Research identifies a critical architectural flaw in Galileo’s Open Service Navigation Message Authentication (OSNMA) allowing for signal spoofing via Artificially Manipulated Time Synchronization (ATS). By manipulating a receiver's Local Reference Time (LRT), attackers can align forged signals with the OSNMA Time Synchronization (TS) window, effectively bypassing cryptographic authentication checks. This vulnerability enables three primary attack vectors—TS-compliant Replay (TSR), TS-compliant Forgery (TSF), and TS-compliant Dual-frequency Forgery (TSDF)—affecting both single and dual-frequency receivers. The impact extends to critical timing-dependent infrastructure, autonomous navigation, and maritime systems, undermining the perceived security of the OSNMA framework.
-
Research Overview: The ATS Vulnerability
- Identifies a systemic reliance on accurate time synchronization within the OSNMA authentication process.
- Introduces "Artificially Manipulated Time Synchronization" (ATS) to bypass authentication checks.
- Targets the receiver's Local Reference Time (LRT) to align illegitimate signals with valid temporal windows.
-
Technical Deep Dive: Attack Frameworks
- TS-compliant Replay (TSR): Captures and replays previous E1 signals within a manipulated temporal window to deceive the receiver.
- TS-compliant Forgery (TSF): Generates forged E1 signals utilizing valid, cryptographically signed OSNMA data.
- TS-compliant Dual-frequency Forgery (TSDF): Orchestrates simultaneous forgery of E1 and E5b signals to bypass cross-band authentication.
-
Systemic Impact & Operational Risks
- Successfully bypasses OSNMA authentication in both commercial and open-source GNSS receivers.
- Renders dual-frequency receivers vulnerable, negating the security benefit of cross-band verification.
- Creates high-risk failure points for autonomous vehicles, maritime navigation, and critical timing infrastructure.
-
Defense Implications & Mitigation
- Highlights the failure of current TS check logic to distinguish between legitimate clock drift and malicious manipulation.
- Necessitates a redesign of the OSNMA authentication engine to integrate more robust time-integrity checks.
- Requires chipset manufacturers, such as u-blox, to implement hardware-level defenses against LRT manipulation.
-
Conclusion
- ATS transforms OSNMA from a definitive anti-spoofing solution into a bypassable security layer.
- The ability to spoof dual-frequency signals represents a significant regression in GNSS security assumptions.
Related posts
- arXiv (Computer Science - Cryptography and Security) — Practical Spoofing Attacks against Galileo OSNMA with Time-Synchronization Manipulation
- Scispace
- Themoonlight
- Researchgate
- Amerisurv
- Pmc
- Esa
- U-blox
- Defence-industry-space
- Berthub