Considering how important it is for everything from navigation to keeping clocks in sync, satellite navigation systems are surprisingly vulnerable to a variety of attacks, ranging from simple jamming to more sophisticated spoofing attacks. This may be changing, though, as Galileo, Europe’s GNSS, recently demonstrated its first cryptographically-secured position fix under spoofing conditions.
Most GNSS systems, including GPS, have no verification measures to keep an adversary from transmitting a false signal at a higher power and hijacking a receiver; since GNSS signals are extremely weak by the time they reach the ground, this presents no great difficulty to a moderately well-equipped attacker.
Galileo’s Signal Authentication System (SAS) aims to fix this. The Galileo ground station pre-selects signal spreading codes, which it then encrypts with a regularly-changing secret key and publishes. A receiver which anticipates needing a verified signal can then download these encrypted codes ahead of time and store them. Galileo satellites then transmit on the E6-C pilot signal, and the receiver records the signal. After transmitting a message block, it then transmits the decryption key on a separate signal, which the receiver uses to recover the spreading codes. The receiver then correlates these spreading codes with the recorded signal to find the satellite’s pseudorange.
It’s a rather complicated system, but it works: earlier this month in Andøya, Norway, the annual Jammertest GNSS testing event took place. For one week, a wide range of organizations tested the resilience of their GNSS systems against various attacks, including jamming, delayed retransmission, and spoofing. Using five Galileo satellites, the European Space Agency was able to obtain a stable lock on their receiver even during spoofing.
In principle, this method could be extended to other GNSS systems. There’s certainly motivation to do so; very large-scale attacks have been demonstrated recently.

Encryption is important and definitely defend against spoofing, until the key get leaked.
But still jamming and meaconing is an issue.
Also the upcoming LEO constellation have this flaws. In this sense Satellites are technologies for the 2010er.
The only way forward I see here are terrestrial systems with long wavelengths and high transmission power, I call it encryption by physics.
Just not practical. An adversary has the advantage when it comes to received power, since they can have a higher gain antenna (they generally know their targets general location ahead of time), they also only need to operate for short periods of time, so average transmit power is in their favour as well.
Encryption seems the most reliable method. There would need to be an ability to do revokation and re-issuing, but this is already a known issue with encryption systems, and there’s means for this available.
There are organisations looking at using the terrestrial TV networks for PNT. It’s less about encryption and more about signing.
As for LORAN, there are many countries testing or deploying eLORAN, for better or for worse. I’m not convinced using 70s tech is a step forward.
For shortwave systems there are no high-gain transmitter antennas. While GNSS can be attacked with a device fitting in your pocket. Good luck trying these with LF. This is what I meant by protection by physics.
Encryption will only protect from one of three possible attacks!
Yeah, in the end rubber hose cryptography is still a thing and if you are targeted for it you better have your gimp suit ready.
“The only way forward I see here are terrestrial systems with long wavelengths and high transmission power, I call it encryption by physics.” … you mean you want this back: https://en.wikipedia.org/wiki/Loran-C ??? That’s not forward, thats backward. There are resons, why we don’t use these anymore.
Having used loran, it issue was accuracy, and thats its not as simple as gps. But it was effective.
They developed the system further; it’s called eLoran, but there are other systems. I strongly believe if you put the same amount of investment into this technology, you get something more robust.
Regarding the accuracy, eLroan can archive 10m for most day-to-day usage, which is more than enough; of course, there are other examples like constructions, etc., but here we can use a not-so-resilient solution, I believe.
You mean like Loran, Decca and Consol, RIP. All closed down years ago as they were deemed unnecessary with GNSS
Encrypted means probably military access to (symmetric) keys only. Why not simply sign it so you have authenticity (pubkey) and public access? If I receive the signed signal I know it is true, because the jamming signal will have no valid signature.
It really is that easy. If the military needs their super accurate encrypted signal that’s fine too. Give me signed low accuracy, at least I know where I am in contested locations.
I think OSMNA (which is already operating) does this – it signs the navigation messages so the receiver knows they come from gallileo.
This appears to be a different system; it allows the signal to be extracted even if it’s below the noise floor (or the jamming). The decryption codes are sent afterwards to prevent an adversary knowing what the signal is ahead of time and so jamming it effectively – without that they can’t target the signal so can only add random noise over the signal.
… someone else who understands this better can probably explain it better?! HAD editors can we get an article on this?!
Thanks for the reply Dan, I see how that could work. All I know is there are ground control stations that update keys. I suppose it will be in some way similar to GPS for cooperation with NATO partners? If it is some rolling cipher it would not be that odd.
The GPS way:
https://insidegnss.com/the-empty-field-that-wasnt-gps-otad-and-two-decades-of-encrypted-broadcasts/
If Galileo could just let the average Joe/Jane in and profit from this too, I’d be happy. Wasn’t there are plane accident at a North American border because of jamming in the last 2 months? Civil use needs signatures. The military can (and probably will) do their own special sauce regardless.
My understanding is that anyone can use this. The encryption is to protect the spreading code until after the transmission has occurred. The decryption keys are sent publicly after transmission.
There’s a completely separate system for high accuracy for the military.
Both OSNMA and SAS are open service, that means available to everyone. Galileo also has a free correction service (HAS) that provides 20cm of accuracy after convergence.
The military signal in Galileo is called PRS (public regulated service) and afaik it is not yet operational.
https://www.gsc-europa.eu/galileo/services/galileo-open-service-navigation-message-authentication-osnma
You can read the details by yourself. It’s open to the public.
https://github.com/gnss-sdr/gnss-sdr implement part of it, you can read the receiver code as well. There are also open simulation libraries that stimulate this (with wrong keys of course…)
I think signatures like that not really work with individual messages and not continuous streams of data. The satellite would need to break up the timing data into packets and sign them.
Alternatively you encrypt the whole stream, but then you need two streams to allow public access.
The system already sends the data as packets.
I think the reasons they don’t use signatures is that they don’t want to increase the bandwidth. I believe signature algorithms also use more energy, but I’m far from sure about that. It seems the goal of this change is to remain backwards compatible with existing receivers.
Every encryption so far was invented by humans and therefore can be cracked. We’d need alien-grade stuff to be not able to crack it.
But isn’t signing not the same? You take the hash of the message, instead of the whole message, encrypt the hash and tgatsbthe signature you can append.
The big advantage is you can already read the message, but can verify it. Otherwise, you have to decrypt it first (which verifies) and then can read it.
In a satellite, you can make the signing predictable in terms of instructions/timing, so you can subtract it or store it as a fixed offset in the message.
GPS does have a secure mode – actually, it has two! – but they’re only available to the US military and authorized partners. The older mode is called the P(Y) mode, and the new one is called M-Code. Both incorporate anti-jamb, anti-spoof and encryption. The encryption algorithm(s) used are not public, but are likely type-1 suite A, although type-2 or -3 is also possible given coalition distribution. By design it would fall into the NSA’s “high risk” category, as the equipment containing it is common and regularly lost on the battlefield, although anti-RE techniques like QUADRANT are almost certainly present. The GPS receivers do have to have keys loaded, although some recent work by Stephen Murdoch at UCL has suggested there is a covert rekeying channel in there for the past 15 years, which may support OTA key refresh or rekeying.
Signing is better than encryption if you want protection from spoofing.
Encryption is necessary to prevent spoofing – and specifically, temporal separation of cyphertext and key distribution. Signing alone is vulnerable to spoofing/retransmission attacks.
Yes, but I think it would use more energy, which may be a factor here. It would also use more bandwidth and I think the point here is to avoid changing the protocol, so old receivers will continue to work.
What I don’t understand though is, can’t an adversary not just put up receivers and rebroadcast their signals at higher power? Receivers running continuously could notice the change of time and then the signal would just be jammed, but receivers that (re)start wouldn’t notice.
Dan’s explanation above seems correct.
The receiver has to store the whole I/Q data stream for a few seconds before the encryption keys are made available on another channel. During this time neither the receiver nor the attacker know the spreading code that is needed to recover the specific signal.
The attacker could rebroadcast a delayed version of the whole E6 channel, but most of the energy would be wasted in broadcasting noise that the receiver will ignore. So it makes spoofing much less efficient than if you know the spreading code beforehand.
Seems overcomplicated,
just include an 8byte signature, which can be verified with public key,
store private key in HSM.
You still have 30other sats to crosscheck solution.
The bandwidth of Galileo E1 is 120 bits per second, not feasible to transmit 8 bytes :)
Things are overcomplicated because they are retrofitted in already working systems. New and better systems are being designed for the future.
In addition to these measures, can’t the receiver just ignore any signal that’s obviously too strong to be coming from a geosynchronous satellite? Not a cure-all, but an easily-implemented sanity check.
No, because Galileo is also used for positioning of the ISS where due to lack of noise coming from atmospehere any satellite signal is 50-100x stronger than on Earth.
I was obviously referring to receivers down here on Earth, where a suspiciously strong received signal strength would be a red flag. You’re right that it would be stupid to use the same reasoning for a receiver on a space station.
PS: If Thopter is short for ornithopter, that’s a cool name.
gps have problem, now gps have big problem without internet.
You cant use gps without codes .