时分双工网络中的GNSS欺骗检测:基于3GPP标准的安全框架
GNSS Spoofing Detection in TDD Networks: A 3GPP Standards-Based Security Framework
浏览论文内容
中文总结 AI 辅助
研究TDD网络中GNSS欺骗检测问题,提出基于3GPP标准的检测和监控框架,引入定时警报等机制,经蒙特卡洛模拟,在特定条件下检测概率超95%,误报率低于1%,无需新接口,通过场景分析验证,为TDD网络安全提供保障。
中文摘要 AI 辅助
时分双工(TDD)移动网络要求同步精度达到±1.5微秒(3GPP TS 38.104),以全球导航卫星系统(GNSS)校准的主时钟作为主要定时源。GNSS欺骗如今是一种有记录的操作威胁,会破坏所有下游基站的定时,但3GPP管理框架(SA5)和安全框架(SA3)都未提供检测或报告此类攻击的标准化机制。本文提出了一种在现有3GPP管理结构内运行的检测和监控框架。该框架引入了与TS 28.111和TS 28.552一致的GNSS定时警报和性能计数器,一种拓扑感知相关机制,通过按服务主时钟对gNB-DU进行分组来对异常进行分类,以及一种将故障管理与SECHAND事件处理(TR 33.894)相桥接的安全事件。蒙特卡洛模拟表明,在配置良好的PTP网络条件下,对于高于0.5 ns/s的漂移率,检测概率超过95%,误报率低于1%。该框架无需新接口,与生成无关,并通过区分欺骗与信号丢失、设备故障和维护瞬变的场景分析进行了验证。
英文摘要
Time Division Duplex (TDD) mobile networks require synchronization accuracy of $\pm$1.5 $μ$s (3GPP TS 38.104), with GNSS-disciplined grandmaster clocks as the predominant timing source. GNSS spoofing -- now a documented operational threat -- can corrupt timing across all downstream base stations, yet neither the 3GPP management framework (SA5) nor the security framework (SA3) provides standardized mechanisms to detect or report such attacks. This paper proposes a detection and monitoring framework operating within existing 3GPP management structures. The framework introduces GNSS timing alarms and performance counters aligned with TS 28.111 and TS 28.552, a topology-aware correlation mechanism that classifies anomalies by grouping gNB-DUs by serving grandmaster, and a security event bridging fault management with SECHAND incident handling (TR 33.894). Monte Carlo simulation demonstrates detection probability exceeding 95% for drift rates above 0.5 ns/s with false positive rates below 1% under well-provisioned PTP network conditions. The framework requires no new interfaces, is generation-agnostic, and is validated through scenario analysis distinguishing spoofing from signal loss, equipment faults, and maintenance transients.