Failure Analysis (Geodesy) 10 min read

Contested Signals: GNSS Reliability in Arctic Offshore Work

Executive Summary

Norway's communications authority Nkom is expanding a network of monitoring stations to detect GNSS jamming and spoofing near the Russian border, where interference now reaches deep into Norwegian airspace and disrupts civilian traffic. For offshore operators, the failure mode is not a receiver fault but a contested electromagnetic environment that defeats unauthenticated civil signals. The engineering response is positioning architecture with genuine reference-system diversity, interference logging, authenticated signals, and inertial coasting – not a better GNSS receiver. Treat GNSS spoofing as a common-mode failure across all satellite-derived references in your DP FMEA and survey QC.

What the Nkom stations are set up to catch

The Norwegian Communications Authority (Nkom) is adding monitoring stations to a network that already includes three dedicated installations in the region bordering Russia, established to detect GNSS disturbances. As the Barents Observer reports, jamming and spoofing have become frequent enough to affect a range of civilian operations, including air traffic, and the interference is being picked up deeper inside Norwegian airspace than before. The expansion is a measurement and localisation effort: spectrum monitoring and direction finding to characterise where the interference originates and how far it propagates.

In engineering terms the message is narrow but important. A national authority has concluded that reliable detection of GNSS interference now requires a fixed, distributed sensing infrastructure. That is an admission that the disturbance is persistent, not episodic, and that a receiver sitting on a bridge or a survey deck cannot be assumed to be operating in a clean electromagnetic environment. For anyone running dynamic positioning (DP) or precise survey work in the Barents Sea and the wider High North, that is the operative fact. The monitoring stations do not fix your position – they confirm that the medium your position depends on is contested.

Denial and deception: two failure modes, one root cause

Jamming and spoofing are often lumped together, but they attack the positioning chain differently and demand different defences. The common root cause is the same physical vulnerability: civil GNSS signals arrive at the antenna at roughly −160 dBW, weaker than the receiver’s own thermal noise floor. They are recovered only through the processing gain of correlating against a known code. A transmitter of a few watts, well within reach of small mobile equipment, raises the noise floor enough to break that correlation across tens of kilometres. This is denial – the receiver loses lock, the position solution degrades or drops out, and the failure is at least honest about itself.

Spoofing is the more dangerous mode because it exploits the same weak-signal assumption to lie rather than to deny. A spoofer transmits counterfeit signals that the receiver acquires in preference to, or alongside, the genuine ones, and computes a position and time from false ranging data. The output is a valid-looking fix – full satellite count, plausible dilution of precision, no obvious alarm – that is simply wrong. A capable spoofer can pull the solution away slowly, walking the reported position at tens of centimetres per second so that no single epoch looks anomalous. The distinction matters operationally: denial triggers your loss-of-position procedures, while a well-executed spoof keeps your automation confidently acting on a false input.

Neither the source reporting nor sound engineering practice supports treating this as a receiver-quality problem. No civil-grade receiver, however good its front end, authenticates a legacy GPS L1 C/A or GLONASS signal, because those signals carry no cryptographic proof of origin. The vulnerability is in the signal design and the link budget, not in the box.

Why the fix looks fine while it is not

The detection gap is the heart of this failure mode, and it is where offshore teams are most exposed. Several standard safeguards fall short against a competent interference source.

Receiver Autonomous Integrity Monitoring (RAIM) tests the consistency of the range measurements against each other. It is effective at catching a single bad satellite, but a spoofer that generates a self-consistent constellation presents a set of ranges that agree with one another. The internal cross-check passes because every measurement is drawn from the same false model. RAIM was built to detect a random fault, not a coordinated deception.

Carrier-to-noise-density (C/N0) monitoring and automatic gain control (AGC) telemetry are more useful, because broadband jamming forces the AGC to react and drives C/N0 down across all channels at once. But few operations log these parameters, fewer still alarm on them, and a matched-power spoof that replaces rather than swamps the genuine signals can hold C/N0 in a normal band. The information that would expose the attack is usually available in the receiver’s raw output and simply not being watched.

The operational layer compounds the gap. On a DP desk, the position reference systems (PRS) feed a weighted model, and the operator’s trust in a green DGNSS status is well earned from thousands of clean hours. When two independent DGNSS references are both derived from the same spoofed satellite signals – different correction services, different frequencies, but the same underlying constellation – they agree with each other and the DP model’s median voting sees no divergence to reject. That is a common-mode failure dressed as redundancy. On the survey side, a slow position walk produces a systematic error that stays inside the epoch-to-epoch noise, so real-time quality checks that watch scatter rather than absolute truth will not flag it.

The Arctic sharpens every one of these edges

High-latitude operations start from a weaker position before any interference. Satellite geometry is poorer for the near-zenith fixes that vertical accuracy depends on, and the geostationary augmentation satellites that carry EGNOS and other SBAS corrections sit low on the horizon or below it above roughly 72°N, so wide-area differential coverage thins out exactly where the border regions are. Ionospheric scintillation in the auroral zone adds its own signal fading, which masks the early signature of interference and gives a spoofer natural cover. There is also little terrestrial fallback – no dense network of tide gauges, reference stations, or radio positioning infrastructure to lean on. The environment that makes the Barents strategically sensitive is the same one that removes your alternatives.

Where this bites: DP station-keeping and survey integrity

The consequences separate into two distinct operational risks, and both deserve to sit in the risk register explicitly.

For DP operations, the concern is a spoof-induced position offset that the control system corrects against. If the reported position walks, the DP model commands thrust to hold the false position, and the vessel physically moves – a drive-off rather than a drift-off. During close-quarters work this is the dangerous case: diving with divers in the water, a walk-to-work gangway landed on a fixed structure, a construction lift over a subsea asset, or ROV operations near a wellhead. The vessel’s own instruments report that it is on station while it is being driven off it. Guidance under IMCA M 103 and the activity-specific operating guidelines (ASOG) framework in IMCA M 220 assume the PRS mix provides genuine independence; a shared GNSS vulnerability across two or three references breaks that assumption. Any DP FMEA that lists two DGNSS units as independent references needs to be re-read with spoofing as a common-mode initiator, because the worst-case failure design intent has to account for losing every satellite-derived reference at once.

For survey and positioning work, the failure is quieter and can be more expensive downstream. A spoofed or jammed solution that still reports a plausible fix injects a systematic horizontal error into everything time-tagged against it – multibeam bathymetry, pipeline and cable as-builts, boulder and debris clearance, UXO surveys, metrology. IHO S-44 Edition 6 sets total horizontal uncertainty at the 95% confidence level, and a spoof that shifts the position by a few metres blows the Order 1 or Special Order budget while the logged uncertainty statistics look compliant. The error is discovered, if at all, when the deliverable fails to tie in against an independent control or a later survey. GNSS also disciplines the timing chain: the pulse-per-second that synchronises sensor data and, in many installations, telecom equipment. A spoofed time solution corrupts data alignment and heading integration even when the horizontal position looks acceptable.

Building positioning that survives a contested spectrum

The defensible response is architectural. We will not out-power a jammer or out-clever a spoofer with a single receiver, so our objective is a positioning system that detects interference early, degrades gracefully, and never relies on GNSS as a single trusted source. The following steps are concrete and mobilisable.

  • Log and alarm on interference signatures. Configure receivers to output per-satellite C/N0 and AGC, log them continuously, and set alarm thresholds so that a broadband drop or an AGC swing raises a bridge and survey alert. This is the cheapest defence and the one most often left unimplemented.
  • Enable authenticated signals. Use receivers that support Galileo Open Service Navigation Message Authentication (OSNMA), now operational, which lets the receiver verify that the navigation message originated from the constellation rather than a spoofer. Combine it with multi-constellation, multi-frequency tracking (GPS, Galileo, GLONASS, BeiDou across L1/L2/L5 and E1/E5) so that denial of one band or one system is not denial of position.
  • Couple GNSS to inertial, tightly. A tightly coupled GNSS/INS using a marine FOG-grade IMU can coast through jamming outages of seconds to minutes and, more importantly, will fight a spoof: the inertial solution diverges from the counterfeit GNSS, and that divergence is a detectable, alarmable quantity. For extended holdover, a navigation-grade IMU extends the drift budget, at cost.
  • Guarantee non-GNSS reference diversity for close work. For DP within reach of a structure, keep at least one PRS that owes nothing to satellites: laser reference (Fanbeam or CyScan), microwave radar (RadaScan), taut wire, or an acoustic reference via HPR/USBL. Where sustained absolute positioning is needed away from structures, deploy an LBL array – a minimum four-transponder box with baseline spacing matched to the work area – as an independent check on the GNSS solution.
  • Put GNSS loss into the ASOG with defined triggers. Under IMCA M 220, write specific green/yellow/red criteria for degraded and lost GNSS, including AGC/C/N0 alarm states, and define set-back distances and hold points so the operator has a rehearsed response rather than a judgement call. Prove it in annual DP trials with a simulated GNSS reference loss, and confirm the model rejects a walked position rather than chasing it.
  • Protect the timing chain. Fit an OCXO or chip-scale atomic clock holdover so the pulse-per-second survives a GNSS outage and a spoofed time is not silently accepted as truth for data time-tagging.
  • Run real-time positioning QC on absolute agreement, not just scatter. Continuously compare independent sources – USBL against GNSS, DVL/INS dead reckoning against the fix – and alarm on divergence beyond the survey uncertainty budget. The joint IMCA/IOGP guidance on GNSS positioning for the oil and gas industry sets the expectation for redundancy and cross-checking; apply it as a live monitor, not a mobilisation checkbox.
  • Assess interference risk before mobilisation. Check aviation jamming NOTAMs and published interference reporting for the operating area, and establish a reporting line to Nkom or the relevant authority so your own observations feed the monitoring effort. A region where a national regulator is installing detection stations is one where the interference risk assessment belongs in the project HIRA (Hazard Identification and Risk Assessment).

The underlying lesson generalises well beyond the Barents. GNSS is a shared, unauthenticated utility, and the moment it becomes contested, any architecture that treats it as a single source of truth inherits that contest as a single point of failure. The teams that will keep working reliably in the High North are the ones that already designed for its loss – with independent references, inertial continuity, and QC that watches absolute agreement rather than trusting a green light.


Based on: Norway placing more monitoring stations to measure Russian GNSS interference

Enjoyed this analysis?