[saag] Fwd: New Version Notification for draft-moskowitz-ads -b-auth-01.txt

Robert Moskowitz <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
During the SAAG session, in the chat, I mentioned the challenges I am 
having with my ADS-B Authentication work.  Particularly conveying 
digital certificates in some shape or form over the 1090ES channel even 
with the added bits from the Phase Overlay.

Forget about PQC, EdDSA25519 hurts.

I said in the chat, that I would soon be pushing out a draft of my 
ADS-Auth protocol for review/comments.  In particular there are aspects 
of use of TESLA that I need review.  But here it is.  The current 
protocol to authenticate ADS-B.

I welcome review.  The cert part is minimal in the ID, as the ID is 
about the 1090ES channel messages.  Not about the needed PKI or how PQC 
makes things really really hard.

Comments on SAAG or the rfc4082-update list are invited.  This design is 
now quite close to 4082, unlike what GNSS SBAS is doing. But that list 
might be the best place for discussions.  Or anywhere else people think 
to take it.

Oh, one last thing.  RTCA basically "owns" ADS-B in their DO-260 MOPS.  
It is behind their paywall.  Even I don't, yet, have a copy. My 
co-authors of the ID do have it and have kept the design consistant to 
the current DO-260C.  We will be taking this protocol to RTCA for the 
work on 260D (just starting up).  RTCA really does not (IMO) have the 
needed depth for a proper security review of this protocol.  Thus the 
public design, at this state, of what the protocol needs to be.  There 
will be similar IDs for parts of the PKI and perhaps how to send certs 
over some other channel because as you will see, 1090ES really cannot 
hack it.

Enough of my thought meanderings for the evening.  See you on lists 
tomorrow!

Bob






-------- Forwarded Message --------
Subject: 	New Version Notification for draft-moskowitz-ads-b-auth-01.txt
Date: 	Thu, 30 Jul 2026 13:22:09 -0700
From: 	[email protected]
To: 	Stuart W. Card <[email protected]>, Mikaëla Ngamboé 
<[email protected]>, José M. Fernandez 
<[email protected]>, Adam Wiethuechter 
<[email protected]>, Jose Fernandez 
<[email protected]>, Mikaela Ngamboe 
<[email protected]>, Robert Moskowitz 
<[email protected]>, Stuart Card <[email protected]>



A new version of Internet-Draft draft-moskowitz-ads-b-auth-01.txt has been
successfully submitted by Robert Moskowitz and posted to the
IETF repository.

Name: draft-moskowitz-ads-b-auth
Revision: 01
Title: ADS-B Authentication
Date: 2026-07-30
Group: Individual Submission
Pages: 42
URL: https://www.ietf.org/archive/id/draft-moskowitz-ads-b-auth-01.txt
Status: https://datatracker.ietf.org/doc/draft-moskowitz-ads-b-auth/
HTML: https://www.ietf.org/archive/id/draft-moskowitz-ads-b-auth-01.html
HTMLized: https://datatracker.ietf.org/doc/html/draft-moskowitz-ads-b-auth
Diff: 
https://author-tools.ietf.org/iddiff?url2=draft-moskowitz-ads-b-auth-01

Abstract:

The Automatic Dependent Surveillance – Broadcast (ADS-B) is a
surveillance technology mandated in many airspaces. It is now widely
deployed but suffers a lack of security and privacy. From a security
point of view, it is relatively easy to spoof the ADS-B messages.
With the appropriate readily available hardware and software. From a
privacy point of view, all the messages contain the aircraft’s
assigned 24-bit ICAO address, which makes it easy to link to data
about the aircraft, in particular to know when a particular aircraft
has flown and where to. In addition, the main transmission medium
utilized for ADS-B, i.e. the 1090 MHz frequency used by Extended
Squitter (1090ES), is approaching saturation in some parts of the
world with ADS-B and other protocol messages, resulting in packet
loss in certain areas [RF_Usage].

This paper presents the IETF TESLA protocol along with X.509
certificates issued by ICAO member states for each aircraft to
authenticate all ADS-B messaging. It leverages the 8PSK phase
overlay (PO) scheme proposed in the Minimum Operational Performance
Standards (MOPS) for ADS-B (RTCA [DO-260C]), which enables 1090ES
ADS-B transmissions to convey three times more information, to
support the transmission of the extra security information required
by the authentication scheme. By doing so, the impact of
authentication on channel usage is negligible. Beyond message
authentication, this scheme protocol has two important additional
benefits: 1) the possibility to implement a Flight Authorization
scheme, allowing ATC and intercepting aircraft to not only
authenticate an aircraft but to verify that it is authorizes to
conduct that flight and 2) a methodology for adequately protecting
the privacy by assigning rotating 24-bit identifiers to designated
aircraft, while maintaining the possibility to (blindly) authenticate
their ADS-B transmissions.



The IETF Secretariat

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.