Publications
Here is a list of my publicications.
2026
- Xona Pulsar: World’s First Over-the-air Rekeying of a Commercial GNSS Service for Defense ApplicationJason Anderson and Neal FedoraIn Presentation, 2026 Joint Navigation Conference (JNC), Jun 2026June 3, 2026
2025
- Authentication Security of PRF GNSS RangingJason Anderson2025
This work derives the authentication security of pseudorandom function (PRF) GNSS ranging under multiple GNSS spoofing models, including the Security Code Estimation and Replay (SCER) spoofer. When GNSS ranging codes derive from a PRF utilizing a secret known only to the broadcaster, the spoofer cannot predict the ranging code before broadcast. Therefore, PRF ranging can be used to establish trust in the GNSS pseudoranges and the resulting receiver position, navigation, and timing (PNT) solution. I apply the methods herein to Galileo’s Signal Authentication Service (SAS) utilizing the encrypted Galileo E6-C signal to compute that, at most, 400 ms of Galileo E6-C data to assert 128-bit authentication security under non-SCER models. For the SCER adversary, I predict the adversary’s needed receiving radio equipment to break authentication security. One can use this work to design a PRF GNSS ranging protocol to meet useful authentication security requirements by computing the probability of missed detection.
@misc{anderson2025authenticationsecurityprfgnss, title = {Authentication Security of PRF GNSS Ranging}, author = {Anderson, Jason}, year = {2025}, archiveprefix = {arXiv}, primaryclass = {cs.CR}, url = {https://arxiv.org/abs/2510.02196}, } - World’s First Authenticated Satellite Pseudorange from OrbitJason AndersonIn Proceedings of the 38th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2025), 2025
Cryptographic Ranging Authentication is here! We present initial results on the Pulsar authenticated ranging service broadcast from space with Pulsar-0 utilizing a recording taken at Xona headquarters in Burlingame, CA. No assumptions pertaining to the ownership or leakage of encryption keys are required. This work discusses the Pulsar watermark design and security analysis. We derive the Pulsar watermark’s probabilities of missed detection and false alarm, and we discuss the required receiver processing needed to utilize the Pulsar watermark. We present validation results of the Pulsar watermark utilizing the transmissions from orbit. Lastly, we provide results that demonstrate the spoofing detection efficacy with a spoofing scenario that incorporates the authentic transmissions from orbit. Because we make no assumption about the leakage of symmetric encryption keys, this work provides mathematical justification of the watermark’s security, and our July 2025 transmissions from orbit, we claim the world’s first authenticated satellite pseudorange from orbit.
@inproceedings{anderson2025world, title = {World’s First Authenticated Satellite Pseudorange from Orbit}, author = {Anderson, Jason}, booktitle = {Proceedings of the 38th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2025)}, pages = {738--748}, year = {2025}, doi = {10.33012/2025.20365}, } - User-Specific Dynamic Authenticated Encryption for Xona’s PULSARJason AndersonIn Presentation at the IEEE/ION Position, Location and Navigation Symposium (PLANS), Apr 2025Presented April 29, 2025
- Combinatorial Watermarking Under Limited SCER Adversarial ModelsJason Anderson, Sherman Lo, and Todd WalterNAVIGATION: Journal of the Institute of Navigation, 2025
Combinatorial watermarking can help establish trust in global navigation satellite system (GNSS) signals. In combinatorial watermarking, the GNSS provider elects to secretly invert a subset of ranging code chips and then later distributes those inversions to receivers. From these ranging code perturbations, receivers can use signal statistics to determine the authenticity of the signal. In previous work, we demonstrated how one can design combinatorial watermarking schemes and derive the distributions of receiver statistics to ensure low probabilities of missed detection and false alarm, assuming that an adversary does not attempt to estimate the watermarked chips and replay. In this work, we extend the analysis of combinatorial watermarking to adversaries capable of engaging in security code estimation and replay (SCER) attacks. We derive the distributions of our statistics for defense against SCER-capable adversaries. Provided a bound on the estimation capability of the SCER-capable adversary, one can use this work to design a combinatorial watermarking scheme that meets security requirements.
@article{anderson2024revisitingJournal, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, title = {Combinatorial Watermarking Under Limited SCER Adversarial Models}, volume = {72}, number = {2}, elocation-id = {navi.696}, year = {2025}, doi = {10.33012/navi.696}, publisher = {Institute of Navigation}, issn = {0028-1522}, journal = {NAVIGATION: Journal of the Institute of Navigation} } - Time Synchronization of TESLA-enabled GNSS ReceiversJason Anderson, Sherman Lo, and Todd WalterIEEE Transactions on Aerospace and Electronic Systems, 2025
As timed efficient stream loss-tolerant authentication (TESLA)-enabled global navigation satellite systems (GNSS) for authenticated positioning reaches ubiquity, receivers must use an onboard, GNSS-independent clock (GIC) and carefully constructed time synchronization algorithms to assert the authenticity afforded. This work provides the necessary checks and synchronization protocols needed in the broadcast-only GNSS context. We provide proof of security for each of our algorithms under a delay-capable adversary. The algorithms included herein enable a GNSS receiver to use its GIC to determine whether a message arrived at the correct time, to determine whether its GIC is safe to use and when the clock will no longer be safe in the future due to predicted clock drift, and to resynchronize its GIC. Each algorithm is safe to use even when an adversary induces delays within the protocol. Moreover, we discuss the implications of GNSS authentication schemes that use two simultaneous TESLA instances of different authentication cadences. To a receiver implementer or standards author, this work provides the necessary implementation algorithms to assert security and provides a comprehensive guide on why these methods are required. We discuss and address a vulnerability related to the standard synchronization protocols in the context of broadcast-only TESLA.
@article{anderson2024timesync, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, journal = {IEEE Transactions on Aerospace and Electronic Systems}, title = {Time Synchronization of TESLA-enabled GNSS Receivers}, year = {2025}, volume = {}, number = {}, pages = {1-16}, keywords = {Receivers;Global navigation satellite system;Clocks;Authentication;Synchronization;Security;Protocols;Delays;Codes;Cryptography;Navigation Message Authentication;Security;TESLA;GNSS}, doi = {10.1109/TAES.2025.3552074}, }
2024
- Designing Cryptography Systems for GNSS Data and Ranging AuthenticationJason AndersonDec 2024
ION Bradford W. Parkinson Award recognizing an outstanding graduate student in the field of Position, Navigation, Timing (PNT) and/or Applications.
RTCA William E. Jackson recognizing an outstanding graduate student in aviation electronics and telecommunications.
William F. Ballhaus Prize for best PhD Thesis by the Stanford Aeronautics and Astronautics Faculty.
@phdthesis{anderson2024gnsscryptothesis, author = {Anderson, Jason}, title = {Designing Cryptography Systems for GNSS Data and Ranging Authentication}, school = {Stanford University}, year = {2024}, month = dec, type = {Ph.D. dissertation}, ION Bradford W. Parkinson Award recognizing an outstanding graduate student in the field of Position, Navigation, Timing (PNT) and/or Applications. RTCA William E. Jackson recognizing an outstanding graduate student in aviation electronics and telecommunications. William F. Ballhaus Prize for best PhD Thesis by the Stanford Aeronautics and Astronautics Faculty. }, } - Authentication Security of Combinatorial Watermarking for GNSS Signal AuthenticationJason Anderson, Sherman Lo, and Todd WalterNAVIGATION: Journal of the Institute of Navigation, 2024
Watermarking signal authentication is a technique in which a global navigation satellite system (GNSS) provider cryptographically perturbs the spreading code to allow for limited cryptographic authentication of a signal. Several proposals and studies have been presented or are underway to augment GNSS signals with this capability. This work reintroduces a generalized combinatorial watermarking function that affords a flexible pathway to cryptographically prove the authentication security of a signal with receiver observables under certain assumptions. The security levels are comparable to those of standard cryptographic security (e.g., 128-bit security) and require little or no additional use of the navigation data bandwidth. We show how our methods can be applied to signals of different designs and signal-to-noise ratios. With our receiver processing strategy, one can design a watermarking signal authentication scheme and the accompanying receiver to have high confidence in a signal’s authenticity.
@article{andersonCombo2024, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, title = {Authentication Security of Combinatorial Watermarking for GNSS Signal Authentication}, volume = {71}, number = {3}, elocation-id = {navi.655}, year = {2024}, doi = {10.33012/navi.655}, publisher = {Institute of Navigation}, issn = {0028-1522}, journal = {NAVIGATION: Journal of the Institute of Navigation} } - Revisiting Combinatorial Watermarking under SCER Adversarial ModelsJason Anderson, Sherman Lo, and Todd WalterIn Proceedings of the ION 2024 Pacific PNT Meeting, 2024
Combinatorial Watermarking Signal Authentication can help establish trust in a GNSS signals. In Combinatorial Watermarking, the GNSS provider elects to invert a subset of spreading code chips secretly and then later distribute those perturbations to receivers. The receivers can use statistics of the signal to make determinations of the signal authenticity. Previous work demonstrated how to design a Combinatorial Watermarking scheme and derive the distributions of receiver statistics to ensure small probabilities of missed detection and false alarm under assuming an adversary does not attempt to estimate the watermarked chips and replay. In this work, we extend the analysis of Combinatorial Watermarking to adversaries capable of engaging in Security Code Estimation and Replay (“SCER”) attacks. We derive the distributions of our statistics under these models and assemble a collection of statistics needed to defend against SCER-capable adversaries. Provided a bound on the estimation capability of the SCER-capable adversary, one can use this work to design a Combinatorial Watermarking scheme that meets security requirements.
@inproceedings{anderson2024revisiting, title = {Revisiting Combinatorial Watermarking under SCER Adversarial Models}, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, booktitle = {Proceedings of the ION 2024 Pacific PNT Meeting}, pages = {732--744}, year = {2024}, doi = {10.33012/2024.19633}, } - Combinatorial Watermarking for GNSS Signal AuthenticationJason Anderson, Sherman Lo, and Todd WalterIn Proceedings of the 2024 International Technical Meeting of The Institute of Navigation, 2024
Watermarking Signal Authentication can establish trust in satellite navigation signals by cryptographically perturbing the spreading code. In previous work, we propose and derive probability distributions that predict receiver statistics for use in scheme design. In this work, we design a SBAS watermarking signal authentication scheme that can afford 32-bit authentication security over a 6-second time interval, matching the cadence of SBAS navigation message authentication proposals and providing 6-12 second time to authentication. The scheme is immediately extendable to other GNSS services, provided the receiver is observing SBAS signals or is network connected. We design with parameters to match worst-case operating conditions and minimum receiver hardware. We validate our models via Monte Carlo simulation and experiments with real WAAS observation and a software-defined radio to support our scheme proposals.
@inproceedings{andersonCombo2023forGNSS, title = {Combinatorial Watermarking for GNSS Signal Authentication}, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, booktitle = {Proceedings of the 2024 International Technical Meeting of The Institute of Navigation}, pages = {314159}, year = {2024}, file = {ITM}, doi = {10.33012/2024.19483}, } - Implementation of Data Authentication on SBASTodd Walter, Jason Anderson, and Sherman LoIn Proceedings of the ION 2024 Pacific PNT Meeting, 2024
Navigation message authentication has been proposed for Satellite Based Augmentation Systems (SBAS) as a means to mitigate a potential threat that could create hazardously misleading information. The SBAS corrections are a trusted source of differential Global Navigation Satellite System (GNSS) corrections and confidence levels. Currently they have no means of protection, and an aircraft will accept any properly formatted signal that it receives. As the signal design is fully open and easily accessible, it is possible for adversarial parties to generate signals impersonating official SBAS providers. Message authentication has been proposed that would add digital signatures such that the data content can be rigorously traced back to the intended trusted source. An initial scheme was proposed in 2019 based upon the Time-Efficient Loss-tolerant Authentication (TESLA) scheme [1]. This method continues to be refined and evaluated. While many aspects of the L1 SBAS message authentication scheme are mature [2], there are still several details still to be harmonized. The use of TESLA to implement the signatures is by now well-agreed to, as is the concept to establish the root of trust using asymmetric elliptic curve cryptography. Several countries have performed preliminary prototyping and agree that the overall concept is feasible. Development of the International Civil Aviation Organization (ICAO) Standards and Recommended Practices (SARPs) has been initiated, but development of the receiver Minimum Operational Performance Standard (MOPS) is on hold. Outreach has been established to the recently founded ICAO Trust Framework Panel (TFP), to help vet the TESLA scheme and to establish the key management and they participate in our teleconferences. A roadmap for the ICAO ad hoc authentication working group is well underway. This paper provides an overview of this TESLA scheme and provides a description of different options for increasing the security provided by the signature message as well as defining a proposed method to be robust against missing messages. Additionally we describe how to retain security when the signature messages are delayed due to SBAS alert messages.
@inproceedings{amac, title = {Implementation of Data Authentication on SBAS}, author = {Walter, Todd and Anderson, Jason and Lo, Sherman}, booktitle = {Proceedings of the ION 2024 Pacific PNT Meeting}, pages = {709 - 721}, year = {2024}, doi = {10.33012/2024.19631}, }
2023
- Authentication Security of Combinatorial Watermarking for GNSS Signal AuthenticationJason Anderson, Sherman Lo, and Todd WalterIn Proceedings of the 36th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2023), 2023
Best Presentation of Session
Watermarking signal authentication is a technique in which a global navigation satellite system (GNSS) provider cryptographically perturbs the spreading code to allow for limited cryptographic authentication of a signal. Several proposals and studies have been presented or are underway to augment GNSS signals with this capability. This work reintroduces a generalized combinatorial watermarking function that affords a flexible pathway to cryptographically prove the authentication security of a signal with receiver observables under certain assumptions. The security levels are comparable to those of standard cryptographic security (e.g., 128-bit security) and require little or no additional use of the navigation data bandwidth. We show how our methods can be applied to signals of different designs and signal-to-noise ratios. With our receiver processing strategy, one can design a watermarking signal authentication scheme and the accompanying receiver to have high confidence in a signal’s authenticity.
@inproceedings{andersonCombo2023, title = {Authentication Security of Combinatorial Watermarking for GNSS Signal Authentication}, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, booktitle = {Proceedings of the 36th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2023)}, pages = {495--509}, year = {2023}, file = {GNSS+}, } - Authentication of Satellite-Based Augmentation Systems with Over-the-Air Rekeying SchemesJason Anderson, Sherman Lo, Andrew Neish, and Todd WalterNAVIGATION: Journal of the Institute of Navigation, 2023
Here we delineate a complete satellite-based augmentation system (SBAS) authentication scheme, including over-the-air rekeying (OTAR), that uses the elliptic curve digital signature algorithm (ECDSA) and timed efficient stream loss-tolerant authentication (TESLA) without the quadrature (Q) channel. This scheme appends two new message types to the SBAS scheduler without over-burdening the message schedule. We have taken special care to ensure that our scheme (1) meets the appropriate security requirements needed to prevent and deter spoofing; (2) is compatible with existing cryptographic standards; (3) is flexible, expandable, and future-proof to different cryptographic and implementation schemes; and (4) is backward compatible with legacy receivers. The scheme accommodates a diverse set of features, including authenticating core-constellation ephemerides. We discuss the SBAS provider and receiver machine state and its startup, including its use by aircraft that traverse differing SBAS coverage areas. We tested our scheme with existing SBAS simulation and analysis tools and found that it had negligible effects on current SBAS availability and continuity requirements.
@article{andersonSBASOTAR2023, author = {Anderson, Jason and Lo, Sherman and Neish, Andrew and Walter, Todd}, title = {Authentication of Satellite-Based Augmentation Systems with Over-the-Air Rekeying Schemes}, volume = {70}, number = {3}, elocation-id = {navi.595}, year = {2023}, doi = {10.33012/navi.595}, publisher = {Institute of Navigation}, issn = {0028-1522}, journal = {NAVIGATION: Journal of the Institute of Navigation}, file = {NAVIGATION} } - Addressing a Critical Vulnerability in Upcoming Broadcast-only TESLA-based GNSS-enabled SystemsJason Anderson, Sherman Lo, and Todd WalterIn Proceedings of the 2023 International Technical Meeting of The Institute of Navigation, 2023
Herein, we delineate and suggest mitigations for a critical security attack involving the time synchronization requirement of any broadcast-only Timed-Efficient Stream Loss-tolerant Authentication (“TESLA”) scheme, including those in development for many Global Navigation Satellite Systems (“GNSS”). TESLA’s bandwidth efficiency and loss-tolerant properties are advantageous, even necessary, to provide GNSS cryptographic authentication security on data channels and ranging signals. TESLA presumes a loose-time synchronization assumption, and receivers must externally (i.e., via an out-of-band channel) verify this assumption (e.g., at startup, routine maintenance, routinely) to assert authentication security. However, the combination of (1) TESLA’s adaptation to the broadcast-only context and (2) the current network timing synchronization standards lends to an attack that could allow receivers to accept forgeries. The time synchronization protocol must be modified to mitigate this threat. We show this attack’s concrete feasibility using data from a study conducted on a Network Time Protocol (“NTP”) server.
@inproceedings{anderson2023addressing, title = {Addressing a Critical Vulnerability in Upcoming Broadcast-only TESLA-based GNSS-enabled Systems}, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, booktitle = {Proceedings of the 2023 International Technical Meeting of The Institute of Navigation}, pages = {277--285}, year = {2023}, file = {ITM}, doi = {10.33012/2023.18623} }
2022
- Time Synchronization for TESLA-based GNSS-enabled SystemsJason Anderson, Sherman Lo, and Todd WalterIn Proceedings of the 35th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2022), 2022
Best Presentation of Session
@inproceedings{anderson2022time, title = {Time Synchronization for TESLA-based GNSS-enabled Systems}, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, booktitle = {Proceedings of the 35th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2022)}, pages = {3408--3417}, year = {2022}, file = {GNSS+}, doi = {10.33012/2022.18442} } - Efficient and Secure Use of Cryptography for Watermarked Signal AuthenticationJason Anderson, Sherman Lo, and Todd WalterIn Proceedings of the 2022 International Technical Meeting of The Institute of Navigation, 2022
This work discusses and applies techniques to efficiently and securely use cryptography for signal authentication in civil (open) satellite navigation signals such as Chips-Message Robust Authentication (“Chimera”). By efficient and secure, we mean maintaining a cryptographic security strength requirement with minimum data bandwidth and watermark signal degradation. We exploit many strategies, including using Timed-Efficient Stream Loss-tolerant Authentication (“TESLA”), sectioned parallelized cryptographic secret distribution, and only one constant, independent spreading code watermark degradation. Our design allows multi-cadence (i.e., slow and fast) distribution even with only a single watermark degradation. Our design maintains standard 128-bit security with a single minimum bandwidth channel while allowing for authentication of many GNSS services.
@inproceedings{anderson2022efficient, title = {Efficient and Secure Use of Cryptography for Watermarked Signal Authentication}, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, booktitle = {Proceedings of the 2022 International Technical Meeting of The Institute of Navigation}, pages = {68--82}, year = {2022}, file = {ITM}, doi = {10.33012/2022.18228}, } - Cryptographic Ranging Authentication with TESLA, Rapid Re-keying, and a PRFJason Anderson, Sherman Lo, and Todd WalterIn Proceedings of the 2022 International Technical Meeting of The Institute of Navigation, 2022
This work examines cryptographic design principles for next-generation GNSS signals that could provide a publicly authenticated ranging signal of comparable security to current encrypted signals. We discuss how any authentication of spreading codes must act as an effective bit-commitment authentication; therefore, we advocate and greedily apply Timed Efficient Stream Loss-tolerant Authentication (“TESLA”) to cryptography-first GNSS design. Since any authentication acts as bit-commitment authentication, greedily using TESLA provides additional features regarding bandwidth efficiency and loss-tolerances relevant to GNSS. Using those design principles, we suggest a new method to generate secure spreading codes and distribute the required cryptographic seeds as a case study on how a cryptography-first design methodology would guide the design of a ranging signal. Moreover, we suggest an alternative publicly authenticated signal achievable by merely modifying the re-keying procedure of existing symmetrically encrypted signals (e.g., GPS’s P(Y)-code, Galileo’s E6B/C signal). This modification would maintain the current, real-time secure use of current encrypted ranging signals while providing a critical infrastructure needed by aviation and autonomous vehicle stakeholders. We compare this method to other publicly authenticated ranging signals and make the case that our suggestion would be easier and faster to achieve because it requires no changes to existing signals. Finally, we suggest that future GNSS systems modularly separate signal purposes. One signal, or signals, could provide the best possible real-time unauthenticated service, unencumbered by applying cryptography. One signal could provide the best possible delayed cryptographic spoofing detection service, unencumbered by existing requirements of real-time signals.
@inproceedings{anderson2022cryptographic, title = {Cryptographic Ranging Authentication with TESLA, Rapid Re-keying, and a PRF}, author = {Anderson, Jason and Lo, Sherman and Walter, Todd}, booktitle = {Proceedings of the 2022 International Technical Meeting of The Institute of Navigation}, pages = {43--55}, year = {2022}, file = {ITM}, doi = {10.33012/2022.18226}, } - SBAS Signal AuthenticationBrady O’Hanlon, Joseph J Rushanan, Christopher Hegarty, Jason Anderson, and 2 more authorsIn Proceedings of the 35th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2022), 2022
The addition of features to authenticate satellite-based augmentation system (SBAS) signals has been under consideration since at least 1994. The considerable amount of the research conducted in this area has been focused on data authentication, i.e., adding digital signatures or other data elements to provide SBAS users assurance that the broadcast messages were generated by a trusted service provider. Authentication features have also been considered for other civilian Global Navigation Satellite System (GNSS) signals in prior research. This prior work has focused on both data authentication and signal authentication. Whereas data authentication methods primarily aim to protect GNSS signal message content from spoofing threats, signal authentication methods aim to additionally protect the ranging information. This paper proposes and assesses signal authentication methods for SBAS L1 and L5 signals. The proposed method involves puncturing the SBAS pseudorandom noise (PRN) codes with watermarks in an adaptation of the Chips Message Robust Authentication (Chimera) scheme that will be tested for the GPS L1C signal on Navigation Technology Satellite – 3 (NTS-3). An exemplary watermark detection method is defined for the purpose of evaluating performance metrics for the proposed watermark scheme. Evaluated performance metrics include probability of watermark detection as a function of received C/N0 and desired false alarm probability and correlation loss for non-participants. Implications for receiver capabilities for users that wish to process this signal are explored.
@inproceedings{o2022sbas, title = {SBAS Signal Authentication}, author = {O’Hanlon, Brady and Rushanan, Joseph J and Hegarty, Christopher and Anderson, Jason and Walter, Todd and Lo, Sherman}, booktitle = {Proceedings of the 35th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2022)}, pages = {3369--3377}, year = {2022}, file = {GNSS+}, doi = {10.33012/2022.18443} }
2021
- On SBAS Authentication with OTAR SchemesJason Anderson, Sherman Lo, Andrew Neish, and Todd WalterIn Proceedings of the 34th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2021), 2021
@inproceedings{andersonSBASOTAR2021, title = {On SBAS Authentication with OTAR Schemes}, author = {Anderson, Jason and Lo, Sherman and Neish, Andrew and Walter, Todd}, booktitle = {Proceedings of the 34th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2021)}, pages = {4288--4304}, year = {2021}, file = {GNSS+} } - SBAS Message Schemes to Support Inline Message AuthenticationTodd Walter, Jason Anderson, and Sherman LoIn Proceedings of the 34th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2021), 2021
The international community is considering the addition of authentication signatures to the Satellite Based Augmentation System (SBAS) Minimum Operational Performance Standards (MOPS). Authentication would protect the user against the possibility of undesired integrity data being mistaken for genuine State provided signals. Several authentication schemes have been proposed over the past years, but recently a preference has been expressed for inline signatures (i.e., signatures that are interleaved with the correction and integrity messages, all in the same data stream). An important concern is whether there is sufficient bandwidth to add these new messages and will their addition negatively affect performance. We have proposed a method that achieves this goal and evaluate its performance. Further, our method ensures rigorous protection for the user by ensuring that unauthenticated data is discarded and cannot cause harm to the user, while maintaining the required Time-To-Alert of the SBAS integrity messages.
@inproceedings{walter2021sbas, title = {SBAS Message Schemes to Support Inline Message Authentication}, author = {Walter, Todd and Anderson, Jason and Lo, Sherman}, booktitle = {Proceedings of the 34th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2021)}, pages = {474--484}, year = {2021}, file = {GNSS+}, doi = {10.33012/2021.17908}, } - SBAS Message Authentication: A Review of Protocols, Figures of Merit and Standardization PlansIgnacio Fernández-Hernández, Todd Walter, Andrew M Neish, Jason Anderson, and 3 more authorsIn Proceedings of the 2021 International Technical Meeting of The Institute of Navigation, 2021
This paper presents an overview of SBAS L5 message authentication protocols proposed in the last years. We analyze 13 protocols from four sources: Stanford University, the EAST and SPARC projects, and a protocol proposed for the Australian SBAS. The protocols use L5Q, L5I, digital signatures and delayed disclosure based on TESLA. We also analyze figures of merit and weight their importance for the SBAS authentication protocol comparison, including protocol-specific figures AER (Authentication Error Rate), TBA (Time Between Authentications) and latency, and SBAS service figures (accuracy, integrity, continuity, availability). A plan for the definition, assessment and standardization of SBAS message authentication to be carried out by U.S.-EU Working Group C, in cooperation with EUROCAE WG62/RTCA-SC-159, is also outlined, with the goal of a potential addition of SBAS message authentication in the next version of the DFMC standard.
@inproceedings{fernandez2021sbas, title = {SBAS Message Authentication: A Review of Protocols, Figures of Merit and Standardization Plans}, author = {Fern{\'a}ndez-Hern{\'a}ndez, Ignacio and Walter, Todd and Neish, Andrew M and Anderson, Jason and Mabilleau, Mikael and Vecchione, Giovanni and Ch{\a}tre, Eric}, booktitle = {Proceedings of the 2021 International Technical Meeting of The Institute of Navigation}, pages = {111--124}, year = {2021}, file = {ITM}, doi = {10.33012/2021.17829}, } - Message Authentication Candidates for the SBAS Dual Frequency Multi-Constellation StandardIgnacio Fernandez-Hernandez, Todd Walter, Mikael Mabilleau, Luciano Tosato, and 6 more authorsIn Proceedings of the 34th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2021), 2021
The first version of the SBAS Dual Frequency Multi-Constellation (DFMC) standard has been recently finalized. It is foreseen that its extension includes message authentication, to protect avionics from SBAS data spoofing attacks. This paper focuses on the main candidate scheme at the moment, based on the TESLA protocol in the L5-I channel. This paper analyzes which data needs to be used before authentication in order to maintain time to alert. It describes two options, named Authenticate-then-Use and Use-then Authenticate, and analyzes its prospective performance for EGNOS and WAAS.
@inproceedings{fernandez2021message, title = {Message Authentication Candidates for the SBAS Dual Frequency Multi-Constellation Standard}, author = {Fernandez-Hernandez, Ignacio and Walter, Todd and Mabilleau, Mikael and Tosato, Luciano and Chiara, Andrea Dalla and Pozza, Daniele and Pozzobon, Oscar and Calabrese, Alessandra and Anderson, Jason and Ch{\a}tre, Eric}, booktitle = {Proceedings of the 34th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+ 2021)}, pages = {443--452}, year = {2021}, file = {GNSS+}, doi = {10.33012/2021.17892} }
2017
- Assembly and metrology of NIF target subassemblies using robotic systemsK Boehm, N Alexander, J Anderson, L Carlson, and 1 more authorHigh Power Laser Science and Engineering, 2017
With European Laser Facilities such as the Extreme Light Infrastructure (ELI) and the Helmholtz International Beamline for Extreme Fields (HIBEF) scheduled to come online within the next couple of years, General Atomics, as a major supplier of targets and target components for the High Energy Density Physics community in the United States, is gearing up to meet their demand for large numbers of low cost targets. Using the production of a subassembly for the National Ignition Facility’s fusion targets as an example, we demonstrate that through automation of assembly tasks, the design of targets and their experimental setup can be fairly complex while keeping the assembly time and cost as a minimum. A six-axis Mitsubishi robot is used in combination with vision feedback and a force–torque sensor to assemble target subassemblies of different scales and designs with minimal change of tooling, allowing for design flexibility and short assembly setup times. Implementing automated measurement routines on a Nikon NEXIV microscope further reduces the effort required for target metrology, while electronic data collection and transfer complete a streamlined target production operation that can be adapted to a large variety of target designs.
@article{Boehm_Alexander_Anderson_Carlson_Farrell_2017, title = {Assembly and metrology of NIF target subassemblies using robotic systems}, volume = {5}, doi = {10.1017/hpl.2017.23}, journal = {High Power Laser Science and Engineering}, author = {Boehm, K and Alexander, N and Anderson, J and Carlson, L and Farrell, M}, year = {2017}, pages = {e25} }
2016
- Dynamical system scaling of integral natural circulation experiments for fluoride-salt cooled reactorsAJ Novak, N Zweibaum, J Anderson, and PF PetersonIn 2016 International Congress on Advances in Nuclear Power Plants, ICAPP 2016, 2016
The Dynamical System Scaling (DSS) method developed by Reyes et al. adds a new dimension to scaling of integral systems where distortion estimates are given as functions of time rather than as static values. The distortion is an important parameter describing a scaled experiment because it evaluates the extent to which results from the experiment can be used to conclude characteristics of the prototype. The DSS method is applied in this paper to develop the scaling criteria for a two-loop natural circulation transient in the Mark 1 Pebble-Bed Fluoride- Salt-Cooled High Temperature Reactor (Mk1 PB-FHR). The necessary steps to perform an optimization study to determine a hypothetical DSS-scaled facility that can be used to validate natural circulation behavior in the primary and secondary loops of the Mk1 PB-FHR are then described in detail. This application of the DSS method to an integral system with multiple loops, where the systems code RELAP5-3D is used to generate model and prototype data, reveals the added complexities associated with the DSS method, while providing the framework to connect the DSS method to a systems code. In particular, the added difficulty of employing a systems code, rather than a numerical solution to governing equations, is addressed by the development of a simple iteration algorithm to determine model parameters needed for the optimization study. The Compact Integral Effects Test (CIET) facility at the University of California-Berkeley, completed in 2014, has successfully validated natural circulation behavior of the Mk1 PB-FHR. This experimental facility was scaled based on the Hierarchical Two-Tiered Scaling (H2TS) method, and allows the application of the DSS method to be compared to the H2TS method, as the DSS method is applied in this paper to the same transient in the same reactor that is modeled by CIET.
@inproceedings{novak2016dynamical, title = {Dynamical system scaling of integral natural circulation experiments for fluoride-salt cooled reactors}, author = {Novak, AJ and Zweibaum, N and Anderson, J and Peterson, PF}, booktitle = {2016 International Congress on Advances in Nuclear Power Plants, ICAPP 2016}, pages = {1268--1277}, year = {2016}, organization = {American Nuclear Society} }