🤖 AI Summary
GNSS is vulnerable to time-of-arrival (ToA) spoofing attacks, against which existing cryptographic authentication mechanisms—such as Galileo’s TESLA—offer no protection due to their inability to detect malicious time manipulation. This paper proposes TRICK, the first scheme that jointly leverages low-Earth-orbit (LEO) satellite two-way ranging and multi-source one-way broadcast signals, enforcing verifiable multilateration via ellipsoidal geometric constraints. TRICK closes the ToA manipulation loophole with only a single trusted reference node and minimal communication overhead. It integrates TESLA-enhanced authentication, lightweight integrity verification, and multi-source fusion modeling. We formally prove that TRICK achieves security guarantees equivalent to classical verifiable positioning schemes and reliably detects arbitrary ToA spoofing attacks. Its computational overhead is negligible, and it significantly reduces dependence on ground-based infrastructure.
📝 Abstract
Global Navigation Satellite Systems (GNSS) provide Positioning, Navigation, and Timing (PNT) information to over 4 billion devices worldwide. Despite its pervasive use in safety critical and high precision applications, GNSS remains vulnerable to spoofing attacks. Cryptographic enhancements, such as the use of TESLA protocol in Galileo, to provide navigation message authentication do not mitigate time of arrival manipulations. In this paper, we propose TRICK, a primitive for secure positioning that closes this gap by introducing a fundamentally new approach that only requires two way communications with a single reference node along with multiple broadcast signals. Unlike classical Verifiable Multilateration (VM), which requires establishing two way communication with each reference nodes, our solution relies on only two measurements with a trusted Low Earth Orbiting (LEO) satellite and combines broadcast navigation signals. We rigorously prove that combining the LEO satellite based two way range measurements and multiple one way ranges such as from broadcast signals of GNSS into ellipsoidal constraint restores the same guarantees as offered by VM whilst using minimal infrastructure and message exchanges. Through detailed analysis, we show that our approach reliably detects spoofing attempts while adding negligible computation overhead.