◂ signal//lock
tech · navigation

GPS Spoofing and Anti-Spoofing — The Radar Game in the Sky

GPS is a radar problem: timing signals from satellites, distance from delay, position from triangulation. Jamming blocks the signal. Spoofing is worse — it sends a fake signal that the receiver trusts.

GPS Spoofing and Anti-Spoofing — The Radar Game in the Sky
tech · navigation

How spoofing works

A spoofer transmits counterfeit GPS signals at higher power than the real satellites. The receiver locks onto the stronger fake and computes a false position. A drone thinking it is over home base is actually over enemy territory. A ship believing it is in international waters is inside territorial limits. The 2011 drone capture in Iran was allegedly a spoofing success.

Civil vs. military signals

Civilian GPS (L1 C/A) is unencrypted and easy to spoof. Military GPS (M-code, Y-code on P(Y)) is encrypted and significantly harder. But most commercial aviation, maritime and automotive systems rely on civilian signals. The vulnerability is economic as much as technical.

▒ open the radar — lock the signals
▸ Play Signal//Lock now

Multi-sensor countermeasures

The best defence is not trusting GPS alone. Inertial navigation (INS) remembers where you were and integrates motion. Radar altimeters measure height independently. Automatic Dependent Surveillance-Broadcast (ADS-B) can be cross-checked against other aircraft. Multi-constellation GNSS (GPS + Galileo + GLONASS + BeiDou) makes spoofing all of them simultaneously far harder.

CRPA and advanced antennas

Controlled Reception Pattern Antennas (CRPA) use multiple elements and digital beamforming to null out signals arriving from unexpected directions — like a spoofing transmitter on the ground while real satellites are overhead. CRPA is standard on military aircraft and increasingly on commercial ships in high-risk waters.

Clock drift and clock-offset monitoring

In a spoofing event, the counterfeit signal must gradually take over the receiver's tracking loop. Since the spoofer’s internal clock and the genuine GPS atomic clocks are not perfectly synchronized, a sudden jump in the receiver’s clock bias or drift is often the first technical indicator of an attack. High-end receivers monitor the local oscillator's stability against the incoming signal timing. If the calculated time offset shifts at a rate inconsistent with the physics of satellite motion or local crystal stability, the receiver can flag the signal as untrusted before a position shift occurs.

Sophisticated spoofers attempt a 'lift-off' maneuver, where they match the genuine signal's power and timing exactly before slowly slewing the fake signal away. However, maintaining nanosecond-level alignment across multiple simulated satellites is computationally expensive and physically difficult from a single transmission point. By implementing Receiver Autonomous Integrity Monitoring (RAIM), systems can detect statistical inconsistencies between the pseudorange measurements of different satellites. If one satellite signal suggests a position radically different from the consensus of the others, the system discards the outlier, neutralizing the spoofing attempt.

The Black Sea incidents and signal mapping

One of the most documented large-scale spoofing events occurred in June 2017 in the Black Sea. Over 20 ships reported their GPS positions were located at an inland airport rather than their actual maritime coordinates. This was not a targeted attack on a single vessel but a broad-area broadcast. Such incidents highlight the transition of spoofing from a laboratory curiosity to a tool of electronic warfare. The signals were likely generated by a terrestrial transmitter using a 'record-and-replay' approach or a signal simulator, overwhelming the legitimate, low-power signals arriving from orbit.

The maritime industry has since moved toward 'Signal Fingerprinting' to detect these anomalies. Unlike genuine satellite signals that arrive from diverse angles in the sky, a ground-based spoofer produces signals that all originate from the same vector. Even without multiple antennas, a moving receiver can detect the lack of expected Doppler shift variation between the 'satellites.' If the Doppler profile of all incoming signals is identical, it confirms the source is a single stationary transmitter on the ground rather than a constellation of satellites moving at 3.9 kilometers per second.

Signal Correlation and Power Consistency Analysis

A sophisticated detection method involves monitoring the signal-to-noise ratio (SNR) and absolute signal strength during the 'takeover' phase. Authentic GPS signals arrive from orbit with remarkably low power, often below the thermal noise floor, necessitating high processing gain to extract. A spoofer must typically broadcast at a higher power level to force the receiver's phase-locked loop (PLL) to transition from the authentic signal to the counterfeit. Modern defensive software monitors for these sudden jumps in signal strength or inconsistencies in the automatic gain control (AGC) levels, which serve as immediate red flags indicating a local, terrestrial transmitter is overriding the satellite feed.

Furthermore, spatial correlation analysis can expose spoofing. Because an amateur spoofer often broadcasts multiple satellite signals from a single antenna, all fake signals appear to originate from the same point in space. An authentic constellation provides signals from diverse sky coordinates. Advanced receivers equipped with angle-of-arrival (AoA) estimation can detect that the carrier phases for dozens of 'satellites' are perfectly correlated, a physical impossibility in a legitimate orbital scenario. This spatial consistency check remains one of the most robust software-defined methods for identifying spoofing without requiring the multi-element hardware of a CRPA system.

The Role of Chimera and NMA Authentication

To bridge the security gap between civilian and military signals, new authentication protocols like Chips-Message Robust Authentication (Chimera) and Navigation Message Authentication (NMA) are being implemented. Galileo’s Open Service Navigation Message Authentication (OSNMA) is a leading example, utilizing a cryptographic digital signature embedded within the navigation data. This allows the receiver to verify that the signal truly originated from a Galileo satellite and has not been altered in transit. While it does not prevent a raw signal replay attack, it makes the generation of entirely synthetic, coordinated fake positions computationally prohibitive for most adversaries.

Chimera takes this further by binding the cryptographic markers directly to the code chips of the signal. By adding unpredictable 'security bits' that are revealed only after a short delay via a secure data channel, the receiver can retrospectively confirm the physical legitimacy of the signal it just processed. This creates a temporal 'trust window.' If a spoofer attempts to guess these bits in real-time, it will fail; if it waits for the bits to be revealed, the signal will be delayed enough for the receiver to detect the timing discrepancy. These methods represent the shift from physical-layer defense to a zero-trust cryptographic architecture in global positioning.

Related reading

▒ ready to lock on?
▸ play signal//lock free

no install · plays in any browser