← Back to Daily Briefing

Research identifies a critical architectural flaw in Galileo’s Open Service Navigation Message Authentication (OSNMA) allowing for signal spoofing via Artificially Manipulated Time Synchronization (ATS). By manipulating a receiver's Local Reference Time (LRT), attackers can align forged signals with the OSNMA Time Synchronization (TS) window, effectively bypassing cryptographic authentication checks. This vulnerability enables three primary attack vectors—TS-compliant Replay (TSR), TS-compliant Forgery (TSF), and TS-compliant Dual-frequency Forgery (TSDF)—affecting both single and dual-frequency receivers. The impact extends to critical timing-dependent infrastructure, autonomous navigation, and maritime systems, undermining the perceived security of the OSNMA framework.

  • Research Overview: The ATS Vulnerability

    • Identifies a systemic reliance on accurate time synchronization within the OSNMA authentication process.
    • Introduces "Artificially Manipulated Time Synchronization" (ATS) to bypass authentication checks.
    • Targets the receiver's Local Reference Time (LRT) to align illegitimate signals with valid temporal windows.
  • Technical Deep Dive: Attack Frameworks

    • TS-compliant Replay (TSR): Captures and replays previous E1 signals within a manipulated temporal window to deceive the receiver.
    • TS-compliant Forgery (TSF): Generates forged E1 signals utilizing valid, cryptographically signed OSNMA data.
    • TS-compliant Dual-frequency Forgery (TSDF): Orchestrates simultaneous forgery of E1 and E5b signals to bypass cross-band authentication.
  • Systemic Impact & Operational Risks

    • Successfully bypasses OSNMA authentication in both commercial and open-source GNSS receivers.
    • Renders dual-frequency receivers vulnerable, negating the security benefit of cross-band verification.
    • Creates high-risk failure points for autonomous vehicles, maritime navigation, and critical timing infrastructure.
  • Defense Implications & Mitigation

    • Highlights the failure of current TS check logic to distinguish between legitimate clock drift and malicious manipulation.
    • Necessitates a redesign of the OSNMA authentication engine to integrate more robust time-integrity checks.
    • Requires chipset manufacturers, such as u-blox, to implement hardware-level defenses against LRT manipulation.
  • Conclusion

    • ATS transforms OSNMA from a definitive anti-spoofing solution into a bypassable security layer.
    • The ability to spoof dual-frequency signals represents a significant regression in GNSS security assumptions.

Related posts

  1. arXiv (Computer Science - Cryptography and Security) — Practical Spoofing Attacks against Galileo OSNMA with Time-Synchronization Manipulation
  2. Scispace
  3. Themoonlight
  4. Researchgate
  5. Amerisurv
  6. Pmc
  7. Esa
  8. U-blox
  9. Defence-industry-space
  10. Berthub

LINK COPIED TO CLIPBOARD