Europe’s Galileo system has demonstrated a civilian position fix that remained authenticated during spoofing, showing how encrypted ranging signals could help receivers reject counterfeit satellite-navigation signals.

A satellite-navigation receiver can be tricked into calculating the wrong position when a transmitter broadcasts counterfeit signals that appear to come from satellites. Europe’s Galileo system has now demonstrated a way for civilian receivers to detect such spoofing and maintain an authenticated position.
Receivers using Galileo’s new Signal Authentication Service (SAS) successfully established their positions during real-world spoofing tests in Norway and at the European Space Agency’s navigation laboratory in the Netherlands. EUSPA describes it as the first civil GNSS position authenticated using both navigation data and ranging information.
What happened
Between 14:00 and 16:00 UTC, five Galileo satellites — E06, E21, E23, E34 and E36 — encrypted the E6-C signal component at 1,278.75MHz for the test. Receivers at Andøya in Norway and ESA’s ESTEC navigation laboratory processed the signals and established authenticated position fixes.
Much of the demonstration took place during Jammertest on Norway’s Andøya island, where controlled jamming and spoofing signals are broadcast to test satellite-navigation equipment. Under the spoofing scenarios, conventional receivers were deceived and reported false positions, while the Galileo SAS receiver detected the attack and maintained the correct position.

How it works
A GNSS receiver needs two key pieces of information to calculate its position: the navigation message transmitted by satellites and the ranging measurement, which is based on the time taken for the signal to reach the receiver.
Galileo already protects the first through Open Service Navigation Message Authentication (OSNMA), which was declared operational in July 2025. OSNMA allows receivers to verify that navigation data came from Galileo and has not been modified.
SAS adds authentication for the ranging signal. It uses an encrypted portion of the Galileo E6-C signal. The receiver records samples of this signal and later uses authentication information associated with OSNMA to verify the recorded signal. This provides protection for the measurement used to determine the receiver’s position, complementing OSNMA’s protection of the navigation message.
Together, OSNMA and SAS are designed to allow receivers to detect and reject a wide range of spoofing attacks. The services are planned to be free and available worldwide.
Compared With Conventional Satnav
Civil GNSS receivers have historically had limited ways to verify that the signals they receive genuinely originated from navigation satellites. A spoofer can transmit counterfeit signals that cause a receiver to calculate a false position.
Galileo’s approach adds cryptographic authentication to both the navigation data and ranging information. This does not prevent a spoofer from transmitting a signal, but it gives a compatible receiver a way to determine whether the information used for its position solution can be trusted.
Authentication also does not solve jamming. Jamming overwhelms or blocks legitimate GNSS signals rather than attempting to make a receiver accept a false position.
Maturity And Limits
The demonstration was a test of an upcoming service rather than a live, fully operational capability. EUSPA plans further testing with additional Galileo satellites, followed by validation and accreditation activities in 2027 before SAS is declared operational.
A receiver also needs hardware capable of processing the relevant E6-C signal and implementing the authentication process. This means the capability cannot automatically be added to every existing smartphone through a software update.
What It Means For India
GNSS spoofing is already a documented aviation issue in India. In a Rajya Sabha response dated 1 December 2025, the Ministry of Civil Aviation said some flights had reported GPS spoofing near Indira Gandhi International Airport while using GPS-based landing procedures approaching Runway 10. It also said GNSS interference reports were being received from Kolkata, Amritsar, Mumbai, Hyderabad, Bengaluru and Chennai airports.
The Directorate General of Civil Aviation had issued a procedure in November 2025 for real-time reporting of GPS spoofing and GNSS interference around IGI Airport, while the Airports Authority of India had asked the Wireless Monitoring Organisation to help identify sources of interference.
India also operates NavIC alongside other GNSS systems, but the current deployment status of equivalent civilian signal-authentication capabilities would need to be established separately. For Indian aviation, smartphones and other positioning systems, Galileo’s approach demonstrates how authentication could add another layer of protection against false positioning as compatible receivers become available.
For more information, click here.




