GNSS Navigation Message Authentication During Delayed-Key Interruptions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing GNSS authentication techniques, such as OSNMA, face challenges in obstructed environments where service interruptions prevent authentication due to delayed key disclosure, leading to degraded availability and continuity, and potential security vulnerabilities from collision attacks.
Innovation Solution
The Enhanced Message-to-Code Data Tie (EMCDT) module generates and stores EMCDT blocks for authenticated messages in a buffer, allowing cross-authentication during service interruptions by matching transmitter identifiers and version stamps, using previously authenticated messages' codes and keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If delayed key disclosure protocol is used for authentication, then security against spoofing and corruption is improved, but availability and continuity are degraded during service interruptions
Solution Approach 1:
The system performs preliminary authentication by storing EMCDT blocks containing authentication codes and keys in advance during periods when authentication data is successfully received. When service interruptions occur, these pre-stored blocks enable continuous authentication without requiring real-time key disclosure, thus resolving the contradiction between security and availability.
2Loss of energy
If delayed verification mechanism is used, then bandwidth efficiency is improved, but authentication continuity is degraded during reception interruptions
Solution Approach 1:
The invention extracts authentication codes and keys from the delayed verification stream and stores them in EMCDT blocks during successful reception periods. This extracted authentication data can then be independently applied during interruptions, maintaining authentication continuity while preserving the bandwidth efficiency of the original delayed verification mechanism.
3Reliability
If standard OSNMA authentication is used, then cryptographic security is improved, but vulnerability to collision attacks increases
Solution Approach 1:
The system combines multiple authentication elements (navigation message identifiers, version stamps, transmitter identifiers, and authentication codes) into composite EMCDT blocks. This composite structure creates a more robust authentication mechanism that maintains cryptographic security while resisting collision attacks through multiple verification layers.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Techniques are provided for Enhanced Message-to-Code Data Tie (EMCDT) for electronic message authentication. A processor may receive a navigation message with navigation data that requires authentication and adheres to a delayed key disclosure protocol. There may be a service interruption to the authentication service. The processor can still authenticate the navigation data based on performance of an EMCDT algorithm that uses a Message Authentication Code and Key (MACK) MACK that corresponds to previously authenticated navigation message. Specifically, the MACK for the previously authenticated message can be used when the transmitter identifier of the navigation data to be authenticated matches a PRND value associated with the previously authenticated message and when a version identifier of the navigation data to be authenticated matches the version identifier of the previously authenticated message.