Cloud-based GNSS spoofing alert and detection

A cloud-based system processes GNSS data to detect and alert aircraft crews to spoofing events, addressing real-time detection challenges and improving aviation safety by leveraging EFB tablets and deep learning for anomaly detection.

GB2639682APending Publication Date: 2025-10-01SPIRENT COMMUNICATIONS PLC
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
GB2024006732
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-21
Filing Date
2024-05-13
Publication Date
2025-10-01

AI Technical Summary

Technical Problem

The aviation industry faces a growing threat from GNSS spoofing and jamming events, leading to navigation failures, safety risks, and increased flight cancellations and delays, affecting critical systems like ADS-B and GPWS/TAWS, with existing systems struggling to detect and mitigate these events in real-time.

Method used

A cloud-based alert system processes GNSS data from multiple sources, including ADS-B and external GNSS receivers, to detect spoofing events and provide timely alerts to aircraft crews through EFB tablets, utilizing deep learning for anomaly detection and analysis.

Benefits of technology

Enhances situational awareness and safety by promptly identifying GNSS interference, enabling timely responses and reducing the impact of spoofing events on aircraft navigation and air traffic control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A process of cloud processing for global navigation satellite system (GNSS) interference data from a plurality of GNSS receivers to alert aircraft personnel to GNSS spoofing of aircraft guidance systems. The method including receiving at a cloud based server, GNSS interference data from plural GNSS receivers including one or more of certified avionics GNSS receiver on an aircraft, and external GNSS linked to an electronic flight bag tablet device, cellular networks, automatic dependent surveillance broadcast networks or dedicated GNSS monitoring facilities. The process analysing the GNSS interference ata involving one or more of comparing a set of GNSS data for a particular aircraft to plural operational limitations for the aircraft, comparing a first set of GNSS data to a second set of GNSS data, the two being received independently from different independent receivers onboard the same aircraft or comparing first and second sets of data for a first and second aircraft. Identifying an interference event where an anomalous flight path characteristic of an aircraft o an anomalous signal characteristic is identified. Where an interference event is identified, the cloud based server provides an alert to EFB tablet devices onboard the aircraft notifying aircraft personnel of a potential spoofing event.
Need to check novelty before this filing date? Find Prior Art

Description

Inventors: Jeremy Charles Bennington Paul Hansen Daniel Tillett PRIORITY

[0001] This application claims priority to U.S. Provisional Application No. 63 / 568,400 titled “Cloud-Based GNSS Spoofing Alert and Detection,” filed 21 March 2024 (Attorney Docket No. SPIR 1175-1). The priority application is incorporated by reference for all purposes. RELATED CASES

[0002] This application is related to the following commonly owned applications:

[0003] U. S. Application No. 17 / 948,171 titled “GNSS Forecast Impacting Receiver Startup,” filed 19 September 2022 (Attorney Docket No. SPIR 1169-2); and

[0004] U.S. Application No. 17 / 948,176 titled “GNSS Forecast and Spoofing / Jamming Detection,” filed 18 September 2022 (Attorney Docket No. SPIR 1169-3), which claims the benefit of U. S. 63 / 407,589 titled “Accuracy of a GNSS Receiver That Has a Non-Directional Antenna, filed 16 September 2022 (Attorney Docket No. SPIR 1169-1).

[0005] U. S. Application No. 17,948 / 182 titled “GNSS Forecast and Background Obscuration Prediction,” filed 19 September 2022 (Attorney Docket No. SPIR 1169-4); and

[0006] U. S. Application No. 17 / 948,171 titled “GNSS Forecast and Line of Sight Detection” filed 19 September 2022 (Attorney Docket No. SPIR 1169-5); and

[0007] U. S. Application No. 17,948 / 182 titled “Utilizing GNSS Risk Analysis Data for Facilitating Safe Routing Of Autonomous Drones” filed 19 September 2022 (Attorney Docket No. SPIR 1164-2); and

[0008] U. S. Application No. 17 / 948,218 titled “Generating and Distributing GNSS Risk Analysis Data for Facilitating Safe Routing Of Autonomous Drones” filed 19 September 2022 (Attorney Docket No. SPIR 1164-3).

[0009] The related applications are incorporated by reference for all purposes. INCORPORATIONS

[0010] The following materials are incorporated by reference for all purposes as if fully set forth herein:

[0011] U.S. Application 17 / 374,882 entitled “Accuracy Of A GNSS Receiver That Has a Non-Directional Antenna,” (Attorney Docket No. SPIR 1139-5) filed 13 July 2021 and

[0012] US Application No. 17 / 374,891, titled “Path Planning Using Forecasts Of Obscuration And Multipath” filed 13 July 2021 (Atty Docket No, SPIR 1139-6); and

[0013] Recommendation ITU-RP.681-11 (08 / 2019), Propagation data required for the design systems in the land mobile-satellite service; and

[0014] Recommendation ITU-RP.681-11 (08 / 2019), Propagation data required for the design systems in the land mobile-satellite service; and

[0015] Report ITU-R P.2145-2, (09 / 2017), Model parameters for the physical-statistical wideband model in Recommendation ITU-R P.681; and

[0016] Recommendation ITU-RP. 1407-7, (08 / 2019), Multipath propagation and parameterization of its characteristics; and

[0017] GB Application No. Ill 1305.7, titled Recording, Storage and Playback of GNSS Signals, , filed 4 July 2011, now GB Patent No. 2492547, issued 7 November 2018 (Atty Docket No. SPIR 1134-1GB); and

[0018] US Application No. 13 / 786,020, titled System and Method for Testing Real World A-GNSS Performance Of A Device, filed 5 March 2013, now US Patent 9,519,063, issued 13 December 2016 (Atty Docket No. SPIR 1071-1); and

[0019] Federal Aviation Administration (FAA) Technical Standard Order (TSO)-C199 for Traffic Awareness Beacon System (TABS) FIELD OF THE TECHNOLOGY DISCLOSED

[0020] The technology disclosed relates to data processing, aircraft, navigation and relative location. The technology disclosed provides for electrical computers, digital data processing systems, and data processing processes for transferring data between a plurality of computers or processes wherein the computers or processes employ the data before or after transferring and the employing affects the transfer of data therebetween.

[0021] In particular, the technology disclosed relates to using a cloud-based alert system for processing GNSS reported positions to detect a GNSS spoofing event and alerting aircraft crew of the detected GNSS spoofing event. BACKGROUND

[0022] The subject matter discussed in this section should not be assumed to be prior art merely as a result of its mention in this section. Similarly, a problem mentioned in this section or associated with the subject matter provided as background should not be assumed to have been previously recognized in the prior art. The subject matter in this section merely represents different approaches, which in and of themselves may also correspond to implementations of the claimed technology.

[0023] Aircraft require accurate global navigation satellite system (GNSS) data (e.g., GPS, GLONASS, Galileo, etc.) to function efficiently and safely. However, the aviation industry is experiencing an increased number of GNSS spoofing or jamming events (referred to collectively as GNSS interference events), leading to an increase in safety risk and rates of cancel led / delayed flights. In one example, GNSS spoofing events have occurred in regions over Russia, Bulgaria, Poland, Romania, Turkey, Israel, and Pakistan. In another example, certain delays and cancellations at U.S. commercial airports in recent years have been attributed to GNSS interference events.

[0024] Certified avionics systems relying on GPS LI are vulnerable to many types of failures as a consequence of a GNSS interference event. In response to GNSS spoofing or jamming attacks, certified avionics systems may experience a navigation fail or reversion event. Position information reported via Automatic Dependent Surveillance-Broadcast (ADS-B) may incorrectly locate the plane’s position, impacting other aircraft crews and air traffic control (ATC). The impact of incorrect ADS-B reporting may extend to channels, weather, air traffic, etc. Incorrect position and altitude data may impact Ground Proximity Warning Systems (GPWS) and Terrain Awareness and Warning Systems (TAWS). Other areas of risk include inconsistencies with and potential resetting of an inertial navigation system (INS). Also autopilot failures, attitude and heading reference system (AHRS) failures, and heading indicator failures. Collectively, such problems related to positioning, navigation and timing (PNT) technology have a significant impact on commercial / civil aviation as well as the defense sector.

[0025] An opportunity arises for providing a cloud-based alert system for processing GNSS data to detect spoofing events and alert aircraft crews in-flight, as well as ATC and other GNSS users, of detected spoofing events. The disclosed technology can aid in preventing atypical PNT errors and corruption of PNT sources, detecting atypical errors or anomalies of PNT sources, responding quickly and appropriately to detected atypical errors or anomalies (including by reporting, mitigation, and / or containment mechanisms), and recovering from atypical errors in order to return to a proper working state and defined performance. The disclosed technology can improve both real time and route planning for both terrestrial and airborne vehicles, by providing improved information about the potential GNSS interference events affecting the reliability of GNSS signal data. SUMMARY

[0026] The technology disclosed involves a distributed network and methods for cloud processing of ADS-B data, GNSS signal data, and other forms of GNSS interference data to alert aircraft personnel to GNSS spoofing of aircraft guidance systems. The technology disclosed can be implemented using a cloud-based server of a cloud-based alert system receiving data from one or more sources. Useful data includes ADS-B integrity, track, and position data, GNSS integrity data, GNSS signal data, GNSS interference data, and other forms of PNT data. These data are evaluated to detect a potential GNSS spoofing event and alert onboard aircraft personnel of the GNSS spoofing (or a potential of GNSS spoofing) via an Electronic Flight Bag (EFB) tablet device onboard the aircraft.

[0027] Particular aspects of the technology disclosed are described in the claims, specification and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The included drawings are for illustrative purposes and serve only to provide examples of possible structures and process operations for one or more implementations of this disclosure. These drawings in no way limit any changes in form and detail that may be made by one skilled in the art without departing from the spirit and scope of this disclosure. A more complete understanding of the subject matter may be derived by referring to the detailed description and claims when considered in conjunction with the following figures, wherein like reference numbers refer to similar elements throughout the figures.

[0029] The patent or application file contains at least one drawing executed in color. Copies of this patent or patent application publication with color drawing(s) will be provided by the Office upon request and payment of the necessary fee. The color drawings also may be available in PAIR via the Supplemental Content tab.

[0030] FIG. 1 shows an example architecture for cloud processing of GNSS data to alert aircraft personnel to GNSS spoofing of aircraft guidance systems, according to one implementation of the disclosed technology.

[0031] FIG. 2 shows an example schematic of GNSS spoofing of aircraft guidance systems.

[0032] FIG. 3 shows a block diagram for various cloud-based approaches of processing GNSS data to alert personnel to GNSS spoofing of aircraft guidance systems, according to one implementation of the disclosed technology.

[0033] FIG. 4A shows a block diagram for GNSS spoofing detection using an external GNSS receiver, according to one implementation of the technology disclosed.

[0034] FIG. 4B shows a block diagram for GNSS spoofing detection using an external GNSS receiver and a cloud-based alert system for GNSS spoofing detection and notification.

[0035] FIG. 4C shows a block diagram for GNSS spoofing detection using an external GNSS receiver, ADS-B receivers, a cloud-based alert system for GNSS spoofing detection and notification.

[0036] FIG. 4D shows a block diagram for GNSS spoofing detection using GNSS data obtained from certified avionics and a cloud-based alert system for GNSS spoofing detection and notification.

[0037] FIG. 4E shows a block diagram for GNSS spoofing detection using GNSS data obtained from a plurality of GNSS receiver sources and a cloud-based alert system for GNSS spoofing detection and notification.

[0038] FIG. 5 shows a block diagram for a distributed network configured to analyze global navigation satellite system (GNSS) interference data from a plurality of GNSS receiver sources to detect spoofing events impacting a plurality of aircraft. DETAILED DESCRIPTION

[0039] The following detailed description is made with reference to the figures. Sample implementations are described to illustrate the technology disclosed, not to limit its scope, which is defined by the claims. Those of ordinary skill in the art will recognize a variety of equivalent variations on the description that follows.

[0040] Aircraft navigation often depends on positioning information from satellite constellations, such as GPS, GLONASS, Galileo, and GNSS more generally. In recent years, the aviation industry has experienced a concerning rise in the occurrence of GNSS interference events, including spoofing and jamming incidents. These events pose significant safety risks and lead to heightened rates of flight cancellations and delays.

[0041] Increasingly, GNSS interference events are being reported in various regions globally, causing disruptions and safety hazards. Both position and altitude reporting are impacted. The impact extends beyond mere inconvenience, as these events can result in navigation failures, ADS-B malfunctions affecting aircraft crews and air traffic control, and failures of critical systems like Ground Proximity Warning Systems (GPWS) and Terrain Awareness and Warning Systems (TAWS). Such failures compromise the integrity of aircraft navigation technology, affecting both commercial and defense sectors.

[0042] To address this critical issue, there is a pressing need for a solution that can effectively detect and mitigate GNSS interference events in real-time. The disclosed cloud-based alert system presents a promising opportunity to process GNSS data and detect spoofing events promptly, rather than retrospectively using historical data. By leveraging cloud technology, this solution can provide timely alerts to aircraft crews, air traffic control, and other GNSS users, enabling them to take necessary precautions and mitigate risks associated with spoofing.

[0043] The technology disclosed includes systems and methods to prevent atypical GNSS errors and corruption of GNSS sources, detect anomalies or errors in GNSS data, respond swiftly to detected anomalies, and recover from errors to restore proper functionality. By offering improved real-time information and route planning capabilities, this solution enhances the reliability of GNSS data for terrestrial and airborne vehicles.

[0044] The technology disclosed integrates with existing Electronic Flight Bag (EFB) systems, such as tablet devices like the Apple iPad™ running applications such as Foreflight, commonly used by pilots for navigation and situational awareness. Leveraging the EFB platform, the solution can provide alerts directly to aircraft crews without requiring complex certification or integration processes. This immediate notification empowers crews to differentiate between GNSS interference events and equipment failures, enabling them to take appropriate actions to ensure safety.

[0045] Furthermore, the solution utilizes GNSS receivers, which are not part of certified avionics, to detect spoofing events independently. The receivers can be built into a tablet or linked to a tablet. The tablet transmits data from these receivers to cloud-based servers for analysis, allowing for the identification of anomalous signal characteristics indicative of spoofing. The certified avionics also transmit data to ADS-B networks that can be utilized. By combining data from multiple sources, including ADS-B networks and cellular networks, the system enhances its detection capabilities and provides comprehensive coverage.

[0046] In addition to detecting spoofing events, a cloud-based spoofing alert system offers an approach for analyzing GNSS interference data and tracking identified events over time. This capability enables collaborative analysis across multiple GNSS receivers, enhancing the understanding of spoofing threats and their impact.

[0047] The technology disclosed provides a solution towards addressing the growing threat of GNSS interference in aviation. By leveraging cloud-based processing and integrating with existing EFB systems, the solution enhances situational awareness and enables timely response to spoofing events, ultimately contributing to the safety and efficiency of air travel. Acronyms

[0048] Acronyms used in this disclosure are identified the first time that they are used. These acronyms are terms of art, often used in standards documents. Except where the terms are used in a clear and distinctly different sense than they are used in the art, we adopt the meanings found in testing standards. For the reader’s convenience, many of them are listed here: ADS-B Automatic Dependent Surveillance Broadcast AGC Automatic Gain Control AHARS Attitude Heading and Reference System API Application Programming Interface ATC Air Traffic Control CFIT Controlled Flight Into Terrain CMS Content Management System CDN Content Delivery Network CDNG CDN Gateway DOP Dilution of Precision EFB Electronic Flight Bag GBAS Ground Based Augmentation System GNSS Global Navigation Satellite System GPS Global Positioning System GPWS Ground Proximity Warning System IMC Instrument Meteorological Conditions NM Nautical Mile LEO Low Earth Orbit P2CDNS Public to CDN Service PNT Position, Navigation and Time RINEX Receiver Independent Exchange Format RTK Real-Time Kinematics SBAS Space Based Augmentation System TAWS Terrain Avoidance and Warning System VMC Visual Meteorological Conditions VOR / DME Very high frequency Omni-directional Range / Distance Measuring Equipment V2X Vehicle to Everything

[0049] Some implementations of the disclosed method involve cloud processing of ADS-B data received from one or more sources to detect potential GNSS spoofing events affecting aircraft guidance systems. The cloud processing further includes receiving ADS-B integrity, GNSS integrity, track, and position data for an aircraft and analyzing the ADS-B data by comparing to the operational limitations of the aircraft. In response to an anomalous flight path characteristic identified within the analyzed ADS-B integrity, GNSS integrity, track, and position data, a cloud-based server provides an alert to an EFB tablet device onboard the aircraft, notifying aircraft personnel of a potential spoofing event. Anomalous flight path characteristics can include, for example, sudden position jumps, excessive speed or turn rates, or significant changes in altitude trigger alerts to aircraft personnel via the onboard EFB tablet.

[0050] Alerts of potential spoofing can also be shared with other aircraft or GNSS users. Data from detected spoofing events is stored in a cloud database for further analysis, including for use in training deep learning models to classify affected data and detect interference events. Additionally, data from multiple aircraft can be analyzed to identify areas impacted by spoofing and determine spoofing frequencies.

[0051] Many implementations of the distributed network include a cloud-based alert system and EFB tablets on each aircraft. In some implementations, an auxiliary GNSS receiver is carried onboard the aircraft that operates independently from the certified avionics system of the aircraft, referred to herein as an external GNSS receiver. Spoofing events trigger alerts based on anomalous flight path characteristics or anomalies within signal data (e.g., GNSS data received from external GNSS receivers). The cloud-based alert system can compare data from different sources, store it, and utilize deep learning models for analysis. It can also correlate GNSS data with ADS-B reports from numerous aircraft to identify spoofing sources and track patterns over time. For example, it can correlate ADS-B receiver activity data, taking into account when a particular ground station ADS-B receiver is active. The cloud based system can process ADS-B messages from particular ground station ADS-B receivers and the GNSS data associated with a detected spoofing event to aid in identifying spoofing attacks on GNSS. The ADS-B messages processed can include position, velocity, operational status and uncertainty messages. Among the data quality indicators in ADB-S messages, the system can use uncertainty indicators, accuracy indicators and integrity indicators.

[0052] Some implementations involve cloud processing of GNSS signal data from external GNSS receivers onboard aircraft to detect and alert aircraft personnel of potential spoofing events. The system can process GNSS data using both onboard and cloud-based resources. The processing further involves analyzing signal data for anomalous characteristics such as anomalous values within recorded signal strengths, elevation or azimuth of source satellites, pseudo ranges, clock stability, time codes, or missing / null values within the GNSS signal data. Alerts are sent to aircraft personnel via EFB tablets upon detecting anomalies indicative of spoofing events.

[0053] The method may also include analyzing GNSS integrity, track, and position data to identify anomalous flight path characteristics, comparing data from certified avionics with external GNSS data, and sharing alerts with other aircraft or GNSS users. Position data can include both position and velocity. Track data refers to position over time. GNSS integrity data can include GNSS measurements of signals and heuristics evaluating the completeness, accuracy, precision, and plausibility of positions derived from GNSS signal data. Monitoring the accuracy, reliability, availability and plausibility, of GNSS position and track allows the system to identify anomalous data. Similarly, a GNSS signal characteristics having measured values outside of a pre-defined acceptable range or a null value or an error message can be flagged as anomalous. An implausible, sudden change in in position or velocity that is not within the realm of physical possibility or indicative of a catastrophic failure also can be flagged. For example, civil aircraft landing systems leverage fixed ground reference stations for integrity monitoring to continuously measure GNSS signal characteristics, identify anomalous values, correct the anomalous values when possible, and in the event of an uncorrectable error, excluding the affected satellite from the aircraft’s position calculation. Aircraft navigation systems leverage GNSS signal data, sent by satellites and received by GNSS receivers, to calculate the range of the aircraft from the satellites, and then to calculate three-dimensional position and time data. GNSS tracking systems record the GNSS position and time data of an aircraft at regular intervals in order to create a log of movements, thereby generating GNSS track data describing the navigation path of the aircraft. GNSS spoofing events can interfere with integrity monitoring processes.

[0054] The GNSS integrity, track, and position data from multiple sources can be analyzed upon receipt, as well as stored within a cloud storage database for further analysis at a later time (e.g., using deep learning classification) to determine impacted areas and spoofing frequencies are further components of the method. Alerts are triggered by anomalous signal or flight path characteristics detected from GNSS interference data received from various sources. The system can process different types of GNSS data, store it, and utilize deep learning models for analysis. It can also track interference events over time and correlate GNSS data with ADS-B receiver activity. GNSS interference data can be processed using both onboard and cloud-based resources.

[0055] A system architecture for analyzing global navigation satellite system (GNSS) interference data from a plurality of GNSS receiver sources to detect spoofing events impacting a plurality of aircraft is described next. System Architecture

[0056] FIG. 1 shows an example architecture 100 for cloud processing of GNSS data to alert aircraft personnel to GNSS spoofing of aircraft guidance systems, according to one implementation of the disclosed technology. Because FIG. 1 is an architectural diagram, certain details are intentionally omitted to improve clarity of the description. The discussion of FIG. 1 is organized as follows. First, the elements of the figure will be described, followed by their interconnections. Then, the use of the elements in the system will be described in greater detail.

[0057] System architecture 100 includes applicant’s cloud 146 with cloud database 148, content delivery network 166, aircraft 144a through 144n, satellite(s) 142a through 142n, base station(s) 102a through 102n, EFB tablet device(s) 124a through 124n, and external GNSS receiver(s) 104a through 104n. Each aircraft 144n contains an integrated GNSS navigation system 164a-n, comprising certified avionics, and an ADS-B data link 184a-n (also referred to herein as an ADS-B transponder). In addition, onboard each aircraft 144n is an EFB tablet device 124n, and in some aircraft, an external GNSS receiver 104n coupled to the tablet. The EFB tablet can have a built-in GNSS receiver. The EFB tablet device 124n and external GNSS receiver 104n operate independently of the certified avionics GNSS 164n. Each ADS-B data link 184n communicates with a network of ADS-B base stations 102a-n (also referred to herein as an ADS-B receiver) via respective ADS-B in and out channels. GNSS signals are transmitted by satellites 142a-n within satellite constellations, such as those within LEO or MEO orbits.

[0058] Each EFB tablet device 124n can be linked to GNSS receivers, such as the certified avionics GNSS receiver 164n or an external GNSS receiver 104n, and may also contain its own internal GNSS receiver. GNSS data from any of these sources can be transmitted by the EFB tablet 124n to the cloud-based alert system operating via cloud network 146. The GNSS data may be processed locally on the EFB tablet 124n (e.g., when connectivity to the cloud is not possible), by the cloud-based alert system operating via cloud network 146, or a combination of both. The GNSS data and other associated data, such as analytics outputs, timing and weather condition data, and / or aircraft operational limitations, can be stored on the cloud database 148 for additional processing in the future. Additional processing may be performed by a deep learning network, trained using a training database containing ground truth data for GNSS interference events and corresponding associated data, configured to detect and classify GNSS interference events.

[0059] When a potential spoofing event is detected by the cloud-based alert system, the spoofing alert is communicated to the EFB device(s) 124a-n for aircraft(s) 144a-n using content delivery network 166. For further information regarding the content delivery network, reference can be made to commonly owned US Patent Application No. 17 / 948,176, which is fully incorporated by reference for all purposes as if fully set forth herein.

[0060] The disclosed cloud architecture provides a distributed network configured to analyze global navigation satellite system (GNSS) interference data from a plurality of GNSS receiver sources to detect spoofing events impacting a plurality of aircraft. GNSS spoofing events affecting aircraft will now be briefly introduced before the discussion turns to various implementations of the disclosed spoofing detection and alert methods in further detail.

[0061] FIG. 2 shows an example schematic 200 of GNSS spoofing of aircraft guidance systems. Schematic 200 includes an aircraft traveling from a true starting location 222 to an intended destination 228, currently located at a true current location 244. The GNSS receiver of the aircraft receives GNSS signals for PNT guidance from source satellites 142a-n. A spoofer 242 has activated a spoofing attack, comprising the integrity of the aircraft’s GNSS signals. The aircraft has a true current location 244. The spoofing interference causes the position of the aircraft to appear to the aircraft’s GNSS system to be at the spoofed current location 204. As a result, instead of staying on the intended flight path 226 from location 244 to the destination 228, the aircraft’s navigation system will attempt to guide the aircraft from the spoofed location 204 to destination location 228, shown as the spoofing impacted flight path 206 within schematic 200. Consequently, such navigation will take the aircraft from location 244 to the spoofing impacted destination 248 via the flight path 246 (e.g., ADS-B track data).

[0062] In addition to affecting the aircraft’s navigation integrity, ADS-B out messages that report a spoofed GNSS position can impair ATC’s ability to monitor air traffic to varying degrees. In some cases, a difference between the ADS-B out position and position determined by radar can lead to position errors or omissions in ATC systems. Moreover, outside of radar coverage, ATC is dependent on the GNSS position sent in the ADS-B out messages. A spoofed position results in ATC perceiving the aircraft at a different location than it actually is. Potential adverse scenarios include collision and near-collision events in “crowded sky” situations, impaired management of air traffic by ATC, and emergencies involving severe weather, plane hijackings or conflict zone airspace.

[0063] The example given in schematic 200 is an example provided for illustrative purposes. Impacts beyond what is illustrated in the figure are referenced above. No one will doubt that it is important to promptly detect such events and alert aircraft personnel of detected events in order to mitigate or entirely prevent high risk consequences. The technology disclosed includes distributed networks and methods for detecting and alerting aircraft of potential GNSS spoofing events that leverage existing EFB tablets onboard aircraft and a cloud-based alert system. Cloud-Based Detection and Alerts of GNSS Spoofing Events

[0064] FIG. 3 shows a block diagram 300 for various cloud-based approaches of processing GNSS data to alert personnel to GNSS spoofing of aircraft guidance systems, according to one implementation of the disclosed technology.

[0065] Diagram 300 includes aircraft 144a, 144b, and 144c each containing certified avionics including a GNSS receiver 164a, 164b, and 164c, respectively, and an ADS-B data link 184a, 184b, 184c. In operation 322, GNSS track information and signal properties for at least one of aircraft 144a-c can be collected, and the collected data is analyzed within operation 324 to detect potential spoofing events from anomalies in the collected data. The GNSS data may be transmitted to a cloud-based server for processing (operation 326) or processed locally on an EFB device onboard the aircraft before being transmitted to the cloud-based server. The GNSS data is also stored to a cloud database in operation 306, along with additional metadata (e.g., aircraft operational limitations) and analysis outputs (e.g., detected spoofing). When a potential spoofing event has been detected, the cloud-based alert system can communicate an alert to aircraft personnel in-flight via the EFB tablet device onboard the aircraft, ATC, other GNSS users, etc., in operation 346.

[0066] The collection of GNSS data for an aircraft 144 can be performed in a variety of ways according to different implementations of the technology disclosed. Certain GNSS data sources will briefly be summarized, then example implementations including collecting and detecting spoofing events within GNSS track data will be presented with reference to FIGs. 4A-4E.

[0067] GNSS track information for a particular aircraft may be obtained from ADS-B track data for the particular aircraft. The GNSS data collected by 164a for aircraft 144a is communicated to an ADS-B receiver network (e g., ATC) via ADS-B data link 184a, and similarly for aircraft 144b and aircraft 144c. The transmitted ADS-B integrity, GNSS-integrity, track, and position data is collected via a plurality of sources, including ATC and various crowdsourced ADS-B data resources such as ADS-B Exchange and The OpenSky Network. From these sources, ADS-B integrity, GNSS integrity, track, and position data for an aircraft can be collected and processed using the cloud-based server (operation 326), stored to the cloudbased server (operation 326) and either analyzed for GNSS spoofing detection (operation 324) before transmitting data to the cloud, when connectivity to the cloud is not possible, or analyzed for GNSS spoofing detection (operation 324) by the cloud-based alert system itself.

[0068] In some implementations, aircraft 144a, for example, can be equipped with an external GNSS receiver that operates independently of the certified avionics GNSS receiver 164a. The external GNSS receiver can be linked to the EFB tablet, which collects the GNSS data from the external receiver and transmits the data to the cloud-based server for processing, including analysis of the data for GNSS spoofing detection, and alert. The data being analyzed may include GNSS integrity, track, and position data and / or GNSS signal properties. In one implementation, the GNSS data received is from the internal GNSS receiver of the EFB tablet device. In other implementations, the EFB tablet receives GNSS data from the certified avionics GNSS receiver 164a and transmits the certified avionics GNSS data to the cloud-based server for GNSS spoofing detection and alert. For either the certified avionics or an external GNSS receiver, the spoofing detection may be performed locally and transmitted to the cloud-based server at a later time (e.g., if connectivity is not possible at the time of data collection) for further processing and storage, or the EFB tablet device may transmit the data to the cloud upon receipt for detected spoofing alerts in closer to real-time.

[0069] Analysis of ADS-B / GNSS integrity, track, and position data from ADS-B data sources or an onboard GNSS receiver (within, or external to, the aircraft’s certified avionics) can include identification of one or more flight path abnormalities for the aircraft. An anomalous flight path characteristic can be, for example, a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute. Other criteria can be applied, such as a turn performed exceeding 1, 2, or degrees per second or a threshold in a range of 1-3 or 2-3 degrees per second. Another criteria can be a change in speed greater than a threshold of 7.5, 10 or 12.6 knots / second or a threshold in a range of 7-15 knots / second. A change in altitude threshold can be greater than 4000, 4500 or 5000 feet / minute or in a range of 4000 to 7000 feet / minute. These examples of anomalous flight path characteristics are not limiting, and a user skilled in the art will recognize that other anomalies in the GNSS integrity, track, and position data may also be identified to indicate that a potential spoofing event has occurred.

[0070] The GNSS signal data received by the certified avionics or an external GNSS receiver can also be analyzed to identify one or more abnormal signal properties. An anomalous signal characteristic in the GNSS signal data may be, for example, an anomalous signal strength of satellite signals compared to other received satellite signal strengths, an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals, an anomalous pseudo range of the satellite signals, an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, incorrect, missing, or null values in the GNSS signal data, an anomalous change to broadcast almanac data, an anomalous change in AGC input levels, or a loss of usable GNSS signals followed by the anomalous signal characteristic. Signals can be monitored for any combination of one or more of these anomalies.

[0071] In some implementations, GNSS data can be collected from a plurality of data sources for the aircraft and data from different sources can be compared to one another to identify anomalous data values. This can include, for example, comparing the ADS-B track to the GNSS track from an external GNSS receiver, comparing GNSS track or GNSS signal properties from the certified avionics to that of the external GNSS receiver, comparing GNSS track and position data to the expected flight path track and position data, or comparing GNSS data between different satellite constellations, to identify nonsimilar data values between the compared data sources. In one implementation, ADS-B track and position data obtained from collected ADS-B communication data can be compared to the GNSS track and position data obtained from an external GNSS receiver onboard the aircraft to identify dissimilar values indicative of a spoofing event, such as the ADS-B track and position data showing the aircraft on a different flight path than the GNSS track and position data. The ADS-B track and position data can also be compared to the certified avionics GNSS track and position data in addition to, or instead of, comparing the ADS-B track and position data and the external GNSS receiver track and position data. In another implementation, a similar comparison analysis can be performed using the certified avionics GNSS track and position data and the external GNSS receiver track and position data. Alternatively, signal characteristics like elevation, azimuth, or clock stability can be compared between the certified avionics GNSS data and external receiver GNSS data. Some implementations include a comparison of in-flight GNSS track and position data, collected from ADS-B track and position data, the certified avionics, and / or an external GNSS receiver, with the expected flight path of the aircraft to identify deviations from the expected navigation route. In another implementation, GNSS data from different satellite constellations, like GPS versus GALILEO, can be compared. In implementations involving the comparison of GNSS data from two or more sources, anomalous data may be identified by detecting a deviation / dissirmlarity in paired, contrasted values from each respective source that exceeds a pre-defined acceptable threshold value.

[0072] In other implementations, GNSS data can be collected from a plurality of data sources for different aircraft for comparison to one another to identify anomalous data values, or to determine the region that is affected by a detected spoofing event. The data collected within a particular region for one or more aircraft may be collected all within an overlapping time period (in near real-time or historically) or from different time periods to analyze GNSS interference data for trends over time.

[0073] When a potential spoofing event is detected within the data, in response to one or more anomalous flight path characteristics, anomalous signal characteristics, inconsistencies in the GNSS data, or anomalous patterns identified in the GNSS data across a plurality of aircraft and / or over a period of time, the potential spoofing event can be communicated to an aircraft via the EFB tablet on board to inform aircraft personnel of the detected spoofing. The spoofing alert may also be communicated to, for example, other aircraft or ATC. In one implementation, an aircraft may be warned when it is about to enter a region where spoofing may occur, notified of when the aircraft has left the region, or notified of when a detected spoofing event has ceased.

[0074] Data collected within the cloud database can undergo further analysis, such as processing by a deep learning classifier. The collected GNSS data, related metadata, ground truth classifications, and / or cloud processing outputs can be used as training data for the deep learning classifier. Input features can include PNT values from the collected GNSS integrity, track, and position data as defined above, GNSS signal characteristics, date and time data, metadata associated with the aircraft including operational limitations or specifications, and / or descriptive statistics and pre-processing outputs obtained from these input features like mean / minimum / maximum values, reduced dimensionality datasets from principal component analysis, and so on. In some implementations, the input data includes values collected from a plurality of sources for the same aircraft, such as two or more of the ADS-B integrity, GNSS integrity, track, and position data, the certified avionics GNSS receiver integrity, track, and position data, and external GNSS receiver integrity, track, and position data. In certain implementations, the input data includes data collected for a plurality of aircraft. Ground truth labelling for training data can include whether a GNSS interference event was detected in response by analysis of the collected GNSS data and related metadata, a classification of the GNSS interference event (e.g., spoofing or jamming, malicious or accidental error, etc.). The classifier may be trained, for example, to detect spoofing events, identify predictors of spoofing events, classify types of spoofing events, and so on.

[0075] FIGs. 4A-E illustrate various particular implementations of GNSS spoofing detection. Within FIGs. 4A-E, collection of GNSS track and signal data is indicated by solid arrows, while data communication for processing and alert of detected GNSS spoofing is indicated by dotted arrows. The spoofing detection approach is indicated by a star.

[0076] FIG. 4A shows a block diagram 400A for GNSS spoofing detection using an external GNSS receiver 464, according to one implementation of the technology disclosed. Diagram 400A shows an aircraft 144a including certified avionics 402 and external devices 404. The certified avionics 402 include, for example, a navigation system 422, GPWS / TAWS 442, an ADS-B transponder 462, and AHARS / flight instruments 482. External devices 404 include an external GNSS receiver 424 and a tablet 444 configured to run EFB software 464. GNSS data from the external GNSS receiver 424, such as GNSS track and / or signal data, is collected and processed for spoofing detection, as indicated by the star icon. The external GNSS receiver 424 is linked to tablet 444, enabling analysis of the GNSS data for spoofing detection using EFB software 464. In some implementations, analysis is performed by an application running on tablet 444. In other implementations, the external GNSS receiver 424 is configured to perform spoofing detection, and notifies the aircraft personnel, via EFB 464, of a detected spoofing event.

[0077] FIG. 4B shows a block diagram 400B for GNSS spoofing detection using an external GNSS receiver 424 and a cloud-based alert system 426 for GNSS spoofing detection and notification. Diagram 400B contains many of the same components as diagram 400A, which will not be repeated here for the sake of conciseness and clarity. However, diagram 400B further includes a cloud-based server including a cloud-based alert system 426. GNSS spoofing detection is performed by analysis of the GNSS signals from external GNSS receiver 424 by the cloud-based alert system 426, as indicated by the star icons. In addition to the processes described in diagram 400A, the collected GNSS data from external GNSS receiver 424 may also be transmitted by EFB 464 to the cloud network for cloud processing, and the cloud-based alert system 426 communicates an alert of potential detected GNSS spoofing back to the EFB 464.

[0078] FIG. 4C shows a block diagram 400C for GNSS spoofing detection using an external GNSS receiver 424, ADS-B receivers 406, a cloud-based alert system 426 for GNSS spoofing detection and notification. Diagram 400C contains many of the same components as diagram 400B, which will not be repeated here for the sake of conciseness and clarity. However, diagram 400B further includes a network of ADS-B receivers 406. In addition to cloud processing of GNSS signals from the external GNSS receiver 424, the ADS-B integrity, GNSS integrity, track, and position data communicated from the ADS-B transponder 462 to the ADS-B receivers 406 can also be collected and analyzed, as described above. The ADS-B data and external GNSS data may be compared to one another, analyzed separately, or aggregated for analysis.

[0079] FIG. 4D shows a block diagram 400D for GNSS spoofing detection using GNSS data obtained from certified avionics 402 and a cloud-based alert system 426 for GNSS spoofing detection and notification. Diagram 400D contains many of the same components as diagram 400B, which will not be repeated here for the sake of conciseness and clarity. In diagram 400D, GNSS track and signal data from the certified avionics 402 are also collected and communicated to the cloud-based alert system 426 for spoofing detection and alert. The certified avionics data and external GNSS data may be compared to one another, analyzed separately, or aggregated for analysis.

[0080] FIG. 4E shows a block diagram 400E for GNSS spoofing detection using GNSS data obtained from a plurality of GNSS receiver sources and a cloud-based alert system 426 for GNSS spoofing detection and notification. Diagram 400E contains many of the same components as diagram 400C, which will not be repeated here for the sake of conciseness and clarity. In diagram 400E, GNSS track and signal data may be collected from the certified avionics 402, ADS-B network 406, and / or the external GNSS receiver 424 and communicated to the cloud-based alert system 426 for spoofing detection and alert. The certified avionics data, ADS-B data, and external GNSS data may be compared to one another, analyzed separately, or aggregated for analysis.

[0081] FIG. 5 shows a block diagram 500 for a distributed network configured to analyze global navigation satellite system (GNSS) interference data from a plurality of GNSS receiver sources to detect spoofing events impacting a plurality of aircraft. Cloud network 144 of diagram 500, including a cloud-based alert system, is configured to perform spoofing detecting 502 and spoofing notification 506. Spoofing detection may be performed using ADS-B path analysis 512, including the processing of GNSS ADS-B track data 513 and aircraft operating limits 523. Spoofing detection may be also performed using external GNSS receiver path analysis 522, including the processing of external GNSS receiver track data 533 and aircraft operating limits 523. Spoofing detection may be also performed using certified avionics path analysis 532, including the processing of external certified avionics track data 543 and aircraft operating limits 523. Spoofing detection can be performed using GNSS signal analysis 514, including the processing of external GNSS receiver track data 533 and / or external certified avionics track data 543. A combination of GNSS ADS-B track data 513, external GNSS receiver track data 533 and / or external certified avionics track data 543 can be used for spoofing detection using a path comparison analysis 542. On-board spoofing alerts may be performed from analysis of external GNSS track data 533, GNSS avionics track data 543, and / or GNSS signal analysis 514. GNSS data may be compared from different aircraft at the same time in the same region 562, or at the same area over different times 572.

[0082] The collected data, as well as data associated with any detected spoofing, is collected and stored in a cloud database 582. Collected data may be used for alert notification(s) 526 to one or more aircraft, ATC, or other GNSS users. The collected data can be leveraged for intent classification of the spoofing attack, as well as analyzed in combination with ADS-B receiver status history 566 to further inform intent classification 546. In one example, if an ADS-B receiver history shows that the receiver operation overlaps with a history of one or more spoofing events, it can be inferred that the spoofer is using that ADS-B receiver in their attack. Furthermore, collected data may be used for ML training processes 592, as described previously.

[0083] The preceding description is presented to enable the making and use of the technology disclosed. Various modifications to the disclosed implementations will be apparent, and the general principles defined herein may be applied to other implementations and applications without departing from the spirit and scope of the technology disclosed. Thus, the technology disclosed is not intended to be limited to the implementations shown but is to be accorded the widest scope consistent with the principles and features disclosed herein. The scope of the technology disclosed is defined by the appended claims. Some Particular Implementations

[0084] We describe some particular implementations and features usable for providing detection and alert of GNSS spoofing.

[0085] We describe some particular implementations related to the use of ADS-B data, GNSS track and position data, and / or GNSS signal data collected by ADS-B networks, certified avionics, and / or external GNSS receivers corresponding to one or more aircraft.

[0086] One implementation includes a disclosed method of cloud processing for automatic dependent surveillance-broadcast (ADS-B) data to alert aircraft personnel to GNSS spoofing of aircraft guidance systems. The method further includes receiving at a cloud-based server, from one or more ADS-B data sources. The ADS-B data can include some or all of ADS-B integrity, GNSS integrity, track, and position data for an aircraft. The method includes analyzing the ADS-B integrity, GNSS integrity, track, and position data upon receipt. Analyzing can include comparing the ADS-B integrity, GNSS integrity, track, and position data to a plurality of operational limitations for the aircraft and / or identifying an anomalous flight path characteristic from the analyzed ADS-B integrity, GNSS integrity, track, and position data. Comparison of track data to operational limitations is a significant improvement on prior spoofing detection. In response to an identified anomalous flight path characteristic, the cloud-based server can provide an alert to an Electronic Flight Bag (EFB) tablet device onboard the aircraft notifying aircraft personnel of a potential spoofing event. An anomalous flight characteristic may include one or more of a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute. Alternative thresholds and ranges for thresholds are given above.

[0087] This method and other implementations of the technology disclosed can include one or more of the following features and / or features described in connection with additional methods disclosed. In the interest of conciseness, the combinations of features disclosed in this application are not individually enumerated and are not repeated with each base set of features. The reader will understand how features identified in this section can readily be combined with sets of base features identified as implementations.

[0088] For some implementations, the ADS-B data for the aircraft is transmitted by an ADS-B transponder onboard the aircraft, received by ADS-B receivers, and collected by a plurality of ADS-B data sources including crowd-sourced ADS-B data services and air traffic control systems.

[0089] For some implementations, the method further includes providing an alert of potential spoofing in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, or other GNSS users via a cloud-based connection.

[0090] For some implementations, the method further includes storing one or more of the ADS-B integrity, GNSS integrity, track, and position data, with corresponding aircraft limitations, to a cloud storage for detected spoofing events.

[0091] For some implementations, the method further includes training a deep learning model, using the stored ADS-B integrity, GNSS integrity, track, and position data and corresponding aircraft limitations, to process ADS-B integrity, GNSS integrity, track, and position data and generate, as output, a classification of the ADS-B integrity, GNSS integrity, track, and position data as affected or unaffected by spoofing. In some implementations, the trained deep learning model is further trained to generate, as output, a classification of a detected interference event within the ADS-B integrity, GNSS integrity, track, and position data.

[0092] For some implementations, the method further includes receiving ADS-B integrity, track, and position data for a plurality of aircraft, analyzing the ADS-B integrity, GNSS integrity, track, and position data for the plurality of aircraft, and comparing the analyzed ADS-B integrity, GNSS integrity, track, and position data across the plurality of aircraft to determine an area impacted by a detected spoofing threat, a size of the impacted area, and an expected impact on different types of GNSS systems.

[0093] For some implementations, the method further includes receiving ADS-B integrity, GNSS integrity, track, and position data for a plurality of aircraft located within the impacted area over multiple different times to determine a spoofing frequency within the impacted area.

[0094] One method of cloud processing for automatic dependent surveillance-broadcast (ADS-B) data to alert aircraft personnel to GNSS spoofing of aircraft guidance systems includes including receiving ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between the ADS-B integrity, GNSS integrity, track, and position data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with a detected spoofing event. Another method includes tracking a pattern of identified anomalous flight path characteristics over time, detecting a pattern within the identified anomalous flight path characteristics over time, and using the detected pattern to score the identified anomalous flight path characteristics over time to quantify a certainty of spoofing. Other implementations of the method can further include providing an alert to the aircraft when the aircraft is approaching an area with detected spoofing or when the detected spoofing event has ceased based on a correction to the anomalous flight characteristic.

[0095] This method and other implementations of the technology disclosed can include one or more of the following features and / or features described in connection with additional methods disclosed. In the interest of conciseness, the combinations of features disclosed in this application are not individually enumerated and are not repeated with each base set of features. The reader will understand how features identified in this section can readily be combined with sets of base features identified as implementations.

[0096] One implementation includes a distributed network configured to process automatic dependent surveillance-broadcast (ADS-B) integrity, track, and position data to detect spoofing events impacting a plurality of aircraft. The distributed network further includes a cloud-based alert system configured to analyze the ADS-B integrity, GNSS integrity, track, and position data, received from one or more ADS-B data sources, for the plurality of aircraft in order to detect spoofing events and report detected spoofing events to Electronic Flight Bag (EFB) equipment onboard the plurality of aircraft, wherein analyzing the ADS-B integrity, GNSS integrity, track, and position data further includes (i) comparing the ADS-B integrity, GNSS integrity, track, and position data of a first aircraft to a plurality of operational limitations for the first aircraft or (ii) comparing the ADS-B integrity, GNSS integrity, track, and position data of the first aircraft with the ADS-B integrity, GNSS integrity, track, and position data of a second aircraft. The distributed network also further includes an EFB tablet device, located on-board each aircraft within the plurality of aircraft, with a wireless connection to the cloud-based alert system, wherein the tablet device receives spoofing reports from the cloud-based alert system.

[0097] In some implementations, a spoofing event is detected when an anomalous flight path characteristic is identified from the analyzed ADS-B integrity, GNSS integrity, track, and position data, and wherein an anomalous flight path characteristic is one or more of a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute.

[0098] In some implementations, the ADS-B data for the plurality of aircraft is transmitted by an ADS-B transponder onboard each aircraft, received by ADS-B receivers, and collected by a plurality of ADS-B open data sources including crowd-sourced ADS-B data services and air traffic control systems.

[0099] In one implementation, the cloud-based alert system is further configured to provide an alert of potential spoofing in a specific area to other aircraft via onboard EFB tablets, an air traffic base station, or other GNSS users. The distributed network can further include a deep learning model, trained using the stored ADS-B integrity, GNSS integrity, track, and position data and corresponding aircraft limitations, configured to process ADS-B integrity, GNSS integrity, track, and position data and generate, as output, a classification of the ADS-B integrity, GNSS integrity track, and position data as affected or unaffected by spoofing. The trained deep learning model can be further configured to generate, as output, a classification of a detected interference event within the ADS-B integrity, GNSS integrity, track, and position data.

[00100] One implementation further includes the cloud-based alert system receiving ADS-B integrity, GNSS integrity, track, and position data from a plurality of aircraft located within the impacted area over multiple different times to determine a spoofing frequency within the impacted area. Another implementation further includes the cloud-based alert system receiving ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between the ADS-B integrity, GNSS integrity, track, and position data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with a detected spoofing event. Yet another implementation further includes the cloud-based alert system providing an alert to an aircraft when the aircraft is approaching an area with detected spoofing or when the detected spoofing event has ceased.

[0101] This method and other implementations of the technology disclosed can include one or more of the following features and / or features described in connection with additional methods disclosed. In the interest of conciseness, the combinations of features disclosed in this application are not individually enumerated and are not repeated with each base set of features. The reader will understand how features identified in this section can readily be combined with sets of base features identified as implementations.

[0102] Some implementations include a disclosed method of cloud processing for global navigation satellite system (GNSS) signal data from an external GNSS receiver onboard an aircraft, operating independently from certified avionics of the aircraft, to detect GNSS spoofing of aircraft guidance systems. The method can further include receiving, from an Electronic Flight Bag (EFB) tablet device linked to the external GNSS receiver at a cloud-based server, GNSS signal data from the external GNSS receiver, analyzing the GNSS signal data upon receipt, further including identifying an anomalous signal characteristic from the GNSS signal data, and in response to an identified anomalous signal characteristic, the cloud-based server providing an alert to the EFB tablet device onboard the aircraft notifying aircraft personnel of a potential spoofing event. An anomalous signal characteristic can be an anomalous signal strength of satellite signals compared to other received satellite signal strengths, an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals, an anomalous pseudo range of the satellite signals, an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, incorrect, missing, or null values in the GNSS signal data, an anomalous change to broadcast almanac data, an anomalous change in AGC input levels, and / or a loss of usable GNSS signals followed by the anomalous signal characteristic.

[0103] In some implementations, the method further includes receiving, from the external GNSS receiver, GNSS track and position data, and analyzing the GNSS track and position data to identify an anomalous flight path characteristic indicative of a spoofing event, wherein the anomalous flight path characteristic is one or more of a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute.

[0104] In some implementations, the method further includes receiving certified avionics GNSS data from the aircraft and comparing the certified avionics GNSS data to the external GNSS data to detect anomalous signal characteristics or anomalous flight path characteristics.

[0105] In some implementations, the method further includes providing an alert of potential spoofing in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, or other GNSS users via a cloud-based connection.

[0106] The method can include storing the GNSS signal data to a cloud storage.

[0107] In some implementations, the method includes training a deep learning model, using the stored GNSS signal data, to process GNSS signal data and generate, as output, a classification of the GNSS signal data as affected or unaffected by spoofing. The trained deep learning model can be further trained to generate, as output, a classification of a detected interference event within the GNSS signal data.

[0108] The method can further include receiving GNSS signal data from multiple GNSS receivers including external GNSS receivers and onboard certified avionics GNSS receivers, analyzing the GNSS signal data from the multiple GNSS receivers, and comparing the analyzed GNSS signal data across the multiple GNSS receivers to determine an area impacted by a detected spoofing threat, a size of the impacted area, and an expected impact on different types of GNSS systems.

[0109] Other implementations include receiving GNSS signal data from a plurality of GNSS receivers located within the impacted area over multiple different times to determine a spoofing frequency within the impacted area. Another implementation includes receiving ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between the GNSS signal data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with a detected spoofing event. One implementation includes tracking identified anomalous signal characteristics over time, detecting a pattern within the identified anomalous signal characteristics over time, and using the detected pattern to score the identified anomalous signal characteristics over time to quantify a certainty of spoofing. [OHO] Various implementations of the technology disclosed include processing the GNSS signal data using an API running on the EFB device and further processing the GNSS signal data using the cloud-based server.

[0111] One implementation of a disclosed distributed network is configured to analyze GNSS signal data from an external GNSS receiver onboard an aircraft, operating independently from certified avionics of the aircraft, to detect spoofing events impacting a plurality of aircraft. The distributed network also includes a cloud-based alert system configured to analyze the GNSS signal data from the external GNSS receiver, received from an Electronic Flight Bag (EFB) tablet device linked to the external GNSS receiver, in order to detect spoofing events and report detected spoofing events to the EFB tablet device onboard the plurality of aircraft, wherein analyzing the GNSS signal data further includes (i) identifying an anomalous signal characteristic within the GNSS signal data of a first GNSS receiver or (ii) comparing the GNSS signal data of the first GNSS receiver with the GNSS signal data of a second GNSS receiver and the EFB tablet device, located on-board each aircraft within the plurality of aircraft, with a wireless connection to the cloud-based alert system, wherein the tablet device (i) receives spoofing reports from the cloud-based alert system and (ii) reports GNSS signal data, from the external GNSS, to the cloud-based alert system. The method also includes detecting a spoofing event in response to an identified anomalous signal characteristic, wherein the identified anomalous signal characteristic is one or more of an anomalous signal strength of satellite signals compared to other received satellite signal strengths, an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals, an anomalous pseudo range of the satellite signals, an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, incorrect, missing, or null values in the GNSS signal data, or a loss of usable GNSS signals followed by the anomalous signal characteristic.

[0112] The method also includes detecting a spoofing event in response to an identified anomalous flight path characteristic indicative of a spoofing event, wherein the anomalous flight path characteristic is one or more of a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots second, or a change in altitude greater than 6000 feet / minute.

[0113] In one implementation, the cloud-based alert system is further configured to provide an alert of potential spoofing in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, or other GNSS users via a cloud-based connection. In one implementation, the cloud-based alert system is further configured to store the GNSS signal data to a cloud storage. [0H4] This method and other implementations of the technology disclosed can include one or more of the following features and / or features described in connection with additional methods disclosed. In the interest of conciseness, the combinations of features disclosed in this application are not individually enumerated and are not repeated with each base set of features. The reader will understand how features identified in this section can readily be combined with sets of base features identified as implementations.

[0115] In some implementations, the distributed network further includes a deep learning model, trained using the stored GNSS signal data, configured to process GNSS signal data and generate, as output, a classification of the GNSS signal data as affected or unaffected by spoofing. The trained deep learning model can be further configured to generate, as output, a classification of a detected interference event within the GNSS signal data. [0H6] In some implementations, the cloud-based alert system is further configured to receive GNSS signal data from multiple GNSS receivers including external GNSS receivers, and onboard certified avionics GNSS receivers, analyze the GNSS signal data from the multiple GNSS receivers, and compare the analyzed GNSS signal data across the multiple GNSS receivers to determine an area impacted by a detected spoofing threat, a size of the impacted area, and an expected impact on different types of GNSS systems. [0H7] In some implementations, the cloud-based alert system is further configured to receive GNSS signal data from a plurality of GNSS receivers located within the impacted area over multiple different times to determine a spoofing frequency within the impacted area.

[0118] In some implementations, the cloud-based alert system is further configured to receive ADS-B receiver data including a history of ADS-B receiver activity and detect a correlation between the GNSS signal data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with a detected spoofing event.

[0119] In some implementations, the cloud-based alert system is further configured to track identified anomalous signal characteristics over time, detect a pattern within the identified anomalous signal characteristics over time, and use the detected pattern to score the identified anomalous signal characteristics over time to quantify a certainty of spoofing. In other implementations, the GNSS signal data is processed using an API running on the EFB device and further processed by the cloud-based alert system.

[0120] One implementation is disclosed including a method of cloud processing for global navigation satellite system (GNSS) interference data from a plurality of GNSS receivers to alert aircraft personnel to GNSS spoofing of aircraft guidance systems, the method including receiving at a cloud-based server, GNSS interference data from the plurality of GNSS receivers including one or more of a certified avionics GNSS receiver onboard an aircraft, an external GNSS receiver linked to an Electronic Flight Bag (EFB) tablet device and independent of onboard certified avionics, cellular networks, automatic dependent surveillance-broadcast (ADS-B) networks, or dedicated GNSS monitoring facilities. Data from two or three or more of these data sources can be used. The method also includes analyzing the GNSS interference data upon receipt, including one or more of comparing a set of GNSS data for a particular aircraft to a plurality of operational limitations for the aircraft, comparing a first set of GNSS data to a second set of GNSS data, wherein the first and second sets of GNSS data are received from different GNSS receivers, onboard the same particular aircraft and operating independently of one another, or comparing a set of GNSS data for a first aircraft to a set of GNSS data for a second aircraft. The method also includes identifying an interference event from the analyzed GNSS interference data, wherein the interference event is an anomalous flight path characteristic of an aircraft or an anomalous signal characteristic of a GNSS signal, and in response to an identified interference event, the cloud-based server providing an alert to EFB tablet devices onboard the aircraft notifying aircraft personnel of a potential spoofing event.

[0121] This method and other implementations of the technology disclosed can include one or more of the following features and / or features described in connection with additional methods disclosed. In the interest of conciseness, the combinations of features disclosed in this application are not individually enumerated and are not repeated with each base set of features. The reader will understand how features identified in this section can readily be combined with sets of base features identified as implementations.

[0122] In some implementations, the GNSS interference data further includes one or more of GNSS track and position data, GNSS signal data, GNSS signal timing data, Receiver Independent Exchange Format (RINEX) data, GNSS data by satellite data, uncompressed radiofrequency recordings, or GNSS dilution of precision (DOP) value data.

[0123] In some implementations, the method further includes further including analyzing the GNSS track and position data to identify an anomalous flight path characteristic indicative of a interference event, wherein the anomalous flight path characteristic is one or more of a detected jump in position along a flight path segment that exceeds an airspeed limitation for an aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute.

[0124] In some implementations, the method further includes analyzing the GNSS signal data upon receipt, further including identifying an anomalous signal characteristic from the GNSS signal data, and in response to an identified anomalous signal characteristic, the cloudbased server providing an alert to the EFB tablet device onboard the aircraft notifying aircraft personnel of a potential spoofing event. An anomalous signal characteristic can be an anomalous signal strength of satellite signals compared to other received satellite signal strengths, an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals, an anomalous pseudo range of the satellite signals, an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, incorrect, missing, or null values in the GNSS signal data, an anomalous change to broadcast almanac data, an anomalous change in AGC input levels, and / or a loss of usable GNSS signals followed by the anomalous signal characteristic.

[0125] In some implementations, the method further includes further including providing an alert of the potential spoofing event in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, mobile network operators, airports, vehicle networks including V2X networks, or other GNSS users via a cloud-based connection. In other implementations, the method further includes storing the GNSS interference data to a cloud storage.

[0126] In some implementations, the method further includes training a deep learning model, using the stored GNSS interference data, to process GNSS interference data and generate, as output, a classification of the GNSS interference data as affected or unaffected by interference. The deep learning model can be further trained to generate, as output, a classification of a detected interference event within the GNSS interference data.

[0127] One implementation includes a distributed network configured to analyze global navigation satellite system (GNSS) interference data from a plurality of GNSS receiver sources to detect spoofing events impacting a plurality of aircraft, the distributed network including a cloud-based alert system configured to analyze the GNSS interference data received from the plurality of sources in order to detect spoofing events and report detected spoofing events to EFB tablet devices onboard the plurality of aircraft, wherein analyzing the GNSS interference data further includes one or more of comparing a set of GNSS data for a particular aircraft to a plurality of operational limitations for the aircraft, comparing a first set of GNSS data to a second set of GNSS data, wherein the first and second sets of GNSS data are received from different GNSS receivers, onboard the same particular aircraft and operating independently of one another, or comparing a set of GNSS data for a first aircraft to a set of GNSS data for a second aircraft. In some implementations, the GNSS interference data is collected from networks such as 4G, 5G, and other communications networks included but not limited to terrestrial cellular communications or LEO satellite-based communication systems. The distributed network further includes an Electronic Flight Bag (EFB) tablet device, located on-board each aircraft within the plurality of aircraft, with a wireless connection to the cloud-based alert system, wherein the EFB tablet device (i) receives spoofing reports from the cloud-based alert system and (ii) reports GNSS interference data to the cloud-based alert system.

[0128] This distributed networks and other implementations of the technology disclosed can include one or more of the following features and / or features described in connection with additional methods disclosed. In the interest of conciseness, the combinations of features disclosed in this application are not individually enumerated and are not repeated with each base set of features. The reader will understand how features identified in this section can readily be combined with sets of base features identified as implementations.

[0129] This system implementation and other systems disclosed optionally include one or more of the following features. System can also include features described in connection with methods disclosed. In the interest of conciseness, alternative combinations of system features are not individually enumerated. Features applicable to systems, methods, and articles of manufacture are not repeated for each statutory class set of base features. The reader will understand how features identified in this section can readily be combined with base features in other statutory classes.

[0130] The technology disclosed can be practiced as a system, method, or article of manufacture. One or more features of an implementation can be combined with the base implementation. Implementations that are not mutually exclusive are taught to be combinable. One or more features of an implementation can be combined with other implementations. This disclosure periodically reminds the user of these options.

[0131] While the technology disclosed is disclosed by reference to the preferred embodiments and examples detailed above, it is to be understood that these examples are intended in an illustrative rather than in a limiting sense. It is contemplated that modifications and combinations will readily occur to those skilled in the art, which modifications and combinations will be within the spirit of the innovation and the scope of the following claims. CLAUSES

[0132] We disclose the following clauses. In these clauses, each dependency should be understood to relate to any and all preceding clauses of the same statutory type in the same clause set, even when only a single prior clause is expressly called out. Clauses Set 1; Tablet using track data 1. A method of cloud processing for automatic dependent surveillance-broadcast (ADS-B) data to alert aircraft personnel to GNSS spoofing of aircraft guidance systems, the method including: receiving at a cloud-based server, from one or more ADS-B data sources, ADS-B integrity, GNSS integrity, track, and position data for an aircraft; analyzing the ADS-B integrity, GNSS integrity, track, and position data upon receipt, including comparing the ADS-B integrity, GNSS integrity, track, and position data to a plurality of operational limitations for the aircraft; identifying an anomalous flight path characteristic from the analyzed ADS-B integrity, GNSS, integrity, track, and position data, wherein the anomalous flight path characteristic is one or more of: a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute; and in response to an identified anomalous flight path characteristic, the cloud-based server providing an alert to an Electronic Flight Bag (EFB) tablet device onboard the aircraft notifying aircraft personnel of a potential spoofing event. 2. The method of clause 1, wherein the ADS-B data for the aircraft is transmitted by an ADS-B transponder onboard the aircraft, received by ADS-B receivers, and collected by a plurality of ADS-B data sources including crowd-sourced ADS-B data services and air traffic control systems. 3. The method of clause 1, further including providing an alert of potential spoofing in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, or other GNSS users via a cloud-based connection. 4. The method of clause 1, further including storing the ADS-B integrity, GNSS integrity, track, and position data, with corresponding aircraft limitations, to a cloud storage for detected spoofing events. 5. The method of clause 4, further including training a deep learning model, using the stored ADS-B integrity, track, and position data and corresponding aircraft limitations, to process ADS-B integrity, GNSS integrity, track, and position data and generate, as output, a classification of the ADS-B integrity, track, and position data as affected or unaffected by spoofing. 6. The method of clause 5, wherein the trained deep learning model is further trained to generate, as output, a classification of a detected interference event within the ADS-B integrity, GNSS integrity, track, and position data. 7. The method of clause 1, further including: receiving ADS-B integrity, GNSS integrity, track, and position data for a plurality of aircraft; analyzing the ADS-B integrity, GNSS integrity, track, and position data for the plurality of aircraft; and comparing the analyzed ADS-B integrity, GNSS integrity, track, and position data across the plurality of aircraft to determine an area impacted by a detected spoofing threat, a size of the impacted area, and an expected impact on different types of GNSS systems. 8. The method of clause 7, further including receiving ADS-B integrity, GNSS integrity, track, and position data for a plurality of aircraft located within the impacted area over multiple different times to determine a spoofing frequency within the impacted area. 9. The method of clause 1, further including receiving ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between ADS-B-reported GNSS integrity, track, and position data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with a detected spoofing event. 10. The method of clause 1, further including tracking a pattern of identified anomalous flight path characteristics over time, detecting a pattern within the identified anomalous flight path characteristics over time, and using the detected pattern to score the identified anomalous flight path characteristics over time to quantify a certainty of spoofing. 11. The method of clause 1, further including providing an alert to the aircraft when the aircraft is approaching an area with detected spoofing or when the detected spoofing event has ceased based on a correction to the anomalous flight characteristic. 12. A distributed network configured to process automatic dependent surveillance-broadcast (ADS-B) integrity, track, and position data to detect spoofing events impacting a plurality of aircraft, the distributed network including: a cloud-based alert system configured to analyze the ADS-B integrity, GNSS integrity, track, and position data, received from one or more ADS-B data sources, for the plurality of aircraft in order to detect spoofing events and report detected spoofing events to Electronic Flight Bag (EFB) equipment onboard the plurality of aircraft, wherein analyzing the ADS-B integrity, GNSS integrity, track, and position data further includes (i) comparing the ADS-B integrity, GNSS integrity, track, and position data of a first aircraft to a plurality of operational limitations for the first aircraft or (ii) comparing the ADS-B integrity, GNSS integrity, track, and position data of the first aircraft with the ADS-B integrity, GNSS integrity, track, and position data of a second aircraft; and an EFB tablet device, located on-board each aircraft within the plurality of aircraft, with a wireless connection to the cloud-based alert system, wherein the tablet device receives spoofing reports from the cloud-based alert system. 13. The distributed network of clause 12, wherein a spoofing event is detected when an anomalous flight path characteristic is identified from the analyzed ADS-B integrity, GNSS integrity, track, and position data, and wherein an anomalous flight path characteristic is one or more of a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute. 14. The distributed network of clause 12, wherein the ADS-B data for the plurality of aircraft is transmitted by an ADS-B transponder onboard each aircraft, received by ADS-B receivers, and collected by a plurality of ADS-B open data sources including crowd-sourced ADS-B data services and air traffic control systems. 15. The distributed network of clause 12, wherein the cloud-based alert system is further configured to provide an alert of potential spoofing in a specific area to other aircraft via onboard EFB tablets, an air traffic base station, or other GNSS users. 16. The distributed network of clause 12, wherein the cloud-based alert system is further configured to store the ADS-B integrity, track, and position data, and corresponding aircraft limitations, to a cloud storage for detected spoofing events. 17. The distributed network of clause 16, further including a deep learning model, trained using the stored ADS-B integrity, GNSS integrity, track, and position data and corresponding aircraft limitations, configured to process ADS-B integrity, GNSS integrity, track, and position data and generate, as output, a classification of the ADS-B integrity, GNSS integrity, track, and position data as affected or unaffected by spoofing. 18. The distributed network of clause 17, wherein the trained deep learning model is further configured to generate, as output, a classification of a detected interference event within the ADS-B integrity, GNSS integrity, track, and position data. 19. The distributed network of clause 12, wherein the cloud-based alert system is further configured to compare the analyzed ADS-B integrity, GNSS integrity, track, and position data across the plurality of aircraft to determine an area impacted by a detected spoofing threat, a frequency and recurrence of spoofing in an area, a size of the impacted area, and an expected impact on different types of GNSS systems. 20. The distributed network of clause 19, further including the cloud-based alert system receiving ADS-B integrity, GNSS integrity, track, and position data from a plurality of aircraft located within the impacted area over multiple different times to determine a spoofing frequency within the impacted area. 21. The distributed network of clause 20, further including the cloud-based alert system receiving ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between the ADS-B integrity, GNSS integrity, track, and position data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with a detected spoofing event. 22. The distributed network of clause 20, further including the cloud-based alert system providing an alert to an aircraft when the aircraft is approaching an area with detected spoofing or when the detected spoofing event has ceased. Clauses Set 2; Using external GNSS receiver to analyze signal data 1. A method of cloud processing for global navigation satellite system (GNSS) signal data from an external GNSS receiver onboard an aircraft, operating independently from certified avionics of the aircraft, to detect GNSS spoofing of aircraft guidance systems, the method including: receiving, from an Electronic Flight Bag (EFB) tablet device linked to the external GNSS receiver at a cloud-based server, GNSS signal data from the external GNSS receiver; analyzing the GNSS signal data upon receipt, further including identifying an anomalous signal characteristic from the GNSS signal data, wherein the anomalous signal characteristic is: an anomalous signal strength of satellite signals compared to other received satellite signal strengths, an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals, an anomalous pseudo range of the satellite signals, an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, incorrect, missing, or null values in the GNSS signal data, an anomalous change to broadcast almanac data, an anomalous change in AGC input levels, or a loss of usable GNSS signals followed by the anomalous signal characteristic; and in response to an identified anomalous signal characteristic, the cloud-based server providing an alert to the EFB tablet device onboard the aircraft notifying aircraft personnel of a potential spoofing event. 2. The method of clause 1, further including receiving, from the external GNSS receiver, GNSS track and position data, and analyzing the GNSS track and position data to identify an anomalous flight path characteristic indicative of a spoofing event, wherein the anomalous flight path characteristic is one or more of: a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute. 3. The method of clause 1, further including receiving certified avionics GNSS data from the aircraft and comparing the certified avionics GNSS data to the external GNSS data to detect anomalous signal characteristics or anomalous flight path characteristics . 4. The method of clause 1, further including providing an alert of potential spoofing in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, or other GNSS users via a cloud-based connection. 5. The method of clause 1, further including storing the GNSS signal data to a cloud storage. 6. The method of clause 5, further including training a deep learning model, using the stored GNSS signal data, to process GNSS signal data and generate, as output, a classification of the GNSS signal data as affected or unaffected by spoofing. 7. The method of clause 6, wherein the trained deep learning model is further trained to generate, as output, a classification of a detected interference event within the GNSS signal data. 8. The method of clause 1, further including: receiving GNSS signal data from multiple GNSS receivers including external GNSS receivers and onboard certified avionics GNSS receivers; analyzing the GNSS signal data from the multiple GNSS receivers; and comparing the analyzed GNSS signal data across the multiple GNSS receivers to determine an area impacted by a detected spoofing threat, a size of the impacted area, and an expected impact on different types of GNSS systems. 9. The method of clause 8, further including receiving GNSS signal data from a plurality of GNSS receivers located within the impacted area over multiple different times to determine a spoofing frequency within the impacted area. 10. The method of clause 1, further including receiving ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between the GNSS signal data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with a detected spoofing event. 11. The method of clause 1, further including tracking identified anomalous signal characteristics over time, detecting a pattern within the identified anomalous signal characteristics over time, and using the detected pattern to score the identified anomalous signal characteristics over time to quantify a certainty of spoofing. 12. The method of clause 1, further including processing the GNSS signal data using an app running on the EFB device and further processing the GNSS signal data using the cloud-based server. 13. A distributed network configured to analyze GNSS signal data from an external GNSS receiver onboard an aircraft, operating independently from certified avionics of the aircraft, to detect spoofing events impacting a plurality of aircraft, the distributed network including: a cloud-based alert system configured to analyze the GNSS signal data from the external GNSS receiver, received from an Electronic Flight Bag (EFB) tablet device linked to the external GNSS receiver, in order to detect spoofing events and report detected spoofing events to the EFB tablet device onboard the plurality of aircraft, wherein analyzing the GNSS signal data further includes (i) identifying an anomalous signal characteristic within the GNSS signal data of a first GNSS receiver or (ii) comparing the GNSS signal data of the first GNSS receiver with the GNSS signal data of a second GNSS receiver; and the EFB tablet device, located on-board each aircraft within the plurality of aircraft, with a wireless connection to the cloud-based alert system, wherein the tablet device is configured to (i) receive spoofing reports from the cloud-based alert system and (ii) report GNSS signal data, from the external GNSS, to the cloud-based alert system. 14. The distributed network of clause 13, wherein a spoofing event is detected in response to an identified anomalous signal characteristic, and wherein the identified anomalous signal characteristic is one or more of: an anomalous signal strength of satellite signals compared to other received satellite signal strengths, an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals, an anomalous pseudo range of the satellite signals, an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, incorrect, missing, or null values in the GNSS signal data, or a loss of usable GNSS signals followed by the anomalous signal characteristic. 15. The distributed network of clause 14, wherein the cloud-based alert system is further configured to receive, from the EFB tablet device linked to the external GNSS receiver, GNSS track and position data, and analyze the GNSS track and position data to identify an anomalous flight path characteristic indicative of a spoofing event, wherein the anomalous flight path characteristic is one or more of: a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute. 16. The distributed network of clause 13, wherein the cloud-based alert system is further configured to provide an alert of potential spoofing in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, or other GNSS users via a cloud-based connection. 17. The distributed network of clause 13, wherein the cloud-based alert system is further configured to store the GNSS signal data to a cloud storage. 18. The distributed network of clause 17, further including a deep learning model, trained using the stored GNSS signal data, configured to process GNSS signal data and generate, as output, a classification of the GNSS signal data as affected or unaffected by spoofing. 19. The distributed network of clause 18, wherein the trained deep learning model is further configured to generate, as output, a classification of a detected interference event within the GNSS signal data. 20. The distributed network of clause 13, wherein the cloud-based alert system is further configured to: receive GNSS signal data from multiple GNSS receivers including external GNSS receivers, and onboard certified avionics GNSS receivers; analyze the GNSS signal data from the multiple GNSS receivers; and compare the analyzed GNSS signal data across the multiple GNSS receivers to determine an area impacted by a detected spoofing threat, a size of the impacted area, and an expected impact on different types of GNSS systems. 21. The distributed network of clause 20, wherein the cloud-based alert system is further configured to receive GNSS signal data from a plurality of GNSS receivers located within the impacted area over multiple different times to determine a spoofing frequency within the impacted area. 22. The distributed network of clause 13, wherein the cloud-based alert system is further configured to receive ADS-B receiver data including a history of ADS-B receiver activity and detect a correlation between the GNSS signal data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with a detected spoofing event. 23. The distributed network of clause 13, wherein the cloud-based alert system is further configured to track identified anomalous signal characteristics over time, detect a pattern within the identified anomalous signal characteristics over time, and use the detected pattern to score the identified anomalous signal characteristics over time to quantify a certainty of spoofing. 24. The distributed network of clause 13, wherein the GNSS signal data is processed using an app running on the EFB device and further processed by the cloud-based alert system. Clauses Set 3; Using interference data from a plurality of sources 1. A method of cloud processing for global navigation satellite system (GNSS) interference data from a plurality of GNSS receivers to alert aircraft personnel to GNSS spoofing of aircraft guidance systems, the method including: receiving at a cloud-based server, GNSS interference data from the plurality of GNSS receivers including one or more of: a certified avionics GNSS receiver onboard an aircraft, an external GNSS receiver linked to an Electronic Flight Bag (EFB) tablet device and independent of onboard certified avionics, cellular networks, automatic dependent surveillance-broadcast (ADS-B) networks, or dedicated GNSS monitoring facilities; analyzing the GNSS interference data upon receipt, including one or more of: comparing a set of GNSS data for a particular aircraft to a plurality of operational limitations for the aircraft, comparing a first set of GNSS data to a second set of GNSS data, wherein the first and second sets of GNSS data are received from different GNSS receivers, onboard the same particular aircraft and operating independently of one another, or comparing a set of GNSS data for a first aircraft to a set of GNSS data for a second aircraft; identifying an interference event from the analyzed GNSS interference data, wherein the interference event is an anomalous flight path characteristic of an aircraft or an anomalous signal characteristic of a GNSS signal; and in response to an identified interference event, the cloud-based server providing an alert to EFB tablet devices onboard the aircraft notifying aircraft personnel of a potential spoofing event. 2. The method of clause 1, wherein the GNSS interference data further includes one or more of: GNSS track and position data, GNSS signal data, GNSS signal timing data, Receiver Independent Exchange Format (RINEX) data, GNSS data by satellite data, uncompressed radiofrequency recordings, or GNSS dilution of precision (DOP) value data. 3. The method of clause 2, further including analyzing the GNSS track and position data to identify an anomalous flight path characteristic indicative of a interference event, wherein the anomalous flight path characteristic is one or more of: a detected jump in position along a flight path segment that exceeds an airspeed limitation for an aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute. 4. The method of clause 2, further analyzing the GNSS signal data to identify an anomalous signal characteristic indicative of a interference event, wherein the anomalous signal characteristic is one or more of: an anomalous signal strength of satellite signals compared to other received satellite signal strengths, an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals, an anomalous pseudo range of the satellite signals, an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, or a loss of usable GNSS signals followed by the anomalous signal characteristic. 5. The method of clause 1, further including providing an alert of the potential spoofing event in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, mobile network operators, airports, vehicle networks including V2X networks, or other GNSS users via a cloud-based connection. 6. The method of clause 1, further including storing the GNSS interference data to a cloud storage. 7. The method of clause 6, further including training a deep learning model, using the stored GNSS interference data, to process GNSS interference data and generate, as output, a classification of the GNSS interference data as affected or unaffected by interference. 8. The method of clause 7, wherein the trained deep learning model is further trained to generate, as output, a classification of a detected interference event within the GNSS interference data. 9. The method of clause 1, further including analyzing the GNSS interference data from the plurality of GNSS receivers, and comparing the analyzed GNSS interference data across the plurality of GNSS receivers to determine an area impacted by a detected interference threat, a size of the impacted area, and an expected impact on different types of GNSS systems. 10. The method of clause 9, further including receiving GNSS interference data from the plurality of GNSS receivers located within the impacted area over multiple different times to determine an interference frequency within the impacted area. 11. The method of clause 1, further including receiving ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between the GNSS interference data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with an identified interference event. 12. The method of clause 1, further including tracking identified interference events over time, detecting a pattern within the identified interference events over time, and using the detected pattern to score the identified interference events over time to quantify a certainty of spoofing. 13. The method of clause 1, further including processing the GNSS interference data using an app running on the EFB device and further processing the GNSS interference data using the cloud-based server. 14. A distributed network configured to analyze global navigation satellite system (GNSS) interference data from a plurality of GNSS receiver sources to detect spoofing events impacting a plurality of aircraft, the distributed network including: a cloud-based alert system configured to analyze the GNSS interference data received from the plurality of sources in order to detect spoofing events and report detected spoofing events to EFB tablet devices onboard the plurality of aircraft, wherein analyzing the GNSS interference data further includes one or more of: comparing a set of GNSS data for a particular aircraft to a plurality of operational limitations for the aircraft, comparing a first set of GNSS data to a second set of GNSS data, wherein the first and second sets of GNSS data are received from different GNSS receivers, onboard the same particular aircraft and operating independently of one another, or comparing a set of GNSS data for a first aircraft to a set of GNSS data for a second aircraft; and an Electronic Flight Bag (EFB) tablet device, located on-board each aircraft within the plurality of aircraft, with a wireless connection to the cloud-based alert system, wherein the EFB tablet device (i) receives spoofing reports from the cloud-based alert system and (ii) reports GNSS interference data to the cloud-based alert system. 15. The distributed network of clause 14, wherein the plurality of GNSS receivers includes at least one of: a certified avionics GNSS receiver onboard an aircraft, an external GNSS receiver linked to the EFB tablet device and independent of onboard certified avionics, 5G networks, automatic dependent surveillance-broadcast (ADS-B) networks, or dedicated GNSS monitoring facilities. 16. The distributed network of clause 14, wherein the GNSS interference data further includes one or more of: GNSS track and position data, GNSS signal data, GNSS signal timing data, Receiver Independent Exchange Format (RINEX) data, GNSS data by satellite data, uncompressed radiofrequency recordings, or GNSS dilution of precision (DOP) value data. 17. The distributed network of clause 16, wherein the cloud-based alert system is further configured to analyze the GNSS track and position data to identify an anomalous flight path characteristic indicative of a potential spoofing event, wherein the anomalous flight path characteristic is one or more of: a detected jump in position along a flight path segment that exceeds an airspeed limitation for the aircraft, a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft, a turn performed exceeding a range of 1.5-3 degrees per second, a change in speed greater than 10 knots / second, or a change in altitude greater than 6000 feet / minute. 18. The distributed network of clause 16, wherein the cloud-based alert system is further configured to analyze the GNSS signal data to identify an anomalous signal characteristic indicative of a potential spoofing event, wherein the anomalous signal characteristic is one or more of: an anomalous signal strength of satellite signals compared to other received satellite signal strengths, an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals, an anomalous pseudo range of the satellite signals, an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, incorrect, missing, or null values in the GNSS signal data, or a loss of usable GNSS signals followed by the anomalous signal characteristic. 19. The distributed network of clause 14, wherein the cloud-based alert system is further configured to provide an alert of a potential spoofing event in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, mobile network operators, airports, vehicle networks including V2X networks, or other GNSS users via a cloud-based connection. 20. The distributed network of clause 14, wherein the cloud-based alert system is further configured to store the GNSS interference data to a cloud storage. 21. The distributed network of clause 20, further including a deep learning model, trained using the stored GNSS interference data, to process GNSS interference data and generate, as output, a classification of the GNSS interference data as affected or unaffected by spoofing. 22. The distributed network of clause 21, wherein the trained deep learning model is further configured to generate, as output, a classification of a detected interference event within the GNSS interference data. 23. The distributed network of clause 14, wherein the cloud-based alert system is further configured to analyze the GNSS interference data from the plurality of GNSS receivers, and compare the analyzed GNSS interference data across the plurality of GNSS receivers to determine an area impacted by a detected interference threat, a size of the impacted area, and an expected impact on different types of GNSS systems. 24. The distributed network of clause 23, wherein the cloud-based alert system is further configured to receive GNSS interference data from the plurality of GNSS receivers located within the impacted area over multiple different times to determine an interference frequency within the impacted area. 25. The distributed network of clause 14, wherein the cloud-based alert system is further configured to receive ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between the GNSS interference data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with an identified interference event. 26. The distributed network of clause 14, wherein the cloud-based alert system is further configured to track identified interference events over time, detect a pattern within the identified interference events over time, and use the detected pattern to score the identified interference events over time to quantify a certainty of spoofing. 27. The distributed network of clause 14, wherein the GNSS interference data is processed using an app running on the EFB device and further processed by the cloud-based alert system.

Claims

We claim as follows:

1. A method of cloud processing for global navigation satellite system (GNSS) interference data from a plurality of GNSS receivers to alert aircraft personnel to GNSS spoofing of aircraft guidance systems, the method including:receiving at a cloud-based server, GNSS interference data from the plurality of GNSS receivers including one or more of:a certified avionics GNSS receiver onboard an aircraft,an external GNSS receiver linked to an Electronic Flight Bag (EFB) tablet device and independent of onboard certified avionics, cellular networks,automatic dependent surveillance-broadcast (ADS-B) networks, ordedicated GNSS monitoring facilities;analyzing the GNSS interference data upon receipt, including one or more of:comparing a set of GNSS data for a particular aircraft to a plurality of operational limitations for the aircraft,comparing a first set of GNSS data to a second set of GNSS data, wherein the first and second sets of GNSS data are received from different GNSS receivers, onboard the same particular aircraft and operating independently of one another, orcomparing a set of GNSS data for a first aircraft to a set of GNSS data for a second aircraft;identifying an interference event from the analyzed GNSS interference data, wherein the interference event is an anomalous flight path characteristic of an aircraft or an anomalous signal characteristic of a GNSS signal; andin response to an identified interference event, the cloud-based server providing an alert to EFB tablet devices onboard the aircraft notifying aircraft personnel of a potential spoofing event.

2. The method of claim 1, wherein the GNSS interference data further includes one or more of: GNSS track and position data, GNSS signal data, GNSS signal timing data, Receiver Independent Exchange Format (RINEX) data, GNSS data by satellite data, uncompressed radiofrequency recordings, or GNSS dilution of precision (DOP) value data.

3. The method of claim 1 or claim 2, further including analyzing the GNSS track and position data to identify an anomalous flight path characteristic indicative of a interference event, wherein the anomalous flight path characteristic is one or more of:a detected jump in position along a flight path segment that exceeds an airspeed limitation for an aircraft,a detected movement along the flight path segment that exceeds the airspeed limitation for the aircraft or a minimum turn radius limitation for the aircraft,a turn performed exceeding a range of 1.5-3 degrees per second,a change in speed greater than 10 knots / second, ora change in altitude greater than 6000 feet / minute.

4. The method of any preceding claim, further analyzing the GNSS signal data to identify an anomalous signal characteristic indicative of a interference event, wherein the anomalous signal characteristic is one or more of:an anomalous signal strength of satellite signals compared to other received satellite signal strengths,an anomalous signal strength of satellite signals for an elevation and azimuth of source satellites, an anomalous elevation or azimuth of the satellite signals,an anomalous pseudo range of the satellite signals,an anomalous clock stability of the satellite signals, anomalous time codes of the satellite signals compared to other received satellite signals, or a loss of usable GNSS signals followed by the anomalous signal characteristic.

5. The method of any preceding claim, further including providing an alert of the potential spoofing event in a specific area to other aircraft via onboard EFB tablets, an air traffic control base station, mobile network operators, airports, vehicle networks including V2X networks, or other GNSS users via a cloud-based connection.

6. The method of any preceding claim, further including receiving ADS-B receiver data including a history of ADS-B receiver activity and detecting a correlation between the GNSS interference data and the history of ADS-B receiver activity to associate a particular ADS-B receiver with an identified interference event.

7. The method of any preceding claim, further including tracking identified interference events over time, detecting a pattern within the identified interference events over time, and using the detected pattern to score the identified interference events over time to quantify a certainty of spoofing.

8. The method of any preceding claim, further including processing the GNSS interference data using an app running on the EFB device and further processing the GNSS interference data using the cloud-based server.

9. The method of any preceding claim, further including storing the GNSS interference data to a cloud storage.

10. The method of claim 9, further including training a deep learning model, using the stored GNSS interference data, to process GNSS interference data and generate, as output, a classification of the GNSS interference data as affected or unaffected by interference.

11. The method of claim 10, wherein the trained deep learning model is further trained to generate, as output, a classification of a detected interference event within the GNSS interference data.

12. The method of any preceding claim, further including analyzing the GNSS interference data from the plurality of GNSS receivers, and comparing the analyzed GNSS interference data across the plurality of GNSS receivers to determine an area impacted by a detected interference threat, a size of the impacted area, and an expected impact on different types of GNSS systems.

13. The method of claim 12, further including receiving GNSS interference data from the plurality of GNSS receivers located within the impacted area over multiple different times to determine an interference frequency within the impacted area.

14. A tangible non-transitory computer readable storage media impressed with computer program instructions that, when executed, implement the method of any of claims 1-13.

15. A distributed network configured implement the method of any of claims 1-13, the distributed network including a cloud-based alert system and an Electronic Flight Bag (EFB) tablet device.50

Citation Information

Patent Citations

  • Recording, storage and playback of GNSS signals

    GB2492547A

  • GNSS forecast impacting receiver startup

    US12265159B2

  • Generating and distributing GNSS risk analysis data for facilitating safe routing of autonomous drones

    US12292515B2

  • GNSS forecast and background obscuration prediction

    US12298409B2

  • GNSS forecast and spoofing / jamming detection

    US12429599B2