Satellite Navigation Receiver Authentication Using Galileo MACs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing GNSS receivers lack authentication mechanisms to verify the authenticity of satellite navigation data, making them vulnerable to spoofing and jamming, particularly in urban environments, which poses a risk to location-based services.
Innovation Solution
Implementing a method and system that utilize Galileo message authentication codes (MACs) generated from a securely embedded seed key to authenticate satellite navigation receivers, ensuring only certified receivers can access sensitive data and perform reliable positioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If GNSS receivers use open service signals with publicly known structure and format, then receiver compatibility and ease of access are improved, but vulnerability to spoofing and lack of authentication worsen
Solution Approach 1:
The patent introduces authentication intermediaries (trusted authorities, certificate authorities) that mediate between the open GNSS signal structure and the need for security. These intermediaries issue digital certificates and authentication codes that verify the legitimacy of receivers and signals without changing the fundamental open structure of GNSS communications, thus maintaining compatibility while adding security verification layers.
Solution Approach 2:
The patent implements preliminary authentication actions by pre-registering receivers with trusted authorities before they operate. Receivers obtain authentication credentials in advance, and signals are pre-verified through authentication codes and digital signatures. This preliminary verification prevents spoofing attempts before they can compromise the system, maintaining open signal access while ensuring reliability.
2Device complexity
If GNSS receivers operate without authentication mechanisms, then device complexity and cost are reduced, but susceptibility to spoofing and jamming increases
Solution Approach 1:
The patent extracts the authentication functionality into separate modular components (authentication modules, certificate verification units) that can be integrated into receivers without fundamentally redesigning the entire system. This extraction allows authentication mechanisms to be added as distinct functional blocks, minimizing impact on overall device complexity while providing protection against spoofing.
Solution Approach 2:
The patent changes the operational parameters of GNSS receivers by introducing verification parameters (authentication codes, digital signatures, certificate validity checks) that receivers must evaluate. These parameter changes enable authentication without requiring complete system redesign, as receivers simply need to incorporate additional verification steps using the provided authentication credentials.
3Reliability
If authentication mechanisms are implemented in GNSS receivers, then security and reliability are improved, but device complexity and processing requirements increase
Solution Approach 1:
The patent implements partial authentication action by verifying only critical authentication parameters rather than performing complete cryptographic verification of all signal elements. Receivers check essential authentication codes and certificate validity without requiring full cryptographic processing of all navigation data, thus providing security verification while limiting processing complexity to the minimum necessary level.
4Adaptability or versatility
If open service GNSS signals are used without authentication, then accessibility for mass market devices is improved, but trustworthiness of location data deteriorates
Solution Approach 1:
The patent enables self-service authentication where receivers automatically verify their own authentication credentials and the authenticity of received signals without requiring manual intervention. The authentication system serves itself by having receivers independently verify certificates and authentication codes, maintaining mass market accessibility while ensuring location data trustworthiness through automated verification processes.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A mobile device, which comprises a satellite navigation system receiver with embedded confidential seed key for generating Galileo MACs for any desired time instant, generates a MAC for a given time instant and transmits the MAC or a derived code as a verification code. A receiving entity authenticates the satellite navigation system receiver by comparing the obtained verification code with an available verification code known to be valid for the given time instant. The satellite navigation system receiver is considered to be an authentic satellite navigation system receiver of a mobile device only, in case the at least one obtained verification code matches the available verification code. Selected further actions are enabled only, if the satellite navigation system receiver is considered an authentic satellite navigation system receiver.