GNSS Spoofing Detection Method and System Based on the Fusion of In-Phase Branch Output and PCS
By fusing the in-phase branch output with PCS, building and sliding average processing of AELCP detection volumes is solved, and the existing technology has poor detection effect in many navigation spoofing scenarios is achieved, and efficient GNSS spoofing detection is achieved, especially in carrier synchronization scenarios.
Patent Information
- Application Number
- CN202411521567.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-29
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-10-29
AI Technical Summary
The existing navigation spoof detection methods cannot be applied to multiple navigation spoof scenarios, especially in carrier synchronization spoof scenarios. The detection effect is not ideal.
The GNSS spoof detection method based on in-phase branch output and PCS is adopted. By constructing the AELCP detection amount and performing sliding average processing, the AELCP-MA detection amount is generated to improve the detection ability of multiple spoof scenarios.
This method can effectively detect fraud in different spoof scenarios, with a high detection probability, especially in carrier synchronization scenarios, which significantly improves the detection effect.
Smart Images

Figure CN119355763B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of navigation and positioning, and particularly relates to a GNSS spoofing detection method and system based on the output of the in-phase branch and PCS fusion. Background Art
[0002] The Global Navigation Satellite System (GNSS) can provide all-weather positioning, navigation, and timing services for global users. Since the GNSS signal arrives at the ground with weak energy and the signal structure of civilian GNSS is public, it is vulnerable to external interference. Spoofing interference is one of the main threats faced by GNSS. It affects the receiver's lock on the real signal by transmitting spoofing signals similar to GNSS signals, causing the receiver's positioning and calculation to be incorrect. Satellite spoofing interference can be divided into retransmitted spoofing and generated spoofing. Compared with retransmitted spoofing, the detection of generated spoofing is more difficult. Generated spoofing is divided into primary, intermediate, and advanced spoofing. Among them, intermediate spoofing has moderate complexity, high feasibility, and good concealment. Currently, intermediate spoofing is the main type in GNSS spoofing.
[0003] GNSS spoofing detection technologies mainly include space processing, measurement domain, and baseband signal processing technologies, etc. Among them, the baseband signal processing technology has the advantages of simple design and good detection performance. As one of the baseband signal processing technologies, the Signal Quality Monitoring (SQM) technology was initially used to detect multipath interference and later used for spoofing detection. The SQM technology mainly includes the Ratio measurement and the Delta measurement. Both types of measurements are composed of the outputs of the correlators in the in-phase branch, and whether there is spoofing is judged by detecting the deformation of the correlation peak. The ELP (Early Late Phase) measurement uses the change in the characteristics of the output of the quadrature branch for detection. When there is spoofing, the phases of the early code and the late code are not equal. When the carrier phase difference between the spoofing signal and the real signal is close to π, the ELP algorithm fails. To comprehensively utilize multiple SQM measurements, one solution is to propose a composite SQM algorithm, which constructs a measurement by linearly weighting Ratio and ELP. The detection performance is significantly improved compared with the original single measurement. Another solution proposes a composite SQM variance algorithm, which has a higher detection probability compared with the composite SQM, but the detection performance is not ideal for scenarios where the power changes with time. In response to this, researchers proposed a spoofing detection algorithm based on the fusion of absolute power monitoring and SQM (Power Combined with SQM, PCS), which is suitable for the detection of high-power spoofing scenarios, but the detection effect for spoofing scenarios with carrier synchronization is not ideal. Summary of the Invention
[0004] To solve the technical problem that existing navigation spoofing detection methods cannot be applied to multiple navigation spoofing scenarios, an embodiment of the present invention provides a GNSS spoofing detection method and system based on the integration of the in-phase branch output and PCS.
[0005] The technical solution of the embodiment of the present invention is implemented as follows:
[0006] An embodiment of the present invention provides a GNSS spoofing detection method based on the integration of the in-phase branch output and PCS. The method includes: obtaining the in-phase branch leading and lagging outputs, and the PCS detection quantity; constructing a first detection quantity based on the in-phase branch leading and lagging outputs and the PCS detection quantity; the first detection quantity is:
[0007] M AELCP =(|I E |+|I L |)×(M PCS ) Equation (1)
[0008] where M AELCP is the first detection quantity, I E and I L are the in-phase branch leading and lagging outputs respectively, and M PCS is the PCS detection quantity; M PCS =E+L-2P, where E, L, and P are the autocorrelation amplitudes of the leading, prompt, and lagging correlators respectively.
[0009]
[0010] where I E is the in-phase branch leading output, Q E is the quadrature branch leading output, I P is the in-phase branch prompt output, Q P is the quadrature branch prompt output, I L is the in-phase branch lagging output, and Q L is the quadrature branch lagging output;
[0011] Performing a moving average process on the first detection quantity to obtain a second detection quantity; the second detection quantity is:
[0012]
[0013] where M AELCP-MA (n) is the second detection quantity, ω is the length of the moving window; n = 1, 2, ···, N, where N is the number of moving windows; l is the moving interval, and i is the independent variable;
[0014] Using the second detection quantity to perform GNSS navigation spoofing detection.
[0015] In one embodiment, using the second measurement for GNSS navigation spoofing detection includes: obtaining a detection threshold; and based on the detection threshold and the second measurement, performing GNSS navigation spoofing detection using the following calculation formula:
[0016]
[0017] where H 0 is without spoofing interference, H 1 is with spoofing interference, Th l is the lower limit of the detection threshold, Th u is the upper limit of the detection threshold, M AELCP-MA (t) is the second measurement.
[0018] In one embodiment, obtaining the detection threshold includes: determining the detection threshold using the following calculation formula:
[0019]
[0020] where Th u is the upper limit of the detection threshold, Th l is the lower limit of the detection threshold, μ i is the mean of the measurements, is the variance of the measurements, erfc -1 is the inverse complementary error function, P fa is the false alarm probability.
[0021] In one embodiment, before performing GNSS navigation spoofing detection based on the detection threshold and the second measurement, the method further includes: determining whether the second measurement satisfies a normal distribution; if it is determined that the second measurement satisfies a normal distribution, then performing GNSS navigation spoofing detection based on the detection threshold and the second measurement.
[0022] In one embodiment, determining whether the second measurement satisfies a normal distribution includes: determining the probability density function of the first measurement; determining whether the probability density function of the first measurement satisfies a normal distribution; if the probability density function of the first measurement satisfies a normal distribution, then the second measurement satisfies a normal distribution.
[0023] In one embodiment, determining whether the probability density function of the first measurement satisfies a normal distribution includes: obtaining the statistical skewness and statistical kurtosis based on the probability density function of the first measurement; obtaining the standard error of skewness and the standard error of kurtosis; calculating the Z-scores of skewness and kurtosis using the statistical skewness, the statistical kurtosis, the standard error of skewness, and the standard error of kurtosis; and determining whether the probability density function of the first measurement satisfies a normal distribution based on the Z-scores of skewness and kurtosis.
[0024] In one embodiment, the probability density function of the first measurement is as follows:
[0025]
[0026] where is the joint probability density function of X and Y, X = |I E | + |I L |, Y = M PCS , Z = XY; I E is the in-phase branch leading output, I L is the in-phase branch lagging output, M AELCP is the first measurement;
[0027] The statistical skewness is:
[0028]
[0029] where is the statistical skewness, N S is the sample point, is the signal sample mean;
[0030] The statistical kurtosis is:
[0031]
[0032] where is the statistical kurtosis, N S is the sample point, is the signal sample mean;
[0033] The skewness standard error is:
[0034]
[0035] where is the skewness standard error, N S is the sample point;
[0036] The kurtosis standard error is:
[0037]
[0038] where is the kurtosis standard error, N S is the sample point, is the skewness standard error.
[0039] In one embodiment, the Z-scores of the skewness and kurtosis are:
[0040]
[0041] where For skewness statistics, For kurtosis statistics, For the standard error of skewness, For the standard error of kurtosis.
[0042] An embodiment of the present invention also provides a GNSS spoofing detection system based on the fusion of the in-phase branch output and PCS, including: a processor and a memory for storing a computer program that can run on the processor; wherein, when the processor is used to run the computer program, it executes the steps of the method described in any one of the above.
[0043] An embodiment of the present invention also provides a storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the method described in any one of the above are implemented.
[0044] The solution of this embodiment has the following beneficial effects:
[0045] 1. Based on different spoofing scenarios, the solution of this embodiment can effectively detect spoofing;
[0046] 2. Under multiple spoofing scenarios, the solution of this embodiment has a high detection probability. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is a schematic diagram of medium-level spoofing;
[0048] Figure 2 It is a schematic flowchart of the GNSS spoofing detection method based on the fusion of the in-phase branch output and PCS according to the embodiment of the present invention;
[0049] Figure 3 It is a schematic diagram of AELCP-MA according to the embodiment of the present invention;
[0050] Figure 4 It is a schematic flowchart of obtaining the AELCP-MA detection quantity according to the embodiment of the present invention;
[0051] Figure 5 It is a schematic diagram of the output of the AELCP detection quantity in PRN23 according to the embodiment of the present invention;
[0052] Figure 6 It is a schematic diagram of the AELCP detection quantity of PRN23 in the DS7 scenario according to the embodiment of the present invention;
[0053] Figure 7 It is a schematic diagram of the AELCP-MA detection quantity of PRN23 in the DS7 scenario according to the embodiment of the present invention;
[0054] Figure 8 It is a schematic diagram of the comparison of detection probabilities according to the embodiment of the present invention;
[0055] Figure 9 Schematic diagram of binary decision comparison for the embodiments of the present invention;
[0056] Figure 10 Schematic diagram of comparison of detection probabilities after sliding processing for the embodiments of the present invention;
[0057] Figure 11 Schematic diagram of comparison of the curve of the detection probability of AELCP-MA varying with... for the embodiments of the present invention; where Figure 11 (a) is the curve of variation with 25 ms, Figure 11 (b) is the curve of variation with 50 ms, Figure 11 (c) is the curve of variation with 100 ms;
[0058] Figure 12 Schematic diagram of comparison of ROC curves for the embodiments of the present invention; where Figure 12 (a) is the single-star ROC curve, Figure 12 (b) is the multi-star ROC curve;
[0059] Figure 13 Schematic diagram of comparison of single-star ROC curves in different scenarios for the embodiments of the present invention; where Figure 13 (a) is the single-star ROC curve in the PRN23 scenario of DS3, Figure 13 (b) is the single-star ROC curve in the PRN23 scenario of DS4, Figure 13 (c) is the single-star ROC curve in the PRN22 scenario of DS5; Figure 13 (d) is the single-star ROC curve in the PRN23 scenario of DS7;
[0060] Figure 14 Schematic diagram of comparison of multi-star ROC curves in different scenarios for the embodiments of the present invention; where Figure 14 (a) is the multi-star ROC curve in the DS3 scenario, Figure 14 (b) is the multi-star ROC curve in the DS4 scenario, Figure 14 (c) is the multi-star ROC curve in the DS5 scenario; Figure 14 (d) is the multi-star ROC curve in the DS7 scenario;
[0061] Figure 15 Internal structure diagram of the computer device for the embodiments of the present invention. Detailed implementation manners
[0062] Before introducing the solutions of this embodiment, the following content is introduced first.
[0063] 1. Received signal and intermediate spoofing process
[0064] The attack process of intermediate deception is divided into four stages: deception injection, deception alignment, deception traction and deception separation, namely stages I to IV. Stage I: the deception signal slowly approaches the real signal; Stage II: the deception signal begins to align with the real signal, and the deception signal gradually increases the signal power. At this time, the receiver is still locked on the real signal; Stage III: the deception signal uses its power advantage to make the receiver lock on the deception signal and begin to move away from the real signal; Stage IV: the deception signal deviates from the real signal, and the completion of the intermediate deception causes the receiver to receive the deception signal, resulting in errors in the final positioning solution. The intermediate deception process is as follows: Figure 1 shown.
[0065] In a deceptive environment, the received signal consists of the real signal, the deceptive signal and noise.
[0066] x(t)=x a (t)+x s (t)+n(t) Formula (1)
[0067] Among them, x(t) represents the received signal, x a (t) represents the real signal, x s (t) represents the spoofing signal, and n(t) is the Gaussian white noise with zero mean.
[0068] Real signal x a (t) and the spoofing signal x s (t) have similar structures and similar powers, and their expressions are:
[0069]
[0070] Among them, x a (t) represents the real signal, x s (t) represents the deceptive signal, P a , P s is the power of the real signal and the spoofing signal, C a , C s is the pseudo-random spreading code of the real signal and the spoofing signal, D a , D s is the navigation data of the real signal and the deceptive signal, τ a , τ s is the code delay between the real signal and the spoofed signal, f 0 is the center frequency, is the Doppler shift of the real signal and the spoofing signal, is the carrier phase of the real signal, and t is the independent variable.
[0071] 2. Receive loop correlator output
[0072] The correlator is an important part of the receiver and has the function of stripping the pseudo-code. Taking the C / A code of the L1 carrier of the Global Positioning System (GPS) as an example, since the C / A code has good autocorrelation characteristics, it can be stripped by the correlator. The correlation output is:
[0073] r(t,τ) = R a (t,τ) + R s (t,τ) + R n (t,τ) Equation (4)
[0074] Among them, R(t,τ) is the cross-correlation result of the signal and the local code. The superscripts a, s, and n represent the true signal, the spoofing signal, and the noise signal respectively. The cross-correlation result of the true signal and the local code is:
[0075]
[0076] Since the spoofing signal has the same signal structure as the true signal and similar power, R s (t,τ) can be expressed as:
[0077] R s (t,τ) = R a (τ - τ') Equation (6)
[0078] Among them, τ' is the code phase difference between the spoofing signal and the true signal.
[0079] The tracking loop uses three pairs of correlators: early, prompt, and late. When the navigation data code is 1, the in-phase branch output I P and the quadrature branch output Q P are:
[0080]
[0081] Among them, I P is the in-phase branch output, Q P is the quadrature branch output, P a 、P s are the powers of the true signal and the spoofing signal respectively, τ c 、τ a 、τ s are the code phases of the local spreading code, the true signal, and the spoofing signal respectively, are the carrier phases of the true signal, the spoofing signal, and the replica signal respectively, and R(·) is the cross-correlation function of the spreading code.
[0082] In addition, I E (Q E )、I L (QL ) is I P (Q P ) are the correlator outputs adjacent to both sides, and the immediate correlator is separated from them by 0.5 chip respectively, and the coherent integration is 1 ms.
[0083] 3. PCS detection quantity
[0084] The PCS detection quantity is as follows:
[0085] M PCS = E + L - 2P Equation (9)
[0086] where E, L, and P are the autocorrelation amplitudes of the early, immediate, and late correlators respectively. It satisfies:
[0087]
[0088] where I E is the early output of the in-phase branch, Q E is the early output of the quadrature branch, I P is the immediate output of the in-phase branch, Q P is the immediate output of the quadrature branch, I L is the late output of the in-phase branch, Q L is the late output of the quadrature branch.
[0089] When the signal-to-noise ratio is much greater than 1, E, P, and L approximately follow a Gaussian distribution, so the PCS detection quantity after linear combination approximately follows a Gaussian distribution.
[0090] Based on the above content, the present invention will be further described in detail below in conjunction with the drawings and embodiments.
[0091] The embodiment of the present invention provides a GNSS spoofing detection method based on the fusion of the in-phase branch output and PCS. As Figure 2 shown, this method includes:
[0092] Step 101: Obtain the early and late outputs of the in-phase branch and the PCS detection quantity;
[0093] Step 102: Based on the early and late outputs of the in-phase branch and the PCS detection quantity, construct a first detection quantity; the first detection quantity is:
[0094] M AELCP =(|I E | + |I L |)×(M PCS ) Equation (11)
[0095] where M AELCP is the first detection quantity, I E and I LThey are the in-phase branch leading and lagging outputs, respectively, M PCS is the PCS detection quantity; M PCS = E + L - 2P, where E, L, and P are the autocorrelation amplitudes of the leading, instantaneous, and lagging correlators, respectively. Among them,
[0096]
[0097] Among them, I E is the in-phase branch leading output, Q E is the quadrature branch leading output, I P is the in-phase branch instantaneous output, Q P is the quadrature branch instantaneous output, I L is the in-phase branch lagging output, Q L is the quadrature branch lagging output;
[0098] Step 103: Perform a moving average process on the first detection quantity to obtain a second detection quantity; the second detection quantity is:
[0099]
[0100] Among them, M AELCP-MA (n) is the second detection quantity, ω is the length of the moving window; n = 1, 2, ···, N, N is the number of moving windows; l is the moving interval, and i is the independent variable;
[0101] Step 104: Use the second detection quantity to perform GNSS navigation spoofing detection.
[0102] The solution of this embodiment can effectively detect spoofing based on different spoofing scenarios; and in multiple spoofing scenarios, it has a high detection probability.
[0103] The first detection quantity in this embodiment can also be called the AELCP detection quantity, and the second detection quantity can also be called the AELCP-MA detection quantity.
[0104] As can be seen from the above, the PCS detection quantity can eliminate the influence of the carrier phase and rely on power monitoring to have a high detection probability for high-power scenarios. However, the output of the PCS detection quantity does not contain the carrier phase. Therefore, in this embodiment, the PCS detection quantity is combined with the output of the same branch to improve the detection effect for the carrier synchronization scenario. That is, take the weighted absolute values of the in-phase branch leading and lagging outputs and multiply them by PCS to construct the AELCP detection quantity.
[0105] In addition, to achieve the goal of reducing the influence of noise to improve the detection effect, this embodiment performs a moving average operation on the AELCP detection quantity. That is, adopt the method of moving average processing of the AELCP detection quantity to construct the AELCP-MA detection quantity. The schematic diagram of the moving window processing of the AELCP-MA detection quantity can be asFigure 3 as shown
[0106] That is, the construction process of the AELCP-MA detection quantity in this embodiment can be referred to Figure 4 . Based on the autocorrelation amplitude of the leading, immediate, and lag correlators, the PCS detection quantity is constructed. The absolute values of the outputs of the leading and lag branches are taken, and after weighting the two and multiplying them with the PCS, the AELCP detection quantity is constructed, and then the AELCP-MA detection quantity is constructed after moving average processing
[0107] To improve the scene applicability of the SQM class deception detection algorithm, this embodiment constructs an AELCP detection quantity based on the combination of the in-phase branch output and the PCS, and determines the detection threshold by combining probability distribution analysis. To reduce the influence of noise, a deception detection method of AELCP moving average (AELCP-Moving Average, AELCP-MA) is proposed
[0108] Specifically, in the deception detection algorithm, the reasonable selection of the detection threshold determines the detection performance. Therefore, it is necessary to analyze the distribution characteristics of the AELCP detection quantity. For the convenience of theoretical analysis, let X = |I E | + |I L |, Y = M PCS , Z = XY, then the probability density function of the AELCP detection quantity
[0109]
[0110] where is the joint probability density function of X and Y
[0111] When equation (13) satisfies the normal distribution, it brings many conveniences to the selection of the detection threshold and the evaluation of the detection performance. To demonstrate whether equation (13) approximately satisfies the normal distribution, the skewness and kurtosis indexes commonly used in the normality test are used to measure it
[0112] Skewness is a measure of the symmetry of the probability distribution of a random variable: when the skewness is equal to 0, the probability distribution of the random variable has good symmetry. Due to the limited number of sample points of the actual sampling signal, the sample statistical skewness is usually used instead of the theoretical skewness. The statistical skewness of the sample is
[0113]
[0114] where is the signal sample mean, and N S is the sample point
[0115] Kurtosis reflects the thickness of the probability tail of a random variable. If the kurtosis is equal to 3, the tail-drop speed of the probability density function of the random variable is approximately the same as that of the Gaussian distribution. In practice, the sample statistical kurtosis is usually used instead of the theoretical kurtosis. The sample statistical kurtosis is:
[0116]
[0117] Furthermore, the standard error of skewness and the standard error of kurtosis are introduced, which are respectively:
[0118]
[0119] where N S is the sample point.
[0120] The Z-scores of skewness and kurtosis are respectively:
[0121]
[0122] Under the test level of the significance level α = 0.05, if the Z-scores of the skewness and kurtosis of the sample data are within (-1.96, 1.96), it is considered that the sample follows a normal distribution.
[0123] To evaluate and verify whether the AELCP measurement of the actual navigation signal conforms to the normal distribution, without loss of generality, the first 100 s (without spoofing) data of 7 stars in DS7 are taken, and the measurement indexes of AELCP are calculated respectively. The results are shown in Table 1.
[0124] Table 1
[0125]
[0126] As can be seen from Table 1, is close to 0, and the kurtosis is close to 3, indicating that the AELCP measurement basically conforms to the normal distribution. The Z-scores corresponding to the significance levels α of 0.02 and 0.01 are 2.330 and 2.575 respectively. α = 0.01 represents a 99% correct rate. According to the principle of mathematical statistics, the smaller the significance level, the wider the acceptance region and the higher the Z-score. In Table 1, and are much greater than 2.575, representing that the significance level α ≈ 0.01 and the correct rate is close to 100%. Therefore, the AELCP measurement approximately follows the Gaussian distribution, and its probability density function can be expressed as:
[0127]
[0128] where μ AELCP and σ 2 AELCP are the mean and variance of AELCP respectively.
[0129] In PRN23, the output of the AELCP measurement is as Figure 5 shown.
[0130] In Figure 5 , the mean of the AELCP measurement output is -4.4831×10^13, and the variance is 5.8540×10^12. The distribution of the AELCP output samples approximately follows a Gaussian distribution, which is consistent with the theoretical analysis. Therefore, the AELCP-MA measurement after moving average processing also approximately follows a Gaussian distribution.
[0131] Since the AELCP-MA measurement approximately satisfies the Gaussian distribution, according to the binary hypothesis testing theory, deception detection can be implemented through a double threshold. Denote H 0 to represent the scenario without deception interference, and H 1 to represent the scenario with deception interference, then there are:
[0132]
[0133] where Th u is the upper detection limit, Th l is the lower detection limit, and M AELCP-MA (t) represents the value of the AELCP-MA measurement output.
[0134] Based on the above assumptions, when the measurement is within the detection double threshold, it is reasonable to judge as no deception; otherwise, it is judged as deception. Under the H 0 hypothesis, if the measurement is judged as deception, it is a false alarm event, and the false alarm probability is P fa ; under the H 1 hypothesis, if the measurement is judged as deception, it is a detection event, and the detection probability is P d .
[0135] Theoretically, the false alarm probability P fa and the detection probability P d calculation expressions are:
[0136]
[0137] where f(g) is the probability density function.
[0138] Since the parameters of the deception signal are time-varying and unknown, the theoretical result of the detection probability P d cannot be obtained through Equation (23), so generally statistical methods are used to obtain:
[0139]
[0140] where q is the total number of samples without deception, p represents the total number of samples in the sliding window, Th u and Thl represent the detection upper and lower limits respectively, and N(·) represents the number of satisfied conditions.
[0141] For the detected quantity with a Gaussian distribution, the detection upper and lower limits Th u and Th l are symmetric about the mean
[0142]
[0143] where μ i is the mean of the detected quantity, is the variance of the detected quantity, and erfc -1 is the inverse complementary error function.
[0144] Based on the above, this embodiment also uses Data Scenario 3 (DS3), DS4, DS7 in the Texas Spoofing Test Battery (TEXBAT) of the University of Texas at Austin, and the dynamic scenario DS5 to verify the algorithm performance.
[0145] The TEXBAT spoofing test dataset of the University of Texas at Austin is a commonly used dataset for verifying the performance of spoofing algorithms. TEXBAT contains 8 different attack scenarios, corresponding to DS1 - DS8 respectively. Among them, DS1 is the instantaneous jump from a real signal to a spoofing signal, and it is difficult to detect its spoofing; DS2 and DS5 are static / dynamic scenarios under high power, and the detection difficulty is relatively small; DS3 is a time spoofing scenario with low static power; DS4 is a location spoofing scenario with static power matching, and the spoofing signal power is close to the real signal, making it difficult to detect; in the DS6 scenario, the noise and multipath interference have a serious impact, and it is difficult to distinguish the spoofing attack from the multipath interference; DS7 is a carrier synchronization scenario, and the detection difficulty is relatively large; DS8 is similar to DS7, but DS8 is a spoofing interference with continuous repeated attacks, which is difficult to detect by existing technologies. Combining the content of this embodiment, four spoofing scenarios, DS3, DS4, DS5, and DS7, are selected for spoofing detection experiments, and the specific parameters of the experimental dataset are shown in Table 2.
[0146] Table 2
[0147] Data Scene description Category Power advantage / dB Frequency-locked state ds3 Static low power Time 1.3 Locked ds4 Static power matching Position 0.4 Locked ds5 Dynamic high power Time 9.9 Unlocked ds7 Static power matching Time 1.3 Locked
[0148] For the experimental datasets DS3, DS4, and DS5, there is no spoofing interference from 0 to 100 s. The spoofing injection phase is from 100 to 110 s, the spoofing alignment phase is from 110 to 180 s, the spoofing traction phase is from 180 to 280 s, and the spoofing separation phase starts after 280 s. For DS7, the spoofing signal is injected from 110 to 130 s, the spoofing signal aligns with the real signal from 130 to 150 s, the receiver is pulled to the spoofing signal from 150 to 400 s, and after 400 s, the receiver locks onto the spoofing signal and the spoofing signal starts to separate from the real signal. Taking PRN23 of DS7 as an example, the AELCP detection quantity is as Figure 6 shown.
[0149] In Figure 6 , during the non-spoofing phase and the first and second phases, the waveform of AELCP shows no obvious change. During the third phase, AELCP undergoes certain changes with a large fluctuation range. During the fourth phase, AELCP gradually decreases with a reduced degree of change. To more intuitively analyze the change trend of AELCP, the MA processing is performed on AELCP with a 100 ms window, and the obtained AELCP-MA detection quantity is as Figure 7 shown.
[0150] As can be seen from Figure 7 , there are obvious changes in the waveform of AELCP-MA around 110 s. From 110 to 150 s, the waveform is relatively stable, but its magnitude is greater than that in the non-spoofing case. From 150 to 400 s, AELCP-MA shows a trend of first increasing and then decreasing, and its magnitude is greater than that in the non-spoofing case. After 400 s, AELCP-MA continues to decrease. Generally speaking, when there is spoofing, the magnitude of AELCP-MA is greater than that in the non-spoofing case.
[0151] By comparing Figure 6 and Figure 7 , it can be seen that compared with AELCP, the change trend characteristics of the AELCP-MA detection quantity are more obvious. During the spoofing injection phase, the change of AELCP-MA can be observed. During the spoofing alignment and traction phases, the magnitude of AELCP-MA is different from that in the non-spoofing case.
[0152] Setting the false alarm probability to 10%, according to Equations (25) and (26), the upper and lower detection limits of AELCP-MA are calculated to be 2.190×10^12 and -4.467×10^13 respectively. Further, substituting the upper / lower limit values into Equation (24), the detection probability values are calculated. Taking the sliding window width as 100 ms, one detection probability value is calculated every 1 s. By comparing the detection probabilities of the five detection quantities of AELCP-MA, AELCP, PCS, Delta, and ELP, the results are as Figure 8 shown.
[0153] In Figure 8 From 130 to 150 s, there is a significant change in the detection probability of the AELCP-MA measurement, with the maximum reaching about 70%. The detection probabilities of the other four measurements are all below 50%. After 160 s, the detection probability of the AELCP-MA measurement remains at about 100%. In contrast, the detection probability of the AELCP measurement increases to 90% and significantly decreases after 400 s. The detection probability of the PCS measurement increases to about 90% but starts to rapidly decrease around 250 s. The detection probabilities of the Delta and ELP measurements are always below 50%. From the above results analysis, it can be seen that compared with other measurements, the AELCP-MA measurement shows a higher detection probability and better detection immediacy.
[0154] Based on the binary decision, when the detection probability is greater than or equal to 50%, it is determined that deception exists and is represented by an output result of 1; when the detection probability is less than 50%, it is considered that there is no deception and is represented by an output result of 0. The decision results of AELCP-MA, AELCP, PCS, Delta, and ELP are as Figure 9 shown.
[0155] In Figure 9 , the numbers of detections determined as deceptive interference for the AELCP-MA, AELCP, PCS, ELP, and Delta measurements are 343, 289, 117, 0, and 0 respectively. The number of detections determined by the AELCP-MA measurement is 54 more than that of the AELCP and 226 more than that of the PCS. In the second stage, only the AELCP-MA has a detection result determined as deceptive interference; in the third stage, the numbers of detections determined as deceptive for the AELCP-MA and AELCP measurements are quite the same and significantly more than that of the PCS measurement. Compared with other measurements, the AELCP-MA measurement has more detections determined as deceptive and a wider detection range.
[0156] To further analyze the detection performance of the moving average measurement, MA processing with a sliding window of 100 ms is performed on the three measurements of PCS, Delta, and ELP, and the detection probability curves of PCS-MA, Delta-MA, ELP-MA, and AELCP-MA are plotted, as Figure 10 shown.
[0157] As Figure 10 can be seen, after 130 s, the detection probability of the AELCP-MA measurement remains at about 100%. From (170 - 300) s, the detection probability of the PCS-MA measurement remains at about 100% and is below 50% after 400 s. Only a very small part of the detection probability of the ELP-MA is greater than 50%. The detection probability of the Delta-MA is below 50%.
[0158] From the above analysis, it can be seen that compared with the detection quantities of PCS, ELP, and Delta, the detection quantity of AELCP has a higher detection probability, and all four algorithms detect deception after 160 s; after 130 s, the detection quantity of AELCP-MA can detect deception, and the detection probability always remains at 100%. Compared with the detection quantity of AELCP, the detection quantity of AELCP-MA has better detection timeliness and a higher detection probability.
[0159] To analyze the influence on the detection quantity of AELCP-MA, select = 25 ms, 50 ms, and 100 ms to plot the detection probability curve, as Figure 11 shown.
[0160] In Figure 11 , as ω increases, the fluctuation trend of the detection probability curve of AELCP-MA becomes smaller, and the detection timeliness of AELCP-MA decreases. In the AELCP-MA algorithm, selecting an appropriate window length can improve the timeliness of deception detection.
[0161] Use the common Receiver Operating Characteristic (ROC) curve to analyze the detection probability performance under different false alarm rates. In the ROC curve, the horizontal axis is the false alarm probability, and the vertical axis is the average detection probability from the beginning of the second stage to the end of the third stage of deception. The closer the ROC curve is to the upper left corner, the higher the detection accuracy of the algorithm. Taking PRN7, PRN19, and PRN23 of DS7 as examples, calculate the ROC curves of each detection algorithm, and the results are as Figure 12 shown.
[0162] From Figure 12 it can be seen that for any same satellite, at a given false alarm probability, the ROC curve of AELCP-MA is always higher than other detection quantities. Specifically, taking PRN23 and a false alarm rate of 10% as an example, the detection probabilities of AELCP-MA, PCS-MA, ELP-MA, and Delta-MA are 99.89%, 84.32%, 10.24%, and 9.37% respectively. Among the three selected satellites, the detection probabilities of the detection quantity of AELCP-MA are all above 80%, the detection probabilities of the detection quantity of PCS-MA are all below 70%, and the detection probabilities of the detection quantities of Delta-MA and ELP-MA are all below 30%. Through comprehensive analysis, it can be known that compared with PCS-MA, Delta-MA, and ELP-MA, AELCP-MA has a higher detection probability and deception detection sensitivity.
[0163] To further analyze the universality of the algorithm, multiple deception scenarios are selected for deception detection experiments. Without loss of generality, taking a certain moment of a satellite in four deception scenarios, namely DS3, DS4, DS5, and DS7, as an example, the ROC curves of four detection metrics, namely AELCP-MA, PCS-MA, Delta-MA, and ELP-MA, are calculated. The results are as Figure 13 shown.
[0164] As Figure 13 can be seen, in Figures (a) and (b), the detection probability of the AELCP-MA metric is above 80%, and that of the PCS-MA is above 60%. In Figure (c), the detection probabilities of AELCP-MA and PCS-MA are comparable, both reaching above 90%. In Figure (d), the detection probability of AELCP-MA reaches above 90%, and that of PCS-MA is above 30%. In the four deception scenarios, the detection probabilities of Delta-MA and ELP-MA are both relatively low. Combining the above results analysis, it can be seen that compared with PCS-MA, on the premise of taking into account the detection performance of high-power deception scenarios, the detection probability of AELCP-MA is increased by at least 10% and has higher universality.
[0165] Furthermore, in the four deception environments, 3 different satellites are selected for deception detection analysis, and the multi-satellite ROC curves of different detection metrics are compared. Since the satellites captured in the DS5 dynamic scenario are different from those in the other three static scenarios, PRN18, PRN21, and PRN22 are selected for DS5, and PRN7, PRN19, and PRN23 are selected for the other three static deception scenarios. The multi-satellite ROC curves under different scenarios are as Figure 14 shown.
[0166] As Figure 14 can be seen, in Figures (a), (b), and (d), compared with other detection metrics, the AELCP-MA metric has a higher detection probability. In Figure (c), the detection probabilities of AELCP-MA and PCS-MA are comparable, both above 90%. From the analysis of the experimental results, it can be known that when conducting deception detection experiments in multiple deception scenarios, the AELCP-MA metric demonstrates higher detection probability and robustness.
[0167] This embodiment is based on the TEXBAT deception test dataset of the University of Texas in the United States. The deception detection algorithm is used to detect deception in the dataset. The experimental results show that the solution of this embodiment can effectively detect deception.
[0168] To implement the method of the embodiments of the present invention, the embodiments of the present invention further provide a GNSS spoofing detection system based on the fusion of in-phase branch output and PCS, including: a processor and a memory for storing a computer program that can run on the processor; wherein, when the processor is used to run the computer program, it executes the steps of the method described in any one of the above.
[0169] The above system provided in this embodiment and the above method embodiment belong to the same concept. For the specific implementation process, please refer to the method embodiment, which will not be elaborated here.
[0170] To implement the method of the embodiments of the present invention, the embodiments of the present invention further provide a computer program product. The computer program product includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the steps of the above method.
[0171] Based on the hardware implementation of the above program module, and to implement the method of the embodiments of the present invention, the embodiments of the present invention further provide an electronic device (computer device). Specifically, in one embodiment, the computer device may be a terminal, and its internal structure diagram may be as Figure 15 shown. The computer device includes a processor A01, a network interface A02, a display screen A04, an input device A05 and a memory (not shown in the figure) connected through a system bus. Among them, the processor A01 of the computer device is used to provide computing and control capabilities. The memory of the computer device includes an internal memory A03 and a non-volatile storage medium A06. The non-volatile storage medium A06 stores an operating system B01 and a computer program B02. The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 in the non-volatile storage medium A06. The network interface A02 of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor A01, it implements the method of any one of the above embodiments. The display screen A04 of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device A05 of the computer device may be a touch layer covered on the display screen, or a button, a trackball or a touchpad provided on the computer device housing, or an external keyboard, touchpad or mouse, etc.
[0172] Those skilled in the art can understand that Figure 15 the structure shown in
[0173] The device provided by an embodiment of the present invention includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, the method of any one of the above embodiments is implemented.
[0174] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0175] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0176] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0177] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0178] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.
[0179] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0180] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for information storage. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technologies, compact disc read only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0181] It can be understood that the memory in the embodiments of the present invention can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM, Read-Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), an erasable programmable read-only memory (EPROM, Erasable Programmable Read-Only Memory), an electrically erasable programmable read-only memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), a ferromagnetic random access memory (FRAM, ferromagnetic random access memory), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM, Compact Disc Read-Only Memory); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM, Random Access Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as a static random access memory (SRAM, Static Random Access Memory), a synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory), a dynamic random access memory (DRAM, Dynamic Random Access Memory), a synchronous dynamic random access memory (SDRAM, Synchronous Dynamic Random Access Memory), a double data rate synchronous dynamic random access memory (DDR SDRAM, Double Data Rate Synchronous Dynamic Random Access Memory), an enhanced synchronous dynamic random access memory (ESDRAM, Enhanced Synchronous Dynamic Random Access Memory), a sync link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and a direct rambus random access memory (DRRAM, Direct Rambus Random Access Memory).The memories described in the embodiments of the present invention are intended to include, but are not limited to, these and any other suitable types of memories.
[0182] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or apparatus comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or apparatus. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element.
[0183] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A GNSS spoofing detection method based on in-phase branch output and PCS fusion, characterized in that: The method comprises: Obtain the leading and lagging outputs of the in-phase branch, as well as the PCS detection quantity; Based on the leading and lagging outputs of the in-phase branch and the PCS detection quantity, a first detection quantity is constructed; the first detection quantity is: M AELCP = (|I E | + |I L |) × (M PCS ) Equation (1) Among them, M AELCP is the first detection quantity, I E and I L are the leading and lagging outputs of the in-phase branch, M PCS is the PCS detection quantity; M PCS =E+L-2P, E, L, P are the autocorrelation amplitudes of the leading, immediate and lagging correlators respectively, where, Among them, I E The leading output of the in-phase branch, Q E is the orthogonal branch leading output, I P is the instantaneous output of the in-phase branch, Q P is the instantaneous output of the orthogonal branch, I L is the lagging output of the in-phase branch, Q L It is the lagging output of the orthogonal branch; The first detection amount is subjected to sliding average processing to obtain a second detection amount; the second detection amount is: Among them, M AELCP-MA (n) is the second detection quantity, ω is the length of the sliding window; n=1, 2, ···, N, N is the number of sliding windows; l is the sliding interval, i is the independent variable; The second detection amount is used to perform GNSS navigation spoofing detection.
2. The GNSS spoofing detection method based on in-phase branch output and PCS fusion according to claim 1 is characterized in that: Utilizing the second detection amount to perform GNSS navigation spoofing detection includes: Get the detection threshold; According to the detection threshold and the second detection amount, GNSS navigation spoofing detection is performed using the following calculation formula: Among them, H0 is without deceptive interference, H1 is with deceptive interference, Th l is the lower limit of the detection threshold, Th u is the upper limit of the detection threshold, M AELCP-MA (t) is the second detection quantity.
3. The GNSS spoofing detection method based on in-phase branch output and PCS fusion according to claim 2 is characterized in that: Get the detection threshold, including: The detection threshold is determined using the following calculation: Among them, Th u is the upper limit of the detection threshold, Th l is the lower limit of the detection threshold, μ i is the mean value of the detection quantity, is the variance of the detected quantity, erfc -1 is the inverse complementary error function, P fa is the false alarm probability.
4. The GNSS spoofing detection method based on in-phase branch output and PCS fusion according to claim 2 is characterized in that: Before performing GNSS navigation spoofing detection according to the detection threshold and the second detection amount, the method further includes: Determining whether the second detection quantity satisfies a normal distribution; If it is determined that the second detection quantity satisfies a normal distribution, GNSS navigation spoofing detection is performed based on the detection threshold and the second detection quantity.
5. The GNSS spoofing detection method based on in-phase branch output and PCS fusion according to claim 4 is characterized in that: Determining whether the second detection quantity satisfies a normal distribution includes: Determining a probability density function of the first detected quantity; Determining whether the probability density function of the first detection quantity satisfies a normal distribution; If the probability density function of the first detection value satisfies the normal distribution, then the second detection value satisfies the normal distribution.
6. The GNSS spoofing detection method based on in-phase branch output and PCS fusion according to claim 5 is characterized in that: Determining whether the probability density function of the first detection quantity satisfies a normal distribution includes: Obtaining statistical skewness and statistical kurtosis according to the probability density function of the first detection quantity; Get the standard error of skewness and kurtosis; Calculating a Z score for skewness and kurtosis using the statistical skewness, the statistical kurtosis, the standard error of skewness, and the standard error of kurtosis; Based on the Z score of the skewness and kurtosis, it is determined whether the probability density function of the first detection amount satisfies a normal distribution.
7. The GNSS spoofing detection method based on in-phase branch output and PCS fusion according to claim 6 is characterized in that: The probability density function of the first detection quantity is: in, is the joint probability density function of X and Y, X=|I E |+|I L |,Y=M PCS , Z=XY;I E is the leading output of the in-phase branch, I L is the lagging output of the in-phase branch, M AELCP is the first detection quantity; The statistical skewness is: in, is the statistical skewness, N S is the sample point, is the signal sample mean; The statistical kurtosis is: in, is the statistical kurtosis, N S is the sample point, is the signal sample mean; The skewness standard error is: in, is the standard error of skewness, N S is the sample point; The standard error of kurtosis is: in, is the standard error of kurtosis, N S is the sample point, is the standard error of skewness.
8. The GNSS spoofing detection method based on in-phase branch output and PCS fusion according to claim 7, characterized in that: The Z scores for skewness and kurtosis are: in, is the statistical skewness, is the statistical kurtosis, is the standard error of skewness, is the standard error of kurtosis.
9. A GNSS spoofing detection system based on in-phase branch output and PCS fusion, characterized in that: include: A processor and a memory for storing a computer program that can be run on the processor; wherein, when the processor is used to run the computer program, the steps of the method according to any one of claims 1 to 8 are executed.
10. A storage medium storing a computer program, wherein: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
GNSS deception jamming detection method based on combined SQM square
CN115236701A
SQM satellite navigation deception detection method based on IQ branch
CN115755108A