Radionavigation Authentication via Server-Side Key Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing radionavigation systems require a communication channel between the server and receiver for authentication, and the server typically stores a private key, making them unsuitable for standalone operation without a security module or when the server lacks the secret key.
Innovation Solution
A method where a series of keys k2,i is generated in the radionavigation infrastructure, used to encrypt and re-encrypt spreading code signals, allowing the receiver to authenticate signals without storing a secret key by transmitting re-encrypted sequences and keys, enabling standalone operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the server stores a private key for authentication, then authentication security is improved, but device complexity and security module requirements increase
Solution Approach 1:
The patent extracts the secret key from the receiver and relocates it exclusively to the server. The receiver no longer needs to store or process the secret key, eliminating the need for security modules in the receiver. The server retains full responsibility for key management and authentication operations.
Solution Approach 2:
The patent introduces an intermediary mechanism where the server generates authentication sequences using the secret key and transmits them to the receiver. This intermediary approach allows the receiver to perform authentication without directly handling the secret key, reducing device complexity while maintaining security.
2Reliability
If a communication channel is used for authentication between server and receiver, then authentication capability is improved, but adaptability to standalone operation deteriorates
Solution Approach 1:
The patent implements preliminary action by having the server generate and transmit authentication sequences to the receiver before the receiver needs to perform standalone authentication. The receiver stores these pre-transmitted sequences and can use them for authentication without requiring real-time communication with the server, enabling standalone operation.
3Reliability
If the receiver stores a secret key for spreading code encryption, then authentication integrity is improved, but device complexity and security requirements increase
Solution Approach 1:
The patent extracts the secret key from the receiver's architecture and centralizes it in the server. The receiver performs authentication operations using authentication sequences generated by the server, eliminating the need for the receiver to store or manage the secret key, thus reducing device complexity and security module requirements.
4Reliability
If spreading code authentication is implemented with encryption, then authentication security is improved, but ease of operation deteriorates due to key management requirements
Solution Approach 1:
The patent implements self-service by having the server automatically generate, manage, and transmit authentication sequences to the receiver. The receiver simply receives and uses these sequences without needing to manage keys manually. This automates the key management process and significantly improves ease of operation.
Data Source
AI summary
A method carried out in a radionavigation system (2), the radionavigation system (2) comprising a receiver (4) and a radionavigation infrastructure (6), the radionavigation infrastructure comprising a plurality of satellite-borne transmitters (8, 8′, 8″, 8′″), and encryption component (10) configured for communication with the transmitters (8, 8′, 8″, 8′″) and the receiver (4). The method comprises the following, for one or more given transmitters (8) of the plurality of satellite-borne transmitters (8, 8′, 8″, 8′″). In the radionavigation infrastructure (6), a series of keys k2,i are generated in respect of a predetermined authentication interval [0,T] of duration T and commencing at t=0 and a spreading code-encrypted signal e(t) is generated from a first radionavigation signal s1(t) using a keystream K1(t), the keystream K1(t) being generated with a secret key k1 of the radionavigation infrastructure (6). The method further comprises generating, in the encryption component (10) of the radionavigation infrastructure, a re-encrypted sequence Ri using a keystream K2,i generated with the series of keys k2,i. The method further comprises the encryption component (10) transmitting, prior to t=0, the re-encrypted sequence Ri to the receiver (4). The method further comprises transmitting, from the given transmitter (8), the spreading code-encrypted signal e(t) and transmitting, from one of the plurality of transmitters (8, 8′, 8″, 8′″), the series of keys k2,i. The method further comprises, at the receiver (4), (i) receiving and storing, prior to t=0, the re-encrypted sequence Ri; (ii) receiving the spreading code-encrypted signal e(t); (iii) receiving the series of keys k2,i; (iv) decrypting the re-encrypted sequence Ri, using the series of keys k2,i to obtain encrypted sequences Ei. The method further comprises, correlating, at the receiver (4), at least portions of the received spreading code-encrypted signal e(t) with the encrypted sequences Ei and thereby generating a code phase measurement for the given transmitter (8). The method may further comprise extracting, at the component (10), from the spreading code-encrypted signal e(t), a plurality of encrypted sequences Ei associated with respective periods of time within the predetermined authentication interval [0,T], wherein the re-encrypted sequence R′i is generated from the extracted encrypted sequences Ei using the keystream K2,i, the re-encrypted sequence Ri being associated with the given transmitter (8). In an embodiment, the encryption component (10) at which the re-encrypted sequence Ri is generated is a ground-based server. Methods carried out in the infrastructure (6) and at the receiver (4), and a radionavigation system (2), infrastructure (6) and receiver (4) are also disclosed.

