SPACE-TIME KEY ENCRYPTION FOR AUTHENTICATION AND ENCRYPTION OF COMMUNICATION AND INFORMATION SYSTEMS
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-05-17
- Publication Date
- 2026-04-08
AI Technical Summary
Existing data protection methods require complex key exchanges and infrastructure, making them vulnerable to intrusions and difficult to implement without trusted third parties, especially in securing information beyond georeferencing.
A spatio-temporal encryption method using GNSS signals for authentication and encryption, leveraging unique spatio-temporal characteristics to secure information at its source, without requiring additional infrastructure or key sharing, by deriving encryption keys from GNSS measurements.
Provides secure authentication and encryption of information at its source, minimizing infrastructure constraints and ensuring integrity and confidentiality against unauthorized access or alteration, adaptable to varying threat levels.
Description
Summary of the invention
[0001] The invention describes a method of authentication and encryption without third-party authority, called spatio-temporal encryption, applied for the protection of information of interest in order to guarantee the origin and integrity of its content for the purpose of recording or transmission, based on the positioning and precise GNSS timestamping.
[0002] The approach taken is part of a so-called "zero trust" approach, applied to the protection of the confidentiality and integrity of data in information and communication systems, which, based on the observation that firewalls and access protections are never completely impervious to intrusions, recommends favoring multi-factor authentication solutions and information encryption, and monitoring breaches of data integrity.
[0003] The solution according to the invention makes it possible to achieve the protection and authentication of information at its sources, regardless of the generation platform, on the basis of multi-dimensional hidden data linked to the position and date of creation of the document, exploiting intermediate characteristics specific to the processing of GNSS signals and taking advantage of the protection of access to secure signals broadcast by global GNSS systems.
[0004] Such an approach makes it possible, without additional dedicated security infrastructure, to protect the data circulating in the information system, and to assess, anywhere and anytime, and at any level of the system, the associated cybersecurity risk, by controlling the consistency and integrity of the data contained (authentication based on the position and time of the information constituting the master key, encryption of data according to derived dynamic keys, traceability for security control).
[0005] Leveraging the different levels of access protection for GNSS signal services, known as navigation services, the solution offers different robustness and control capabilities whose complexity and security can be adapted according to the level of threats, while minimizing the impact on the performance of the communication network. Scope of the invention
[0006] The field of the invention relates to the authentication and protection of information of interest for recording purposes, understood both in the sense of referencing for archiving, and in the sense of transmission through a communication network or computer servers.
[0007] The term "information of interest" covers all digital information intended to be transmitted, stored or referenced for archiving, whether this information is exchanged on an ad hoc or continuous basis, for example, messages, documents, certified acts, personal data or data intended for time stamping.
[0008] The context of use of the invention relates to data protection, the certification of records of individual or company information, as well as the traceability and control of cryptographic digital fingerprints embedded in the information.
[0009] The implementation framework is that of an environment presenting a cyber risk likely to lead to attacks on the integrity of data (modification of their content), on the identity of their source (modification of the origin of the information) or on the confidentiality of the information (unwanted reading by third parties).
[0010] The types of malicious acts envisaged concern the compromise of information and its source, such as identity, date, place, signature and information of interest, as well as the falsification of this data.
[0011] The invention proposes a solution for protecting information at the source, minimizing constraints on security infrastructure (access control to premises and equipment) and requiring no specific access privileges or dedicated security infrastructure. This solution leverages the unique, unambiguous, and always-available spatiotemporal characteristics of the source at the time the information to be recorded or transmitted is created. Information thus referenced and protected at the source can be exchanged with minimal risk of alteration or interception in insecure infrastructures.
[0012] As such, GNSS constellations can be used as global referencing sources, available continuously and everywhere, in order to characterize an event uniquely according to a set of multiple parameters (called multi-factor) and intrinsically presenting levels of protection and authentication of access to signals, linked to said GNSS navigation services delivered by construction by the signals.
[0013] Furthermore, due to the multiplicity of constellations and frequency bands used, they provide independent signal sources that offer a wide variety of observation conditions, potentially increasing the availability and accuracy of the characteristics used for referencing. Managed and guaranteed by different authorities, they constitute a trusted, legal, and sustainable medium, capable of establishing a secure information solution associated with satellite geolocation.
[0014] Another advantage lies in the widespread use of geolocation equipment, whether in consumer applications, professional applications, critical infrastructure, or for security and defense. Technical problem
[0015] The technical problem is to use characteristics of GNSS signals, unique in time and space, to authenticate and protect information of interest to be referenced.
[0016] The basic principle consists of inextricably linking the information of interest contained with a unique spatio-temporal event whose characteristics can be recognized and identified.
[0017] The approach consists of tightly encapsulating the data of interest, exchanged in the information system, with the precise and secure date and location of their creation, the geolocation information being used to uniquely identify an event.
[0018] It is easy to reference a document for archiving (photograph, measurements, document, certified acts, ...) using position and time information provided by a GNSS receiver and equipment ensuring capture (camera, tachograph, ...) and to store it on a Cloud, for example for timestamping purposes.
[0019] However, if the digital file containing this information, referred to as the container hereafter, is not secure, it can be easy for third parties to access the information of interest, or even to appropriate it by changing the identifying information of the author or the date and place, or even to falsify the information contained.
[0020] Therefore, it is necessary that the solution implemented ensures: Secure identification for container creation; authentication of the source by the recipient; integrity of the data of interest against falsification by third parties; confidentiality of the data of interest against disclosure by third parties
[0021] A simple capture of GNSS position and time outputs cannot provide such protection capabilities without involving the use of one-way functions to perform encryption and strong constraints on the management and verification of public-private keys and electronic signatures via a private key infrastructure (PKI) to perform symmetric or asymmetric encryption and double-check authentication with public and private keys.
[0022] The object of the invention is to provide such capabilities without having to put in place such security infrastructures, nor asymmetric cryptography algorithm, by relying solely on the information characterizing the GNSS satellite signals which constitute unique and specific attributes of the message sender, accessible to recipients possessing the same privileges of access to the signals.
[0023] A device that provides proof that the position and date are not corrupted can prevent people from falsifying information (the photograph) with malicious intent. Prior art
[0024] The techniques developed in communication to protect and authenticate information exchanged between provider and recipient of confidential data classically implement methods of encryption with symmetric or asymmetric public-private keys, involving external infrastructures to ensure the management of multi-user keys and authorities guaranteeing the protection of secrecy.
[0025] Authentication and encryption / decryption processes involve exchanges of keys and signatures which can be observed, although intrusions remain rare and are the domain of experts, as encryption algorithms become increasingly efficient.
[0026] However, key generation remains complex and requires significant computing resources, whether remote or not, as well as increasing cybersecurity constraints to ensure access protection.
[0027] The new recommendations for deploying so-called "Zero Trust" cybersecurity infrastructures described in the publication NIST.SP.800-207 tend to revisit traditional approaches to standard cybersecurity based on protecting access to infrastructures.
[0028] The Zero Trust approach aims to deploy security solutions within a "software-defined perimeter" that provides privileged access to human and non-human users, regardless of their geographic location, the terminal used, and the location where data and workloads are hosted.
[0029] Patent [D1] US 2015 / 365824 A1 (Gustafson Bo [US]; "Satellite based key agreement for authentication", publication date December 17, 2015 (2015-12-17)) describes an algorithm for exchanging keys between satellites and ground stations using information shared by two partners (e.g., distance or Doppler). It performs a "key agreement" based on keys reconstructed by calculation after the exchange of position and velocity information between the platforms, and not a "key transport" that would not depend on physical quantities shared in plain text, possibly observable or measurable by third parties.
[0030] Simultaneously with the development of GNSS-based services, new threats have emerged, linked to the deliberate dissemination of false identification information, by corrupting the outputs of GNSS receivers, for example relating to the position and time of a vehicle, or relating to the risk of spoofing the received GNSS signals which can lead to false estimates by the user receiver of the position and time, difficult for users to detect.
[0031] A recently developed approach to monitoring and controlling such situations involves transferring the Radio Frequency (RF) GNSS signal received by the user to a remote processing station or server, in order to process the signals of regulated or defense GNSS navigation services, available for reception in parallel with open navigation signals.
[0032] Access to these navigation services is regulated and the signal codes are highly protected, making it extremely difficult for an unauthorized third party to access and falsify them.
[0033] An authorized authority can therefore use this method to verify whether the position and time information disseminated by users is falsified and whether the received signals are spoofed, thus achieving authentication of the identification.
[0034] Such a principle is described by patent [D2] EP 2 674 779 (Marc Revol & Al; "Remote Architecture Satellite Radionavigation System", filing date: 13.06.2013)
[0035] This same principle is described in patent [D3] US 2014 / 368380 A1 (Revol Marc & Al; "Satellite radio navigation system with remote architecture", publication date December 18, 2014 (2014-12-18)). However, a drawback of this approach lies in the impact on the communication rate of the transmission of broadband GNSS signals.
[0036] Patent [D4] EP 2 790 035 (Marc Revol; "Method and device for compressing a broadband radio navigation signal, associated method and device for calculating the correlation function of the spreading code of said compressed signal", filing date: 07.03.2014) proposes an approach to compressing GNSS signals, also called Compressive Sensing in English, which reduces the bandwidth used for the transmission of GNSS signals while maintaining their time transfer and positioning capabilities.
[0037] On the same subject, the following publications relate to the processing and monitoring capabilities of remote GNSS signals: [D5] (Alexander Rugamer, Manuel Stahl, Ivana Lukcin, Gunter Rohmer - Fraunhofer IIS Nuremberg, Germany, “Privacy Protected Localization and Authentication of Georeferenced Measurements using Galileo PRS”, published in the Proceedings of IEEE / ION PLANS 2014 May 5 - 8, 2014 ) describes how ordinary Galileo users can benefit from privacy-protected location and authentication of georeferenced measurements using the Galileo Regulated Public Signal (PRS) service. [D6] (Marc Revol - Thales Avionics, "Distant positioning for GNSS securing", published in the Proceedings of ENC 2015 - session 08 - April 8-10, 2015) )describes the means enabling the use of encrypted GPS or Galileo signals (which are inherently more resistant to interference than civilian signals) for secure and robust positioning with strong integration constraints (police, military and government radio).
[0038] [D7] ( Marc Revol - Thales Avionics, "Compressing a wide band radio-navigation signal and method for calculating the correlation function for remote positioning" Navitech 2016 - Proceeding ISBN: 978-1-5090-3885-5 / P02- 14-16 December 2016 - ESA / ESTEC, The Nether-lands ) introduces a method for compressing GNSS signals, exploiting the CDMA (time and space) orthogonality of GNSS signals, facilitating the deployment of remote GNSS authentication services. Limitations
[0039] As previously mentioned, traditional protection methods require key exchanges and complex calculation algorithms, which are vulnerable to observation and disclosure of the secret, and involve the intervention of trusted third parties. These vulnerabilities, partly dependent on the security infrastructure's access protection capabilities, must be assessed in light of the security risks that may depend on the nature or context of the applications or services.
[0040] The "Zero Trust" approach, which advocates for decentralized security at the source of information, appears synergistic with the capabilities of GNSS systems to meet these objectives.
[0041] However, the first work carried out in this direction in the GNSS world is limited to securing only information related to georeferencing, without considering generalizing its use for securing all types of data, at all levels and according to levels of protection adapted to the security risks.
[0042] The concept of Remote Positioning in particular is considered as a way to increase the geolocation capabilities of users of open GNSS navigation services, who are more sensitive to disturbances in the receiving environment, and remains focused on the ability to calculate a position and time in a secure physical environment, enabling the implementation of procedures for accessing encrypted GNSS navigation service signals, which standard users do not have access to. Solutions to the problem
[0043] The proposed approach to securing information of interest aims to partially satisfy the recommendations of NIST SP 800-207 related to the new principles of cybersecurity implementation, in that the information is secured at the source and can be received and verified with varying levels of confidence, depending on the recipient's processing capabilities and authorization to handle trusted information.
[0044] Furthermore, it can be deployed anywhere and at any time, without trusted third parties and without dedicated security infrastructure for generating secret keys or encryption algorithms, without requiring additional specific protections for the equipment implementing them.
[0045] It is based on a principle of subsidiarity that empowers authorized users of GNSS systems implementing the principle of the invention to secure the information of interest themselves, relying on the signal access regulations established by the GNSS systems. This delegation is made possible by linking the information of interest to be secured with georeferencing and time-stamping characteristics accessible through the widely deployed GNSS systems, which also possess protected infrastructures and the inherent capacity to deliver position and time information with varying levels of security.
[0046] The ability to establish such a link and to leverage it to inherit the security capabilities offered by GNSS systems for the benefit of information or data security is at the heart of the present invention.
[0047] The value of the proposed cybersecurity solution lies primarily in the high availability and sustainability of existing GNSS systems and their future developments, which essentially contribute to maintaining and improving the robustness of precise positioning and time transfer, and to mitigating their vulnerability to cyberattacks such as spoofing and jamming.
[0048] It aims to satisfy two main security objectives: Protect sensitive data at its source before it is exchanged, preventing any intentional or unintentional alteration or disclosure of its content. Verify, at every level, the origin of the information and ensure that it has not been created or modified by third parties.
[0049] The objective of the solution is to provide such protections for communication and information storage without increasing security infrastructure and constraints beyond those already implemented for the deployment of GNSS navigation services, and to provide adaptable security protection corresponding to the threat level of the operation.
[0050] Another objective is to avoid increasing the complexity of the processing beyond what is already necessary to access the GNSS navigation services already used in information systems.
[0051] The solution consists of securing the information of interest to be recorded or transmitted via a data encryption and authentication process based on a symmetric cryptography mechanism, but capable of working without the obligation to share secret keys to perform the encryption and decryption of the document.
[0052] Based on the observation that there is only one coincidence of date and physical location associated with a given event, such a capability is obtained by deriving the secret encryption keys from the measurements of the date and position of the event, constituting the master key, characteristics of the instant and physical location of creation of the encrypted and authenticable container.
[0053] To achieve an unbreakable virtual encapsulation of the information of interest with the source identification, encryption is performed using spatiotemporal characteristics common to both authentication and encryption of the container, linked to the date and location of the event. These spatiotemporal characteristics of the event are the basis for generating both the authentication characteristics and the encryption keys.
[0054] To this end, encryption keys are calculated based on the code phases of the GNSS signals received for that date and position, and for user privileges of access to GNSS signals defined by the constellation, the navigation service, the frequencies, the type of spreading codes.
[0055] The code phases of the received signals, aligned to the GNSS system time base and dependent on the propagation delay between the satellites and the receiving antenna, provide a unique combination of phase measurements used as roots of encryption and authentication in the creation of the encrypted data container.
[0056] The moment and the physical place thus play the role of the seed of encryption, or even of the master key, which makes it possible to develop the secret encryption keys and to constitute the authentication characteristics.
[0057] At the creation of the container, subsequently likened to the creation of the encrypted document or the creation of the encrypted message, the position and time of the event are determined by receiving the GNSS signal delivered by an antenna whose location serves as a recognized reference to help authenticate the origin of the certified act (for example, a notary's office, an administration, or any reference authority).
[0058] In the general use case, it is not necessary for the antenna position to be referenced; any user wishing to create their own encrypted document can use their own GNSS georeferencing method regardless of the position and date of the event.
[0059] The GNSS system therefore plays an important role in transforming the moment and the physical place, immaterial notions but support of the secret key, into tangible measurable characteristics which are used to estimate time and position and, through this means, to develop encryption keys.
[0060] Upon reading the protected container, reconstructing the encryption keys therefore requires access to the time and position of creation of the encrypted message.
[0061] A third-party observer will not be able to reconstruct the encryption keys if they do not have the location and date information corresponding to the creation of the encrypted document, nor the access privileges to the GNSS navigation service used to perform the encryption.
[0062] The invention makes different modes of transmission possible: Providing the time and position of the encrypted document in plain text, with the generation of encryption codes requiring in this case the generation of additional random variables (such as encrypted PRN codes associated with certain navigation services) making it impossible for a third party to acquire the noisy code phases, the roots of the algorithm for generating the codes associated with the position and date being known only to authorized users, Providing the encrypted time and position in the same container or via a separate secure medium, Sending a fingerprint of the signal received at the time of the creation of the encrypted document, consisting of a limited time slice of the received signal, which allows the recipient to make their own estimation of the position and time of creation of the encrypted document and to reconstruct the encryption keys based on the code phases.
[0063] The invention describes different implementation options for transmitting secret keys that can be adopted depending on the field of application or the desired level of protection against cyber threats.
[0064] The encryption of the data to be protected relies on known and available pseudo-random codes which are used to identify GNSS satellites and to estimate the GNSS time received from the signals (also called the code phase) in the GNSS timescale, at the precise moment of reception corresponding to the date of creation of the message.
[0065] The encryption method consists of the following steps when creating the encrypted message: to use the measured code phases of the satellite signals received at the place and time of the creation of the information, as a key to encrypt the data of interest in order to protect against any access by unauthorized third parties, to generate a signature, called the GNSS fingerprint, consistent with the measured code phases, which will allow, when read, the authentication of the position and time of the creation of the message and the reconstruction of the encryption keys.
[0066] Each code phase, measured by the GNSS receiver, also generates a delay, proportional to the number of code chips (hereafter referred to as code fragments), applied to the pseudo-random sequence combined with the data sequence. This delay is equivalent to a key serving as the root for generating the PRN code sequence, which itself may be access-protected or not, but is always available and tamper-proof without precise knowledge of the position and date of the corresponding event.
[0067] The codes used, which differ from one satellite to another, are applied in time slices according to a deterministic or coded sequence which can itself be used to increase the complexity of the encryption.
[0068] Third parties who lack knowledge of the codes used, or of the delay in aligning the code chip sequence with the encrypted data, will find it extremely difficult to successfully perform the reverse decryption operation. This operation involves searching, through a sliding exploration of the uncertainty domain in time and space, for the delay that maximizes the correlation between the ciphertext sequence and the encryption code. A characteristic of pseudo-random (PRN) codes is that the correlation result remains zero as long as the code phases are not aligned. Decryption requires acquiring or knowing the code phases with less than 1 µs of uncertainty for most open-access codes, and even less than 0.1 µs in the case of restricted-access signals.
[0069] The GNSS fingerprint, which can be used to transmit position and time information to the recipient and also to authenticate the origin of the container, contains a time slice of the received signal collected at the time and place of message creation (including by default the signals from all constellations, for all navigation services and all satellites) which is consistent with the measured code phases, used at the creation of the message to encrypt the data of interest and to calculate the position and time of message creation.
[0070] Such a fingerprint contains the actual signals as received, with a low signal-to-noise ratio, before any demodulation of the code phase and navigation message, and before any decryption of the signal code and data when available for a given signal service.
[0071] The authentication process for the origin of the encrypted document, carried out at the recipient's level, consists of acquiring the code phases from the satellites using the GNSS signal slice transmitted by the fingerprint, then verifying the consistency with the transmitted position and time measurements encapsulated in the message, and when they are consistent, decrypting the encrypted data of interest based on these code phases.
[0072] One possible way of implementing the process is to perform locally, over a limited delay range, the correlation between the recorded slice of the GNSS signal contained in the footprint with slices of local code, initialized with code phases calculated as a function of the Time and Position of identification transmitted by the container, and knowledge of the ephemerides of the satellites.
[0073] If the maximum correlation level is sufficiently high, the recorded signal corresponds to the time and position provided; otherwise, the recorded GNSS signal is not consistent with the time and position provided in the container identifier, meaning the fingerprint has been falsified.
[0074] In specific implementation modes to ensure the protection of the identifier contained in the container (i.e., the position and time information of the identifier), the GNSS code phases can be intentionally noisy, by a random sequence of adjustable standard deviation in order to noise the GNSS position and time identification information transmitted in the container, in order to make it difficult for a third party who had access, by reading the container, to the position and time of creation of the encrypted document, or who would intercept this information in the event that it was disseminated in plain text, for non-critical information of interest, to acquire the delay from the fingerprint.
[0075] This phase noise can be generated by a noise generator, which can be publicly available. The initial noise depends on the GNSS time of creation of the encrypted document, given in GNSS time quantified in round epochs on the order of 10 to 100 ms. Such a generator is then shared by all users authorized to use the data protection system for recording or transmission. The adjustable standard deviation of the randomness allows for fine-tuning the spatial and temporal search domain, and therefore the computational complexity required to acquire the encrypted data without knowledge of the randomness.
[0076] In such a context of high cyber threat, involving a suspicion of container breach and GNSS signal spoofing, authentication certification by an accredited external authority is conceivable within the framework of protecting sensitive security infrastructures, by performing fingerprinting based on regulated access GNSS signals, such as Galileo's PRS navigation service.
[0077] In the case of an implementation of the authentication process on open signals, although the received signals present in the hash have the same root code phases as those of the signals received and continued at the creation of the message, they are much more difficult to acquire without prior information, even approximate, on the position and time of the creation of the encrypted document, due to the limited duration of the hash, which implies the implementation of substantial processing means, known as brute force, to carry out the exploration of the reception phases in ranges of significant delays.
[0078] In such an approach, it is therefore the complexity of the processing of the acquisition of the encryption roots that acts as protection, and requires a battery of massively parallel correlators to perform an almost instantaneous acquisition, called a snapshot in English, of the signal sequence of the fingerprint.
[0079] Implementing brute-force processing to perform said snapshot acquisition and key extraction from the fingerprint, while more secure and functionally simple in design, is not the only possible approach.
[0080] One way to reduce snapshot acquisition complexity is to provide in parallel the position and date estimates obtained by a GNSS receiver at message creation, in order to help acquire root phase measurements made from the footprint.
[0081] Three data encryption options, for combined or separate applications, are possible at this level: The GNSS position and date at the time of container creation are provided in plain text and without noise, but the data encryption performed using the unnoiseeded code phases relies on a protected encrypted GNSS PRN code, whose access keys are shared by all authorized GNSS users. The use of encrypted GNSS codes, such as the Commercial Navigation (CS) or Public Regulated Signal (PRS) services of the Galileo constellation, addresses this need without requiring the use of keys other than those already available for receiving GNSS signals to generate the encrypted code sequences. The GNSS position and date at the time of container creation are provided in plain text, but encrypted, thus protecting access by third parties. Unlike the first option, this requires a specific encryption infrastructure using symmetric or asymmetric keys.However, the codes used for data encryption and decryption can remain freely accessible, for example, the Open Signal (OS) service of the Galileo constellation. Protection is ensured simply by the decorrelation of the codes when they are not synchronized to the same phase. The GNSS position and time at the time of container creation are provided with noise generated using a pseudo-random algorithm whose initial seed is based on the GNSS time of the message creation moment. In parallel, the measured GNSS code phases, used to offset the codes used for data encryption, are themselves affected by biases (called offsets) that are functions of the difference between the noisy and unnoised positions at creation.This requires the recipient either to be able to calculate, in order to correct them, the noise variations added to the position and time at the time the message was created, or to have sufficient processing resources to perform, from the GNSS position and date, or the transmitted fingerprint of the signal, the exploration of the uncertainty domain of the decryption code phases.
[0082] For all three options, the provided position and time information is used to perform position and time authentication based on the fingerprint, and to narrow the search area of the code phases. The ephemerides, which allow the calculation of satellite positions, and the error models, which correct for atmospheric propagation delays and satellite clocks, are known and accessible to users of the GNSS constellation.
[0083] In the case of the third option, the generation of randomness, applied to the position measured at the date of creation of the container, is controlled in amplitude such that the standard deviation of the resulting position error causes a computational load sufficient to discourage intrusion attempts by snapshot acquisition of the fingerprint by unauthorized third parties while remaining admissible for authorized recipients, but who would not have the noise algorithm.
[0084] In order to prevent access to the encryption of the data by the code phases by a third party who would have implemented means of acquiring the code phases by brute force from the observation of the authentication fingerprint, the amplitudes of said code phase offsets added to the code phases estimated at the creation of the container are calculated by applying a random proportion factor to the code phase differences between the estimated non-noisy position, and the transmitted noisy position, the same noise generator being used to generate the position randomness and the proportion factor.
[0085] In the case of authorized users with the random number generation algorithm, they must also know the value of the standard deviation of the added error, which must remain secret, and initialize the generation algorithm with the transmitted noisy time information converted into round epochs of one millisecond, the noise added to the time not exceeding 1ms.
[0086] It is also possible to implement an approach without specific protection for transmitting position and date, or for encrypting encryption codes. In this case, a third-party observer of the container can reconstruct the spatiotemporal encryption keys, provided they have the model for calculating these keys from the code phases, as well as the ephemerides and error correction models applied.
[0087] This lack of understanding of the processes and models may prove sufficient in the case of consumer applications that do not initially require cyber protection.
[0088] An alternative solution allowing the use of publicly accessible codes, instead of regulated access codes, when the GNSS position and date at the creation of the container are provided in plain text, consists of performing a periodic or random interleaving, called interleaving, of sequences of different open PRN codes used for data encryption, for example by pseudo-randomly selecting the codes of the satellites, possibly taken from several constellations, several frequencies, according to sequences to be kept secret, known only to the users of the symmetric encryption service.
[0089] These different authentication and encryption options based on spatio-temporal keys are detailed through the explanations associated with the figures illustrating the processing principles envisaged by the invention as well as the particular embodiments and implementations related to the synchronization of the processing with the GNSS signal data. Benefits provided
[0090] This innovation provides new capabilities for verifying and certifying the authenticity of the origin and content of documents or reports by offering a means to demonstrate, where applicable, the authenticity of their location and creation date. It also serves as a means of authenticating any equipment that transmits an identification message including its identity and dated location.
[0091] It allows information to be protected at the source, minimizing constraints on security infrastructure (regulation of access to premises and equipment) and not requiring specific access privileges or dedicated security infrastructure.
[0092] The proposed solution offers significant advantages over standard encryption processes based on symmetric or asymmetric keys, which require centralized and / or secure cryptographic management, in particular: There is no need for external key management infrastructure, secure communication, or a cryptographic authority other than that of the GNSS. Cyber protection relies primarily on the difficulty for a malicious third party to access key phases of the encryption code without precise knowledge of the message's position and creation date and / or without possessing the keys to generate the codes for the signals protected by the GNSS system. Secure encapsulation of the encrypted message container is unnecessary due to the robust authentication and source-side encryption offered by the solution. Its implementation requires no additional accreditation beyond that necessary for the user to access GNSS navigation services, and the processing technology is based on mature and proven GNSS technology. It is available anytime, anywhere, and also allows for the authentication of messages recorded in the past..
[0093] A variety of independent GNSS constellations can be considered as global referencing sources, available continuously and everywhere, each allowing an event to be characterized uniquely according to a set of multiple parameters.
[0094] Different levels of authentication and security control, using the protection levels and access privileges to signals available by construction, can be implemented.
[0095] The same GNSS fingerprint can be used to certify information according to the perspective of different constellations. Brief description of the figures
[0096] The invention will be better understood upon reading the description of several embodiments that follows, given solely by way of example and with reference to the drawings in which: [ Fig.1] presents the most general implementation of the spatio-temporal encryption process based on GNSS precise positioning and dating, [ Fig. 2 ] presents the general principle of generating, in writing, spatio-temporal encryption keys based on the characteristics of the received GNSS signal, [ Fig.3 ] presents the general principle of write encryption of data of interest based on the characteristics of the received GNSS signal, [ Fig. 4 ] presents the principle of noiseing in writing the GNSS position and time at the time of message creation, [ Fig. 5 ] presents the general principle of reconstructing, during reading, the spatio-temporal encryption keys based on the GNSS fingerprint captured at the creation of the message, [ Fig. 6 ] presents the general operating principle of spatio-temporal encryption / decryption based on the joint capture of GNSS position and time and a fingerprint of the GNSS signal, [ Fig. 7] illustrates the synchronism of GNSS signals in transmission and reception in the case of periodic codes, as well as the GNSS fingerprint capture range at time t 0 of creation of the encrypted message, [ Fig. 8 ] presents the data encryption timing diagram by the code chips of the selected satellite, offset from the code phase received at t 0 , [ Fig. 9 ] presents the encryption of data in successive chunks, by the code chips of the satellite allocated to each chunk, offset at the beginning of each chunk by the code phase of the corresponding satellite received at t 0 , [ Fig. 10 ] illustrates the principle of identifying the source of useful information, which consists of adding an identifier to the information of interest, made up of the source reference, the precise GNSS position and date of creation of the encrypted message, [ Fig. 11] illustrates the principle of generating spatio-temporal encryption keys from GNSS georeferencing, by capturing the code phases of the GNSS signals being tracked at the time the encrypted message was created, [ Fig. 12 ] describes a first method of implementing the encryption of utility information from spatio-temporal keys for the purpose of transmitting encrypted data as soon as the container is created, achieved by combining binary-encoded data of interest and delayed PBSK codes according to the code phases captured at the time of creation of the encrypted message, [ Fig. 13 ] describes a second method of implementing encryption of utility information from generated spatio-temporal keys, for recording purposes, carried out without timing constraints, [ Fig. 14 ] illustrates the principle of GNSS fingerprint capture performed after analog-to-digital conversion of the received GNSS signal, [ Fig. 15] describes an implementation of multi-factor authentication of GNSS position and time from extracted spatiotemporal keys, comparing the GNSS position and time at the time of creation transmitted in the container, and the position and time estimated from the GNSS fingerprint, [ Fig. 16 ] describes an implementation of snapshot acquisition of code phases from the GNSS fingerprint, aided by the GNSS position and time transmitted in the container, in the case of a GNSS signal modulated with navigation data involving alignment of the coherent integration of the correlation on the data transitions of the GNSS message, [ Fig. 17 ] describes a method for decrypting useful information from spatiotemporal keys, obtained by extracting code phases from signals derived from the GNSS fingerprint, [ Fig. 18] describes the principle of cyber risk assessment based on the success of authentication and decryption operations according to the nature of the GNSS signals used, [ Fig. 19 ] describes a preferred but not limiting implementation of the system used for identification and encryption by spatiotemporal write encryption, implementing a GNSS positioning receiver and associated computing means to perform the encryption processing, [ Fig. 20 ] describes a preferred but not limiting implementation of the system used for authentication and decryption by spatio-temporal encryption in reading, implementing a GNSS receiver and associated computing means to perform the decryption processing. Technical solution
[0097] The technical solution adopted by the invention incorporates, while streamlining them, the previous approaches considered earlier in the exploration of solutions to the problem.
[0098] In view of the different options presented, and with the aim of ensuring the best compromise between robust security and implementation complexity, the technical solution adopted by the invention focuses on achieving the following capabilities: The exchange of keys necessary for authentication and encryption is based on the sharing of a hash between the sender and the recipient. The recipient acquires the encryption keys from the hash using the secret position and time information associated with it, which is transmitted in noisy form by the sender to the recipient. Authentication is performed by calculating the position and time difference from the phase differences of the received satellite signals, measured on the GNSS signal received at the time the message was created and the date extracted from the hash by the recipient. In a first embodiment, the PRN codes used to encrypt the data of interest are those of public GNSS signals. The phase changes of the received GNSS satellite signals constitute the primary encryption keys for the data of interest, applied according to a deterministic or random sequence.The identification information, consisting of the date and position of creation of the encrypted document, is not provided in plain text, but quantized (for the date) and noisy (for the position) according to a noise generation seed given by the quantified creation time (corresponding to a rounded GNSS date),
[0099] The solution addresses both aspects of authentication and encryption of the data of interest: At the source, the encoding of authentication characteristics linked to the received GNSS signal and the PRN code phase of the satellites, and the encryption of the data of interest; at the destination, the authentication of the origin of the message and the decoding of the encrypted data, which are based on the consistency of the phases of the PRN codes extracted from the fingerprint of the received signal, verified with regard to the position and time information associated with the message.
[0100] The general operating principle consists of implementing the following functions: i. At the message generation level: The data of interest to be transmitted or stored in the container is available as unprotected input. The position and time of message creation are calculated by a GNSS receiver based on the selected GNSS signal service(s). The GNSS receiver also provides: ▪ the corresponding code phases of the satellite signals, as extracted at message creation, ▪ a short time slice of the received GNSS signal (called a snapshot), collected at the time and position of message generation, at the RF level. The data of interest is then encrypted by modulation using PRN code sequences, linked to the received visible satellite signals, in cyclically or randomly generated slices, aligned with the measured code phase, at initialization, of the associated satellite signal.The message is then formatted by encapsulating the following information in a single sequence: ▪ The identification (ID) of the generating device or source, ▪ The position of the antenna linked to the device and the precise time the message was generated, ▪ The snapshot slice of the received signal (fingerprint), ▪ The encrypted data of interest. ii. At the message user level: Information is extracted from the message (ID, P(V), T, snapshot, data). Satellite signal acquisition is performed by correlation with local PRN codes using the signal slice, initialized by the position and time provided in the message, and the known ephemerides of the satellites: ▪ If the correlation level is sufficiently high and the signature corresponds to the provided position and time, the acquisition is successful, the message is authenticated, and the data of interest can be decrypted. ▪ If this is not the case,The position and time indicated in the message do not correspond to the signal available when the message was generated. Since the signature, or the position and time, may have been falsified, the message is not authenticated. The data of interest is then demodulated using locally generated PRN codes aligned with the satellite code phases obtained by fingerprinting. Different levels of authentication control can be performed based on the same GNSS fingerprint slice, depending on the access privileges to the GNSS signals used to search for the embedded proof of the authenticity of the transmitted time and position. For example, the Galileo and GPS constellations provide different signal services—OS, C / A, CS, PRS, and PPS—which can be used within the scope of the invention. The Galileo CS service can be accessed for commercial authentication, while the Galileo PRS navigation service,With restricted access, it is only accessible to accredited users.
[0101] Within the framework of this general operating principle, the technical solution according to the invention relates to an authentication and encryption process, known as spatio-temporal encryption, not requiring a third-party authority, applied to protect information of interest in order to guarantee the origin and integrity of its content for the purpose of recording or transmission, based on precise positioning and time-stamping using GNSS signals, consisting of: to stamp the container of the information of interest with the source reference and the position and date of its creation, to protect access to the information of interest by encryption linked to the position and date of creation, to anonymize the transmitted position and date of creation in such a way as to render this information unusable by third parties, the authentication factors and encryption keys of said process being uniquely defined from the code phases of the GNSS signals received at the time and place of creation of the encrypted message.
[0102] Depending on specific embodiments, the spatio-temporal encryption process includes one or more of the following characteristics, taken individually or in combination: Encryption of the information of interest by combining the initial binary-encoded data [1, 0] with at least one of the pseudo-random codes of GNSS signals, known as PRN codes (Pseudo-Random Noise), received at time t 0 of the creation of the encrypted message, for the chosen constellation and navigation service. This combination consists of multiplying, bit by bit, the initial sequence of data of interest by the PRN code's chip sequence, which may be periodic or aperiodic, depending on the type of navigation service implemented in the process. The bit-by-bit multiplication is performed after conversion of the binary data into coded data [+1, -1], a code denoted #BPSK hereafter. Authentication of the origin of the encrypted message is carried out using the transmitted noisy GNSS position and date, as well as a GNSS fingerprint representing the characteristics of the GNSS signal received at the time of creation and added to the container.said GNSS fingerprint consisting of a slice of the digitized GNSS signal output from the GNSS RF receiving stage, filtered into a GNSS signal reception band compatible at a minimum with the frequency spreading of the navigation service code implemented, extraction of code phases at the date of creation of the encrypted message, estimated from the transmitted GNSS fingerprint, consisting of an instantaneous acquisition of the codes of the satellites visible on the sole length of the fingerprint, aided by the noisy GNSS position and date transmitted in the container, decryption of the data of interest encrypted by the local codes aligned with the code phase of the signals received at the time of creation of the encrypted message, adjustment of the authentication security level by selection of the constellation and the GNSS navigation service, robust to the anticipated spoofing of the signals,said authentication security adjustment process consisting of extracting code phases from the GNSS fingerprint using, for accredited users or authorities, an encrypted GNSS navigation service a priori inaccessible to the perceived threat, validation of data of interest after decryption, and assessment of the cyber attack risk,
[0103] The invention also relates to a device comprising a GNSS signal receiver, a computer and computer programs, implementing methods for encrypting and decrypting information of interest for the purpose of recording or transmitting it according to the invention, characterized in that it comprises: i) a GNSS receiving antenna, ii) a single or multi-constellation GNSS receiver capable of processing one or more navigation services in parallel and of taking a slice of RF signal, called a snapshot, upon receipt of an external command, and of providing the code phases of the satellites visible at that moment, iii) for the creation of the protected container, a processing module and software interfaced with the GNSS receiver, configured in encryption, capable of performing the container identification processes and the encryption of the information of interest to be recorded or transmitted, iv) for reading the protected container, a processing module and software, configured in decryption, capable of performing the container authentication processes and the decryption of the recorded or transmitted information of interest.
[0104] Another object of the present invention is an additional authentication service for the information of interest, deliverable by an accredited third-party authority capable of certifying the origin and content of the data of interest with at least one additional level of security compared to that provided by the nominal device. Detailed description
[0105] The invention is described in detail in the following paragraphs, alongside the various explanatory figures which specify: the most general embodiment of the process, [ Fig.1 ], the principle of key generation and data writing encryption, [ Fig. 2 ] , [ Fig.3 ], [ Fig. 4 ], the general principle of data reading and decryption, [ Fig. 5 ], the general operating principle of encryption / decryption based on the provision of the GNSS fingerprint, [ Fig. 6], the synchronization schedules for fingerprinting and data encryption, [ Fig. 7 ], [ Fig. 8 ], [ Fig. 9 ], the detailed processing corresponding to the different stages of the write encryption process, [ Fig. 10] to [Fig. 14] ], the detailed processing corresponding to the different stages of the read encryption process, [ Fig. 15] to [Fig. 17] ], the principle outline for cyber risk assessment, [ Fig. 18 ], the embodiments of the encryption and decryption system implementing the process [ Fig. 19 ] And [ Fig. 20 ],
[0106] [ Fig.1 ] presents the most general embodiment of the robust and resilient authentication process by spatio-temporal encryption based on GNSS signals for communication and information systems.
[0107] The method according to the invention comprises a set (102) of steps, configured to implement an encryption-decryption strategy not requiring a security infrastructure external to the system, defined on the basis of hidden data related to position and creation date, derived from instantaneous intermediate characteristics measured on GNSS signals, and taking advantage of access protection to signals broadcast by global GNSS systems for referencing the useful information source.
[0108] The set (104) of steps of the robust and resilient authentication process by spatio-temporal encryption based on GNSS signals includes, in a first step (106), in writing, an initialization phase, followed by a phase of encryption of the information and multi-factor characterization of the source which rely on the spatial and temporal synchronization of the received GNSS signals, according to steps (108), (110), (112), then a phase of multi-factor authentication of the source and decryption of the information according to steps (116), (118), implementing in particular, in step (114), a spatio-temporal key extraction process carried out from a fingerprint taken from the GNSS signal and finally a phase of cyber risk assessment in case of failure of the decryption in step (120).
[0109] The first initialization step (106), generic for all implementation modes, consists, at the time of transmission, of associating with the reference of the source of the encrypted information (defined as the identity of the natural person or the reference of the equipment), the date and place of creation of the encrypted message provided by a GNSS receiver connected to an antenna serving as a reference.
[0110] This information is used to transport the keys necessary for authentication and decryption of the encrypted message by the recipient.
[0111] To ensure the confidentiality of this data, the precise position and time measurements delivered by the GNSS receiver are noisy via the use of a random number generator, for example initialized with the unnoised GNSS time of creation of the encrypted message (called, seed of the random number generator), so as to allow access to authentication only to recipients possessing the computing resources enabling these operations and / or able to access the unnoised position and time by a separate medium.
[0112] To further secure the transfer, the noise-free time used for data encryption may be shifted, for each code used, by an integer number of epochs, known as the code phase offset, such a shift being known only to authorized recipients and specific to the sending source.
[0113] The principles of processing step (106) are detailed in Fig. 10 .
[0114] The second step (108) consists, at the time of transmission, of generating the so-called spatio-temporal encryption keys from the GNSS georeferencing, keys defined as corresponding to the phases of each of the PRN codes of the satellites visible at time t 0, previously biased voluntarily by code phase offsets calculable and compensable by only authorized users, converted into an integer number of PRN code chips, called integer chip code phases.
[0115] These entire, biased code phases subsequently serve in the process to initialize the encryption frame of useful information by the PRN codes of the satellite signals received at t 0.
[0116] The principles for processing step (108) are detailed in Fig. 11 .
[0117] The third step (110) consists, at transmission, of encrypting the information of interest using the generated spatiotemporal keys. This encryption is defined as the bit-by-bit combination of the binary-encoded information of interest and the PRN code of at least one of the visible satellites, chosen cyclically or pseudo-randomly, initialized on the biased integer phase code provided in the spatiotemporal encryption key. The bit-by-bit combination is preceded by a conversion of the binary [0,1] encoding bits of the information of interest into phase-encoding equivalent to BPSK [+1,-1] (called pseudo-BPSK and denoted #BPSK) before multiplication by the chips of the #BPSK [+1,-1] encoded PRN codes.
[0118] The processing principles for step (110) are detailed in Fig. 12 in the case of encryption for transmission (timing of data encryption by an external time base) and in Fig. 13in the case of encryption for recording or archiving (encryption timing based on a time base internal to the process).
[0119] The fourth step (112) consists, at the transmission, of capturing the GNSS fingerprint, a fingerprint defined as a short time sequence of the received GNSS signal, with a minimum length of one millisecond, configurable according to the impact on the communication rate or the additional volume of data to be stored and the types of signals to be taken into account, captured precisely and in synchronicity (within a few tens of nanoseconds) with the instant t 0 of capture of the code phases and calculation of the position and time of the event by the GNSS receiver.
[0120] The GNSS signal is captured at the output of the RF stage of the GNSS receiver after analog-to-digital conversion in the widest possible bandwidth, allowing the collection of signals from different navigation services and constellations.
[0121] The capture can preferably be carried out on several frequency bands, although this is not a requirement for the described process.
[0122] The processing principles for step (112) are detailed in Fig. 14 .
[0123] The fifth step (114) consists, at reception, of performing the extraction of spatio-temporal keys from the GNSS fingerprint, the extraction consisting of estimating, by correlation with the codes of visible satellite signals, the code phases from which will be derived the whole code phases to be applied to perform the decryption of the received data.
[0124] This operation can be extremely computationally intensive, and can be aided by the position and time information of the fingerprint capture, provided in noisy form in the message identifier, which reduces the search space for acquisition in the spatial and temporal domains. Fig. 16 provides the processing principle for an instantaneous assisted acquisition, known as a snapshot, performed from the GNSS footprint,
[0125] When the amplitude of the noise added to the transmitted position and time is zero, the acquisition of the code phases can be carried out directly, from the transmitted position and time information, the satellite ephemeris information and the correction models being known from elsewhere.
[0126] When the amplitude of the noise added to the position and the transmitted time is significant, the acquisition of the code phases of the fingerprint can be prohibitively computationally expensive for recipients who do not have sufficient computing resources or the seed of randomness initialization of the generation algorithm.
[0127] The noise-free code phases thus extracted remain, at this stage, indeterminate due to the phase biases voluntarily added to the transmission, which must only be accessible to authorized users or attributed to any recipient whose identity is known.
[0128] Once corrected for this latter bias, the resulting code phases can be converted into whole code chip phases, for the initialization of the PRN codes to be applied to perform the decryption.
[0129] The principles of step (114) are presented in Fig. 5and the processing of code phase acquisition from the fingerprint is presented in Fig. 16 .
[0130] The sixth step (116) consists of performing multi-factor authentication of the GNSS position and time transmitted from the GNSS fingerprint, the authentication being performed by comparing the position and time calculated by a PVT algorithm from the code phases extracted from the fingerprint, with the position and date transmitted in the container identifier, corrected for the voluntary bias introduced at the transmission attributed to the recipient group.
[0131] In practice, the noisy code phases, extracted by a PVT-1 algorithm from the noisy position and time transmitted in the container identifier, serve, as in the key extraction process of step (114), to aid in acquiring the code phases from the fingerprint. When the acquisition process is successful, the extracted code phases in GNSS-resolved time are converted into line-of-sight distances from the satellites, using the ephemerides and correction models known to the GNSS system, and then the position and time discrepancies are calculated by direct PVT from the pseudorange discrepancies.
[0132] Authentication is accepted when the discrepancies are below a threshold dependent on the noise of error models and a function of the standard deviation of intentional noise added to the emission, if the latter is not corrected.
[0133] The processing principles for step (114) are detailed in Fig. 15 .
[0134] The seventh step (118) consists of decrypting the useful information from the extracted spatio-temporal keys, derived from the code phases, themselves estimated from the noisy position and creation time information of the encrypted message, in the case where the recipient has the characteristics of the amplitude random number generator and the initialization seed, and from the GNSS fingerprint, after snapshot acquisition aided by the denoised position and time information provided by the container identifier.
[0135] These unbiased estimated code phases are corrected prior to decrypting the data of interest, by adding the voluntary code phase shift (code offset) introduced to perform encryption by the PRN codes out of phase and shifted when writing the encrypted message, then converted into an integer chip code phase.
[0136] Preferably, the processing performs the sequencing over time of the codes of visible satellites, according to a periodic or pseudo-random cycle.
[0137] The processing principles for step (116) are detailed in Fig. 17 .
[0138] The eighth step (120) consists of estimating the risk of a cyberattack based on the successes or failures observed in the different stages of the process, which relies on a logic that takes into account: authentication of the fingerprint on open signals, decryption of data of interest, georeferencing of the source, usable when the position and time of creation are known, at least approximately, moreover (called geofencing), authentication of the fingerprint on regulated GNSS signals.
[0139] [ Fig. 2] provides a description of the general principle of generating, in writing, spatio-temporal encryption keys based on the characteristics of the received GNSS signal, consisting of extracting the code phases of the GNSS signals in line of sight, captured at the precise moment of creation of the message to be encrypted for transmission or recording.
[0140] The pair formed by the date (t0) and the geographical location (P(t0)) of the source (20) constitutes the master key of the encryption because of the uniqueness of their realization when they are associated with the encryption event of the message containing the information. Such an event can be punctual, because it is limited to a single action (for example, the creation of a document), periodic (for example, the sending of data over a communication network), or random (for example, the sending of observational data on a mobile platform).
[0141] The date and location of the event, physical but immaterial quantities referencing the event, are characterized, according to the invention, by tangible measurements of time and absolute position delivered by GNSS systems (23), regardless of the type of constellations, the nature of the services, the nature and frequency band of the signals.
[0142] To this end, it is necessary that the event be physically linked to a GNSS receiver (24) capable of capturing the time and position measurements associated with it, itself linked to a GNSS antenna (22), placed in reception of GNSS satellite signals (21) and serving as a spatial reference, regardless of its relative position chosen with respect to that of the event (for example, on the roof of the building or vehicle at the origin of the event).
[0143] The absolute time measurement performed by the GNSS receiver is linked to the time of the event via a measurement synchronization device capable of transmitting a physical pulse (33) to ensure precise capture of the position measurements and the creation date of the encrypted message and its associated encryption keys. Thus, it is the time of reception of the pulse that must be precisely dated to allow referencing and encryption based on the GNSS signals; the latency between the occurrence of the event and the arrival of the synchronization pulse is of little importance for this sole purpose.
[0144] The position and time of the event provided in an absolute GNSS time scale (in principle converted to UTC time) and a geodetic geographic reference (in principle, WGS 84), delivered by a GNSS receiver (24) connected to the synchronization signal and the antenna, make it possible to obtain the code phases of the signals received from the satellites at the antenna level and at the time of reception of the synchronization top.
[0145] The code phases are given by the GNSS times measured on each of the satellite signals received at the time of the signal pulse. Since all satellite signals are precisely synchronized to the absolute GNSS time at transmission, by design of GNSS systems, the times received from the GNSS satellites are therefore delayed relative to the absolute GNSS time by the propagation times of the waves.
[0146] These delays depend on the distance between the signal-emitting satellites, orbiting along precisely known trajectories, and the receiving antenna, and include the characteristics of the ionospheric and tropospheric propagation layers, and various measurement errors related to the receiving environment (multiple paths) or to the electronics (clock bias, RF bias, latencies).
[0147] At a given date, for the selected GNSS constellation and navigation service, there is only one realization of all the propagation delays of the satellite signals visible from the same reception point, the ephemerides of the satellites being perfectly known and deterministic, as well as of all the code phases of the GNSS satellite signals, these being perfectly synchronized with GNSS time.
[0148] The GNSS constellation, the navigation service, the reception frequencies as well as the type of signal spreading code, and even the indices of accessible satellites, constitute characteristic attributes of user classes allowing different levels of access to the encryption service to be defined based on GNSS characteristics (25).
[0149] The phase measurements of the codes of the satellite signals used, according to user privileges, for location and time transfer are used to develop secret keys for data encryption and signatures for message authentication.
[0150] The code phases of multi-satellite signals received simultaneously on a given date thus constitute a set of multifactorial, unique and unforgeable characteristics of the fingerprint, inseparable from the event, defining the secret encryption keys derived from the position and time of creation of the encryption.
[0151] Knowledge of the precise ephemerides of the satellites (26) and of the correction models (27) of the sources of propagation and electronic error (calibration), makes it possible to link the position and the GNSS time, provided by the receiver, to the GNSS times received for each of the satellite signals, with an accuracy on the order of a few tens of nanoseconds.
[0152] In an embodiment of the invention where the GNSS receiver is external and independent of the message encryption system, the noise-free median code phases can be obtained by calculation from the time and position delivered by the GNSS receiver by applying the mathematical transformation (28), classically known as PVT -1<, inverse to that implemented by GNSS receivers for calculating position and time. The code phases thus reconstructed from an estimated position are called median code phases because they are virtually reconstructed from propagation error models and ephemerides, without taking into account code phase estimation noise or model noise.
[0153] The inverse transformation, PVT -1< , consists of: Calculate the line-of-sight geometric distances between the antenna and the satellites at the provided GNSS date, with the satellite positions at that date calculated from their ephemerides and the antenna position being that provided by the GNSS receiver. Then, deduce the corresponding propagation delays after applying propagation and reception error models. Finally, convert these delays, for each satellite, into absolute GNSS received times at the synchronization pulse delivered by the receiver. The absolute GNSS received time is then transformed into a code phase (29) corresponding to the delay given in code chips, in real value, from the origin of time of the GNSS constellation, modulo the code period (for example, 1 ms, corresponding to the 1023 chips of a GPS C / A code period).
[0154] The middle code phases therefore lead to additional indeterminacy of lock-on, linked to the imprecision of the correction and estimation models, when reconstructing the code phases used for encryption from the GNSS signal fingerprint.
[0155] In a preferred implementation where the receiver is integrated with the encrypted message generation device, the receiver can instantly extract the code phases from the satellite signals being tracked at the time of receiving the synchronization pulse, and provide them with the calculated position and time without having to perform an inverse transformation.
[0156] The resulting code phases, (φ c_nb ) GNSS, are referred to as "noiseless" by misuse of the term, although the instantaneous measurements provided by a receiver are always affected by estimation noise and propagation correction model errors, distributed around the median phase values, as opposed to the code phases subsequently described as "intentionally noisy," which will serve as keys for data encryption (30), the principle of which is detailed Fig. 11 .
[0157] In parallel with the development of the encryption keys, a fingerprint of the GNSS signal, based on the RF signal from the receiving antenna, is captured (31) to provide access, for different user classes, to the characteristics of the code phases used to construct the encryption keys, in order to ensure the authentication (32) of the encrypted message and its origin, the principle of which is detailed Fig. 15 .
[0158] [ Fig.3This presents the general principle of write encryption of data of interest based on the characteristics of the received GNSS signal. It consists of using the PRN codes and corresponding code phases of the satellites in line of sight as sources to encrypt the data of interest in the message to be protected during transmission.
[0159] The encryption (31) consists of combining bit by bit, at the rate of writing the message, the data of the message of interest, converted into binary, with the chips of the codes of the visible satellites, delayed by an integer number of chips according to the measured code phases of the signals, the codes themselves being interleaved according to a predefined or pseudo-random sequence.
[0160] This principle, illustrated by the chronograms in [ Fig. 7 ], [ Fig. 8 ] And [ Fig. 9 ], is detailed [ Fig. 12 ]
[0161] [ Fig. 4] presents the principle of noise in writing the GNSS position estimated at the instant (t 0 ) of creation of the message triggered on the synchronization top (40) consisting of adding (41), after calculation of the position and time by the GNSS receiver (49), Gaussian noises on each of the coordinates of the estimated position without noise (40), independent from one coordinate to another, but of the same standard deviation, adjustable and known only to the users.
[0162] The setpoint value for the added position noise standard deviation (42) is defined by selecting an average value for the precision dilution (DOP) to induce an objective position and time error sufficient to prevent key acquisition through the fingerprint transmitted by unauthorized recipients. The biased phases of the corresponding satellite codes (45) are calculated by inverse transformation (PVT -1<) from the noisy position (44) and knowledge of the satellite ephemerides and GNSS signal propagation correction models.
[0163] The random number generator is initialized by a seed (43) whose knowledge allows the sequence of pseudo-random draws to be reconstructed identically by the authorized recipients.
[0164] The initial trigger for random generation (germ) is provided by the GNSS time estimated by the receiver (49) at the instant (40) of message synchronization rounded by round time periods chosen between 10ms and 100ms
[0165] The code phase offsets applied (48) for data encryption are determined, for each tracked satellite, as a proportion of the code phase difference existing between the biased code phase corresponding to the intentionally noisy position at the rounded date E(t0) and the code phase estimated by the GNSS receiver at the estimated date T(t0).
[0166] The unique proportion coefficient applied for the code phase offset calculation is defined so as to prevent a third party from accessing the code phase offset values by deriving the value of the noisy position transmitted in the container, and the estimated acquisition position from the transmitted footprint.
[0167] The value of this coefficient, which changes with each activation of the random draw of position noise, is obtained using the pseudo-random number generator with uniform distribution over the interval ]0,1[, initialized on the round transmitted time E(t0) (43), which is used for the noise draw (44) according to a normal Gaussian law N(0,1) for position noise.
[0168] This offset is calculated (48) by subtracting the biased code phases (45) and the estimated code phases (41), expressed as an integer number of code chips, possibly supplemented by an additional integer chip offset representing the precise code phase estimated by the receiver inside the code chip, coded in integer meters.
[0169] [ Fig. 5] presents the general principle of reconstructing, during reading, the spatio-temporal encryption keys based on the GNSS fingerprint stored at the creation of the message, consisting of performing, from the GNSS fingerprint of the RF signal captured at the creation of the message, an instantaneous acquisition, called a snapshot, of the PRN codes of the visible satellites, in order to estimate the noise-free code phases ( φ c − nb ^ ) of the signals captured in the fingerprint, at the date of creation of the message (54).
[0170] Based on knowledge of the initialization seeds applied by the noise generator to the creation of the container to noise the estimated noiseless position and the corresponding median code phases can be reconstructed by inverse PVT (PVT -1< ) (51), and thus allow to provide a noiseless code phase help (φ c_nb ) to facilitate snapshot acquisition.
[0171] The snapshot acquisition (52) is aided by the median code phases obtained by PVT -1< (51) from the noisy position and time (P&T) b information provided in the container identification, in parallel with the fingerprint.
[0172] The snapshot acquisition processing is detailed in [ Fig. 16 ]
[0173] Since the duration of the GNSS fingerprint is reduced, the code phases obtained from the fingerprint (54) have higher estimation noise than that of the receiver at the time of message creation, obtained after signal pursuit with much narrower loop filtering bands.
[0174] Since the resolution of the whole-chip phase registration applied for data encryption by the code is limited to the width of a PRN code chip, it remains, however, an order of magnitude lower than the inaccuracy of the code phase estimation obtained from the GNSS fingerprint.
[0175] During the decryption step, and to deal with cases of estimation noise framing the transition of an entire chip, an additional local search on the code chips located on either side of the extracted entire chip phase can be carried out to lift the residual indeterminacy, allowing the possible gap to be corrected before complete decryption of the encrypted data sequence.
[0176] [ Fig. 6 ] describes the general organization of the spatio-temporal encryption (by the message provider) / decryption (by the message recipient) processing based on the joint capture of GNSS position and time and a GNSS signal fingerprint, thus reiterating the main steps of the [ Fig. 1 ].
[0177] The GNSS signal received by the GNSS antenna (60) serves as the basis for acquiring the time and position associated with the creation of the message.
[0178] The unbiased GNSS code phases (φ c_nb ) of the tracked satellite signals are captured (62) at the precise instant of reception of the measurement synchronization signal by the receiver. Since the receiver typically schedules its tasks on its own time base and on sampling deadlines attached to each satellite, the code phases linked to the precise and unique date of reception of the measurement synchronization signal (called the measurement top) must be interpolated from the frame measurements.
[0179] The code phases are intentionally affected by additional biases (65), compensable by only authorized users, obtained from knowledge of the noise model added to the transmitted position (66) and its initialization seed, provided by the rounded GNSS time E(t 0 ) of the instant of creation of the container, as well as the standard deviation of this noise, kept secret, in order to make impossible any attempt to synchronize the encryption code by a third party not having this information.
[0180] In parallel, a slice of the digitized RF signal is taken (63) from the moment of reception of the measurement pulse over a short duration greater than 1ms to contain at least one period of the shortest GNSS PRN codes, but which may be longer, up to 20ms, over a GNSS data period, if the communication rate or the volume of data to be stored allows it,
[0181] During the generation of codes used for encrypting the data of interest, the GNSS codes are pre-shifted (641) as close as possible to an integer number of chips corresponding, for each satellite, to the sum of the precise non-noisy code phase (φ c_nb ) GNSS, continued by the receiver at the time of container creation, and the code bias offset (δφ c ).
[0182] The useful data converted into binary is encrypted (64), by the satellite PRN codes delayed according to the biased code phases in accordance with the principle presented [ Fig. 4 ].
[0183] In the case where the recipient is aware of the initialization points of the random generators, it is possible to denoise the code phases obtained by PVT -1< , and compare them to those extracted from the GNSS footprint by calculating the difference in distance and time, and verify (69) that the difference remains consistent with the estimation noise on position and time,
[0184] If the recipient is unaware of the initialization seeds of the random number generators but knows the standard deviation of the noise, it is not possible to denoise the code phases obtained by PVT -1<, and authentication (69) is only feasible with lower confidence in the distance and time discrepancy, and only if the standard deviation of the Gaussian noise intentionally added by the message provider is known to the recipient. In other cases, container authentication is not feasible.
[0185] Upon reading the container, the receiver reconstructs, using the PVT-1 algorithm (67), the noisy median code phases (φ c_b ) from the noisy position, satellite ephemerides, and propagation correction models. Sharing the random noise generation model between senders and receivers, along with the transmission of the noise generator's initialization seed E(t 0 ) and knowledge of the noise generation standard deviation, allows the receiver to access the estimated noise-free X,Y,Z position and, by applying the PVT-1 algorithm, determine the corresponding median code phases, as close as possible to the estimated unbiased code phases.
[0186] These median code phases corresponding to the estimated position are used to aid in the snapshot acquisition of satellite signals from the GNSS signal fingerprint (68) in order to extract the actual and accurate unbiased code phase information (φ c_nb). If the snapshot acquisition fails, neither message authentication nor decryption is possible.
[0187] Following the acquisition of accurate unbiased code phases from the GNSS fingerprint, and after obtaining median code phases derived from the noisy position, we can calculate (67) a proportion of the code phase deviations, corresponding to the code phase biases added voluntarily to encrypt the data, at the time of writing the container.
[0188] This makes it possible to carry out the deciphering, detailed in [ Fig. 17], encrypted data (610) by the delayed PRN codes (612) of the code phases of the signal received by the message provider, provided however that the voluntary bias added to the phase measurements at the construction of the message is known.
[0189] Finally, if authentication or decryption of the message by an authorized recipient fails, a cyber risk assessment step (611) is carried out based on the observed states.
[0190] [ Fig. 7 ] illustrates the synchronicity of GNSS signals in transmission and reception in the case of periodic codes, as well as the GNSS fingerprint capture range at time t 0 of creation of the encrypted message, in the case of different propagation delays of satellite signals i (72), j (73) and k (74) , as well as for the signal transmitted at the satellite level (71).
[0191] The classic data channel structure of a periodic-coded GNSS signal is presented, composed of the occurrences (j) of the periodic codes. C k j i of the satellite (i) contained in the data D k (i) of occurrence (k) of the GNSS message of the satellite (i).
[0192] φ 0 ( t 0 ) is the absolute code phase of the GNSS time-synchronized signal emitted by the satellite (i).
[0193] δφ 0 (t 0 ) is the phase of periodic codes (modulo the code length) at the satellite (i) transmission at time t 0 , defined by: δφ 0 t 0 = modulo φ 0 t 0 , T C Or, t0 is the measurement time corresponding to the message creation date. TC is the duration of the periodic code φ i ( t0) is the absolute code phase of the signal received on the antenna, at time t0 in the GNSS time base, for satellite (i). δφi(t0) is the periodic code phase (modulo the code length) of the signal received on the antenna of satellite (i), a function of the propagation delay, at time t0 in the GNSS time base, for satellite (i), defined by: δφ i t 0 = modulo φ i t 0 , T C
[0194] The signals captured in the capture range, common to all satellites, thus have different periodic code phases depending on the satellites and GNSS data phases whose state and transition depend on the code phase.
[0195] [ Fig. 8 ] presents the timing diagram of the data encryption by the code chips of the selected satellite, offset from the code phase received at t 0. For this, a detail (81) of the timing diagram of the [ Fig. 7 ] previous is extended to the level of the sequencing of code chips (82) and no longer of code periods.
[0196] The precise measurement time t 0 corresponds to a code phase delay δφ i (t 0 ) which does not correspond to an integer number k of PRN Cb k (i) code chips.
[0197] (83) indicates that the first code chip retained to encrypt the binary data of the message (Mb k ) corresponds to the integer value of the code phase expressed in code chips Φ i ( t 0) .
[0198] The integer chip code phase Φ i ( t 0) is defined by: Φ i t 0 = INT modulo φ i t 0 , T b
[0199] Step (84) represents the data bit sequence to be encrypted, Mb k, encoded #BPSK.
[0200] Step (83) represents the sequence bj (i) of index chips (j) of the PRN code of satellite (i), generated from the integer chip code phase Φ i ( t 0). b j i = B Φ i t 0 i = C i j + Φ i t 0 − 1
[0201] Step (85) represents the data sequence of the encrypted message (Kb j) obtained after bitwise multiplication of the sequences: Kb j i = Mb j × b j i
[0202] [ Fig. 9 ] presents the encryption of data by successive slices, by the sequence of code chips of the satellite associated with each slice, shifted at the beginning of each slice by the code phase of the corresponding satellite received at t 0.
[0203] Similarly to [ Fig. 8 ], the PRN code is multiplied with the bits of the binary message after PBSK conversion.
[0204] The PRN code of the same satellite (i) is applied over a limited time slice (T i ). At the end of each time slice, the code of another satellite is applied, offset from the start by the value of its phase in integer values of the code chip.
[0205] Step (91) represents the sequence of code chips allocated to each of the #BPSK-coded time slices.
[0206] Step (92) represents the converted #BPSK message bit sequence to be encrypted.
[0207] Step (93) represents the result of the bitwise multiplication.
[0208] Step (94) represents the encrypted data slices with different satellite PRN codes
[0209] [ Fig. 10 ] details the method of generating the identification of the useful information source, consisting of adding to the information of interest an identifier, made up of the source reference and the precise GNSS position and date of creation of the encrypted message.
[0210] Step (101), the GNSS receiver receives the analog signal in the frequency bands suitable for the navigation service to be used and performs the digital conversion.
[0211] Step (102), the GNSS receiver performs code and carrier tracking of visible satellite signals, on epochs timed to the reception rate of each of the received satellite signals.
[0212] Step (103), the GNSS receiver captures the code phases of the satellites being tracked, at the moment of receiving a message creation pulse, by performing an interpolation between the epochs of code phase measurements that frame the date of pulse reception.
[0213] Step (104), the receiver calculates the position and time P(t 0 ), T(t 0 ) associated with the message creation synchronization pulse from the code phases interpolated at t 0 . and generates a TMP pulse (acronym in English for Time Marked Pulse) synchronized to the instant t 0 used to launch the sampling of a short sequence of the input RF antenna signal (called the GNSS signal fingerprint).
[0214] Step (105), the reception position P(t 0 ) estimated at time t 0 is noisy (P b (t 0 )) along each of the axes of the geographic coordinate system X, Y, Z by a Gaussian noise generator initialized on a seed depending on a rounding E(t 0 ), chosen according to a difference between 10ms and 100ms, d the estimated date in GNSS time T(t 0 ) of calculation of the position P(t 0 ).
[0215] Step (106), the biased code phases {φ b (E(t 0 )} corresponding to the noisy position P b (t 0 ) are calculated by PVT -1< in order to link the transmitted noisy position with the biased code phases used for the encryption of the data of interest, equivalent to adding bias on the code phases corresponding to the difference between the estimated position P(t 0 ) at t 0 and the noisy position P b (t 0 ).
[0216] Step (107), the message container identifier consists of the source reference as well as the noisy position P b (t 0 ) and the rounded estimated time E(t 0 ).
[0217] [ Fig. 11 ] details the method of generating spatio-temporal encryption keys from GNSS georeferencing, by capturing the code phases of the GNSS signals pursued at the moment of creation of the encrypted message.
[0218] Step (111) the GNSS receiver receives the analog signal in the frequency bands suitable for the navigation service to be used and performs the digital conversion.
[0219] Step (112) the GNSS receiver performs code and carrier tracking of visible satellite signals, on epochs timed to the reception rate of each of the received satellite signals.
[0220] Step (113) the GNSS receiver captures the code phases of the satellites being tracked, at the time of receiving a message creation pulse, by performing an interpolation between the epochs of code phase measurements that frame the date of pulse reception.
[0221] The noise-free code phases are used to calculate the true, precise, and noise-free position and time. The true time, quantized (called round time) in adjustable steps between 10ms and 100ms, is used as the seed for generating phase noise. Rounding the time masks the precise time associated with the container and introduces uncertainty in the satellite positions that can be calculated using ephemerides. This uncertainty is sufficient to reconstruct pseudo-distances from observations of the code phases that could have been extracted from the GNSS signal fingerprint, with the aim of accessing the noise-free position. This round time is transmitted to authorized recipients to eliminate the position noise added to the transmitted position and to enable the acquisition of the noise-free code phases from the fingerprint, which is used for authentication and decryption.
[0222] Step (114) the measured noise-free code phases are modified for each of the tracked satellites by adding phase bias corresponding to a proportion of the code phase difference between the noisy position Pb(t0) and the noise-free position P(t0), not accessible to unauthorized third parties.
[0223] Step (115) the biased code phases are converted into whole chip code phases for encryption of the data of interest.
[0224] [ Fig. 12 ] describes a first method of implementing encryption of information of interest using spatio-temporal keys for the purpose of transmitting encrypted data from the moment the container is created, achieved by combining binary-encoded data of interest with delayed PBSK codes according to the code phases captured at the time of creation of the encrypted message,
[0225] Step (121) represents the input file containing the information of interest to be protected.
[0226] Step (122) performs the binary encoding of the information of interest.
[0227] Step (123) performs the reading of binary data at the required transmission rate, timed by the time base of the transmitter (124), from the reception of the message creation pulse.
[0228] Step (125) performs the conversion of the binary encoding [0,1] into #BPSK encoding [+1,-1] of the data in order to perform a bit-by-bit multiplication with the chips of the PRN code performing the encryption of the data.
[0229] Step (128) performs, for the constellation and navigation service authorized to implement encryption, the generation of the chip sequence of the PRN code corresponding to the satellite ID code defined in step (127) according to the sequencing defined by the interleaving, for the current encryption slice (TK i ) at the rate (T d ) and synchronized with the data transmission rate (124). The chip sequence is initialized on the integer chip code phase {τ Bi (t 0 )}.
[0230] Step (126) performs bitwise multiplication in #BPSK encoding between the data sequence and the local PRN code, before transmission.
[0231] Step (129) performs the conversion of the resulting encrypted information into binary code.
[0232] [ Fig. 13] describes a second method for implementing encryption of utility information using generated spatiotemporal keys, for recording purposes, without timing constraints. The method is similar to that described in [ Fig. 12 ] with the sole difference that the coding timing is no longer dictated by the data transmission rate, but solely by the rate of the local clock (124) controlling the recording.
[0233] [ Fig. 14 ] presents the method of capturing the GNSS fingerprint performed after analog-to-digital conversion of the received GNSS signal.
[0234] Step (141), the GNSS receiver receives the GNSS signal for the frequency band corresponding to the GNSS navigation service to be implemented for encryption and authentication.
[0235] Step (142), the RF signal is conventionally digitized to 4 to 12 bits
[0236] In step (143), a pilot initiates recording precisely at the moment of reception of the pulse received at the creation of the message (TMP(t 0), for Time Mark Pulse). The precision in question reflects the synchronization difference, based on the receiver's local time base, between the moment chosen to capture the code phases of the satellite signals and the moment at which the fingerprinting begins.
[0237] This difference must remain negligible compared to the duration of a GNSS signal code chip (for example, 10ns allows compatibility with most GNSS codes and RF signal sampling frequencies).
[0238] The fingerprint recording duration, which can be ordered, is adjusted externally according to the navigation service, depending on the impact on the authorized communication or recording speed (a 1ms fingerprint coded on 12 bits and digitized at 100MHz occupies a volume of 1.2 Mbits).
[0239] [ Fig. 15 ] describes a method of implementing multi-factor authentication of GNSS position and time from extracted spatio-temporal keys performing the comparison between the GNSS position and time at the time of creation transmitted in clear text (but possibly noisy) in the container, and the position and time estimated from the GNSS fingerprint.
[0240] The input (150) consists of the position and time calculated by the GNSS receiver from the code phases captured at the date of reception of the message creation pulse, this information may have been intentionally noisy according to a Gaussian distribution of controllable standard deviation and with seeds of generation of randomness related to the unnoised resolved time and to the satellites.
[0241] Input (151) is the GNSS fingerprint captured on the same date of reception, at the output of the RF chain of the GNSS receiver.
[0242] Step (152) reconstructs, by application of the PVT-1 algorithm, the line-of-sight distances between the antenna and the satellites, using the known satellite ephemerides (158), from which the propagation delays are derived using the propagation correction models and the known satellite clock correction models.
[0243] Propagation delays allow the calculation of code phases corresponding to the date of reception of the message creation pulse (t0).
[0244] Step (153) performs snapshot acquisition of the visible satellite signal codes by sliding correlation of the fingerprint signal with the visible satellite PRN codes, initialized on the code phases provided by (152), and within a search window linked to the uncertainty of the position and time estimates provided and accessible by the fingerprint over its duration, as well as to the position and time standard deviation of the intentionally added phase noise. The snapshot acquisition is detailed [ Fig. 16 ]
[0245] The offsets of the correlation maxima represent the code phase difference between the code phases captured by the receiver at the time the encrypted message was created and the code phases extracted from the hash.
[0246] Step (154) determines the observable pseudo-distances of the footprint (and not distances, the date of receipt of the footprint not being perfectly aligned with the date t 0 of instant capture, due to the offset of the snapshot time slice) antenna-satellite by line-of-sight axis, after application of the propagation correction and satellite clock correction models.
[0247] Step (155) performs the calculation of pseudo-distance deviations per axis by sight.
[0248] Step (156) performs the calculation of the position deviation and the residual time deviation from the visual pseudo-distance deviations, by application of the direct PVT algorithm.
[0249] Step (157) performs the evaluation of the compatibility between the position and time differences with respect to the estimation error margins and the intentionally added noise.
[0250] [ Fig. 16] describes an embodiment of acquiring snapshot code phases from the GNSS footprint, aided by the GNSS position and time transmitted in the container, in the case of a GNSS signal containing navigation data involving alignment of the coherent integration of the correlation on the data transitions of the GNSS message.
[0251] One difficulty of snapshot acquisition carried out on a capture of the received GNSS signal is related to the fact that the message data carried by the GNSS signal can create phase flips which compromise the performance of the correlation-aided acquisition.
[0252] It is therefore necessary to identify, prior to the search by sliding correlation, the expected position of each of these transitions (predictable from the resolved GNSS positions and times, possibly noisy, provided in the container), allowing to carry out the coherent integration of the correlation by parts, then to sum them in a non-coherent way, so as to minimize the loss of estimation.
[0253] The entry (160) corresponds to the expected code phases obtained from the resolved GNSS position and time transmitted by the container, already presented in [ Fig. 15 ].
[0254] Input (161) is the resolved GNSS position and time transmitted by the container.
[0255] Entry (162) is the GNSS footprint.
[0256] Step (163) generates the local code associated with the satellite signal to be acquired, sampled at the same frequency as the footprint signal, the search code phase being defined in a delay domain framing the expected code phase.
[0257] Step (164) performs the estimation of the data transition epoch within the fingerprint duration from the prediction of the received code phase obtained by applying the PVT-1 algorithm (identically to step (152) of the [ Fig. 15 ]).
[0258] The absolute code phase φ c ( tThe received code phase (relative to the GNSS time origin) at time t0 is converted modulo the duration (TD) of a GNSS data period, thus providing the position of the received code phase relative to the start of the current GNSS data. We then check whether the next data transition falls within the fingerprint sampling duration (TE) by testing whether δφ, the remaining phase increment after t0, is less than the fingerprint duration: δφ D = T D − modulo φ c t 0 , T D
[0259] If δφ D < TE SO δφ D is converted into a code phase.
[0260] If Tb is the code chip period, the code phase corresponding to the next data transition, expressed in code chips, is: φ D t 0 = δφ D T b
[0261] Step (165) then performs part-consistent integration: F c − δφ = ∫ 0 φ D t 0 E t . C * t − δφ dt F c + δφ = ∫ φ D t 0 TE E t . C * t − δφ dt
[0262] Step (166) performs the inconsistent integration; the expression for the correlation function is then: F c 2 δφ = F c − δφ 2 + F c + δφ 2 Or, E(t) is the fingerprint signal. C(t) is the code of the satellite signal under consideration. δφ is the phase shift introduced for scanning the uncertainty domain
[0263] Step (167) determines, for each of the visible satellites, the code phase difference δφ c existing between the code phase measured by the receiver and the code phase extracted from the fingerprint by searching for the maximum correlation by scanning the code phase shift: δφ c = Max δφ F c 2 δφ
[0264] [ Fig. 17 ] summarizes a possible overall, but not unique, method of decrypting useful information from spatio-temporal keys, obtained by extracting code phases from signals derived from the GNSS fingerprint.
[0265] Step (172) tests the availability of the seed of the added noise hazard generator.
[0266] Step (1711) performs the calculation of the noise-free position estimated by drawing position noise identically to the creation of the container by applying the same noise generation algorithm and the same initialization seed.
[0267] Step (171) performs the calculation, using PVT -1< at round time E(t 0), of the noise-free median code phases from the estimated noise-free position
[0268] Step (174) performs the estimation of accurate unbiased code phases by snapshot acquisition from the GNSS fingerprint, in accordance with the description of the [ Fig. 16 ], and provides the unbiased code phases estimated at t 0.
[0269] Step 173 performs the calculation of the code phase deviations corresponding to the noisy position at time E(t0) and the unbiased code phases at time t 0 extracted from the footprint la between, and calculates the code phase offsets by applying a proportion factor from the same equally distributed random draw on ]0,1[ already provided by the noise generator at the time of the denoising of the position (1711).
[0270] Step (175) performs the calculation of the encryption code phases by adding the estimated noise-free code phases acquired via the fingerprint (174) and the code phase offsets derived from the noisy position (173)
[0271] Step (176) performs the conversion of the encryption code phase into whole chips for each of the visible satellites at t 0, considered as the spatio-temporal encryption keys to be taken into account to perform the decryption of the encrypted data of interest.
[0272] Step (177) performs, according to the satellite designated according to the satellite coding frame in step (1710), the generation of the PRN code offset from the corresponding integer chip code phase, at the rate of the data restitution clock.
[0273] In parallel, step (178) performs the reading of the encrypted data of interest, previously converted into #BPSK encoding, at the same rate.
[0274] The two sequences can then be multiplied bit by bit in step (1711) and, after conversion to binary, provide the deciphered information of interest (1712)
[0275] [ Fig. 18 ] describes a particular, but not exclusive, method of assessing cyber risk based on the success of authentication and decryption operations according to the nature of the GNSS signals implemented.
[0276] Step (181) prioritizes the success of authentication performed on the fingerprint using open GNSS signals. A failure of authentication leads to suspicion of an attack by falsifying the position and / or time contained in the message identifier.
[0277] If successful, step (182) verifies the successful decryption of the data of interest. Failure to decrypt the data following successful authentication leads to suspicion of identity forgery by copying a valid identifier from another message, or by reconstructing a consistent hash of the transmitted position and time, but without having been able to access the data.
[0278] If successful, step (183) verifies (Geofencing operation) that the position and time transmitted in the identifier are consistent with information known to the provider (fixed antenna position, predefined creation date, sending on other communication channels), thereby revealing risks of receiving GNSS repeater signals (Meaconing).
[0279] A failure leads to suspicion of a risk of spoofing open GNSS signals, all information and data remaining consistent although false.
[0280] If successful, an additional verification step (184) resolves any doubt by authenticating the GNSS fingerprint using the encrypted or regulated signals it contains, performed by authorized users. Suspicion of open signal spoofing can be confirmed if authentication using encrypted signals fails.
[0281] [ Fig. 19 ] describes a preferred but not limiting implementation of the system used, in transmission, for identification and encryption by spatio-temporal encryption in writing, implementing a GNSS positioning receiver and associated computing means to perform the encryption processing.
[0282] The system implemented in transmission includes a GNSS receiver and a specific processing module preferably entirely software-based (SW) and implemented in the communication system in parallel with the GNSS receiver, or a specific hardware (HW) module (called an add-on in English) allowing encryption operations to be carried out in a secure manner by HW-wired processing.
[0283] The system described implements: (191) a GNSS antenna (192) a GNSS receiver (193) the receiver's local PRN code generation module, which can be activated on demand upon external requests (195) a SW and / or HW add-on performing authentication and encryption of the data of interest (194) to be transmitted or recorded according to the principles of the invention, and delivering to the recipient the container containing the encrypted information (197) (196) a sub-module performing encryption of the message of interest using phase-shifted GNSS codes
[0284] [ Fig. 20 ] describes a preferred but not limiting implementation of the system used for authentication and decryption by spatio-temporal encryption in reading, implementing a GNSS receiver and associated computing means to perform the decryption processing.
[0285] The system implemented in reception includes a GNSS receiver, responsible for generating local PRN codes on external command, and a specific processing module which can be entirely software (SW) and implemented in the communication system in parallel with the GNSS receiver, or a specific hardware (HW) module (called an add-on in English) allowing in particular to accelerate snapshot acquisition operations from the GNSS footprint by wired HW processing in addition to the task control operations carried out by SW.
[0286] Note that a single, configurable HW module allows encryption and decryption operations to be performed with the same interface definition with the GNSS receiver.
[0287] The system described implements: (201) a GNSS receiver (202) the receiver's local PRN code generation module, which can be activated on demand upon external requests (204) a SW and / or HW add-on performing authentication and decryption of encrypted data (203) to be transmitted or recorded according to the principles of the invention, and delivering the decrypted and authenticated information to the recipients (206) (206) a sub-module performing decryption using synchronized out-of-phase PRN codes Possible industrial applications of the invention
[0288] Many industrial services and application areas requiring protection of data integrity and authentication of their source with simplified cybersecurity procedures can benefit from and leverage the advantages of the invention, in particular, but not limited to; systems used for issuing reference documents or certified acts for time stamping, or performing an authentication audit of transactions, devices delivering tachography information, allowing verification of the status and movement history of vehicles, devices for identifying and protecting transfers of observations transmitted by robots and drones, the protection of communications and personal archives.
[0289] Authorities accredited for the use of regulated GNSS navigation services can also offer a transaction audit service by securely verifying their authenticity, and even assessing potential cyberattacks. List of documents cited
[0290] [D1] US 2015 / 365824 A1 - Gustafson Bo [US]; "Satellite based key agreement for authentication", publication date 17 December 2015 (2015-12-17) [D2] EP 2 674 779 - Marc Revol; "Satellite radio navigation system with remote architecture", filing date: 13.06.2013 [D3] US 2014 / 368380 A1 - Revol Marc & Al; "Satellite radio navigation system with remote architecture", publication date 18 December 2014 (2014-12-18) [D4] EP 2 790 035 - Marc Revol; "Method and device for compressing a broadband radio navigation signal, associated method and device for calculating the correlation function of the spreading code of said compressed signal", filing date: 07.03.2014 [D5] - Alexander Rugamer, Manuel Stahl, Ivana Lukcin, Gunter Rohmer - Fraunhofer IIS Nuremberg, Germany, «Privacy Protected Localization and Authentication of Georeferenced Measurements using Galileo PRS", publié dans les Proceedings of IEEE / ION PLANS 2014 May 5 - 8, 2014 [D6] - Marc Revol - Thales Avionics, « Distant positioning for GNSS securing", publié dans les Proceeding de ENC 2015- session 08- April 8-10, 2015 [D7] - Marc Revol - Thales Avionics, "Compressing a wide band radio-navigation signal and method for calculating the correlation function for distant positioning" Navitech 2016 - Proceeding ISBN: 978-1-5090-3885-5 / P02- 14-16 December 2016 - ESA / ESTEC, The Netherlands.
Claims
1. Method for authentication and encryption, referred to as spatio-temporal encryption, without a dedicated third-party authority to generate access keys, applied for the protection of information of interest in order to guarantee the origin and integrity of the data, for the purpose of recording or transmission, exploiting the precise positioning and dating accessible via GNSS signals, said spatio-temporal encryption method consisting in: - Timestamping the container of the information of interest with the source reference and the position and date of its creation, - Protecting access to the information of interest by encryption linked to the position and date of creation, - Adding noise to the transmitted position and creation date so as to render this information unusable by third parties, said spatio-temporal encryption method being characterized in that the authentication factors and encryption keys of said method depend on specific user privileges, uniquely defined based on the privileges of access to GNSS navigation services and the code phases of the GNSS signals received at the time and place of creation of the protected file, referred to as the container, said container consisting of the following information: - An identifier, characteristic of the container, uniquely referencing the source, the noised position, and the rounded date at the creation of the container, added to the information of interest, - The encrypted information of interest, resulting from the encryption of the initial information of interest as a function of the code phases of the GNSS signals captured at the time and place of creation of the container, - A short temporal sequence of the GNSS signal received at the time and place of creation, referred to as the GNSS fingerprint of the source, used for multi-factor authentication of the identifier and for decryption of the encrypted information of interest, Said spatio-temporal encryption method comprising the following steps at the creation of the container: - Identification of the information source (106), - Generation of spatio-temporal encryption keys from GNSS georeferencing (108), - Encryption of the information of interest from the generated spatio-temporal keys (110), - Capture of the GNSS fingerprint used to transport and protect the spatio-temporal keys to be transmitted (112), Said spatio-temporal encryption method comprising the following steps at the reading of the container: - Extraction of spatio-temporal keys from the GNSS fingerprint (114), - Multi-factor authentication of the GNSS position and time from the spatio-temporal keys extracted from the GNSS fingerprint (116), - Decryption of the information of interest from the extracted spatio-temporal keys (118), - Evaluation of cyber risk in case of failure to read the container (120).
2. Method according to Claim 1, for encrypting the information of interest by combining the initial data encoded in binary [1,0] with at least one of the pseudo-random codes of the GNSS signals, referred to as PRN codes (Pseudo-Random Noise), tracked in reception at the instant to of creation of the encrypted message, for the chosen constellation and navigation service, said combination consisting in multiplying bit by bit the sequence of initial data of interest by the sequence of chips of the PRN code, periodic or aperiodic in nature, depending on the navigation service implemented in the method, said multiplication being characterized in that: - It is applied to the input data of interest encoded in binary after their conversion to #BPSK [+1,-1] coding (Binary Phase Keying), the local PRN code chips already being #BPSK coded, - The applied local PRN codes, specific to the navigation service used, are each delayed before multiplication by an integer number of chips closest to the instantaneous code phase of the corresponding received satellite signal (115), sampled at the instant to, shifted by a hidden random value, referred to as random phase offset (114), - The different local PRN codes are applied, according to a cyclic or random sequencing, referred to as interleaving, in temporal slices of the same length over the entire sequence of data of interest, Said encryption method comprising the following steps for the constitution of the encrypted data sequence: - Selection of the constellation and navigation service according to user privileges, - Identification of the GNSS satellites tracked at the instant to (112), - Capture of periodic or aperiodic code phases, according to the chosen navigation service and the satellites tracked at the instant to (113), congruent modulo a duration sufficient to protect against direct acquisition of the associated pseudo-distances, for example 100 ms, - Addition of the random phase offset (114) calculated jointly with the position noise, initialized on a rounding of the creation date and with a secret standard deviation known only to authorized users. The code phase offset is determined as a proportion of the existing differences between the instantaneous code phases tracked by the receiver and the median noised code phases obtained by inverse transformation PVT-1 (171) of the transmitted noised position, the proportionality coefficient resulting from the same uniformly distributed random draw on ]0,1[ as that performed by the noise generator for position noising, - Reading of the binary data to be encrypted at the chosen data recording or transmission rate (123), - Conversion of binary data into #BPSK coded data (125), - Sequencing of the local satellite codes to be applied in successive temporal slices to perform encryption by the satellite codes according to said interleaving defined to contribute to data encryption (127), - For each temporal slice, alignment of the origin of the generation of code sequences as a function of the code phases captured at the instant to and the random phase offset (128), - Bit-by-bit multiplication at the chosen recording or transmission rate between the #BPSK coded data and the #BPSK coded code chips (126), - Conversion of the multiplication outputs into binary coded data (129).
3. Method according to Claim 1, referred to as authentication of the origin of said container, implementing the transmitted noised GNSS position and date as well as the GNSS fingerprint representative of the characteristics of the GNSS signal received at the time of creation and added to the container, said GNSS fingerprint consisting of a slice (143) of the digitized GNSS signal at the output of the GNSS RF reception stage (142), filtered in a GNSS signal reception band (141) compatible at least with the frequency spreading containing the code of the navigation service implemented, Said authentication method being characterized in that: - The code phases of the visible GNSS signals are extracted from the fingerprint, consisting of a short slice of the GNSS signal of a few milliseconds, captured at the time of creation of the encrypted message (151), - The code phases extracted from the fingerprint are used to estimate the differences between the position and the date of capture of the fingerprint, estimated from the fingerprint, and the noised position and the rounded creation date of the message provided in the container identifier, the ephemerides of the satellites being known data provided elsewhere by the GNSS system (156), - The position and time differences calculated from the code phases extracted from the fingerprint (154) and the code phases corresponding to the noised position and the rounded date transmitted in the container (152), after correction of the noise voluntarily added during transmission, with a known draw law to the recipient, are evaluated in relation to the distribution of GNSS errors depending on the standard precision of the GNSS navigation service implemented, the quantization of the rounding of the creation date, and the duration of the fingerprint (157).
4. [Method according to Claims 1 and 3, for extracting the code phases used for authentication, from the GNSS fingerprint captured at the date of creation of the encrypted message, consisting of a direct acquisition (52), referred to as snapshot, of the codes of the visible satellites over the sole length of the fingerprint, aided by the code phases corresponding to the non-noised position and the rounded GNSS time (51), obtained after suppression of the noise (53) added to the position transmitted in the container, the noise draw law being known both to the sender and the recipient, said snapshot acquisition being characterized in that: - The position of the satellites corresponding to the date of creation of the message, provided in rounded GNSS time, transmitted in the container, is calculated from the known ephemerides of the GNSS satellites for the navigation service implemented in reception, - The acquisition of the code phases of the GNSS fingerprint is carried out over a GNSS time exploration range framing the expected code phases of the visible satellites, the start date of the fingerprint being initialized on the actual creation time of the message, - The expected code phases used for initialization are calculated from the non-noised position, obtained after correction of the noised position from the container, and the positions of the satellites calculated for the rounded GNSS time of creation of the message from the container (51): ▪ The model for generating the position noise randomness used during writing being known to the recipient, the noised position provided by the container is corrected for the values of the position randomness generated from the same generation seed as during writing, initialized on the rounded GNSS time of creation of the message (53), - The acquisition of the phase of each of the codes of the GNSS fingerprint is carried out by scanning the delay applied to the local code (163) in the exploration range (168) as a function of the residual standard deviation of phase noise and the positioning inaccuracy of the satellites, to search for the date of best correlation (167) between the code of the fingerprint signal (162) and the synchronized local code, in a delay range located around the delay corresponding to the expected code phase (160).
5. Method according to Claims 1 and 2, for decrypting the encrypted data of interest by the local codes aligned on the non-noised code phase of the signals received at the time of creation of the message, shifted by a random phase offset, obtained by generating the position noise at the creation of the encrypted message, characterized in that: - The constellation and navigation service to be used for decrypting the data of interest are identical to those used for encryption, - The extraction of non-noised code phases is carried out from the GNSS fingerprint captured at the instant to of creation of the encrypted message, by snapshot acquisition of the codes (174), aided by the median code phases derived after correction of the randomness of the noised GNSS position transmitted in the container, - The phase offsets are calculated (173) for the rounded GNSS date of creation of the message, as a proportion of the differences between the code phases of the non-noised estimated position extracted from the fingerprint and the median code phases obtained by inverse transformation PVT-1 (171) of the received noised GNSS position, the proportionality factor being obtained simultaneously with the calculation of the position noise randomness (1711) reconstituted by implementing, identically to the transmission, the random noise generation algorithm parameterized by its standard deviation, kept secret and known to the recipient, as well as the ephemerides of the satellites of the GNSS satellite constellation, - The phase offsets are added (175) to the code phases extracted from the fingerprint, to adjust the delays of the local codes by an integer number of chips (176) closest to the code phases applied to encrypt the message, at the instant to of creation of the container, Said decryption method comprising the following steps for the constitution of the decrypted data sequence: - Selection of the constellation and navigation service used for encryption, - Identification of the GNSS satellites tracked at the instant to, - Correction of the bias of the transmitted noised position, by implementing the noise generator with the same initialization characteristics on the rounded GNSS time as during the creation of the container, - Calculation of the median code phases from the corrected position for initialization of the local search for the instantaneous code phases from the signal fingerprint, - Extraction from the fingerprint of the periodic or aperiodic code phases, according to the chosen navigation service, of the satellites tracked at the instant to, - Calculation of the phase offsets as a proportion of the differences between the code phases of the non-noised estimated position and the median code phases obtained by inverse transformation PVT-1 of the noised position transmitted in the container identifier for the rounded creation date of the message, - Reading of the binary data to be decrypted at the chosen data recording or transmission rate, - Conversion of binary data into #BPSK coded data, - Sequencing according to the interleaving of the local satellite codes to be applied in successive temporal slices to perform decryption by the encrypted satellite codes following said interleaving, - For each temporal slice, alignment of the origin of the generation of code sequences as a function of the periodic or aperiodic code phases extracted from the fingerprint and the reconstituted random phase offset, - Bit-by-bit multiplication, at the chosen recording or transmission rate, between the #BPSK coded data and the #BPSK coded code chips, - Conversion of the multiplication outputs into binary coded data.
6. Method according to Claims 1, 3, and 4, for adjusting the level of security of authentication and encryption by selecting the GNSS constellation and navigation service, robust against signal spoofing, said security adjustment method consisting in implementing, for accredited users or authorities, an a priori encrypted GNSS navigation service not accessible to the perceived threat, the method being characterized in that: - The GNSS fingerprint, when captured in a wide band, captures the signals of all constellations and all associated navigation services, - The constellation used for encryption-decryption and authentication (158) is chosen according to the geographical availability of the constellation and the approval provided by the authority guaranteeing the use of GNSS navigation services, - The security check (157), which requires the access keys to the encrypted GNSS signals, can be carried out directly by the user if they are accredited or by a mandated authority to carry out the confirmation.
7. Method according to Claims 1 to 6, for validating the decryption of the data of interest after decryption, and for evaluating the risk of cyber attack in case of failure (611), characterized in that: - A failure of fingerprint authentication (181) implies falsification, by intrusion into the container, of the position or creation time transmitted in the container, inconsistent with the fingerprint, - In case of successful authentication, a failure to decrypt the data of interest (182) implies falsification, by intrusion into the container, of the position and creation time consistent with the fingerprint, inconsistent with the interleaving and the encryption code phases of the data, - In case of successful decryption of the data of interest, a test referred to as Geofencing (183), consisting in verifying, when the information is available elsewhere, that the expected position and creation time correspond to the identification information available in the container. A failure of the Geofencing verification is indicative of spoofing of the GNSS signals at reception on the antenna, for example by superimposition of signals created by simulation of constellation signals (accessible for open navigation services), - Finally, an ultimate verification (184) consists in checking the authentication of the fingerprint based on regulated encrypted GNSS signals, via an accredited authority having the GNSS signal encryption keys. A failure of authentication by the encrypted GNSS signals is indicative of a targeted attack on the area of implementation of the secured recordings or communications.
8. Device for encryption and decryption guaranteeing the origin and integrity of information of interest for the purpose of recording or transmission, implementing the methods of Claims 1 to 7, characterized in that it comprises: - A GNSS reception antenna (191), - A single or multi-constellation GNSS receiver capable of processing one or more navigation services in parallel and of capturing a slice of RF signal, referred to as snapshot, upon reception of an external command, and of providing the code phases of the satellites visible at that instant (192), - For the creation of the protected container, a processing module (193) and software interfaced with the GNSS receiver (195), configured for encryption, capable of performing the container identification and encryption treatments of the information of interest to be recorded or transmitted, - For reading the container, a processing module (204) and software, configured for decryption (205), capable of performing the container authentication and decryption treatments of the recorded or transmitted information of interest.
9. Encryption and decryption device for the purpose of recording or transmission according to the preceding Claim 8, for which the GNSS constellation used is the Galileo constellation, and the navigation services implemented use the signals of the open service, referred to as OS, and the encrypted signals of the commercial service, referred to as CS, or the regulated service, referred to as PRS.
10. Method for authenticating the information of interest according to Claims 3 and 4, at the service of an accredited third-party authority, making it possible to validate the origin and content of the data of interest with at least one additional level of security compared to that provided by a device based on periodic open signals, characterized in that the authentication provided by the service relies respectively on: - The pilot channels of the open GNSS signals with a period of 100 ms, - The encrypted CS or PRS signals of the Galileo constellation, if the nominal service only implements open GNSS signals, - The encrypted PRS signals of the Galileo constellation, if the nominal service only implements commercial GNSS signals, such as Galileo CS, - The signals of constellations different from the constellation implemented by the nominal service, if it only implements one constellation.