论文标题

检测GNSS攻击的身份验证时间

Authenticated time for detecting GNSS attacks

论文作者

Spanghero, M., Zhang, K., Papadimitratos, P.

论文摘要

信息交叉验证可以是检测操纵,可疑GNSS数据的强大工具。一种有希望的方法是利用移动设备可以连接到的网络获得的时间,并检测GNSS提供的时间和网络时间之间的差异。挑战在于,作为GNSS攻击检测的基础,具有可靠的准确和值得信赖的网络时间。在这里,我们提供了一个具体的建议,该提案与网络时间服务器一起利用了几乎无处不在的IEEE 802.11(WI-FI)基础架构。我们的框架支持Wi-Fi访问点(APS)的应用程序层,安全且健壮的实时广播,基于哈希链和不频繁的数字签名验证,以最大程度地减少计算和通信开销,从而使移动节点在漫游时可以有效地获得认证的和丰富的时间信息。我们将此方法与网络时间安全性(NTS)配对,以通过多种来源同时可用,以增强弹性。我们在专用设置中分析了计划的性能,并为身份验证的时间数据(Wi-Fi时间戳的信标和NTS)衡量开销。结果表明,即使是配备了GNSS的节点是移动的,也可以为GNSS时间来源提供安全性,并具有最小的身份验证和完整性的开销,并且与Wi-Fi基础架构和可能的Intermant Internet连接性以及有限的资源以及有限的资源进行了简短的交互。

Information cross-validation can be a powerful tool to detect manipulated, dubious GNSS data. A promising approach is to leverage time obtained over networks a mobile device can connect to, and detect discrepancies between the GNSS-provided time and the network time. The challenge lies in having reliably both accurate and trustworthy network time as the basis for the GNSS attack detection. Here, we provide a concrete proposal that leverages, together with the network time servers, the nearly ubiquitous IEEE 802.11 (Wi-Fi) infrastructure. Our framework supports application-layer, secure and robust real time broadcasting by Wi-Fi Access Points (APs), based on hash chains and infrequent digital signatures verification to minimize computational and communication overhead, allowing mobile nodes to efficiently obtain authenticated and rich time information as they roam. We pair this method with Network Time Security (NTS), for enhanced resilience through multiple sources, available, ideally, simultaneously. We analyze the performance of our scheme in a dedicated setup, gauging the overhead for authenticated time data (Wi-Fi timestamped beacons and NTS). The results show that it is possible to provide security for the external to GNSS time sources, with minimal overhead for authentication and integrity, even when the GNSS-equipped nodes are mobile, and thus have short interactions with the Wi-Fi infrastructure and possibly intermittent Internet connectivity, as well as limited resources.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源