Systems and methods for third-party time and location authentication

The method addresses GNSS spoofing by using I/Q spectrum recording for independent time and location authentication, ensuring secure and reliable verification through a distributed ledger, thereby preventing spoofing and enhancing navigation and timing systems.

JP2026501190APending Publication Date: 2026-01-14TRUSTPOINT INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025535129
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-14
Filing Date
2023-12-14
Publication Date
2026-01-14

AI Technical Summary

Technical Problem

GNSS signals are vulnerable to spoofing due to their unencrypted nature, leading to inaccurate position and time solutions that cannot be independently verified by third parties, posing safety, security, and privacy risks.

Method used

Implementing a method for third-party authentication using in-phase/quadrature (I/Q) spectrum recording to derive independent time and location solutions, comparing them with covert data sequences to authenticate the covert time and location solutions, and posting this information to a distributed ledger for verification.

Benefits of technology

Ensures secure, independent verification of time and location data, preventing spoofing and enhancing the reliability of navigation and timing systems by using a distributed ledger for immutability and timeboxing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026501190000001_ABST
    Figure 2026501190000001_ABST
Patent Text Reader

Abstract

Some implementations herein relate to an authentication device (AE) that receives an in-phase / quadrature (I / Q) spectrum record of a covert data sequence, the I / Q spectrum record indicating the received spectrum of a signal in which the covert data sequence is transmitted, and a covert time and position solution. The AE derives a covert time and position solution from the covert data sequence, indicating a location and a time at which the location was derived. The AE processes the I / Q spectrum record to derive an independent time and position solution, indicating another location at which the I / Q spectrum record was recorded and another time at which the I / Q spectrum was recorded at another location. The AE determines whether the covert time and position solution and the independent time and position solution match. The AE authenticates the covert time and position solution based on a match between the covert time and position solution and the independent time and position solution.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims the benefit of U.S. Provisional Application No. 63 / 432,438, filed December 14, 2022, which is incorporated herein by reference in its entirety. This disclosure includes subject matter related to subject matter disclosed in International Application No. PCT / US2022 / 014274, filed January 28, 2022, and U.S. Provisional Application No. 63 / 315,679, filed March 2, 2022, each of which is incorporated herein by reference in its entirety. [Background technology]

[0002] Position, velocity, and time (PVT) technologies are used in navigation and timing systems. Position technology is concerned with determining the location or coordinates of an object in a given space. Time technology is concerned with the precise measurement and synchronization of time signals. Velocity technology is concerned with measuring the rate of change of an object's position with respect to time. Summary of the Invention [Means for solving the problem]

[0003] Some implementations provided herein relate to a method related to third-party time and location authentication. The method may include receiving, by an authentication device, an in-phase / quadrature (I / Q) spectrum recording of a covert data sequence showing a received spectrum of a signal in which the covert data sequence is transmitted, and a covert time and location solution derived from the covert data sequence indicating a location and a time at which the location was derived; processing, by the authentication device, the I / Q spectrum recording to derive an independent time and location solution indicating another location at which the I / Q spectrum recording was recorded and another time at which the I / Q spectrum was recorded at the other location; determining, by the authentication device and based on a comparison of the covert time and location solution with the independent time and location solution, whether the covert time and location solution and the independent time and location solution match; and authenticating, by the authentication device, the covert time and location solution based on a match between the covert time and location solution and the independent time and location solution.

[0004] Some implementations described herein relate to a transceiver device that receives an overt data sequence and a covert data sequence indicative of a received spectrum of a signal on which the overt data sequence is transmitted; derive from the overt data sequence an overt time and position solution indicating a location of the transceiver device and a time the transceiver device was at that location; record an in-phase, quadrature (I / Q) spectrum record of the overt data sequence; digitally sign the transceiver's unique identifier, the overt time and position solution, and the I / Q spectrum record to create a unique data representation of the unique identifier, the overt time and position solution, and the I / Q spectrum record; and provide the unique data representation to be posted to an unauthenticated distributed ledger entry in an unauthenticated distributed ledger.

[0005] Some implementations described herein relate to a non-transitory computer-readable medium storing a set of instructions, the set of instructions including one or more instructions that, when executed by one or more processors of an authentication device, cause the authentication device to: receive an in-phase, quadrature (I / Q) spectral recording of the covert data sequence indicating a received spectrum of the signal in which the covert data sequence was transmitted, and a covert time and position solution derived from the covert data sequence indicating a location of the user equipment and a time the user equipment was at that location; process the I / Q spectral recording to derive an independent time and position solution indicating a location at which the I / Q spectral recording was recorded and a time at which the I / Q spectrum was recorded at that location; determine whether the covert time and position solution and the independent time and position solution match based on a comparison of the covert time and position solution and the independent time and position solution; and authenticate the covert time and position solution based on a match between the covert time and position solution and the independent time and position solution. [Brief explanation of the drawings]

[0006] [Figure 1A] FIG. 1 illustrates an example related to blockchain-based domain registration and device authentication, according to some embodiments of the present disclosure. [Figure 1B] FIG. 1 illustrates an example related to blockchain-based domain registration and device authentication, according to some embodiments of the present disclosure. [Figure 1C] FIG. 1 illustrates an example related to blockchain-based domain registration and device authentication, according to some embodiments of the present disclosure. [Figure 1D] FIG. 1 illustrates an example related to blockchain-based domain registration and device authentication, according to some embodiments of the present disclosure. [Figure 1E] FIG. 1 illustrates an example related to blockchain-based domain registration and device authentication, according to some embodiments of the present disclosure. [Figure 2]FIG. 1 is a diagram of an example environment in which the systems and / or methods described herein may be implemented, according to some embodiments of the present disclosure. [Figure 3] FIG. 1 is a diagram of example components of a device associated with third-party time and location authentication, according to some embodiments of the present disclosure. [Figure 4] 1 is a flowchart of an example process related to third-party time and location authentication, according to some embodiments of the present disclosure. [Figure 5] 1 is a flowchart of an example process related to third-party time and location authentication, according to some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0007] The following detailed description of the exemplary embodiments refers to the accompanying drawings, in which the same reference numbers in different drawings may identify the same or similar elements.

[0008] Geolocation satellite systems, such as the Global Positioning Satellite System (GNSS), provide positioning, navigation, and timing information. For example, GNSS typically transmits openly (e.g., broadcasts openly for public or civilian use) GNSS signals (e.g., unencrypted GNSS signals) that contain the positioning, navigation, and timing information. Interface control documents, which are typically published, describe the specifications, protocols, and parameters of GNSS signals and provide standardized guidelines for position, velocity, and time (PVT) technical organizations (or associations) to develop receivers capable of accurately processing GNSS signals.

[0009] However, because GNSS signals are not encrypted and are transmitted openly, they are vulnerable to spoofing (e.g., malicious activity in which a false signal is generated to mimic an authentic GNSS signal). For example, spoofing involves transmitting a counterfeit signal that mimics an authentic GNSS signal, causing a navigation receiver to calculate inaccurate PVT information. The lack of encryption means that the GNSS signals are not authenticated, and receivers may struggle to distinguish between genuine satellite transmissions and false signals, which can lead to negative and harmful consequences. For example, spoofing can lead to misleading navigation information, safety risks during transportation, security concerns for organizational infrastructure, adverse impacts on emergency services, and privacy concerns, among other examples.

[0010] Furthermore, typical security techniques used to enhance security associated with processing GNSS signals only allow for first-party verification (e.g., the receiver that generated the time and position solution can verify the time and position solution, but the time and position solution is not verified by a third party). In other words, typical security techniques do not provide independent verification of the time and position solution generated by the receiver. As a result, a third party cannot rely on the time and position solution generated and verified by the receiver.

[0011] Some implementations described herein enable third-party (e.g., independent) time and location authentication. As an example, an authenticating equipment (AE) may receive an in-phase / quadrature (I / Q) spectrum record of a covert data sequence showing the received spectrum of the signal in which the covert data sequence is transmitted, and a covert time and position solution derived from the covert data sequence indicating a location and the time at which the location was derived. The AE may process the I / Q spectrum record to derive an independent time and position solution indicating another location at which the I / Q spectrum record was recorded and another time at which the I / Q spectrum was recorded at another location. The AE may determine whether the covert time and position solution and the independent time and position solution match based on a comparison of the covert time and position solution and the independent time and position solution. The AE may authenticate the covert time and position solution based on a match between the covert time and position solution and the independent time and position solution.

[0012] 1A-1F are diagrams of an example 100 related to third-party time and location authentication. As shown in FIGS. 1A-1F, the example 100 includes a set of geolocation satellites (e.g., shown in FIG. 1A as a set of GNSSs 102), a user equipment (UE) 104, and an AE 106. In some implementations, the set of GNSSs 102, the UE 104, and the AE 106 form a third-party time and location authentication architecture (e.g., the UE 104 and / or the AE 106 may process GNSS signals 108 to authenticate time and position solutions, as described in more detail elsewhere herein). These devices are described in more detail in connection with FIGS. 2 and 3.

[0013] 1A, a set of GNSS signals 108 are transmitted by the GNSS set 102 and received by the UE 104, which may be referred to herein individually as a GNSS signal 108 and collectively as GNSS signals 108. Each GNSS signal 108 in the set of GNSS signals 108 may include an overt data sequence (e.g., a first data sequence) and a covert data sequence (e.g., a second data sequence). Time and position information may be derived from the overt data sequence, such as an overt time and position solution that indicates a position and the time at which the position was derived. The covert data sequence may indicate or indicate the received spectrum of the signal in which the overt data sequence is transmitted.

[0014] Because the overt data sequences transmitted by the GNSS set 102 using the set of GNSS signals 108 are overt data sequences, the overt data sequences are readily observable or measurable by the UE 104 (or another device with access to the communication channel used to transmit the set of GNSS signals 108). Furthermore, because the covert data sequences transmitted by the GNSS set 102 using the set of GNSS signals 108 are covert data sequences, the UE 104 uses specialized knowledge or techniques to detect, measure, and process the covert data sequences. For example, the UE 104 may use one or more pre-processing, demodulation, decoding, pattern recognition, decryption, and / or post-processing techniques to detect, measure, and process the covert data sequences.

[0015] In some implementations, the received spectrum of the signal in which the overt data sequence is transmitted (e.g., as dictated by the covert data sequence) may include information associated with the spectrum of the set of GNSS signals 108 received by the UE 104. By way of example, the received spectrum may include frequency domain information (e.g., associated with the frequency components represented in the GNSS signals 108), amplitude information (e.g., associated with the amplitude of the GNSS signals 108 at each frequency), modulation characteristics (e.g., associated with the modulation scheme used to transmit the GNSS signals 108), transmission characteristics (e.g., associated with the transmission environment, noise level, interference, and / or signal-to-noise ratio (SNR)), metadata and synchronization information (e.g., associated with synchronization and / or error correction), and / or timestamp information (e.g., associated with the time the data in the GNSS signals 108 is received), among other examples.

[0016] Furthermore, the overt and covert data sequences may be transmitted at any suitable frequency and on any suitable channel. For example, the overt and covert data sequences may be transmitted on the same frequency within the same channel, on different frequencies within the same channel, on the same frequency within different channels, or on different frequencies within different channels. Additionally or alternatively, the overt and covert data sequences may be transmitted simultaneously or consecutively.

[0017] 1B, the overt data sequence and the covert data sequence form a two-sequence signal structure. In this manner, the overt data sequence may be transmitted periodically (e.g., consecutively) or in parallel (e.g., as shown in FIG. 1B). Thus, the GNSS set 102 may periodically transmit the GNSS signal set 108 such that the two-sequence signal structure is transmitted periodically or in parallel.

[0018] In some implementations, the UE 104 processes the overt and covert data sequences (e.g., by using one or more PVT techniques, as described in more detail elsewhere herein). For example, the UE 104 processes the overt data sequence by deriving an overt time and position solution from the overt data sequence, which indicates the location of the UE 104 and the time the UE 104 was at that location. To derive the overt time and position solution, the UE 104 may perform a trilateration operation (or any other suitable location and time determination technique). As another example, the UE 104 processes the overt data sequence by performing an I / Q spectral recording of the overt data sequence (e.g., a covert I / Q file). The I / Q spectral recording includes a covert (e.g., covert) signal that is transmitted synchronized to the overt data sequence (e.g., associated with the overt time and positioning signal). The covert signal allows for independent authentication of the overt time and position solution, as described in more detail elsewhere herein.

[0019] As shown in FIG. 1C , the UE 104 processes four GNSS signals 108 (e.g., the GNSS signal 108 transmitted by satellite A, the GNSS signal 108 transmitted by satellite B, the GNSS signal 108 transmitted by satellite C, and the GNSS signal 108 transmitted by satellite D). The UE 104 performs a trilateration operation at a first time t0 to generate a first overt time and position solution (e.g., a first overt in situ time and position solution). The UE 104 performs an I / Q spectrum recording operation at a second time t0 + delta to generate a first I / Q spectrum recording (e.g., a first in situ I / Q spectrum recording). As further shown in FIG. 1C , the UE 104 performs a trilateration operation at a third time t1 to generate a second overt time and position solution (e.g., a second overt in situ time and position solution). The UE 104 performs an I / Q spectrum recording operation at a fourth time t1+delta to generate a second I / Q spectrum record (e.g., a second in-situ I / Q spectrum record). The first public time and location solution, the first I / Q spectrum record, the second public time and location solution, and the second I / Q spectrum record may be included in time and location information associated with the UE 104, among other information, as described in more detail elsewhere herein.

[0020] The UE 104 may provide time and location information (e.g., public time and location solutions, and I / Q spectrum records, among other examples) to be posted to entries in a database, such as a distributed ledger (e.g., a blockchain-based distributed ledger or a non-blockchain-based distributed ledger), as described in more detail elsewhere herein. As used herein, a distributed ledger is a decentralized database that uses one or more technologies and / or techniques to maintain a secure, decentralized record of information, such as information associated with a transaction (e.g., a transaction conducted between two parties).

[0021] A distributed ledger may be shared and synchronized consensually across multiple sites, institutions, and / or participants in a network. The distributed ledger may be public (e.g., the distributed ledger is available for viewing by at least each participant in the network) or private (e.g., the distributed ledger is made available to a select community of users and accessed by certificates). Changes to the distributed ledger are independently verified and agreed upon through a consensus mechanism (e.g., one or more cryptographic techniques and consensus mechanisms, among other examples). This maintains the integrity of the information posted to the distributed ledger and ensures that all participants have a consistent, up-to-date view of the information contained in the distributed ledger. In this way, the distributed ledger may be used to create an immutable, or unchanging, ledger for tracking information such as time and location information provided by the UE 104 and / or another device (e.g., the AE 106).

[0022] In some implementations, the time and location information provided by the UE 104 to be posted to a distributed ledger entry in the distributed ledger may include a user identification (e.g., a unique alphanumeric identifier associated with the UE 104 and / or the user of the UE 104), an overt time and location solution (e.g., generated by processing an overt data sequence), an I / Q spectrum record (e.g., generated by processing an overt data sequence), and / or other desired information (e.g., information the user desires to be posted to a distributed ledger entry, including other data).

[0023] In some implementations, the UE 104 may digitally sign the time and location information to create a unique data representation of the time and location information (e.g., the UE 104 may digitally sign one or more portions of the time and location information to create one or more unique data representations of the one or more portions of the time and location information). As an example, the UE 104 may digitally sign a unique identifier of the UE 104, a public time and location solution, and an I / Q spectrum recording to create a unique data representation of the unique identifier, the public time and location solution, and the I / Q spectrum recording.

[0024] As another example, the UE 104 may digitally sign the time and location information to create digitally signed time and location information, digitally sign the public time and location solution to create a digitally signed public time and location solution, and / or digitally sign the I / Q spectrum record to create a digitally signed I / Q spectrum record. Additionally or alternatively, the UE 104 may perform one or more hash functions and / or one or more encryption operations on the time and location information. As an example, the UE 104 may perform a hash function on the user identification, the public time and location solution, and the I / Q spectrum record, among other examples, to generate a hash code (which may be on the order of several hundred bits or any suitable number of bits) of the user identification, the public time and location solution, and the I / Q spectrum record. As another example, the UE 104 may perform an encryption operation (e.g., using a private key associated with the UE 104 and / or the user of the UE 104) on the user identification, the public time and location solution, and the I / Q spectrum record to generate a ciphertext (e.g., on the order of several hundred bits or any suitable number of bits) of the user identification, the public time and location solution, and the I / Q spectrum record, among other examples.

[0025] In some implementations, the UE 104 may provide the digitally signed time and location information (and / or any other suitable data) to be posted to an unauthenticated distributed ledger entry in the unauthenticated distributed ledger. By way of example, the UE 104 may send, and a device (e.g., not shown) associated with the unauthenticated distributed ledger may receive, the digitally signed time and location information. The device associated with the unauthenticated distributed ledger may process the digitally signed time and location information and add the digitally signed time and location information to the unauthenticated distributed ledger entry.

[0026] Additionally, each unauthenticated distributed ledger entry may include digitally signed time and location information (and / or any other suitable data) associated with multiple UEs and / or users of multiple UEs. In other words, digitally signed time and location information associated with multiple UEs and / or users of multiple UEs may be included in a single unauthenticated distributed ledger entry. By way of example, a single unauthenticated distributed ledger entry may include digitally signed time and location information provided by multiple UEs for addition to the single unauthenticated distributed ledger entry over a time period such as 60 seconds or 120 seconds. The digitally signed time and location information included in the unauthenticated ledger entry may be authenticated, as described in more detail elsewhere herein.

[0027] As shown in FIG. 1D , the UE 104 sends and the AE 106 receives the public time and position solution and the I / Q spectrum record. The AE 106 may process the I / Q spectrum record to derive an independent time and position solution indicating another location at which the I / Q spectrum record was recorded and another time at which the I / Q spectrum was recorded at another location. The AE 106 may determine whether the public time and position solution and the independent time and position solution match based on a comparison of the public time and position solution and the independent time and position solution. The AE 106 may authenticate the public time and position solution based on a match between the public time and position solution and the independent time and position solution. The AE 106 may receive a request to authenticate the public time and position solution. The AE 106 may provide an indication that the public time and position solution are authentic.

[0028] In some implementations, the AE 106 may provide the authenticated time and location information to be posted to an entry in a database, such as a distributed ledger (e.g., a blockchain-based distributed ledger or a non-blockchain-based distributed ledger). By way of example, the AE 106 may provide the authenticated time and location information to be posted to an authenticated distributed ledger entry in the authenticated distributed ledger. The authenticated time and location information may be sent by the AE 106, and may be received by a device (e.g., not shown) associated with the authenticated distributed ledger. The device associated with the authenticated distributed ledger may process the authenticated time and location information and add the authenticated time and location information to the authenticated distributed ledger entry.

[0029] In some implementations, the authenticated time and location information provided by the AE106 to be posted to the authenticated distributed ledger entry may include an authenticating entity identifier (an identifier of the authenticating entity associated with the AE106), an independent time and location solution, and / or a unique data representation of the authenticated time and location information (e.g., the AE106 may digitally sign one or more portions of the authenticated time and location information to create one or more unique data representations of the one or more portions of the authenticated time and location information).

[0030] As an example, the AE 106 may digitally sign the independent time and position solution to create digitally signed independent time and position solution data. As another example, the AE 106 may digitally sign the I / Q spectrum record to create digitally signed IQ spectrum record data. Additionally or alternatively, the AE 106 may perform one or more hash functions and / or one or more cryptographic operations on the authenticated time and position information (in a similar or identical manner as described in more detail elsewhere herein). An authenticated distributed ledger entry including the authenticated time and position information provided by the AE 106 corresponds to an unauthenticated ledger entry including the public time and position solution (and / or other time and location information associated with the UE 104 and / or the user of the UE 104) that the AE 106 authenticates.

[0031] As shown in Figure 1E, a block T of unauthenticated distributed ledger entries includes N entries with unauthenticated time and location information (e.g., shown as unauthenticated user IDs, public time and location solutions, I / Q spectrum records, hash codes, ciphertext, and other data). A block X of authenticated distributed ledger entries includes N entries corresponding to the N entries of block T with authenticated time and location information (e.g., authenticated user IDs, public time and location solutions, I / Q spectrum records, hash codes, ciphertext, and other data).

[0032] As further shown in Figure 1E, block T+1 of unauthenticated distributed ledger entries includes N entries with unauthenticated time and location information (e.g., shown as unauthenticated user IDs, public time and location solutions, I / Q spectrum records, hash codes, ciphertext, and other data). Block X+1 of authenticated distributed ledger entries includes N entries corresponding to the N entries of block T+1 with authenticated time and location information (e.g., authenticated user IDs, public time and location solutions, I / Q spectrum records, hash codes, ciphertext, and other data). Thus, the authenticated time and location are posted to the authenticated distributed ledger entry at a later time than when the unauthenticated time and location information was posted to the unauthenticated distributed ledger entry.

[0033] Thus, an entry made into a distributed ledger (e.g., an unauthenticated distributed ledger and / or an authenticated distributed ledger) establishes a past time and date when the data in the entry existed. In this way, the posted data is at least as old as the distributed ledger entry, but not newer. This creates a timeboxing feature that can be described as a "no later than" timeboxing feature.

[0034] Additionally, the private data sequence may be unique, non-repeatable, and sufficiently random so as not to be predicted in advance by the user of the UE and / or the authentication entity, among other examples. The geolocation satellite system may then be configured to transmit the unique, random private data sequence only once, the first time the data sequence enters the public domain. Any UE that acquires or possesses the private data sequence will not be able to receive it prior to its transmission. If the private data sequence is then used in some process or transaction, that process or transaction essentially cannot occur prior to the emission of the private data sequence. This creates a time-boxing feature that may be described as a "no earlier than" time-boxing feature. Furthermore, when an unofficial data sequence (or a hash of an unofficial data sequence) is posted to a distributed ledger (e.g., an unauthenticated distributed ledger and / or an authenticated distributed ledger), this combines the "before" and "after" timeboxing features into a single instance, fully timeboxing the process, entry, or transaction as occurring before the entry in the distributed ledger and since the release or transmission of the unofficial data set to the public domain. In this manner, the time and location information contained in the unauthenticated distributed ledger entry can be compared to the time and location information contained in the authenticated distributed ledger entry to verify the overt time and location solution indicating the location of the UE 104 and the time the UE 104 was at that location (or another location and the time that location was derived).

[0035] Thus, the systems and methods described herein may be used for a variety of purposes, such as material procurement provenance (e.g., to verify the location and time corresponding to where a tree was cut, where a fish was caught, or what route an aircraft traveled, among other examples), location-based information technology (IT) access (e.g., allowing geofenced access to certain databases, such that only company employees can access employer IT services from certain locations), and / or deepfake protection (e.g., allowing authentication of the location where a video was taken and the time the video was taken).

[0036] 2 is a diagram of an example environment 200 in which the systems and / or methods described herein may be implemented. As shown in FIG. 2, the environment 200 may include a set of GNSS satellites 102, a UE 104, an AE 106, and a network 202. The devices of the environment 200 may be interconnected by wired connections, wireless connections, or a combination of wired and wireless connections.

[0037] The set of GNSS satellites 102 may include a set, or constellation, of satellites in orbit (e.g., around the Earth) that provide positioning, navigation, and timing information via GNSS signals 108. The GNSS signals 108 may be received by ground-based receivers (e.g., the UE 104, the AE 106, and / or transceivers, among other examples) to enable accurate determination of position and precise timekeeping.

[0038] The UE 104 may include one or more devices capable of receiving, generating, storing, processing, providing, and / or routing information associated with third-party time and location authentication, as described elsewhere herein. The UE 104 may include a communication device and / or a computer. For example, the UE 104 may include a wireless communication device, a mobile phone, a user equipment, a laptop computer, a tablet computer, a desktop computer, a wearable communication device (e.g., a smart wristwatch, smart glasses, a head-mounted display, or a virtual reality headset, among other examples), or a similar type of device.

[0039] The AE 106 may include a communication device and / or a computer. For example, the AE 106 may include a server, such as an application server, a client server, a web server, a database server, a host server, a proxy server, a virtual server (e.g., running on computing hardware), or a server in a cloud computing system. In some implementations, the AE 106 may include computing hardware used in a cloud computing environment.

[0040] Network 202 may include one or more wired and / or wireless networks. For example, network 202 may include a wireless wide area network (e.g., a cellular network or a public land mobile network), a local area network (e.g., a wired local area network or a wireless local area network (WLAN) such as a Wi-Fi network), a personal area network (e.g., a Bluetooth network), a near field communication network, a telephone network, a private network, the Internet, and / or a combination of these or other types of networks. Network 202 enables communication between devices in environment 200.

[0041] The number and arrangement of devices and networks shown in Figure 2 are given as an example. In fact, there may be additional, fewer, different, or differently arranged devices and / or networks than those shown in Figure 2. Furthermore, two or more devices shown in Figure 2 may be implemented within a single device, or a single device shown in Figure 2 may be implemented as multiple distributed devices. Additionally or alternatively, a set of devices (e.g., one or more devices) of environment 200 may perform one or more functions that are described as being performed by another set of devices of environment 200.

[0042] 3 is a diagram of example components of a device 300 associated with third-party time and location authentication. The device 300 may correspond to the set of GNSS satellites 102, the UE 104, and / or the AE 106. In some implementations, the set of GNSS satellites 102, the UE 104, and / or the AE 106 may include one or more devices 300 and / or one or more components of the device 300. As shown in FIG. 3 , the device 300 may include a bus 310, a processor 320, a memory 330, an input component 340, an output component 350, and / or a communication component 360.

[0043] The bus 310 may include one or more components that enable wired and / or wireless communication between the components of the device 300. The bus 310 may couple two or more components of FIG. 3 to one another by operative coupling, communicative coupling, electronic coupling, and / or electrical coupling, etc. For example, the bus 310 may include electrical connections (e.g., wires, traces, and / or leads) and / or a wireless bus. The processor 320 may include a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field-programmable gate array, an application-specific integrated circuit, and / or another type of processing component. The processor 320 may be implemented in hardware, firmware, or a combination of hardware and software. In some implementations, the processor 320 may include one or more processors that can be programmed to perform one or more operations or processes described elsewhere herein.

[0044] The memory 330 may include volatile and / or nonvolatile memory. For example, the memory 330 may include random access memory (RAM), read-only memory (ROM), a hard disk drive, and / or another type of memory (e.g., flash memory, magnetic memory, and / or optical memory). The memory 330 may include internal memory (e.g., RAM, ROM, or a hard disk drive) and / or removable memory (e.g., removable via a universal serial bus connection). The memory 330 may be a non-transitory computer-readable medium. The memory 330 may store information, one or more instructions, and / or software (e.g., one or more software applications) related to the operation of the device 300. In some implementations, the memory 330 may include one or more memories coupled (e.g., communicatively coupled) to one or more processors (e.g., processor 320), such as via the bus 310. The communicative coupling between the processor 320 and the memory 330 may allow the processor 320 to read and / or process information stored in the memory 330 and / or store information in the memory 330.

[0045] The input components 340 may enable the device 300 to receive input, such as user input and / or sensed input. For example, the input components 340 may include a touchscreen, a keyboard, a keypad, a mouse, buttons, a microphone, switches, sensors, global positioning system sensors, accelerometers, gyroscopes, and / or actuators. The output components 350 may enable the device 300 to provide output, such as via a display, a speaker, and / or a light-emitting diode. The communication components 360 may enable the device 300 to communicate with other devices via wired and / or wireless connections. For example, the communication components 360 may include a receiver, a transmitter, a transceiver, a modem, a network interface card, and / or an antenna.

[0046] The device 300 may perform one or more operations or processes described herein. For example, a non-transitory computer-readable medium (e.g., memory 330) may store a set of instructions (e.g., one or more instructions or code) for execution by the processor 320. The processor 320 may execute the set of instructions to perform one or more operations or processes described herein. In some implementations, execution of the set of instructions by one or more processors 320 causes one or more processors 320 and / or the device 300 to perform one or more operations or processes described herein. In some implementations, hardwired circuitry may be used in place of or in combination with instructions to perform one or more operations or processes described herein. Additionally or alternatively, the processor 320 may be configured to perform one or more operations or processes described herein. Thus, the implementations described herein are not limited to any specific combination of hardware circuitry and software.

[0047] The number and arrangement of components shown in Figure 3 are given as an example. Device 300 may include additional, fewer, different, or differently arranged components compared to the components shown in Figure 3. Additionally or alternatively, a set of components (e.g., one or more components) of device 300 may perform one or more functions that are described as being performed by another set of components of device 300.

[0048] 4 is a flowchart of an example process 400 related to third-party time and location authentication. In some implementations, one or more process blocks of FIG. 4 may be performed by the AE 106. In some implementations, one or more process blocks of FIG. 4 may be performed by another device (e.g., the UE 104) or a group of devices separate from or including the AE 106. Additionally or alternatively, one or more process blocks of FIG. 4 may be performed by one or more components of the device 300, such as the processor 320, the memory 330, the input component 340, the output component 350, and / or the communication component 360.

[0049] As shown in FIG. 4, process 400 includes receiving, by AE 106, as described above, an I / Q spectral record of the overt data sequence, which indicates the received spectrum of the signal on which the overt data sequence is transmitted, and an overt time and position solution derived from the overt data sequence, which indicates the position and the time at which that position was derived (block 410).

[0050] As further shown in FIG. 4 , process 400 includes processing, by AE 106, the I / Q spectral recording, as described above, to derive independent time and location solutions (block 420) indicating different locations at which the I / Q spectral recording was recorded and different times at which the I / Q spectrum was recorded at different locations.

[0051] As further shown in FIG. 4, process 400 includes determining whether the official time and position solution and the independent time and position solution match (block 430) by AE 106 and based on a comparison of the official time and position solution and the independent time and position solution, as described above.

[0052] As further shown in FIG. 4, process 400 includes authenticating, by the AE 106, the public time and position solution based on a match between the public time and position solution and the independent time and position solution (block 440), as described above.

[0053] Although FIG. 4 illustrates example blocks of process 400, in some implementations, process 400 may include additional, fewer, different, or differently ordered blocks compared to the blocks illustrated in FIG. 4 . Additionally or alternatively, two or more of the blocks of process 400 may be performed in parallel. FIG. 5 is a flowchart of an example process 500 related to third-party time and location authentication. In some implementations, one or more process blocks of FIG. 5 may be performed by the UE 104. In some implementations, one or more process blocks of FIG. 5 may be performed by another device (e.g., the AE 106 and / or another UE) or a group of devices separate from or including the UE 104. Additionally or alternatively, one or more process blocks of FIG. 5 may be performed by one or more components of the device 300, such as the processor 320, the memory 330, the input component 340, the output component 350, and / or the communication component 360.

[0054] As shown in FIG. 5, process 500 includes receiving an overt data sequence from which time and location information is derived, as described above, and a covert data sequence indicative of the received spectrum of the signal on which the overt data sequence is transmitted (block 510).

[0055] As further shown in FIG. 5, process 500 includes deriving an overt time and position solution from the overt data sequence (block 520), as described above, that indicates the location of the transceiver device and the time the transceiver device was at that location.

[0056] As further shown in FIG. 5, process 500 includes recording an in-phase / quadrature (I / Q) spectral recording of the overt data sequence (block 530), as described above.

[0057] As further shown in FIG. 5, process 500 includes digitally signing the I / Q spectral recording to create digitally signed I / Q spectral data (block 540), as described above.

[0058] As further shown in FIG. 5, process 500 includes providing the public time and position solutions and digitally signed I / Q spectrum data, as described above, to be posted to an unauthenticated distributed ledger entry in the unauthenticated distributed ledger (block 550).

[0059] 5 illustrates example blocks of process 500, in some implementations process 500 may include additional, fewer, different, or differently ordered blocks compared to the blocks illustrated in FIG 5. Additionally or alternatively, two or more of the blocks of process 500 may be performed in parallel.

[0060] As used herein, the term "component" should be broadly interpreted as hardware, firmware, or a combination of hardware and software. It should be apparent that the systems and / or methods described herein may be implemented in various forms of hardware, firmware, and / or combinations of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods is not intended to limit the implementation. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code. It should be understood that software and hardware can be used to implement the systems and / or methods based on the description herein.

[0061] As used herein, "meeting a threshold" can refer to a value being greater than the threshold, greater than or equal to the threshold, less than the threshold, less than or equal to the threshold, equal to the threshold, not equal to the threshold, etc., depending on the context.

[0062] To the extent the above-described implementations collect, store, or use personal information about individuals, it should be understood that such information shall be used in accordance with all applicable laws regarding the protection of personal information. Furthermore, the collection, storage, and use of such information may be subject to the individual's consent to such actions, for example, through well-known "opt-in" or "opt-out" processes, as may be appropriate to the status and type of information. The storage and use of personal information may be in a suitably secure manner that reflects the type of information, for example, through various encryption and anonymization techniques for particularly sensitive information.

[0063] Although particular combinations of features are recited in the claims and / or disclosed herein, these combinations do not limit the disclosure of various implementations. Indeed, many of these features may be combined in ways not specifically recited in the claims and / or disclosed herein. Although each dependent claim listed below may depend directly on only one claim, the disclosure of various implementations includes each dependent claim in combination with every other claim in the set of claims. As used herein, a phrase referring to "at least one of" a list of items refers to any combination of those items, including single members. By way of example, "at least one of a, b, or c" is intended to encompass a, b, c, ab, ac, bc, and abc, as well as any combination with multiple instances of the same item.

[0064] When a "processor" or "one or more processors" (or another device or component, such as a "controller" or "one or more controllers") is described or claimed (in a single claim or across multiple claims) as performing or configured to perform multiple operations, this language is intended to broadly cover a variety of processor architectures and environments. For example, unless expressly claimed otherwise (e.g., by the use in a claim of a "first processor" and a "second processor" or other language distinguishing between processors), this language is intended to cover a single processor that performs or is configured to perform all of the operations, a group of processors that collectively perform or are configured to perform all of the operations, a first processor that performs or is configured to perform a first operation and a second processor that performs or is configured to perform a second operation, or any combination of processors that perform or are configured to perform operations. For example, when a claim has the form "one or more processors configured to perform X, to perform Y, and to perform Z," the claim should be interpreted to mean "one or more processors configured to perform X, one or more (possibly different) processors configured to perform Y, and one or more (again, possibly different) processors configured to perform Z."

[0065] No element, act, or instruction used herein should be construed as critical or essential unless explicitly described as such. Additionally, as used herein, the articles "a" and "an" are intended to include one or more items and may be used interchangeably with "one or more." Additionally, as used herein, the article "the" is intended to include one or more items referred to in conjunction with the article "the" and may be used interchangeably with "one or more." Additionally, as used herein, the term "set" is intended to include one or more items (e.g., related items, unrelated items, or a combination of related and unrelated items) and may be used interchangeably with "one or more." Where only one item is intended, the phrase "only one" or similar language is used. Additionally, as used herein, terms such as "has," "have," and "having" are intended to be open-ended terms. Additionally, the phrase "based on" is intended to mean "based at least in part on," unless expressly stated otherwise. Also, as used herein, the term "or" is intended to be inclusive when used consecutively and may be used interchangeably with "and / or" unless otherwise specified (e.g., when used in combination with "either" or "only one of").

[0066] In the preceding specification, various exemplary embodiments have been described with reference to the accompanying drawings. However, it will be apparent that various modifications and changes may be made thereto and further embodiments may be implemented without departing from the broad scope of the invention as set forth in the following claims. Accordingly, the specification and drawings should be regarded in an illustrative sense and not a restrictive sense. [Explanation of symbols]

[0067] 102 GNSS set, GNSS satellite set 104 User Equipment (UE) 106 AE 202 Network 300 devices 310 Bus 320 processor 330 memory 340 Input Components 350 Output Components 360 Communication Components

Claims

1. receiving, by the authentication device, an in-phase / quadrature (I / Q) spectral recording of the overt data sequence showing the received spectrum of the signal in which the overt data sequence was transmitted, and an overt time and position solution derived from the overt data sequence indicating the location and the time at which the location was derived; processing, by the authentication device, the I / Q spectral recording to derive independent time and location solutions indicating different locations at which the I / Q spectral recording was recorded and different times at which the I / Q spectrum was recorded at the different locations; determining, by the authentication device and based on a comparison of the public time and position solution with the independent time and position solution, whether the public time and position solution and the independent time and position solution match; authenticating, by the authenticator, the public time and position solution based on a match between the public time and position solution and the independent time and position solution; A method comprising:

2. receiving, by the authentication device, a request to authenticate the public time and position solution; providing, by the authenticator, an indication that the public time and position solution is authentic; 10. The method of claim 1, further comprising:

3. digitally signing the I / Q spectral record by the authentication device to create digitally signed I / Q spectral data; digitally signing, by the authenticator, the independent time and position solution to create digitally signed independent time and position solution data; providing, by the authentication device, the digitally signed I / Q spectrum data and the digitally signed independent time and position solution data to be posted to an authenticated distributed ledger entry of an authenticated distributed ledger; the authenticated distributed ledger entry corresponds to an unauthenticated ledger entry in an unauthenticated distributed ledger that indicates a digitally signed public time and position solution that matches the digitally signed I / Q spectrum data and the digitally signed isolated time and position data; the unauthenticated distributed ledger entry was entered into the unauthenticated distributed ledger at an earlier time than the authenticated distributed ledger entry was entered into the authenticated distributed ledger; 10. The method of claim 1, further comprising:

4. receiving, by the authentication device, a request to authenticate the public time and position solution; providing, by the authenticator, a message; and wherein the message further comprises: an identifier of the unauthenticated ledger entry that enables retrieval of the digitally signed public time and location data and the digitally signed I / Q spectrum data from the unauthenticated ledger entry; an identifier of the authenticated ledger entry that enables retrieval of the digitally signed independent time and location data and the digitally signed I / Q spectrum data from the authenticated ledger entry; 4. The method of claim 3, comprising:

5. The method of claim 1 , wherein the covert data sequence and the overt data sequence are contained within a geolocation satellite signal.

6. The method of claim 1 , wherein the location and the time from which the location was derived correspond to a transaction.

7. The covert data sequence comprises: Unique structure, Unique bandwidth, Unique signal strength, Unique polarization, Unique modulation, unique encoding, or Unique Encryption The method of claim 1 , comprising at least one of:

8. 1. A transceiver device, comprising: one or more memories; one or more processors communicatively coupled to the one or more memories; wherein the one or more processors: receiving an overt data sequence and a covert data sequence indicative of a received spectrum of a signal on which the overt data sequence is transmitted; deriving an overt time and position solution from the overt data sequence indicating a location of the transceiver device and a time the transceiver device was at the location; recording an in-phase / quadrature (I / Q) spectral recording of the overt data sequence; digitally signing the transceiver's unique identifier, the public time and position solution, and the I / Q spectrum recording to create a unique data representation of the unique identifier, the public time and position solution, and the I / Q spectrum recording; providing the unique data representation to be posted to an unauthenticated distributed ledger entry in an unauthenticated distributed ledger; a transceiver device configured to:

9. the one or more processors: providing said I / Q spectrum recording and said public time and position solutions; 9. The transceiver device of claim 8, configured to:

10. the one or more processors: Encrypting said unique data representation 9. The transceiver device of claim 8, configured to:

11. the one or more processors digitally sign the unique identifier of the transceiver, the public time and position solution, and the I / Q spectrum recording to create the unique data representation of the unique identifier of the transceiver, the public time and position solution, and the digitally signed I / Q spectrum data; 9. The transceiver device of claim 8, configured to hash the unique identifier of the transceiver, the public time and location solution, and the I / Q spectrum recording using a hashing algorithm to create a hashed representation of the unique identifier of the transceiver, the public time and location solution, and the I / Q spectrum recording.

12. 12. The transceiver device of claim 11, wherein the hashing algorithm is Secure Hash Algorithm 3 (SHA-3).

13. the one or more processors: sending a request to verify the public time and position solution; receiving an indication that the public time and position solution is authentic in response to the request; 9. The transceiver device of claim 8, configured to:

14. 1. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of an authentication device, cause the authentication device to: receiving an in-phase / quadrature (I / Q) spectral recording of the overt data sequence showing the received spectrum of the signal in which the overt data sequence is transmitted, and an overt time and position solution derived from the overt data sequence indicating the location and the time at which the location was derived; processing the I / Q spectral recording to derive independent time and position solutions indicating the location at which the I / Q spectral recording was recorded and the time at which the I / Q spectrum was recorded at that location; determining whether the public time and position solution and the independent time and position solution match based on a comparison of the public time and position solution and the independent time and position solution; authenticating the public time and position solution based on a match between the public time and position solution and the independent time and position solution; A non-transitory computer-readable medium for causing

15. The one or more instructions, when executed by the one or more processors, cause the authentication device to: receiving a request to authenticate the public time and position solution; providing an indication that said public time and position solution is authentic; and 15. The non-transitory computer-readable medium of claim 14,

16. The one or more instructions, when executed by the one or more processors, cause the authentication device to: digitally signing the I / Q spectral record to create digitally signed I / Q spectral data; digitally signing the independent time and position solution to create digitally signed independent time and position solution data; providing the digitally signed I / Q spectrum data and the digitally signed independent time and position solution data to be posted to an authenticated distributed ledger entry of an authenticated distributed ledger; the authenticated distributed ledger entry corresponds to an unauthenticated ledger entry in an unauthenticated distributed ledger that indicates the digitally signed I / Q spectrum data and the public time and position solution that matches the digitally signed isolated time and position data; the unauthenticated distributed ledger entry was entered on the unauthenticated distributed ledger at an earlier time than the authenticated distributed ledger entry was entered on the authenticated distributed ledger; and 15. The non-transitory computer-readable medium of claim 14,

17. The one or more instructions, when executed by the one or more processors, cause the authentication device to: receiving a request to authenticate the public time and position solution; providing a message, the message comprising: an identifier of the unauthenticated ledger entry that enables retrieval of the digitally signed public time and location data and the digitally signed I / Q spectrum data from the unauthenticated ledger entry; an identifier of the authenticated ledger entry that enables retrieval of the digitally signed independent time and location data and the digitally signed I / Q spectrum data from the authenticated ledger entry; providing, including 17. The non-transitory computer-readable medium of claim 16,

18. 15. The non-transitory computer-readable medium of claim 14, wherein the covert data sequence and the overt data sequence are contained within a geolocation satellite signal.

19. 15. The non-transitory computer-readable medium of claim 14, wherein the location and the time from which the location was derived correspond to a transaction.

20. The covert data sequence comprises: Unique structure, Unique bandwidth, Unique signal strength, Unique polarization, Unique modulation, unique encoding, or Unique Encryption 15. The non-transitory computer-readable medium of claim 14, comprising at least one of:

Citation Information

Patent Citations

  • Cell organization and transmission method in Wide Area Positioning Systems (WAPS)

    JP2014529729A

  • Progressive global positioning system and progressive global positioning method

    JP2021081434A

  • Method for covertly delivering a packet of data over a network

    US11032257B1

  • Secure memory device with unique identifier for authentication

    US20180307867A1

  • Supporting a secure terrestrial transmitter based positioning

    US20190059068A1