GNSS Navigation Message Authentication During Delayed-Key Interruptions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing GNSS authentication techniques, such as OSNMA, face challenges in obstructed environments where service interruptions prevent authentication due to delayed key disclosure, leading to degraded availability and continuity, and potential security vulnerabilities from collision attacks.

Innovation Solution

The Enhanced Message-to-Code Data Tie (EMCDT) module generates and stores EMCDT blocks for authenticated messages in a buffer, allowing cross-authentication during service interruptions by matching transmitter identifiers and version stamps, using previously authenticated messages' codes and keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If delayed key disclosure protocol is used for authentication, then security against spoofing and corruption is improved, but availability and continuity are degraded during service interruptions

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication by storing EMCDT blocks containing authentication codes and keys in advance during periods when authentication data is successfully received. When service interruptions occur, these pre-stored blocks enable continuous authentication without requiring real-time key disclosure, thus resolving the contradiction between security and availability.

Inventive Principle:
Principle #10Preliminary action

2Loss of energy

If delayed verification mechanism is used, then bandwidth efficiency is improved, but authentication continuity is degraded during reception interruptions

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidauthentication continuity
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The invention extracts authentication codes and keys from the delayed verification stream and stores them in EMCDT blocks during successful reception periods. This extracted authentication data can then be independently applied during interruptions, maintaining authentication continuity while preserving the bandwidth efficiency of the original delayed verification mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If standard OSNMA authentication is used, then cryptographic security is improved, but vulnerability to collision attacks increases

Engineering Contradiction:
Improvecryptographic securityVSAvoidcollision attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system combines multiple authentication elements (navigation message identifiers, version stamps, transmitter identifiers, and authentication codes) into composite EMCDT blocks. This composite structure creates a more robust authentication mechanism that maintains cryptographic security while resisting collision attacks through multiple verification layers.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentEP4711818A1Systems, methods, and media for enhanced message-to-code data tie (EMCDT) for electronic message authentication
Publication Date: 2026.03.18 NOVATEL INC
  • EP4711818A1 patent drawingFigure 1
  • EP4711818A1 patent drawingFigure 2
  • EP4711818A1 patent drawingFigure 3A

AI summary

Techniques are provided for Enhanced Message-to-Code Data Tie (EMCDT) for electronic message authentication. A processor may receive a navigation message with navigation data that requires authentication and adheres to a delayed key disclosure protocol. There may be a service interruption to the authentication service. The processor can still authenticate the navigation data based on performance of an EMCDT algorithm that uses a Message Authentication Code and Key (MACK) MACK that corresponds to previously authenticated navigation message. Specifically, the MACK for the previously authenticated message can be used when the transmitter identifier of the navigation data to be authenticated matches a PRND value associated with the previously authenticated message and when a version identifier of the navigation data to be authenticated matches the version identifier of the previously authenticated message.