Space based authentication utilizing signals from low and medium earth orbit
Abstract
Systems and methods for position-based authentication using Medium Earth Orbit (MEO) and Low Earth Orbit (LEO) satellites are provided. The location of the client device is based on at least one client-received MEO satellite signal received by the client device from at least one MEO satellite and at least one client-received LEO satellite signal received by the client device from at least one LEO satellite. Be authenticated. [Selection diagram] Fig. 1

Term
Projected expiry 12 September 2033.
- Priority
- Filed
- Published
- Today
- Projected expiry
16 claims: 2 independent, 14 dependent
- 1中地球軌道(MEO)衛星および低地球軌道(LEO)衛星を使用する位置ベースの認証のための方法であって、 少なくとも1つのMEO衛星から受信した少なくとも1つのクライアント受信MEO衛星信号のMEO署名期間にわたるサンプルを含むクライアントMEO信号署名を受信することと、 前記少なくとも1つのMEO衛星から受信した少なくとも1つのサーバ受信MEO衛星信号の前記MEO署名期間にわたるサンプルを含むサーバMEO信号署名を形成することと、 前記クライアントMEO信号署名と前記サーバMEO信号署名とを比較してMEO比較結果を提供することと、 少なくとも1つのLEO衛星から受信した少なくとも1つのクライアント受信LEO衛星信号のLEO署名期間にわたるサンプルを含むクライアントLEO信号署名を受信することと、 前記少なくとも1つのLEO衛星の少なくとも1つのサーバLEO衛星信号の前記LEO署名期間にわたるサンプルを含むサーバLEO信号署名を形成することと、 前記クライアントLEO信号署名と前記サーバLEO信号署名とを比較してLEO比較結果を提供することと、 前記MEO比較結果および前記LEO比較結果に基づいてクライアント装置がある位置を認証すること、とを含む方法。
- 2サーバ装置で前記MEO比較結果および前記LEO比較結果を評価することと、 ホスト装置で前記クライアント装置の位置を認証すること、とをさらに含む、請求項1に記載の方法。
- 3前記少なくとも1つのMEO衛星からサーバ装置で前記少なくとも1つのサーバ受信MEO衛星信号を受信することと、 前記サーバ装置で前記少なくとも1つのクライアント受信LEO衛星信号のレプリカを形成して、前記少なくとも1つのサーバLEO衛星信号を提供すること、とをさらに含む、請求項1に記載の方法。
- 4前記少なくとも1つのMEO衛星から前記少なくとも1つのクライアント受信MEO衛星信号を前記クライアント装置で受信することと、 前記少なくとも1つのLEO衛星から前記少なくとも1つのクライアント受信LEO衛星信号を前記クライアント装置で受信すること、とをさらに含む、請求項1に記載の方法。
- 5前記少なくとも1つのクライアント受信MEO衛星信号の前記MEO署名期間にわたるサンプルを含む前記クライアントMEO信号署名を形成することと、 前記少なくとも1つのクライアント受信LEO衛星信号の前記LEO署名期間にわたるサンプルを含む前記クライアントLEO信号署名を形成すること、とをさらに含む、請求項1に記載の方法。
- 62つのLEO衛星から受信した2つのクライアント受信LEO衛星信号の前記LEO署名期間にわたるサンプルを含む前記クライアントLEO信号署名を受信することと、 前記2つのLEO衛星から受信した2つのサーバLEO衛星信号の前記LEO署名期間にわたるサンプルを含む前記サーバLEO信号署名を形成すること、とをさらに含む、請求項1に記載の方法。
- 7少なくとも1つの地上発信源から受信した少なくとも1つのクライアント受信地上信号の地上期間にわたるサンプルを含むクライアント地上信号署名を受信することと、 サーバ装置で少なくとも1つのクライアント受信地上信号のレプリカを形成してサーバ地上信号署名を提供することと、 前記クライアント地上信号署名と前記サーバ地上信号署名とを比較して地上比較結果を提供すること、とをさらに含む、請求項1に記載の方法。
- 8前記MEO比較結果、前記LEO比較結果、および前記地上比較結果に基づいてクライアント装置の位置を認証することをさらに含む、請求項7に記載の方法。
- 9前記クライアントMEO信号署名、前記クライアントLEO信号署名、および前記地上信号署名をサーバに送信することをさらに含む、請求項7に記載の方法。
- 10中地球軌道(MEO)衛星および低地球軌道(LEO)衛星を使用する位置ベースの認証システムであって、 少なくとも1つのMEO衛星からクライアント装置で受信した少なくとも1つのクライアント受信MEO衛星信号、および少なくとも1つのLEO衛星から前記クライアント装置で受信した少なくとも1つのクライアント受信LEO衛星信号に基づいて、前記クライアント装置がある位置を認証するように動作可能な認証モジュールを備えたシステム。
- 11少なくとも1つのMEO衛星から受信した少なくとも1つのクライアント受信MEO衛星信号のMEO署名期間にわたるサンプルを含むクライアントMEO信号署名を受信し、かつ 少なくとも1つのLEO衛星から受信した少なくとも1つのクライアント受信LEO衛星信号のLEO署名期間にわたるサンプルを含むクライアントLEO信号署名を受信する、ように動作可能なサーバクライアントデータモジュールと、 前記少なくとも1つのMEO衛星から受信した少なくとも1つのサーバ受信MEO衛星信号の前記MEO署名期間にわたるサンプルを含むサーバMEO信号署名を形成し、かつ 前記少なくとも1つのLEO衛星の少なくとも1つのサーバLEO衛星信号の前記LEO署名期間にわたるサンプルを含むサーバLEO信号署名を形成する、ように動作可能なサーバデータモジュールと、 前記クライアントMEO信号署名と前記サーバMEO信号署名とを比較してMEO比較結果を提供し、かつ 前記クライアントLEO信号署名と前記サーバLEO信号署名とを比較してLEO比較結果を提供する、ように動作可能な比較モジュールと、をさらに備えた、請求項10に記載のシステム。
- 12サーバ装置は前記比較モジュールを含み、 ホスト装置は前記認証モジュールを含む、請求項11に記載のシステム。
- 13前記認証モジュールはさらに、前記MEO比較結果および前記LEO比較結果に基づいて前記クライアント装置の位置を認証するように動作可能である、請求項11に記載のシステム。
- 14前記クライアントデータモジュールはさらに、少なくとも1つの地上発信源から受信した少なくとも1つのクライアント受信地上信号のクライアント地上時間ウィンドウを含むクライアント地上信号署名を受信するように動作可能であり、 前記サーバデータモジュールはさらに、前記少なくとも1つの地上発信源から受信した少なくとも1つのサーバ受信地上信号のサーバ地上時間ウィンドウを含むサーバ地上信号署名を形成するように動作可能であり、 前記比較モジュールはさらに、前記クライアント地上信号署名と前記サーバ地上信号署名とを比較して地上比較結果を提供するように動作可能であり、かつ 前記認証モジュールはさらに、前記MEO比較結果、前記LEO比較結果、および前記地上比較結果に基づいてクライアント装置の位置を認証するように動作可能である、請求項13に記載のシステム。
- 15少なくとも1つのクライアント受信MEO衛星信号のMEO署名期間にわたるサンプルを含む前記クライアントMEO信号署名を形成し、かつ 少なくとも1つのクライアント受信LEO衛星信号のLEO署名期間にわたるサンプルを含む前記クライアントLEO信号署名を形成する、ように構成されたクライアント署名モジュールをさらに備えた、請求項11に記載のシステム。
- 16前記少なくとも1つのクライアント受信LEO衛星信号は、2つのLEO衛星から受信した2つのクライアント受信LEO衛星信号を含み、 前記少なくとも1つのサーバLEO衛星信号は、前記2つのLEO衛星の2つのサーバLEO衛星信号を含む、請求項11に記載のシステム。
Independent claims16
154 paragraphs, as filed
The embodiments of the present disclosure generally relate to cyber and network security. More specifically, embodiments of the present disclosure relate to satellite systems for position-based authentication.
A significant portion of the power of satellite signals, such as Global Navigation Satellite System (GNSS) signals, can be lost in urban and indoor environments where satellite signals are frequently blocked. Blocking satellite signals diminishes coverage in urban and indoor environments, and power loss reduces performance in low signal-to-noise ratio (SNR) environments. Poor performance in low signal-to-noise environments can reduce or minimize the ability of authentication systems to verify the authenticity of position calculations or position-based assertions.
Systems and methods for position-based authentication using Medium Earth Orbit (MEO) and Low Earth Orbit (LEO) satellites are provided. At least one client-received MEO satellite signal received by the client device from at least one MEO satellite and at least one client-received LEO received by the client device from at least one LEO satellite that the client device may be in a location. Estimate based on satellite signals. Receives a client MEO signal signature containing a sample over the MEO signature period of the signal received from the MEO satellite. Form a server MEO signal signature, including a sample of the signal received from the MEO satellite over the MEO signature period. Receives a client LEO signal signature containing a sample over the LEO signature period of the signal received from the LEO satellite. Form a server LEO signal signature containing a sample over the LEO signature period of the LEO satellite signal. The location of the client device is authenticated based on a comparison between the client MEO signal signature and the server MEO signal signature, and a comparison between the client LEO signal signature and the server LEO signal signature.
In this way, the disclosed embodiments provide protection against spoofing and counterfeiting such as melee and offshore attacks, as well as strong coverage in urban and indoor environments where satellite signals are frequently blocked.
In one embodiment, a position-based authentication method using Medium Earth Orbit (MEO) and Low Earth Orbit (LEO) satellites includes a client MEO signal that includes a sample of the client received MEO satellite signal received from the MEO satellite over the MEO signature period. Receive the signature. The method also forms a server MEO signal signature that includes a sample of the server-received MEO satellite signal received from the MEO satellite over the MEO signature period. The method further compares the client MEO signal signature with the server MEO signal signature to provide the MEO comparison result. The method also receives a client LEO signal signature that includes a sample of the client-received LEO satellite signal received from the LEO satellite over the LEO signature period. The method also forms a server LEO signal signature that includes a sample of at least one server LEO satellite signal received from the LEO satellite over the LEO signature period. The method further compares the client LEO signal signature with the server LEO signal signature to provide the LEO comparison result. In this method, the position of the client device is further authenticated based on the MEO comparison result and the LEO comparison result.
In another embodiment, a position-based authentication system using Medium Earth Orbit (MEO) and Low Earth Orbit (LEO) satellites is a client-received MEO satellite signal received from the MEO satellite on the client device and from the LEO satellite on the client device. Includes an authentication module that authenticates that the client device is in a location based on the received client-received LEO satellite signal.
In a further embodiment, the non-temporary computer-readable storage medium is a computer executable instruction for client location-based authentication that receives the MEO satellite signal from the MEO satellite at the client device and provides the client-received MEO satellite signal. including. The computer executable instruction also receives the LEO satellite signal from the LEO satellite on the client device to provide the client received LEO satellite signal. The computer executable instruction also forms a client MEO signal signature containing a sample over the MEO signature period of the client received MEO satellite signal. The computer executable instruction further forms a client LEO signal signature containing a sample over the LEO signature period of the client received LEO satellite signal. The computer executable instruction also sends a client MEO signal signature, a client LEO signal signature, a sample over the MEO signature period, and a sample over the LEO signature period to the server for location authentication of the client device.
This overview is presented in a simplified form to provide an excerpt of a concept that will be further detailed in the detailed description below. This summary is not intended to identify the key or essential features of the claim, nor is it intended to be used as an aid in determining the scope of the claims.
The embodiments of the present disclosure will be better understood by reference to the detailed description and claims when considered in the light of the following figures. The same reference number refers to similar elements throughout the figure. The figures are provided to facilitate understanding of the disclosure without limiting the breadth, scope, scale, or applicability of the disclosure. Drawings are not always drawn to a certain scale.
<figref num="1">It is a figure which represents the exemplary wireless communication system for authenticating the assert position which concerns on embodiment of the disclosure.</figref><figref num="2">Shown is an exemplary simplified function block diagram of a navigation satellite receiver.</figref><figref num="3">FIG. 5 illustrates an exemplary wireless communication environment showing how navigation satellite signals can be blocked in indoor and urban environments.</figref><figref num="4">Represents an exemplary schematic showing the signal structure of a medium earth orbit (MEO) navigation satellite.</figref><figref num="5">Shows an exemplary schematic showing the line-of-sight vectors of MEO satellites (GPS) and Low Earth orbit (LEO) satellites (Iridium ) over the city.</figref><figref num="6">Shown is an exemplary schematic showing an authentication system based on signals from MEO, LEO, and terrestrial sources according to an embodiment of the disclosure.</figref><figref num="7">Represents an exemplary schematic showing an antenna beam within one Iridium satellite footprint.</figref><figref num="8">Signal-to-noise ratio (C / N) of four antenna beams from the Iridium satellite over time<sub>0</sub>) Is shown as an exemplary chart.</figref><figref num="9">Represents an exemplary schematic showing a melee signature forgery attack that can be performed by a signature forger.</figref><figref num="10">Shown is an exemplary schematic showing the prevention of a melee signature forgery attack using MEO satellite signals according to an embodiment of the disclosure.</figref><figref num="11">Represents an exemplary functional block diagram of an offshore signature counterfeiting attack simulation system that can be performed by a signature counterfeiter.</figref><figref num="12">FIG. 10 shows an exemplary functional block diagram of the offshore signature forgery simulation system shown in FIG. 10, showing how to use LEO satellite signals to thwart offshore signature forgery attacks according to a disclosed embodiment.</figref><figref num="13">Shown is an exemplary functional block diagram of a hybrid attack signature forgery simulation system based on proximity signal capture and offshore processing that can be performed by a signature forger.</figref><figref num="14">It is a figure which shows the exemplary functional block diagram of the space-based authentication system which concerns on embodiment of disclosure.</figref><figref num="15">It is a figure which represents the exemplary flowchart which shows the client position-based authentication process which concerns on embodiment of disclosure.</figref><figref num="15A">It is a figure which represents the exemplary flowchart which shows the client position-based authentication process which concerns on embodiment of disclosure.</figref><figref num="15B">It is a figure which represents the exemplary flowchart which shows the client position-based authentication process which concerns on embodiment of disclosure.</figref><figref num="16">It is a figure which represents the exemplary flowchart which shows the client position-based authentication process which concerns on embodiment of disclosure.</figref>
The following detailed description is of an exemplary nature and is not intended to limit the use and use of the disclosures or embodiments of the present application. Descriptions of specific devices, techniques, and applications are provided by way of example only. Modifications of the examples described herein will be readily apparent to those skilled in the art. The general principles defined herein can be applied to other examples and uses without departing from the spirit and scope of the disclosure. Moreover, it is not intended to be limited by any theory expressed or suggested in the aforementioned technical fields, background techniques, outlines, or detailed description below. The present disclosure should be given a scope consistent with the claims and should not be limited to the examples described and illustrated herein.
Disclosure embodiments are described herein in terms of functional and / or logical block components as well as various processing steps. It should be understood that such block components can be implemented by any number of hardware, software, and / or firmware components that are configured to perform a particular function. For brevity, prior art and components related to communication systems, network protocols, global positioning systems, satellites, and other functional aspects of the system (as well as the individual operating components of the system) are described herein. Not detailed.
Disclosure embodiments are described herein in the context of authentication systems for non-limiting applications, ie cellphone applications. However, the disclosed embodiments are not limited to such cellphone applications, and the techniques described herein can also be used for other applications. For example, embodiments are desktop computers, laptop or notebook computers, iPod , iPad , cell phones, personal digital assistants (PDAs), mainframes that are desirable or suitable for a given application or environment. , Servers, routers, Internet Protocol (IP) nodes, servers, Wi-Fi nodes, clients, or any other type of dedicated or general purpose computing device.
As will be apparent to those skilled in the art by reading this description, the following are embodiments and embodiments disclosed, and are not limited to operations according to these embodiments. Other embodiments may be used and modifications may be made without departing from the scope of the exemplary embodiments of the present disclosure.
An embodiment of the disclosure provides an authentication system for satellite signals received by a client device (client) that may be located in a low signal-to-noise ratio (SNR) environment, such as indoors in an urban building. , It provides sufficient received signal strength. In one embodiment, signals from low earth orbit (LEO) satellites are combined with signals from medium earth orbit (MEO) satellites. In another embodiment, the MEO and / or LEO satellite signal is augmented by a coded signal from a terrestrial source.
By combining the LEO and MEO signals, the embodiment prevents attempts to forge digital signatures from clients. Two examples of attack strategies used by counterfeiters are the proximate attack and the offshore attack. Compared to existing solutions, the disclosed embodiments significantly increase the cost and complexity of counterfeit attacks, resulting in a more secure authentication system. As an example, according to the disclosed embodiments, a melee attacker is forced to deploy an attack receiver within tens of meters of the victim's location. As another example, according to a disclosed embodiment, an offshore attacker is forced to deploy a complex receiver within tens of kilometers (or hundreds of meters) of the victim's location.
Further, the embodiment requires that the digital signature include a code from two overlapping antenna beams. By doing so, according to the embodiment, the offshore attacker is forced to exist within tens of kilometers from the victim's location. For high-value transactions, the authentication server may require that the second signature be obtained when the two beams overlap on the assert position. Such an overlapping situation can occur within tens of seconds.
In other embodiments, a terrestrial source of security / secret signature is used with MEO and LEO satellite signals. Terrestrial transmitter coverage The terrestrial antenna footprint can be very small (hundreds of meters), forcing the attack receiver to be very close to the victim's location.
FIG. 1 is a diagram illustrating an exemplary wireless communication system 100 (system 100) for authenticating an assert position based on a satellite signal, according to an embodiment of the disclosure. System 100 includes MEO satellites 102, 104, and 106 orbiting Medium Earth orbit (MEO) 108, LEO satellites 110, 112, and 114 orbiting Low Earth orbit (LEO) 116, and optional terrestrial broadcasting stations 122 (ground). It may include a source 122), a client 126 including a satellite receiver 200, an authentication server 128 including a satellite receiver 200, and a host network 194.
In one embodiment, the MEO satellite signal 118 from at least one of the MEO satellites 102, 104, and 106 in MEO 108 is combined with the LEO satellite signal 120 from at least one of the LEO satellites 110, 112, and 114 in LEO 116. Will be done.
In another embodiment, the MEO satellite signal 118 from at least one of the MEO satellites 102-106 in MEO 108 and the LEO satellite signal 120 from at least one of the LEO satellites 110-114 in LEO 116 are from the ground source 122. Enhanced by the coded ground signal 160 of.
LEO satellites 110-114 may include, for example, Iridium , Iridium NEXT, Global Star constellations satellites, or other satellites available for position, navigation, or timing related applications. , Not limited to them.
MEO satellites 102-106 are, for example, Global Navigation Satellite System (GNSS) satellites, Global Positioning System (GPS ) satellites, Globalnaya Navigatsionnaya Sputnikovaya Sistema (GLONASS ) satellites, BeiDou Navigation System (COMPASS ) satellites. ) Satellites, Galileo satellites, or other satellites available for position, navigation, or timing related applications, but not limited to them.
The terrestrial source 122 may include a cellphone base station, a wireless or wired access point, or other terrestrial source.
By processing the MEO satellite signal 118 from the MEO satellite 102 by the client receiver module 200 of the client 126, the position 130, speed, and time of the client 126 can be determined. By processing the LEO satellite signal 120 from the LEO satellite 110 (eg, Transit satellite navigation), it is also possible to generate estimates of client 126 position 130, velocity, and time.
Position 130 of client 126 is estimated using measurements available based on MEO satellite signals 118 from at least one of MEO satellites 102-106 and LEO satellite signals 120 from at least one of LEO satellites 110-114. be able to. The estimation of position 130 is based on the smallest set of signal sources. System 100 applies to similar systems with a small number of MEO satellites as well as a small number of LEO satellites, with or without a high quality user clock. Position 130 can be estimated, for example, based on the smallest set of signal sources, by using any suitable mathematical method.
System 100 enables space-based authentication indoors and in downtown areas. System 100 is configured to work with a small set of visible satellites. One MEO satellite 102 and one LEO satellite 110 are sufficient. If one MEO satellite 102 and one LEO satellite 110 are visible, if the third dimension (eg altitude) is known and the user equipment has a sufficiently accurate clock, the system 100 will It is possible to instantly estimate and authenticate the two-dimensional position.
The client 126 (client device 126) may include a satellite receiver 200 (client receiver module 200) and a client signature module 170. The client 126 is configured to track and locate the client 126 based on receiving at least one of the MEO satellite signal 118 and / or the LEO satellite signal 120 via the client antenna 198 as described above. ing.
The client receiver module 200 is configured to supply at least one client-received MEO satellite signal 146 by receiving at least one MEO satellite signal 118 from at least one MEO satellite 102 on the client 126. The client receiver module 200 is also configured to supply at least one client-received terrestrial signal 162 by receiving at least one terrestrial signal 160 from at least one terrestrial source 122 on the client device 126. The client receiver module 200 is also configured to supply at least one client-received LEO satellite signal 158 by receiving at least one LEO satellite signal 120 from at least one LEO satellite 110 on the client device 126. ..
The client signature module 170 is configured to form a client MEO signal signature 164, including a sample of at least one client received MEO satellite signal 146 over the MEO signature period. The client signature module 170 is also configured to form a client LEO signal signature 166, including a sample of at least one client received LEO satellite signal 158 over the LEO signature period. The client signature module 170 also has a client terrestrial time of at least one client received terrestrial signal 162. It is configured to form a client ground signal signature 168, including window). The client-received MEO satellite signal 146, the client-received LEO satellite signal 158, and the client-received terrestrial signal 162 are collectively referred to herein as client-received signals 146, 158, 162. Also, the client MEO signal signature 164, the client LEO signal signature 166, and the client ground signal signature 168 may be collectively referred to herein as the signature signal 164, 166, 168, client signature set 190, or location signature 190. is there.
The data transmission of the client ground signal signature 168 from the client device 126 to the authentication server 128 can be sent with a single broadband signature from the client or in multiple separate data packets. At least one terrestrial source 122 can also send single or multiple data transmissions to the authentication server 128.
Client 126 can support many consumer applications. For example, many financial transactions use cellphones as clients 126 indoors in urban buildings. Client 126 includes, for example, but not limited to, desktop computers, laptop or notebook computers, iPod , iPad , cell phones, personal digital assistants (PDAs), mainframes, servers, routers, the Internet. Any other type desirable and suitable for a given application or environment, with a protocol (IP) node, server, Wi-Fi node, or satellite receiver 200 capable of receiving client-received MEO satellite signals 146. It may include wired or wireless communication devices such as dedicated or general purpose computing devices.
Authentication server 128 is configured to receive or estimate signature signals 164, 166, and 168 (client signature set 190) for location 130. The authentication server 128 can receive the client signature set 190 via the wired communication link 136, the wireless communication channel 138, and a combination thereof, or the authentication server 128 can estimate the client signature set on the spot. The authentication server 128 may include a satellite receiver 200 (server receiver module 200), a server client data module 172, a server data module 174, a correlation module 152, and an authentication module 154.
The server receiver module 200 can also be configured to supply at least one server-received MEO satellite signal 156 by receiving at least one MEO satellite signal 118 at the authentication server 128 (server device 128). The server receiver module 200 is also configured to supply at least one server LEO satellite signal 148 by receiving at least one LEO satellite signal 120 at the server device 128. The server receiver module 200 can also be configured to supply at least one server-received terrestrial signal 196 by receiving at least one terrestrial signal 160 at the server device 128. The server LEO satellite signal 148, the server reception MEO satellite signal 156, and the server reception ground signal 196 are collectively referred to herein as server reception signals 148, 156, 196.
The client-received LEO satellite signal 158 may include two client-received LEO satellite signals received from two of the LEO satellites 110 and 112 (eg, overlapping region 712 in FIG. 7). The server LEO satellite signal 148 may include two server-received LEO satellite signals from two of the LEO satellites 110 and 112 (eg, overlapping region 712 in FIG. 7).
The server-client data module 172 is configured to receive client MEO signal signature 164, including a sample of at least one client-received MEO satellite signal 146 received from at least one of MEO satellites 102-106 over the MEO signature period. There is. The server-client data module 172 is also configured to receive a client-client LEO signal signature 166, including a sample of at least one client-received LEO satellite signal 158 received from at least one LEO satellite 110 over the LEO signature period. The server-client data module 172 can also be configured to receive a signal signature 168 containing a time window of at least one client-received terrestrial signal 162 received from at least one terrestrial source 122.
The server data module 174 is configured to form a server MEO signal signature 176, including a sample of at least one server received MEO satellite signal 156 received from at least one MEO satellite 102 over the MEO signature period. The server data module 174 is also configured to form a server LEO signal signature 178, which includes a sample of at least one server LEO satellite signal 148 of at least one LEO satellite 110 over the LEO signature period. At least one server LEO satellite signal 148 can be transmitted to and received from at least one LEO satellite 110. The server data module 174 can also be configured to form a server ground signal signature 180 that includes a client ground time window of at least one server received ground signal 196 received from at least one ground source 122. The server data module 174 can operate to function with different types of satellite signals (eg, from iridium-LEO, MEO satellites, etc.) and can use different numbers of server data modules 174. For example, there may be a separate server data module 174 for each received signal type.
Correlation module 152 (comparison module 152) is configured to provide MEO comparison result 182 by comparing client MEO signal signature 164 with server MEO signal signature 176. Correlation module 152 is also configured to provide LEO comparison result 184 by comparing client LEO signal signature 166 with server LEO signal signature 178. In one embodiment, the correlation module 152 can also be configured to provide a ground comparison result 186 by comparing the client ground signal signature 168 with the server ground signal signature 180.
The authentication module 154 is configured to authenticate the position 130 of the client device 126 based on the MEO comparison result 182 and the LEO comparison result 184. In one embodiment, the authentication module 154 is configured to authenticate position 130 of client device 126 based on MEO comparison result 182, LEO comparison result 184, and ground comparison result 186. The authentication module 154 is also configured to generate an authentication message 124 indicating an authentication decision. In at least one embodiment, the authentication module 154 is configured to generate an authentication message 124 that can be used by another module to make an authentication decision and helps to perform appropriate actions related to the decision. You may. Such processing includes, for example, allowing, but not limiting, the client device 126 to access the protected resource, and denying the client device 126 access to the protected resource. Can be included.
In at least one embodiment, the authentication module 154 used to perform the authentication is part of the same authentication system 100. In at least one other embodiment, for example, if the authentication service is provided to the host network 194, the authentication module 154 used to perform the authentication is part of the host network 194 separate from the authentication server 128. ..
Host network 194 may include, but is not limited to, for example, banks, e-commerce systems, financial institutions, or other systems. For example, the authentication response in host network 194 is responsible for management policies such as the authentication decision policy. The authentication response may include location estimation and covariance, and the host network 194 should use its decision policy to determine whether the client device 126 is within a predetermined threshold for authentication or to refuse authentication. Decide whether or not. Host network 194 may also take into account other authentication / authorization information before allowing / restricting access to protected resources.
An attacker may attempt to spoof a satellite signal so that client 126 detects and / or reports a false position 132. Spoofing is a common concern as networked systems are increasingly being used to support location transactions that have monetary value or are life-threatening. Is becoming.
System 100 utilizes security / secret codes transmitted by LEO satellites 110-114, MEO satellites 102-106, and terrestrial sources 122, as described in more detail below in connection with FIGS. 4 and 6. By doing so, it prevents attempts to impersonate the signature set from client 126. In this way, System 100 fends off clever attempts to spoof signature sets in melee and offshore attacks. The term security / secret code may be used herein to refer to the code used to make information selectively accessible.
Compared to existing systems, System 100 improves coverage indoors and in downtown areas. This is because the authentication message 124 can be created based on one LEO satellite signal and one MEO satellite signal, as described in more detail below in connection with FIG.
Many financial transactions utilize mobile devices such as cell phones and laptops, such as Client 126, indoors or in the city centre. Such financial transactions may take place on platforms that are low cost and operate in a jamming environment. To design such a cost-effective satellite-based authentication system, it is important to meet two criteria. First, the data must be available from the satellite receiver 200 included in the cellphone. Second, satellite-based authentication systems must operate with expected client reception signals 146, 158, and 168 in places where cellphone users gather, namely indoors and in downtown areas. The first criterion is reflected in FIG. 2, which shows the basic signal processing steps in the satellite receiver 200. The second criterion for satellite-based authentication systems is shown in Figure 3.
FIG. 2 is an exemplary simplified functional block diagram of the satellite receiver 200 shown in FIG. The satellite receiver 200 may include satellite receiver elements that are widely used to estimate position from global navigation satellite systems. The satellite receiver 200 shown in FIG. 1 can utilize the existing infrastructure and receiver by utilizing the existing satellite receiver architecture, and therefore does not significantly increase the complexity of the receiver. .. Satellite receiver 200 may include, but is not limited to, for example, LEO satellite receivers, MEO satellite receivers, or other receivers. FIG. 2 is an exemplary simplified functional block diagram of a satellite receiver widely used to estimate position from a global navigation satellite system. The satellite receiver 200 shown in FIG. 1 largely utilizes the architecture of the satellite receiver with almost no complexity of the receiver shown in FIG.
As shown in FIG. 2, the satellite receiver 200 (client receiver module 200) receives radio frequency signals such as the client reception MEO satellite signal 146 and the client reception LEO satellite signal 158 at the client antenna 198. The satellite receiver 200 then demodulates the client-received MEO satellite signal 146 and the client-received LEO satellite signal 158 from the MEO satellite signal 118 and the LEO satellite signal 120 received by the client 126, respectively. The satellite receiver 200 down-converts the client-received MEO satellite signal 146 and the client-received LEO satellite signal 158 from the radio frequency (RF) to the intermediate frequency (IF) or the baseband by the down converter 202, and the down-converted client reception. The client-received MEO satellite signal 146 and the client-received LEO satellite signal 158 are demodulated by bandpass-filtering the signal 218 with the bandpass filter 204.
The satellite receiver 200 then supplies the digital client receive signal 222 by converting the low frequency pass or bandpass filtered client receive signal 220 from an analog signal to a digital signal by an analog-to-digital converter (ADC) 206. .. The satellite receiver 200 then removes the C / A code from the digital client received signal 222 by means of a code wipe off 210. The satellite receiver 200 may then remove the common mode carrier 402 from the digital client received signal 222 by means of carrier wipe-off 212. Code and carrier wipeoffs are commonly used in consumer receivers similar to those in FIG. 2, but code and carrier wipeoffs may or may not be performed in receiver 200.
The satellite receiver 200 then uses a correlation module 214 to correlate the digital client receive signal 222 with each replica of the digital client receive signal 222 in the client 126 to provide a pseudo distance for each satellite in the field of view. To estimate. The estimated pseudo-distance of each satellite in the field of view is then used to estimate the position 130, velocity, and time offset of client 126 at output 216. The position 130 can be calculated using one LEO satellite and one MEO satellite as described above.
FIG. 3 is a diagram illustrating an exemplary wireless communication environment (environment 300) showing how indoor and urban environments can block navigation satellite signals. The nominal received signal strength 304 of the received GPS signal can be, for example, about -130 dBm (or 10E-16 watts). The outdoor satellite receiver 200 can expect this nominal received signal strength of 304. However, a client 126, such as a cellphone, may operate indoors in an urban building, where the attenuated received signal strength 302 drops to -140 dBm or -160 dBm, or even weaker. Therefore, the authentication server 128 can operate with these low levels of attenuated received signal strength 302.
FIG. 4 shows an exemplary schematic 400 showing a signal structure 400 transmitted by the MEO satellite. The MEO satellite signal 118 includes a frequency L1 signal 402, which is modulated by a code division multiple access (CDMA) code 406, commonly referred to as a "Coarse / Acquisition" (C / A) code. Used as a carrier (in-phase carrier 402) to modulate the navigation message 410. For GPS systems, C / A codes are known in various forms as "coarse / capture", "Clear / Access", and "Civil / Access". The MEO satellite signal 118 transmits at least one other signal (orthogonal signal 406) that uses the same carrier frequency shifted 90 degrees. For GPS, quadrature signal) 404 is modulated by another code known as encryption "P (Y)" code 408. The P (Y) code 408 is either a publicly known "high precision" (P) code (known (P) code) or an encrypted "Y" code (unknown Y code). The GNSS satellite uses an unknown code, and therefore the resulting transmitted signal encoded by the unknown code can only be used by those who have the decoding algorithm and key for the unknown code.
Navigation message 410 modulates both known and unknown codes transmitted by MEO satellites 102-106. Navigation message 410 includes information such as the position and time of MEO satellite 102, the coarse position of other MEO satellites 104, 106, and other information. Navigation message 410 modulates both known and unknown codes transmitted, for example, by MEO satellite 102 via MEO satellite signal 118. In the case of GNSS, the navigation message 410 is transmitted at 50-1000 bits per second (bps) and is therefore distinguished from the spectral diffusion code that also modulates the MEO satellite signal 118 from the MEO satellite 102. Compared to the underlying spectral diffusion code of 1.023 Mcps (C / A code) or 10.023 Mcps (Y code), the navigation message 410 changes slowly at 50-1000 bits per second.
The C / A code is publicly known and therefore the satellite receiver 200 is exposed to spoofing signals. Hostile parties can generate duplicates of one or more satellite signals that carry fraudulent information. The existing satellite receiver of the existing client that accepts the spoofing signal may calculate the incorrect position, and the hostile party may actually calculate the position that the existing satellite receiver is trying to calculate. is there.
FIG. 5 is an exemplary schematic showing the line-of-sight vector 500 of MEO satellites 102-106 (eg GPS) and LEO satellites 110-114 (eg Iridium ) over the city. As explained above, compared to existing solutions, System 100 can make authenticity checks based on only one LEO satellite and one MEO satellite, resulting in better indoor and downtown Bring coverage. FIG. 5 shows the line-of-sight vector 502 from 11 GPS satellites of MEO108 and the line-of-sight vector 504 from 2 LEO satellites of LEO116. Since the Iridium satellite travels large in the airspace, for example in a window of about 200 seconds, as shown in Figure 5, the line-of-sight vector 504 from the LEO satellite signals 120 of the two LEO satellites 110 and 112 is shown as a sector. ..
Since the LEO satellite signal 120 has a much lower altitude than the MEO satellite signal 118, one of the line-of-sight vectors 504 from the two LEO satellites 110 and 112 is the client. It is likely to be captured by 126. The received signal strength from the LEO satellites 110 and 112 is, for example, about 30 to 40 dB stronger than the received signal strength from the MEO satellites 102 to 106.
In addition, since there are many navigation satellites in MEO108, at least one of the 11 line-of-sight vectors 502 from MEO108 can be captured by client 126. One or more of the MEO satellites 102-106 will be captured through the windows of the building. In addition, one or more MEO satellite signals 118 of MEO satellites 102-106 may be strong enough to propagate through walls or roofs.
Compared to existing systems, System 100 significantly improves indoor and downtown coverage for space-based certification. In addition, System 100 allows the use of security / secret signatures sent by terrestrial source 122, which can further enhance the authentication process in harsh signaling environments.
In addition, the security / secret code from either MEO or LEO is not known in advance, so System 100 can thwart attempts to forge signature set 190 from client 126. In addition, System 100 is also effective against attackers who simultaneously observe security / secret code and attempt to send altered fake in real time. Two real-time attack strategies that counterfeiters can use, namely melee and offshore attacks, are considered herein as described in more detail below.
For melee attacks, place the receiver near the victim's location. Melee attacks may not require expensive equipment, but the attack receiver must be close to the victim's location so that the attack receiver can capture virtually the same signal signature. System 100 can thwart melee attacks by utilizing precision ranging signals, such as precision ranging signals typically transmitted from the MEO108 GNSS satellite. The precision ranging signal provides an instantaneous accuracy of about 10 meters. Therefore, the use of high-precision ranging signals forces the attack receiver to be very close to the victim's location, according to the disclosed embodiments. At short distances, the attack receiver is noticeable and is substantially easier to detect than at long distances.
Counterfeiters may also attempt so-called offshore attacks in real time or near real time. In this case, the attacker processes the received signal to create a digital signature that should be received at a remote location. Offshore attacks differ from melee attacks because attackers use more complex signal processing to reduce the number of melee attack receivers. System 100 launches offshore attacks by utilizing the LEO satellite signal 120, which has a smaller (smaller) ground antenna footprint 702 (antenna beam footprint 702) (Figure 7) than the antenna footprint of the MEO satellite. Stop. For example, the Iridium satellite has an antenna footprint of only a few hundred kilometers and has a unique security / secret code 602 (Figure 6) for each of the smaller ground antenna footprint 702 (antenna beam footprint 702). Can be used. Therefore, offshore attackers are forced to be within the diameter range of the small ground antenna footprint 702. Further, in one embodiment, the signature may be required to include security / secret code 602 from two overlapping small ground antenna footprints 702 (FIG. 7).
FIG. 6 is an exemplary schematic showing an authentication system based on signals from MEO, LEO, and terrestrial sources according to an embodiment of the disclosure. System 600 utilizes security / secret codes (eg, satellite beam-specific keys and pseudo-satellite ground keys) transmitted by LEO satellite 110 and MEO satellite 102 as well as ground source 122.
MEO measurements are authenticated by a security / secret code 408 (eg, Y or M code in GPS, or Public Regulated Service in Galileo) that is relevant to most global navigation satellite systems. Client 126 collects a radio frequency or intermediate frequency (RF or IF) signature (client MEO signal signature 164) and sends this signature to authentication server 128. This signature can be accompanied by an assert position at position 130 and / or an associated request. Authentication server 128 correlates these snapshots with the security / secret code received elsewhere. Authentication server 128 verifies that the security / secret code 408 in the client signature set 190 has the correct time delay with respect to the public code 406. Instead, the authentication server 128 determines that the position 130 of the client 126 based on the client signature set 190 is approximately equal to the asserted client position.
As shown in Figure 6, LEO satellite 110 also transmits security / secret code 602. Again, client 126 collects RF and / or IF snapshots (client LEO signal signature 166) and sends them to authentication server 128 for correlation and verification. In one embodiment, the MEO security / secret code 408 and the LEO security / secret code 602 are contained in a single broadband signature, such as signature set 190 from client 126.
In one embodiment, security / secret code 604 from server ground signal 196 of ground source 122 is used. These security / secret codes 604 are especially important in a signal environment that blocks satellite signals and where offshore attacks are likely to occur. If the server ground signal 196 is in the adjacent frequency band, their signatures can also be included in the LEO / MEO signature of signature set 190. If not within the adjacent frequency band, all three signals (LEO, MEO, and terrestrial) can be converted to a common intermediate frequency and thus included in the common signature of the signature set.
In some embodiments, code 604 from server ground signal 196 at ground source 122 does not have to be security / secret. Thanks to their coverage area, the security / non-secret code 604 can add additional obstacles to electromagnetic attackers without embedded security / secret code.
Correlation aspects are similar, but there are some important differences between LEO and MEO signatures. For example, LEO satellite signals 120 are much stronger than MEO satellite signals 118 because LEO satellites 110-114 are closer to Earth. However, the MEO satellite signal 118 tends to be more present for any receiver because the MEO satellites 102-106 are located at higher altitudes and are therefore more widely visible. As mentioned earlier, these properties are complementary. Since the LEO signal is strong and the MEO signal is numerous, the client signature set 134 will include at least one LEO satellite signal 120 and at least one MEO satellite signal 118.
As another example of the difference between the LEO signature and the MEO signature, the client 126 may be a transceiver and can send and receive control signals to and from the LEO control segment. In this way, the client 126 can request the authentication server 128 to start transmitting the security / secret code 602 from the LEO satellite 110. Alternatively, the authentication server 128 may instruct client 126 to collect RF snapshots at a specific time.
As another example of the difference between the LEO and MEO signatures, the security / secret code 602 of the LEO satellite 110 is an antenna beam that can be transmitted individually to each of the antenna beam footprints 702 within the satellite footprint 700. Figure 7 shows a typical antenna footprint of the Iridium satellite in North America.
FIG. 7 is an exemplary schematic showing the antenna beam footprint 702 within one Iridium satellite footprint 700 (footprint 700). Figure 7 shows a typical footprint, such as the Iridium® footprint 700 of the Iridium® satellite in North America. Iridium Footprint 700 covers almost all of North America. That is, the diameter of the footprint 700 is about 4000 km. However, the footprint 700 includes more than 20 individual small terrestrial antenna beam footprints 702 (antenna beam 702), also shown in FIG. The antenna beam footprint 702 near the edge 704 of the footprint 700 tends to be large. That is, their major axis can be 500 km or more. The antenna beam 706 near the center 710 of the footprint 700 can be extremely small, with a diameter of about 100 km. Since the entire footprint 700 passes overhead in 8 to 10 minutes, each of the antenna beam footprints 702 can individually pass overhead in 100 to 200 seconds. The overlapping area 712 is generally substantially smaller than one area of the antenna beam footprint 702. Figure 8 shows the C / N for four of the antenna beam footprint 702 when received by a quiesced client such as client 126.<sub>0</sub>Are shown individually.
Figure 8 shows the signal-to-noise ratio (C / N) over time for four of the antenna beam footprints 702 from the Iridium satellite.<sub>0</sub>) Is shown as an exemplary chart 800. Figure 8 shows the C / N for four of the antenna beams 702 when received by a quiescent client such as client 126.<sub>0</sub>Curves 802/804/806/808 are shown individually. Curves 802 and 804 show the C / N of the antenna beam 702 in the field of view for about 200 seconds.<sub>0</sub>Is shown. Curves 806 and 808 are C / N for antenna beams that last only about 100 seconds.<sub>0</sub>Is shown.
Because security / secret MEO code 408 and LEO code 602 are difficult to predict, security / secure MEO code 408 and LEO code 602 are used to authenticate the estimated location asserted by client 126 through signature set 190. Can be used. Therefore, an attacker cannot easily obtain the signature set 190 and store it for future convenience. More importantly, the space-based authentication system 100 works well in the presence of advanced spoofing attempts to forge signatures in real time.
This forces an "offshore" attacker to be located within tens of kilometers of the victim's location, according to System 100. If the transaction is expensive, the authentication server can request that the second signature be obtained when the two beams overlap at the assert position. These overlapping situations can occur, for example, within about tens of seconds. System 100 can include terrestrial radio signals that carry security / secret signatures. In this case, the attack radius is reduced to the range of the terrestrial radio signal. This means that the attack receiver must be within a few hundred meters of the victim's location.
In some embodiments, the system 100 may include terrestrial radio signals carrying non-security / non-secret signatures. In this case, the attack radius is still in the range of terrestrial radio signals, in the sense that the attack receiver must be located within a few hundred meters of the victim's location, even to receive a non-security / non-secret signature. Can be reduced to. Such systems that utilize non-security / non-secret signatures can utilize existing ground systems, both with and without security / secret codes in transmission.
FIG. 9 shows an exemplary schematic 900 showing a means of stopping a melee signature forgery attack that can be carried out by a signature forger. As shown in FIG. 9, the attacker places the receiver 902 near the position 130 to attack. The attacker wants to generate a signature that closely resembles the signature set 190 that would be collected at position 130 under attack. To this end, the attacker simply observes the same set of satellites that the (authentic) client 126 observes, and generates a forged signature 904 based on these observations. This forged signature 904 is sent to the authentication server 128 together with the assert position determination. This attack may be effective as it originates from position 906, which is close to the assert position at position 130.
FIG. 10 shows an exemplary schematic showing a means of using MEO signals to thwart melee signature forgery attacks according to a disclosed embodiment. Due to the high bandwidth of MEO Security / Secret Code 408, the MEO section of System 100 mitigates melee attacks. Therefore, MEO security / secret code 408 is very accurate and maintains high accuracy. For example, GPS Y-code accuracy 1002 is generally better than 5 meters. Even in urban and indoor environments, this accuracy is typically around 50 meters. Therefore, this MEO accuracy can distinguish between the attack position and the victim position unless the attacker is located within about 100 meters from the assert position. In addition, if all of the attacks originate from a single attack location, eg, a parking lot in a busy shopping center, Authentication Server 128 can detect those attacks.
Offshore attacks attempt to defeat MEO-signed and LEO-signed compound authentication with sophisticated antennas, receivers, and processing systems. This is distinctly different from melee attacks. A melee attack places a very simple device near the location of the user being attacked. Therefore, melee attacks require a great deal of effort in the placement of equipment. After all, the attack receiver must be placed close to the location of the attack target so that the receiver can capture the satellite signature from that location. In contrast, offshore attackers have eliminated the need for proximity by complicating the process. This attack uses advanced signal processing to allow it to be attacked from a distance. By using this signal processor, it is possible to generate a signature that may be present at a remote location under attack. For melee attacks, the receiver must be placed within, for example, about 100 meters from the target position. In contrast, an offshore attack can have its antenna and signal processing engine located, for example, about 1000 km or more from the target location.
FIG. 11 is an exemplary functional block diagram of an offshore signature forgery attack simulation system 1100 that can be performed by a signature forger. Although there are many variants, this attack system can be divided into two parts: satellite-specific processing 1102 and victim-specific processing 1110.
By using satellite-specific processing 1102, signals from different satellites within the field of view of an offshore attacker are received and separated. A controlled radiation pattern antenna (CRPA) 1104 can be used to extract individual satellite signals, but offshore attackers may also use other techniques. For example, Doppler shift or W-code processing can be used to separate satellite signals.
The Controlled Radiation Pattern Antenna (CRPA) 1104 can synthesize a beam that amplifies and separates signals from individual GNSS satellites in the field of view. These signals are processed by the individual receiver front end 1106, which amplifies, filters, and downconverts the signal. The signal is then phase-shifted by phase shifter 1108 to synthesize individual beams of each satellite within the field of view of the offshore attack facility. The phase shift operation can be thought of as a matrix of rows K and columns N, where K is the number of satellites in the field of view and N is the number of elements in the beam-forming antenna. The literature describes a number of algorithms that can be used to adapt weights to produce beams directed at individual satellites. These algorithms can also generate nulls to attenuate nearby radio frequency interference.
Victim-specific processing 1110 creates satellite signatures for any victim location by introducing appropriate time delays and Doppler shift 1112 into the signals separated by satellite-specific processing 1102. A GNSS simulator can be used to provide appropriate time delays and Doppler shift 1112 for clients 126 in victim locations such as location 130. This process is complicated, but today there are suitable (or nearly suitable) simulators on the market.
Victim-specific processing 1110 predicts pseudo-distance delays and Doppler shifts that should be present at the victim's location, such as position 130. The signal captured by the satellite-specific processor 1102 is time-shifted by using the predicted pseudo-distance delay. By using the predicted Doppler shift, the signal captured by the satellite-specific processor 1102 is frequency-shifted. After the shift, the satellite signal is attenuated to emulate the victim's environment. If victim location 130 is downtown or indoors, multipath is probably added. After the individual satellite signals are created, they are added and sampled with random noise to form the forged signal signature 1114.
FIG. 12 illustrates an exemplary functional block diagram 1200 of the simulation system for offshore signature forgery attacks shown in FIG. 10 and how offshore signature forgery attacks are thwarted with LEO signals according to the disclosed embodiments. Indicates whether it will be done.
Offshore attacks are complex but feasible. It may even be cost-effective if one attack location can attack many victim locations. Fortunately, the system 100 described herein reduces the feasibility of offshore attacks. System 100 counters offshore attacks based on LEO satellite 110. As mentioned above, the LEO Footprint 700 has a diameter of approximately 4000km. However, it is divided into a number of smaller ground antenna beam footprints 702 or antenna beam footprint 702, as shown in FIG. These individual small terrestrial antenna beam footprints 702 (antenna beam 702) are typically about 100 km in diameter and pass overhead in, for example, about 100 to 200 seconds. System 100 sends a code 602 specific to each beam. In fact, the system only sends a unique code 602, for example, in response to a client 126 authentication request. Therefore, the offshore attacker must be within 100 km of the victim's location, such as location 130. Figure 12 illustrates this constraint. That is, an attacker located at position 1202 cannot attack position 1204. Even with the signal processing shown in Figure 11, the attacker simply cannot see the code transmitted from the beam covering position 1204. Therefore, an attacker cannot create a forged signal signature 1114.
System 100 includes two additional features that further increase the cost of offshore attacks. For high-value transactions, authentication server 128 can require that a supposed object, such as client 126, provide an RF signature containing code from two overlapping beams. As shown in Figures 7 and 12, beam overlap 708 is common, but has a very small area, some with diameters of only a few tens of kilometers. Therefore, an "offshore" attacker must be within tens of kilometers of the victim's location. That is, it is no longer offshore. Victim location may not be present in one of the beam overlap 708 at the time of the offered transaction. The antenna beam footprint 702 from LEO satellite 110 is moving at high speed and the delay is only tens of seconds as shown in Figure 8, so if the transaction value is high, the authentication server 128 will be second at the time of overlap. You may request a signature.
FIG. 13 represents an exemplary functional block diagram 1300 of a simulation system for hybrid attack signature forgery based on proximity signal capture and offshore processing that a signature forgery can perform.
As shown in Figure 13, the attacker places the antenna near the victim's location. Therefore, the attacker is in the same LEO beam as the victim. Moreover, the attacker can even be located within the same beam overlap. The attack hardware can consist of a beam steering antenna or a single element antenna. In either case, the collected signature is sent back to the attack server with any suitable data link.
Hybrid attack servers are even more complex than offshore attack servers. Both have to isolate signals from different satellites, but the hybrid attacker must generate an isolation process for each satellite and victim location. If there are K satellites in the field of view and there are V victims, the attack server must maintain K × V processes. Recall that the offshore attacker only had to separate the satellites within the attack server's field of view (K processes). Therefore, System 100 imposes two major costs on the hybrid attacker: both measuring equipment in close proximity to all victim locations of the attack target and complex processors with time delays.
FIG. 14 is an exemplary functional block diagram of the space-based authentication system 1400 (system 1400) according to the disclosed embodiment. Some embodiments of system 1400 may include additional components and elements configured to enable publicly known or conventional operating functions that do not need to be detailed herein. In the embodiment shown in FIG. 14, system 1400 can be used to send and receive data according to the disclosed embodiments. System 1400 may have the same functions, materials, and structures as the embodiments shown in FIGS. 1-8. Therefore, common features, functions, and elements will not be repeated here.
System 1400 generally includes a client 126 and an authentication server 128.
The client 126 includes a client demodulation module 1450, a client signing module 170, an encryption module 1404, a client processor module 1406 (processor module 1406), a client memory module 1408 (memory module 1408), and a software configuration, including a downconverter 202 and ADC206. It may include a possible wireless module 1436 (SCR1436).
The SCR1436 may include the MEO processor module 1442, the LEO processor module 1444, and the ground processor module 1446 for demodulating the MEO satellite signal 118, the LEO satellite signal 120, and the encoded ground signal 160, respectively. The SCR1436 can manage the contribution of the MEO satellite signal 118, the LEO satellite signal 120, and the encoded ground signal 160 to the authentication of the position of the client 126.
Each client signature set 190 sent from the client 126 to the authentication server 128 via the signature signals 164, 196, 168 contains an RF / IF signature 208. The RF / IF signature 208 is a client-received MEO satellite signal 146, a client-received LEO satellite signal 158, and a client-received terrestrial signal 162 (radio frequency (RF) or intermediate frequency (IF) signal) captured by the client antenna 198 on the client 126. ) Is included to generate the client signature set 190.
In the embodiment shown in FIG. 14, the client 126 does not need to track the client-received MEO satellite signal 146, the client-received LEO satellite signal 158, and the client-received ground signal 162. As shown in FIG. 14, tracking and bit demodulation is performed by the tracking and bit demodulation module 1428 located on authentication server 128. However, other configurations may be used.
The authentication server 128 includes a server antenna 150, a server demodulation module 1440, an authentication verdict module 1424, a tracking and bit demographic module 1422, a server data module 174, a server client data module 172, a decryption module 1430, and a server processor module 1432 (processor module 1432). , Server memory module 1434 (memory module 1434), and software configurable wireless module 1436 (SCR1436).
The server demodulation module 1440 is configured to perform a downconverter 1412 configured to perform RF to baseband conversion, a bandpass filter 1414 configured to perform bandpass filtering, and analog-digital conversion. Includes the ADC 1416, the code wipeoff 1418 configured to remove the C / A code, and the carrier wipeoff 1420 configured to remove the in-phase carrier 402.
The tracking and bit demodulation module 1422 can be configured to estimate the data bits of the server received signals 148, 156, and 196.
The tracking and bit demodulation module 1428 can be configured to estimate the data bits of the client received signals 146, 158, and 162.
The server-client data module 172 is configured to provide signature set 190 as described above by forming a client MEO signal signature 164, a client LEO signal signature 166, and a client ground signal signature 168.
The server data module 174 is configured to provide a server signature set 192 by forming a server MEO signal signature 176, a server LEO signal signature 178, and a server ground signal signature 180.
The client signature set 190 and the server signature set 192 are compared by the authentication decision module 1424 and generate authentication message 124.
Encryption module 1404 and decryption module 1430 are used to further enhance authentication performance. The client-specific key (or device signature) is concatenated with the GNSS signature set from client 126. The client-specific key can be based on, for example, Cryptographic Symmetry Cryptography (eg AES), Asymmetric Cryptography (eg Public-Secret Cryptography), Physical Non-Replicatable Function (PUF), or other cryptography. Yes, but not limited to them. The client-specific key is used to modify the client signature set 190, and this modification only authenticates if the server replication of the client-specific key matches the one used to create the server signature set. Location verification on server 128 is generally done to be successful.
The satellite signature can be considered as plaintext for device encryption. The satellite signature may also include client position velocity time (PVT) information verified by correlating the satellite signature captured by the client 126 with the corresponding data in the satellite reference receiver. Therefore, a consolidated security system is generated.
Processor module 1406/1432 is a general purpose processor designed to perform the functions described herein, content addressable memory, digital signal processors, application-specific integrated circuits, field programmable gate arrays, any suitable. It can be implemented or implemented by programmable logic devices, individual gate or transistor logic, individual hardware components, or any combination thereof. In this way, the processor can be realized as a microprocessor, a controller, a microcontroller, a state machine, and the like.
Processors are also implemented as a combination of computing devices, such as a combination of digital signal processors and microprocessors, multiple microprocessors, one or more microprocessors that work with a digital signal processor core, or any other similar configuration. You can also do it. In practice, processor module 1406/1432 contains processing logic configured to perform functions, techniques, and processing tasks related to the operation of system 1400.
In particular, the processing logic is configured to support the authentication methods described herein. For example, processor module 1406/1432 may each include a software-configurable wireless module 1436 (SCR1436), which modules provide parameters for demodulating signals based on various satellite and terrestrial communication protocols. It can be operated to select. For example, the SCR1436 can include the MEO processor module 1442, the LEO processor module 1444, and the ground processor module 1446 for demodulating the MEO satellite signal 118, the LEO satellite signal 120, and the encoded ground signal 160, respectively.
In another embodiment, the client processor module 1406 can be adequately configured to send the client signature set 190 from the client 126 via an antenna (not shown) to the authentication server 128. As another example, the server processor module 1432 can be adequately configured to send authentication message 144 to another server or client 126 via an antenna (not shown). In addition, the steps of methods or algorithms described in connection with the embodiments disclosed herein are performed directly by hardware, firmware, software modules executed by processor modules 1406/1432, or any combination thereof. can do.
The memory module 1408/1434 is a non-volatile storage device (non-volatile semiconductor memory, hard disk device, optical disk device, etc.), a random access storage device (eg, SRAM, DRAM), or any other form of storage known in the art. It can be realized as a medium. A memory module 1408/1434 can be attached to a processor module 1406/1432, respectively, so that the processor module 1406/1432 can read and write information from the memory module 1408/1434.
As an example, processor module 1406 and memory module 1408, processor module 1432 and memory module 1434 can reside in their respective ASICs. Memory modules 1408/1434 can also be incorporated into processor modules 1406/1432, respectively. In one embodiment, memory module 1408/1434 may include cache memory for storing temporary variables or other intermediate information during the execution of instructions executed by processor module 1406/1432. Memory module 1408/1434 may also include non-volatile memory for storing instructions executed by processor module 1406/1432.
For example, memory module 1408/1434 may include a location database (not shown) for storing location signatures 190/192 and other data in accordance with the disclosed embodiments. As another example, the client memory module 1408 may store a replica of the digital client receive signal 222 on the client 126. The various exemplary blocks, modules, circuits, and processing logic described in connection with the embodiments disclosed herein can be realized in hardware, computer-readable software, firmware, or any combination thereof. Those skilled in the art will understand that there is. To articulate such interchangeability and compatibility of hardware, firmware, and software, various exemplary components, blocks, modules, circuits, and steps are generally described in terms of their functionality. ing.
In some embodiments, the system 1400 is an arbitrary number of processor modules, any number of memory modules, any number of transmitter modules, and any number of receivers suitable for the operations described herein. May include modules. The illustrated system 1400 represents a simple embodiment for ease of description. These and other elements of System 1400 are interconnected to allow communication between the various elements of System 1400. In one embodiment, these and other elements of system 1400 may be interconnected via a data communication bus (not shown).
Transmitter modules and receiver modules may be located in each processor module 1406/1432 connected to their respective shared antennas (not shown). A simple module may use only one shared antenna, but more complex modules may have multiple and / or more complex antenna configurations. In addition, although not shown in FIG. 14, those skilled in the art understand that transmitters may transmit to more than one receiver, or multiple transmitters may transmit to the same receiver. Will do.
Whether a feature is implemented as hardware, firmware, or software depends on the specific application and design constraints placed on the entire system. Those familiar with the concepts described herein may perform such functions in a manner suitable for a particular application, but decisions of such practice are within the scope of the invention. It should not be interpreted as causing a deviation.
FIG. 15B represents an exemplary flowchart showing the location-based authentication process 1500 according to the disclosed embodiment. The various tasks performed in connection with Process 1500 may be performed by computer-readable media with computer-executable instructions to execute software, hardware, firmware, process methods, or any combination thereof. it can. Process 1500 can be recorded on a computer-readable medium such as a semiconductor memory, magnetic disk, optical disk, etc., and is accessed and executed by a computer CPU such as the processor module 1406/1432 in which the computer-readable medium is stored. be able to.
Note that process 1500 may include any number of additional or alternative tasks, the tasks shown in FIG. 15B need not be performed in the order shown, and process 1500 is detailed herein. Can be incorporated into a more comprehensive procedure or process that does not have additional functionality. In some embodiments, a portion of process 1500 can be performed by various elements of systems 100 and 1400, such as client 126, authentication server 128, and the like. Process 1500 can have the same functions, materials, and structures as the embodiments shown in FIGS. 1-12. Therefore, common features, functions, and elements will not be repeated here.
Process 1500 is initiated by receiving at least one client-received MEO satellite signal from at least one MEO satellite on the client device (task 1502). At least one MEO satellite is, for example, the Global Navigation Satellite System (GNSS) satellite, the Global Positioning System (GPS ) satellite, the Globalnaya Navigatsionnaya Sputnikovaya Sistema (GLONASS ) satellite, the BeiDou Navigation System (COMPASS ). ) Satellites, Galileo satellites, or other satellites that can be used to support positioning, navigation, or timing-related applications, but not limited to them.
Process 1500 is then continued by receiving at least one client-received LEO satellite signal from at least one LEO satellite on the client device (task 1504).
Process 1500 is then continued by forming a client MEO signal signature containing a sample over the MEO signature period of at least one client received MEO satellite signal (task 1506).
Process 1500 is then continued by forming a client LEO signal signature containing a sample over the LEO signature period of at least one client received LEO satellite signal (task 1508).
Process 1500 is then continued by receiving at least one MEO satellite signal at the server unit and supplying at least one server-received MEO satellite signal (task 1510).
Process 1500 is then continued by forming a replica of at least one LEO satellite signal on the server unit and supplying at least one server LEO satellite signal (task 1512).
Process 1500 continues by receiving a client MEO signal signature containing a sample of at least one client-received MEO satellite signal received from at least one MEO satellite over the MEO signature period (task 1514).
Process 1500 is then continued by forming a server MEO signal signature containing a sample of at least one server-received MEO satellite signal received from at least one MEO satellite over the MEO signature period (task 1516).
Process 1500 is then continued by comparing the client MEO signal signature with the server MEO signal signature and providing the MEO comparison results (task 1518).
Process 1500 is then continued by receiving a client LEO signal signature containing a sample of at least one client-received LEO satellite signal received from at least one LEO satellite over the LEO signature period (task 1520).
Process 1500 is then continued by forming a server LEO signal signature containing a sample of at least one server LEO satellite signal over the LEO signature period of at least one LEO satellite (task 1522).
Process 1500 is then continued by comparing the client LEO signal signature with the server LEO signal signature and providing the LEO comparison results (task 1524).
Process 1500 is then continued by authenticating that the client device is in a location based on the MEO and LEO comparison results (task 1526).
Process 1500 is then continued by evaluating the MEO and LEO comparison results on the server unit and authenticating the location of the client unit on the host unit (task 1528).
Process 1500 is then continued by receiving a client LEO signal signature containing a sample of the two client-received LEO satellite signals received from the two LEO satellites over the LEO signature period (task 1530).
Process 1500 is then continued by forming a server LEO signal signature containing samples over the LEO signature period of the two server LEO satellite signals of the two LEO satellites (task 1532).
Process 1500 is then continued by receiving a client terrestrial signal signature containing a terrestrial sample of at least one client received terrestrial signal received from at least one terrestrial source (task 1534).
Process 1500 is then continued by sending the client MEO signal signature, the client LEO signal signature, and the terrestrial signal signature to the server unit (task 1536).
Process 1500 is then continued by forming a replica of at least one client-received terrestrial signal on the server unit and providing the server terrestrial signal signature (task 1538).
Process 1500 is then continued by comparing the client ground signal signature with the server ground signal signature and providing ground comparison results (task 1540).
Process 1500 is then continued by authenticating the location of the client device based on the MEO comparison results, the LEO comparison results, and the ground comparison results (task 1542).
FIG. 16 represents an exemplary flowchart showing the client location-based authentication process 1600 according to the disclosed embodiment. The various tasks performed in connection with Process 1600 may be performed by computer-readable media with computer-executable instructions to execute software, hardware, firmware, process methods, or any combination thereof. it can. Process 1600 can be recorded on a computer-readable medium such as a semiconductor memory, magnetic disk, optical disk, etc., and is accessed and executed by a computer CPU such as the processor module 1406/1432 in which the computer-readable medium is stored. be able to.
Note that process 1600 may include any number of additional or alternative tasks, the tasks shown in FIG. 16 need not be performed in the order shown, and process 1600 is detailed herein. Can be incorporated into a more comprehensive procedure or process that does not have additional functionality. In some embodiments, a portion of process 1600 can be performed by various elements of systems 100, 600, and 1400, such as client 126, authentication server 128, and the like. Process 1600 can have similar functions, materials, and structures to the embodiments shown in FIGS. 1, 6, and 12. Therefore, common features, functions, and elements will not be repeated here.
Process 1600 is initiated by receiving at least one client-received MEO satellite signal from at least one MEO satellite on the client device (task 1602). At least one MEO satellite is, for example, the Global Navigation Satellite System (GNSS) satellite, the Global Positioning System (GPS ) satellite, the Globalnaya Navigatsionnaya Sputnikovaya Sistema (GLONASS ) satellite, the BeiDou Navigation System (COMPASS ). ) Satellites, Galileo satellites, or other satellites that can be used to support positioning, navigation, or timing related applications, but not limited to them.
Process 1600 is then continued by receiving at least one client-received LEO satellite signal from at least one LEO satellite on the client device (task 1604).
Process 1600 is then continued by forming a client MEO signal signature containing a sample over the MEO signature period of at least one client received MEO satellite signal (task 1606).
Process 1600 is then continued by forming a client LEO signal signature containing a sample over the LEO signature period of at least one client received LEO satellite signal (task 1608).
Process 1600 is then continued by sending the client MEO signal signature and the client LEO signal signature to the server for authentication of the location of the client device (task 1610).
Process 1600 is then continued by forming a client LEO signal signature containing samples over the LEO signature period of the two client received LEO satellite signals received from the two LEO satellites (task 1612).
Process 1600 is then continued by receiving a client terrestrial signal signature containing a sample of at least one client received terrestrial signal received from at least one terrestrial source over the client terrestrial period (task 1614).
Process 1600 is then continued by sending the client MEO signal signature, the client LEO signal signature, and the ground signal signature to the server for authentication of the location of the client device (task 1616).
In this way, the disclosed embodiments provide protection against spoofing and counterfeiting such as melee and offshore attacks, as well as strong coverage in urban and indoor environments where satellite signals are frequently blocked. The disclosed embodiments provide an authentication system that provides adequate received signal strength for navigation satellite signals received by client devices located in low signal-to-noise ratio (SNR) environments such as indoors and downtown.
Although at least one exemplary embodiment has been presented in the detailed description above, it should be understood that there are numerous variations. It should also be understood that the exemplary embodiments described herein are not intended to limit the scope, applicability, or configuration of the gist of the invention in any way. Rather, the detailed description described above will provide one of ordinary skill in the art with useful guidance for implementing the described embodiments. It is possible to make various changes to the function and composition of the elements without departing from the scope of the claims, which are known equivalents and equivalents foreseeable at the time of filing of the present application. Please understand that it includes.
As used herein, the term "module" refers to software, firmware, hardware, and any combination of these elements for performing the relevant functions described herein. In addition, although various modules are described as individual modules for the purpose of explanation, as will be understood by those skilled in the art, two or more modules may be combined to provide related functions according to the embodiment of the present disclosure. You may form a single module to execute.
As used herein, terms such as "computer program product" and "computer-readable medium" may be used generally to refer to media such as memory, storage devices, or storage units. These and other forms of computer-readable media can be provided to store one or more instructions used by processor module 1406/1432 to cause processor module 1406/1432 to perform a particular operation. .. Such instructions are commonly referred to as "computer program code" or "program code" (they may be grouped in the form of computer programs or other groups), and when they are executed, System 100, A method using 600, and 1400 becomes feasible.
The above description refers to an element, node, or part that is "connected" or "connected." As used in this document, "connected" means that one element / node / part is directly joined to another, if not necessarily mechanical, unless explicitly stated otherwise. Means (or is in direct contact). Similarly, unless explicitly stated otherwise, "concatenated" means that one element / node / part is joined directly or indirectly to another element / node / part, although not necessarily mechanically. (Or you are in direct or indirect contact). Thus, although FIGS. 1-12 show exemplary configurations of elements, additional intervening elements, devices, parts, or components may be present in the embodiments of the present disclosure.
The terms and phrases used herein, as well as their variants, should be construed as non-limiting, as opposed to limiting, unless expressly stated otherwise. As an example above, the term "includes" should be interpreted to mean "include without limitation" and the like. The term "example" is used to provide an example of the item being discussed and is not intended to provide an exclusive or limited list thereof. Also, adjectives such as "conventional," "conventional," "ordinary," "standard," and "known," and terms with similar meanings, refer to the item at a particular time. It should not be construed as being limited to things or items available at any given time, but rather traditional, conventional, normal, available or known at any time, now or in the future. Or should be construed as embracing standard techniques.
Similarly, a group of items connected by the conjunction "and" should not be construed as requiring that all of these items be present in that group, but rather "and" unless explicitly stated otherwise. Should be interpreted as / or ". Similarly, a group of items connected by the conjunction "or" should not be construed as requiring mutual exclusivity within that group, but rather, unless otherwise explicitly stated. Should be interpreted as "and / or".
In addition, the items, elements, or components of this disclosure may be described or claimed in the singular, but the plural is also within the scope of the disclosure unless explicitly stated to limit it to the singular. it is conceivable that. There are broader terms and expressions, such as "one or more," "at least," and "but not limited," and in some cases other similar expressions, such as. If there is no broadening expression, it should not be construed as intended or a requirement for a narrower range of cases. The term "about" is intended to include values that result from experimental errors that may occur during measurement when referring to numbers or numerical ranges.
As used herein, unless expressly stated otherwise, "workable" means that it can be used, is suitable for use or service, or is ready for use, and can be used for a particular purpose. And, it means that the notice or desired function described in the present specification can be performed. With respect to systems and equipment, the term "operable" means that the system and / or equipment is fully functional and calibrated, has elements to perform the functions of the bulletin board when it is started, and is applicable. It means that it meets the operability requirements. With respect to systems and circuits, the term "operable" means that the system and / or circuits are fully functional and calibrated, have the logic to perform the posted functions when activated, and are applicable. It means that it meets the operability requirements.
19 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO0154091A2 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | – |
| WO2005098468A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | – |
| US2009195354A1 | Cites | United States of America | A | Search report | – |
| US2012131650A1 | Cites | United States of America | X | Search report | 1-16 |
| US2012144451A1 | Cites | United States of America | X | Search report | 1-16 |
| 山口 正ほか: "GPS情報とWLAN信号情報を用いた位置証明方式", 電子情報通信学会技術研究報告, vol. 112, no. 135, JPN6017036326, 12 July 2012 (2012-07-12), pages 43 - 48, ISSN: 0003646684 | Non-patent | – | – | Search report | – |
12 members in 5 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 13653385 | United States of America | – | |
| 201213653385 | United States of America | A | |
| 201213653385 | United States of America | A | |
| 2013059531 | United States of America | W | |
| 2013059531 | United States of America | W | |
| 13653385 | – | – | – |
| US201213653385 | – | – | – |
| US2013059531 | – | – | – |
| WO2013US59531 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| US2014104102A1 | United States of America | A1 | |
| WO2014062315A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US8811614B2 | United States of America | B2 | |
| US2014321511A1 | United States of America | A1 | |
| CN104704749A | China | A | |
| US9059784B2 | United States of America | B2 | |
| EP2909953A1 | European Patent Office (EPO) | A1 | |
| JP2016500953AThis record | Japan | A | |
| CN104704749B | China | B | |
| JP2019050608A | Japan | A | |
| EP2909953B1 | European Patent Office (EPO) | B1 | |
| JP6905969B2 | Japan | B2 |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2016500953
- Publication, DOCDB
- 2016500953
- Publication, EPODOC
- JP2016500953
- Application
- 2015536777
- Application, DOCDB
- 2015536777
- Application, EPODOC
- JP20150536777
Titles2
- Japanese
- 低および中地球軌道からの信号を利用する宇宙ベースの認証
- English
- Space-based certification using signals from low and medium earth orbits
Classification
- CPC, 14
- G01S19/03
- H04W4/02
- H04B1/707
- G01S19/215
- H04B7/19
- H04K3/22
- H04K3/65
- H04K3/86
- H04K3/90
- H04W12/06
- H04K2203/32
- H04W12/63
- H04B7/1851
- G01S19/396
- IPC, 4
- H04L9 32
- G01S19 28
- G01S19 25
- H04W4 02
Designated states5
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo
- National, 1
- Uzbekistan