Standards Unpacked (Geodesy) 9 min read

Spoofed DGNSS corrections offshore: what to do before authentication arrives

Positioning & Geodesy Working Group ·

Executive Summary

Falsifying augmentation correction messages, rather than the ranging signal, lets an attacker push an unbounded position bias into a DGNSS solution while leaving GNSS-derived velocity and acceleration untouched – defeating the usual inertial cross-check. The vulnerability is amplified by SBAS/GBAS message formats that still permit Selective-Availability-era correction magnitudes long after SA was switched off. Cryptographic authentication for SBAS is years away, so the near-term defence is to bound acceptable correction magnitudes to real constellation performance and to keep position reference systems genuinely independent at the correction-source level. Survey and DP managers should treat correction-stream integrity as a distinct failure mode from signal spoofing and screen for it now.

What the SBAS message-spoofing work actually flags

InsideGNSS recently set out a threat that sits to one side of the jamming-and-spoofing coverage now common in the trade press: deliberate corruption of the correction and integrity messages that augmentation systems broadcast. Its focus is the satellite- and ground-based augmentation systems (SBAS and GBAS) that civil aviation relies on for its most demanding accuracy and integrity needs, but the engineering carries straight across to marine positioning.

Message spoofing means falsifying the correction data itself rather than the ranging signal. The article gives three reasons this is attractive to an attacker. It can be mounted with a single PRN. It need not overpower any live broadcast. And it can drive a bias into the computed position while leaving GNSS-derived velocity and acceleration untouched, which quietly defeats the obvious defence of comparing the GNSS position against an inertial or Doppler-derived motion estimate.

The sharpest point concerns magnitude. When SBAS and GBAS were designed, GPS still ran Selective Availability, the deliberate range-domain degradation that GPS eliminated in 2001. To correct for SA, the augmentation message formats allowed very large corrections: more than 250 m for satellite clock error and over 128 m in each of three orbital axes. GPS has since committed to far smaller errors, but the L1 SBAS and GBAS standards were fixed before SA was removed, so those generous limits remain in the message definitions. The best answer is cryptographic authentication, and a backward-compatible scheme for SBAS is in development; the source is candid that standardising and fielding it will take several more years. GBAS already carries a simple authentication in its VHF Data Broadcast, but only to the extent of tying message slots to a named ground station. In the interim, simpler methods have been proposed to bound how large an error a spoofed message can force.

A Selective Availability hangover, still baked into the message format

Understand why the bounds are so loose and the mitigation becomes obvious. Under SA, the broadcast satellite clock could be dithered by tens of metres, so an augmentation system needed the headroom to correct errors of that order. Sizing the fast and long-term corrections to cover well over 100 m was sound engineering for the constellation of the day.

That day ended more than two decades ago. Post-SA residual clock and ephemeris errors are metre-class, and the corrections a real SBAS actually applies are correspondingly small. The message format never caught up. A receiver that accepts any correction up to the standardised ceiling will therefore accept a fabricated correction far larger than anything the genuine system would ever transmit, and it will do so without objection because the value is technically legal.

The proposed fix is to stop treating the standard’s maximum as the acceptance threshold. If a receiver rejects corrections whose magnitude exceeds what the current constellation could plausibly need – a bound set by real post-SA performance rather than legacy worst case – the attacker’s room to manoeuvre collapses, and the worst-case injected error is capped at the tighter bound. This is a screening rule, not authentication. It proves nothing about provenance. What it does is deny the large, unbounded error that makes message spoofing worth attempting.

Why this lands on the survey desk, not just the flight deck

Marine survey rarely runs aviation SBAS as its primary correction source. Offshore spreads lean on commercial precise point positioning and PPP-RTK delivered over L-band geostationary links, on IALA medium-frequency radiobeacon DGNSS carrying RTCM SC-104 messages, and on network RTK streamed over IP. The delivery mechanisms differ, but the exposure is identical in principle: corrections are data, and any data stream that is neither authenticated nor origin-verified can be forged, replayed, or selectively altered.

The consequence is measured against the accuracy budgets we already work to. IHO S-44 (Edition 6) sets total horizontal uncertainty of 2 m for Special Order and 5 m plus 5% of depth for Order 1a, with Exclusive Order tighter still. A correction-message spoof that injects even a few metres of slowly-ramping horizontal bias will breach a Special Order or Exclusive Order THU allowance without any accompanying signal-quality alarm. For construction support, touchdown monitoring, or metrology, a metre-scale undetected bias is not a nuisance; it is a wrong answer delivered with full confidence.

Dynamic positioning is exposed through the same door. IMCA guidance for DP operations calls for redundant, independent position reference systems, and DGNSS is almost always one of them. If a slow, spoofed bias is fed into the position model, the DP controller will hold the vessel to a drifting reference and the operator will see a stable, healthy screen. The integrity case for augmentation over DP is worth reading alongside this, and we have set out the argument in our look at LEO augmentation and the DP integrity case.

The blind spot: why your inertial cross-check will not catch it

The most instructive detail in the source is that a correction-message spoof biases position without biasing velocity or acceleration. That property matters because so much of our integrity architecture assumes the two move together.

GNSS velocity is derived from carrier-phase Doppler and the difference of successive position or phase measurements. It depends on the ranging observables, not on the differential correction applied to the pseudorange. A falsified correction shifts the corrected position but leaves the instantaneous rate estimates essentially clean. The familiar comparison – GNSS position and velocity against an INS coasting solution, against a DVL over the seabed, against gyro heading – is calibrated to catch a jump or a rate mismatch. A correction spoof gives it neither. The INS and the GNSS will agree on how fast the vessel is moving even as they diverge on where it is, and if the bias is ramped in gently the innovation sequence in the navigation filter stays inside its gate.

A second common-mode trap sits behind the first. Running two or three GNSS receivers as independent position references buys nothing against this attack if all of them consume the same corrupted correction stream. They will agree with each other, beautifully, on the wrong position. Independence has to exist at the correction-source layer, not merely at the antenna and receiver layer, or the redundancy is cosmetic.

It is also worth being precise about what authentication schemes do and do not cover, because the terminology invites conflation. Galileo OSNMA (Open Service Navigation Message Authentication) authenticates the navigation message on the ranging signal – it tells you the satellite data is genuine. It says nothing about the integrity of a separate SBAS or commercial differential correction stream. Likewise, streaming NTRIP over TLS secures the transport pipe and the caster connection; it does not, by itself, prove that the reference-station data injected upstream is honest, nor does it defend a one-to-many L-band broadcast that has no per-user handshake. Encryption of a commercial service protects confidentiality and raises the bar, but encryption is not the same as end-to-end message integrity against replay.

Bounding the worst case now: practical countermeasures

Cryptographic authentication is the destination, and firmware roadmaps should track it, but nothing above needs to wait for it. The following steps are things a survey or positioning team can specify and test on the current spread.

1. Screen correction magnitudes against real performance, not legacy ceilings

Adopt the core idea from the source. Where the receiver or the positioning-processing software exposes it, set acceptance limits on correction magnitude sized to modern constellation behaviour – metre-class residuals – rather than the SA-era maxima still allowed by the message standard. Reject or flag any correction that exceeds a plausible physical bound. This caps the worst-case injected error and costs nothing in availability under normal conditions, because genuine corrections never approach those legacy limits.

2. Make position references independent at the correction source

For DP2/DP3 and for critical survey work, ensure at least two position solutions draw on genuinely separate correction inputs – different service providers, different delivery paths (L-band versus IP), or a different constellation mix. Better still, hold one reference that does not depend on any external correction at all: a well-aided INS with acoustic aiding (USBL or LBL) provides a position estimate immune to correction-message spoofing over the timescales that matter, and its slow drift signature is exactly what you want to compare against.

3. Reconfigure integrity monitoring to look for slow divergence

Stop relying only on step-change and rate-mismatch alarms. Add a monitor that compares the GNSS position against an inertial or acoustic coasting solution over a meaningful window – minutes, not seconds – and set the divergence threshold with reference to the S-44 THU budget for the order of survey in hand. If Special Order demands 2 m THU, a persistent GNSS-versus-INS separation approaching 1 m deserves an alert well before it becomes an error in the record.

4. Harden the ranging layer as well, and keep the layers distinct in the risk register

Enable OSNMA where receivers support it and run multi-constellation, multi-frequency to reduce the value of any single-signal attack. Treat this as defence of the ranging observables, logged separately from correction-stream integrity, so the two failure modes are assessed on their own terms. The broader discipline here – treating positioning QA as a quantified integrity problem rather than a pass/fail check – is something we have argued at length in the context of GNSS integrity rigour.

5. Log the correction data and rehearse the response

Record the raw correction stream alongside the position solution and retain it for post-processing and audit. A spoof that evades real-time detection is often obvious in reprocessing, and the log is the only way to reconstruct what the receiver was actually fed. Fold correction-message spoofing into the positioning risk assessment and the DP ASOG as a named scenario with a defined response: which reference to drop, when to fall back to the correction-independent solution, and who has authority to suspend the operation.

6. Push provenance requirements to your correction providers

Ask commercial PPP and network-RTK suppliers directly what integrity protection their stream carries – authentication, replay resistance, reference-station monitoring – and make it a procurement criterion. The market is moving on jamming and signal spoofing; correction-message integrity deserves the same scrutiny. The regulatory direction of travel supports the argument, and the operational reading we take from aviation’s stance is set out in our note on ICAO’s GNSS jamming position.

The underlying lesson is a standards lesson. A worst-case limit written for one operational reality – Selective Availability – has quietly become an attack surface in another. Until authentication closes the gap, our defence is to bound what a correction is allowed to be, to keep our references independent where it counts, and to watch for the slow, silent bias that our usual alarms were never built to see.


Based on: What simple measures can be taken to limit the potential impact of spoofing of differential GNSS correction messages?

PGW

Published by

Positioning & Geodesy Working Group

GNSS, INS/IMU & Coordinate Systems

A working group of positioning specialists covering GNSS, inertial navigation, datum transformations, and geodetic network design for marine and land survey operations.

GNSS Inertial Navigation Geodesy Coordinate Systems

Enjoyed this analysis?