[论文解读] Cryptography Is Not Enough: Relay Attacks on Authenticated GNSS Signals
本文展示了一种实时、低成本的中继攻击,可欺骗GNSS接收机至任意位置(最远达4,000公里),且无需修改经过认证的导航消息内容。通过利用伪距估计中常见的接收与发射时间同步方法,攻击者仅使用本地接收的信号实时操纵信号时序,使加密认证机制失效。
Civilian-GNSS is vulnerable to signal spoofing attacks, and countermeasures based on cryptographic authentication are being proposed to protect against these attacks. Both Galileo and GPS are currently testing broadcast authentication techniques based on the delayed key disclosure to validate the integrity of navigation messages. These authentication mechanisms have proven secure against record now and replay later attacks, as navigation messages become invalid after keys are released. This work analyzes the security guarantees of cryptographically protected GNSS signals and shows the possibility of spoofing a receiver to an arbitrary location without breaking any cryptographic operation. In contrast to prior work, we demonstrate the ability of an attacker to receive signals close to the victim receiver and generate spoofing signals for a different target location without modifying the navigation message contents. Our strategy exploits the essential common reception and transmission time method used to estimate pseudorange in GNSS receivers, thereby rendering any cryptographic authentication useless. We evaluate our attack on a commercial receiver (ublox M9N) and a software-defined GNSS receiver (GNSS-SDR) using a combination of open-source tools, commercial GNSS signal generators, and software-defined radio hardware platforms. Our results show that it is possible to spoof a victim receiver to locations around 4000 km away from the true location without requiring any high-speed communication networks or modifying the message contents. Through this work, we further highlight the fundamental limitations in securing a broadcast signaling-based localization system even if all communications are cryptographically protected.
研究动机与目标
- 证明GNSS导航消息的加密认证无法防止实时、任意位置的欺骗攻击。
- 识别出基于广播的GNSS系统中一个根本性的设计缺陷,即通过信号的时序操纵可实现欺骗。
- 开发并评估一种无需高速网络或消息修改的实时欺骗装置。
- 证明欺骗可实现与受害者或攻击者运动状态无关的动态运动路径。
- 评估现有检测机制对这一新型攻击向量的有效性。
提出的方法
- 利用标准GNSS接收机通过共同时接收时间与共同时发射时间估算伪距的技术。
- 为每颗卫星计算精确的信号延迟,以模拟对应目标欺骗位置的伪距。
- 实时处理解码后的导航消息比特(每20毫秒处理一次),无需完整解密消息,从而实现低延迟欺骗。
- 使用软件定义无线电平台接收、处理并重新传输带有受控时间偏移的欺骗信号。
- 采用实时信号生成流水线,在引入人工时间延迟的同时保持信号完整性。
- 在商用uBlox和开源GNSS-SDR接收机上验证攻击,确保其广泛适用性。
实验结果
研究问题
- RQ1GNSS导航消息的加密认证能否防止实时位置欺骗攻击?
- RQ2是否可能在不修改导航消息内容的前提下,将GNSS接收机欺骗至任意位置?
- RQ3攻击者能否仅使用本地接收的信号,在无需在目标位置预先采集信号的情况下实时生成欺骗信号?
- RQ4基于机器学习或物理层特征的现有欺骗检测技术,在此攻击下仍有多大概率保持有效?
- RQ5信号时序操纵对长距离(如4,000公里)及复杂运动路径下的欺骗精度与可行性有何影响?
主要发现
- 该攻击成功将GNSS接收机欺骗至距离真实位置最远4,000公里外的位置,且未修改导航消息内容。
- 实时欺骗装置实现了小于24毫秒的端到端信号处理延迟,每比特平均处理时间为317.485微秒。
- 该攻击无需高速通信网络,也无需在目标位置预先录制信号。
- 攻击者可为任意动态运动路径生成欺骗信号,且与受害者或攻击者的真实运动状态无关。
- 加密认证机制(如OSNMA和CHIMERA)因攻击操纵的是信号时序而非消息完整性而完全失效。
- 现有检测方法(包括基于SCER分析和机器学习的方法)因攻击具备低延迟、实时信号操纵特性而无效。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。