Satellite reveals immense scale of GPS signal tampering
space.com
space.com
- The greatest safety concern is the degraded functionality of the Ground Proximity Warning System (GPWS). The system does not operate correctly after spoofing, even if GPS coverage is restored. The number of false alerts is astounding. ...
- A similar concern is the significant possibility of the GPS Receiver appearing normal to flight crew after spoofing, but in reality being contaminated with false data. ...
- This year, a 500% increase in spoofing has been observed. On average 1500 flights per day are now spoofed, versus 300 in Q1/Q2 of 2024...
They included maps. Most of the Middle East and parts of Eastern Europe no longer have useful GPS coverage. It's not just jamming. There's active spoofing, which sends out false position info.
And this was before the Iran war.
Before this, everybody in the industry thought GPS solved the aerial navigation problem. In the US, the FAA wanted to shut down many of the old radionavigation aids. Now, there's a lot more interest in improving the other systems. The military wants to go mostly inertial and is working on better inertial systems.
[1] https://ops.group/dashboard/wp-content/uploads/2024/09/GPS-S...
Many people in industry believed this but no one with a brain ever did. The vulnerability of GPS has been cause for concern for a long time, and the decimation of the VOR network has always had a lot of people up in arms.
Like you first have to infer what satellite you are even measuring, before you can decide where it might be.
If the math works, and it’s just the domain of one-off ridiculously expensive devices today, it’s inevitably feasible in the long run.
1. Public ephemeris from space-track (celestrak) is notoriously inaccurate after a while. Less of a problem for starlink as they give free access to high accuracy ephemeris from their onboard GPS receiver: https://starlink.com/satellite-operators
2. For proprietary signals like starlink they can change signals whenever they want without telling you and break your positioning algorithm. For example, starlink used to transmit some sort of narrowband CW wave at their frequency band, which can be received by cheap ($20 ish) RTL-SDR dongle and satellite TV antenna: https://www.rtl-sdr.com/receiving-starlink-signals-with-an-r... . Everyone speculates that its a beacon signal, research papers were written trying to exploit doppler positioning from those signals. Then the signal disappears, as its possible that they don't intentionally transmit those signal. They you can't use cheap hardware to capture the signal, you need expensive hardware that can capture the full 250 MHz bandwidth. This is not a problem if you use standardized signals where they can even intentionally add positioning signals like 5G or digital TV
(EDIT: I see the other reply thread is already asking the same thing, didn't intend to ask about the same thing)
If you want to prevent replaying as well, add a counter.
Obviously not, but solving problems is always a cost benefit and we went from all spoofing is impossible to some spoofing is possible. What is the benefit of doing this and what is the cost?
> If you want to prevent replaying as well, add a counter.
It's not clear that would be able to prevent spoofing if the attacker could overwhelm and degrade the real signal.
> Because an attacker can just replay legitimate broadcasts with slightly skewed time and origin and introduce huge errors into the fix.
Galileo uses a signing system (Timed Efficient Stream Loss-Tolerant Authentication, TESLA) to protect the authenticity of its messages, including preventing replays:
* https://gssc.esa.int/navipedia/index.php/Galileo_Open_Servic...
* https://datatracker.ietf.org/doc/html/rfc4082 (TESLA)
* https://people.eecs.berkeley.edu/~tygar/papers/TESLA_broadca...
* https://users.ece.cmu.edu/~adrian/projects/stream/node1.html
If the receiver expects a key to have been revealed at a particular timestep, it won't accept a replayed message with that key after that, so you can't record and replay indefinitely.
EDIT: Unless you indeed meant to instantly replay - would the receiver accept the highest strength signal, ie. yours?
For most payloads and targets, this requires very little distortion.
There's a reason GPS satellites are used as reference clock for PPS, PTP and NTP. A naval vessel you could carry a Rubidium clock on, I guess. But on ground vehicles or mobile receivers... nope.
[ed.: OCXOs aren't that large, 1cm^3 box ballpark, too large* for a smartphone or laptop but not a problem on larger quadcopters, cars or military radio equipment. And 1ppm is long term drift, you can try compensating a bit beyond that, so - I guess it's a question of spending the money and energy** on OCXOs.
* thick specifically, can't easily be made thin AFAIK
** the first O there is Oven - roughly 0.5W continuous draw.]
Are you confident in these numbers? They add up to 52 minutes of drift/year.
Good modern quartz watches specify 5 seconds/year drift, almost 3 orders of magnitude better.
The difference with a quartz watch is that it's factory calibrated with the load capacitance on the crystal, and that it's a 32768Hz tuning fork. For a variety of reasons, generating higher frequency clocks off 32768Hz is... "annoying" (huge PLL ratio, very slow feedback loop step), and typical crystals in the 10-100MHz range are just less precise and thermally stable. (Not sure why, I'm not an oscillator manufacturer...)
(NB: you can of course correct for initial deviation in software. The actual problem is stability over temperature.)
Ed.: https://www.digikey.com/en/products/filter/crystals/171 (or, in the hopes the filter on the link works, https://www.digikey.com/en/products/filter/crystals/171?s=N4... ) - look at the options and prevalence for frequency stability & tolerance.
Ed.2: a wristwatch also benefits from being kept at constant-ish body temperature.
I think most quarts watches oscillate at 32 kHz = 2^15 Hz, high precision quartz watches at 8.4 MHz = 2^23 Hz.
> The actual problem is stability over temperature
Apparently, designers of these watches compensating for that somehow: https://en.wikipedia.org/wiki/Quartz_clock#Thermal_compensat...
> benefits from being kept at constant-ish body temperature
Some people take off their watches every day before going to sleep.
These high-end quartz oscillators are probably too expensive to use in commodity computers. Still, the cost shouldn’t look too bad when compared to a price or an airplane, marine vessel, or most military equipment.
(GPS sync is a question of nanoseconds.)
The 'time sync' does not need to be done in the same absolutely sense (time_t is the same everywhere), but only in the relative sense:
Various approaches exist for time synchronization [15,16,17,18].
TESLA only requires the receiver to know an upper bound on the delay
of its local clock with respect to the sender's clock, so a simple
algorithm is sufficient.
* https://datatracker.ietf.org/doc/html/rfc4082#section-3.3.1Knowing the (rough) broadcast delay from sender to receiver is sufficient.
You're citing things without understanding them.
First, you've mangled that summarisation, knowing an upper bound on delay is not the same as knowing delay.
Second, that's true for using TESLA for data streams. Not for when the timing of the stream itself is the information content. That bound on delay translates into a spatial zone of spoofability. The RFC refers to the content being timely (not stale) and authenticated, but timely is not the same as using the timing itself as data.
> Global Navigation Satellite Systems (GNSS) are critical for infrastructure like energy, telecommunications, and transportation, making their accuracy vital. To enhance security especially against location spoofing, in 2024, the Galileo GNSS system adopted the Timed Efficient Stream Loss-Tolerant Authentication (TESLA) protocol, for Navigation Message Authentication (NMA). However, past and present TESLA versions have lacked formal verification due to challenges in modelling their streaming and timing mechanisms. Given the importance of formal verification in uncovering protocol flaws, this work addresses that gap by formally modelling and verifying the latest TESLA protocol used in Galileo; we verify Galileo’s TESLA protocol in the well-known Tamarin prover. We discuss our findings and, since this is work-in-progress, we contextualise them in terms of next steps for us, as well as for future Navigation Message Authentication protocols inside GNSS systems.
> Then, security-wise, via 8 lemmas, we show: […] timeliness of the messages: the receiver will reject messages (even when they have cryptographic integrity) if they were received outside of their validity time-interval; […] replay-related security: i.e., replay attacks are possible, but only if the acceptability time interval is not violated (i.e., messages replayed too late will be rejected). […]
Of course, they dont protect against jamming.
There's another frequency they could be using that is higher power but hasn't been put into production yet.
I don't understand how "spoof-to" works. If you have to mimic a satellite then isn't everyone going to get a different location? Unless you're tracking a specific target how can you intentionally spoof them to a desired location? I'd assume the best you could do is create a fixed offset.
> The military wants to go mostly inertial and is working on better inertial systems.
Given the drift rate this is an idea for munitions but exceptionally difficult to actually operate in a vehicle.
Because the clocks internal to GNSS receivers are not that accurate, if they're not at the "targeted" location they'll see that all satellites are off by a given time offset, and think that their clock is just off by that much.
So I assume that the research effort is directed towards reducing the cost and size.
Those coded transmissions are far harder to jam unless you have the key. So it's all about selling to as many customers as possible whilst having not a single customer leak the key.
That's why militaries use keys that rotate daily and won't let anyone else use the military signal.
So you have to send out one (or maybe a couple) of signals protected by a key.
Yes, you can distribute that key individually to clients using public key cryptography over the same link (and many services like pay TV do exactly that).
But fundamentally any client who is able to decrypt the main stream can also share the key with someone evil who can use that info to jam the same stream.
To add to that, other people won't be able to spoof the original stream (as that needs the private key), but instead only jam it.
It would be the same failure mode as SSL certificates.
An attacker can record the streams and replay them milliseconds later.
A client can protect against this if they have an atomic clock, but that's only for clients willing to pay a decent amount.
Obviously you could have some "revoke each players keys in turn until the jamming stops" scheme, but it seems suboptimal.
I would have to look at the math more specifically, but I would think it would be impossible to both disguise the compromised key and take advantage of the key to interfere with the signal in the way its designed to prevent. And even if you did, I’m fairly sure the jamming would only affect users whose decryption runs through your branch, and in your geographic proximity so I don’t think it would have an advantage of countering the below the noise floor decryption designed to mitigate against jamming.
Will this suddenly make offending countries scramble for an alternative?
The article itself reads like guerilla advertising so I'm inclined not to take it at face value.
So they basically will launch 300 satellites with an alternative that will face the exact same issues once jamming output signals increase too?
Encryption and LEO make this significantly harder to jam. I see value in it.
Military hardware uses different signals, encryption, more advanced receivers, etc etc, but these things are on ITAR lists and not shared with the public.
It's a little surprising to me that there's a commercial venture that has been allowed to provide these things to the public at some point.
Another example is high frame rate thermal camera, US companies are banned from exporting cameras above 9 fps, while chinese companies freely sells 50 fps cameras
39C3: "Who cares about the Baltic Jammer?" / "Terrestrial Navigation in the Baltic Sea Region"
First few minutes give a summary, remainder is about DLR's attempt to fix it.
Also, https://gpsjam.org/ (ADS-B data from planes, hence limited coverage area.)
I think by “fly”, they mean several hundred km in the air where you have sharply reduced below-the-horizon blocking.
Anyone got any leads on Doppler shift detecting equipment? Not hard to detect you’re getting spoofed or jammed with based on that. Power levels being all improbable wouldn’t be hard to detect either. Difficult to detect if “tuned” to a particular target but blanket spoofing would be hard.
Then at the consumer level, fallback options exist (hi wifi); but having something more local would be nice. FM radio stations maybe? Can mess with those too ofc. AM systems are already a fallback in aviation for gross navigation.
A private GNSS constellation has very business cases.
All radio receivers? Detecting the radio doppler frequency shift for satellites is kinda trivial.
Spoofing/jamming systems also trivially include doppler shifts. The more someone is trying to interfere with your specific location, the harder it is to defeat the spoofing.
Unfortunately gpsjam.org relies on ADS-B data and if you don't have a lot of flights (or ads-b receivers) in an area, it leaves a lot of gaps. Plus it's far from real-time.
I give it 2-10 years before one of the two threatens an imagined adversary with detonating a nuke in orbit, with the explicit intent of causing Kessler syndrome.
The US has HARM (anti radiation missiles) but it would be very easy for Ukraine, or anyone, to create an inexpensive drone, which you would program with a frequency, a signal strength, and a general direction and send it to ride the radio signal straight to the jammer. Repeat daily as needed.
Anything on the ground transmitting high power on GPS freqs is up to no good for the global community.
Their L5 signal has been in experimental operation for probably over a decade, still "experimental".
> However, the program was unable to deliver needed capabilities on an operationally relevant timeline at an acceptable level of risk to meet the GPS constellation modernization needs.
Hopefully the newer equipment and incremental improvements can bridge over to whatever's next.
[1] https://www.spaceforce.mil/News/Article-Display/Article/4465...
Right. So have they employed ground truthing to quantify this uncertainty? Truth was important when I went to GIS school.
To find your place on the globe you need to know the current time, and the azimuth and elevation of a feature in the astronomical sky.
Since the pulsars have different periods, observing them should allow you to reconstruct the time, and the directions of these emissions then allow you to determing where on the globe you are for such a time.