security//cyber-physical security//GNSS spoofing

GNSS spoofing is an attack in which a transmitter broadcasts counterfeit satellite navigation signals so that a receiver computes the position or time the attacker chooses, and it threatens anything that trusts GPS, Galileo or their peers: drones, ships, aircraft, and the grid and telecom equipment that take their clocks from satellites. It works because civil signals arrive extremely weak, around −130 dBm, below the thermal noise of the receiver, and for most of their history without any authentication; a fake signal a little stronger than the real one captures the receiver's tracking loops. In 2013 a team from the University of Texas steered a yacht off course in the Mediterranean this way, with the owner's permission.


GNSS spoofing is an attack in which a transmitter broadcasts counterfeit satellite navigation signals so that a receiver computes the position or time the attacker chooses, and it threatens anything that trusts GPS, Galileo or their peers: drones, ships, aircraft, and the grid and telecom equipment that take their clocks from satellites. It works because civil signals arrive extremely weak, around −130 dBm, below the thermal noise of the receiver, and for most of their history without any authentication; a fake signal a little stronger than the real one captures the receiver's tracking loops. In 2013 a team from the University of Texas steered a yacht off course in the Mediterranean this way, with the owner's permission.

It is easy to confuse with GNSS jamming, which simply drowns the signals in noise. Jamming leaves a receiver without a fix, and it knows it: the autopilot falls back to its inertial sensors and raises an alarm. Spoofing leaves the receiver with a fix that looks perfectly good, and a patient attacker moves it slowly, within what the navigation filter considers normal noise, so that a drone drifts away while believing it flies straight (stealthy attack).

The best defence against a lying GPS is another sensor.

An inertial unit, odometry or a camera knows nothing of radio and cannot be spoofed by the same transmitter; against them the fake GPS produces a residual, and a test that accumulates evidence catches even a slow drag (CUSUM).

The defences are stacked: residuals against the IMU, wheel odometry or visual-inertial odometry; monitoring of received power and of the receiver clock, which jump when a spoofer takes over; several antennas, since all fake signals arrive from one direction while real ones come from across the sky; and signal authentication. Galileo has added navigation message authentication, OSNMA, to its free open service, which lets a receiver verify that the navigation data come from the system.

Authentication of the message does not stop every attack. A meaconer records real signals and rebroadcasts them with a delay, which passes message checks and still shifts the computed position, so the physical cross-checks stay necessary.

The receiver itself is described in GNSS receiver; the general problem of attacks that keep residuals in band is cyber-physical security.