Satellite Navigation Signal Authentication via Shared Key Chain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current satellite navigation systems lack effective means to authenticate signals, particularly in environments with difficult reception conditions, where the integrity and authenticity of signals and time-of-arrival measurements are compromised, and existing authentication methods require all data from transmitters to be received for authentication, which is not optimal for minimizing the number of bits required for authentication across multiple satellites.

Innovation Solution

A radio navigation system utilizing a single one-way key chain shared among multiple transmitters, where each transmitter includes a message authentication code (MAC) and a further encryption key in their signals, allowing receivers to authenticate signals using any received key from the chain, even if not directly from the transmitting satellite, thereby reducing the number of bits needed for authentication and improving robustness in degraded reception conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used where each transmitter sends its own key, then each signal can be authenticated independently, but the number of bits required for authentication increases and reliability decreases in difficult reception conditions

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnumber of bits for authentication
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the authentication keys from multiple transmitters into a single shared key chain. Instead of each transmitter using its own independent key, all transmitters share a common one-way key chain, allowing the receiver to authenticate multiple signals using a single key from the chain, thereby reducing the total number of authentication bits required while improving reliability through redundancy

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single shared key chain serves multiple functions: it authenticates signals from multiple different transmitters, provides redundancy in case some signals are lost or corrupted, and enables the receiver to authenticate signals even when not all transmitter keys are received, making the authentication system more universal and robust

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If all data from transmitters must be received for authentication, then authentication can be performed, but the system becomes inefficient in environments with signal loss or difficult reception conditions

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidadaptability to reception conditions
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements partial action by allowing authentication to proceed with only a subset of transmitter data rather than requiring all data. The receiver can authenticate signals using data from any sufficient number of transmitters, eliminating the need to wait for or receive data from all transmitters, thereby improving efficiency in environments with signal loss

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The one-way key chain is pre-established and shared among all transmitters before authentication begins. This preliminary setup allows the receiver to immediately authenticate incoming signals using the pre-shared key chain without needing to receive and process complete data sets from all transmitters first

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10732290B2Method and system to optimise the authentication of radionavigation signals
Publication Date: 2020.08.04 EUROPEAN COMMUNITY (EC)
  • US10732290B2 patent drawing
  • US10732290B2 patent drawing
  • US10732290B2 patent drawing

AI summary

A radio navigation system (100; 400), comprising a plurality of satellite-borne transmitters (110, 114, 118, 122) and at least one ground-based receiver (104), the receiver (104) being adapted to receive radionavigation signals (112, 116, 120, 124; 412, 416, 420, 424) from each of a plurality of the transmitters (110, 114, 118, 122). Each of the transmitters (110, 114, 118, 122) and the receiver (104) being adapted to access a predetermined first key chain, the first key chain comprising a first encryption key (K; Kj) and one or more further encryption keys (K; Kj,1, Kj,2, Kj,3, Kj,4). The system may comprise a first group of transmitters from said plurality of transmitters (110, 114, 118, 122), each transmitter in the first group of transmitters being operable to transmit a first radio navigation signal (112, 116, 120, 124; 412, 416, 420, 424), the first radionavigation signals including, at a given instant or for a given subframe (k, k+1), radionavigation data, a MAC (MAC1, MAC2, MAC3, MAC4), and one of said one or more further encryption keys (K; Kj,1, Kj,2, Kj,3, Kj,4). The MAC code (MAC1, MAC2, MAC3, MAC 4) is unique to each transmitter (110, 114, 118, 122) and is generated using the first encryption key (K; Kj,) and the one of said one or more further encryption keys (K; Kj,1, Kj,2, Kj,3, Kj,4) is transmitted a predetermined time after transmission of the MAC. The receiver (104) is operable, upon receipt of all or part of the first radionavigation signal (112, 116, 120, 124; 412, 416, 420, 424) from one or more of the first group of transmitters (110, 114, 118, 122), to authenticate a first radionavigation signal received from one of the first group of transmitters based on one of said one or more further encryption keys (K; Kj,1, Kj,2, Kj,3, Kj,4) received from that transmitter or from any other transmitter in said first group of transmitters. The same key K may be used for all transmitters in the first group, or each transmitter may use different key from the key chain. The transmitters may be formed into a second group, in addition to the first, with the second group using its own key chain in a similar manner. An advantage is to increase the availability of an authenticated position even in degraded reception environments. Embodiments also relate to the optimal transmission of authentication information—though the use of unpredictable bits interleaved with predictable bits—so as to minimize the signal predictability time and the increase of robustness against replay attacks.