GNSS spoofing detection method facing back related domain radio frequency fingerprint

CN122592436APending Publication Date: 2026-08-18NAT UNIV OF DEFENSE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611083200.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-21
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

然而实际应用中欺骗手段未知且多变,采集所有潜在欺骗样本并不现实,且随着星历演变及接收机温漂,特征参数会发生漂移

Benefits of technology

[0006] The aforementioned GNSS spoofing detection method based on post-correlation domain RF fingerprints firstly effectively eliminates time-varying and static channel interference through a high-resolution multicorrelator array, SVD spatiotemporal subspace projection, and an asymmetric weighted window based on the physical law of multipath positive delay. It also defines 11-dimensional low-redundancy physical features to characterize the fundamental hardware differences between real satellite links and software-defined radio spoofers. Regarding the detection model, an adaptive anomaly detection architecture is constructed using a single-class support vector machine, relying solely on dynamic training of the decision boundary during the initial tracking phase of real samples, thus avoiding the dependence on spoofing samples found in traditional supervised classification. Furthermore, this application innovatively introduces PLL/DLL tracking loop jitter features, utilizing receiver internal phase detector data as a supplement to the RF fingerprint, effectively solving the problem of difficulty in distinguishing high-fidelity relay-type spoofing based solely on correlation peak waveforms. Experiments show that real constellation features exhibit a broad discrete distribution, while single-source multi-satellite spoofing exhibits variance collapse due to shared front-end. This application requires no additional hardware or modification of the signal system and demonstrates high robustness in GNSS spoofing detection with good generalization ability against unknown spoofing methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122592436A_ABST
    Figure CN122592436A_ABST
Patent Text Reader

Abstract

This application relates to a GNSS spoofing detection method based on post-correlation domain radio frequency fingerprints. The method includes: acquiring the complex correlation peak vector in the post-correlation domain using a high-resolution multicorrelator array; reconstructing the message polarity and accumulating it to build a spatiotemporal observation matrix; extracting the first principal component and aligning its phase using SVD spatiotemporal subspace projection to filter out time-varying channel noise; applying an asymmetric weighted spatial window to suppress static multipath and obtain a clean hardware radio frequency fingerprint waveform; extracting 11-dimensional physical distortion features from the left effective interval to form a feature vector; training a single-class support vector machine using only real samples in the initial tracking stage to dynamically fit the security decision boundary; calculating the anomaly score of the unknown signal in real time and comparing it with a dynamic threshold to determine spoofing interference. This method enables open-set, highly robust detection of unknown spoofing attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of satellite spoofing detection technology, and in particular to a GNSS spoofing detection method based on post-correlation domain radio frequency fingerprinting. Background Technology

[0002] With the widespread application of Global Navigation Satellite Systems (GNSS), spoofing and interference detection has become a research hotspot in the field of navigation security. Existing detection methods mainly involve array antenna technology in the space domain, encryption and authentication technology in the information domain, anomaly monitoring technology in the signal domain, and integrated navigation technology in the system domain. However, array antennas are limited by high costs and complex cooperative correction mechanisms, making them difficult to popularize in ordinary commercial receivers; encryption and authentication technology requires updating and upgrading the entire navigation signal system, which is difficult to implement on existing civilian satellites and is still susceptible to delayed replay attacks; anomaly monitoring technologies based on automatic gain control, absolute power, and carrier-to-noise ratio cannot completely defend against near-zero delay relay-based spoofing attacks; multi-source integrated navigation requires additional hardware, resulting in high system complexity and power consumption, making it unsuitable for low-cost terminals.

[0003] Radio frequency fingerprinting (RFF) identification technology based on physical layer security offers a new approach to spoofing detection because it requires no modification to the signal system and is difficult to clone or forge. However, traditional RFF methods mostly focus on the raw I / Q data (i.e., the pre-correlation domain) output by the receiver's RF front-end. The weak hardware RFF features are easily masked by drastically changing channel characteristics and multipath noise, leading to a significant decline in the robustness of spoofing detection models in complex or cross-scenario environments. Furthermore, most existing research treats GNSS spoofing detection as a supervised binary classification problem, requiring the training dataset to contain a large number of labeled real and spoofing signal samples. However, in practical applications, spoofing methods are unknown and variable, making it impractical to collect all potential spoofing samples. Moreover, feature parameters drift with ephemeris evolution and receiver temperature drift. Therefore, there is an urgent need for a detection method that does not require prior spoofing samples, can effectively remove channel interference, and has the ability to generalize to unknown spoofing. Summary of the Invention

[0004] Therefore, it is necessary to provide a GNSS spoofing detection method based on post-correlation domain radio frequency fingerprints that can effectively remove channel interference and generalize to unknown spoofing, without requiring spoofing prior samples.

[0005] A GNSS spoofing detection method based on post-correlation domain radio frequency fingerprinting, the method comprising: Using the high-resolution multicorrelator array of the receiver, the GNSS signal of the Global Navigation Satellite System is despread and coherently integrated to obtain the high-resolution complex correlation peak vector of the current epoch; The high-resolution complex correlation peak vectors of multiple consecutive epochs are reconstructed by the message polarity, and the reconstructed multi-epoch vectors are accumulated to construct a spatiotemporal observation matrix. Singular value decomposition is performed on the spatiotemporal observation matrix to extract the first principal component, and the first principal component is phase-rotated and aligned to obtain the denoised complex waveform after filtering out time-varying channel noise. An asymmetric weighted spatial window is applied to the denoised complex waveform to suppress static multipath components and obtain a clean hardware RF fingerprint feature waveform. From the left effective region of the pure hardware RF fingerprint feature waveform, multiple dimensions of physical distortion features are extracted to form the RF fingerprint feature vector. During the initial stable tracking phase of a satellite by the receiver, multiple sets of radio frequency fingerprint feature vectors are collected as real samples to train a single-class support vector machine and dynamically fit the security decision boundary under the current environment. For unknown signals input in real time, extract real-time radio frequency fingerprint feature vectors, calculate the anomaly score from the real-time radio frequency fingerprint feature vector to the security decision boundary, compare the anomaly score with the dynamic alarm threshold, and determine deception interference when the anomaly score exceeds the threshold.

[0006] The aforementioned GNSS spoofing detection method based on post-correlation domain RF fingerprints firstly effectively eliminates time-varying and static channel interference through a high-resolution multicorrelator array, SVD spatiotemporal subspace projection, and an asymmetric weighted window based on the physical law of multipath positive delay. It also defines 11-dimensional low-redundancy physical features to characterize the fundamental hardware differences between real satellite links and software-defined radio spoofers. Regarding the detection model, an adaptive anomaly detection architecture is constructed using a single-class support vector machine, relying solely on dynamic training of the decision boundary during the initial tracking phase of real samples, thus avoiding the dependence on spoofing samples found in traditional supervised classification. Furthermore, this application innovatively introduces PLL / DLL tracking loop jitter features, utilizing receiver internal phase detector data as a supplement to the RF fingerprint, effectively solving the problem of difficulty in distinguishing high-fidelity relay-type spoofing based solely on correlation peak waveforms. Experiments show that real constellation features exhibit a broad discrete distribution, while single-source multi-satellite spoofing exhibits variance collapse due to shared front-end. This application requires no additional hardware or modification of the signal system and demonstrates high robustness in GNSS spoofing detection with good generalization ability against unknown spoofing methods. Attached Figure Description

[0007] Figure 1 This is a flowchart illustrating a GNSS spoofing detection method based on post-correlation domain radio frequency fingerprinting in one embodiment. Figure 2 The ROC curves for deception detection under different types of deception interference are shown for the integrated fusion model proposed in this application and other existing models in one embodiment. Figure 2 (a) is the ROC curve of the deception detection of the model in response to high-power deception interference; Figure 2 (b) ROC curve of deception detection for the model in response to low-power deception interference; Figure 3 Here is a ROC curve of the spoofing detection for the model in one embodiment to deal with matched power spoofing interference; Figure 4 This is a probability density distribution diagram of the first 6 features of the 11-dimensional radio frequency fingerprint feature proposed in this application under different types of spoofing interference in one embodiment; Figure 4 (a) shows the probability density distribution of feature 1 in three deception scenarios; Figure 4 (b) Probability density distribution of feature 2 in three deception scenarios Figure 4 (c) shows the probability density distribution of feature 3 in the three deception scenarios. Figure 4 (d) shows the probability density distribution of feature 4 in the three deception scenarios. Figure 4 (e) is the probability density distribution of feature 5 in the three deception scenarios. Figure 4 (f) is the probability density distribution of feature 6 in three deception scenarios; Figure 5 This is a probability density distribution diagram of the last 5 features of the 11-dimensional radio frequency fingerprint feature proposed in this application under different types of spoofing interference in one embodiment; Figure 5 (a) shows the probability density distribution of feature 7 in three deception scenarios. Figure 5 (b) shows the probability density distribution of feature 8 in the three deception scenarios. Figure 5 (c) shows the probability density distribution of feature 9 in the three deception scenarios. Figure 5 (d) shows the probability density distribution of feature 10 in the three deception scenarios. Figure 5 (e) is the probability density distribution of feature 11 in three deception scenarios. Detailed Implementation

[0008] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0009] In one embodiment, such as Figure 1 As shown, a GNSS spoofing detection method based on post-correlation domain radio frequency fingerprinting is provided, including the following steps: Step 102: Using the receiver's high-resolution multicorrelator array, despread and coherently integrate the GNSS signal of the Global Navigation Satellite System to obtain the high-resolution complex correlation peak vector of the current epoch.

[0010] Real GNSS signals inevitably undergo nonlinear compression by a power amplifier and spectral truncation by a bandpass filter at the transmitter. Assuming the transmitter's inherent baseband equivalent impulse response is... Then, after passing through the spatial physical channel, the down-converted complex baseband signal captured by the receiving antenna... It can be modeled as a superposition of the Line of Sight (LOS), multipath components, and additive white Gaussian noise: ; in, For ideal digital baseband signals; Represents the LOS signal. Representing the Multipath signal components; , , These represent the complex fading amplitude, delay, and carrier phase drift for the corresponding path. This refers to the receiver's local thermal noise.

[0011] Traditional GNSS receivers typically use three correlators (early, prompt, and late) for code phase tracking. This sparse sampling design can be considered a type of low-pass filter, which will severely lose signal strength. This causes microscopic waveform distortion. Therefore, this application reconstructs the traditional EPL architecture of the GNSS receiver into a high-resolution multi-correlator array architecture in the baseband processing stage. Assume the pseudo-random noise code sequence generated locally by the receiver is... In the One coherent integral period Internally, after using a phase-locked loop and a delay-locked loop to remove the Doppler frequency shift, a setting is made. If there are n parallel local copy code generator branches, then the nth The complex correlation output of each correlator tap It can be represented as: ; in, and These are the LOS code phase and carrier phase estimated by the receiver loop, respectively. This is the set phase offset of the multicorrelator array code.

[0012] To fully cover the signal distortion region caused by band-limiting effects, this application extends the observation interval beyond the theoretical triangular peak base, setting... , For a chip width, the step size is set to A chip. Therefore, the observation data of a single epoch is mapped to a... 3D high-resolution complex correlation peak vector ,satisfy: .

[0013] The above steps fully cover the signal distortion region caused by the band-limiting effect through high-density sampling, preserving high-resolution waveform details for subsequent purification of the transmitter hardware fingerprint, and solving the problem of losing microscopic distortion due to sparse sampling in the traditional EPL architecture.

[0014] Step 104: Reconstruct the message polarity of the high-resolution complex correlation peak vectors of multiple consecutive epochs, and accumulate the reconstructed multi-epoch vectors to construct a spatiotemporal observation matrix.

[0015] Furthermore, before feature extraction, the phase reversal problem in the navigation message caused by BPSK modulation must be considered. Taking the GPS L1 band C / A signal as an example, a data bit jump occurs every 20ms, causing the polarity of the correlation peak to change. and The random flipping between these points leads to energy cancellation upon direct integration. Traditional GNSS receivers typically employ incoherent integration to accumulate signal-to-noise ratio (SNR) to address this issue. However, the squared nonlinearity introduced by incoherent integration not only causes non-Gaussian distortion of the noise distribution but also results in the loss of I / Q imbalance defects hidden in the complex domain phase. To minimize the loss of RFF feature purification, this application abandons incoherent integration and uses a hard decision symbol function of the baseband in-phase branch to analyze the entire high-resolution complex correlation peak sequence. Polarity reconstruction is performed to overcome data bit jumps while achieving pure linear coherent accumulation of multi-epoch data. This maximizes the preservation of high-frequency edge distortions and phase eigenmorphisms of the transmitter bandpass filter impulse response, providing an ideal data basis for subsequent SVD linear subspace projection. Therefore, the sign function of the prompt branch in-phase component is utilized. Perform message stripping: ; Through cumulative continuity Vectors of each epoch are used to construct a spatiotemporal observation matrix. for: ; The above steps eliminate the incoherent integration used by traditional receivers to process message flips, avoid noise non-Gaussian distortion and phase information loss caused by square nonlinear operations, achieve pure linear coherent accumulation, and preserve the high-frequency edge distortion and phase eigenmorphism of the transmitter bandpass filter impulse response to the greatest extent, providing an ideal data basis for subsequent SVD linear subspace projection.

[0016] Step 106: Perform singular value decomposition on the spatiotemporal observation matrix, extract the first principal component, and perform phase rotation alignment on the first principal component to obtain the denoised complex waveform after filtering out time-varying channel noise; apply an asymmetric weighted spatial window to the denoised complex waveform to suppress static multipath components and obtain a clean hardware RF fingerprint feature waveform.

[0017] Although coherent integration of GNSS receivers helps improve the signal-to-noise ratio, observation matrices from consecutive epochs... It is still inevitably affected by high-frequency thermal noise and time-varying multipath propagation. Considering that the transmitter hardware RFF is an inherent physical static characteristic, while environmental noise and channel fading are high-frequency time-varying characteristics, this application introduces a spatiotemporal subspace projection mechanism to decouple the features and apply it to the matrix. Singular value decomposition is performed as follows: ; in, For containing singular values A diagonal matrix, arranged in descending order; matrix The row space corresponds to the time manifold, and the column space corresponds to the code phase (space) manifold.

[0018] According to the principal component manifold distribution principle, the largest singular value and its corresponding right singular vector represent The most common and stable time-invariant hardware property contributing the largest variance in each epoch is the distortion of the direct wave and the inherent bandpass filter of the transmitter. Within a short time window, it is absolutely static and contributes the largest covariance to the entire matrix. The secondary singular vector... This characterizes time-varying multipath fading caused by receiver motion or environmental disturbances, as well as independent and identically distributed Gaussian white noise. By retaining only the first principal component... Furthermore, by rotating and aligning the residual carrier drift of its center phase to the in-phase real axis in the complex plane, this application reconstructs the denoised complex waveform after filtering out dynamic channel interference: .

[0019] This sub-step utilizes the inherent properties of hardware, which is absolutely static within a short time window while time-varying channel noise changes at a high frequency, to remove dynamic channel interference through principal component analysis.

[0020] Although SVD can orthogonally separate high-frequency thermal noise from time-varying multipath, thus effectively filtering out dynamic channel noise, it is less effective against static multipath caused by completely static reflectors in the environment. The time-invariant characteristic is also present in each epoch, and will remain in This interferes with subsequent measurements of the transmitter's inherent distortion.

[0021] Therefore, this application introduces the asymmetric physical causality law of GNSS physical propagation. Since the spatial physical propagation distance of any multipath reflection link must be greater than that of the direct wave, the arrival time of the multipath signal must exhibit a positive lag, that is, the time delay of the multipath component is always positive relative to the direct wave. Based on this physical theorem, the right half of the correlation peak... It is full of multipath distortion, and the left half is full of multipath distortion. Theoretically, there is no multipath propagation. Any asymmetric stretching and basis oscillations in the waveform on the left can be considered entirely due to RFF defects in the transmitter's RF front-end. Based on this physical prior, this application designs an asymmetric weighted spatial window. Physical truncation is performed on the reconstructed waveform: ; in, , Indicates the chip cycle, for The region is assigned an absolute weight of 1 to preserve the transmitter's RFF characteristics without loss; for The region is gradually attenuated using a smooth decreasing cosine function, which eliminates potential far-end static multipath tails while avoiding spectrum leakage caused by abrupt truncation.

[0022] Finally, the clean hardware RFF features, after channel feature filtering and multipath stripping, are obtained. This can be expressed as the Hadamard product normalized to the instantaneous branch amplitude: ; In summary, the original received signal, affected by the environment, is reconstructed into RFF characteristics that highlight the transmitter's inherent nature. By utilizing the physical prior of positive multipath delay, static multipath signals, which exhibit time-invariant characteristics similar to direct waves, are completely suppressed, ensuring that subsequent characteristics fully reflect transmitter hardware distortion.

[0023] Step 108: Extract physical distortion features of multiple dimensions from the left effective range of the pure hardware RF fingerprint feature waveform to form an RF fingerprint feature vector.

[0024] An 11-dimensional physical distortion feature vector is constructed from the left effective region (multipath immune region) of the pure hardware RF fingerprint feature waveform. The specific calculation methods for these features are detailed in the embodiments corresponding to the subsequent dependent claims. This step transforms waveform data that is difficult to compare directly into distortion measures with clear physical meaning, including the morphological variance of the mapped group delay, the morphological skewness of the mapped power amplifier nonlinearity, the morphological kurtosis of the mapped DAC quantization noise, the early ringing energy of the mapped out-of-band attenuation characteristics, the slope asymmetry ratio of the mapped spectral asymmetry, the harmonic distortion ratio of the mapped harmonic components, the differential kurtosis of the mapped local abrupt changes, the segment residual entropy of the mapped energy distribution, the correlation peak symmetry deviation of the mapped left-right symmetry, and the channel-normalized PLL jitter and DLL jitter introduced from the tracking loop. These features, after Z-score normalization, form a high-dimensional feature space of equal scale, providing physically interpretable and low-redundancy input for subsequent classification. Specifically: This application focuses on the baseband impulse response of the transmitter simulation front end. Only in the pure waveform of multipath immunity Within the effective range on the left, an 11-dimensional physical RFF distortion feature vector covering four dimensions—amplitude, frequency domain, morphology, and tracking loop—was constructed. .

[0025] Assuming an ideal PRN code autocorrelation function under infinite bandwidth ,extract Calculate the relative amplitude distortion residual vector with respect to the ideal waveform for the real part amplitude within the left effective interval. for: ; Assuming that within the selected valid interval, there are a total of If there are discrete sampling taps, then the vector The The elements are denoted as , defined in the At a specific code phase offset point, the physical deviation between the real part amplitude of the receiver-purified true correlation peak and the amplitude of the infinite bandwidth ideal triangular peak maps the degree of microscopic distortion of the ideal straight line by the transmitter filter band-limiting effect and the power amplifier nonlinearity. Based on Based on the higher-order statistical moments and out-of-band response of the filter, this application constructs a multidimensional characteristic manifold covering the overall waveform distribution and transient response. Their physical mapping mechanisms are defined as follows: (1) Morphological variance The group delay of the mapped transmitter bandpass filter satisfies: ; in, The number of valid taps. The mean of the residual sequence represents the degree of dispersion of the overall waveform from the ideal slope, and quantifies the degree of out-of-band spectrum cutoff by the band-limited filter of the deceiving transmitter's RF front-end and its nonlinear group delay distortion.

[0026] (2) Morphological skewness The nonlinear compression of the mapped power amplifier satisfies: ; in, The standard deviation of the residual sequence represents the asymmetry of waveform distortion. Since the low-cost power amplifiers of SDR spoofers generally operate in the critical saturation region, the AM-AM and AM-PM nonlinear compression they exhibit leads to a significant asymmetric skewness in the rising edge of the ideal correlation peak.

[0027] (3) Morphological kurtosis The transient defects of the mapped DAC and numerically controlled oscillator satisfy: ; When the spoofer generates high-frequency pseudocode at the digital baseband layer, the quantization noise and clock jitter of its DAC will be reflected in the smoothness transient spike at the top of the correlation peak, while the kurtosis calculated using the fourth-order central moment is more sensitive to the high-frequency transient tail.

[0028] (4) Early ringing energy Mapping out-of-band attenuation characteristics, satisfying: ; Assuming unlimited bandwidth, The correlation peak in the region is theoretically always 0. However, the Gibbs phenomenon generated by the real band-limited system will inevitably lead to the generation of floor ripples. Therefore, the mean square energy of this region is extracted to characterize the out-of-band attenuation characteristics of the filter.

[0029] (5) Slope asymmetry ratio The asymmetric distortion of the transmitter spectrum is mapped to satisfy: ; in, It is a first-order difference operator; This represents the amplitude gradient of the rising edge of the relevant peak. This represents the amplitude gradient of the falling edge. Real satellite transmitters, due to the asymmetry in the frequency response of their bandpass filters, exhibit different slope characteristics on the rising and falling edges. In contrast, SDR spoofers use a general-purpose software radio platform, whose transmit filters differ fundamentally from the satellite payload hardware in terms of spectral asymmetry. This results in a systematic shift in the slope asymmetry ratio between the two signal types, making it an effective amplitude-domain discriminant for distinguishing between genuine and spoof signals.

[0030] (6) Harmonic distortion ratio The harmonic components generated by the nonlinearity of the mapped transmitter power amplifier satisfy: ; in, for through The frequency domain complex spectrum after point FFT transformation, with a set frequency point. For high-frequency components, calculate the proportion of energy of high-frequency components in the total energy of the entire frequency band in the power spectrum. An ideal triangular wave contains only low-order harmonics, while the AM-AM nonlinear compression of the transmitter power amplifier will excite higher-order harmonics on the high-frequency side. The operating point and nonlinear coefficient of the power amplifier vary among different transmitters, and the harmonic distortion ratio is not affected by channel multipath interference.

[0031] (7) Differential kurtosis The local morphological abrupt change in the mapped correlation peak waveform satisfies: ; calculate The kurtosis of the first-order differential is significant because differential operations can amplify local irregular jumps in waveforms, while the differential kurtosis of a real satellite high-precision atomic clock is significantly lower than that of an SDR spoofer using a cheap crystal oscillator.

[0032] (8) Sub-segment residual entropy The energy distribution fingerprint of the transmitter impulse response is mapped to satisfy: ; Among them, Divide the waveform into multiple segments and calculate the residual variance of each segment relative to the ideal waveform. Normalized to a probability distribution Then calculate the Shannon entropy. Because the band-limited filter frequency response of a real satellite exhibits stable and unique passband ripple in each frequency band, the residual variance of each sub-segment displays a specific distribution, and the sub-segment residual entropy... It can capture the diversity of residuals in each subband simultaneously.

[0033] (9) Symmetry deviation of related peaks The mirror-symmetric deviation of the left and right sides of the quantification correlation peak satisfies: ; in, The Pearson correlation coefficient is... This is the reverse order of the amplitude sequence to the left of the relevant peak. The right-hand amplitude sequence is used for comparison, with the shortest overlap length between the two sides being selected. An ideal triangular wave is perfectly symmetrical, but the asymmetry of the group delay frequency response of the transmitter's bandpass filter disrupts the symmetry of the correlation peaks, and the frequency response asymmetry varies between different transmitters.

[0034] (10) In-channel normalized PLL jitter The degree of abnormal deviation of the current epoch carrier phase tracking loop is reflected, satisfying the following: ; in, The standard deviation of the PLL phase detector output within the current epoch window. and These are the mean and standard deviation of the channel during the real signal phase, respectively, used as the intra-channel reference. Intra-channel normalization completely eliminates the systematic bias caused by antenna gain differences between different receiver channels, making... Characterizes the phase noise increment relative to the channel's own reference. Spoofing signals introduce additional phase jitter. Significantly increased.

[0035] (11) In-channel normalized DLL jitter The degree of abnormal deviation of the current epoch code phase tracking loop is reflected, satisfying: ; in, This outputs the DLL phase detector within the current epoch window. The stability changes of code phase tracking are quantified: when the spoofer pulls the receiver to track a false target, the code phase loop error will systematically increase, exceeding the normal fluctuation reference range of the channel. NDDS normalizes this increment and provides discrimination information independent of the channel absolute gain.

[0036] Furthermore, to eliminate the differences in the dimensions and numerical ranges of different characteristic physical quantities, for continuous... The feature matrix extracted from each epoch is Z-score normalized to... This allows for the construction of a high-dimensional RFF feature space of equal scale.

[0037] Step 110: During the initial stable tracking phase of a satellite by the receiver, multiple sets of radio frequency fingerprint feature vectors are collected as real samples to train a single-class support vector machine and dynamically fit the security decision boundary under the current environment.

[0038] During the initial stable tracking phase of a satellite by the receiver (at which point the signal has not yet been hijacked by the deception device and is in a safe state), the model extracts this clean time-series feature sequence in real time. A single-class support vector machine, independent of any negative samples, is dynamically trained to dynamically fit the deception detection boundary under the current ephemeris elevation angle and temperature drift environment. Simultaneously, a radial basis function (RBF) kernel function is introduced. By mapping the features to a high-dimensional space, the dynamic fitting is transformed into solving a convex optimization problem. ; in, Let be the normal vector of the hyperplane in high-dimensional space; This represents the geometric distance from the origin to the hyperplane. As a relaxation variable, it provides tolerance for the very few true benchmark data points that may deviate from the normal range due to transient thermal noise jitter or ionospheric scintillation; penalty factor. It is a regularization parameter that controls the ratio of support vectors and the false positive rate of the training set.

[0039] Without requiring any deception samples, it dynamically fits the decision boundary based solely on real signals in the current environment, and can adapt to different ephemeris elevation angles and temperature drift conditions. This solves the problem that traditional supervised classification requires a large number of labeled deception samples and cannot generalize to unknown deceptions.

[0040] Step 112: Extract the real-time radio frequency fingerprint feature vector for the real-time input unknown signal, calculate the anomaly score from the real-time radio frequency fingerprint feature vector to the security decision boundary, compare the anomaly score with the dynamic alarm threshold, and determine the deception interference when the anomaly score exceeds the threshold.

[0041] For unknown signals input in real time, extract the unknown features of the real-time input following the same process. Define its timing anomaly score The negative value of the distance from the feature point to the safe decision boundary: ; in, To find the Lagrange multipliers for solving convex optimization problems. When When this occurs, it indicates that the current signal is outside the safety boundary. To achieve robust constant false alarm rate control, this application extracts anomaly scores from the benchmark training set. Quantiles as dynamic alarm thresholds The real-time anomaly detection criteria are as follows: ; By introducing a dynamic threshold for constant false alarm rate control, the failure of fixed thresholds in different environments is avoided, and the anomaly score directly reflects the degree to which the signal deviates from the true distribution, thus having good interpretability.

[0042] In the aforementioned GNSS spoofing detection method based on post-correlation domain RF fingerprinting, firstly, unlike the traditional pre-correlation domain RFF method where weak hardware features are easily masked by channel noise, this application utilizes the post-correlation domain data after the GNSS signal is despread and demodulated by the receiver. Its signal-to-noise ratio is significantly higher than that of the pre-correlation domain, providing a clean data foundation for mining RF fingerprint features. Furthermore, combined with channel feature stripping mechanisms (including high-resolution multicorrelator arrays, SVD spatiotemporal subspace projection, and asymmetric multipath suppression windows), a deep decoupling of the transmitter's inherent hardware properties and the channel's transient features is achieved, thus solving the problem of significant robustness degradation caused by channel changes across different scenarios in traditional methods. Secondly, addressing the issue that existing supervised classification methods rely on a large number of labeled... To address the limitations of relying solely on deception samples and being unable to handle unknown deception attacks, this application introduces the physical law that multipath signals only exist with positive delay. It designs an asymmetric weighted spatial window to losslessly preserve the left-side multipath immune region and combines it with SVD to extract the most stable first principal component, constructing an asymmetric spatiotemporal filtering method for RF fingerprint feature extraction. This ensures that the purified waveform distortion fully reflects the essential differences in transmitter hardware. Based on this, this application constructs a single-class novelty deception detection model under open-set conditions. Real samples are collected only during the initial stable tracking phase of the satellite by the receiver, and a single-class support vector machine is trained to dynamically fit the security decision boundary under the current environment. This allows for anomaly detection of real-time input unknown signals without any prior deception samples. This application achieves highly robust open-set recognition against unknown deception attacks without requiring additional hardware, signal system modifications, or relying on deception samples, fundamentally overcoming the bottlenecks of high cost, poor compatibility, and weak cross-scenario generalization ability of traditional methods.

[0043] In one embodiment, the code phase observation interval of the high-resolution multiple correlator array covers a chip width of [-1.5, +1.5], with a step size of 0.05 chips; the high-resolution complex correlation peak vector is represented as... ,in This represents the number of correlator taps, with each tap corresponding to a code phase offset. For the first The complex correlation output of each correlator tap.

[0044] Specifically, this parameter selection fully covers the region of correlation peak distortion caused by band-limiting effects (outside the theoretical triangular peak base), and the 0.05-chip resolution is sufficient to capture the microscopic edge distortions of the transmitter filter. Compared to traditional EPL three-point sparse sampling, this setting significantly improves the sensitivity to hardware fingerprints, providing high-fidelity waveform data for subsequent purification.

[0045] In one embodiment, the high-resolution complex correlation peak vectors of multiple consecutive epochs are reconstructed for message polarity, and the reconstructed multi-epoch vectors are accumulated to construct a spatiotemporal observation matrix, including: The polarity of the high-resolution complex correlation peak vector is corrected using the hard-decision symbol function of the in-phase component of the early-delayed branch of the receiver, followed by accumulation of continuous... The corrected vectors of each epoch are used to construct the spatiotemporal observation matrix. ,in The number of epochs, This is the corrected vector.

[0046] Specifically, the above method avoids the nonlinear distortion of incoherent integrals, achieves pure linear coherent accumulation, preserves phase information in the complex domain, and improves the signal-to-noise ratio, enabling weak hardware features to be effectively separated by SVD.

[0047] In one embodiment, singular value decomposition is performed on the spatiotemporal observation matrix to extract the first principal component, and the first principal component is phase-rotated and aligned to obtain a denoised complex waveform after filtering out time-varying channel noise, including: Singular value decomposition of the spatiotemporal observation matrix is ​​performed as follows: ; in, For containing singular values A diagonal matrix with its singular values ​​arranged in descending order. The row space corresponds to the time manifold, and the column space corresponds to the code phase manifold. For the first i A left singular vector For the first i A right singular vector, superscript H Indicates the transpose operation; Extracting the maximum singular value The first principal component consists of the first singular vector and its corresponding right singular vector. The residual carrier drift of its center phase is then rotated and aligned to the in-phase real axis in the complex plane to obtain the noise-reduced complex waveform. ,in, For the instantaneous code phase position Quantity.

[0048] Specifically, after SVD decomposition, only the first principal component is retained and rotated for alignment. The right singular vector corresponding to the largest singular value represents the most stable common feature within the shortest time window (i.e., direct wave and transmitter hardware distortion), while the secondary singular vectors represent time-varying multipath and noise. Orthogonal separation of time-varying channel interference and static hardware features solves the problem of RFF being masked by the channel in the precorrelation domain.

[0049] In one embodiment, an asymmetric weighted spatial window is applied to the denoised complex waveform to suppress static multipath components, resulting in a clean hardware RF fingerprint feature waveform, including: Define the asymmetric weighted spatial window as The reconstructed waveform is then physically truncated, where: ; in, , Indicates the chip cycle, Indicates the relevant peak, for The region is assigned an absolute weight of 1 to preserve the transmitter's RFF characteristics without loss; for The region is gradually attenuated using a smooth decreasing cosine function. The clean hardware RF fingerprint waveform, after channel feature filtering and multipath stripping, is as follows: ; in, This represents a noise-reduced complex waveform. This represents an asymmetric weighted spatial window. Indicates the position of the instant code Quantity, This represents the real part operator.

[0050] Specifically, without introducing spectral leakage, static multipath coupled with the direct wave is effectively suppressed, so that the waveform distortion on the left side is entirely derived from the transmitter hardware, thus enhancing the robustness of the feature under different multipath environments.

[0051] In one embodiment, the physical distortion features across multiple dimensions include morphological variance, which is calculated as follows: ; in, represents the standard deviation of the residual sequence, which characterizes the asymmetry of waveform distortion. The relative amplitude distortion residual vector, For discrete sampling taps, For vectors The One element, is the mean of the residual sequence.

[0052] Specifically, in the calculation of morphological variance, the residual is the difference between the real part amplitude of the true correlation peak and the amplitude of the ideal triangular peak. A larger morphological variance indicates more severe group delay distortion in the transmitter's bandpass filter. This feature is sensitive to the differences between the band-limited filters of real satellites and SDR spoofers, and has good discriminative power.

[0053] In one embodiment, the physical distortion features across multiple dimensions include morphological skewness, which is calculated as follows: ; in, represents the standard deviation of the residual sequence, which characterizes the asymmetry of waveform distortion. For discrete sampling taps, The relative amplitude distortion residual vector The One element, is the mean of the residual sequence.

[0054] Specifically, morphological skewness characterizes the asymmetry of waveform distortion. Since the low-cost power amplifiers of SDR spoofers typically operate in the critical saturation region, they produce significant AM-AM and AM-PM nonlinear compression, leading to a skewed rising edge of the relevant peaks. Therefore, the morphological skewness is significantly higher than that of genuine satellites. This feature is sensitive to power amplifier nonlinearity and is unaffected by multipath propagation (extracted from the left-hand region), making it an effective indicator for distinguishing genuine from spoof signals.

[0055] In one embodiment, the multi-dimensional physical distortion features include the slope asymmetry ratio, which is calculated as follows: ; in, It is a first-order difference operator. This represents the amplitude gradient of the rising edge of the relevant peak. This represents the amplitude gradient at the falling edge.

[0056] Specifically, the slope asymmetry ratio is calculated as the ratio of the gradient along the rising edge to the gradient along the falling edge. The bandpass filter frequency response of a real satellite exhibits a stable asymmetry, while the spectral asymmetry of the general-purpose software radio platform filter in an SDR spoofer differs fundamentally from that of the satellite payload, leading to a systematic shift in the slope asymmetry ratio. This feature is directly extracted from the waveform slope, making calculation simple and its physical meaning clear.

[0057] In one embodiment, the multi-dimensional physical distortion features include in-channel normalized PLL jitter and in-channel normalized DLL jitter, respectively: ; ; in, The standard deviation of the PLL phase detector output within the current epoch window. and These are the mean and standard deviation of the channel during the real signal phase, respectively, used as the benchmark within the channel. This outputs the DLL phase detector within the current epoch window.

[0058] Specifically, this feature introduces discrimination information independent of the relevant peak waveform from the internal tracking loop of the receiver, which is particularly effective against high-fidelity repeater spoofing. When the spoofer pulls the loop, it introduces additional phase / code phase jitter, which leads to a significant increase in the normalized jitter value, making it a key feature for detecting covert spoofing.

[0059] In one embodiment, the single-class support vector machine introduces a radial basis kernel function. By mapping features to a high-dimensional space, dynamic fitting is transformed into solving a convex optimization problem. ; in, Let be the normal vector of the hyperplane in high-dimensional space. Let be the geometric distance from the origin to the hyperplane. For slack variables, penalty factors It is a regularization parameter that controls the ratio of support vectors and the false positive rate of the training set. , Representing different radio frequency fingerprint feature vectors, Indicates the kernel bandwidth parameter; The process of calculating the anomaly score from the real-time RF fingerprint feature vector to the security decision boundary includes: During the spoofing detection phase, for the real-time input RF fingerprint feature vector Define its timing anomaly score The negative value of the distance from the feature point to the safe decision boundary: ; in, To find the Lagrange multipliers for solving convex optimization problems, The radio frequency fingerprint characteristics of real GNSS signals, This represents the total number of samples in the training set.

[0060] Specifically, the model only requires training with real samples, can dynamically adapt to environmental changes, and achieves constant false alarm rate detection through anomaly score thresholds, avoiding the dependence of traditional binary classifiers on deceptive samples, and has a natural generalization ability against unknown types of deceptive attacks.

[0061] In a specific embodiment, the effectiveness of this scheme is verified without requiring prior knowledge of the deception signal. The core of this verification lies in revealing the physical layer differences between a real navigation satellite constellation and a single-source deception device in the principal component manifold space. The specific scheme is as follows: (1) A real space-based constellation consists of multiple heterogeneous satellites with independent high-precision atomic clocks and RF links, and the trace of the covariance matrix in its RFF space. It exhibits a highly discrete macroscopic distribution. Conversely, when a multi-channel SDR spoofer performs a multi-satellite spoofing attack, all fake signals share the same baseband and RF link. This hardware homogeneity eliminates inter-satellite hardware differences, resulting in a more refined feature set. The feature points will overlap and collapse into relatively dense tiny clusters, a phenomenon that provides a physical basis for identifying deceptive signals.

[0062] (2) High-power spoofing quickly deprives the GNSS receiver of tracking loop control, resulting in a waveform exhibiting a more obvious spoofing signal pattern. Concealed matched power spoofing, because the spoofing signal energy is comparable to the real signal, causes significant misalignment and superposition of the true and false correlation peaks within the baseband, leading to asymmetrical waveform skew distortion and local multi-peaks, resulting in abnormal scores. A more significant leap occurs.

[0063] (3) Statistical analysis shows that due to the different physical RF front-ends used to generate them, the extracted features of real and fake signals inevitably differ in their marginal probability densities. A real constellation consists of multiple space-based satellites with independent clocks and heterogeneous RF links, exhibiting a broad Gaussian-like distribution in its feature space; while a cheap SDR spoofer, due to the use of low-quality components, will have its out-of-band ringing attenuation and skewness distortion mean centers significantly deviating from the reference position of the space-based equipment. By comparing the probability density distributions of real and fake constellations using kernel density estimation (KDE), the separability of the RFF can be confirmed from the underlying physical properties.

[0064] To comprehensively evaluate the effectiveness of the RFF-based deception detection architecture proposed in this application, the publicly available GNSS deception dataset TEXBAT was used for experimental verification. The TEXBAT dataset was generated by a high-fidelity commercial GNSS simulator and a high-dynamic software radio (SDR) device. In this embodiment, the following four typical scenarios were selected to construct an experimental comparison group: (1) CleanStatic scenario: a pure and real static signal without interference, which serves as an ideal control group for extracting the baseline RFF features of heterogeneous satellites; (2) Ds2 scenario: a high-power static deception interference scenario, where the deception signal has a significant energy advantage over the real signal and can quickly take over the tracking loop control of the GNSS receiver; (3) Ds3 scenario: a low-power static deception interference scenario, where the power of the deception signal is slightly higher than that of the real signal; (4) Ds7 scenario: a matched power concealment deception scenario, where the energy of the deception signal is almost equal to that of the real signal, and traditional detection algorithms based on AGC or simple energy transitions generally fail in this scenario.

[0065] At the signal processing end, this embodiment configures 61 correlator taps to extract complex correlation peaks at a chip resolution of 0.05. In the spoofing detection model, the upper limit parameter of the support vector error of the single-class support vector machine is set to 0.1, and the dynamic alarm threshold is set to the 99th percentile of the anomaly score of the benchmark training set to ensure a constant false alarm rate.

[0066] To verify the effectiveness of the feature set proposed in this application, a systematic evaluation of the 11-dimensional features was conducted, specifically including two aspects: hardware homogeneity and statistical separability.

[0067] Given the difficulty in obtaining all possible deception samples in real-world scenarios, this embodiment adopts a single-class novelty detection paradigm. That is, the model training phase only trains on known real signals, while the test set consists of real signals and unknown deception signals from various scenarios. To address the insufficient generalization ability of a single classifier under covert deception interference, this paper introduces a stacked ensemble framework. This framework comprises two layers: the first layer uses a One Class-Support Vector Machine (OC-SVM) and an Isolation Forest (IF) as base learners, responsible for capturing boundary features and global anomaly features of the signal distribution, respectively; the second layer introduces Logistic Regression (LR) as a meta-learner, which adaptively adjusts the contribution weights of each model by weighted fusion of the anomaly scores output by the base learners. Experiments compare Mahalanobis distance, ROC curves of statistical measures, the EllipticEnvelope algorithm, the single IF algorithm, and the proposed stacked ensemble framework under three different deception interference scenarios. Figure 2 and Figure 3 As shown, Figure 2 The ROC curves for deception detection under different types of deception interference are shown for the integrated fusion model proposed in this application and other existing models in one embodiment. Figure 2 (a) is the ROC curve of the deception detection of the model in response to high-power deception interference; Figure 2 (b) is the ROC curve of the model in response to low-power spoofing interference. Figure 3 The ROC curve for deception detection in response to matching power deception interference is shown in the model.

[0068] like Figure 4 and Figure 5 As shown, Figure 4 This is a probability density distribution diagram of the first 6 features of the 11-dimensional radio frequency fingerprint feature proposed in this application under different types of spoofing interference in one embodiment; Figure 4 (a) shows the probability density distribution of feature 1 in three deception scenarios; Figure 4(b) Probability density distribution of feature 2 in three deception scenarios. Figure 4 (c) shows the probability density distribution of feature 3 in the three deception scenarios. Figure 4 (d) shows the probability density distribution of feature 4 in the three deception scenarios. Figure 4 (e) is the probability density distribution of feature 5 in the three deception scenarios. Figure 4 (f) is the probability density distribution of feature 6 in three deception scenarios; Figure 5 This is a probability density distribution diagram of the last 5 features of the 11-dimensional radio frequency fingerprint feature proposed in this application under different types of spoofing interference in one embodiment; Figure 5 (a) shows the probability density distribution of feature 7 in three deception scenarios. Figure 5 (b) shows the probability density distribution of feature 8 in the three deception scenarios. Figure 5 (c) shows the probability density distribution of feature 9 in the three deception scenarios. Figure 5 (d) shows the probability density distribution of feature 10 in the three deception scenarios. Figure 5 (e) shows the probability density distribution of feature 11 under three deception scenarios, where the blue line represents the real signal, the red line represents the high-power deception signal, the orange line represents the low-power deception signal, and the purple line represents the matched-power deception signal. Figure 4 and Figure 5 It can be seen that there are distinguishable differences in probability density distribution between the real signal and the spoofed signal for each feature, and the multi-star spoofing exhibits a feature collapse effect due to sharing the same radio frequency front end, which verifies the effectiveness of the feature set proposed in this application.

[0069] The simulation results above demonstrate that the GNSS spoofing detection method based on post-correlation domain RF fingerprinting proposed in this application can effectively remove channel interference, extract physically interpretable hardware distortion features, and achieve highly robust, near real-time detection of unknown spoofing attacks in open set scenarios, without requiring spoofing prior samples, modifying the signal system, or relying on additional hardware.

[0070] It should be understood that, although Figure 1 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated in this application, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Furthermore, Figure 1At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0071] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0072] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A GNSS spoofing detection method based on post-correlation domain radio frequency fingerprinting, characterized in that, The method includes: Using the high-resolution multicorrelator array of the receiver, the GNSS signal of the Global Navigation Satellite System is despread and coherently integrated to obtain the high-resolution complex correlation peak vector of the current epoch; The high-resolution complex correlation peak vectors of multiple consecutive epochs are reconstructed by message polarity, and the reconstructed multi-epoch vectors are accumulated to construct a spatiotemporal observation matrix. Singular value decomposition is performed on the spatiotemporal observation matrix to extract the first principal component, and the first principal component is phase-rotated and aligned to obtain a denoised complex waveform after filtering out time-varying channel noise; an asymmetric weighted spatial window is applied to the denoised complex waveform to suppress static multipath components and obtain a clean hardware RF fingerprint feature waveform. Multiple dimensions of physical distortion features are extracted from the left effective range of the pure hardware RF fingerprint feature waveform to form an RF fingerprint feature vector. During the initial stable tracking phase of a satellite by the receiver, multiple sets of the aforementioned radio frequency fingerprint feature vectors are collected as real samples to train a single-class support vector machine and dynamically fit the security decision boundary under the current environment. For unknown signals input in real time, extract real-time radio frequency fingerprint feature vectors, calculate the anomaly score of the real-time radio frequency fingerprint feature vectors to the security decision boundary, compare the anomaly score with the dynamic alarm threshold, and determine deception interference when the anomaly score exceeds the threshold.

2. The method according to claim 1, characterized in that, The code phase observation interval of the high-resolution multicorrelator array covers a chip width of [-1.5, +1.5], with a step size of 0.05 chips; the high-resolution complex correlation peak vector is represented as... ,in This represents the number of correlator taps, with each tap corresponding to a code phase offset. For the first The complex correlation output of each correlator tap.

3. The method according to claim 1, characterized in that, The high-resolution complex correlation peak vectors of multiple consecutive epochs are reconstructed for message polarity, and the reconstructed multi-epoch vectors are accumulated to construct a spatiotemporal observation matrix, including: The high-resolution complex correlation peak vector is polarity corrected using the hard-decision symbol function of the in-phase component of the early-delayed branch of the receiver, and then accumulated continuously. The corrected vectors of each epoch are used to construct the spatiotemporal observation matrix. ,in The number of epochs, This is the corrected vector.

4. The method according to claim 1, characterized in that, Singular value decomposition is performed on the spatiotemporal observation matrix to extract the first principal component, and the first principal component is phase-rotated and aligned to obtain a denoised complex waveform after filtering out time-varying channel noise, including: The spatiotemporal observation matrix is ​​subjected to singular value decomposition as follows: ; in, For containing singular values A diagonal matrix with its singular values ​​arranged in descending order. The row space corresponds to the time manifold, and the column space corresponds to the code phase manifold. For the first i A left singular vector For the first i A right singular vector, superscript H Indicates the transpose operation; Extracting the maximum singular value The first principal component consists of the first singular vector and its corresponding right singular vector. The residual carrier drift of its center phase is then rotated and aligned to the in-phase real axis in the complex plane to obtain the noise-reduced complex waveform. ,in, For the instantaneous code phase position Quantity.

5. The method according to claim 1, characterized in that, An asymmetric weighted spatial window is applied to the denoised complex waveform to suppress static multipath components, resulting in a clean hardware RF fingerprint feature waveform, including: The asymmetric weighted spatial window is defined as The reconstructed waveform is then physically truncated, where: ; in, , Indicates the chip cycle, Indicates the relevant peak, for The region is assigned an absolute weight of 1 to preserve the transmitter's RFF characteristics without loss; for The region is gradually attenuated using a smooth decreasing cosine function. The clean hardware RF fingerprint waveform, after channel feature filtering and multipath stripping, is as follows: ; in, This represents a noise-reduced complex waveform. This represents an asymmetric weighted spatial window. Indicates the position of the instant code Quantity, This represents the real part operator.

6. The method according to claim 1, characterized in that, The multiple dimensions of physical distortion features include morphological variance, which is calculated as follows: ; in, represents the standard deviation of the residual sequence, which characterizes the asymmetry of waveform distortion. The relative amplitude distortion residual vector, For discrete sampling taps, For vectors The One element, is the mean of the residual sequence.

7. The method according to claim 1, characterized in that, The multiple dimensions of physical distortion features include morphological skewness, and the morphological skewness calculation process is as follows: ; in, represents the standard deviation of the residual sequence, which characterizes the asymmetry of waveform distortion. For discrete sampling taps, The relative amplitude distortion residual vector The One element, is the mean of the residual sequence.

8. The method according to claim 1, characterized in that, The multiple dimensions of physical distortion features include the slope asymmetry ratio, which is calculated as follows: ; in, It is a first-order difference operator. This represents the amplitude gradient of the rising edge of the relevant peak. This represents the amplitude gradient at the falling edge.

9. The method according to claim 1, characterized in that, The multiple dimensions of physical distortion features include in-channel normalized PLL jitter and in-channel normalized DLL jitter, which are as follows: ; ; in, The standard deviation of the PLL phase detector output within the current epoch window. and These are the mean and standard deviation of the channel during the real signal phase, respectively, used as the benchmark within the channel. This outputs the DLL phase detector within the current epoch window.

10. The method according to claim 1, characterized in that, The single-class support vector machine introduces a radial basis kernel function. By mapping features to a high-dimensional space, dynamic fitting is transformed into solving a convex optimization problem. ; in, Let be the normal vector of the hyperplane in high-dimensional space. Let be the geometric distance from the origin to the hyperplane. For slack variables, penalty factors It is a regularization parameter that controls the ratio of support vectors and the false positive rate of the training set. , Representing different radio frequency fingerprint feature vectors, Indicates the kernel bandwidth parameter; The process of calculating the anomaly score from the real-time radio frequency fingerprint feature vector to the security decision boundary includes: During the spoofing detection phase, for the real-time input RF fingerprint feature vector Define its timing anomaly score The negative value of the distance from the feature point to the safe decision boundary: ; in, To find the Lagrange multipliers for solving convex optimization problems, The radio frequency fingerprint characteristics of real GNSS signals, This represents the total number of samples in the training set.