SearcharxivSearch

arXiv subjects

Eric Jedermann

Publications and source records attributed to Eric Jedermann.

2 recordsLinked to original sources

Chi-MERA: Defending Orbit-Based Authentication of LEO Satellites with the Space Oddity of MLAT (Long Version)

An active research area, physical layer security can be a last resort in insecure legacy systems, a resource-efficient alternative, or a complementary backup for cryptographic techniques. In this paper, we demonstrate that previously established authentication schemes for LEO satellites are vulnerable to attackers that control multiple devices. In extensive experiments, such attackers produce false positive rates (FPR) of up to 40%. Based on a root cause analysis, we develop a novel scheme, called Chi-MERA, that improves authentication performance and is robust against multi-device attackers. Our scheme uses two enhancements: (1) multilateration (MLAT) to clearly distinguish between attackers and legitimate satellites, and (2), a new resilient signature scheme without dependency on a single dedicated reference receiver. Our evaluation shows that exploiting MLAT characteristics such as residual analysis to classify vastly different signal source categories (orbit vs. non-orbit) is highly effective. In extensive simulations, we show that the new authentication achieves low FPR of $<$2% and false negative rates of $<$3% for accidentally rejecting valid signals. Furthermore, our scheme's defense scales linearly: $n$ receivers reliably withstand spoofing (FPR $< 1%$) from attackers with $\frac{n}{2}$ devices.

cs.CR

Systematic Security Analysis of the Iridium Satellite Radio Link

The Iridium Low Earth Orbit (LEO) satellite constellation remains a unique provider of global communications for critical industries, governments, and private users, serving over 2.5 million active subscribers despite recent market competition. In contrast to terrestrial wireless standards such as 3GPP, Iridium protocol specifications are proprietary and have not undergone rigorous, public, and systematic security evaluation. In this work, we present the first comprehensive security analysis of Iridium authentication and radio link protocols. We reverse engineer Iridium SIM-based authentication mechanism and demonstrate that the secret key can be extracted from the SIM card, enabling full device cloning and impersonation attacks. Leveraging a month-long dataset of Iridium up- and downlink satellite traffic, we further show that nearly all signaling and radio communication protocols currently in use lack encryption, resulting in the exposure of sensitive information in cleartext over the air such as login credentials and large volumes of personal data. Finally, we develop custom software-defined radio (SDR) tools to carry out spoofing and jamming attacks, revealing that modestly equipped adversaries can inject falsified messages or disrupt the Iridium service locally due to the absence of source authentication. Our findings uncover systemic vulnerabilities in the Iridium radio link and highlight the urgent need for users of critical applications to transition to more secure communication radio links.

cs.CR