GNSS Replay Attack Detection via UTC Time Delay Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Replay attacks in GNSS systems are difficult to detect as fake signals mimic valid signals, making it challenging to determine whether a position report is fake, especially due to time delays and the use of valid signals in spoofing attacks.

Innovation Solution

A method involving a computing device that monitors GNSS time from satellites, identifies alert conditions based on detected delays between universal coordinated time (UTC) and GNSS time, and provides an alert notification, utilizing neural networks and directional antennas to differentiate between replay attacks and multipath conditions, and can execute these processes in a cloud computing environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If replay attack detection is implemented using time delay analysis, then detection capability is improved, but false positives from multipath conditions increase

Engineering Contradiction:
Improvereplay attack detection capabilityVSAvoidtime delay measurement accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the time delay analysis into multiple components by comparing different time references (GNSS signal time, receiver clock time, and external time source) to distinguish replay attacks from multipath conditions. The system divides the detection process into separate analysis stages: initial time synchronization, continuous time delay monitoring, and anomaly classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an external time source (such as atomic clock or network time protocol) as an intermediary reference to mediate between the GNSS receiver and the multipath environment. This external reference acts as a neutral mediator that provides a stable time baseline, allowing the system to differentiate between legitimate time variations and replay attack indicators without being affected by multipath propagation delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If monitoring of GNSS time is continuously performed, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvetime delay detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements partial monitoring by focusing computational resources on analyzing only the critical time delay parameters rather than processing all GNSS signal characteristics. The system performs excessive action by continuously monitoring time references even when no anomalies are detected, maintaining a running baseline that enables rapid detection when attacks occur.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The GNSS receiver utilizes its own internal clock and existing signal processing infrastructure to perform self-monitoring of time delays. The system serves itself by using the received GNSS signals to discipline its own clock and simultaneously using that same clock to detect anomalies, eliminating the need for separate dedicated monitoring hardware.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If neural network detectors are used to distinguish replay attacks from multipath conditions, then false positives are reduced, but computational requirements increase

Engineering Contradiction:
Improveattack classification accuracyVSAvoidcomputational energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary action by pre-training the neural network detector offline with labeled datasets containing both replay attack and multipath condition scenarios. The pre-trained model is then deployed to the GNSS receiver where it requires minimal computational resources for inference. This preliminary preparation transfers the heavy computational burden from the resource-constrained receiver to the training phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameters of the neural network implementation by using simplified architectures (such as shallow networks or decision trees) optimized for embedded systems. The system adjusts network depth, width, and activation functions to balance classification accuracy with computational energy consumption, selecting parameters that are sufficient for the specific threat model rather than maximizing theoretical performance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4038503B1Method for detecting replay attacks in GNSS systems and devices thereof
Publication Date: 2024.12.25 OROLIA USA INC
  • EP4038503B1 patent drawingFigure 1
  • EP4038503B1 patent drawingFigure 2
  • EP4038503B1 patent drawingFigure 3

AI summary

A method, non-transitory computer readable medium, device, and system that detects a replay attack includes monitoring Global Navigation Satellite System (GNSS) time obtained by a GNSS receiver from a GNSS signal from a GNSS satellite. An alert condition for the replay attack is identified based on at least a detected delay between a universal coordinated time (UTC) and the GNSS time. An alert notification is provided based on the identification of the alert condition for the replay attack.