpredictable bits when the false alarm probability is 0.02, with each bit having a correlation of 250 ms. These figures are based on estimated attacks and take into account that the user simultaneously receives both real and spoofed signals. In the top figure, the spoofer receives the signal from the satellite at the same power as the user, while in the bottom figure, the spoofer receives the signal at a power higher (3 dB) than the user. The graph illustrates that techniques R2 and R3 provide optimal performance. When the spoofer has a 3 dB advantage over the user receiver, R2 and R3 detectors can detect the spoofing attack with a detection probability of 0.9 using 200 and 220 bits, respectively. However, if the spoofer receives the signal at the same power as the user receiver, the user receiver can detect the spoofing attack using approximately 100 and 120 bits, respectively, using R2 and R3 techniques. Note that the performance of this R1 metric is worse than all other metrics, especially regarding the number of unpredictable symbols N. b In rare cases.

[0109] The preceding simulations assumed that the user received signals from both the spoofer and the satellite at the same power. However, for Figure 5 The curve at the top assumes that the user receives a 3dB stronger signal from the spoofer than from the satellite. In this case, the user receiver can detect the spoofing attack more easily than in previous simulations. When the spoofer has a 3dB advantage over the user's receiver, and the user receives the same signal power from both the spoofer and the satellite, the R3 metric requires 200 bits to detect a spoofing attack with a detection probability of 0.9. Figure 4 (Bottom curve). However, when the signal received by the user from the spoofer is 3dB stronger than the signal transmitted by the satellite, R3 only needs 65 bits to detect a spoofing attack with a detection probability of 0.9. Figure 5 Under these conditions, the best detector is R3. It's worth noting that R1's performance wasn't too bad in this simulation because the user's receiver received more power from the spoofer than from the satellite.

[0110] exist Figure 6 In this paper, we analyze how using different window lengths (0.125 ms (top) and 0.500 ms (bottom)) affects detector performance. Note that the case with a window length of 0.250 ms... Figure 4 The bottom curves are shown. While these correlations are much shorter than the standard 4-ms Galileo E1 code, they ensure sufficient gain for detection even with cross-correlation noise from other satellites. Results show that different window lengths R3 used to calculate partial correlations provide very similar performance, while others are more sensitive to this parameter. In some cases, the metric R2 for desired performance is also affected by the window length. If the window length is appropriate, it can provide very good performance. However, the detection probability of this technique decreases regardless of whether the time window is too short or too large.

[0111] The simulation analysis concludes that the R2_R5 metric (based on the partial correlation of composite values) performs significantly better than the R1 metric, which is based on gain (i.e., the true value obtained from the partial correlation of composite values). Furthermore, among the proposed metrics, R3 performs best and is robust enough for all cases, provided it accumulates sufficient energy from a sufficient number of bits. With a sufficient number of bits, approximately on the order of 200, the detector can detect spoofing attacks with a probability exceeding 90%, even when the spoofer has a power advantage over the user's receiver.

[0112] A remaining aspect of implementing this method is defining the unpredictable portions, symbols, or bits of the GNSS signal. The current Galileo OSNMA protocol is designed to authenticate satellite navigation data. We consider a baseline use case for OSNMA with 2 MACK (Message Authentication Code and Key) blocks per block, a 20-bit MAC, a 96-bit key, and 4 MACs. This configuration allows the receiver to have 80 unpredictable bits per 15-second MACK block, regardless of the key bits, and approximately 160 unpredictable bits over a similar timeframe if the first 80 bits of the key are considered unpredictable. We can conclude that even when the key is predictable, the detector can base its calculations on 30 or 45 seconds (i.e., 2 or 3 MACK blocks) to obtain 160 or 240 unpredictable bits. Based on simulation results, we can see that the metric (some of these) can work even in the case of a spoofer's advantage. The receiver can decide to wait for two Galileo I / NAV subframes, a total of 60 seconds, providing 320 unpredictable bits to increase the confidence of the metric.

[0113] Since the R3 metric appears to be the most promising measure for detecting GNSS spoofing, an example of calculating its detection threshold γ is given below. Spoofer detection boils down to a comparison between the metric R3 and the detection threshold to distinguish whether a user's receiver has been spoofed. The detection threshold is affected by the probability of false alarms:

[0114]

[0115] in It is the cumulative density function that measures R3.

[0116] The probability of a false alarm requires knowing the cumulative density function of R3 under the null hypothesis H0 (i.e., the spoofer does not exist). When the spoofer is absent, the R3 metric closely resembles a Rayleigh distribution. This is because the partial correlation values ​​at the beginning and end of the bit (or another predictable part of the signal) are actually the same constant value, with Gaussian noise added. Thus, the terms within the absolute value can be considered as zero-mean composite Gaussian noise, and the metric R3 follows a Rayleigh distribution. Utilizing the relationship between the Rayleigh distribution and the underlying Gaussian variable, the mean of the Rayleigh distribution can be derived from the predictable part B. end The mean of the Rayleigh distribution is obtained from the standard deviation of the partial correlation of (k). Where σ B It is B end The variance of (k). Therefore, the detection threshold γ can be defined as...

[0117]

[0118] Figure 7The probability density functions of the theory and simulation (top curve) are compared with the probability of false alarms under the null hypothesis of the metric R3 (bottom curve). The figure shows that the metric R3 does indeed approximate the Raleigh distribution very well.

[0119] It will be easy to understand how the above example of how to calculate the threshold for the metric R3 so that the desired false alarm probability can also be applied to other metrics. Furthermore, other thresholds can be used that are independent of the false alarm probability and / or not based on the cumulative density function of the metric.

[0120] Although the method according to the invention has been described with reference to the Galileo OSNMA protocol, the invention should not be considered limited thereto, and the proposed method can also be applied to other protocols.

[0121] Although aspects of this disclosure have been described with respect to specific embodiments, it will be readily understood that these aspects may be implemented in other forms within the scope of the invention as defined in the claims.

Claims

1. A computer-implemented method (100) for detecting GNSS signal spoofing in a Global Navigation Satellite System, the method comprising: a) At a receiver, digitize, acquire, and track (110) GNSS signals from at least one GNSS satellite, the GNSS signals comprising a predictable portion and an unpredictable portion, wherein the predictable portion comprises predictable bits and the unpredictable portion comprises unpredictable bits; b) A sample sequence of the predictable portion of the GNSS signal stored by the receiver (120). and the sample sequence of the unpredictable portion ; c) The receiver verifies (125) the value of the unpredictable bit extracted from the unpredictable sample sequence; d) The receiver calculates (130) a first partial correlation between the unpredictable sample sequence and the locally stored copy of the GNSS signal in the following manner. and a second part of the correlation between the predictable sample sequence and the locally stored GNSS signal copy. : ;as well as And remove the sign of the first part of the correlation (134), And remove the sign of the second part of the correlation in (134). ,in It is the value of the unpredictable bit; e) The receiver calculates (140) a predefined metric from the first partial correlation and the second partial correlation. R 3 The predefined metric R 3 yes: as well as f) Compare a predefined metric with a predefined threshold (150) to detect GNSS signal spoofing.

2. The method according to claim 1, characterized in that, Step b) includes: Sample sequence of the beginning of unpredictable bits Stored as unpredictable sample sequences and the sample sequence of the part following the unpredictable bit. Stored as predictable sample sequences ;or Sample sequence of the beginning of unpredictable bits Stored as unpredictable sample sequences and the sample sequence of predictable bits Stored as predictable sample sequences .

3. The method according to claim 1 or 2, characterized in that, in It is the duration of a single stored, unpredictable sample sequence, and It is the duration of a single stored, predictable sample sequence.

4. The method according to claim 3, characterized in that, in and / or Greater than 0.05 ms and less than 1 ms.

5. The method according to claim 1, characterized in that, Step b) includes storing a sample sequence of at least 50 bits representing the unpredictable sample and / or a portion of the predictable sample.

6. The method according to claim 1, characterized in that, Wherein, under the assumption that the GNSS signal is real, the predefined threshold is based on a metric. R 3 cumulative density function ,in H0 is the detection threshold, and H0 is the null hypothesis.

7. The method according to claim 6, characterized in that, The predefined threshold is set to a value that results in a false alarm probability of 0.

02.

8. The method according to claim 1, characterized in that, Step f) includes authenticating the GNSS signal by the following steps when no signal spoofing is detected: When the predefined metric of the GNSS signal is lower than the predefined threshold, the GNSS signal is authenticated (152); as well as When the predefined metric of the GNSS signal is higher than the predefined threshold, GNSS signal spoofing is detected (154).

9. The method according to claim 1, characterized in that, Step a) includes receiving GNSS signals from at least four different GNSS satellites, the GNSS signals including spreading codes and satellite data, the satellite data including the unpredictable portion, and wherein the method further includes: g) The receiver calculates (160) the arrival time of the GNSS signal based on the spreading code; and h) The receiver calculates (170) the position, velocity and time of the satellite by demodulating the satellite data.

10. The method according to claim 9, characterized in that, Step f) includes authenticating the GNSS signal by the following steps when no signal spoofing is detected: When the predefined metric of the GNSS signal is lower than the predefined threshold, the GNSS signal is authenticated (152); and When the predefined metric of the GNSS signal is higher than the predefined threshold, GNSS signal spoofing is detected (154), and Steps g) and h) are performed only if at least four GNSS signals from at least four different GNSS satellites have been authenticated.

11. The method according to claim 1, characterized in that, Step b) includes storing the sample sequence of the unpredictable portion of the GNSS signal based on randomly selected unpredictable bits. ;or Step d) includes calculating a first partial correlation between the unpredictable sample sequence and a locally stored GNSS signal copy x(n) based on a randomly selected subset of the unpredictable sample sequence. .

12. A data processing apparatus comprising means for performing the method as described in any one of claims 1 to 11.

13. A computer program product comprising instructions that, when executed by a computer, cause the computer to perform the method as claimed in any one of claims 1 to 11.

14. A computer-readable storage medium including instructions that, when executed by a computer, cause the computer to perform the method as claimed in any one of claims 1 to 11.

Citation Information

Patent Citations

  • Device and method to detect spoofing of a terminal

    EP3495848A1

  • Augmenting GNSS User Equipment to Improve Resistance to Spoofing

    US20110102259A1

  • System and method for protecting against spoofed A-GNSS measurement data

    US7956803B2

  • Method and apparatus for autonomous, in-receiver prediction of gnss ephemerides

    CN102209911A

  • System and method for detecting false global navigation satellite system satellite signals

    CN112703425A