[saag] Fwd: New Version Notification for draft-moskowitz-ads -b-auth-01.txt
Robert Moskowitz <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
During the SAAG session, in the chat, I mentioned the challenges I am having with my ADS-B Authentication work. Particularly conveying digital certificates in some shape or form over the 1090ES channel even with the added bits from the Phase Overlay. Forget about PQC, EdDSA25519 hurts. I said in the chat, that I would soon be pushing out a draft of my ADS-Auth protocol for review/comments. In particular there are aspects of use of TESLA that I need review. But here it is. The current protocol to authenticate ADS-B. I welcome review. The cert part is minimal in the ID, as the ID is about the 1090ES channel messages. Not about the needed PKI or how PQC makes things really really hard. Comments on SAAG or the rfc4082-update list are invited. This design is now quite close to 4082, unlike what GNSS SBAS is doing. But that list might be the best place for discussions. Or anywhere else people think to take it. Oh, one last thing. RTCA basically "owns" ADS-B in their DO-260 MOPS. It is behind their paywall. Even I don't, yet, have a copy. My co-authors of the ID do have it and have kept the design consistant to the current DO-260C. We will be taking this protocol to RTCA for the work on 260D (just starting up). RTCA really does not (IMO) have the needed depth for a proper security review of this protocol. Thus the public design, at this state, of what the protocol needs to be. There will be similar IDs for parts of the PKI and perhaps how to send certs over some other channel because as you will see, 1090ES really cannot hack it. Enough of my thought meanderings for the evening. See you on lists tomorrow! Bob -------- Forwarded Message -------- Subject: New Version Notification for draft-moskowitz-ads-b-auth-01.txt Date: Thu, 30 Jul 2026 13:22:09 -0700 From: [email protected] To: Stuart W. Card <[email protected]>, Mikaëla Ngamboé <[email protected]>, José M. Fernandez <[email protected]>, Adam Wiethuechter <[email protected]>, Jose Fernandez <[email protected]>, Mikaela Ngamboe <[email protected]>, Robert Moskowitz <[email protected]>, Stuart Card <[email protected]> A new version of Internet-Draft draft-moskowitz-ads-b-auth-01.txt has been successfully submitted by Robert Moskowitz and posted to the IETF repository. Name: draft-moskowitz-ads-b-auth Revision: 01 Title: ADS-B Authentication Date: 2026-07-30 Group: Individual Submission Pages: 42 URL: https://www.ietf.org/archive/id/draft-moskowitz-ads-b-auth-01.txt Status: https://datatracker.ietf.org/doc/draft-moskowitz-ads-b-auth/ HTML: https://www.ietf.org/archive/id/draft-moskowitz-ads-b-auth-01.html HTMLized: https://datatracker.ietf.org/doc/html/draft-moskowitz-ads-b-auth Diff: https://author-tools.ietf.org/iddiff?url2=draft-moskowitz-ads-b-auth-01 Abstract: The Automatic Dependent Surveillance – Broadcast (ADS-B) is a surveillance technology mandated in many airspaces. It is now widely deployed but suffers a lack of security and privacy. From a security point of view, it is relatively easy to spoof the ADS-B messages. With the appropriate readily available hardware and software. From a privacy point of view, all the messages contain the aircraft’s assigned 24-bit ICAO address, which makes it easy to link to data about the aircraft, in particular to know when a particular aircraft has flown and where to. In addition, the main transmission medium utilized for ADS-B, i.e. the 1090 MHz frequency used by Extended Squitter (1090ES), is approaching saturation in some parts of the world with ADS-B and other protocol messages, resulting in packet loss in certain areas [RF_Usage]. This paper presents the IETF TESLA protocol along with X.509 certificates issued by ICAO member states for each aircraft to authenticate all ADS-B messaging. It leverages the 8PSK phase overlay (PO) scheme proposed in the Minimum Operational Performance Standards (MOPS) for ADS-B (RTCA [DO-260C]), which enables 1090ES ADS-B transmissions to convey three times more information, to support the transmission of the extra security information required by the authentication scheme. By doing so, the impact of authentication on channel usage is negligible. Beyond message authentication, this scheme protocol has two important additional benefits: 1) the possibility to implement a Flight Authorization scheme, allowing ATC and intercepting aircraft to not only authenticate an aircraft but to verify that it is authorizes to conduct that flight and 2) a methodology for adequately protecting the privacy by assigning rotating 24-bit identifiers to designated aircraft, while maintaining the possibility to (blindly) authenticate their ADS-B transmissions. The IETF Secretariat _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]