GPS attack simulator
By using software radio technology and the open source project HackRF One, a portable GPS spoofing jammer was designed, which solved the problem of portable and low-cost GPS spoofing devices, achieved high-precision positioning spoofing of mobile terminals and drones, and improved the spoofing effect and device flexibility.
Patent Information
- Application Number
- CN202410310919.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-19
- Publication Date
- 2025-09-19
AI Technical Summary
Existing technologies make it difficult to realize portable, low-cost GPS spoofing jamming equipment, and lack the ability to deceive mobile terminals and drones with high-precision positioning.
A portable GPS spoofing jammer is designed by combining software-defined radio technology with the open source project HackRF One. Through signal receiving, generation, and transmission modules, a spoofing signal similar to the real signal but with incorrect location information is generated, achieving fixed-point and trajectory spoofing.
It achieves high-precision fixed-point and trajectory deception, improves the deception effect, and the equipment is low-cost and well concealed, making it suitable for positioning interference of mobile terminals and drones.
Smart Images

Figure BSA0000297818250000041 
Figure HSA0000297818260000011 
Figure HSA0000297818260000012
Abstract
Description
Technical Field
[0001] This invention relates to the development of a GPS attack simulator. Currently, most mobile terminal devices use the GPS positioning system. This invention mainly studies the deception of mobile phone and drone positioning systems. Based on software radio technology and open source projects, this invention designs and implements a portable, low-cost GPS generative deception jammer. Background Art
[0002] The Global Positioning System (GPS) is widely used for mobile device positioning, navigation, and timing. However, due to the long transmission distance of satellite signals, they are limited and vulnerable to interference and spoofing. Furthermore, most mobile devices lack mechanisms to detect received satellite navigation signals. This situation creates the potential for mobile terminal positioning and navigation spoofing.
[0003] With information warfare and navigation warfare emerging as new forms of warfare, civilian GPS spoofing has become a research hotspot. Currently, civilian GPS spoofing is primarily categorized into forwarding spoofing and generative spoofing. Generative spoofing can adjust navigation message parameters based on the intended purpose, autonomously generating high-precision navigation signals and posing a greater threat to GPS receiving terminals. Research on simulating and transmitting GPS satellite navigation messages through radio equipment to spoof the terminal's location can help developers implement effective spoofing detection methods for mobile terminals and prevent unauthorized drones from entering specific areas through GPS positioning, thus significantly impacting radio information security.
[0004] Currently, there are numerous research results targeting GPS spoofing attacks. Gao Yangjun, Lü Zhiwei, and others proposed the concept of a portable GPS-generating spoofing jammer, applying low-cost hardware to spoofing mobile terminals. Zhang et al. proposed a feasible method for detecting GPS spoofing attacks. Researchers at UT Austin documented their successful GPS spoofing of a yacht at sea, causing it to deviate from its pre-set track. In their theoretical analysis of DS-smart jamming technology, Wang Xiaoyin, Zhan Yi, and Zhang Jun proposed a smart jamming method for coherent interference in DS-smart communications. By varying the signal pseudo-code rate, a sliding smart jamming signal is generated, achieving automatic pseudo-code phase alignment. Huang Long, Lü Zhicheng, and Wang Feixue studied spoofing jamming against satellite navigation receivers, applying this technology to spoofing navigation receivers and analyzing the power requirements for successful spoofing. At a spoofing gain of 4 dB, the receiver's tracking state can be disrupted for up to 50 minutes. Hu Yanfeng, Bian Shaofeng, and others analyzed power control strategies for GNSS receiver spoofing jamming. Chen Bi proposed a solution to the synchronization problem of GPS spoofing jamming signals. He Liang completed the design and implementation of a GNSS deceptive jamming simulation system, studied the power control during the sliding process, and pointed out that as long as the deceptive signal has a power advantage, the receiver can be pulled, and the deceptive power should not be too large.
[0005] Based on the principles of GPS satellite positioning, mobile phone positioning, and drone navigation, this invention combines software-defined radio (SDR) technology with open-source projects to create a portable, low-cost GPS spoofing jammer. Compared to existing technologies, this invention offers the following advantages: 1) It uses SDR technology to implement the transmitter, generating simulated GPS navigation data files and achieving efficient GPS signal generation; 2) It uses the open-source HackRF One project as the transmitter hardware device, enabling low-cost GPS signal spoofing; 3) It implements both fixed-point and trajectory spoofing jamming methods; and 4) It can spoof dual-frequency devices, improving the accuracy and effectiveness of the spoofing. Summary of the Invention
[0006] Problems solved by the present invention: Based on the existing technology, a portable GPS deception jammer based on software radio technology is designed and implemented, which can realize two major functions: fixed-point deception and trajectory deception.
[0007] The technical solution of the present invention is to use a GPS generation deception system, such as Figure 1 As shown in Figure 1, the generative deception system structure consists of three parts: signal receiving module, signal generating module and signal transmitting module.
[0008] A signal receiver receives real GNSS signals sent by navigation satellites;
[0009] The signal generation module estimates the signal strength, code phase, and carrier frequency of the received navigation signal to generate a signal with a similar signal structure and the same Doppler frequency shift as the real GNSS signal, but with incorrect navigation position information. The deceptive jamming signal has a higher power, thereby increasing time delay or causing the user to receive incorrect position information, resulting in incorrect positioning of the device.
[0010] The signal transmitter transmits a high-power deception signal to gradually draw the pseudo-code tracking loop of the navigation signal receiver to the deception signal.
[0011] The deceptive signal generation block diagram is as follows Figure 2 As shown in the figure, the signal receiver mainly completes the reception and signal processing of GNSS signals. The RF front end receives satellite signals through the antenna and uses the deceptive receiver to calculate the current transmission time of each satellite t k , code phase τ k , carrier phase θ k , Satellite Doppler frequency Satellite clock difference t c , signal amplitude A k , navigation message D and the current speed of the deceptive receiver and position (x s ,y s , z s ), and solve the current speed of the satellite and position (x i ,y i , z i The signal generation module in the deception system is used to save the calculated speed and position information. Based on the specific deception strategy, the generated deception signal is synchronized with the real satellite signal in space, ensuring that the carrier frequency and code phase offsets in the two signals are highly similar. In addition, each communication channel generates a satellite deception signal corresponding to a visible star.
[0012] Each GPS satellite is equipped with an atomic clock and broadcasts its position, time, and pseudo-random noise (PRN) code in real time. PRN codes can be used to identify the source of a signal, and the PRN code calculation data format for civilian GPS-band satellites is generally public. Therefore, by using the ephemeris to obtain the positions and related parameters of at least four orbiting satellites near the target within the specified timeframe, the characteristics of the PRN code calculation method can be exploited to fabricate PRN code information for different satellites.
[0013] Simulating and transmitting satellite PRN code information requires software-defined radio (SDR) technology, which includes both a transmitter and receiver. The receiver consists of a receiver antenna, receiver RF front-end, ADC (analog-to-digital converter), and a programmable code section. The transmitter consists of a transmitter antenna, transmitter RF front-end, DAC (digital-to-analog converter), and a programmable code section. The RF front-end performs frequency modulation. For example, to process a low-pass signal with a bandwidth of 0 to fmax, the Nyquist theorem requires a sampling rate of at least 2*fmax. If the ADC sampling rate does not meet the target, the RF front-end must frequency-convert the received signal. Therefore, the HackRF One was chosen to simulate and transmit a virtual satellite signal carrying PRN code information.
[0014] gps-sdr-sim outputs a binary signal file based on the specified satellite information file, coordinate information, sampling frequency, and other parameters. This is a digital I / Q sample file of the GPS signal. Importing this binary file into the HackRF One simulates the GPS signal, simulating a GPS signal with navigation messages and three-dimensional position information. This simulated GPS signal is then transmitted through an antenna to interfere with devices equipped with GPS positioning modules. HackRF One's deceptive jamming of mobile terminals requires hardware dependencies to be installed on a specified virtual machine or real machine platform. When a device uses dual-frequency GPS positioning, two simulated GPS signals, one in the L1 and one in the L5 bands, are simulated and transmitted simultaneously by two HackRF Ones to mislead the positioning device.
[0015] In addition, the entire system is controlled and managed through a software control platform, including the control of the generation, transmission, and receiving equipment of deceptive signals, as well as the management of signal processing and interference.
[0016] Compared to existing technologies, this device offers the following advantages: the transmitted jamming GPS signal is identical in format to the actual GPS signal. Because its frequency is equal to the nominal frequency of the GPS satellites, it is optimally suited for receiver detection. The probability of being detected by a GPS receiver is higher than that of the actual signal, making it more likely to interfere with the signal and cause positioning errors. Furthermore, the system features low transmission power and excellent concealment, making GPS spoofing jammers more flexible, secure, and reliable in practical applications. Specific implementation methods
[0017] The specific implementation process is as follows Figure 3As shown, a virtual machine running Ubuntu or Kali is used to build a working platform, install hardware dependencies, and run HackRF One stably under Linux. gps-sdr-sim outputs a binary signal file based on a specified satellite information file (satellite ephemeris), coordinate information, sampling frequency, and other parameters. By importing this binary file into a radio frequency device (HackRF One), GPS signals can be forged, simulating a GPS spoofing signal with navigation messages and 3D location information. The signal is then frequency-converted and transmitted to interfere with devices equipped with GPS positioning modules.
[0018] Based on the analysis of effective GPS deception jamming, the present invention mainly includes two deception jamming methods: fixed-point deception and trajectory deception. When generating a fixed-point deception GPS signal, it is necessary to obtain the static location information of the target location in advance, such as longitude, latitude and
[0019] Horizontal height is a valid parameter for gps-sdr-sim. When generating a GPS signal for trajectory spoofing, you need to draw and generate a target trajectory file in advance and use it as a valid parameter for gps-sdr-sim to forge the GPS spoofing signal.
[0020] Based on the analysis of devices containing GPS positioning modules and consideration of the actual experimental environment, the deception targets of the present invention mainly include mobile terminals and drones represented by mobile phones. When a device is located through dual-frequency GPS, such as a dual-frequency mobile phone, two GPS simulation deception signals with frequency bands of L1 (1575.42MHz) and L5 (1176.45MHz) will be simulated and generated, and transmitted simultaneously by two HackRF Ones to interfere with the positioning device. This patent conducted experiments on the proposed method to deceive and interfere with mobile phones in indoor and outdoor environments, and compared the deception effects in the two environments. The detection indicators include the farthest distance of successful deception (m) and the time required for successful deception (s). We ensure that the mobile phone is equipped with a sim card, the mobile network and WIFI are turned on, the positioning mode is adjusted to high precision (GPS, WIFI and base station joint positioning), and the same GPS deception signal is used. We conducted deception interference experiments in indoor and outdoor environments respectively, and the result data are shown in the following table:
[0021]
[0022] As can be seen from the table, the maximum distance at which spoofing is successful is much shorter in outdoor environments than indoors. This analysis leads us to the conclusion that the strength of the real GPS satellite signal increases outdoors, while the strength of the simulated GPS spoofing signal decreases rapidly with increasing transmission distance. When the strength of the spoofing GPS signal falls below that of the real GPS signal, the phone relocks to the real GPS satellites for positioning. Therefore, variations in the strength of the real GPS signal both indoors and outdoors affect the maximum distance at which spoofing is successful.
[0023] The present invention conducted an experiment on deceiving and interfering with a drone using the proposed method. When the drone was stationary, the deceiving signal affected its GPS positioning, preventing successful positioning and causing the drone to be unable to take off. When the drone was flying, the deceiving signal interfered with the drone's GPS positioning signal. In addition, since the strength of the real GPS satellite signal increased in the outdoor environment, the strength of the false GPS signal would decrease rapidly with the increase of the transmission distance. When the strength of the false GPS signal was lower than that of the real GPS signal, the real GPS satellite would be re-locked for positioning. The false and real signals would alternate, making the drone uncontrollable by remote control. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It is the structure of the generative deception system;
[0025] Figure 2 A block diagram of a generated deception signal based on a signal received by a navigation receiver;
[0026] Figure 3 For the specific implementation process.
Claims
1. A portable GPS spoofing jammer utilizes software-defined radio (SDR) technology to achieve low-cost, portable GPS signal generation and spoofing. This device helps developers implement effective spoofing detection methods for mobile terminals and can prevent illegal drones from entering specific areas via GPS positioning. This invention primarily studies the spoofing of mobile phone and drone positioning systems. Currently, most mobile phones use GPS positioning systems, while GPS navigation technology is primarily used in drone navigation. The GPS global satellite positioning system typically consists of three core components: a ground control system, a satellite space system, and a terminal device. It can be said that it is the coordinated cooperation of these three components that enables the entire positioning process. The spoofing process works by receiving a genuine GNSS signal transmitted by a navigation satellite through a signal receiver. By estimating the signal strength, code phase, and carrier frequency of the received navigation signal, a signal with a similar signal structure and the same Doppler frequency shift as the genuine GNSS signal is generated, but with erroneous navigation location information. The spoofing jammer has a higher power, thereby increasing time delay or causing the user to receive erroneous location information, resulting in a misplaced positioning of the device. During the spoofing jamming process, a spoofing signal is generated whose relative pseudocode can shift relative to the true signal. A high-power spoofing signal is then transmitted to gradually draw the navigation signal receiver's pseudocode tracking loop toward the spoofing signal. Based on the principle, its implementation consists of the following two parts: (1) HackRF One, based on the open source project, is used as the transmitter hardware device. (2) Software radio technology is used to implement the transmitter, which is used to generate simulated GPS navigation data files. The transmitter generates sample files through the compilable code area, and then transmits them through the antenna through digital-to-analog conversion and frequency modulation of the RF front end.
2. The portable GPS spoofing jammer according to claim 1, characterized in that: The process of implementing the HackRF One transmitter hardware device based on the open source project is as follows: 1) HackRF One is an open-source SDR hardware device with the lowest price and complete transceiver functions. It supports most open-source SDR projects, including gps-sdr-sim and hackrf-tools. gps-sdr-sim is responsible for simulating and generating GPS navigation data files, while hackrf-tools is responsible for transmitting the generated data files through the hackrf_transfer command. 2) The HackRF One spoofs dual-band GPS mobile terminals in the L1 (1575.42MHz) and L5 (1176.45MHz) frequency bands. The absolute value of the TX power is less than 10dBM, so the HackRF One's RF front-end amplifier is required to increase the antenna gain to 30dB. This ensures that the HackRF One's output power meets the requirements for short-range over-the-air transmission or driving an external amplifier. To achieve longer-range spoofing, a 20dB gain RF transmitter chip is added to the antenna's ANT port. 3) The shell script used to implement the spoofing does not reference a timer. The only part that requires an external clock is the transmission delay when transmitting the simulated GPS signal. Since the transmission is performed by the hackrf_transfer command included in the HackRF One software tool hackrf-tools, there is no need to adjust the clock parameters. 4) HackRF One removed the PCB antenna from its test version, leaving only the SAN antenna port. We connected it to the AWS-RF antenna, which can transmit radio signals from 700MHz to 2700MHz, meeting the spoofing requirements. 5) HackRF One has a reset button that reconnects the USB and refreshes the internal buffer. Since we need to record and transmit large data files during the spoofing process, we need to use the reset button to refresh the internal buffer when transmitting different files to free up enough space for the virtual machine's memory. 6) The transmission gain of the transmitting part is set to the maximum value of 47dB to expand the influence range of the transmitting antenna.
3. The portable GPS spoofing jammer according to claim 1, characterized in that: The process of using software radio technology to implement the transmitter and generate simulated GPS navigation data files is as follows: 1) Obtaining GPS satellite observation data. Satellite ephemeris is used to describe the position and velocity of a space object and obtain GPS navigation messages. 2) Obtain the deceptive three-dimensional position information or NEMA format trajectory file to implement two deceptive jamming methods: fixed-point deception and trajectory deception; 3) gps-sdr-sim outputs a binary signal file based on the specified satellite information file, coordinate information, sampling frequency and other parameters, that is, a digital VQ sample file of the GPS signal. By importing this binary file into HackRF One, you can forge the GPS signal and simulate a GPS simulation signal with navigation message and 3D position information. Then, you can transmit the GPS simulation signal through the antenna to interfere with devices with GPS positioning modules.