GNSS Spoofing Timing Protection

Arxiv pdf 2026-06-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

A GNSS timing receiver under spoofing has no nominal-geometry fault to bound with position-domain receiver autonomous integrity monitoring: the threat is a slow, commonmode pull of served clock time that the receivers own timeaccuracy flag need not reveal. We make three contributions of graded strength. First, a field measurement: solving the receiver clock-solution trajectory from the raw L1 pseudoranges, the receivers clean dual-band position, and broadcast ephemeris, we show that a recorded over-the-air spoof in the public JammerTest 2024 campaign pulled a survey-grade u-blox ZED-F9P by roughly 1.01 ms of served time while the receiver reported a self-assessed time accuracy of at most 51 ns, a claim-versus-reality gap near $2 \times 10^4$. Second, an impossibility observation: against an adversary free to choose the ramp rate, no finite unconditional bound on undetected time error exists under a single selfreferential clock-aided monitor, because a ramp slow enough to keep the disciplined reference in lock-step (equivalently, below a sequential tests reference value) is never alarmed while the integrated error grows without limit. A finite guarantee is therefore necessarily conditional. Third, the conditional bound itself: the Timing Protection Level (TPL), equal to a modelfree monitors static detectability floor plus the oscillators coast uncertainty over the detection latency, holds given detection by an independent cross-satellite consistency check that a coherent spoofer does not drive in lock-step. Each term is a closed form over a primitive verified separately in the open Kshana simulator, so the sum is reproducible by hand. Calibrated on the recorded attack, the holdover budget is 114 ns at a one-second recovery and 458 ns even at a 60-second coast, between 2200 and 8800 times below the 1.01 ms the receiver silently accepted; on this slow ramp a clock-aided sequential test alone gives essentially no protection (it alarms only after 993 s), whereas the model-free consistency monitor crosses its alarm during the spooers ramp, minutes before the capture. We are explicit about the boundary: the bound is calibrated on real data but not independently validated against ground-truth field error, it carries no aviationstyle integrity-risk budget, and its long-coast value is governed by the oscillators long-tau red-noise floor and is reported as a swept band rather than a single scalar. The simulator, the bound, and the calibration example are open source under AGPL-3.0.

Loading executive summary...

LINK COPIED TO CLIPBOARD