Source-linked AI summary
Secure Pseudonymetry with DSSS Watermarking for LEO Satellites
Nisanur Camuzcu, Alireza Vahid
TL;DR
Passive LEO signals offer useful PNT opportunities, but weak beacons, overlapping satellites, and limited waveform access complicate reliable satellite attribution. The paper embeds a low-power DSSS watermark with public pseudonym and HMAC-SHA256 authentication fields, using a motion-aware receiver for passive recovery and verification. Simulations demonstrate candidate detection, public-ID recovery, keyed verification, and limited perturbation of modeled downlink observables.
Problem
Passive LEO PNT receivers may lack reliable satellite attribution when beacon or pilot components are weak, signals overlap, or full downlink demodulation is unavailable.
Method
The framework superimposes a low-power DSSS watermark carrying a public satellite pseudonym and HMAC-SHA256 authentication field, recovered by a motion-aware passive receiver.
Results
The multi-satellite simulation demonstrates candidate-satellite detection, public-ID recovery, keyed verification, and limited perturbation to beacon/pilot and primary downlink components.
Takeaways & Limitations
The framework supports passive satellite identification and authorized verification without full downlink demodulation while remaining below the primary waveform.
Abstract
from arXiv · showhide
Low-Earth-orbit (LEO) constellations offer dense signals of opportunity (SOP) for positioning, navigation, and timing (PNT) without dedicated navigation infrastructure. However, using these signals passively, by only listening to the downlink, is difficult when beacon/pilot components are weak, signals from multiple satellites overlap, or the receiver cannot reliably identify which satellite generated a given observable. This paper proposes a low-power direct-sequence spread-spectrum (DSSS) watermarking framework that embeds a recoverable pseudonymous satellite identifier and keyed authentication field into a LEO downlink signal. The watermark carries a public satellite pseudonym for identification and a keyed HMAC-SHA256-based authentication field for authorized verification, enabling passive detection and verification without full downlink demodulation. We evaluate the framework in a multi-satellite simulation using Starlink two-line-element (TLE)-derived geometry, Doppler, and link-budget scaling with Sionna RT-based local propagation. The results demonstrate candidate-satellite detection, public-ID recovery, and keyed verification under co-observed satellite interference, with limited perturbation to the simulated beacon/pilot and primary downlink components. The framework targets future transmitter-enabled LEO systems while remaining transparent to legacy receivers that do not process the low-power watermark.
I. INTRODUCTION
Passive LEO signals can support PNT without dedicated infrastructure, but weak or overlapping observables may be difficult to associate with the correct satellite. The paper proposes a low-power DSSS watermark carrying public identification and keyed authentication for passive attribution and verification.
- LEO constellations provide dense, fast-moving signals of opportunity for passive PNT without dedicated navigation payloads, two-way links, or new terrestrial infrastructure.
- Full downlink processing can require wideband sampling, detailed waveform knowledge, and frame-structure access unavailable to low-complexity passive receivers.
- Multiple visible satellites can place reference components in nearby time-frequency regions, making satellite association unreliable for receivers outside network control protocols.
- The proposed framework superimposes a low-power DSSS watermark below the existing downlink and recovers it through correlation without full payload demodulation.
- Evaluation uses Starlink TLE-derived geometry and Sionna RT-based local propagation to test watermark recovery and authentication under multi-satellite coexistence.
- The watermark separates public pseudonym detection from HMAC-SHA256-based keyed authentication for authorized passive receivers.
II. SYSTEM MODEL
The system models a multi-satellite LEO downlink containing a primary component, beacon/pilot, and low-power DSSS watermark, then processes the watermark using motion-aware correlation and authentication.
- Signal model: Each satellite signal combines a primary downlink, beacon/pilot component, and proposed low-power DSSS watermark.The receiver observes these components together in a multi-satellite environment.
- Watermark structure: The watermark encodes a public pseudonym/code index through Lc-chip spreading and supports synchronization, identification, and keyed authentication.The authentication field uses HMAC-SHA256 with a secret key provisioned to authorized receivers.
- Signal model: The received candidate watermark is modeled amid co-observed satellites, primary and beacon/pilot components, multipath, Doppler, and receiver noise.The candidate and co-observed satellite contributions have satellite-dependent propagation and Doppler terms.
- Receiver processing: TLE-based Doppler and Doppler-rate compensation removes the dominant LEO motion trend before residual frequency estimation and watermark processing.Beacon/pilot guidance supplies coarse timing and frequency information, narrowing the residual frequency search neighborhood.
- Receiver processing: Chip-rate samples are formed by integrate-and-dump processing over intervals of duration Tc = 1/Rc.Rc denotes the chip rate.
- Receiver processing: DSSS acquisition correlates chip-rate samples with candidate codes across code-index, delay, and residual-frequency hypotheses, using coherent blocks and noncoherent accumulation.The synchronization/public-ID interval is Tacq = (Nsync + NID)LcTc, while full verification uses Tpkt = NsymLcTc.
III. SIMULATION SETUP
The simulation combines TLE-derived satellite geometry and propagation with Sionna RT local multipath, modeling co-observed signals and a low-power DSSS watermark superimposed on the primary downlink.
- The simulation uses Starlink TLEs and Skyfield to derive geometry, slant range, path loss, delay, Doppler, and Doppler drift.A Sionna RT RIT campus scene models local receiver-side propagation using a proxy transmitter aligned with the satellite direction.
- The multi-satellite snapshot superposes candidate and co-observed satellite signals with independent delays, Doppler shifts, and channel responses.The representative closest interferer is separated from the candidate by about 77 µs, or roughly 31 DSSS chips.
- The modeled signal contains a primary downlink, beacon/pilot, low-power DSSS watermark, and noise within a limited baseband observation.The watermark is superimposed on the modeled primary downlink rather than placed in a protected quiet subband.
- The watermark is set 35 dB below the primary downlink, while the beacon/pilot is 25 dB below it, so recovery depends on DSSS processing gain and correlation.The design uses 511 chips per watermark symbol and an approximately 65.9 kHz offset to avoid direct overlap with the beacon/pilot comb.
- Table I lists receiver, propagation, and watermark parameters, distinguishing TLE-derived geometry quantities from proposed chip-rate, code, offset, and authentication-field settings.
IV. RESULTS
The results assess watermark detection, keyed verification, candidate attribution, and effects on existing observables in a dish-assisted future multi-satellite setting.
- The evaluation covers detection and keyed verification across watermark power and coexistence conditions.
- The evaluation tests whether the receiver can attribute recovered watermark signals to the correct candidate satellite amid co-observed components.
- The evaluation examines the watermark’s impact on beacon/pilot and primary downlink observables.
A. Watermark Detection and Keyed Verification
Detection and keyed verification require sufficient watermark power, while the receiver maintains high keyed verification and low wrong-ID probability under the tested coexistence load.
- Below about −37.5 dB relative to the primary downlink, blind acquisition and keyed verification remain unreliable.
- Around the selected −35 dB operating region, blind acquisition and keyed verification rise sharply toward near-unity success.The watermark remains low-power relative to the primary downlink while becoming reliably recoverable through correlation-based DSSS processing gain.
- Under the tested coexistence load, keyed verification remains high while wrong-ID probability remains low as additional co-observed satellites are included.
- Keyed verification depends on validation of the expected frame counter.
B. Candidate Attribution in a Multi-Satellite Setting
Candidate attribution improves with stronger candidate watermark quality and greater separation from co-observed watermark components, reducing wrong-ID events and increasing identification confidence.
- Increasing candidate watermark C/N0 improves blind acquisition and keyed verification.C/N0 measures candidate watermark strength relative to receiver noise density before despreading.
- Increasing the candidate-to-other watermark ratio improves authentication-bit recovery and keyed verification.
- As candidate-to-other separation increases, wrong-ID probability decreases and the receiver can associate the watermark with the correct candidate satellite.
- The ID-margin plot reports the separation between the strongest and second-strongest public-ID hypotheses as an attribution diagnostic.
C. Impact on Existing Downlink Observables
The DSSS watermark causes limited changes to existing beacon/pilot and primary-waveform observables at the selected operating point, while stronger watermark power increases perturbation.
- At −35 dB, beacon amplitude bias is ∼0.5 dB and phase-bias magnitude is about 2◦.
- At −35 dB, projected primary-waveform distortion is −46.61 dB, corresponding to 0.00009 dB equivalent SNR loss and 0.0013 dB total power change.
- Stronger DSSS-toprimary power increases beacon amplitude and phase bias relative to the no-watermark reference.
- The power-dependent bias demonstrates a tradeoff between watermark recoverability and compatibility with existing beacon/pilot observables.
V. CONCLUSION
The paper presents a low-power DSSS watermark for secure pseudonymetry in passive LEO-aided PNT. Simulations support satellite detection, public-ID recovery, and keyed verification under interference, while future work addresses broader validation and implementation conditions.
- The framework superimposes a low-power DSSS watermark below the primary downlink for secure pseudonymetry in passive LEO-aided PNT.
- The watermark carries a public satellite pseudonym and an HMAC-SHA256 authentication field, recovered through correlation without full downlink demodulation.
- A motion-aware system combines TLE-assisted Doppler compensation, beacon/pilot-aided residual correction, DSSS acquisition, and authentication checking.
- Simulation supports satellite detection, public-ID recovery, and keyed verification under co-observed satellite interference.
- Future work will optimize frame length and power allocation, evaluate smaller-aperture and bare-LNB receivers, study ephemeris uncertainty, and validate hardware-calibrated measurements.