Spatio-Temporal Key Encryption for Authentication and Encryption of Communication and Information Systems

By leveraging GNSS positioning and precise dating to create spatio-temporal encryption keys, the solution addresses the vulnerabilities of existing authentication and encryption methods, offering robust and infrastructure-light security for information systems.

FR3150678B1Active Publication Date: 2025-05-23REVOL MARC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023006731
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-06-27
Publication Date
2025-05-23
Estimated Expiration
2043-06-27

AI Technical Summary

Technical Problem

Existing methods for authenticating and encrypting information in communication and information systems rely on third-party authorities and complex key management infrastructures, making them vulnerable to intrusions and cyber threats.

Method used

The proposed solution employs spatio-temporal key encryption, utilizing GNSS positioning and precise dating to create unique encryption keys, thereby authenticating and encrypting information without the need for external security infrastructures.

Benefits of technology

This approach provides robust authentication and encryption capabilities, ensuring the integrity and confidentiality of information while minimizing the need for additional security infrastructure and complex key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000051_0000
    Figure 00000051_0000
  • Figure 00000051_0001
    Figure 00000051_0001
  • Figure 00000052_0000
    Figure 00000052_0000
Patent Text Reader

Abstract

Authentication and encryption process without third party authority, called spatio-temporal encryption, applied for the protection of information of interest in order to guarantee the origin and integrity of its content for the purpose of recording or transmission, based on hidden characteristics associated with the position and creation date of the message, resulting from the processing of GNSS signals. The process allows, without additional dedicated security infrastructure, to protect and authenticate, anywhere and at any time, any data inserted into the information system, and to evaluate, at any level of the system, the associated security risk. Taking advantage of the different levels of access protection to GNSS signal services, the solution offers different robustness capabilities whose complexity and security can be adapted according to the level of threat, while minimizing the impact on the performance of the communication network.Abstract figure: [Fig.2].
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Spatio-temporal key encryption for authentication and encryption of communication and information systems Summary of the invention

[0001] The invention describes a method of authentication and encryption without third-party authority, called spatio-temporal encryption, applied for the protection of information of interest in order to guarantee the origin and integrity of its content for the purpose of recording or transmission, based on precise GNSS positioning and dating.

[0002] The approach followed is part of a so-called "zero trust" approach, applied to the protection of the confidentiality and integrity of data in information and communication systems, which, based on the observation that firewalls and access protections are never completely impervious to intrusions, recommends favoring multi-factor authentication and information encryption solutions, and monitoring attacks on data integrity.

[0003] The solution according to the invention makes it possible to achieve the protection and authentication of information at its sources, regardless of the generation platform, on the basis of multi-dimensional hidden data linked to the position and creation date of the document, exploiting intermediate characteristics specific to the processing of GNSS signals and taking advantage of the protection of access to secure signals broadcast by global GNSS systems.

[0004] Such an approach makes it possible, without additional dedicated security infrastructure, to protect the data circulating in the information system, and to evaluate, anywhere and anytime, and at any level of the system, the associated cyber-security risk, by controlling the consistency and integrity of the data contained (authentication based on the position and time of the information constituting the master key, encryption of the data according to derived dynamic keys, traceability for security control).

[0005] Taking advantage of the different levels of protection of access to GNSS signal services, called navigation services, the solution offers different robustness and control capabilities whose complexity and security can be adapted according to the level of threats, while minimizing the impact on the performance of the communication network. Field of invention

[0006] The field of the invention relates to the authentication and protection of information of interest for recording purposes, including both in the sense of indexing for archiving and in the sense of transmission through a communication network or computer servers.

[0007] The term "information of interest" covers all digital information intended to be transmitted, stored or indexed for archiving, whether these information are exchanged punctually or continuously, for example, messages, documents, certified acts, personal data or intended for timestamping.

[0008] The context of use of the invention concerns the protection of data, the certification of records of individual or company information, as well as the traceability and control of cryptographic digital signatures integrated in the information.

[0009] The implementation framework is that of an environment presenting a cyber risk likely to lead to attacks on the integrity of the data (modification of their content), on the identity of their source (modification of the origin of the information) or even on the confidentiality of the information (unwanted reading by third parties).

[0010] The types of malicious acts considered concern the compromise of information and its source, such as identity, date, location, signature and information of interest, as well as the falsification of this data.

[0011] The invention proposes a solution for protecting information at the source, making it possible to minimize constraints on security infrastructures (regulation of access to premises and equipment) and not requiring specific access privileges or dedicated security infrastructures, by taking advantage of spatio-temporal characteristics that are always available, singular and unambiguous, characteristic of the source at the time of creation of the information to be recorded or transmitted. The information thus referenced and protected at the source can be exchanged with a minimum risk of alteration or observation in insecure infrastructures.

[0012] In this respect, GNSS constellations can be used as global referencing sources, available continuously and in all locations, with a view to characterizing an event in a unique manner according to a set of multiple parameters (called multi-factors) and intrinsically presenting levels of protection and authentication of access to the signals, linked to said GNSS navigation services delivered by construction by the signals.

[0013] Furthermore, due to the multiplicity of constellations and frequency bands used, they provide independent sources of signals that offer a wide variety of observation conditions, likely to increase the availability and accuracy of the characteristics used for referencing. Managed and guaranteed by different authorities, they constitute a trusted, legal and sustainable medium, capable of establishing an information security solution associated with satellite geolocation.

[0014] Another interest lies in the wide dissemination of geolocation equipment, whether in the context of general public or professional applications, for critical infrastructures or even for security and defense. Technical problem

[0015] The technical problem consists of using characteristics of GNSS signals, unique in time and space, to authenticate and protect information of interest to be referenced.

[0016] The basic principle consists of inseparably linking the information of interest contained, with a unique spatio-temporal event of which it will be possible to recognize and identify the characteristics.

[0017] The approach consists of tightly encapsulating the data of interest, exchanged in the information system, with the precise and secure date and position of their creation, the geolocation information being used to uniquely identify an event.

[0018] It is simple to reference a document for archiving (photograph, measurements, document, certified acts, etc.) using position and time information provided by a GNSS receiver and equipment ensuring capture (camera, tachograph, etc.) and to store it on a Cloud, for example for timestamping purposes.

[0019] However, if the digital file containing this information, hereinafter referred to as the container, is not secure, it may be easy for third parties to access the information of interest, or even to appropriate it by changing the identification information of the author or the date and place, or even to falsify the information contained.

[0020] It is therefore necessary that the solution implemented ensures: - Secure container creation identification - Authentication of the source by the recipient - Integrity of data of interest against falsification by third parties - Confidentiality of data of interest against disclosure by third parties

[0021] A simple capture of GNSS position and dating outputs cannot provide such protection capabilities without involving the use of one-way functions to perform encryption and strong constraints on management and verification of public-private keys and electronic signatures via a private key infrastructure (PKI) to perform symmetric or asymmetric encryption and dual-control authentication with public and private keys.

[0022] The object of the invention is to provide such capabilities without having to set up such security infrastructures, nor an asymmetric cryptography algorithm, relying solely on the information characterizing the GNSS satellite signals which constitute unique and specific attributes of the sender of the message, accessible to recipients having the same signal access privileges.

[0023] A device that provides proof that the position and date are not corrupted can prevent people from falsifying the information (the photograph) with malicious intent. State of the prior art

[0024] The techniques developed in communication to protect and authenticate information exchanged between the provider and recipient of confidential data traditionally implement public-private symmetric or asymmetric key encryption methods, involving external infrastructures to ensure the management of multi-user keys and authorities guaranteeing the protection of secrecy.

[0025] The authentication and encryption / decryption processes involve exchanges of keys and signatures which can be observed, even if intrusions remain rare and the business of experts, the encryption algorithms being increasingly efficient.

[0026] However, the generation of keys remains complex and requires significant computing resources, whether remote or not, as well as increasing cyber-security constraints to ensure access protection.

[0027] The new recommendations for deploying so-called "zero trust" cybersecurity infrastructures described by the publication NIST.SP.800-207 tend to revisit traditional approaches to standard cybersecurity based on protecting access to infrastructures.

[0028] The Zero Trust approach aims to deploy security solutions following a “software-defined perimeter” that provides privileged access to human and non-human users, regardless of their geographic location, the device used, and regardless of where data and workloads are hosted.

[0029] Simultaneously with the development of GNSS-based services, new threats have appeared, linked to the voluntary dissemination of false identification information, by corrupting the outputs of GNSS receivers, for example relating to the position and dating of a vehicle, or again, relating to the risk of deception of the received GNSS signals which can lead to false estimations by the user receiver of the position and time, which are difficult to detect by users.

[0030] A recently developed approach to monitoring and controlling such situations consists of transferring the GNSS Radio Frequency (RF) signal received by the user to a remote processing station or server, in order to process the signals from the services. regulated or defense GNSS navigation, available for reception in parallel with open navigation signals.

[0031] Since access to these navigation services is regulated and the signal codes are highly protected, it is extremely difficult for an unaccredited third party to access them in order to falsify them.

[0032] An authorized authority can therefore verify by this means whether the position and time information broadcast by the users is falsified and whether the signals received are deceived, thus carrying out an authentication of the identification.

[0033] Such a principle is described by patent [Dl] EP 2 674 779 (Marc Revol; “Satellite radionavigation system with remote architecture”, filing date: 13.06.2013)

[0034] However, a disadvantage of this approach lies in the impact on the communication throughput of transmitting wideband GNSS signals.

[0035] Patent [D2] EP 2 790 035 (Marc Revol; “Method and device for compressing a wideband radio navigation signal, associated method and device for calculating the correlation function of the spreading code of said compressed signal”, filing date: 07.03.2014) proposes an approach to compressing GNSS signals, also called Compressive Sensing in English, making it possible to reduce the bandwidth used for transmitting GNSS signals while maintaining their time transfer and positioning capabilities.

[0036] On the same subject, the following publications relate to the capabilities of processing and monitoring GNSS signals remotely: - [D3] (Alexander Rugamer, Manuel Stahl, Ivana Lukcin, Gunter Rohmer - Fraunhofer IIS Nuremberg, Germany, “Privacy Protected Localization and Authentication of Georeferenced Measurements using Galileo PRS”, published in the Proceedings of IEEE / ION PLANS 2014 May 5-8, 2014) describes how ordinary Galileo users can benefit from privacy-protected localization and authentication of georeferenced measurements using the Galileo Public Regulated Signal (PRS) service. - [D4] (Marc Revol - Thaïes Avionics, “Distant positioning for GNSS securing”, published in the Proceedings of ENC 2015 - session 08 - April 8-10, 2015) describes the means enabling the use of encrypted GPS or Galileo signals (by nature more resistant to interference than civilian signals) for secure and robust positioning with strong integration constraints (police, military and government radio). - [D5] (Marc Revol - Thaïes Avionics, “Compressing a wide band radio navigation signal and method for calculating the correlation function for distant positioning” Navitech 2016 - Proceeding ISBN: 978-1-5090-3885-5 / P02-14-16 December 2016 - ESA / ESTEC, The Netherlands) introduces a method for performing GNSS signal compression, exploiting the CDMA (time and space) orthogonality of GNSS signals facilitating the deployment of remote GNSS authentication services. Limitations

[0037] As indicated above, conventional protection methods require key exchanges and complex calculation algorithms, vulnerable to observation and disclosure of the secret, and involve the intervention of trusted third parties. These vulnerabilities, partly dependent on the capabilities for protecting access to security infrastructures, must be assessed in relation to the security risks which may depend on the nature or context of the applications or services.

[0038] The “Zero Trust” approach, which advocates delocalized and source-based security of information, appears synergistic with the capabilities of GNSS systems to meet these objectives.

[0039] However, the first works carried out in this direction in the GNSS world are limited to securing only information linked to georeferencing, without considering generalizing their exploitation for securing all types of data, at all levels and according to levels of protection adapted to the security risks.

[0040] The concept of Remote Positioning in particular is considered as a means of increasing the geolocation capabilities of users of open GNSS navigation services, more sensitive to disturbances in the reception environment, and remains focused on the ability to calculate a position and a time in a physical environment with secure access, making it possible to implement procedures for accessing the signals of encrypted GNSS navigation services, to which standard users do not have access. Solutions to the problem

[0041] The proposed approach to securing information of interest aims to partially satisfy the recommendations of NIST SP 800-207 related to the new principles of implementing cybersecurity, in that the information is secured at the source and can be received and verified with different levels of confidence, depending on the processing capabilities of the recipient and their authorization to process trusted information.

[0042] It can also be deployed anywhere and at any time, without a trusted third party and without a security infrastructure dedicated to the generation of secret keys or encryption algorithms, without requiring additional specific protections for the equipment implementing them.

[0043] It is based on a principle of subsidiarity which gives the capacity to authorized users of GNSS systems implementing the principle of the invention, to carry out themselves the securing of information of interest by relying on the signal access regulations put in place by GNSS systems. Such delegation is made possible by linking the information of interest to be secured with characteristics related to georeferencing and dating, accessible through GNSS systems, widely deployed, which also have protected infrastructures and the intrinsic capacity to deliver position and time information with different levels of security.

[0044] The ability to ensure such a link and to use it to inherit the security capabilities offered by GNSS systems for the benefit of securing information or data is at the heart of the present invention.

[0045] The interest of the proposed cybersecurity solution is mainly based on the high availability and durability of existing GNSS systems and their future developments which contribute, in essence, to maintaining and improving the robustness of precise positioning and time transfer, and to mitigating their vulnerability to cyber attacks such as decoying and jamming.

[0046] It aims to satisfy two main security objectives: - Protect at the source the data of interest that must be exchanged, preventing any intentional or unintentional modification and disclosure of their contents. - Verify, at any level, the origin of the information and ensure that it has not been created or modified by third parties.

[0047] The objective of the solution is to provide such protections in communication and information storage without increasing security infrastructures and constraints, beyond those already implemented for the deployment of GNSS navigation services, and to provide adaptable security protection corresponding to the threat level of the operation.

[0048] Another objective is not to increase the complexity of the processing beyond what is already necessary to access the GNSS navigation services already used in the information systems.

[0049] The solution consists of securing the information of interest to be recorded or transmitted via a data encryption and authentication process based on a symmetric cryptography mechanism, but capable of operating without the obligation to share secret keys to carry out the encryption and decryption of the document.

[0050] Based on the observation that there is only one coincidence of date and physical location associated with a given event, such a capability is obtained by deriving the secret encryption keys from the measurements of the date and position of the event, constituting the master key, characteristic of the time and physical location of creation of the encrypted and authenticatable container.

[0051] In order to achieve an indivisible virtual encapsulation of the information of interest with the identification of the source, the encryption is carried out using spatio-temporal characteristics common to the authentication and encryption of the container, linked to the date and place of the event. The spatio-temporal characteristics of the event are the source of the generation of both the authentication characteristics and the encryption keys.

[0052] For this purpose, the encryption keys are calculated according to the code phases of the GNSS signals received for this date and this position, and for the user attributes of access to the GNSS signals defined by the constellation, the navigation service, the frequencies, the type of spreading codes.

[0053] The code phases of the received signals, aligned with the time base of the GNSS system and dependent on the propagation delay between the satellites and the receiving antenna, provide a unique combination of phase measurements used as encryption and authentication roots in the creation of the encrypted data container.

[0054] The instant and the physical place thus play the role of encryption seed, or even master key, which makes it possible to develop secret encryption keys and to constitute the authentication characteristics.

[0055] When the container is created, subsequently assimilated to the creation of the encrypted document or the creation of the encrypted message, the position and time of the event are determined by receiving the GNSS signal delivered by an antenna whose location serves as a recognized reference to help authenticate the origin of the certified act (for example a notary's office, an administration or any reference authority).

[0056] In the general case of use, it is not necessary for the position of the antenna to be referenced, any user wishing to create an encrypted document by himself being able to use his own GNSS georeferencing means whatever the position and date of the event.

[0057] The GNSS system therefore plays an important role in the transformation of the instant and the physical place, immaterial notions but support of the secret key, into tangible measurable characteristics which are used to estimate time and position and, through this, to develop encryption keys.

[0058] When reading the protected container, the reconstruction of the encryption keys therefore requires access to the time and position of creation of the encrypted message.

[0059] A third-party observer will not be able to reconstruct the encryption keys if he does not have the location and dating information corresponding to the creation of the encrypted document, nor the access privileges to the GNSS navigation service used to carry out the encryption.

[0060] Different transmission modes are made possible by the invention: - The provision in clear text of the time and position of the encrypted document, the generation of encryption codes requiring in this case the generation of additional random variables (such as encrypted PRN codes associated with certain navigation services) making it impossible for a third party to acquire the noisy code phases, the roots of the algorithm for generating the codes associated with the position and the date being known only by authorized users, - Encrypted provision of time and position, in the same container or via a separate secure medium, - Sending a fingerprint of the signal received at the time of creation of the encrypted document, consisting of a time slice of limited duration of the received signal, which allows the recipient to make his own estimate of the position and time of creation of the encrypted document and to reconstruct the encryption keys based on the code phases.

[0061] The invention describes different options for implementing the transmission of secret keys which may be adopted depending on the field of application or the level of protection desired against cyber threats.

[0062] The encryption of the data to be protected is based on the known and available pseudo-random codes which are used for the identification of the GNSS satellites as well as for the estimation of the GNSS time received from the signals (also called the code phase) in the GNSS time scale, at the precise instant of reception corresponding to the date of creation of the message.

[0063] The encryption method consists, when creating the encrypted message: - in using the measured code phases of the satellite signals received at the place and time of creation of the information, as a key to encrypt the data of interest in order to protect any access by unauthorized third parties, - to generate a signature, called the GNSS fingerprint, consistent with the measured code phases, which will allow reading to authenticate the position and time of creation of the message and to reconstruct the encryption keys.

[0064] Each of the code phases, measured by the GNSS receiver, also serves to generate a delay, proportional to the number of code chips, called code chips in its common name in English hereinafter, applied to the pseudorandom sequence combined with the data sequence. This delay is equivalent to a key serving as a root for the generation of the PRN code sequence, itself with protected access or not, always available and inviolable without precise knowledge of the position and date of the corresponding event.

[0065] The codes used, which differ from one satellite to another, are applied per time slot according to a deterministic or coded sequencing which can itself be used to increase the complexity of the encryption.

[0066] Third parties who have neither knowledge of the codes used nor of the alignment delay of the code chip sequence on the data to be encrypted will find it very difficult to successfully perform the reverse decryption operation. This consists of searching, by sliding exploration of the uncertainty domain in time and space, for the delay maximizing the correlation between the encrypted sequence and the encryption code, a characteristic of pseudo-random codes (PRN) being that the correlation result remains zero as long as the code phases are not aligned. Decryption requires acquiring or knowing the code phases with less than 1 ps of uncertainty for most open service codes, or even less than 0.1 ps in the case of regulated access signals.

[0067] The GNSS fingerprint, which can be used for transmitting position and time information to the recipient and also for authenticating the origin of the container, contains a time slice of the received signal collected at the time and place of message creation (by default including signals from all constellations, for all navigation services and all satellites) which is consistent with the measured code phases used at message creation to encrypt the data of interest and to calculate the position and time of message creation.

[0068] Such a fingerprint contains the actual signals as received, at low signal-to-noise ratio, before any demodulation of the code phase and navigation message, and before any decryption of the signal code and data when available for a given signal service.

[0069] The processing of authentication of the origin of the encrypted document, carried out at the recipient, consists of acquiring the code phases of the satellites using the GNSS signal slice transmitted by the fingerprint, then checking the consistency with the transmitted position and time measurements encapsulated in the message, and when they are consistent, decrypting the encrypted data of interest on the basis of these code phases.

[0070] A possible mode of implementation of the method consists in carrying out locally, over a limited delay range, the correlation between the recorded slice of the GNSS signal contained in the footprint with local code slices, initialized with code phases calculated as a function of the Time and the Position of identification transmitted by the container, and of the knowledge of the ephemerides of the satellites.

[0071] If the level of the maximum correlation is sufficiently high, the recorded signal corresponds to the time and position provided, otherwise, the recorded GNSS signal is not consistent with the time and position provided in the container identifier, which means that the fingerprint has been falsified.

[0072] In particular implementation modes to ensure the protection of the identifier contained in the container (i.e. the position and time information of the identifier), the GNSS code phases can be deliberately noisy, by a random sequence of adjustable standard deviation in order to noise the GNSS position and time identification information transmitted in the container, in order to make it difficult to acquire the delay from the fingerprint, for a third party who would have had access, to the reading of the container, to the position and time of creation of the encrypted document, or who would intercept this information in the event that it was broadcast in clear, for non-critical information of interest.

[0073] This phase noise can be achieved by a noise generator whose seed depends on the GNSS date of creation of the encrypted document given in time epochs less than a millisecond. Such a generator is then shared and kept secret by all users authorized to use the data protection system for recording or transmission. The adjustable standard deviation of the phase randomness makes it possible to adjust the spatial and temporal search domain, and therefore the computational complexity necessary to acquire the encrypted data without knowledge of the randomness.

[0074] In such a context of high cyber threat, involving a suspicion of violation of the container and the usurpation of the GNSS signal, certification of the authentication by an accredited external authority is conceivable in the context of the protection of sensitive security infrastructures, by carrying out the control of the fingerprint on the basis of the GNSS signals with regulated access, such as the Galileo PRS navigation service.

[0075] In the case of an implementation of the authentication method on open signals, although the received signals present in the fingerprint have the same root code phases as those of the signals received and continued at the creation of the message, they are much more difficult to acquire without a priori information, even approximate, on the position and time of the creation of the encrypted document, due to the limited duration of the fingerprint, which implies putting in place substantial processing means, called brute force, to carry out the exploration of the reception phases in significant delay ranges.

[0076] In such an approach, it is therefore the complexity of the processing of acquiring the encryption roots which acts as protection, and requires a battery of massively parallel correlators to achieve a virtually instantaneous acquisition, called a snapshot in English, of the signal sequence of the fingerprint.

[0077] The implementation of brute force processing to carry out said snapshot acquisition and the extraction of keys from the fingerprint, if it is more secure and functionally simple in design, is not the only possible approach.

[0078] One way to reduce the complexity of snapshot acquisition is to provide in parallel the position and date estimates obtained by a GNSS receiver at the creation of the message, in order to assist in the acquisition of root phase measurements made from the fingerprint.

[0079] Three options for data encryption, for combined or separate applications, are possible at this level: - the GNSS position and date at container creation are provided in clear and noise-free form, but the data encryption performed from the noise-free code phases uses a protected encrypted GNSS PRN code, whose access keys are shared by all authorized GNSS users. The use of encrypted GNSS codes, for example the Commercial (CS) or Public Regulated Signal (PRS) navigation services of the Galileo constellation, meets this need without having to use keys other than those already available when receiving GNSS signals to generate the encrypted code sequences, - the GNSS position and date at the creation of the container are provided without noise, but encrypted, so as to protect their access by third parties, requiring, unlike the first option, a specific encryption infrastructure using symmetric or asymmetric keys. However, the codes used to carry out the encryption and decryption of the data can remain freely accessible, for example the Open Signals (OS) service of the Galileo constellation, the protection being ensured simply by the decorrelation of the codes when they are not synchronized on the same phase. - the GNSS position and date at the creation of the container are provided noisy according to a pseudo-random generation algorithm whose original seed is based on the GNSS time of the instant of creation of the message. On the other hand, the code phases, used for the encryption of the data remain noise-free. This requires for the recipient, either that it can calculate, in order to correct them, the noise hazards added to the position and time at the creation of the message, or that it has sufficient processing resources to carry out, from the GNSS position and date, or from the transmitted fingerprint of the signal, the exploration of the uncertainty domain of the decryption code phases.

[0080] For all three options, the position and time information provided is used to perform position and time authentication based on the fingerprint, and to reduce the search domain of the code phases. The ephemerides, which allow the satellite positions to be calculated, and the error models, which allow the atmospheric propagation delay and satellite clocks to be corrected, are known and accessible elsewhere by users of the GNSS constellation.

[0081] In the case of the third option, the generation of randomness, applied to the measured GNSS code phases, is amplitude controlled such that the standard deviation of the resulting position error causes a computational load sufficient to discourage intrusion attempts by acquiring a snapshot of the fingerprint by unauthorized third parties while remaining admissible for authorized recipients, but which would not have the noise algorithm.

[0082] In the case of authorized users having the random number generation algorithm, they must also know the value of the standard deviation of the added error, which must remain secret, and initialize the generation algorithm with the transmitted noisy time information converted into round epochs of one millisecond, the noise added to the time then not having to exceed 1 ms.

[0083] It also remains possible to implement an approach without particular protection to transmit the position and the date, or to encrypt the encryption codes. In this case, it is possible for a third party observing the container to reconstruct the spatio-temporal encryption keys, provided that the calculation model of these keys from the code phases is available, as well as the ephemerides and the error correction models applied.

[0084] This lack of knowledge of processing and models alone may prove sufficient in the case of consumer applications not requiring cyber protection as a first approach.

[0085] An alternative solution allowing the use of public access code, in place of regulated access codes, when the GNSS position and date at the creation of the container are provided in clear, consists of carrying out a periodic or random interleaving, called interleaving, of sequences of different open PRN codes used for the encryption of the data, for example by pseudo-randomly selecting the codes of the satellites, possibly taken from several constellations, several frequencies, according to sequencing to be kept secret, known only to the users of the symmetric encryption service.

[0086] These different authentication and encryption options based on spatio-temporal keys are detailed through the explanations associated with the figures illustrating the processing principles envisaged by the invention as well as particular embodiments and implementations linked to the synchronization of the processing with the GNSS signal data. Benefits provided

[0087] This innovation provides new capabilities to verify and certify the authenticity of the origin and content of documents or reports by providing the means to demonstrate, where appropriate, the authenticity of the position and date of its creation. It is also a means of authenticating any equipment delivering an identification message including its identity and dated position.

[0088] It allows information to be protected at the source, minimizing constraints on security infrastructures (regulation of access to premises and equipment) and not requiring specific access privileges or dedicated security infrastructures

[0089] The proposed solution offers significant advantages over standard encryption processes based on symmetric or asymmetric keys, requiring centralized and / or secure cryptographic management, in particular: - There is no need for external key management infrastructure or secure communication or cryptographic authority other than that of the GNSS - Cyber ​​protection is mainly based on the complexity, for a malicious third party, of accessing key code phases of the encryption without precise knowledge of the position and the date of creation of the message and / or without having the keys for generating the codes of the signals protected by the GNSS system, - A protected encapsulation of the encrypted message container is not required due to the strong authentication and data encryption at the source offered by the solution. - Its implementation does not require any additional accreditation other than that necessary for the user to access GNSS navigation services, and the processing technology is based on mature and proven GNSS technology - It is available anywhere and anytime, also allowing the authentication of messages recorded in the past.

[0090] A variety of independent GNSS constellations can be considered as global referencing sources, available continuously and in all locations, each allowing an event to be characterized in a unique way according to a set of multiple parameters.

[0091] Different levels of authentication and security control, using the levels of protection and signal access privileges available by construction, can be implemented.

[0092] The same GNSS fingerprint can be used to certify information through the prism of different constellations Brief description of the figures

[0093] The invention will be better understood on reading the description of several embodiments which follows, given solely by way of example and made with reference to the drawings in which:

[0094] [Fig. 1] presents the most general embodiment of the spatio-temporal encryption method based on GNSS positioning and precise dating,

[0095] [Fig.2] presents the general principle of generation, in writing, of encryption keys spatio-temporal based on the characteristics of the received GNSS signal,

[0096] [Fig.3] presents the general principle of encryption in writing, of the data of interest based on the characteristics of the received GNSS signal,

[0097] [Fig.4] presents the principle of noise in writing the GNSS position and time to the creation of the message,

[0098] [Fig.5] presents the general principle of reconstitution, in reading, of the encryption keys spatio-temporal based on the GNSS fingerprint captured at message creation,

[0099] [Fig.6] presents the general operating principle of encryption / decryption spatio-temporal based on the joint capture of GNSS position and time and a GNSS signal fingerprint,

[0100] [Fig.7] illustrates the synchronism of the GNSS signals in transmission and reception in the case of periodic codes, as well as the capture range of the GNSS fingerprint at the date to of creation of the encrypted message,

[0101] [Fig.8] shows the data encryption timing diagram by the code chips of the selected satellite, shifted from the received code phase to to,

[0102] [Fig.9] shows the encryption of data in successive slices, by the chips of satellite code allocated to each of the slots, offset at the start of each of the slots by the corresponding satellite code phase received at to,

[0103] [Fig. 10] illustrates the principle of identifying the source of useful information, consisting of adding to the information of interest an identifier, consisting of the reference of the source, the position and the precise GNSS date of creation of the encrypted message,

[0104] [Fig. 11] illustrates the principle of generating spatio-temporal encryption keys from GNSS georeferencing, by capturing the code phases of the GNSS signals tracked at the time of creation of the encrypted message,

[0105] [Fig. 12] describes a first mode of implementation of the encryption of the utility information from the spatio-temporal keys for the purpose of transmitting the encrypted data from the creation of the container, carried out by combination between the binary coded data of interest and the PBSK codes delayed according to the code phases captured at the time of creation of the encrypted message,

[0106] [Fig. 13] describes a second mode of implementation of the encryption of the utility information from the generated spatio-temporal keys, for recording purposes, carried out without timing constraints,

[0107] [Fig. 14] illustrates the principle of capturing the GNSS fingerprint carried out after analog-digital conversion of the received GNSS signal,

[0108] [Fig. 15] describes an embodiment of the multi-factor authentication of the GNSS position and time from the extracted spatio-temporal keys performing the comparison between the GNSS position and time at the creation time transmitted in the container, and the position and time estimated from the GNSS fingerprint,

[0109] [Fig. 16] describes an embodiment of the snapshot acquisition of the code phases from the GNSS fingerprint, aided by the GNSS position and time transmitted in the container, in the case of a GNSS signal modulated with navigation data involving an alignment of the coherent integration of the correlation on the data transitions of the GNSS message,

[0110] [Fig. 17] describes an embodiment of the decryption of useful information from the spatio-temporal keys, obtained by extraction of the code phases of the signals from the GNSS fingerprint,

[0111] [Fig. 18] describes the principle of cyber risk assessment based on the success of authentication and decryption operations according to the nature of the GNSS signals implemented,

[0112] [Fig. 19] describes a preferred but non-limiting implementation of the system used for identification and encryption by spatio-temporal writing encryption, implementing a GNSS positioning receiver and associated calculation means for carrying out the encryption processing,

[0113] [Fig.20] describes a preferred but non-limiting implementation of the system serving to authentication and decryption by spatio-temporal encryption in reading, implementing a GNSS receiver and associated computing means to carry out the decryption processing. Technical solution

[0114] The technical solution adopted by the invention takes up, by rationalizing them, the previous approaches previously considered in the exploration of solutions to the problem.

[0115] With regard to the different options presented, and with the aim of ensuring the best compromise between the robustness of security and the complexity of the implementation, the technical solution adopted by the invention focuses on achieving the following capabilities: - The exchange of keys necessary for authentication and encryption is carried out on the basis of sharing a fingerprint between the sender and the recipient, - The acquisition of the encryption keys is carried out by the recipient from the fingerprint using the secret information of position and associated time and transmitted in noisy form by the sender to the recipient, - Authentication is performed by calculating the position and time deviation calculated from the code phase deviations of the received satellite signals, measured on the GNSS signal received on the date of creation of the message and that extracted from the fingerprint by the recipient - A priori, in a first embodiment, the PRN codes used to encrypt the data of interest are those of the public GNSS signals, - The code phases of the received GNSS satellite signals constitute the main encryption keys of the data of interest, applied according to a deterministic or random sequencing, - The identification information consisting of the date and position of creation of the encrypted document, are provided noisy according to a noise generation seed given by the creation time,

[0116] The solution addresses both aspects of authentication and encryption of data of interest: - At the source, the encoding of the authentication characteristics linked to the received GNSS signal and to the PRN code phase of the satellites, and the encryption of the data of interest, - At the destination, authentication of the origin of the message and decoding of the encrypted data, which are based on the consistency of the phases of the PRN codes extracted from the fingerprint of the received signal, verified with regard to the position and time information associated with the message.

[0117] The general principle of operation consists of the implementation of the following functions:

[0118] i. At the message generation level: - The data of interest to be transmitted or recorded in the container are available at the input without protection, - The position and time of creation of the message are calculated by a GNSS receiver based on the selected GNSS signal service(s), - The GNSS receiver also provides: • the corresponding code phases of the satellite signals, as extracted when the message was created, • a short time slice of the received GNSS signal (called instantaneous), collected at the time and position of message generation, at the RF level, • The data of interest are then encrypted by modulation using PRN code sequences, linked to the visible satellite signals received, in cyclically or randomly generated slices, aligned with the code phase measured, at initialization, of the associated satellite signal, • The message is then formatted by encapsulating the following information in a single sequence: • The identification (ID) of the device or generation source, • The position of the antenna linked to the device and the precise time of generation of the message, • The snapshot slice of the received signal (fingerprint), • Encrypted data of interest.

[0119] ii. At the message user level: - Information is extracted from the message (ID, P(V), T, snapshot, data) - Acquisition of satellite signals is carried out by correlation with local PRN codes using the signal slice, initialized by the position and time provided in the message, and the known ephemerides of the satellites: • If the correlation level is high enough and the signature matches the provided position and time, the acquisition is successful, the message is authenticated and the data of interest can be decrypted. • If not, the position and time indicated in the message do not match the signal available when the message was generated. Since the signature or the position and time may have been forged, the message is not authenticated. - The data of interest are then demodulated using locally generated PRN codes and aligned with the satellite code phases obtained by fingerprint acquisition. - Different levels of authentication control can be performed based on the same GNSS fingerprint slice depending on the access privileges to the GNSS signals used to search for the buried proof of the authenticity of the transmitted time and position. For example, the Galileo and GPS constellations provide different signal services OS, C / A, CS, PRS and PPS that can be leveraged within the scope of the invention. The Galileo CS service can be accessed to perform authentication for commercial use, while the Galileo PRS navigation service, with restricted access, is only accessible to accredited users.

[0120] Within the framework of this general operating principle, the technical solution according to the invention has as its object an authentication and encryption method, called spatio-temporal encryption, not requiring a third-party authority, applied for the protection of information of interest in order to guarantee the origin and integrity of its content for the purpose of recording or transmission, based on positioning and precise dating using GNSS signals, consisting of: - to stamp the container of the information of interest with the reference of the source and the position and date of its creation, - to protect access to information of interest by encryption linked to the position and date of creation, - to distort the position and creation date transmitted so as to make this information unusable by third parties, the authentication factors and the encryption keys of said method being defined in uniquely from the code phases of the GNSS signals received at the time and place of creation of the encrypted message.

[0121] According to particular embodiments, the spatio-temporal encryption method comprises one or more of the following characteristics, taken individually or in combination: - encryption of the information of interest by combining the initial data coded in binary [1,0], by at least one of the pseudo-random codes of the GNSS signals, called PRN codes, for Pseudo-Random Noise in English, continued in reception at the instant t0 of creation of the encrypted message, for the constellation and the navigation service chosen, said combination consisting of multiplying bit by bit the initial sequence of data of interest by the sequence of chips of the PRN code, of periodic or aperiodic type, according to the type of navigation service implemented in the method. The bit by bit multiplication is carried out after conversion of the binary data into coded data [+1,-1], coding noted #BPSK thereafter, - authentication of the origin of said encrypted message, implementing the noisy transmitted GNSS position and date as well as a GNSS fingerprint representative of the characteristics of the GNSS signal received at the time of creation and added to the container, said GNSS fingerprint consisting of a slice of the digitized GNSS signal at the output of the GNSS reception RF stage, filtered in a reception band of the GNSS signal compatible at least with the frequency spread of the code of the navigation service implemented, - extraction of the code phases at the date of creation of the encrypted message, estimated from the transmitted GNSS fingerprint, consisting of an instantaneous acquisition of the codes of the satellites visible over the sole length of the fingerprint, aided by the noisy GNSS position and date transmitted in the container - decryption of the encrypted data of interest by the local codes aligned with the code phase of the signals received at the time of creation of the encrypted message, - adjustment of the security level of the authentication by selection of the constellation and the GNSS navigation service, robust to the anticipated deception of the signals, the said method of adjusting the security of the authentication consisting of extracting the code phases from the GNSS fingerprint by using, for accredited users or authorities, an encrypted GNSS navigation service a priori not accessible to the anticipated threat, - validation of data of interest after decryption, and assessment of the risk of cyber attack,

[0122] The invention also relates to a device composed of a signal receiver GNSS, a computer and computer programs, implementing the methods of encryption and decryption of information of interest for the purpose of recording or transmission according to the invention, characterized in that it comprises: i. a GNSS receiving antenna, ii. a single or multi-constellation GNSS receiver capable of processing one or more navigation services in parallel and of taking a slice of RF signal, called a snapshot, upon receipt of an external command, and of providing the code phases of the satellites visible at that moment, iii. for the creation of the protected container, a processing module and software interfaced with the GNSS receiver, configured in encryption, capable of carrying out the container identification processing and encryption of the information of interest to be recorded or transmitted, iv. for reading the protected container, a processing module and software, configured for decryption, capable of carrying out the processing of authentication of the container and decryption of the information of interest recorded or transmitted.

[0123] Another object of the present invention is an additional authentication service of the information of interest deliverable by a third accredited authority capable of certifying the origin and the content of the data of interest with at least one additional level of security compared to that provided by the nominal device. Detailed description

[0124] The description of the invention is detailed in the following paragraphs with regard to the various explanatory figures which specify: - the most general embodiment of the method, [Fig.l], - the principle of key generation and data writing encryption, [Fig.2], [Fig.3], [Fig.4], - the general principle of decryption when reading data, [Fig.5], - the general operating principle of encryption / decryption based on the provision of the GNSS fingerprint, [Fig.6], - the synchronization timing diagrams for fingerprint collection and data encryption, [Fig.7], [Fig.8], [Fig.9], - the detailed treatments corresponding to the different stages of the write encryption process, [Fig. 10] to [Fig. 14], - the detailed treatments corresponding to the different stages of the write encryption process, [Fig.15] to [Fig.17], - the synopsis of the principle of cyber risk assessment, [Fig. 18], - the embodiments of the encryption and decryption system carrying out the method [Fig. 19] and [Fig.20],

[0125] [Fig. 1] presents the most general embodiment of the robust and resilient authentication method by spatio-temporal encryption based on GNSS signals for communication and information systems.

[0126] The method according to the invention comprises a set (102) of steps, configured to implement an encryption-decryption strategy not requiring a security infrastructure external to the system, defined on the basis of hidden data linked to the position and the date of creation, originating from instantaneous intermediate characteristics measured on the GNSS signals, and taking advantage of the protection of access to the signals broadcast by the global GNSS systems for referencing the source of useful information.

[0127] The set (104) of steps of the robust and resilient authentication method by spatio-temporal encryption based on GNSS signals comprises, in a first step (106), in writing, an initialization phase, followed by a phase of encryption of the information and multi-factor characterization of the source which are based on the spatial and temporal synchronization of the received GNSS signals, according to steps (108), (110), (112), then a phase of multi-factor authentication of the source and decryption of the information according to steps (116), (118), implementing in particular, in step (114), a method of extracting spatio-temporal keys carried out from a fingerprint taken from the GNSS signal and finally a phase of evaluating the cyber risk in the event of failure of the decryption in step (120).

[0128] The first initialization step (106), generic for all implementation modes, consists, upon transmission, in associating with the referencing of the source of the encrypted information (defined as the identity of the physical person or the reference of the equipment), the date and the place of creation of the encrypted message provided by a GNSS receiver connected to an antenna serving as a reference.

[0129] This information is used to transport the keys necessary for authentication and decryption of the encrypted message by the recipient.

[0130] In order to ensure the confidentiality of these data, the precise position and time measurements, delivered by the GNSS receiver, are noisy via the use of a randomness generator, for example initialized with the GNSS time, not noisy, of creation of the encrypted message (called, seed of the randomness generator), so as to allow access to the authentication only to recipients having the computing resources allowing these operations and / or being able to access the position and the time not noisy by a separate medium.

[0131] In order to further secure the transfer, the noise-free time used for data encryption may be shifted by an integer number of epochs, called the phase offset of code, such an offset being known only by authorized recipients and being specific to the transmitting source.

[0132] The processing principles of step (106) are detailed in [Fig. 10].

[0133] The second step (108) consists, upon transmission, in generating the so-called spatio-temporal encryption keys from the GNSS georeferencing, keys defined as corresponding to the phases of each of the PRN codes of the satellites visible at time to, previously voluntarily corrected by an arbitrary bias known only to authorized users, converted into an integer number of PRN code chips, called integer chip code phases.

[0134] These biased, whole code phases are subsequently used in the process to initialize the encryption frame of the useful information by the PRN codes of the satellite signals received at t0.

[0135] The processing principles of step (108) are detailed in [Fig. 11].

[0136] The third step (110) consists, upon transmission, in carrying out the encryption of the information of interest from the generated spatio-temporal keys, encryption defined as the bit-by-bit combination of the information of interest coded in binary and the PRN code of at least one of the visible satellites, chosen cyclically or pseudo-randomly, initialized on the biased entire code phase provided in the spatio-temporal encryption key. The bit-by-bit combination is preceded by a conversion of the binary coding bits [0,1] of the information of interest into phase coding equivalent to BPSK [+1,-1] (called pseudo BPSK and noted #BPSK) before multiplication by the chips of the PRN codes coded #BPSK [+1,-1].

[0137] The processing principles of step (110) are detailed in [Fig. 12] in the case of encryption for transmission (timing of the encryption of the data by an external time base) and in [Fig. 13] in the case of encryption for recording or archiving (timing of the encryption on a time base internal to the process).

[0138] The fourth step (112) consists, upon transmission, in capturing the GNSS fingerprint, a fingerprint defined as a short time sequence of the received GNSS signal, of minimum length of one millisecond, configurable according to the impact on the communication rate or the additional volume of data to be stored and the types of signals to be taken into account, captured precisely and in synchronism (to within a few tens of nanoseconds) of the instant t0 of capture of the code phases and calculation of the position and time of the event by the GNSS receiver.

[0139] The GNSS signal is captured at the output of the RF stage of the GNSS receiver after analog-to-digital conversion in the widest possible bandwidth allowing the collection of signals from different navigation services and different constellations.

[0140] The capture can preferably be carried out on several frequency bands, without this being an imperative for the process described.

[0141] The processing principles of step (112) are detailed in [Fig. 14].

[0142] The fifth step (114) consists, upon reception, in extracting the spatio-temporal keys from the GNSS fingerprint, the extraction consisting in estimating, by correlation with the codes of the visible satellite signals, the code phases from which the entire code phases to be applied will be derived to decrypt the received data.

[0143] As this operation can be extremely computationally intensive, it can be aided by the information on the position and capture time of the fingerprint, provided noisy in the message identifier, which makes it possible to reduce the search space of the acquisition in the spatial and temporal domains. [Fig. 16] provides the principle of processing an instantaneous aided acquisition, called a snapshot, carried out from the GNSS fingerprint,

[0144] When the amplitude of the noise added to the position and time transmitted is zero, the acquisition of the code phases can be carried out directly, by inverse PVT transformation (denoted PVT 1 hereinafter) from the position and time information transmitted, the satellite ephemeris information and the correction models being known elsewhere, this without using the imprint of the GNSS signal.

[0145] When the amplitude of the noise added to the position and time transmitted is significant, the acquisition of the code phases of the fingerprint can be prohibitive in terms of calculation time for recipients who do not have sufficient calculation resources or the random initialization seed of the generation algorithm.

[0146] The noise-free code phases thus extracted remain, at this stage, undetermined due to the bias voluntarily added to the transmission which must only be known by authorized entities or attributed to any recipient whose identity is known.

[0147] Once corrected for this latter bias, the resulting code phases can be converted into entire code chip phases, for the initialization of the PRN codes to be applied to perform the decryption.

[0148] The principles of step (114) are presented in [Fig.5] and the processing of acquiring the code phases from the fingerprint is presented in [Fig. 16].

[0149] The sixth step (116) consists of carrying out multi-factor authentication of the GNSS position and time transmitted from the GNSS fingerprint, the authentication being carried out by comparing the position and time calculated by a PVT algorithm from the code phases extracted from the fingerprint, corrected for the voluntary bias introduced at the transmission attributed to the group of recipients, with the position and date transmitted in the container identifier.

[0150] In practice, the noisy code phases, extracted, by a PVT * algorithm, from the noisy position and time transmitted in the container identifier, serve, as for the key extraction processing of step (114), to aid in the acquisition of the code phases from the fingerprint. When the acquisition processing is successful, the code phases extracted in GNSS resolved times are converted into line-of-sight distances of the satellites, using the ephemerides and correction models known to the GNSS system, then the position and time deviations are calculated by direct PVT from the pseudodistance deviations.

[0151] Authentication is accepted when the deviations are less than a threshold dependent on the noise of error models and a function of the standard deviation of voluntary noise added to the transmission, if the latter is not corrected.

[0152] The processing principles of step (114) are detailed in [Fig. 15].

[0153] The seventh step (118) consists of carrying out the decryption of the useful information from the extracted spatio-temporal keys, derived from the code phases, themselves estimated either from the noisy position and creation time information of the encrypted message, in the case where the recipient has the characteristics of the amplitude randomness generator and the initialization seed, or from the GNSS fingerprint in the opposite case, after snapshot acquisition aided by the noisy position and time information provided by the container identifier.

[0154] These unbiased estimated code phases are corrected prior to decryption of the data of interest, by adding to them the voluntary code phase shift (code offset) introduced to perform the encryption by the phase-shifted and offset PRN codes when writing the encrypted message, then converted into the code phase in whole chip.

[0155] Preferably, the processing performs the sequencing in time of the codes of the visible satellites, according to a periodic or pseudo-random cycle.

[0156] The processing principles of step (116) are detailed in [Fig. 17].

[0157] The eighth step (120) consists of carrying out an estimate of the risk of cyber attack based on the successes or failures observed in the different steps of the process, which is based on logic taking into account: - authentication of the fingerprint on open signals, - decryption of data of interest, - georeferencing of the source, usable when the position and creation time are known, at least approximately, elsewhere (called geofencing), - fingerprint authentication on regulated GNSS signals.

[0158] [Fig.2] provides a description of the general principle of generating, in writing, keys spatio-temporal encryption based on the characteristics of the received GNSS signal, consisting of extracting the code phases of the GNSS signals in visibility, captured at the precise moment of creation of the message to be encrypted for transmission or recording.

[0159] The time and geographical location of the source (20) constitute the master key of the encryption due to the uniqueness of their realization when they are associated with the encryption event of the message containing the information. Such an event can be punctual, because limited to a single action (for example, the creation of a document), periodic (for example, the sending of data on a communication network), or random (for example, the sending of observation data on a mobile platform).

[0160] The time and place of the event, physical but immaterial quantities referencing the event, are characterized, according to the invention, by tangible measurements of absolute time and position delivered by the GNSS systems (23), whatever the type of constellations, the nature of the services, the nature and the frequency band of the signals.

[0161] To this end, it is necessary for the event to be physically connected to a GNSS receiver (24) capable of capturing the time and position measurements associated with it, itself connected to a GNSS antenna (22), placed in reception of the GNSS satellite signals (21) and serving as a spatial reference, whatever its relative position chosen with respect to that of the event (for example, on the roof of the building or vehicle at the origin of the event).

[0162] The absolute time measurement carried out by the GNSS receiver is linked to the instant of the event through a measurement synchronization device capable of transmitting a physical tick (33) in order to ensure precise capture of the position measurements and the date of creation of the encrypted message and the associated encryption keys. It is thus the instant of reception of the tick which must be dated precisely to allow referencing and encryption on the basis of the GNSS signals, the latency between the occurrence of the event and the arrival of the synchronization tick having little importance for this sole purpose.

[0163] The position and time of the event provided in an absolute GNSS time scale (in principle converted to UTC time) and a geodetic geographic reference system (in principle, WGS 84), delivered by a GNSS receiver (24) connected to the synchronization signal and to the antenna, make it possible to obtain the code phases of the signals received from the satellites at the antenna and at the time of reception of the synchronization signal.

[0164] The code phases are given by the GNSS times measured on each of the satellite signals received at the instant of the peak. All the satellite signals being precisely synchronized on the absolute GNSS time at transmission, by construction of the GNSS systems, the times received from the GNSS satellites are therefore delayed relative to the absolute GNSS time by the wave propagation times.

[0165] These delays depend on the distance between the satellites transmitting the signals, in orbits according to precisely known trajectories, and the receiving antenna, and include the characteristics of the ionospheric and tropospheric propagation layers, and different measurement errors linked to the receiving environment (multipath) or to the electronics (clock bias, RF bias, latencies).

[0166] On a given date, there exists, for the GNSS constellation and the selected navigation service, only a single realization of all the propagation delays of the satellite signals visible from the same reception point, the ephemerides of the satellites being perfectly known and deterministic, as well as of all the code phases of the GNSS satellite signals, these being perfectly synchronized with the GNSS time.

[0167] The GNSS constellation, the navigation service, the reception frequencies as well as the types of signal spreading code, or even the indices of the accessible satellites, constitute characteristic attributes of user classes making it possible to define different levels of access to the encryption service based on the GNSS characteristics (25).

[0168] Phase measurements of codes of satellite signals used, according to user attributes, for location and time transfer are used to develop secret keys for data encryption and signatures for message authentication.

[0169] The code phases of the multi-satellite signals received simultaneously on a given date thus constitute a set of multifactorial, unique and unfalsifiable characteristics of the imprint, inseparable from the event, defining the secret encryption keys derived from the position and time of creation of the encryption.

[0170] Knowledge of the precise ephemerides of the satellites (26) and of the correction models (27) of the propagation and electronic error sources (calibration), make it possible to link the GNSS position and time, provided by the receiver, to the GNSS times received for each of the satellite signals, with a precision of the order of a few tens of nanoseconds.

[0171] In an implementation of the invention where the GNSS receiver is external and independent of the message encryption system, the code phases can be obtained by calculation from the time and position delivered by the GNSS receiver by applying the inverse mathematical transformation (28) to that implemented by the GNSS receivers for calculating the position and time, conventionally called PVT.

[0172] The inverse transformation, called PVT *, consists of: - calculate the geometric distances in view between the antenna and the satellites on the GNSS date provided, the position of the satellites on the GNSS date being calculated from their ephemeris and the position of the antenna being that provided by the GNSS receiver, then, - deduce the corresponding propagation delays after applying the propagation and reception error models, and finally, - convert, for each of the satellites, these delays into absolute GNSS received times, at the instant of the synchronization peak, delivered by the receiver. The absolute GNSS received time is finally transformed into code phase (29) corresponding to the delay given in code chip, in real value, from the origin of the GNSS constellation time, modulo the code period (for example 1ms, corresponding to the 1023 chips of a GPS C / A code period).

[0173] In another implementation where the receiver is integrated with the device for generating the encrypted message, the receiver can instantly take the code phases of the satellite signals being tracked at the time of reception of the synchronization pulse, and provide them with the calculated position and time without having to perform an inverse transformation.

[0174] The obtained code phases, (jc_nb)GNss are said to be noise-free by misuse of language, although the measurements provided by a receiver are always affected by estimation noise, as opposed to the subsequently voluntarily noisy code phases which will serve as keys for encrypting the data (30), the principle of which is detailed [Fig.11].

[0175] In parallel with the development of the encryption keys, a fingerprint of the GNSS signal, based on the RF signal from the receiving antenna, giving access, for the different classes of users, to the characteristics of code phases used to construct the encryption keys, is captured (31) in order to ensure the authentication (32) of the encrypted message and its origin, the principle of which is detailed [Fig. 15].

[0176] [Fig.3] presents the general principle of encryption in writing, of the data of interest Based on the characteristics of the received GNSS signal. It consists of using the PRN codes and the corresponding code phases of the visible satellites as sources to encrypt the data of interest in the message to be protected at the transmitter.

[0177] The encryption (31) consists of bit-by-bit combining, at the message writing rate, the data of the message of interest, converted to binary, with the chips of the codes of the visible satellites, delayed by an integer number of chips according to the measured code phases of the signals, the codes themselves being interleaved according to a predefined or pseudo-random sequencing.

[0178] This principle, illustrated by the timing diagrams in [Fig.7], [Fig.8] and [Fig.9], is detailed in [Fig.12]

[0179] [Fig.4] shows the principle of GNSS position and time write noise at the creation of the message, (P&T)b, consisting of adding, before the calculation of the position and time by the GNSS receiver (48), a Gaussian noise to the non-noisy code phases (41), independent from one satellite to another, but with the same standard deviation, adjustable and known only to users.

[0180] The set value of the standard deviation of the added code phase noise (42) is defined by retaining an average value of the dilution of precision (called DOP) so as to cause, after application (48) of the direct transformation (PVT), an objective position and time error, sufficient to prevent the acquisition of the keys through the fingerprint transmitted by unauthorized recipients.

[0181] The random generator is initialized by a seed (43) whose knowledge makes it possible to reconstruct identically the sequence of pseudo-random draws by the authorized recipients.

[0182] The initialization of the generation of random numbers (seed) is linked to the GNSS time of creation of the message and the satellite on which the phase noise is applied.

[0183] [Fig.5] presents the general principle of reconstitution, in reading, of the encryption keys spatio-temporal based on the GNSS fingerprint stored at the creation of the message, consisting of carrying out, from the GNSS fingerprint of the RF signal captured at the creation of the message, an instantaneous acquisition, called a snapshot, of the PRN codes of the visible satellites, so as to estimate the noise-free code phase ("T"") of the signals captured in the fingerprint, at the date of creation of the message (54).

[0184] The snapshot acquisition is aided (52) from the code phases obtained by PVT 1 (51) from the noisy position and time (P&T) information provided in the container identification, in parallel with the fingerprint.

[0185] The snapshot acquisition process is detailed in [Fig. 16]

[0186] In the case where the recipient knows the germs and the random number generator used to create the message to noise the code phases of the received signals before the calculation of the position and time, the code phase noise can be reconstructed (53) for each satellite signal, and thus provide an un-noisy code phase assistance (jc_nb) to facilitate snapshot acquisition.

[0187] Since the GNSS footprint duration is reduced, the phases thus obtained (54) have an estimation noise higher than that of the receiver at the time of message creation, obtained after tracking the signals with much narrower loop filtering bands.

[0188] The resolution of the whole chip phase recalibration applied for the encryption of data by the code being limited to the width of a PRN code chip, it remains however an order of magnitude lower than the inaccuracy of estimation of the code phase obtained from the GNSS fingerprint.

[0189] During the decryption step, and to deal with cases of estimation noise surrounding the transition of an entire chip, an additional local search on the code chips located on either side of the extracted entire chip phase can be performed to remove the residual indeterminacy, allowing the possible deviation to be corrected before complete decryption of the encrypted data sequence.

[0190] [Fig.6] describes the general organization of the spatio-temporal encryption (by the message provider) / decryption (by the message recipient) processing based on the joint capture of the GNSS position and time and a fingerprint of the GNSS signal, thereby repeating the main steps of [Fig. 1].

[0191] The GNSS signal received by the GNSS antenna (61) serves as support for the acquisition of the time and position associated with the creation of the message.

[0192] The code phases (jc_nb)GNss of the tracked satellite signals are captured (62) at the precise instant of reception of the measurement synchronization signal by the receiver. The receiver generally timing its tasks on its own time base, and on sampling deadlines attached to each satellite, the code phases linked to the precise and unique date of reception of the measurement synchronization signal (called, measurement peak) must be interpolated from the framing measurements.

[0193] These code phases can optionally receive an additional bias unique to all measurements, known only to authorized users, in order to make any attempt at synchronization by a third party of the encryption code impossible.

[0194] In parallel, a slice of the digitized RF signal is taken (63) from the instant of reception of the measurement peak over a short duration greater than 1 ms to contain at least one period of the shortest GNSS PRN codes, but which may be longer, up to 20 ms, over a period of GNSS data, if the communication rate or the volume of data to be stored allows it,

[0195] The sampled code phases (jcb), which are used to calculate via a PVT the position and time information entered in the container identification, are previously noisy (65) according to the principle presented in [Fig.4], with a Gaussian noise generator whose seed is linked to time and to the satellite.

[0196] In parallel, the useful data converted into binaries are encrypted by the satellite PRN codes delayed according to the measured code phases (64), in accordance with the principle presented [Fig.4].

[0197] When reading the container, the recipient reconstructs by PVT 1 (67), the noisy code phases (jc b) from the noisy but unbiased position and time information (P&T)b, contained in the container identifier and,

[0198] These noisy code phases are then used to assist in the snapshot acquisition of the satellite signals from the GNSS signal fingerprint (68) in order to extract the unbiased and unnoisy code phase information. (^^)- In case of failure of the snapshot acquisition, neither the message authentication nor the decryption are possible.

[0199] In the case where the recipient is aware of the initialization seeds of the random generators, it is possible to denoise the code phases obtained by PVT *, and to compare them with those extracted from the GNSS fingerprint by calculating the difference in distance and time, and verify (69) that the difference remains compatible with the estimation noise on the position and time,

[0200] In the case where the recipient does not know the initialization seeds of the random generators, but knows the standard deviation of the noise, it is not possible to denoise the code phases obtained by PVT *, and the authentication (69) is only achievable with less confidence on the difference in distance and time, and this only if the standard deviation of the Gaussian noise added voluntarily by the message provider is known to the recipient. In other cases, the authentication of the container is not achievable.

[0201] Following the acquisition of the noise-free and unbiased code phases carried out from the GNSS fingerprint, it becomes possible to carry out the decryption, detailed in [Fig. 17] of the encrypted data (610) by the PRN codes delayed by the code phases by the message provider, provided however that the voluntary bias added to the phase measurements is known when constructing the message.

[0202] Finally, in the event of failure of authentication or decryption of the message by an authorized recipient, a cyber risk assessment step (611) is carried out based on the observed states.

[0203] [Fig.7] illustrates the synchronism of the GNSS signals in transmission and reception in the case of periodic codes, as well as the capture range of the GNSS fingerprint at the date to of creation of the encrypted message, in the case of different propagation delays of the satellite signals i (72), j (73) and k (74), as well as for the signal transmitted at the satellite level (71).

[0204] The classical structure of the data channel of a GNSS signal with periodic code is presented, composed of the occurrences (j) of the periodic codes Ckj(i) of the satellite (i) contained in the data Dk(i) of occurrence (k) of the GNSS message of the satellite (i).

[0205] f0) is the absolute code phase of the transmitted GNSS time-synchronized signal by satellite (i).

[0206] djo(to) is the phase of periodic codes (modulo the code length) at the emission of satellite (i) at date to, defined by:

[0207] ^îq) = modula^ Tc)

[0208] where,

[0209] t0 is the measurement time corresponding to the message creation date.

[0210] Tc is the duration of the periodic code

[0211] ^.(¾) is the absolute code phase of the signal received on the antenna, at date todans la GNSS time base, for satellite (i).

[0212] dji(t0) is the periodic code phase (modulo the code length) of the signal received on the antenna of satellite (i), function of the propagation delay, at date to in the GNSS time base, for satellite (i), defined by:

[0213] = modulc((p. ( t 0 ),

[0214] The signals captured in the capture range, common to all satellites, thus have different periodic code phases depending on the satellites and GNSS data phases whose state and transition depend on the code phase.

[0215] [Fig-8] shows the timing diagram for encrypting data by the code chips of the selected satellite, shifted from the code phase received at t0. For this, a detail (81) of the timing diagram of the previous [Fig.7] is expanded to the level of the sequencing of the code chips (82) and no longer of the code periods.

[0216] The precise measurement time t0 corresponds to a code phase delay dj;(t0) which does not correspond to an integer number k of PRN code chips Cbk(i).

[0217] (83) indicates that the first code chip retained to encrypt the binary data of the message (Mbk) corresponds to the integer value of the code phase expressed in code chip ¢.(¾).

[0218] The integer chip code phase ¢.(¾) is defined by:

[0219] ¢^ = INT(modulo(^.(t 0 ), 7^))

[0220] Step (84) represents the sequence of data bits to be encrypted, Mbk, coded #BPSK.

[0221] Step (83) represents the sequence bj(i) of chips of index (j) of the PRN code of the satellite (i), generated from the phase of integer chip code ¢(¾).

[0222] b . ( q = + $ (

[0223] Step (85) represents the data sequence of the encrypted message (Kbj) obtained after bit-by-bit multiplication of the sequences:

[0224] A7? / i) = Mbj xb / ï)

[0225] [Fig.9] shows the encryption of data in successive slices, by the sequence of code chips of the satellite associated with each of the slices, shifted at the start of each of the slices by the code phase of the corresponding satellite received at t0.

[0226] Identical to [Fig.8], the PRN code is multiplied with the bits of the binary message after PBSK conversion.

[0227] The PRN code of the same satellite (i) is applied over a time slot of limited duration (Tj). At the end of each time slot, the code of another satellite is applied to shift from the start of its phase value to the integer value of the code chip.

[0228] Step (91) represents the sequence of code chips allocated to each of the #BPSK coded time slots.

[0229] Step (92) represents the converted #BPSK message bit sequence to be encrypted.

[0230] Step (93) represents the result of the bitwise multiplication.

[0231] Step (94) represents the encrypted data slices with different PRN codes satellite

[0232] [Fig. 10] details the method of generating the identification of the useful information source, consisting of adding to the information of interest an identifier, consisting of the reference of the source and the precise GNSS position and date of creation of the encrypted message.

[0233] Step (101), the GNSS receiver performs the reception of the analog signal in the frequency bands adapted to the navigation service to be used and performs the digital conversion.

[0234] Step (102), the GNSS receiver carries out the code and carrier tracking of the visible satellite signals, over periods timed to the reception rate of each of the satellite signals received.

[0235] Step (103), the GNSS receiver captures the code phases of the satellites being tracked, at the time of reception of a message creation pulse, by performing an interpolation between the code phase measurement epochs which frame the date of reception of the pulse.

[0236] Step (104), the receiver calculates the position and time P(t0), T(t0) associated with the synchronization pulse for creating the message from the code phases interpolated at t0.

[0237] Step (105), the code phases sampled at t0 are noisy by a Gaussian noise generator initialized on a seed depending on the sampling date T(t0) and the satellite tracked.

[0238] Step (106), the GNSS receiver calculates a new PVT using the noisy code phases at to

[0239] Step (107), the identifier of the message container is made up of the reference of the source as well as the noisy position and time at T(to).

[0240] [Fig. 11] details the method of generating spatio-temporal encryption keys from GNSS georeferencing, by capturing the code phases of the GNSS signals tracked at the time of creation of the encrypted message.

[0241] Step (111) the GNSS receiver performs the reception of the analog signal in the frequency bands adapted to the navigation service to be used and performs the digital conversion.

[0242] Step (112) the GNSS receiver performs code and carrier tracking of the visible satellite signals, at epochs spaced at the reception rate of each received satellite signal.

[0243] Step (113) the GNSS receiver performs capture of the code phases of the satellites being tracked, at the instant of reception of a pulse for message creation, by performing an interpolation between the epochs of code phase measurements that bracket the date of reception of the pulse.

[0244] The noise-free code phases are used for the calculation of the true position and time; the true time is used as a seed for the generation of phase noise random numbers. The true time can be transmitted secretly to authorized recipients in order to eliminate code phase noise for the calculation of the precise position and time used to simplify authentication and decoding.

[0245] Step (114) the measured phases not voluntarily noisy are biased by an identical value for all the satellites, not disclosed to unauthorized third parties.

[0246] Step (115) the biased code phases are converted into an integer chip code phase for encryption of the data of interest.

[0247] [Fig. 12] describes a first mode of implementation of the encryption of the information of interest from the spatio-temporal keys for the purpose of transmitting the encrypted data from the creation of the container, carried out by combination between the data of interest coded in binary and the PBSK codes delayed according to the code phases captured at the time of creation of the encrypted message,

[0248] Step (121) represents an input file containing the information of interest to be protected.

[0249] Step (122) performs the binary coding of the information of interest.

[0250] Step (123) performs the reading of the binary data at the transmission rate required, clocked by the transmitter's time base (124), from the reception of the message creation pulse.

[0251] Step (125) performs the conversion of the binary coding [0,1] into #BPSK coding [+1,-1] of the data in order to perform a bit-by-bit multiplication with the chips of the PRN code performing the encryption of the data.

[0252] Step (128) performs, for the constellation and the navigation service authorized to implement the encryption, the generation of the chip sequence of the PRN code corresponding to the ID code of the satellite defined in step (127) according to the sequencing defined by the interlacing, for the current encryption slice (TK;), at the rate (Td) and synchronized with the data transmission timing (124). The chip sequence is initialized on the integer chip code phase {tBi(to)} •

[0253] Step (126) performs the bit-by-bit multiplication in #BPSK coding between the data sequence and the local PRN code, before transmission.

[0254] Step (129) performs the conversion of the resulting encrypted information into code binary.

[0255] [Fig. 13] describes a second mode of implementing the encryption of the utility information from the generated spatio-temporal keys, for recording purposes, carried out without timing constraints. The method is similar to that described in [Fig. 12] with the only difference being that the coding timing is no longer dictated by the data transmission rate, but only by the rate of the local clock (124) controlling the recording.

[0256] [Fig. 14] presents the method of capturing the GNSS fingerprint carried out after analog-digital conversion of the received GNSS signal.

[0257] Step (141), the GNSS receiver performs the reception of the GNSS signal for the frequency band corresponding to the GNSS navigation service to be implemented for encryption and authentication.

[0258] Step (142), the RF signal is digitized conventionally on 4 to 12 bits

[0259] Step (143), a pilot launches the recording precisely at the time of reception of the pulse received at the creation of the message (TMP(t0), for Time Mark Pulse in English). The precision in question reflects the synchronization difference, on the local time base of the receiver, between the time chosen to capture the code phases of the satellite signals and the time of start of taking the fingerprint.

[0260] This deviation must remain negligible compared to the duration of a GNSS signal code chip (for example, 10ns allows for compatibility with most GNSS codes and RF signal sampling frequencies).

[0261] The duration of recording of the fingerprint, controllable, is adjusted externally according to the navigation service, according to the impact on the authorized communication or recording rate (a 1ms fingerprint coded on 12 bits and digitized at 100MHz occupies a volume of 1.2 Mbits).

[0262] [Fig. 15] describes an embodiment of the multi-factor authentication of the GNSS position and time from the extracted spatio-temporal keys performing the comparison between the GNSS position and time at the creation time transmitted in clear (but possibly noisy) in the container, and the position and time estimated from the GNSS fingerprint.

[0263] The input (150) consists of the position and time calculated by the GNSS receiver from the code phases captured on the date of reception of the message creation pulse, this information possibly having been voluntarily noisy according to a Gaussian distribution of controllable standard deviation and with seeds of generation of random events linked to the non-noisy resolved time and to the satellites.

[0264] Input (151) is the GNSS fingerprint captured on the same reception date, at the output of the RF chain of the GNSS receiver.

[0265] Step (152) reconstructs, by applying the PVT * algorithm, the distances to view between the antenna and the satellites, using the known satellite ephemerides (158), from which the propagation delays are derived using the known propagation correction and satellite clock correction models.

[0266] The propagation delays make it possible to calculate the code phases corresponding to the date of reception of the message creation pulse (t0).

[0267] Step (153) performs the snapshot acquisition of the codes of the visible satellite signals by sliding correlation of the fingerprint signal with the PRN codes of the visible satellites, initialized on the code phases provided by (152), and in a search window linked to the uncertainty of the position and time estimation provided and accessible by the fingerprint over its duration, as well as to the standard deviation of position and time of the phase noise added voluntarily. The snapshot acquisition is detailed [Fig. 16]

[0268] The shifts of the correlation maxima represent the code phase difference between the code phases captured by the receiver at the date of creation of the encrypted message and the code phases extracted from the fingerprint.

[0269] Step (154) determines the observable pseudo-distances of the imprint (and not distances, the date of reception of the imprint not being perfectly aligned with the date to of instant capture, due to the shift of the snapshot time slice) antenna-satellites by axis in view, after application of the propagation correction and satellite clock correction models.

[0270] Step (155) performs the calculation of the pseudo-distance deviations per axis in view.

[0271] Step (156) performs the calculation of the position deviation and the residual time deviation at from the visual pseudo-distance deviations, by applying the direct PVT algorithm.

[0272] Step (157) performs the evaluation of the compatibility between the position and time differences relative to the estimation error margins and the deliberately added noise.

[0273] [Fig. 16] describes an embodiment of snapshot acquisition of code phases from the GNSS footprint, assisted by the GNSS position and time transmitted in the container, in the case of a GNSS signal containing navigation data involving coherent integration alignment of the correlation on the data transitions of the GNSS message.

[0274] A difficulty of snapshot acquisition carried out on a capture of the received GNSS signal is related to the fact that the data of the messages carried by the GNSS signal can create phase jumps that compromise the performance of correlation-assisted acquisition.

[0275] It is therefore necessary to identify, prior to the sliding correlation search, the expected position of each of these transitions (predictable from the resolved GNSS positions and times, possibly noisy, provided in the container), making it possible to carry out the coherent integration of the correlation by parts, then to sum inconsistently, so as to minimize estimation loss.

[0276] Input (160) corresponds to the expected code phases obtained from the resolved GNSS position and time transmitted by the container, already presented in [Fig.15].

[0277] Input (161) is the resolved GNSS position and time transmitted by the container.

[0278] Input (162) is the GNSS fingerprint.

[0279] Step (163) generates the local code associated with the satellite signal to be acquired, sampled at the same frequency as the fingerprint signal, the search code phase being defined in a delay domain surrounding the expected code phase.

[0280] Step (164) performs the estimation of the data transition epoch within the duration of the fingerprint from the prediction of the received code phase obtained by application of the PVT 1 algorithm (identically to step (152) of [Fig.15]).

[0281] The absolute code phase ^.(¾) (relative to the GNSS time origin) received at date to is converted modulo the duration (TD) of a GNSS data period, thus providing the position of the received code phase relative to the start of the current GNSS data. It is then checked whether or not the next data transition falls within the fingerprint collection duration (TE,) by testing whether ôq> the remaining phase increment after t0 is less than the fingerprint duration:

[0282] -TD~ modul(^(p c (j Q ),T D )

[0283] Yes oh <pD <Te alors Bip est converti en phase de code.

[0284] If Tb is the code chip period, the code phase corresponding to the next data transition expressed in code chip, is:

[0286] Step (165) then performs the coherent integration by parts:

[0287]

[0288] F c_(^ ) - J o E(t). C (t- d(p]dt ( TE F c+ (ô(p) C\t-ô(p)dt

[0289] Step (166) performs the non-coherent integration, the expression of the correlation function is then:

[0290] |2+ \Fc+(ô(p) |2

[0291] where,

[0292] E(t) is the fingerprint signal

[0293] C(t) is the code of the satellite signal considered

[0294] Bip is the phase shift introduced for scanning the uncertainty domain

[0295] Step (167) determines, for each of the visible satellites, the code phase deviation Oh <p . existant entre la phase de code mesurée par le récepteur et extraite l’empreinte recherche du maximum corrélation balayage décalage :

[0296] - Maxg^Fc ( ^(p )

[0297] [Fig. 17] summarizes a possible, but not unique, overall embodiment of the decryption of useful information from the spatio-temporal keys, obtained by extracting the code phases of the signals from the GNSS fingerprint.

[0298] Step (171) performs the estimation of the noisy code phases at time t0 by PVT 1, from the GNSS position and time, noisy before transmission in the container.

[0299] Step (172) tests the availability of the seed of the added noise random generator.

[0300] If the initialization seed is available, step 173 performs the denoising of the code phases with the random generator initialized with these seeds, and provides the unbiased code phases at t0.

[0301] If the initialization seed is not available, step (174) performs the estimation of the noise-free code phases by snapshot acquisition from the GNSS fingerprint, in accordance with the description of [Fig. 16], and provides the unbiased code phases estimated at t0.

[0302] Step (176) performs the conversion of the code phase into whole chips for each of the satellites visible at to, considered as the spatio-temporal encryption keys to be taken into account to perform the decryption of the encrypted data of interest.

[0303] Step (177) performs, according to the satellite designated as a function of the coding frame of the satellites in step (1710), the generation of the PRN code shifted by the corresponding integer chip code phase, at the rate of the data restitution clock.

[0304] In parallel, step (178) reads the encrypted data of interest, previously converted into #BPSK coding, at the same rate.

[0305] The two sequences can then be multiplied bit by bit in step (1711) and, after conversion to binary, provide the decrypted information of interest (1712)

[0306] [Fig. 18] describes a particular, but not exclusive, method of cyber risk assessment based on the success of authentication and decryption operations according to the nature of the GNSS signals implemented.

[0307] Step (181) prioritizes the success of the authentication carried out on the fingerprint using open GNSS signals. A failure of the authentication leads to suspecting an attack by falsification of the position and / or time contained in the message identifier.

[0308] In case of success, step (182) checks the success of the decryption of the information of interest. A failure of the decryption of the data following a success of authentication leads to suspicion of falsification of the identification by copying a valid identification from another message, or reconstitution of a coherent imprint of the position and time transmitted, but without having been able to access the data.

[0309] If successful, step (183) verifies (an operation called Geofencing) that the position and time transmitted in the identifier are consistent with information known to the supplier (fixed antenna position, predefined creation date, sending on other communication channels), thereby revealing risks of receiving signals from GNSS repeaters (called Meaconing in English).

[0310] A failure leads to suspecting a risk of deception of open GNSS signals, all information and data remaining coherent although false.

[0311] In case of success, an additional verification step (184) makes it possible to remove the doubt, by carrying out the authentication of the GNSS fingerprint from the encrypted or regulated signals contained therein, by the authorized users. The suspicion of deception of the open signals can be confirmed in the event of failure of the authentication using the encrypted signals.

[0312] [Fig. 19] describes a preferred but non-limiting implementation of the system used, in transmission, for identification and encryption by spatio-temporal encryption in writing, implementing a GNSS positioning receiver and associated calculation means to carry out the encryption processing.

[0313] The system implemented in transmission comprises a GNSS receiver and a specific processing module, preferably entirely software (SW) and installed in the communication system in parallel with the GNSS receiver, or a specific hardware (HW) module (called add-on in English) allowing encryption operations to be carried out in a protected manner by HW wired processing.

[0314] The system described implements: - (191) a GNSS antenna - (192) a GNSS receiver - (193) the receiver's local PRN code generation module, which can be activated at the request on external requests - (195) a SW and / or HW add-on performing authentication and encryption of data of interest (194) to be transmitted or recorded according to the principles of the invention, and delivering to the recipient the container containing the encrypted information (197) - (196) a sub-module carrying out the encryption of the message of interest by the codes GNSS out of phase

[0315] [Fig.20] describes a preferred but non-limiting implementation of the system used, in reception, for authentication and decryption by spatio-temporal encryption in reading, implementing a GNSS receiver and associated calculation means for carry out the decryption processing.

[0316] The system implemented in reception comprises a GNSS receiver, responsible for generating local PRN codes on external command, and a specific processing module which can be entirely software (SW) and installed in the communication system in parallel with the GNSS receiver, or a specific hardware (HW) module (called add-on in English) making it possible in particular to accelerate the snapshot acquisition operations from the GNSS footprint by HW wired processing in addition to the task control operations carried out by SW.

[0317] Note that a single HW module, defined as configurable, allows encryption and decryption operations to be carried out with the same interface definition with the GNSS receiver.

[0318] The system described implements: (201) a GNSS receiver (202) the receiver's local PRN code generation module, which can be activated on demand following external requests (204) an SW and / or HW add-on performing the authentication and decryption of the encrypted data (203) to be transmitted or recorded according to the principles of the invention, and delivering the decrypted and authenticated information to the recipients (206) (206) a sub-module performing decryption using synchronized phase-shifted PRN codes Possible industrial applications of the invention

[0319] Many services and industrial application fields requiring the protection of the integrity of their data and the authentication of their source with simplified cybersecurity procedures can benefit from and take advantage of the advantages of the invention, in particular, but not limited to; systems used for issuing references to documents or certified acts for timestamping, or carrying out an authentication audit of transactions, devices providing tachograph information, enabling the status and movement history of vehicles to be checked, devices for identifying and protecting observation transfers transmitted by robots and drones, the protection of personal communications and archives.

[0320] Authorities accredited for the use of regulated GNSS navigation services can also offer a transaction audit service by securely verifying their authenticity, or even assessing possible cyber attacks. List of cited documents

[0321] [Dl] EP 2 674 779 - Marc Revol; “Satellite radionavigation system with remote architecture”, filing date: 13.06.2013

[0322] [D2] EP 2 790 035 - Marc Revol; “Method and device for compressing a signal broadband radionavigation, associated method and device for calculating the correlation function of the spreading code of said compressed signal", filing date: 07.03.2014

[0323] [D3] - Alexander Rugamer, Manuel Stahl, Ivana Lukcin, Gunter Rohmer - Fraunhofer IIS Nuremberg, Germany, “Privacy Protected Localization and Authentication of Georeferenced Measurements using Galileo PRS”, published in the Pro-ceedings of IEEE / ION PLANS 2014 May 5 - 8, 2014

[0324] [D4] - Marc Revol - Thaïes Avionics, “Distant positioning for GNSS securing”, published in the Proceedings of ENC 2015 - session 08 - April 8-10, 2015

[0325] [D5] - Marc Revol - Thaïes Avionics, "Compressing a wide band radio-navigation signal and method for calculating the correlation function for remote positioning” Navitech 2016 - Proceeding ISBN: 978-1-5090-3885-5 / P02-14-16 December 2016 -ESA / ESTEC, The Netherlands

Claims

Claims

1. Authentication and encryption method, called spatio-temporal encryption, without a dedicated third-party authority to generate the access keys, applied for the protection of information of interest in order to guarantee the origin and integrity of the data, for the purpose of recording or transmission, exploiting the positioning and precise dating accessible via GNSS signals, said spatio-temporal encryption method consisting of: - Stamp the container of the information of interest with the reference of the source and the position and date of its creation, - Protect access to information of interest by encryption linked to the position and date of creation, - Noise the position and creation date transmitted in such a way as to make this information unusable by third parties, the spatio-temporal encryption method being characterized in that the authentication factors and the encryption keys of said method depend on user-specific attributes, uniquely defined from the access privileges to the GNSS navigation services and the code phases of the GNSS signals received at the time and place of creation of the protected file, called the container, said container consisting of the following information: - An identifier, characteristic of the container, uniquely referencing the noisy source, position and date of creation, added to the information of interest, - The encrypted information of interest, resulting from the encryption of the initial information of interest based on the code phases of the GNSS signals captured at the time and place of creation of the container, - A short time sequence of the GNSS signal received at the time and place of creation, called the GNSS fingerprint of the source, used for multi-factor authentication of the identifier and decryption of the encrypted information of interest, Said spatio-temporal encryption method comprising the steps

2. following when creating the container: - Identification of the source of information (106), - Generation of spatio-temporal encryption keys from GNSS georeferencing (108), - Encryption of the information of interest from the generated spatio-temporal keys (110), - Capture of the GNSS fingerprint used to protect the spatio-temporal keys to be transmitted (112), Said spatio-temporal encryption method comprising the following steps when reading the container: - Extraction of spatio-temporal keys from the GNSS fingerprint (114), - Multi-factor authentication of GNSS position and time from spatio-temporal keys extracted from the GNSS fingerprint (116), - Decryption of the information of interest from the extracted spatio-temporal keys (118), - Cyber ​​risk assessment in case of container reading failure (120). method, according to claim 1, of encrypting the information of interest by combining the initial data coded in binary [1,0], by at least one of the pseudo-random codes of the GNSS signals, called PRN codes for Pseudo-Random Noise in English, continued in reception at the instant t0 of creation of the encrypted message, for the constellation and the navigation service chosen, said combination consisting of multiplying bit by bit the sequence of initial data of interest by the sequence of chips of the PRN code, of a periodic or aperiodic nature, depending on the navigation service implemented in the method, Said multiplication being characterized in that: - It is applied on the binary coded input data of interest after their conversion into #BPSK [+1,-1] coding, for Binary Phase Keying in English language, the chips of the local PRN codes being already #BPSK coded, - The local PRN codes applied, specific to the navigation service used, are each delayed before multiplication by an integer number of chips as close as possible to the code phase of the corresponding received satellite signal (115), taken at time t0, possibly shifted by an arbitrary hidden value, called phase offset (114), - The different local PRN codes are applied, according to a cyclic or random sequencing, called interlacing, in slices of the same length over the entire length of the data of interest, Said encryption method comprising the following steps for the constitution of the encrypted data sequence: - Selection of constellation and navigation service according to user attributes, - Identification of GNSS satellites tracked at time t0 (112), - Capture of periodic or aperiodic code phases, depending on the navigation service chosen and the satellites tracked at time t0 (113), - Reading of the binary data to be encrypted at the chosen data recording or transmission rate (123), - Conversion of binary data into #BPSK (125) encoded data, - Sequencing of local satellite codes to be applied in successive time slots to carry out encryption by satellite codes according to said interlacing defined to contribute to the encryption of the data (127), - For each time slice, alignment of the origin of the generation of the code sequences according to the code phases captured at time t0 and a possible voluntary phase offset (128), - Bit-by-bit multiplication at the chosen recording or transmission rate between the #BPSK coded data and the #BPSK code chips (126), - Conversion of multiplication outputs into binary coded data (129).

3. Method, according to claim 1, said method of authenticating the origin of said container, implementing the noisy transmitted GNSS position and date as well as the GNSS fingerprint representative of the characteristics of the GNSS signal received at the time of creation and added to the container, said GNSS fingerprint consisting of a slice (143) of the digitized GNSS signal at the output of the GNSS reception RF stage (142), filtered in a reception band of the GNSS signal (141) compatible at least with the frequency spread containing the code of the navigation service implemented, said authentication method being characterized in that: - The code phases of the visible GNSS signals are extracted from the fingerprint, consisting of a short slice of the GNSS signal of a few milliseconds, captured at the time of creation of the encrypted message (151),- The code phases extracted from the fingerprint are used to estimate the deviations between the positions and times of capture of the fingerprint and creation of the container, the ephemerides of the satellites being known data provided elsewhere by the GNSS system (156), - The position and time deviations calculated from the code phases extracted from the fingerprint (154) and the code phases corresponding to the position and time transmitted in the container (152), after correction of the noise voluntarily added when it is known to the recipient, are evaluated with regard to the distribution of the GNSS standard errors depending on the precision of the GNSS navigation service implemented and the duration of the fingerprint (157).,

4. Method, according to claims 1 and 3, for extracting the phases of codes used for authentication, from the GNSS fingerprint captured on the date of creation of the encrypted message, consisting of an instantaneous acquisition (52), called snapshot in English, of the codes of the satellites visible over the sole length of the fingerprint, aided by the phases of codes corresponding to the noisy GNSS position and time (51) transmitted in the container, said snapshot acquisition being characterized in that: - The position of the satellites at the time of creation of the message, provided in GNSS time in the container, is calculated from the known ephemerides of the GNSS satellites for the navigation service implemented in reception, - The acquisition of the GNSS footprint code phases is carried out over a GNSS time exploration range framing the expected code phases of the visible satellites, the footprint start date being initialized on the transmitted creation time: • If the model for generating the position and time noise hazards used for writing is known and applied, the code phases expected for reading are calculated by inverse PVT transformation from the noisy position and time provided by the container and the calculated positions of the satellites (51), then corrected by the values ​​of the hazards generated from the same seed as in writing, based on the GNSS message creation time (53), • If the model for generating position and time noise hazards used for writing is not available, the expected code phases are calculated by inverse PVT transformation from the noisy position and time provided by the container and the calculated positions of the satellites, - The acquisition of the phase of each of the codes of the fingerprint is carried out by scanning the delay applied to the local code (163) in the exploration range (168) as a function of the residual standard deviation of the phase noise hazards, to search for the date of best correlation (166) between the code of the fingerprint signal (162) and the synchronized local code, in a delay range located around the delay corresponding to the expected code phase (160).

5. Method, according to claims 1 and 2, for decrypting data of interest encrypted by the local codes aligned with the code phase of the signals received at the time of creation of the encrypted message, and of a possible additional phase offset, depending on the generation model of the position and time noises introduced at the creation of the encrypted message (172), characterized in that: - The constellation and navigation service to be used to perform the decryption of the data of interest are identical to those used to perform the encryption, - The noisy code phases are calculated by inverse PVT transformation (171), for the date of creation of the encrypted message, from the noisy position and time contained in the container, on the basis of the ephemerides of the satellites of the GNSS satellite constellation, and the propagation error correction and clock models used for tracking the satellite signals in reception, - If the model for generating position and time noises used during writing is known and applied, the code phases to be used for decrypting data encrypted by local codes are previously corrected (173) using the same noise random generation algorithm initialized with the same seed as those used for the noisy position and time when creating the message, - If the generation model of the position and time noises used in writing is not known, the extraction of the code phases is carried out from the GNSS fingerprint captured on the date of creation of the encrypted message, by snapshot acquisition of the codes (174), aided by the code phases corresponding to the noisy GNSS position and time transmitted in the container, - The calculated code phases, shifted by the phase offset possibly introduced in the encryption (175), are used to adjust the delays of the local codes of an integer number of chips (176) as close as possible to the code phases of the corresponding received satellite signals, at time t0, - The encrypted interest data (179) is decrypted by bitwise multiplication between the encrypted interest data and the delayed local PRN codes (177), chosen according to the sequencing (1710), cyclic or random of local codes, defined by the encryption interlacing, Said decryption method comprising the following steps for the constitution of the sequence of decrypted data: - Selection of the constellation and the navigation service used for encryption, - Identification of the GNSS satellites tracked at time t0, - Calculation of the phases of periodic or aperiodic codes, according to the chosen navigation service, of the satellites tracked at time t0, by inverse PVT transformation from the position and the transmitted creation time, - Reading of the binary data to be decrypted at the chosen rate of recording or transmission of the data, - Conversion of the binary data into #BPSK coded data,- Sequencing according to the interlacing of the local satellite codes to be applied by successive time slots to carry out the decryption by the encrypted satellite codes according to said interlacing, - For each time slot, alignment of the origin of the generation of the code sequences according to the code phases calculated at time t0 by inverse PVT transformation of the position and creation time received and the possible addition of a phase offset, - Bit-by-bit multiplication, at the chosen recording or transmission rate, between the #BPSK coded data and the #BPSK code chips, - Conversion of the multiplication outputs into binary coded data.,

6. A method, according to claims 1, 3 and 4, for adjusting the security level of authentication by selecting the constellation and the GNSS navigation service, robust to signal deception, said method for adjusting the security of authentication consisting of extracting the code phases from the GNSS fingerprint using, for the

7. accredited users or authorities, an encrypted GNSS navigation service a priori not accessible to the anticipated threat, the process being characterized in that: - The GNSS footprint, when taken in a wide band, captures the signals of all constellations and all associated navigation services, - The constellation used to perform authentication from the fingerprint (158) is chosen according to the geographical availability of the constellation and the approval provided by the authority guaranteeing the use of GNSS navigation services, - Verification (157), which requires access keys to encrypted GNSS signals, can be carried out directly by the user if he is accredited or by an authority mandated to carry out the confirmation. Method, according to claims 1 to 6, for validating the decryption of the data of interest after decryption, and for evaluating the risk of cyber attack in the event of failure (611), characterized in that: - A failure of the authentication of the fingerprint (181) implies a falsification, by intrusion of the container, of the position or the creation time transmitted in the container, inconsistent with the fingerprint, - In case of successful authentication, a failure to decrypt the data of interest (182) implies a falsification, by intrusion of the container, of the position and time of coherent creation of the fingerprint, incoherent of the interlacing and the phases of the data encryption code, - If the decryption of the data of interest is successful, a so-called Geofencing test (183), consisting of verifying, when the information is available elsewhere, that the expected position and creation time correspond to the identification information available in the container. A failure of the Geofencing verification is indicative of deception of the GNSS signals at reception on the antenna, for example by superposition of signals created by simulation of signals from constellation (accessible for open navigation services), - Finally, an ultimate check (184), consists of checking the authentication of the fingerprint based on regulated encrypted GNSS signals, via an authority accredited to have the encryption keys for the GNSS signals. A failure of authentication by encrypted GNSS signals is indicative of a targeted attack on the area where secure recordings or communications are implemented.

8. Encryption and decryption device guaranteeing the origin and integrity of information of interest for the purpose of recording or transmission, implementing the methods of claims 1 to 7, characterized in that it comprises: - A GNSS reception antenna (191), - A single or multi-constellation GNSS receiver capable of processing one or more navigation services in parallel and of taking a slice of RF signal, called a snapshot, upon receipt of an external command, and of providing the code phases of the satellites visible at that moment (192), - For the creation of the protected container, a processing module (193) and software interfaced with the GNSS receiver (195), configured in encryption, capable of carrying out the processing of identification of the container and encryption of the information of interest to be recorded or transmitted, - For reading the container, a processing module (204) and software,configured in decryption (205), capable of carrying out the container authentication and decryption processing of the recorded or transmitted information of interest.,

9. Encryption and decryption device for recording or transmission purposes according to the preceding claim 8, for which the GNSS constellation used is the Galileo constellation, and the navigation services implemented use the signals of the open service (called OS) and the encrypted signals of the commercial service (called CS) or of the regulated service (called PRS)

10. Device for authenticating information of interest according to claims 3 and 4, at the service of an accredited third-party authority, making it possible to validate the origin and content of the data of interest with at least one additional level of security compared to that provided by the nominal device, characterized in that the authentication provided by the service is based respectively on: - On encrypted CS or PRS signals of the Galileo constellation, if the nominal service implements only open GNSS signals, - On encrypted PRS signals of the Galileo constellation, if the nominal service only implements commercial GNSS signals (of the CS Galileo type), - On signals of constellations different from the constellation implemented by the nominal service, if it only implements one constellation.