Signal authentication adapter
The signal authentication adapter addresses spoofing vulnerabilities in positioning devices by authenticating satellite signals using digital signatures, ensuring accurate positioning without additional processing load or cost, and is compatible with devices lacking built-in authentication.
Patent Information
- Application Number
- JP2024041691
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-15
- Publication Date
- 2025-09-29
AI Technical Summary
Existing positioning devices lack a signal authentication function, making them vulnerable to spoofing attacks, and adding a signal authentication function to all devices is costly and burdensome, especially when communication failures prevent authentication verification.
A signal authentication adapter that connects to a positioning device, authenticates satellite signals using digital signatures from a controlled satellite system, and outputs authentication results without imposing a processing load on the device.
Provides satellite signal authentication to devices without a built-in function, ensuring accurate positioning results and preventing spoofing attacks at a lower cost by integrating an authentication function as an add-on device.
Smart Images

Figure 2025141663000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a signal authentication adapter that authenticates satellite signals for positioning. [Background technology]
[0002] Conventionally, there is a positioning technology that receives signals from satellites and estimates the position of a positioning device. This positioning technology basically uses the positions of four or more satellites and the time it takes for the satellite signals from each of these satellites to reach the positioning device (GNSS). In recent years, spoofing attacks have been carried out in which a device that transmits false satellite signals masquerading as satellite signals is installed, causing the positioning device to receive the false satellite signals and calculate false location information. FIG. 9 illustrates an example of a conventional configuration of a positioning system. Conventionally, a positioning device 900 receives satellite signals (including ephemeris data) 91a, 91b, 91c, and 91d from multiple satellites 90a, 90b, 90c, and 90d, respectively, and performs positioning based on these satellite signals. Here, a spoofer 30 attempting a spoofing attack transmits a signal 31 similar to the satellite signal. The spoofer 30 is a device that transmits radio waves masquerading as a satellite. Note that FIG. 9 shows an example in which the spoofer 30 also transmits four signals 31, similar to the satellite signals, but these signals are mutually different. Also, while FIG. 9 shows only one spoofer 30, there may be multiple spoofers, each of which may transmit a signal 31 separately. Here, the spoofer 30 is typically installed on the ground, and if the signal strength is stronger than that of the signal from the satellite, the positioning device 900 may use the signal 31 (and two satellite signals) from this spoofer 30 to estimate its own location information. In this case, the positioning device 900 cannot calculate accurate location information. Therefore, Patent Document 1 discloses a navigation message authentication system that authenticates whether a signal received by an in-vehicle device performing positioning is a legitimate signal. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6427889 Summary of the Invention [Problem to be solved by the invention]
[0004] Many existing receivers do not have a signal authentication function. On the other hand, from the perspective of signal reliability, the spread of receivers with a signal authentication function is inevitable. However, for users who use many receivers, purchasing a new receiver with a signal authentication function is considered to be a burden. By utilizing the technology described in Patent Document 1, the in-vehicle device transmits the received satellite signal to an external authentication center via communication, and the authentication center performs authentication. The in-vehicle device receives the authentication result, so as to avoid imposing a processing load on the in-vehicle device due to the addition of an authentication function. This allows the in-vehicle device to determine whether the received satellite signal is a legitimate satellite signal. However, if the in-vehicle device is unable to communicate with the authentication center due to some reason (e.g., a communication failure), the in-vehicle device may be unable to determine whether the received satellite signal is a legitimate satellite signal. Therefore, there is a need for a device that can authenticate satellite signals at any time, even with receivers that do not have the current signal authentication function, at a lower cost than purchasing a new receiver with a signal authentication function and that can achieve this without imposing a processing load due to authentication on the receiver itself.
[0005] Therefore, the present invention has been made in consideration of the above problems and demands, and aims to provide a signal authentication adapter that can notify whether positioning is normal or not, even for a positioning device that does not have an authentication function. [Means for solving the problem]
[0006] A signal authentication adapter in one embodiment of the present invention includes a connection unit that connects to a positioning device, an I / O unit that receives from the positioning device a satellite signal received by the positioning device, an authentication unit that authenticates the satellite signal received by the I / O unit, and an output unit that outputs the authentication result of the satellite signal by the authentication unit.
[0007] The signal authentication adapter may further include a storage unit that stores a public key, and the satellite signal may be a signal with a digital signature attached that is generated from a hash value of ephemeris data consisting of satellite orbit information and satellite clock information using a private key that corresponds to the public key. The authentication unit may extract the digital signature from the satellite signal received by the I / O unit and verify the digital signature using the ephemeris data included in the satellite signal and the public key that has been stored in advance in the storage unit, thereby authenticating whether the satellite signal is a signal transmitted from a legitimate satellite.
[0008] Furthermore, in the above signal authentication adapter, the positioning device may perform positioning using a first satellite signal from a first satellite that does not have a signal authentication function, the signal authentication adapter may include a receiving unit that receives a second satellite signal from a second satellite that has a signal authentication function, and the authentication unit may authenticate the first satellite signal using authentication information included in the second satellite signal.
[0009] The signal authentication adapter may further include a memory unit that stores a public key, and the authentication information is a digital signature generated from a hash value of ephemeris data included in the first satellite signal using a private key corresponding to the public key. The authentication unit may verify the authentication information included in the second satellite signal using the first satellite signal and the public key corresponding to the private key, thereby authenticating the first satellite signal. [Effects of the Invention]
[0010] A signal authentication adapter according to one embodiment of the present invention can provide a satellite signal authentication function to a positioning device that does not have such a function. [Brief explanation of the drawings]
[0011] [Figure 1] 1 is a system diagram showing an example of the configuration of a positioning system according to a first embodiment. [Figure 2] 1 is a block diagram showing an example of the configuration of a positioning device and a signal authentication adapter according to a first embodiment. [Figure 3] 4 is a first flowchart showing an example of the operation of the positioning device according to the first embodiment. [Figure 4] 10 is a second flowchart showing an example of the operation of the authentication device in the first embodiment. [Figure 5] 10 is a third flowchart illustrating an example of the operation of the positioning device according to the second embodiment. [Figure 6] 10 is a fourth flowchart illustrating an example of the operation of the authentication device according to the second embodiment. [Figure 7] FIG. 11 is a system diagram showing an example of the configuration of a positioning system according to a third embodiment. [Figure 8] 13 is a fifth flowchart showing an example of the operation of the authentication device according to the third embodiment. [Figure 9] FIG. 1 is a diagram illustrating a conventional positioning system. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, a signal authentication adapter according to one embodiment of the present invention will be described in detail with reference to the drawings.
[0013] <First Embodiment> <Summary> FIG. 1 is a diagram illustrating an example of the configuration of a positioning system. Since GPS receivers are currently widely used, the first embodiment will be described using a receiver that performs positioning using GPS (or Galileo or QZSS). That is, the satellite signals to be authenticated are satellite signals to which electronic signature information (also referred to as electronic signature, authentication information, or digital signature) from GPS satellites (or Galileo satellites) is not attached. Note that the satellite signals to be authenticated in this embodiment are the L1C / A signal, L5 signal, and L1C signal in the case of GPS, and the E1BC signal and E5A signal in the case of Galileo, none of which currently have electronic signatures attached. The first embodiment aims to provide a signal authentication adapter that can authenticate even satellite signals to which electronic signatures from the satellites are not attached. Hereinafter, the terms GPS satellite and GPS satellite signal refer to general satellites that transmit satellite signals that do not support signal authentication (i.e., signals to which electronic signature information is not attached), including GPS and Galileo. If other satellites (such as GLONASS and BeiDou) are added in the future, they will also be included.
[0014] A positioning system according to the first embodiment will be described with reference to FIG. 1. A positioning device 200 according to the first embodiment performs positioning using a satellite signal 21a from a satellite 20a, which is a GPS satellite. The positioning device 200 receives satellite signals 21a from multiple satellites 20a and estimates its own position. Here, the positioning device 200 does not have a function for authenticating satellite signals from the satellites. Therefore, a signal authentication adapter 100 having a signal authentication function is externally attached to the positioning device 200.
[0015] At this time, there may be a spoofer (not shown) in the positioning system that transmits a false satellite signal. Therefore, it is conceivable to authenticate the satellite signal by including authentication information (e.g., a digital signature) in the satellite signal 21a. However, the digital signature used for signal authentication cannot be assigned to the satellite signal 21a, whose distribution signal cannot be controlled. Therefore, a satellite signal including the digital signature for the satellite signal 21a is transmitted to the signal authentication adapter 100 by the satellite signal 21b from satellite 20b, a QZSS satellite whose distribution signal can be controlled. Satellite 20b itself does not recognize the type of signal transmitted by satellite 20a. Therefore, the satellite signal 21b transmitted by satellite 20b is generated by the ground control station 300. Specifically, the ground control station 300 first acquires the satellite signal 21a transmitted by satellite 20a. The ground control station 300 may acquire the satellite signal 21a by receiving the satellite signal 21a transmitted from the satellite 20a. Alternatively, the satellite signal 21a to be transmitted by the satellite 20a is appropriately controlled by the ground control station 300 (for time correction, etc.), and the signal may be acquired at the time of this control. The ground control station 300 generates a digital signature using the satellite signal 21a from the GPS satellite 20a. The digital signature is data obtained by encrypting a hash value of the ephemeris data using a private key. In other words, the ground control station 300 generates the digital signature using the hash value of the ephemeris data of the satellite signal 21a and the private key. The ground control station 300 instructs the QZSS satellite 20b to transmit the generated digital signature in a specified signal band (L6 band). The satellite 20b appropriately transmits the satellite signal 21b including the received digital signature. The satellite 21b may also transmit its own ephemeris data as appropriate, in addition to the digital signature of the satellite 20a.
[0016] Therefore, in this case, satellite signal 21b includes information indicating that this signal is a signal including information for authenticating the signal transmitted from satellite 20a, and a digital signature for authentication. Positioning device 200 receives satellite signal 21a transmitted from satellite 20a.
[0017] Here, the positioning device 200 transmits the received satellite signal 21a to the signal authentication adapter 100 to authenticate the received satellite signal 21a. Meanwhile, the signal authentication adapter 100 is connected to the positioning device 200 to receive the satellite signal 21a from the positioning device 200 and also receives the satellite signal 21b transmitted from the satellite 20b. The satellite signal 21b includes a digital signature for authenticating the satellite signal 21a. The received satellite signal 21b is used to authenticate the satellite signal 21a transmitted from the positioning device 200. A public key corresponding to the aforementioned private key is pre-stored in the signal authentication adapter 100. Therefore, the signal authentication adapter 100 authenticates the satellite signal 21a using both the satellite signal 21a and the satellite signal 21b, as well as the public key. As a result, by connecting the signal authentication adapter 100, the positioning device 200 can authenticate the received satellite signal 21a. Furthermore, by providing the signal authentication adapter 100 with the function of receiving the QZSS satellite signal 21b, signal authentication can be performed even if the positioning device 200 is a device that performs positioning using a system that does not support the signal authentication function. This will be explained in detail below.
[0018] <Configuration> In the first embodiment, an example will be described in which a signal authentication adapter 100 externally attached to the positioning device 200 determines whether or not the satellite signal 21a received by the positioning device 200 is a legitimate signal.
[0019] FIG. 2 is a block diagram showing an example of the configuration of the positioning device 200 and the signal authentication adapter 100. As shown in FIG.
[0020] First, the positioning device 200 will be described. The positioning device 200 is basically a conventional positioning device, i.e., a so-called GPS receiver. The positioning device 200 has a function of receiving satellite signals 21a from GPS satellites. The positioning device 200 differs from conventional GPS receivers in that it includes a connection unit that physically connects the signal authentication adapter via a wired connection and an I / O unit 220 for information transmission. This connection unit may be newly provided in the positioning device 200. For example, if the positioning device 200 originally includes a port for connecting to an external device, such as a USB port, this connection unit may be substituted by the USB port. It is desirable that the positioning device 200 be connected to the signal authentication adapter 100 via such a port via a wired connection. However, if the positioning device 200 includes a wireless communication function, such as a short-range wireless communication function, the connection unit may be realized by the wireless communication function. The positioning device 200 includes a receiving unit 210, an I / O unit 220, a positioning unit 230, a storage unit 240, and an output unit 250. The positioning device 200 is an information processing device (computer system) that performs positioning of its own device by executing a program stored in the storage unit 240. The positioning device 200 may be, for example, a car navigation system, but is not limited to this as long as it has a positioning function, and may be, for example, a smartphone or the like.
[0021] The receiving unit 210 receives satellite signals via an antenna and transmits them to the I / O unit 220 and the positioning unit 230. The satellite signals received by the receiving unit 210 may be satellite signals 21a from legitimate satellites or may be signals from spoofers.
[0022] The I / O unit 220 is a communication interface that has the function of transmitting the satellite signal transmitted by the receiving unit 210 to the signal authentication adapter 100. The I / O unit 220 is basically connected to the I / O unit 110 of the signal authentication adapter 100 via a wired connection and transmits information, but this connection may also be wireless.
[0023] The positioning unit 230 calculates the position information of the device itself based on the transmitted satellite signals. The method for calculating the position information may be the same as existing technology, and details thereof will be omitted.
[0024] The storage unit 240 is a storage medium having the function of storing various programs and data required for the operation of the positioning device 200. The storage unit 240 may be realized by, for example, an HDD, an SSD, a flash memory, or the like, and may include a ROM and a RAM. The storage unit 240 may store a program for estimating the position information of the device itself based on the ephemeris of the satellite signal 21.
[0025] The output unit 250 outputs the positioning result measured by the positioning unit 230. The positioning result may be output by plotting the position on a map, or by outputting numerical values of latitude and longitude as text or audio, or may be output in a form that transmits the position information via communication to an external device that requires it.
[0026] The above is an example of the configuration of the positioning device 200.
[0027] The signal authentication adapter 100 includes an I / O unit 110, an authentication unit 120, a storage unit 130, an output unit 140, and a receiving unit 150. The signal authentication adapter 100 is an information processing device (computer system) that executes a program stored in the storage unit 130 to authenticate whether a satellite signal is a signal transmitted from a legitimate satellite. The signal authentication adapter 100 includes a connection unit for physically connecting to the positioning device 200. This connection unit may be implemented by a USB port or the like, or a dedicated connection mechanism may be provided. It is preferable that the signal authentication adapter 100 be connected to the positioning device 200 via such a port via a wired connection. However, if the positioning device 200 has a wireless communication function such as a short-range wireless communication function, the connection unit of the signal authentication adapter 100 may also be implemented by a wireless communication function capable of wireless communication with the wireless communication function of the positioning device 200.
[0028] The I / O unit 110 receives the satellite signal transmitted from the positioning device 200 and transmits it to the authentication unit 120 .
[0029] Authentication unit 120 has a function of authenticating whether satellite signal 21a transmitted from I / O unit 110 is a legitimate satellite signal. Specifically, authentication unit 120 authenticates satellite signal 21a using a digital signature included in satellite signal 21b from a QZSS satellite received by receiver 150 and a public key stored in storage unit 130. Authentication unit 120 transmits information indicating the authentication result to output unit 140. In addition to information indicating whether authentication was successful, the information indicating the authentication result may also include, in the case of an authentication failure, frequency information indicating the frequency band used for communication by the satellite signal that failed to be authenticated, and information on which satellite the satellite signal that failed to be authenticated was received from (which satellite it is masquerading as).
[0030] The storage unit 130 is a storage medium having a function of storing various programs and various data required for the operation of the signal authentication adapter 100. The storage unit 130 may be realized by, for example, a hard disk drive (HDD), a solid state drive (SSD), or a flash memory, and may include a read-only memory (ROM) and a random access memory (RAM). The storage unit 130 pre-stores a public key used for authentication. The storage unit 130 also stores a program for authenticating satellite signals using the satellite signals and the public key. The public key stored in the storage unit 130 may be, for example, a public key received from the ground control station 300 when a public key is requested from the ground control station 300 (or a server providing a satellite signal authentication service) and permission is obtained from the ground control station 300 (when the identity of the user using the positioning device 200 has been verified).
[0031] The output unit 140 has a function of outputting the authentication result transmitted from the authentication unit 120. The output unit 140 may output the authentication result as an image, text, or sound indicating whether the satellite signal is a signal transmitted from a valid satellite, i.e., whether authentication was successful or not. The output unit 140 may output a specific colored lamp (e.g., green) to indicate successful authentication and a specific colored lamp (e.g., red) to indicate unsuccessful authentication, or may output the lamp only in the case of unsuccessful authentication. If the lamp is lit only in the case of unsuccessful authentication, the user of the positioning device 200 can recognize that a spoofer's signal may have been received at that timing. The output unit 140 may also output information indicating the frequency used by the spoofer to transmit the signal. The output unit 140 may also output information indicating which satellite the unsuccessful satellite signal was supposed to have been received from.
[0032] The receiver 150 receives the satellite signals 21b from the QZSS satellites from an antenna connected to the signal authentication adapter. If the antenna connected to the positioning device 100 is capable of receiving the digital signatures included in the satellite signals 21b from the QZSS satellites, the line (cable) from the antenna may be branched and connected to the signal authentication adapter to receive the satellite signals 21b.
[0033] Therefore, by recognizing the output result from the output unit 140, the user of the positioning device 200 can recognize whether the positioning result from the positioning device 200 is correct or possibly incorrect. Therefore, if authentication fails, the signal received by the positioning device 200 may be a spoofer signal, and the user can act on the assumption that the positioning result from the positioning device 200 is incorrect. Furthermore, since the signal authentication adapter 100 is directly connected to the positioning device 200, there is no need to communicate with an authentication center via a network as in Patent Document 1. This avoids a situation in which the user cannot communicate with the authentication center and therefore cannot determine whether the positioning result from the positioning device 200 is correct.
[0034] <Operation> FIG. 3 is a flowchart showing an example of the operation of the positioning device 200.
[0035] 3, the receiver 210 of the positioning device 200 receives a satellite signal via an antenna (step S301). The satellite signal may be a legitimate signal from a satellite or may be a signal from a spoofer. Upon receiving the satellite signal, the receiver 210 transmits the received satellite signal to the I / O unit 220 and the positioning unit 230.
[0036] When the I / O unit 220 receives the satellite signal from the receiving unit 210, it transmits the satellite signal to the signal authentication adapter 100 (step S302). On the other hand, when the positioning unit 230 receives the satellite signal from the receiving unit 210, it performs positioning based on the received satellite signal (step S303). Note that the positioning unit 230 performs positioning using signals from four or more different signal sources transmitted by the receiving unit 210. The positioning unit 230 performs positioning in the same manner as a normal GPS receiver. The positioning unit 230 transmits the positioning result to the output unit 250.
[0037] The output unit 250 outputs the positioning result from the positioning unit 230 (step S304), and ends the process. Note that the positioning device 200 may repeatedly execute the process shown in Fig. 3 unless the power is turned off or an instruction to stop positioning is given.
[0038] 4 is a flowchart showing an example of the operation of the signal authentication adapter 100. As shown in FIG. 4, the I / O unit 110 of the signal authentication adapter 100 receives the first satellite signal 21a from the positioning device 200 (step S401). That is, the I / O unit 110 receives the satellite signal 21a of a GPS satellite that includes ephemeris data but does not include a digital signature as authentication information. The I / O unit 110 transmits the received satellite signal 21a to the authentication unit 120.
[0039] Next, receiver 150 receives second satellite signal 21b from a QZSS satellite (step S402). That is, receiver 150 receives satellite signal 21b from a QZSS satellite that includes a digital signature as authentication information. Receiver 150 transmits received satellite signal 21b to authentication unit 120.
[0040] When the authentication unit 120 receives the first satellite signal (satellite signal 21a from a GPS satellite) and the second satellite signal (satellite signal 21b from a QZSS satellite), it performs authentication using the first satellite signal and the second satellite signal (S403). Specifically, the authentication unit 120 extracts the ephemeris from the received satellite signal 21a. The authentication unit 120 also extracts the digital signature from the received satellite signal 21b. The authentication unit 120 confirms that the second satellite signal 21b corresponds to the first satellite signal 21a, and verifies the digital signature extracted from the satellite signal 21b (QZSS satellite signal) using the ephemeris data extracted from the satellite signal 21a (GPS satellite signal) and the public key stored in the storage unit 130. If the verification is successful, the first satellite signal is determined to be a legitimate signal; if the verification is unsuccessful, the first satellite signal is determined to be an illegitimate signal.
[0041] Based on the verification result, authentication unit 120 determines whether authentication is successful (step S404). That is, it determines whether the first satellite signal is a signal from a legitimate satellite. Authentication unit 120 transmits the authentication result to output unit 140.
[0042] If authentication is successful (YES in step S404), that is, if the first satellite signal is a signal from a legitimate satellite, output unit 140 outputs authentication success (step S405) and ends the process. If authentication fails (NO in step S403), output unit 140 outputs authentication failure (step S406) and ends the process. Note that it is essential for signal authentication adapter 100 to output authentication failure, and if authentication is successful, it may be configured not to output anything. Alternatively, it may output either authentication success or authentication failure instead of the other output.
[0043] The above is an example of the operation of the positioning device 200 and the signal authentication adapter 100.
[0044] <Summary of First Embodiment> The signal authentication adapter 100 according to the first embodiment can authenticate satellite signals received by the positioning device 200 simply by connecting it to a conventional GPS positioning device 200, even if the positioning device 200 receives GPS satellite signals that do not support authentication functions. By directly connecting to the positioning device 200, the signal authentication adapter 100 authenticates satellite signals received by the positioning device 200. If authentication is unsuccessful, the signal authentication adapter 100 can notify the user that the positioning device 200 may have performed positioning using spoofer signals. Therefore, the user of the positioning device 200 can be cautious that the output location information may be incorrect. Furthermore, since the signal authentication adapter 100 simply adds an authentication function to the positioning device 200, it is possible to provide a positioning device with a signal authentication function at a lower cost than replacing the positioning device with one that has the signal authentication function. In other words, the signal authentication adapter 100 can be provided as an add-on device that can easily add authentication functions to a positioning device 200 that does not have the signal authentication function. Furthermore, even if the satellite signal is of a positioning system that does not support the authentication function, the signal authentication adapter 100 can perform authentication by receiving authentication information for the satellite signal received by the connected positioning device from a satellite of another positioning system that supports the signal authentication function. Furthermore, because the signal authentication function itself is realized by the signal authentication adapter, the processing load on the receiver itself does not increase due to signal authentication.
[0045] <Embodiment 2> In the above-mentioned first embodiment, the signal authentication adapter 100 allows a user of the positioning device 200 to recognize whether the satellite signal received by the positioning device 200 is a legitimate signal, but the positioning device 200 in the above-mentioned first embodiment inevitably outputs erroneous position information after positioning. Therefore, in the second embodiment, a positioning device 200 and a signal authentication adapter 100 configured to prevent such erroneous position information from being output will be described. In the second embodiment, differences from the first embodiment will be described.
[0046] <Configuration> The configurations of the positioning device 200 and the signal authentication adapter 100 according to the second embodiment may be the same as those shown in the first embodiment (see the block diagram in FIG. 2). However, the following functions are different from those of the first embodiment.
[0047] In the first embodiment, the I / O unit 220 of the positioning device 200 only transmits the satellite signals received by the receiving unit 210 to the I / O unit 110 of the signal authentication adapter 100. However, in the second embodiment, the I / O unit 220 further receives, from the signal authentication adapter 100, frequency information of satellite signals that have failed to be authenticated in the signal authentication adapter 100 and transmits the received satellite signals to the positioning unit 230. Note that although the frequency information is described as being received here, this may be replaced by a configuration in which the I / O unit 220 receives satellite signals that have been successfully authenticated and transmits them to the positioning unit 230. Note that the frequency information may be transmitted to the receiving unit 210. In this case, the receiving unit 210 may have a filter function that cuts off signals of the frequency indicated by the transmitted frequency information. The frequencies of satellite signals that have failed to be authenticated are unwanted frequencies because they are the frequencies of signals used by spoofers. Furthermore, when the I / O unit 220 receives information indicating successful authentication, it may transmit that information to the positioning unit 230.
[0048] Positioning unit 230 estimates location information using only satellite signals that have been successfully authenticated (satellite signals received at frequencies other than those of satellite signals that have failed authentication). Therefore, positioning device 200 can always output correct location information. Positioning unit 230 may wait without performing positioning based on the received satellite signals until receiving unit 210 receives the authentication result of the received satellite signals.
[0049] On the other hand, the signal authentication adapter 100 according to the second embodiment includes an I / O unit 110, an authentication unit 120, a storage unit 130, an output unit 140, and a receiving unit 150, and the configuration itself is the same as that of the first embodiment. Furthermore, the signal authentication adapter 100 according to the second embodiment is similar in processing up to the point where the I / O unit 110 receives a satellite signal from the positioning device 200 and the authentication unit 120 performs authentication. On the other hand, the signal authentication adapter 100 differs from the first embodiment in that the authentication unit 120 returns frequency information of a satellite signal that has failed to be authenticated to the positioning device 200 via the I / O unit 110. Furthermore, if authentication is successful, the authentication unit 120 may return a message to that effect to the positioning device 200 via the I / O unit 110. Note that the I / O unit 110 may return the satellite signal that has been successfully authenticated, instead of the frequency information of the satellite signal that has failed to be authenticated. The information output by the I / O unit 110 to the I / O unit 110 may be information in RTCM format.
[0050] In the second embodiment, the positioning device 200 basically performs positioning using only satellite signals that have been successfully authenticated, and is therefore configured to basically output only correct location information, so the signal authentication adapter 100 may not be provided with the output unit 140 as shown in the first embodiment.
[0051] <Operation> 5 and 6, the operations of the positioning device 200 and the signal authentication adapter 100 according to the second embodiment will be described. Here, the processes executed by the positioning device 200 and the signal authentication adapter 100, respectively, that differ from those in the first embodiment will be described.
[0052] FIG. 5 is a flowchart showing an example of the operation of the positioning device 200 according to the second embodiment.
[0053] The flowchart shown in Fig. 5 differs from the flowchart shown in Fig. 3 in that the processing in steps S503 to S506 is performed instead of the processing in steps S303 and S304. This difference will be described below.
[0054] The I / O unit 220 of the positioning device 200 transmits the received first satellite signal to the signal authentication adapter 100 (step S302) and waits until it receives from the signal authentication adapter 100 either information indicating successful authentication or frequency information of a satellite signal that has failed to be authenticated (step S503). If the I / O unit 220 receives frequency information of a satellite signal that has failed to be authenticated from the signal authentication adapter 100 (YES in step S503), the I / O unit 220 transmits the received frequency information to the positioning unit 230. Then, the positioning unit 230 excludes satellite signals having the frequency indicated by the transmitted frequency information (step S504). If the I / O unit 220 receives information indicating successful authentication from the signal authentication adapter 100 (NO in step S503), the process proceeds to step S505.
[0055] The positioning unit 230 performs positioning based on satellite signals other than the frequencies indicated by the frequency information (frequencies indicated by all previously received frequency information) (step S505). Then, the output unit 250 outputs the location information determined by the positioning unit 230 (step S506), and the process ends.
[0056] This allows the positioning device 200 to perform positioning using only regular satellite signals, thereby enabling accurate location information to be estimated.
[0057] FIG. 6 is a flowchart illustrating an example of the operation of the signal authentication adapter according to the second embodiment.
[0058] The flowchart shown in FIG. 6 differs from the flowchart shown in FIG. 4 in the processing after authentication in step S404.
[0059] That is, if the authentication unit 120 authenticates that the received satellite signal is a signal from a legitimate satellite (YES in step S404), the authentication unit 120 transmits information indicating that the authentication was successful to the positioning device 200 via the I / O unit 220 (step S605), and ends the processing.
[0060] Furthermore, if the authentication unit 120 authenticates that the received satellite signal is not a legitimate signal (NO in step S404), the authentication unit 120 transmits frequency information indicating the frequency of the satellite signal that failed to be authenticated to the positioning device 200 via the I / O unit 220 (step S606), and terminates the processing.
[0061] This allows the positioning device 200 to perform positioning using authenticated satellite signals.
[0062] Here, the signal authentication adapter 100 is configured to send back to the positioning device 200 frequency information of satellite signals that have failed to be authenticated, but it may also be configured to send back satellite signals that have been successfully authenticated, and the positioning device 200 may be configured to perform positioning using the returned satellite signals.
[0063] Furthermore, in the second embodiment, the signal authentication adapter 100 may output information indicating whether the satellite signal has been successfully authenticated, similar to the first embodiment.
[0064] <Summary of Embodiment 2> According to the positioning system of the second embodiment, the positioning device 200 performs positioning by excluding signals of the frequencies of satellite signals that have failed authentication; that is, the positioning device 200 performs positioning by using only satellite signals that have been successfully authenticated by the signal authentication adapter 100. Therefore, spoofer signals are not mixed in when performing positioning, and the positioning device 200 can estimate and continue to output accurate position information. Furthermore, many existing positioning devices 200 are originally equipped with a function to cut off a set frequency. Therefore, many positioning devices 200 can support the mode of cutting off signals of a frequency band by sending back frequency information of satellite signals that have failed authentication, as shown in the second embodiment, and therefore a highly versatile signal authentication adapter 100 can be provided.
[0065] <Third Embodiment> In the above-described first and second embodiments, an example was described in which the positioning device 200 is a receiver that performs positioning using GPS or Galileo, and uses a signal authentication adapter 100 that is compatible with a receiver that receives satellite signals that do not support the authentication function for the satellite signals to be authenticated. In the third embodiment, a case will be described in which the positioning device 200 that performs positioning using satellite signals that support the signal authentication function is used. In the third embodiment, the description will be given taking as an example positioning using QZSS that supports the signal authentication function. An example of the system configuration in this case is shown in FIG. 7.
[0066] As shown in FIG. 7, the positioning system includes a positioning device 200, a signal authentication adapter 100, a satellite (QZSS) 20, and a ground control station 300. The positioning device 200 receives satellite signals 21 from multiple satellites 20 and estimates its own position information. At this time, a spoofer (not shown) that transmits false satellite signals may exist in the positioning system. QZSS supports a signal authentication function, and authentication information (digital signature) is added to the satellite signals 21 transmitted from the satellites 20. That is, the satellite signals 21 include at least ephemeris data, which includes so-called satellite orbit information and satellite clock information, and the digital signature. When authentication is performed in the positioning device, the satellite signals 21 are generated by the ground control station 300 and transmitted to the satellites 20, and then transmitted from the satellites 20 to the ground.
[0067] A signal authentication adapter 100 according to the present invention is connected to the positioning device 200, and receives a signal from the positioning device 200 and authenticates the satellite signal. The signal authentication adapter 100 holds a public key corresponding to a private key from the ground control station 300 in advance. The signal authentication adapter 100 verifies the digital signature included in the satellite signal 21 using the ephemeris data and public key included in the satellite signal 21. The signal authentication adapter 100 then reports whether the satellite signal received by the positioning device 200 is a legitimate signal. This allows a user of the positioning device 200 to determine whether the positioning result obtained by the positioning device 200 is trustworthy based on the output of the signal authentication adapter 100. This will be explained in detail below.
[0068] <Configuration> The configurations of the positioning device 200 and the signal authentication adapter 100 according to the third embodiment may be the same as those shown in the first and second embodiments, that is, the same as the configuration shown in Fig. 2. However, if the positioning device 200 is configured to receive signals (signals in the L6 band) that support the signal authentication function, the receiving unit 150 of the signal authentication adapter 100 may not be configured. Furthermore, in the third embodiment, as in the first embodiment, the signal authentication adapter 100 is described as being configured to output whether or not authentication was successful. However, as in the second embodiment, the signal authentication adapter 100 may be configured to send back to the positioning device 200 frequency information indicating the frequency of satellite signals that have failed to be authenticated.
[0069] The third embodiment differs from the first embodiment in that a digital signature is included in the satellite signal received by the I / O unit 110. Therefore, the authentication unit 120 performs authentication using the digital signature included in the satellite signal transmitted from the positioning device 200.
[0070] <Operation> The operation of the positioning device 200 shown in the third embodiment is the same as that of the first embodiment (see the flowchart shown in FIG. 3), and differs from the first embodiment only in that it receives satellite signals from QZSS satellites, so a description thereof will be omitted.
[0071] 8 is a flowchart showing an example of the operation of the signal authentication adapter 100. As shown in FIG. 8, the I / O unit 110 of the signal authentication adapter 100 receives the QZSS satellite signal 21 from the positioning device 200 (step S801). That is, the I / O unit 110 receives the satellite signal of the QZSS satellite that includes ephemeris data and a digital signature as authentication information. The I / O unit 110 transmits the received satellite signal to the authentication unit 120.
[0072] When a satellite signal is transmitted from I / O unit 110, authentication unit 120 authenticates the satellite signal. That is, authentication unit 120 extracts ephemeris data and a digital signature from the transmitted satellite signal. Then, authentication unit 120 verifies the digital signature included in the satellite signal using a hash value of the ephemeris data included in the satellite signal and a public key stored in storage unit 130.
[0073] Based on the verification result, the authentication unit 120 determines whether the authentication is successful (step S803), that is, whether the transmitted satellite signal is a signal from a legitimate satellite.
[0074] The processes in steps S405 and S406 are the same as those in the first embodiment, and therefore the description thereof will be omitted.
[0075] In this way, when the positioning device 200 can receive and position satellite signals from satellites of a system (QZSS) that supports the signal authentication function, the signal authentication adapter 100 can authenticate the satellite signals using only the satellite signals transmitted from the positioning device 200.
[0076] <Summary of Embodiment 3> According to the positioning system of the third embodiment, the positioning device 200 itself can receive satellite signals with digital signatures attached, and therefore the signal authentication adapter 100 does not necessarily need to be equipped with the receiving unit 150. Therefore, in this case, it is possible to provide a signal authentication adapter 100 with a simpler configuration than those of the first and second embodiments. That is, it is possible to provide a signal authentication adapter 100 with lower cost than those of the first and second embodiments.
[0077] <Supplementary information> The signal authentication adapter 100 according to the above embodiment is not limited to the above embodiment, and may be realized by other methods. Various modifications will be described below.
[0078] (1) In the above-described embodiments, the signal authentication adapter 100 may be provided with a positioning function, and the positioning function may perform positioning using only satellite signals that have been successfully authenticated. The output unit 140 may be configured to output correct location information determined by the positioning function. Therefore, in the cases of the first and third embodiments, a user using the signal authentication adapter 100 can confirm the correct positioning result output from the signal authentication adapter 100 even when the positioner 200 is outputting an incorrect positioning result.
[0079] The output unit 140 may be configured to output only those satellite signals that have been successfully authenticated, either in their original format or in the international standard RTCM format, from among the satellite signals received by the I / O unit 110. The user can obtain an accurate location by performing positioning using the output authenticated signals.
[0080] (2) In the above embodiment, the signal authentication adapter 100 is implemented by software using a CPU (Central Processing Unit). Specifically, the signal authentication adapter 100 includes a CPU that executes instructions from a program, which is software that implements each function; a ROM (Read Only Memory) or storage device (these are referred to as "recording media") in which the program and various data are recorded so as to be readable by the signal authentication adapter 100 (or the CPU); and a RAM (Random Access Memory) in which the program is deployed. The object of the present invention is achieved when the signal authentication adapter (or the CPU) reads and executes the program from the recording media. The program may also be supplied to the information processing terminal via any transmission medium capable of transmitting the program (such as a communication network or broadcast waves). The present invention may also be realized in the form of a data signal embedded in a carrier wave, in which the program is embodied by electronic transmission. The present invention can also be realized in a form in which the above program is incorporated as software into the base of a system including a receiver owned by a user.
[0081] The above program can be implemented using, for example, a scripting language such as ActionScript or JavaScript (registered trademark), an object-oriented programming language such as Objective-C or Java (registered trademark), or a markup language such as HTML5.
[0082] Furthermore, each functional unit of the signal authentication adapter 100 may be realized by a logic circuit (hardware) formed on an integrated circuit (IC chip) or the like. In this case, each functional unit may be realized as an individual circuit, or multiple functional units may be realized by a single circuit.
[0083] Although the present invention has been described based on the drawings and examples, it should be noted that those skilled in the art would easily be able to make various modifications and alterations based on this disclosure. Therefore, it should be noted that these modifications and alterations are within the scope of the present invention. For example, the functions included in each means, step, etc. can be rearranged so as not to be logically contradictory, and multiple means, steps, etc. can be combined into one or divided. Furthermore, the configurations shown in the above embodiments may be combined as appropriate.
[0084] (3) The aspects and processes described in the above embodiment may be combined or the processing procedures may be changed as appropriate within the scope of the object of the present invention. For example, the processing of steps S401 and S402 may be executed in reverse order or in parallel. [Explanation of symbols]
[0085] 20,20a,20b,20c satellite 30 Spoofer 100 Signal Authentication Adapter 110 I / O section 120 Authentication Department 130 Storage section 140 Output section 200 Positioning Device 210 Receiving unit 220 I / O section 230 Positioning Unit 240 Storage section 250 Output section
Claims
1. a connection part for connecting to a positioning device; an I / O unit that receives, from the positioning device, a satellite signal received by the positioning device; an authentication unit that authenticates a satellite signal received by the I / O unit; an output unit that outputs the authentication result of the satellite signal by the authentication unit; A signal authentication adapter comprising:
2. a storage unit for storing a public key; the satellite signal is a signal to which a digital signature is attached, the digital signature being generated from a hash value of ephemeris data consisting of satellite orbit information and satellite clock information using a private key corresponding to the public key; The authentication unit extracts the digital signature from the satellite signal received by the I / O unit, and verifies the digital signature using ephemeris data included in the satellite signal and the public key previously stored in the storage unit, thereby authenticating whether the satellite signal is a signal transmitted from a legitimate satellite.
10. The signal authentication adapter of claim 1.
3. the positioning device performs positioning using a first satellite signal from a first satellite that does not have a signal authentication function, the signal authentication adapter includes a receiver configured to receive a second satellite signal from a second satellite having a signal authentication function; The authentication unit authenticates the first satellite signal using authentication information included in the second satellite signal.
10. The signal authentication adapter of claim 1.
4. a storage unit for storing a public key; the authentication information is a digital signature generated from a hash value of ephemeris data included in the first satellite signal using a private key corresponding to the public key; The authentication unit verifies the authentication information included in the second satellite signal by using the first satellite signal and a public key corresponding to the private key, thereby authenticating the first satellite signal.
4. The signal authentication adapter of claim 3.
Citation Information
Patent Citations
Horizontal type roll cutter
JP1989027889A