A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing

📅 2026-06-23
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of GNSS timing receivers to undetected, significant time errors under slow common-mode spoofing attacks, which conventional RAIM and clock status flags fail to adequately mitigate. The authors propose a conditional Timing Protection Level (TPL) that integrates the static detectability lower bound from a model-agnostic monitor with oscillator holdover error. This work demonstrates, for the first time, that single-clock-assisted monitoring cannot guarantee unconditional timing integrity and instead formulates a closed-form, reproducible TPL reliant on inter-satellite consistency checks. Using L1 pseudorange and broadcast ephemeris to reconstruct clock trajectories and validating with the Kshana simulator, the calibrated TPL yields error budgets of 114 ns and 458 ns under 1-second recovery and 60-second holdover conditions, respectively—three orders of magnitude tighter than actual spoofing-induced errors and substantially outperforming traditional sequential detection methods.
📝 Abstract
A GNSS timing receiver under spoofing has no nominal-geometry fault for position-domain RAIM to bound: the threat is a slow, common-mode pull of served clock time that the receiver's own time-accuracy flag need not reveal. We make three graded contributions. First, a field measurement: solving the receiver clock trajectory from raw L1 pseudoranges and broadcast ephemeris, we show a recorded over-the-air spoof from the public JammerTest 2024 campaign pulled a u-blox ZED-F9P by about 1.01 ms of served time while it reported at most 51 ns, a gap near 20,000x. Second, an impossibility: against an adversary free to choose the ramp rate, no finite unconditional bound on undetected time error exists under a single self-referential clock-aided monitor, because a ramp slow enough to keep the disciplined reference in lock-step is never alarmed while the error grows without limit, so any finite guarantee is conditional. Third, the conditional bound: the Timing Protection Level (TPL), a model-free monitor's static detectability floor plus the oscillator's coast over the detection latency, holds given detection by an independent cross-satellite consistency check a coherent spoofer does not drive in lock-step. Each term is a closed form over a primitive verified in the open Kshana simulator, so the sum is reproducible by hand. Calibrated on the recorded attack, the budget is 114 ns at one-second recovery and 458 ns at a 60-second coast, thousands of times below the 1.01 ms accepted; a clock-aided sequential test alone gives essentially no protection on this slow ramp (it alarms only near the ~1 ms capture), while the model-free monitor alarms during the ramp. We are explicit: the bound is calibrated, not field-validated; carries no integrity-risk budget; and is reported as a band at long coast. The simulator, bound, and calibration example are open source under AGPL-3.0.
Problem

Research questions and friction points this paper is trying to address.

GNSS spoofing
timing integrity
undetected time error
holdover
protection level
Innovation

Methods, ideas, or system contributions that make the work stand out.

Timing Protection Level
GNSS spoofing
undetected time error
model-free monitoring
clock coasting
🔎 Similar Papers
No similar papers found.
C
Chakshu Baweja