What a spoofer does
A spoofer broadcasts counterfeit satellite signals so that a receiver computes a wrong position or time. The European Union Aviation Safety Agency (EASA) describes spoofing as deceiving receivers into producing incorrect position, navigation and timing data, and sets it apart from jamming, which stops a receiver from locking on at all (GPS jamming covers that case).
Spoofing is possible because civil signals are open. Liu and Papadimitratos note that civilian GNSS signals are usually not cryptographically protected, which makes forging them relatively easy. A receiver that follows the published signal format has nothing in the basic civil signal that proves where it came from; how GPS works explains what that signal carries.
There is also a second, simpler kind of spoofing that never touches the radio. On a phone, an app or a developer tool can feed the operating system a made-up location. Detecting the two kinds takes different tools.
Checking the signal itself
A receiver that can see its own signal measurements has the first chance to notice an attack. Two measurements recur in the published work cited here:
- Carrier-to-noise density (C/N0), which describes how strong each satellite’s signal is relative to background noise.
- Received power, the total energy the antenna picks up in the band.
Kriezis and colleagues combine C/N0 with a calibrated received power measurement to build a detection space that separates nominal, jammed, spoofed and blocked conditions, and validated it with low-cost commercial receivers in controlled jamming tests and in regions that had experienced interference.
Receivers that track carrier phase precisely can go further. Clements, Yoder and Humphreys compare carrier-phase measurements with what a low-cost inertial measurement unit predicts about the vehicle’s movement. A spoofer cannot predict the small movements a car makes over an uneven road, so its forged signals stop matching the motion the sensors record.
Checking the fix against the world
Even without signal access, a position can be tested against other evidence:
- Physics. EASA’s interference analysis treats a speed between two reported positions that would violate the laws of physics as a possible sign of spoofing. A phone that appears to jump across a country in a second is not moving that fast.
- Other sensors. EASA lists symptoms of spoofing on aircraft, including abnormal differences between ground speed and true airspeed and deviations between inertial and GNSS positions.
- Other sources. Liu and Papadimitratos build a detector on opportunistic information, the network connections and onboard sensors that modern devices already have, and test whether the GNSS track fits it.
Each of these raises suspicion rather than proving an attack.
Authenticating the signal
A further step is to make forged data detectable by design. Galileo’s Open Service Navigation Message Authentication (OSNMA) does this for Galileo’s navigation message. According to the European GNSS Service Centre, it gives receivers assurance that the message came from the system and was not modified, using a delayed-disclosure broadcast authentication protocol called TESLA. The authentication data travels in previously reserved fields of the existing message.
OSNMA has conditions. The receiver must be built to process it, must install and update the public key material, and must keep its internal time close enough to Galileo System Time for the delayed disclosure to be safe. The service centre describes it as a data authentication function: it protects the content of the navigation message. The centre declared OSNMA’s initial service operational on 24 July 2025.
Flags for faked locations on phones
Both mobile platforms mark locations that software, rather than the GNSS chip, produced. Android lets apps submit mock locations through LocationManager and exposes isMock() so apps can tell a mock location from the device’s best estimate; Google’s documentation adds that users may have legitimate reasons for mocking. On Apple platforms, CLLocationSourceInformation has an isSimulatedBySoftware property, set when the system generated the location by on-device simulation, for example from a GPX file loaded in the Xcode debugger.
These flags cover only locations the operating system knows are simulated. They say nothing about a counterfeit radio signal reaching a genuine receiver.
Checking a claim from outside the device
A server receiving a coordinate from a phone sees none of the above. It can only compare the claim with independent evidence: network signals, the user’s previous positions, or a third party that observes something about the device. Offline Protocol’s Proof of Location is one example of the last approach: operator witnesses measure network round-trip time to the device and sign individual attestations, and its documentation states that these checks make some claims implausible but do not prevent spoofing and are not proof that a person is physically present.
In practice, detection is layered. Use signal checks where the hardware exposes them, cross-check the fix against motion and other sources, prefer authenticated signals where receivers support them, and treat any single location report as a claim to be weighed.