Location and proof of location

How is GPS spoofing detected?

GPS spoofing is detected by looking for evidence that a position does not fit the real world. Receivers check signal strength and noise for counterfeit signals, systems compare the fix with motion sensors and the laws of physics, Galileo's OSNMA lets receivers authenticate navigation data, and phone operating systems flag locations that software has faked. No single check is conclusive, so detection combines several.

Learning objectives

After reading this article you will be able to:

  • Distinguish counterfeit radio signals from software mock locations on phones
  • Describe signal, sensor and physics checks that raise suspicion of spoofing
  • Explain how Galileo OSNMA authenticates navigation data and what receivers need

What a spoofer does

A spoofer broadcasts counterfeit satellite signals so that a receiver computes a wrong position or time. The European Union Aviation Safety Agency (EASA) describes spoofing as deceiving receivers into producing incorrect position, navigation and timing data, and sets it apart from jamming, which stops a receiver from locking on at all (GPS jamming covers that case).

Spoofing is possible because civil signals are open. Liu and Papadimitratos note that civilian GNSS signals are usually not cryptographically protected, which makes forging them relatively easy. A receiver that follows the published signal format has nothing in the basic civil signal that proves where it came from; how GPS works explains what that signal carries.

There is also a second, simpler kind of spoofing that never touches the radio. On a phone, an app or a developer tool can feed the operating system a made-up location. Detecting the two kinds takes different tools.

Checking the signal itself

A receiver that can see its own signal measurements has the first chance to notice an attack. Two measurements recur in the published work cited here:

  • Carrier-to-noise density (C/N0), which describes how strong each satellite’s signal is relative to background noise.
  • Received power, the total energy the antenna picks up in the band.

Kriezis and colleagues combine C/N0 with a calibrated received power measurement to build a detection space that separates nominal, jammed, spoofed and blocked conditions, and validated it with low-cost commercial receivers in controlled jamming tests and in regions that had experienced interference.

Receivers that track carrier phase precisely can go further. Clements, Yoder and Humphreys compare carrier-phase measurements with what a low-cost inertial measurement unit predicts about the vehicle’s movement. A spoofer cannot predict the small movements a car makes over an uneven road, so its forged signals stop matching the motion the sensors record.

Checking the fix against the world

Even without signal access, a position can be tested against other evidence:

  • Physics. EASA’s interference analysis treats a speed between two reported positions that would violate the laws of physics as a possible sign of spoofing. A phone that appears to jump across a country in a second is not moving that fast.
  • Other sensors. EASA lists symptoms of spoofing on aircraft, including abnormal differences between ground speed and true airspeed and deviations between inertial and GNSS positions.
  • Other sources. Liu and Papadimitratos build a detector on opportunistic information, the network connections and onboard sensors that modern devices already have, and test whether the GNSS track fits it.

Each of these raises suspicion rather than proving an attack.

Authenticating the signal

A further step is to make forged data detectable by design. Galileo’s Open Service Navigation Message Authentication (OSNMA) does this for Galileo’s navigation message. According to the European GNSS Service Centre, it gives receivers assurance that the message came from the system and was not modified, using a delayed-disclosure broadcast authentication protocol called TESLA. The authentication data travels in previously reserved fields of the existing message.

OSNMA has conditions. The receiver must be built to process it, must install and update the public key material, and must keep its internal time close enough to Galileo System Time for the delayed disclosure to be safe. The service centre describes it as a data authentication function: it protects the content of the navigation message. The centre declared OSNMA’s initial service operational on 24 July 2025.

Flags for faked locations on phones

Both mobile platforms mark locations that software, rather than the GNSS chip, produced. Android lets apps submit mock locations through LocationManager and exposes isMock() so apps can tell a mock location from the device’s best estimate; Google’s documentation adds that users may have legitimate reasons for mocking. On Apple platforms, CLLocationSourceInformation has an isSimulatedBySoftware property, set when the system generated the location by on-device simulation, for example from a GPX file loaded in the Xcode debugger.

These flags cover only locations the operating system knows are simulated. They say nothing about a counterfeit radio signal reaching a genuine receiver.

Checking a claim from outside the device

A server receiving a coordinate from a phone sees none of the above. It can only compare the claim with independent evidence: network signals, the user’s previous positions, or a third party that observes something about the device. Offline Protocol’s Proof of Location is one example of the last approach: operator witnesses measure network round-trip time to the device and sign individual attestations, and its documentation states that these checks make some claims implausible but do not prevent spoofing and are not proof that a person is physically present.

In practice, detection is layered. Use signal checks where the hardware exposes them, cross-check the fix against motion and other sources, prefer authenticated signals where receivers support them, and treat any single location report as a claim to be weighed.

Frequently asked questions

Can a phone app tell if GPS is being spoofed?

Partly. An app can read the operating system's flag for mock or simulated locations and can compare the fix with the phone's motion sensors and other location sources. An app mainly sees the fix the receiver computed, so a counterfeit signal that the receiver accepts can look like a normal fix.

Does using Galileo stop spoofing?

Galileo's OSNMA lets a compatible receiver check that the navigation message came from Galileo and was not modified. That raises the bar for forging data, but the receiver must support OSNMA and keep its clock close to Galileo System Time, and it is one layer among several rather than a complete defence.

Sources

Build it with Offline Protocol

Offline Protocol's Proof of Location security page sets out what its round-trip-time witness checks can and cannot establish about a claimed location, including why they do not prevent spoofing.

Read Location evidence security