Preventing GPS spoofing is hard, but you can at least detect it
arstechnica.com
arstechnica.com
Sounds like a cat and mouse game. It only works because current spoofers are doing it sloppily. It's only a matter of time before the bad guys get their hands on this and use it to eliminate any discrepancies that the spoofers have. It doesn't sound like they found something that can't be spoofed.
An article linked by the article contains an informative section "How GNSS spoofing works", [1]. Excerpt:
> Effectively, if you can transmit to a GPS receiver, you can speak GPS to it and it will trust you. There's no authentication process involved, and you might even be able to MacGyver together a working spoofing device out of a hacked $15 USB-to-VGA adapter. Granted, you could easily wind up with thousands of dollars in fines or even prison time for trying it—but in strictly technical terms, there's very little stopping you.
[1] https://arstechnica.com/cars/2019/06/claims-of-tesla-hack-wi...
In reality would that happen? Probably not. There are multiple GNSS constellations these days, so just denying GPS is probably not a safe bet (you can buy civilian uBlox chips for $<50 that are tri-band...)
I love reading about the military aspect of GPS. It is really fascinating the use-cases they plan for. Hopefully they never actually are used in such an extreme scenario.
"Based on the previous position of the object, the GPS derived position, the velocity, the DOP(dilution of precision) and the continuity of satellites for which data is received, the system determines whether the GPS data is reliable."
You can even mark a safe set of ephemeris and almanac or just download it from internet, like many kinds of GPS software do.
You would have to spoof a whole constellation to break such measure. And it could be strengthened by discarding signal from satellites that are too close, preventing the equivalent of Sybil attack. So if you see doubled SATs, you can mark one or both of them as invalid.
Then you can also check ionosphere map and validate that signal distortion roughly matches the satellite reported location.
You can also limit the attack by hard capping relative orbital velocity and instantly rejecting that satellite which is unexpectedly too fast. (You would have to again spoof a whole constellation, and if you're target has correct ephemeris data it's all for nothing.)
Maybe I have guessed their solution in a few minutes...
It depends on how the attack is carried out - there are data attacks and timing attacks (the article is generally terrible and has no info). In a data attack the navigation message is altered. Like you suggest this is easy to validate. Note though that most phones (and all new Android phones afaik - don't know about Apple) use assisted GPS, so they download navigation data anyways and a data attack would generally be ineffective. Timing attacks use authentic nav messages, but simulate signal arrival in an altered order, or replay previously recorded signals.
Whole constellation spoofing is not difficult anymore, especially for state actors whole can carry out full-sky attacks. You have no real way beyond correlation/signal strength (which can be attenuated by an attacker) to tell how far away a signal source is, and if you only have a single (stationary) antenna you cannot tell the geometry either (i.e. if signals are coming from multiple sources as expected, or a single antenna).
Multipath is a huge problem, especially in receivers which have linearly polarized antennas like smartphones. Usually when a receiver tracks GPS signals it looks for the signal arriving first (because later signals would be multipath reflections). It is an expensive operation to track multiple occurences of signals, high end receivers do though.
Ionospheric delay can fluctuate, so I don't think this would be very reliable. Also you seem to have a hidden assumtion that you should know the true geometric range to the satellite, which is true for timing receivers.
Wrt velocity, you're not wrong, but it would take a "dumb" attacker to simulate something unrealistic.
https://researchers.dellmed.utexas.edu/en/publications/civil...
It's really difficult to get ION papers, but they do generally put preprints on their lab page: https://radionavlab.ae.utexas.edu/
You're expecting the signal to come from "up" not mostly from the horizon.
Also if you have an almanac already you'd have to spoof each satellites location.
Granted this would be a good deal more complex to implement...
Project link https://github.com/osqzss/gps-sdr-sim
To the interested, this paper [0] from microsoft mentions a range of 40-50 meters with off the shelf hardware.
A USRP N2X0 will spoof a phone in the same room just through leakage
I have the SDR streaming satellite data for 5min and it then restarts and retransmitts again. That allows units on the assembly table to get a sat lock and pass the factory test.
It will get down to a game of knowing the satellites better and better, in terms of their clocks, orbits, and drifts in those parameters. With the increasing precision of augmentation, spoofers will be hard pressed to keep up and precisely mimic more parameters.