The European Space Agency (ESA)-funded PARTICLE project has demonstrated a multi-layered approach to assured positioning, navigation and timing (PNT), combining authenticated Galileo signals, receiver-based anti-spoofing and security enhancements for 5G positioning. Funded under ESA’s NAVISP program, the activity was led by Qascom, with partners Loctio and the University of Patras.
As critical infrastructure, transport and autonomous systems become increasingly dependent on positioning information, users need to ensure the authenticity and integrity of PNT data. Rather than relying on a single technology, PARTICLE developed a layered solution that integrates Galileo Open Service Navigation Message Authentication (OSNMA), Galileo E6 Signal Authentication Service (SAS), receiver-based interference and spoofing detection, and 5G positioning as a complementary source of navigation.
The consortium developed a GNSS/5G testbed incorporating both service-provider and user-terminal emulators. The platform includes cryptographic key management, a secure element for storing sensitive material, and real-time graphical interfaces to configure scenarios and monitor system performance. The GNSS user terminal is based on Qascom’s QN500-P resilient receiver, enhanced with OSNMA and E6 authentication capabilities.
The PARTICLE team presented the final results of the project during a recent ESA-hosted event. A key element, they said, of the validation program was a comprehensive threat assessment, following the ISO/IEC 27005 risk management methodology, which identified significant physical-layer vulnerabilities affecting both GNSS and 5G positioning.
All angles tested
For the 5G component, the project focused on securing observed time difference of arrival (OTDOA) positioning against false base stations, replay attacks and jamming. The team proposed and evaluated several complementary mitigation techniques, including encrypted positioning reference signals, embedded authentication, angular-based signal authentication, downlink-uplink handshaking and position-tracking anomaly detection. These techniques were assessed individually using the consortium’s VeriLoc simulation platform under both benign and hostile operating conditions.
GNSS testing showed that authenticated E6 signal processing successfully identified spoofing through code-phase inconsistencies, while the 5G evaluation showed that all proposed techniques reliably detected false base station attacks and achieved perfect detection of jamming. Angular-based authentication and downlink-uplink handshaking also proved particularly effective against replay attacks, while encrypted positioning reference signals prevented the synthesis of valid spoofing waveforms.
According to the consortium, the results provide a practical foundation for future resilient PNT receivers combining authenticated GNSS with secure terrestrial positioning. Future work will focus on integrating the secure element directly into the QN500-P hardware, combining multiple detection techniques into a unified architecture, and advancing the technology towards higher technology readiness levels while contributing to future standardization activities.






