5 ms·
Mind you this only helps to tell you if the signal is authentic, you're still without that navigation system at that point, hence the search for a localized alt
by Salgat 2y ago
Mind you this only helps to tell you if the signal is authentic, you're still without that navigation system at that point, hence the search for a localized alternative.
- hylaride 2y agoAlso, the Russians have been playing around with rebroadcasting legit signals with slight delays as well. The Ukraine war has been a very interesting time to observe these tricks.
- brohee 2y agoIf you have a good local clock (e.g. rubidium), you can now detect the signal is from the past and correctly conclude you are jammed and trust INS, starnav or whatever instead...
- cyberax 2y agoTESLA encryption is resistant against rebroadcasting. The idea is to use a PKI infrastructure to digitally sign the timestamp stream at fairly granular intervals. This way, you'll be able to find a set of satellites that are not getting jammed. Another option is to use the low-orbit satellites in addition to regular sats.
- hylaride 2y agoThis is true, but the Russians have demonstrated that combining this with jamming they can make this still possible (along with other tricks). Obviously there's going to be some back and forth movement via countermeasures and updates, but the west has only very recently woken up to these threats.
- cyberax 2y agoEncryption is not widely used right now, so I don't believe it's been defeated.
- Aloisius 2y agoThere have been papers that successfully demonstrated spoofing attacks against OSNMA-enabled GNSS receivers like: https://arxiv.org/abs/2501.09246 https://arxiv.org/abs/2501.09246
- cyberax 2y agoThe key issue here is bypassing the time synchronization requirement during the cold start. This has always been a problem with OSNAM, and it's impossible to solve completely. The workaround is clear, the receiver just needs to do an external clock synchronization without relying on GNSS. Something like NTP is more than sufficient for that. The attack in the paper also assumes that the attacker has complete radio control and can jam ALL the signals. If the receiver gets even one fully authenticated stream from an actual satellite, then the initial timestamp spoofing will fail. Replay attacks on tracking receivers are not particularly powerful either, they will be apparent within 10-30 seconds.
- lxgr 2y agoCan’t an attacker still start meaconing the original (i.e. locally captured) signal and then slowly selectively delay/advance each individual satellite component in the time and frequency domain? Not sure how much latency that would introduce and how feasible that is in terms of tricking a receiver sensitive to any jumps/outages, and its definitely a weaker attacker capability than “simulate any time and location you want”.
- cyberax 2y agoThe attacker can do that, but it will be immediately apparent for the receiver. The only thing you can do is a replay attack, which is useless, if the receiver has a clock that is accurate to within ~1 sec. It'll immediately recognize that the time stream is being tampered with when the next signature is out of whack. You might be able to trick the receiver _once_ into not updating its position for a few seconds. After that, it'll mark the affected satellites as unreliable and will not use them. It's functionally no different from just jamming them.
- lxgr 2y agoWhy would the replay attack necessarily be immediately apparent if you start out synchronously and only very slowly build up a delay, especially if combined (as you suggest) with a momentary gap and re-acquisition to mask any unavoidable slight initial delay?
- cyberax 2y agoIt does not work mathematically. If you delay signals from one satellite, then you need to simulate signals arriving _faster_ from another satellite (on the opposite side of the sky), assuming the receiver is not diving down into the Earth. And you can't do that because you can't predict the timestream. The receiver should be able to detect this inconsistency and try to filter out the faulty signals. To make this attack feasible, you need to "prime" the receiver by delaying ALL the signals, but that is only possible if you control the initial timestamp sync.