I don't want to carry this on forever, but I will add this: the interference from the ionosphere is large, yes, but the difference in error is related to geographic location. For example, the error from the ionosphere at two points on the earth 5m apart is very similar. This is why things like CORS base stations and GNSS post-processing work. The range limit on those that NGS uses is 70km. This can be extended to the error from one frame of the solution to the next. The same is true of other error sources: the a priori error is large, but the error from one moment to the next for a receiver is small, for orbital elements, atmospheric noise, satellite clock error, etc.
For the issue of the gradually-increasing-error type of attack you mention, this article restates the point I've been driving at[0]. Their example is not chip-scale, but in all other respects it's the same. Note that they separately describe using a source of location-truth, but they still describe a method for spoofing attack detection that just relies on a cesium clock.
This[1] article is a good read, too, though their setup was GNSS-only, no IMU. They detect spoofs down to 2m (the shortest distance tested) with CSACs, but do not detect spoofs at that distance with classical receiver clocks.
Again, this doesn't completely remove the potential for spoofing attacks, it just reduces them. I don't have numbers on the actual limits in position change over time that would be detectable. But the principle for detecting gradual spoofed shifts is valid.
(and yes, I did look up these articles to respond.. not sure what that says about my time-management, but it's an interesting topic :)
From article [0]:
"Certain spoofing attacks work by producing and broadcasting a falsified version of the GPS signal, but at a slightly greater power, which tricks a GPS receiver into locking onto the spoofed signal. Once the receiver has locked onto the spoofed signal, the false signal gradually phases out of sync with the GPS signal, causing the GPS receiver to report a false PNT, one dictated by the spoofer. The incremental phase out makes the spoofing attack very difficult to detect.
...
For a trusted input, TADA uses an atomic clock frequency. In simple terms, for each second measured by the incoming GPS timing signal, TADA counts the number of frequency cycles generated by a cesium clock. If the incoming GPS signal is valid, TADA will count exactly the expected number of Cesium frequency cycles. But if TADA measures a higher or lower number of timing signals than expected, it will display the difference. A difference outside the acceptable margin of error will prompt TADA to alert its users that the GPS timing signal is possibly being spoofed."
Comments
I don't want to carry this on forever, but I will add this: the interference from the ionosphere is large, yes, but the difference in error is related to geographic location. For example, the error from the ionosphere at two points on the earth 5m apart is very similar. This is why things like CORS base stations and GNSS post-processing work. The range limit on those that NGS uses is 70km. This can be extended to the error from one frame of the solution to the next. The same is true of other error sources: the a priori error is large, but the error from one moment to the next for a receiver is small, for orbital elements, atmospheric noise, satellite clock error, etc.
For the issue of the gradually-increasing-error type of attack you mention, this article restates the point I've been driving at[0]. Their example is not chip-scale, but in all other respects it's the same. Note that they separately describe using a source of location-truth, but they still describe a method for spoofing attack detection that just relies on a cesium clock.
This[1] article is a good read, too, though their setup was GNSS-only, no IMU. They detect spoofs down to 2m (the shortest distance tested) with CSACs, but do not detect spoofs at that distance with classical receiver clocks.
Again, this doesn't completely remove the potential for spoofing attacks, it just reduces them. I don't have numbers on the actual limits in position change over time that would be detectable. But the principle for detecting gradual spoofed shifts is valid.
(and yes, I did look up these articles to respond.. not sure what that says about my time-management, but it's an interesting topic :)
From article [0]:
"Certain spoofing attacks work by producing and broadcasting a falsified version of the GPS signal, but at a slightly greater power, which tricks a GPS receiver into locking onto the spoofed signal. Once the receiver has locked onto the spoofed signal, the false signal gradually phases out of sync with the GPS signal, causing the GPS receiver to report a false PNT, one dictated by the spoofer. The incremental phase out makes the spoofing attack very difficult to detect.
...
For a trusted input, TADA uses an atomic clock frequency. In simple terms, for each second measured by the incoming GPS timing signal, TADA counts the number of frequency cycles generated by a cesium clock. If the incoming GPS signal is valid, TADA will count exactly the expected number of Cesium frequency cycles. But if TADA measures a higher or lower number of timing signals than expected, it will display the difference. A difference outside the acceptable margin of error will prompt TADA to alert its users that the GPS timing signal is possibly being spoofed."
[0] https://www.mitre.org/publications/project-stories/tada-mitr...
[1] https://www.gpsworld.com/innovation-getting-there-safely-wit...