GNSS Message Authentication Using EMCDT During Key Disclosure Gaps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing GNSS systems face challenges in maintaining authentication integrity and availability during service interruptions, particularly in obstructed environments, due to delayed key disclosure protocols that can be vulnerable to spoofing and collision attacks.

Innovation Solution

The Enhanced Message-to-Code Data Tie (EMCDT) module generates and stores EMCDT blocks for authenticated messages in a buffer, using navigation message identifiers and pseudorandom noise data to enable cross-authentication during service interruptions, allowing navigation data to be authenticated using previously received keys and codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If delayed key disclosure protocol is used for authentication, then bandwidth efficiency is improved, but authentication availability during service interruptions deteriorates

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidauthentication availability
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The system performs preliminary authentication by storing EMCDT blocks containing authentication data from previously authenticated messages. When service interruptions occur, the receiver can use these pre-stored authentication results to maintain authentication availability without requiring real-time key disclosure, thus resolving the contradiction between bandwidth efficiency and authentication availability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If standard OSNMA service is used, then security against spoofing is improved, but service continuity in obstructed environments deteriorates

Engineering Contradiction:
Improvesecurity integrityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The EMCDT module maintains continuous authentication capability by storing authentication data from multiple previously authenticated messages. When the standard OSNMA service is interrupted in obstructed environments, the system can continue authentication operations using the stored EMCDT blocks, ensuring service continuity while maintaining security integrity.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If authentication requires subsequent key reception, then authentication security is improved, but authentication timeliness during interruptions deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by caching EMCDT blocks that contain authentication data from previously authenticated messages. This allows the receiver to authenticate navigation data immediately without waiting for subsequent key reception, thus reducing authentication delay while maintaining security through the use of previously verified authentication data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260075422A1Systems, methods, and media for enhanced message-to-code data tie (EMCDT) for electronic message authentication
Publication Date: 2026.03.12 NOVATEL INC
  • US20260075422A1 patent drawing
  • US20260075422A1 patent drawing
  • US20260075422A1 patent drawing

AI summary

Techniques are provided for Enhanced Message-to-Code Data Tie (EMCDT) for electronic message authentication. A processor may receive a navigation message with navigation data that requires authentication and adheres to a delayed key disclosure protocol. There may be a service interruption to the authentication service. The processor can still authenticate the navigation data based on performance of an EMCDT algorithm that uses a Message Authentication Code and Key (MACK) MACK that corresponds to previously authenticated navigation message. Specifically, the MACK for the previously authenticated message can be used when the transmitter identifier of the navigation data to be authenticated matches a PRND value associated with the previously authenticated message and when a version identifier of the navigation data to be authenticated matches the version identifier of the previously authenticated message.