If you wish to contribute or participate in the discussions about articles you are invited to contact the Editor

Galileo Open Service Navigation Message Authentication: Difference between revisions

From Navipedia
Jump to navigation Jump to search
Major update (EC(IFH & TW))
 
(19 intermediate revisions by one other user not shown)
Line 1: Line 1:
{{Article Infobox2
{{Article Infobox2
|Category=GALILEO
|Category=GALILEO
|Editors=GMV
|Editors=GMV, European Commission
|Level=Basic
|Level=Basic
|YearOfPublication=2021
|YearOfPublication=2026
|Logo=GMV
|Title={{PAGENAME}}
|Title={{PAGENAME}}
}}
}}


Galileo OS-NMA (Open Service – Navigation Message Authentication) represents an authentication mechanism that allows a GNSS receiver to verify the authenticity of the GNSS information and of the entity transmitting it, to ensure that it comes from a trusted source. Authentication is an intrinsic GNSS capability remaining internal to the GNSS receiver, without any new interfaces to the avionics.  
OSNMA (Open Service Navigation Message Authentication) is Galileo’s navigation message [[GNSS Authentication and encryption|authentication]] service. It is provided worldwide and free of charge. Its purpose is to give receivers the assurance that the received navigation data (ephemerides, clocks, satellite status, timing and other parameters) originates from the Galileo system itself and has not been modified, thereby increasing the ability to detect spoofing attacks.


Galileo OS-NMA will be a free-of-charge service which will become available in the near-term evolutions of the Galileo Full Operational capability (FOC), potentially for 2022-2023.  
The Galileo OSNMA concept design took place between 2013 and 2015, followed by its formal introduction into the Galileo legal basis and service baseline<ref>[https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32017D0224 Commission Implementing Decision (EU) 2017/224]</ref><ref>[https://doi.org/10.1002/navi.125 Fernandez-Hernandez, I., et al. (2016). A Navigation Message Authentication Proposal for the Galileo Open Service. J. Inst. Navig., 63(1), pp. 85–102]</ref>. Following the development phase, the OSNMA Internal Testing phase started in October 2020<ref>[https://www.euspa.europa.eu/newsroom-events/news-archive/tests-galileo-osnma-underway Tests of Galileo OSNMA underway]</ref>. The OSNMA Public Observation Phase began in November 2021<ref>[https://www.gsc-europa.eu/news/euspa-launches-the-osnma-public-observation-test-phase EUSPA launches the OSNMA Public Observation Test Phase]</ref>, and finally the Initial Service was declared Operational on 24 July 2025, becoming the first authentication service offered by a GNSS<ref>[https://insidegnss.com/galileo-leads-the-way-in-gnss-spoofing-protection-with-osnma/ Galileo Leads the Way in GNSS Spoofing Protection with OSNMA]</ref>.


==Introduction to Galileo OS-NMA feature==
==Introduction to Galileo OSNMA==


Galileo OS-NMA feature consists of digitally signing the Open Service Navigation message in the E1 band, making use of forty reserved bits (“Reserved 1”) in the Galileo E1B data message (I/NAV) and the Timed Efficient Stream Loss-Tolerant Authentication (TESTA) protocol<ref>I. Fernández-Hernández, V. Rijmen, G. Seco-Granados, J. Simon, I. Rodríguez, and J. David Calle, “A Navi-gation Message Authentication Proposal for the Galileo Open Service,” Navigation, Journal of The Institute of Navigation, vol. 63, no. 1, pp. 85-102</ref>, thus keeping the rest of the navigation message unencrypted<ref>[https://www.gsa.europa.eu/sites/default/files/calls_for_proposals/annex_1-rd4.pdf Galileo Navigation Message Authentication Specification for Signal-In-Space Testing v1.0]</ref> . The use of these reserved bits allows backwards compatibility with older versions of the navigation message ICD.  
Galileo OSNMA provides authentication of the Open Service navigation message transmitted in the E1 band. It uses a 40-bit field of the Galileo E1-B data message (I/NAV), previously unused, and therefore backward compatible with older versions of the Galileo OS Signal-in-Space ICD<ref>[https://www.gsc-europa.eu/sites/default/files/sites/all/files/Galileo_OS_SIS_ICD_in_force.pdf Galileo Open Service Signal-in-Space Interface Control Document]</ref>. OSNMA transmits Message Authentication Codes (MACs) authenticating the navigation data and the related keys with a delayed disclosure of more than 30 seconds. The current OSNMA field is composed of two parts<ref name="OSNMA_SISICD">[https://www.gsc-europa.eu/sites/default/files/sites/all/files/Galileo-OSNMA-SIS-ICD_in_force.pdf Galileo Open Service Navigation Message Authentication Signal-in-Space Interface Control Document]</ref>:
*The Header and Root Key (HKROOT) section (first 8 bits) includes the global headers and the Digital Signature Message (DSM), with information to authenticate the TESLA Root Key and other cryptographic material.
*The MAC and Key (MACK) section (next 32 bits) contains the Message Authentication Codes (MACs) and associated keys.


Galileo_OS_NMA_SIS.png
[[File:Galileo_OS_NMA_SIS.png|500px|OSNMA field in I/NAV word<ref name="OSNMA_SISICD"/>|centre|thumb]]


The OSNMA field is composed of two parts:
==Galileo OSNMA cryptographic functions and protocols==
* The HKROOT section (first 8 bits) includes the global headers and the Digital Signature Message (DSM.
* The MACK section (next 32 bits) contain the MACs and associated keys, delivered later.


==TESTA protocol==
The Galileo OSNMA protocol is based on existing cryptographic standards adapted to GNSS. Its core is based on lightweight cryptography standards<ref>[https://www.iso.org/obp/ui/en/#iso:std:iso-iec:29192:-7:ed-1:v1:en Information security - Lightweight cryptography - Part 7: Broadcast authentication protocols, ISO/IEC Standard 29192-7]</ref>, in particular an adaptation of the Timed Efficient Stream Loss-Tolerant Authentication (TESLA) protocol<ref>[https://doi.org/10.1109/SECPRI.2000.848446 Perrig, A., et al. (2000). Efficient authentication and signing of multicast streams over lossy channels. Proc. 2000 IEEE Symposium on Security and Privacy, pp. 56-73]</ref>. TESLA is particularly suitable for OSNMA because it requires relatively low bandwidth for authentication data and is robust to data loss. However, as a delayed-key-disclosure protocol, it requires the receiver to have a sufficiently accurate time estimate before processing OSNMA data<ref name="OSNMA_RXGL">[https://www.gsc-europa.eu/sites/default/files/sites/all/files/Galileo-OSNMA-RX-Guidelines_in_force.pdf Galileo Open Service Navigation Message Authentication Receiver Guidelines ]</ref>.


Galileo OS-NMA authentication capability is based on the use of TESTA protocol. One of the greatest advantages of this protocol is that it requires low bandwidth to transmit the authentication information, together with a tolerance to data loss in case a message is lost.  
The TESLA implementation used for Galileo OSNMA has two main optimizations with respect to the standard protocol. Firstly, it uses a single key chain for all the satellites, so users will be able to receive the key by any satellite in view. Secondly, satellites transmitting OSNMA can “cross-authenticate” other satellites.


The main idea of TESLA protocol is that the key used in the authentication process belongs to a chain generated using a one-way function F, also called hash function. The chain starts with a secret seed key; and each element of the chain can be constructed by hashing the previous element. This one-way function cannot be used to predict keys. This implies that the receiver must possess some information (the root key) certified as correct independently from the information sent through the Signal in Space.  
TESLA uses a one-way chain of cryptographic keys generated by repeatedly applying a one-way function based on a cryptographic hash. The one-way property makes it computationally infeasible to derive future undisclosed keys from already disclosed keys. But a receiver can verify a newly disclosed key against an earlier authenticated element of the chain. This implies that the receiver must have a previously disclosed key (such as the Root Key) certified as correct.


The TESLA used for Galileo OS-NMA has been optimized to use a single key for all the satellites, so users will be able to receive the key by any satellite in view. This opens the door to authenticate non-Galileo GNSS satellites.
The TESLA Root Key is authenticated through an ECDSA digital signature using an OSNMA Public Key available to the receiver. Public Keys transmitted through the Signal-in-Space can in turn be authenticated using the OSNMA Merkle Tree, whose root acts as a trust anchor, as per the Galileo OSNMA Signal-In-Space ICD<ref name="OSNMA_SISICD"/>. The required cryptographic material, including Public Keys, Merkle Tree data and associated certificates, is also distributed through the OSNMA Internet Data Distribution (IDD) interface<ref>[https://www.gsc-europa.eu/sites/default/files/sites/all/files/Galileo-OSNMA-IDD-ICD_in_force.pdf Galileo Open Service Navigation Message Authentication Internet Data Distribution Interface Control Document]</ref>.


==Authentication based on Galileo OS-NMA==
==Authentication based on Galileo OSNMA==


The way in which authentication based on Galileo OS-NMA works can be summarized as follows:
The way in which authentication based on Galileo OSNMA works can be summarized as follows:
* The receiver demodulates the navigation data and a Message Authentication Code (MAC) that authenticates the plaintext navigation message.
*The receiver demodulates the navigation data and the Message Authentication Code (MAC) that will authenticate the navigation data.
* The key required to authenticate the MAC is broadcast by the system with some delay.
*The receiver demodulates the key required to authenticate the MAC. This key is broadcast by the system with a predefined delay with respect to the associated MAC.
* The receiver demodulates the key.  
*The receiver authenticates the key with a previous key from the chain that is considered authentic, or from the Root Key. As explained before, this key is part of a pre-generated one-way chain whose root is public, and which is transmitted in reverse order with respect to its generation.
* The receiver authenticates the key with a previous key from the chain that is considered authentic or from the root key. As explained before, this key is part of a pre-generated one-way chain whose root is public, and which is transmitted in reverse order with respect to its generation
*The receiver locally re-computes the MAC with the navigation data and the key, which should match the previously received MAC. If this is the case, the navigation data can be considered as authentic.
* The receiver re-generates the MAC key with the data, which should match the previously received MAC.


A summary of the proposed Galileo OS-NMA architecture is shown below.
The Galileo programme recommends to implement OSNMA in receivers in combination with other anti-spoofing measures. Also, the partial unpredictability of the OSNMA bits can be exploited by suitably designed receivers to provide an additional level of protection at signal/ranging level against certain replay and spoofing attacks<ref name="OSNMA_RXGL"/>.


==Credits==
==Galileo OSNMA architecture==
This article has been created based on Galileo Navigation Message Authentication Specification document  and other information as indicated through references.


[[File:Galileo_Art.png‎‎|400px|Galileo Constellation (artistic interpretation)|left|thumb]]
A summary of the Galileo OSNMA architecture is shown below. In order to fit Galileo OSNMA into the Galileo infrastructure within schedule and cost, the OSNMA module was developed as part of the European GNSS Service Centre, located in Torrejón de Ardoz.
[[File:Galileo_OS_NMA_Architecture.png|700px|Galileo OSNMA Architecture<ref>[https://www.euspa.europa.eu/sites/default/files/expo/2.4_moises_navarro-gallardo_-_airbus_-_guidelines_os_nma_implementation_in_smartphones.pdf Navarro-Gallardo, M. (2019). Guidelines: OS-NMA implementation in smartphones]</ref>|centre|thumb]]
 
==Galileo OSNMA adoption and prospects==
 
During the OSNMA public observation phase (2021-2025), Galileo OSNMA started to be integrated by major receiver manufacturers. This was accelerated at the OSNMA official launch in July 2025<ref>[https://www.u-blox.com/en/technologies/osnma-galileo-spoofing U-blox (2025). Galileo OSNMA; The new message authentication feature]</ref><ref>[https://www.septentrio.com/en/learn-more/insights/osnma-latest-gnss-anti-spoofing-security Septentrio (2025). OSNMA: the latest in GNSS anti-spoofing security]</ref>. Since then, a growing number of GNSS receivers incorporate OSNMA as part of their anti-spoofing solutions for applications including road transport, timing and synchronisation, surveying, autonomous systems and other professional markets. EUSPA maintains a non-exhaustive list of receivers including OSNMA as part of their list of Galileo compatible devices<ref>[https://www.gsc-europa.eu/support-to-developers/galileo-compatible-devices/receivers-implementing-galileo-osnma Receivers implementing Galileo OSNMA]</ref>. OSNMA is also being incorporated as part of the next generation standards for civil aviation by the ICAO (International Civil Aviation Organization), envisaged to become applicable by 2028.
 
The Smart Tachograph is a special case of early OSNMA adoption<ref>[https://transport.ec.europa.eu/transport-modes/road/tachograph_en Tachograph - Mobility and Transport - European Commission]</ref>. The latest Smart Tachograph Regulations required the implementation of OSNMA as part of its technical specification. Thanks to that, since December 2025, all new heavy vehicles in Europe of more than 3.5 tonnes, like trucks and buses, carry OSNMA.
 
Galileo OSNMA is the world’s first civil GNSS authentication service, but other satellite navigation systems such as QZSS or GPS have since incorporated or are studying the incorporation of authentication to their signals. Galileo is also testing its new [[Galileo Signal Authentication Service|Signal Authentication Service]] and will improve its overall authentication capabilities as part of its 2<sup>nd</sup> Generation.
 
==Credits and further information==
 
This article has been created based on Galileo OSNMA specifications and other information as indicated through references. Further information about OSNMA can be found on the European GNSS Service Centre website<ref>[https://www.gsc-europa.eu/galileo/services/galileo-open-service-navigation-message-authentication-osnma Galileo Open Service Navigation Message Authentication (OSNMA)]</ref>. EUSPA also publishes regularly performance reports with the Galileo OSNMA performance in the last quarter<ref>[https://www.gsc-europa.eu/electronic-library/performance-reports/galileo-open-service-navigation-message-authentication-osnma Galileo Open Service Navigation Message Authentication (OSNMA) Quarterly Performance Reports]</ref>. Finally, OSNMA open source packages such as OSNMAlib facilitate implementation of the OSNMA protocol and provide some real-time monitoring capability<ref>[https://osnmalib.eu/ OSNMAlib]</ref>.


==References==
==References==

Latest revision as of 17:30, 3 October 2026


GALILEOGALILEO
Title Galileo Open Service Navigation Message Authentication
Edited by GMV, European Commission
Level Basic
Year of Publication 2026


OSNMA (Open Service Navigation Message Authentication) is Galileo’s navigation message authentication service. It is provided worldwide and free of charge. Its purpose is to give receivers the assurance that the received navigation data (ephemerides, clocks, satellite status, timing and other parameters) originates from the Galileo system itself and has not been modified, thereby increasing the ability to detect spoofing attacks.

The Galileo OSNMA concept design took place between 2013 and 2015, followed by its formal introduction into the Galileo legal basis and service baseline[1][2]. Following the development phase, the OSNMA Internal Testing phase started in October 2020[3]. The OSNMA Public Observation Phase began in November 2021[4], and finally the Initial Service was declared Operational on 24 July 2025, becoming the first authentication service offered by a GNSS[5].

Introduction to Galileo OSNMA

Galileo OSNMA provides authentication of the Open Service navigation message transmitted in the E1 band. It uses a 40-bit field of the Galileo E1-B data message (I/NAV), previously unused, and therefore backward compatible with older versions of the Galileo OS Signal-in-Space ICD[6]. OSNMA transmits Message Authentication Codes (MACs) authenticating the navigation data and the related keys with a delayed disclosure of more than 30 seconds. The current OSNMA field is composed of two parts[7]:

  • The Header and Root Key (HKROOT) section (first 8 bits) includes the global headers and the Digital Signature Message (DSM), with information to authenticate the TESLA Root Key and other cryptographic material.
  • The MAC and Key (MACK) section (next 32 bits) contains the Message Authentication Codes (MACs) and associated keys.
OSNMA field in I/NAV word[7]

Galileo OSNMA cryptographic functions and protocols

The Galileo OSNMA protocol is based on existing cryptographic standards adapted to GNSS. Its core is based on lightweight cryptography standards[8], in particular an adaptation of the Timed Efficient Stream Loss-Tolerant Authentication (TESLA) protocol[9]. TESLA is particularly suitable for OSNMA because it requires relatively low bandwidth for authentication data and is robust to data loss. However, as a delayed-key-disclosure protocol, it requires the receiver to have a sufficiently accurate time estimate before processing OSNMA data[10].

The TESLA implementation used for Galileo OSNMA has two main optimizations with respect to the standard protocol. Firstly, it uses a single key chain for all the satellites, so users will be able to receive the key by any satellite in view. Secondly, satellites transmitting OSNMA can “cross-authenticate” other satellites.

TESLA uses a one-way chain of cryptographic keys generated by repeatedly applying a one-way function based on a cryptographic hash. The one-way property makes it computationally infeasible to derive future undisclosed keys from already disclosed keys. But a receiver can verify a newly disclosed key against an earlier authenticated element of the chain. This implies that the receiver must have a previously disclosed key (such as the Root Key) certified as correct.

The TESLA Root Key is authenticated through an ECDSA digital signature using an OSNMA Public Key available to the receiver. Public Keys transmitted through the Signal-in-Space can in turn be authenticated using the OSNMA Merkle Tree, whose root acts as a trust anchor, as per the Galileo OSNMA Signal-In-Space ICD[7]. The required cryptographic material, including Public Keys, Merkle Tree data and associated certificates, is also distributed through the OSNMA Internet Data Distribution (IDD) interface[11].

Authentication based on Galileo OSNMA

The way in which authentication based on Galileo OSNMA works can be summarized as follows:

  • The receiver demodulates the navigation data and the Message Authentication Code (MAC) that will authenticate the navigation data.
  • The receiver demodulates the key required to authenticate the MAC. This key is broadcast by the system with a predefined delay with respect to the associated MAC.
  • The receiver authenticates the key with a previous key from the chain that is considered authentic, or from the Root Key. As explained before, this key is part of a pre-generated one-way chain whose root is public, and which is transmitted in reverse order with respect to its generation.
  • The receiver locally re-computes the MAC with the navigation data and the key, which should match the previously received MAC. If this is the case, the navigation data can be considered as authentic.

The Galileo programme recommends to implement OSNMA in receivers in combination with other anti-spoofing measures. Also, the partial unpredictability of the OSNMA bits can be exploited by suitably designed receivers to provide an additional level of protection at signal/ranging level against certain replay and spoofing attacks[10].

Galileo OSNMA architecture

A summary of the Galileo OSNMA architecture is shown below. In order to fit Galileo OSNMA into the Galileo infrastructure within schedule and cost, the OSNMA module was developed as part of the European GNSS Service Centre, located in Torrejón de Ardoz.

Galileo OSNMA Architecture[12]

Galileo OSNMA adoption and prospects

During the OSNMA public observation phase (2021-2025), Galileo OSNMA started to be integrated by major receiver manufacturers. This was accelerated at the OSNMA official launch in July 2025[13][14]. Since then, a growing number of GNSS receivers incorporate OSNMA as part of their anti-spoofing solutions for applications including road transport, timing and synchronisation, surveying, autonomous systems and other professional markets. EUSPA maintains a non-exhaustive list of receivers including OSNMA as part of their list of Galileo compatible devices[15]. OSNMA is also being incorporated as part of the next generation standards for civil aviation by the ICAO (International Civil Aviation Organization), envisaged to become applicable by 2028.

The Smart Tachograph is a special case of early OSNMA adoption[16]. The latest Smart Tachograph Regulations required the implementation of OSNMA as part of its technical specification. Thanks to that, since December 2025, all new heavy vehicles in Europe of more than 3.5 tonnes, like trucks and buses, carry OSNMA.

Galileo OSNMA is the world’s first civil GNSS authentication service, but other satellite navigation systems such as QZSS or GPS have since incorporated or are studying the incorporation of authentication to their signals. Galileo is also testing its new Signal Authentication Service and will improve its overall authentication capabilities as part of its 2nd Generation.

Credits and further information

This article has been created based on Galileo OSNMA specifications and other information as indicated through references. Further information about OSNMA can be found on the European GNSS Service Centre website[17]. EUSPA also publishes regularly performance reports with the Galileo OSNMA performance in the last quarter[18]. Finally, OSNMA open source packages such as OSNMAlib facilitate implementation of the OSNMA protocol and provide some real-time monitoring capability[19].

References

  1. ^ Commission Implementing Decision (EU) 2017/224
  2. ^ Fernandez-Hernandez, I., et al. (2016). A Navigation Message Authentication Proposal for the Galileo Open Service. J. Inst. Navig., 63(1), pp. 85–102
  3. ^ Tests of Galileo OSNMA underway
  4. ^ EUSPA launches the OSNMA Public Observation Test Phase
  5. ^ Galileo Leads the Way in GNSS Spoofing Protection with OSNMA
  6. ^ Galileo Open Service Signal-in-Space Interface Control Document
  7. ^ a b c Galileo Open Service Navigation Message Authentication Signal-in-Space Interface Control Document
  8. ^ Information security - Lightweight cryptography - Part 7: Broadcast authentication protocols, ISO/IEC Standard 29192-7
  9. ^ Perrig, A., et al. (2000). Efficient authentication and signing of multicast streams over lossy channels. Proc. 2000 IEEE Symposium on Security and Privacy, pp. 56-73
  10. ^ a b Galileo Open Service Navigation Message Authentication Receiver Guidelines
  11. ^ Galileo Open Service Navigation Message Authentication Internet Data Distribution Interface Control Document
  12. ^ Navarro-Gallardo, M. (2019). Guidelines: OS-NMA implementation in smartphones
  13. ^ U-blox (2025). Galileo OSNMA; The new message authentication feature
  14. ^ Septentrio (2025). OSNMA: the latest in GNSS anti-spoofing security
  15. ^ Receivers implementing Galileo OSNMA
  16. ^ Tachograph - Mobility and Transport - European Commission
  17. ^ Galileo Open Service Navigation Message Authentication (OSNMA)
  18. ^ Galileo Open Service Navigation Message Authentication (OSNMA) Quarterly Performance Reports
  19. ^ OSNMAlib