SearcharxivSearch

arXiv subjects

Wim De Wilde

Publications and source records attributed to Wim De Wilde.

2 recordsLinked to original sources

First Galileo SAS Authenticated Time Solution

Spoofing attacks against civilian GNSS receivers have grown more common, especially near conflict zones where they now disrupt civil aviation, maritime operations, and critical infrastructure on a daily basis. Spoofing is possible because legacy civil GNSS signals are largely predictable in both their navigation data and ranging codes, allowing an attacker to forge a signal that imposes a false position and time on an unsuspecting receiver. Cryptographic authentication schemes such as Galileo's Open Service Navigation Message Authentication (OSNMA) mitigate this threat by verifying the authenticity of the navigation data. The ranging code itself, however, remains unprotected. To close this gap, Galileo is introducing a Signal Authentication Service (SAS) in the E6-C signal, which directly authenticates ranging measurements. SAS is currently transmitted by only two satellites in an elliptical orbital plane, of which at most one is visible at a time, meaning a full position solution is not yet possible; however, a georeferenced receiver can still obtain an authenticated time solution. This paper presents, to the authors' knowledge, for the first time, a timing solution computed from an authenticated civil GNSS signal. We develop a snapshot software receiver implementing a simplified version of the Galileo SAS protocol to compute the receiver clock bias from an authenticated pseudorange, using radio-frequency data recorded with an engineering prototype software-defined radio receiver from Septentrio. We evaluate the resulting timing solution using recordings from both SAS-capable satellites collected at different locations, demonstrating the feasibility of authenticated timing ahead of full SAS operational deployment.

cs.CR

Improving Galileo OSNMA Time To First Authenticated Fix

Galileo is the first global navigation satellite system to authenticate their civilian signals through the Open Service Galileo Message Authentication (OSNMA) protocol. However, OSNMA delays the time to obtain a first position and time fix, the Time To First Authentication Fix (TTFAF). Reducing the TTFAF as much as possible is crucial to integrate the technology seamlessly into the current products. In the cases where the receiver already has cryptographic data available, the so-called hot start mode and focus of this article, the currently available implementations achieve an average TTFAF of around 100 seconds in ideal environments. In this work, we explore the TTFAF optimizations available to general OSNMA capable receivers and to receivers with a tighter time synchronization than the required by the OSNMA guidelines. We dissect the TTFAF process, describe the optimizations, and benchmark them in three distinct scenarios with recorded real data (open-sky, soft urban, and hard urban) and the official OSNMA test vectors. The first block of optimizations centers on extracting as much information as possible from broken sub-frames by processing them at page level and combining redundant data from multiple satellites. The second block of optimizations aims to reconstruct missed navigation data by the intelligent use of fields in the authentication tags belonging to the same sub-frame as the authentication key. Combining both optimization ideas improves the TTFAF substantially for all considered scenarios. We obtain an average TTFAF of 60.9 and 68.8 seconds for the test vectors and the open-sky scenario, respectively, with a lowest TTFAF of 44.0 seconds in both. Likewise, the urban scenarios see a drastic reduction of the average TTFAF between the non-optimized and optimized cases. These optimizations have been made available as part of the open-source OSNMAlib library on GitHub.

cs.CR