Chip Scale Atomic Clock (CSAC)
microsemi.com
microsemi.com
https://www.army.mil/article/88361/Miniaturized_atomic_clock...
Also related, NASA has a spaceborne atomic clock in testing that, if it works, will make space navigation much more efficient: https://www.nasa.gov/mission_pages/tdm/clock/index.html
Hrm, it would definitely stop a spoofer from misleading you about what time it is.
If you care about your position: given the fact that GPS satellites are so far away and the signal is so weak, I don't see how it provides any defense against jamming specifically. If you can't hear the satellites, you can't hear them.
Regarding spoofing, it really only defends against spoofed signals emanating from other satellites. This is a big concern for the military. For everybody else "spoofing" means spoofed signals from other land-based or atmospheric transmitters, which once again are close enough to easily drown out the true signal completely.
TL;DR: useful if threat model includes attacker-controlled satellites.
In terms of spoofing, one method is to emit signals from ground based transmitters that match the signal from the actual satellite, but with offset times, and at higher power levels than the actual satellite[1]. This gives the receiver a false location.[2] If you have a source of time-truth, you can reject these signals.
In terms of jamming, you'll note that it allows rapid resynchronization after jamming. During jamming, you don't know where you are. After jamming, without a highly precise clock, you need to solve for the actual time by integrating signals from >=4 satellites. With a highly precise clock, this step is removed.
[0] There are confounding factors, like refraction in the ionosphere, but a rough approximation is that the signal is travelling at c
[1] Higher power is trivial because the signals from the satellites are very weak
[2] This is a classic example: https://en.wikipedia.org/wiki/Iran%E2%80%93U.S._RQ-170_incid...
TL;DR: useful for existing ground/air based threats.
Jamming nowadays does not work by simply throwing off random numbers. This is trivially defeated by gyroscope. It works by feeding time data that initially is exactly the same as the satellite, and slowly changes that as if it was in some other plausible direction, ultimately giving total control.
Against primitive forms of jamming, sure this might work. Against modern spoofing attacks, no there is no fix. Overall, what worked works and what doesn't work won't.
Any introduction of a false timing signal whose time offset from the true signal is greater than the local clock's uncertainty can be flagged as false. Higher-accuracy local clocks reduce the amount of error that can be introduced without detection.
CSACs don't solve the issue, but they do allow for detection of more spoofing signals, and they reduce the amount of error that any successful spoofing signal can introduce.
Without a source of location truth, you have no way of knowing if the change in the time signal is because of your movement relative to the GPS satellites, or because of spoofing.
As I said, the false GPS signal will start with a time offset of zero. They will then progressively offset the time signal of each satellite as if, for example, the GPS receiver was deviating slightly right, after which the drone will turn left.
Because of relativity you cannot use local time to estimate remote time, and hence you cannot use local time to make the difference between time spoofing and location changes.
No. If you have both a source of time-truth and a source of location-truth you can reject these signals.
But if you had a source of location-truth you wouldn't need GPS.
GPS spoofers start off feeding you exactly the same data as the GPS satellites, then start diverging exactly as if you were slowly turning in a different direction.
Ergo, this will not work at all.
Any introduction of a false timing signal whose time offset from the true signal is greater than the local clock's uncertainty can be flagged as false. Higher-accuracy local clocks reduce the amount of error that can be introduced without detection.
CSACs don't solve the issue, but they do allow for detection of more spoofing signals, and they reduce the amount of error that any successful spoofing signal can introduce.
Any introduction of a false timing signal whose time offset from the existing measurements is greater than the local clock's uncertainty can be flagged as false.
If your previous reported satellite time is Sp, previous local time is Lp, local time uncertainty is U, current local time is Lc = Lp + Ld±U, and current reported satellite time is Sc = Sp + Sd, then, roughly speaking,
if Sd > (Ld + U) or Sd < (Ld - U), the reported signal is a spoof.
So the original spoof signal as well as any subsequent spoof signals are subject to the stricter constraints offered by your higher-accuracy local time source.
This offset will progressively increase in a way that is undistinguishable from an offset caused by receiver moving slightly left, for example.
That being said, the main source of error in GPS signals isn't the time-keeping of the receiver, but rather atmospheric interference and rounding errors in computations.
At each frame the attacker has to add to the error in the victim's position. By limiting how much error the attacker can add at each frame, you limit how much damage the attacker can do.
There are other systems involved here, including accelerometers and gyros, that together with a kalman filter allow the moving system to estimate the state, read values, and output new states based on a combination of those inputs. Less uncertainty in time allows for more precise predictions and more rejection of invalid inputs.
Read the link in my original post if you don't believe me: "If GPS is disrupted or jammed, a CSAC could provide precise time to the GPS receiver to enable rapid recovery or to protect receivers from GPS spoofing, a condition where false GPS signals are broadcast to fool GPS receivers with erroneous information. The hope is that the Soldier wouldn't even know that his GPS is being jammed," Olson said. "
I mentioned gyros and accelerometers in my first comment. They are the only thing that can at all help with advanced spoofing attacks. They are not sufficient. If they were sufficient, there would be no use for GPS to begin with.
This chip can only help against primitive attacks. It can help if the GPS signal is being jammed with nonsense signals by allowing the navigation system to lock back into the correct signal more quickly.
In the case of a sophisticated attack, the navigation system will not be able to detect the spoofing at all. The error induced by the spoofing will be completely indistinguishable from gyro drift.
That is to say, in the RQ-170 incident, the attacker was limited in the amount of error that could be added each frame by the gyros and accelerometer. Now, the attacker is still limited by the gyros and accelerometer, there is no change to the amount of error that can be added over time.
This chip can help against unsophisticated attacks. It cannot do anything at all for sophisticated attacks like those that allowed the capture of the RQ-170.
Let us have a thought experiment to ascertain this. Imagine a drone with an unphysically perfect clock. The drone receives time from 4 satellites and uses this time delta to calculate the distance from all four satellites.
Now let us imagine an attacker which overpowers this time signal. Initially, the signal is exactly the same as before the jamming. The signal at time t is such that it is exactly equal to that if the drone was turning left at exactly half of the gyro drift rate.
How would you be able to detect that this signal is incorrect? The answer is, it is impossible.
You may claim that the clock will be able to detect errors in the time by the spoofer. However, there is inherent noise in the time signal from GPS due to numerical errors in the predicted orbit of the satellites as well as interference from the ionosphere. The stochastic component of this noise is equal to more or less 3 meters. So the time is error in the date signal from the GPS is already of the order of 1/(100 000 000) seconds, meaning that any clock with better than that is not useful for discriminating against sophisticated attacks (but still useful against unsophisticated attacks).
For the issue of the gradually-increasing-error type of attack you mention, this article restates the point I've been driving at[0]. Their example is not chip-scale, but in all other respects it's the same. Note that they separately describe using a source of location-truth, but they still describe a method for spoofing attack detection that just relies on a cesium clock.
This[1] article is a good read, too, though their setup was GNSS-only, no IMU. They detect spoofs down to 2m (the shortest distance tested) with CSACs, but do not detect spoofs at that distance with classical receiver clocks.
Again, this doesn't completely remove the potential for spoofing attacks, it just reduces them. I don't have numbers on the actual limits in position change over time that would be detectable. But the principle for detecting gradual spoofed shifts is valid.
(and yes, I did look up these articles to respond.. not sure what that says about my time-management, but it's an interesting topic :)
From article [0]:
"Certain spoofing attacks work by producing and broadcasting a falsified version of the GPS signal, but at a slightly greater power, which tricks a GPS receiver into locking onto the spoofed signal. Once the receiver has locked onto the spoofed signal, the false signal gradually phases out of sync with the GPS signal, causing the GPS receiver to report a false PNT, one dictated by the spoofer. The incremental phase out makes the spoofing attack very difficult to detect.
...
For a trusted input, TADA uses an atomic clock frequency. In simple terms, for each second measured by the incoming GPS timing signal, TADA counts the number of frequency cycles generated by a cesium clock. If the incoming GPS signal is valid, TADA will count exactly the expected number of Cesium frequency cycles. But if TADA measures a higher or lower number of timing signals than expected, it will display the difference. A difference outside the acceptable margin of error will prompt TADA to alert its users that the GPS timing signal is possibly being spoofed."
[0] https://www.mitre.org/publications/project-stories/tada-mitr...
[1] https://www.gpsworld.com/innovation-getting-there-safely-wit...
https://www.microchip.com/en-us/products/clock-and-timing/at...
https://www.nist.gov/system/files/documents/2017/05/09/VCAT-...
Many teams around the world are actively developing improvements on this technology.
https://www.nist.gov/news-events/news/2019/05/nist-team-demo...
Unlike Rubidium references, the light is supplied by a solid state laser, eliminating another huge power sink.
I expect these devices have a practically infinite life. What an amazing set of innovations.
One of those arcseconds passes by approximately 15 times a second, so using an atomic clock for that is way overkill - any time source more accurate than 1/15 of a second is unnecessary.
The main problem is that once you have aligned your telescope, now what you are trying to do is measure the direction of gravity, compared to the direction you're pointing the telescope, and that's a lot harder. Partly because that's a mechanical angle measurement (you need a pendulum that can freely swing and rest with minimal friction pointing directly in the direction of gravity, and then you need to measure angle). But then also, you need to take account of the fact that the gravitational field on the Earth is lumpy. If you're sitting next to a mountain, the gravitational field will be deflected slightly from pointing directly downwards - and in fact that was used a while back to measure the density of the Earth.
But theoretically, if you can solve the angle measurement bit, you could determine your location on Earth with an error of around 30m.
Perhaps it would be possible to have a pair of identical crystals tied together but electrically opposite in phase so that external vibrations tended to cancel. (Like a differential signaling pair in a cable)
I'm not sure if this clock would be good enough for GPS. It's 3 orders of magnitude less accurate than a cesium clock. But with so many StarLink sats overhead, and synchronizing with more accurate ground clocks, might make up for that.
This thing is sufficiently small, low-power, and low-cost to use in something like StarLink sats, and it's accuracy is advertised as "±5.0E-11 accuracy at shipment", compared to about ~3e-15 or so for cesium clocks. With 30k+ StarLink sats in orbit one might be able to see enough sats overhead to provide comparable accuracy on the ground as GPS (but I've not done the math).
I thought Rubidium fountains were easier to minaturise. I can't see where I can find out how the device is made - there's not much detail.
Ah - you're right, it's Caesium. https://ww1.microchip.com/downloads/en/DeviceDoc/A3405FE2-C1...
I used to run an NTP server, in the pool. But it was stratum 2; it would stroke my ego to run a stratum 1 server. But 3.5 kilodollars: I'll wait.
Fountains need to have a minimum size in order to achieve a sufficient flight time when throwing the atoms up on a ballistic trajectory. Obviously, they also have to be very carefully aligned with respect to gravity.
Edit: At second glance, it seems liks they are actually using Cesium now (some other demonstrators use Rubidium). The principle is the same, but the hyperfine splitting is 9.192631770 GHz (by definition) and the laser wavelength is 894 nm.
IMO it was a bit of gimmick. Apart from being a little too chunky for a wristwatch, just because it's an "atomic clock" doesn't mean it's "atomic powered". IIRC the CSAC uses about 1/8 W which is really pushing it for a low-power device like a watch. It might lose "one second per millennium" as advertised but good luck keeping it continuously operating anywhere near a thousand years.