Galileo Open Service Authentication: A Complete Service Design and Provision Analysis

被引:0
|
作者
Walker, P. [1 ]
Rijmen, V. [1 ]
Fernandez-Hernandez, I. [2 ]
Bogaardt, L. [3 ]
Seco-Granados, G. [4 ]
Simon, J.
Calle, D. [5 ]
Pozzobon, O. [6 ]
机构
[1] Univ Leuven, KU Leuven, Dept Elect Engn ESAT, Leuven, Belgium
[2] Commiss European Communities, Galileo Commercial Serv, Pisa, Italy
[3] Commiss European Communities, Pisa, Italy
[4] UAB, Barcelona, Spain
[5] GMV, Madrid, Spain
[6] QASCOM, Louvain, Belgium
关键词
D O I
暂无
中图分类号
TP7 [遥感技术];
学科分类号
081102 ; 0816 ; 081602 ; 083002 ; 1404 ;
摘要
GNSS authentication, and in particular Navigation Message Authentication (NMA), has been already studied in the scientific literature. However, not many references that analyse the assets at risk, existing threats, mitigation actions, and residual risks through standard risk assessment processes, are available. In this paper, we outline how to use such processes to justify the design and selection of some configurable options for the service specification and operational procedures of GNSS Navigation Message Authentication (NMA) using the Galileo Open Service signals. The proposed NMA scheme is based on the TESLA protocol as proposed in [1]. To motivate the design of the service, we first identify the categories of users and associated risks of attack. We then summarize the mitigation capability against these attacks provided by the TESLA solution referred herein. We define the cryptographic parameters to use for the service in the foreseeable future. We also identify further mitigations that the receiver manufacturer or service user might need to consider to ensure security of the position and/or the time fixes according to their risk aversion. These might include a trusted local clock reference, a process to verify or challenge digital certificates and statistical analysis of symbol recovery. We then define crypto parameters and procedures that affect the quality of service for different users, as a function of several system performance scenarios. We show that, for the selected parameters, multi-constellation NMA can be achieved in environments with a masking angle up to 40 degrees. We also show that authentication using only validated signals presents good performance at 5 degrees masking angle, for users requiring four satellites transmitting NMA. This performance may increase through an optimized downlink strategy.
引用
收藏
页码:3383 / 3396
页数:14
相关论文
共 50 条
  • [41] Vascular service provision
    Adiseshiah, M
    HOSPITAL MEDICINE, 1998, 59 (01): : 81 - 81
  • [42] Securing GNSS: An End-to-End Feasibility Study for the Galileo Open Service
    Curran, James T.
    Paonni, Matteo
    PROCEEDINGS OF THE 27TH INTERNATIONAL TECHNICAL MEETING OF THE SATELLITE DIVISION OF THE INSTITUTE OF NAVIGATION (ION GNSS 2014), 2014, : 2828 - 2842
  • [43] Galileo Signals and the Open Service Signal-in-Space Interface Control Document
    Hayes, Dominic
    PROCEEDINGS OF THE 25TH INTERNATIONAL TECHNICAL MEETING OF THE SATELLITE DIVISION OF THE INSTITUTE OF NAVIGATION (ION GNSS 2012), 2012, : 2550 - 2571
  • [44] Service analysis for service design process formalization based on service engineering
    Boyonas, Mark Ismael
    Hara, Tatsunori
    Arai, Tamio
    Shimomura, Yoshiki
    ADVANCES IN LIFE CYCLE ENGINEERING FOR SUSTAINABLE MANUFACTURING BUSINESSES, 2007, : 155 - +
  • [45] Authentication Proxy as a Service
    Abdo, Jacques Bou
    2017 SECOND INTERNATIONAL CONFERENCE ON FOG AND MOBILE EDGE COMPUTING (FMEC), 2017, : 45 - 49
  • [46] Service Management Architecture and System Capacity Design for PhoneFactor™-A Two-Factor Authentication Service
    Qian, Haiyang
    Surapaneni, Chandra Sekhar
    Dispensa, Stephen
    Medhi, Deep
    2009 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2009) VOLS 1 AND 2, 2009, : 73 - +
  • [47] Safety Analysis for a New GNSS Timing Service via Galileo
    Piriz, Ricardo
    Buendia, Fulgencio
    Martin, Juan-Ramon
    Fidalgo, Javier
    Defraigne, Pascale
    Danesi, Antonio
    Jeannot, Marc
    Boyero, Juan Pablo
    PROCEEDINGS OF THE 32ND INTERNATIONAL TECHNICAL MEETING OF THE SATELLITE DIVISION OF THE INSTITUTE OF NAVIGATION (ION GNSS+ 2019), 2019, : 3359 - 3376
  • [48] Efficient Conditional Privacy-Preserving and Authentication Scheme for Secure Service Provision in VANET
    Hong Zhong
    Jingyu Wen
    Jie Cui
    Shun Zhang
    TsinghuaScienceandTechnology, 2016, 21 (06) : 620 - 629
  • [49] Efficient Conditional Privacy-Preserving and Authentication Scheme for Secure Service Provision in VANET
    Zhong, Hong
    Wen, Jingyu
    Cui, Jie
    Zhang, Shun
    TSINGHUA SCIENCE AND TECHNOLOGY, 2016, 21 (06) : 620 - 629
  • [50] Understanding the service component of application service provision: An empirical analysis of satisfaction with ASP services
    Susarla, A
    Barua, A
    Whinston, AB
    MIS QUARTERLY, 2003, 27 (01) : 91 - 123