If you wish to contribute or participate in the discussions about articles you are invited to contact the Editor

Galileo Signal Authentication Service

From Navipedia
Jump to navigation Jump to search


GALILEOGALILEO
Title Galileo Signal Authentication Service
Edited by European Commission
Level Intermediate
Year of Publication 2026


The GALILEO System is an independent, global, European-controlled, satellite-based navigation system and provides a number of services to users equipped with Galileo-compatible receivers.[1]

The GALILEO Signal Authentication Service (SAS) enables an authenticated positioning service by complementing the Open Service Navigation Message Authentication (OSNMA) Service with E6-based ranging authentication capabilities. The SAS service is supported through a SAS server which is accessible through terrestrial means.

The Galileo Signal Authentication Service resulted from the re-scoping of the former Galileo Commercial Service (CS).[2] It is a free-of-charge service targeting civil applications, satisfying the demand for spoofing protection beyond the data authentication offered by OSNMA. The SAS service is currently under an initial testing capability, in view of an Initial Service declaration in 2027.

Main Concept

The SAS service offers ranging authentication based on the Galileo encrypted E6-C pilot signal component. Before operation, users can download so-called Re-Encrypted Code Sequences (RECS) from the SAS server. These RECS are subsequences of the E6-C encrypted signal, and re-encrypted using an OSNMA key that is only transmitted after the RECS.

During operation, a receiver records an E6-C signal snapshot of some tens of milliseconds. Then, after a delay, the OSNMA key is received that can be used to decrypt the RECS and to obtain the so-called ECS (Encrypted Code Sequence). The receiver can then correlate the ECS with the recorded snapshot for each satellite. Only in case of an authentic E6-C signal, a correlation peak can be found. The process is illustrated in the figure below. By making use of authenticated E6-C pseudoranges and authenticated E1B data, under some assumptions, a signal- and data-authenticated PVT can be obtained. Implementation aspects are discussed below.

The core concept of SAS is that, although the RECS can be downloaded in advance, the ECS are only disclosed after their transmission (i.e. after the receiver has already recorded the snapshot). Thus, it is not possible for a spoofer to generate the authentic ECS in advance. As the delayed disclosure of the key vs. the RECS is part of the core concept, sufficiently accurate time synchronisation in the receiver is required, as is the case for OSNMA.[3]

Galileo SAS operation. Left: Download RECS from the server. Center: Capture an E6-C snapshot. Right: Decrypt RECS with OSNMA and perform a-posteriori correlation with E6-C snapshot.

System Level Implementation

At the signal-in-space level, the SAS service consists of the continuous encryption of the E6-C signal component as transmitted by Galileo satellites.

At the ground infrastructure level, the Galileo Service Centre hosts the SAS server which provides RECS, BGD and SLOG files on request:

  • The RECS files contain the re-encrypted code sequences with a configurable duration (up to 16 milliseconds) and period (down to 200 milliseconds). The period corresponds to the Time Between Authentications (TBA). Furthermore, a configurable “randomisation flag” defines whether the start of the RECS within each period is predictable or not. The structure of a RECS period is shown in the figure below.
  • The BGD (Broadcast Group Delay) files contain estimates of the BGDs that are required for applying I/NAV clock corrections to the E6-C pseudorange measurements obtained from the ECS correlations.
  • The SLOG (SAS Status and Log) files provide SAS status information and related events.

Receivers can connect to the SAS server over HTTPS to request RECS, BGD and SLOG files using a query with the desired configuration parameters. The files can be requested for up to one week in advance, so the autonomy period for the user can be up to one week. The files are signed using official Galileo key material and receivers must verify these signatures. The SAS server also acts as an NTS (Network Time Security) server, offering authenticated time synchronisation.

Structure of a RECS period

Receiver Implementation Aspects

The full details of SAS, including the format of the server queries and the required cryptographic operations, will be described in the Galileo SAS interface specification and the Galileo SAS SDD (Service Definition Document), both to be published soon, or other Galileo documentation when the service is officially launched. Preliminary specifications have already been published but are subject to change.[4]

Galileo SAS allows the receiver to obtain authentic data through OSNMA and spreading code-protected E6-C measurements through the RECS correlation. These elements allow to compute an authenticated PVT solution under certain circumstances and assumptions. A SAS receiver may include techniques such as Vestigial Signal Search (VSS) to detect, and even mitigate, meaconing signals. Such aspects which need to be considered to obtain an authenticated PVT will be described in the Galileo SAS Receiver Guidelines document which will be published by the programme.

Galileo SAS Roadmap

The SAS roadmap consists of the following phases:

  • Initial Capability (Phase 0): In this phase, E6-C encryption is activated first on the L3 satellites (GSAT0201 and GSAT0202) and then on the full constellation. Since December 2025, the E6-C encryption is activated permanently on the L3 satellites. During this phase, experimentation takes place using a prototype SAS server and prototype SAS receivers.
  • Initial Service (Phase 1): The Initial Service Declaration in Phase 1 will allow global and free use of SAS. It is foreseen for 2027.
  • Full Service (Phase 2): The Full Service Declaration will introduce improvements with respect to Phase 1. This is foreseen in the next years and is under consolidation with the Galileo 2nd Generation (G2G) schedule, including SAS improvements together with new authentication signals.

References