PNT Signal Validation via Hash Chain Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing GNSS systems are vulnerable to spoofing attacks, and current solutions either require complex and expensive antenna designs or rely on authentication protocols that are not suitable for limited bandwidth signals, while also needing a backhaul connection for validation, which is not always feasible.
Innovation Solution
A method and system that use a hash chain to validate the source of PNT signals without a backhaul connection, where a receiver pre-loaded with the final hash tag of the chain can verify the authenticity of messages by hashing received hash tags, and digital signatures are formed from PNT data across multiple messages to ensure data integrity and authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex antenna designs are used to detect spoofing, then spoofing detection capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent replaces complex mechanical antenna systems with cryptographic validation mechanisms. Instead of using directional antennas or signal processing hardware to detect spoofing, the system uses hash chain tags and digital signatures that can be validated through software-based cryptographic operations, thereby reducing hardware complexity while maintaining spoofing detection capability
Solution Approach 2:
The patent introduces cryptographic intermediaries (hash chain tags and digital signatures) that mediate between the satellite signal and the receiver validation process. These cryptographic elements serve as trusted intermediaries that enable spoofing detection without requiring complex antenna systems, as the validation occurs through cryptographic verification rather than physical signal analysis
2Reliability
If TESLA protocol is used for signal authentication, then authentication capability is improved, but bandwidth efficiency deteriorates due to signal changes
Solution Approach 1:
The patent applies preliminary action by pre-loading the final hash tag of the chain into the receiver before signal reception. This allows the receiver to validate incoming signals by comparing received hash tags against the pre-loaded final hash, eliminating the need for continuous backhaul communication and reducing bandwidth requirements while maintaining authentication capability
Solution Approach 2:
The patent changes the authentication approach from TESLA's time-dependent key distribution to a hash chain-based parameter system where authentication is achieved through iterative hashing of received tags. This parameter change enables authentication with minimal bandwidth consumption, as the validation process relies on local cryptographic operations rather than continuous signal updates
3Area of stationary object
If LEO satellites are used as PNT signal sources, then coverage area is improved, but signal validation becomes more difficult without backhaul connection
Solution Approach 1:
The patent enables LEO satellite signals to be self-validating through the inclusion of digital signatures and hash chain tags within the signal packets themselves. The receiver can validate signals autonomously using pre-loaded cryptographic materials, eliminating the need for external backhaul validation infrastructure. This self-service approach makes LEO satellite validation as simple as traditional GNSS validation while extending coverage area
Data Source
AI summary
For validation of position, navigation, time (PNT) signals, a hash included in messages with PNT data is used to validate the source of the message without backhaul. Different tags from a hash chain are included in different messages. The receiver is pre-loaded with the root or later trusted hash tag of the chain as created. The hash of any received message may be hashed by the receiver. The result of the hashing will match the pre-loaded or trusted hash tag if the transmitter of the message is a valid source. The PNT data may be validated using a digital signature formed from the PNT data for one or more messages and the hash tag wherein a hash tag of the chain in a subsequently received message is used as the key. The digital signature may be formed from data across multiple messages.


