Galileo's Proposed Authentication Algorithm: Part 2 - Bert Hubert's writings
a day ago
- Galileo's OSNMA uses a hierarchical message structure: pages (40 bits for OSNMA: 8 HKROOT, 32 MACK), 15 pages per subframe, 24 subframes per frame.
- The HKROOT field carries the Digital Signature Message (DSM), which includes a signed root key and configuration parameters, transmitted over multiple subframes.
- The MACK field contains MAC signatures and keys, but not for the page it's in; it signs bundles of data from the transmitting satellite and others, including GPS and BeiDou.
- Key verification follows TESLA: keys are disclosed later, and receivers derive the key's position in the chain using timestamps and subframe rate, then verify against the signed root key from the DSM.
- OSNMA is complicated by constraints: simple satellite hardware (bent-pipe), limited ground uplink capacity, and the need to authenticate out-of-reach satellites and other GNSS systems.
- MACK blocks are per subframe (1-3 blocks per subframe), each containing MACs and a key; the key ID is computed from the timestamp and the number of blocks per subframe.