Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

GNSS Spoofing Detection in TDD Networks: A 3GPP Standards-Based Security Framework

A standards-aligned detection and monitoring framework for GNSS timing attacks in 5G TDD networks, validated via Monte Carlo simulation
Ravi Kant Sharma; John Owens; Kevin Kiernanยท 2026ยท DOI 10.48550/arXiv.2607.11398

The core problem

Time Division Duplex (TDD) mobile networks depend on tight synchronization: 3GPP TS 38.104 mandates a synchronization accuracy of . In practice, this timing is predominantly supplied by GNSS-disciplined grandmaster clocks. GNSS spoofing has transitioned from a theoretical concern to a documented operational threat, capable of corrupting timing across all downstream base stations simultaneously. Despite this risk, neither the 3GPP management framework (SA5) nor the security framework (SA3) currently standardizes mechanisms to detect or report such attacks. This paper addresses that gap by proposing a detection and monitoring framework that operates entirely within existing 3GPP management structures, requiring no new interfaces and remaining generation-agnostic. The framework is designed to distinguish spoofing from signal loss, equipment faults, and maintenance transients, and is validated through scenario analysis and Monte Carlo simulation.

Innovation

Monte Carlo simulation results demonstrate that the framework achieves a detection probability exceeding 95% for drift rates above , while maintaining false positive rates below 1% under well-provisioned PTP network conditions. The topology-aware correlation mechanism significantly improves discrimination between spoofing and other anomaly types. Scenario analysis confirms that the framework can reliably distinguish spoofing from signal loss, equipment faults, and maintenance transients. The detection performance is summarized in the following Mermaid diagram, which illustrates the decision flow:

These results indicate that the framework meets the stringent requirements of TDD synchronizati

Time Division Duplex (TDD) mobile networks depend on tight synchronization: 3GPP TS 38.104 mandates a synchronization accuracy of . In practice, this timing is predominantly supplied by GNSS-disciplined grandmaster clocks. GNSS spoofing has transitioned from a theoretical concern to a documented operational threat, capable of corrupting timing across all downstream base stations simultaneously. Despite this risk, neither the 3GPP management framework (SA5) nor the security framework (SA3) currently standardizes mechanisms to detect or report such attacks. This paper addresses that gap by proposing a detection and monitoring framework that operates entirely within existing 3GPP management structures, requiring no new interfaces and remaining generation-agnostic. The framework is designed to distinguish spoofing from signal loss, equipment faults, and maintenance transients, and is validated through scenario analysis and Monte Carlo simulation.
The proposed framework comprises three integrated components:

Why it matters

The proposed framework fills a critical gap in 3GPP standards by providing a standardized, generation-agnostic approach to GNSS spoofing detection. Its key strength lies in leveraging existing management and security structures, which lowers deployment barriers and ensures compatibility across current and future network generations. The topology-aware correlation mechanism is particularly effective because it exploits the inherent hierarchy of timing distribution: a spoofing attack on a grandmaster affects all downstream gNB-DUs, whereas localized faults affect only a subset. This spatial signature enables reliable classification even when individual node metrics are ambiguous.

The framework's reliance on drift rate thresholds () and PTP network quality highlights the importance of well-provisioned backhaul. In networks with poor PTP performance, false positives may increase, necessitating adaptive thresholding. Future work could explore machine learning to dynamically adjust thresholds based on historical data. Additionally, the integration with SECHAND incident handling ensures that detected spoofing events are not only flagged but also trigger appropriate security responses, bridging the gap between fault and security management domains.

Overall, the framework offers a practical and standards-compliant solution to a growing threat, with simulation results confirming its effectiveness under realistic conditions.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ