• Products
    Back

    S-GNSS® Auto

    Next-gen GNSS software delivering better accuracy and reliability for vehicles navigating challenging environments.

    S-GNSS® Cell

    GNSS software to improve location-based services on smartphones – everything from maps to emergency calls.

    S-GNSS® Wear

    Smarter fitness tracking for wearables with a simple, power-efficient upgrade. For accuracy on the go.

  • Solutions
    Back

    Supercorrelation®

    Supercorrelation™ is our patented, chipset-level software that improves the sensitivity, accuracy and reliability of GNSS receivers.

    Automotive

    Reliable GNSS for navigation, safety, and autonomy in tough environments.

    Wearables

    Accurate, efficient tracking for wearables — built for the outdoors, including forest trails and city environments.

    Cellular

    Robust location for smartphones and IoT via a simple firmware upgrade — no hardware change needed.

  • Ecosystem
    Back

    Partnerships

    We work with stakeholders across the supply chain to deliver integrated solutions to the automotive, wearables and smartphones industries.

    Joint solution with STMicroelectronics

    S-GNSS® Auto has been integrated onto ST’s Teseo devices, delivering a step change in GNSS accuracy and reliability for automotive.

  • Resources
    Back

    Tech.AD 2026 Europe

    Date: March 2026
    Location: Berlin

    Read more

    Blog

    Read the latest news and insights from FocalPoint: expert interviews, employee spotlights, event updates, and more.

    White papers

    Experts insights on GNSS performance, innovation, and real-world impact across industries.

    FAQs

    Learn more about the benefits of our GNSS-enhancing software and how you can get the most from it.

    Webinars

    Expert insights, opinions and discussions on the role of GNSS in shaping the future of navigation.

  • About
    Back

    About

    About FocalPoint: our history, milestones and leadership team.

    Our Purpose

    Our purpose is to improve the lives of everyone who relies on positioning technology.

    Careers

    Learn about life at FPP, our impact, and what we offer. Hear from our people about our values and what they like about working here.

    Sustainability

    Read about our commitment to building a sustainable future.

    Recognition
  • Contact

Skyscan: Enabling spatial authentication of GNSS signals using a single antenna

Laurence Bennett
11 min read
7th Oct, 2026
S-GNSS

Spoofing and meaconing attacks work by feeding a GNSS receiver signals that didn’t travel directly from the satellite they claim to come from. Instead, they arrive from a transmitter somewhere else, so they arrive from the wrong direction. One of the most reliable ways to detect these attacks is to use spatial authentication, which checks each signal’s direction of arrival. Until now, that has meant using bulky and expensive hardware, for example a Controlled Reception Pattern Antenna (CRPA), that is impractical in consumer use-cases such as automotive or in smartphones and wearables. Skyscan, built on Supercorrelation®, delivers spatial authentication using the single element antennas typically deployed with mass-market receivers.

In this article, we explain how Skyscan works and present the results from our recent ION GNSS+ paper, showing how a receiver can check that every signal it is tracking really did come from the satellite it claims to. The results are based on recordings from a real-world, open-air meaconing scenario at Jammertest 2025 in Norway.

Supercorrelation as a spatial filter

GNSS signals begin their journey at satellites around 20,000 km overhead. A receiver that knows where those satellites are also knows which direction each signal ought to arrive from.

A key feature of Supercorrelation® is that it focuses on signal power emanating from the satellite’s known direction. This is central to all implementations of Supercorrelation. That selectivity is what suppresses reflected, or non-line-of-sight (NLOS), signals which corrupt the precise satellite range measurements needed to determine position.

The same mechanism suppresses spoofed and meaconed signals. These can be distinguished as they don’t emanate from the known locations of the satellites. Our previous paper and blog post demonstrated this on meaconing data from Jammertest 2025, recovering the authentic line-of-sight signal from beneath a much stronger rebroadcast while attenuating the rebroadcast itself.

In that work, the spatial selectivity provided by Supercorrelation was used implicitly. The known location of the satellite was used to compensate for motion in that direction, and anything originating from elsewhere failed to strongly accumulate. Skyscan takes this a step further: rather than compensating for one known direction, it surveys the signal power arriving from every direction in the sky.

How Skyscan works

Supercorrelation achieves long coherent integration in part by compensating for receiver motion over the integration interval. The applied compensation depends on the direction from which the signal is assumed to arrive, corresponding to the line-of-sight direction for an authentic satellite signal. Energy arriving from the assumed direction accumulates coherently, whereas energy arriving from other directions retains a time-varying residual phase and partially cancels during accumulation. Supercorrelation can therefore be applied to evaluate the received signal energy associated with any candidate arrival direction. Skyscan extends this principle to survey received signal energy across the visible sky.

Skyscan forms a bank of Supercorrelators for a single satellite signal, each compensated for a different azimuth and elevation, and evaluates the resulting correlator outputs over a grid spanning the visible sky. The result is a map of received energy as a function of arrival direction.

 

Figure 1. Left: skyplot showing satellite positions in the sky. Right: Skyscan showing signal power across the sky over one second for Galileo E1C PRN 13. Dark to light indicates low to high recovered signal strength in dB-Hz. The blue marker is the expected direction of PRN 13. 

Both figures are polar plots of the sky above the receiver. Azimuth runs around the edge, north at the top and east to the right; elevation runs from the horizon at the outer rim to zenith at the centre.

The skyplot shows the satellite positions from the received ephemerides. The Skyscan beside it shows the signal power across the sky, computed from the Skyscan algorithm for the Galileo E1C PRN 13 signal. The measured signal power should coincide with the satellite location in the sky (i.e. the white stripe should overlap with the blue marker). If it doesn’t, the signal is likely to be a reflection of the authentic one, or entirely inauthentic.

Why the Skyscan shows stripes and not spots

The Skyscan in Figure 1 shows a bright stripe of energy across the sky, rather than a peak, that passes through the true signal origin. This is not a limitation of the Skyscan algorithm, but a consequence of the geometry of the receiver motion.

It is this geometry that determines what can be resolved. As the receiver moves, its antenna positions over the integration interval form a synthetic array. A stationary receiver forms no array, so no direction can be resolved. A trajectory that curves, such as when the vehicle is turning a corner, can resolve the signal origin to a single direction. However, most commonly, a vehicle’s trajectory over one second is a straight line. As a result, the synthetic array formed by the antenna positions sampled over that interval is therefore also a straight line. A one-dimensional synthetic array constrains the direction of arrival to a cone of solutions, appearing here as a stripe rather than a unique direction.

Angular selectivity therefore depends on how far the receiver moves during the Supercorrelation period as well as the shape of its trajectory. Greater displacement produces larger residual phase for an incorrectly assumed direction, and so sharper discrimination (a narrower stripe). A stripe is enough to authenticate most signals, as we show next. Later, we combine Skyscans taken while the vehicle turns a corner, forming a two-dimensional aperture that resolves each signal to a single direction of arrival.

The real-world meaconing scenario

To demonstrate the capability of Skyscan, we look at data collected from an open-air meaconing scenario during Jammertest 2025 (scenario 3.1.3). A high power stationary meaconer on a nearby mountain receives and rebroadcasts all GNSS signals in the L1 and L2 frequency bands. Our vehicle, set up with a LabSat connected to a single antenna on the roof, moves into the meaconed area while recording the GNSS spectrum.

Because the meaconer rebroadcast only L1 and L2, the authentic L5 signals from the satellites reach our antenna largely free of interference. The Galileo E1C signals in our recording were therefore meaconed and the E5Q signals were not, giving us a known-authentic and a known-inauthentic population recorded through the same antenna, on the same drive, at the same instants.

For more on the meaconing scenario, the hardware and how Supercorrelation recovers the authentic signal from beneath the rebroadcast, see our previous post.

How Skyscan distinguishes authentic from meaconed signals

Figure 2: Skyscans for the Galileo E1C PRN 13 signal before meaconing at 140.5 s (a) and during meaconing at 155.5 s (b, c). Panel (b) shows the Skyscan at the meaconed code phase; panel (c) shows the line-of-sight component recovered during meaconing. The expected satellite direction is indicated in blue and the approximate meaconer direction in red. A common 0–40 dB-Hz scale is used, with values outside this interval clipped.

At 155.5 s the meaconed signal dominates. Evaluated at its code phase (panel b), the stripe has moved off the satellite and instead passes close to the estimated meaconer direction. The red marker is drawn large as the meaconer’s broadcast antenna location is only approximately known.

Panel c shows the same epoch again, this time evaluated at the expected code phase of the authentic satellite signal. Despite the much stronger meaconing signal and increased noise floor due to the rebroadcast, Supercorrelation enables the authentic signal component to be observed, as indicated by the stripe of signal power coinciding with the expected satellite direction.

So from a single 1-second epoch, from a single antenna, we see both signals claiming to be PRN 13 and we can tell them apart by their angle of arrival.

The next figure shows the impact of meaconing across multiple signals.


Figure 3: Skyscans for the meaconed Galileo E1C PRNs 8, 13 and 15 at epoch 165.5 s.

A clear indication that a receiver is being meaconed or spoofed, is that many different satellite signals appear to originate from a single source. This is exactly what the figure above demonstrates with the E1C signals.

Occasionally, the geometry of the trajectory places the meaconed signal’s Skyscan stripe close to the authentic satellite direction. This occurs for PRN 15 roughly between 150 and 157 s. For linear motion, a single epoch is then not enough to verify a signal’s origin as authentic. In the paper we address this with a cone-angle error, δcone. This is the difference between the angle of the measured Skyscan stripe and the angle towards the true satellite direction, both with respect to the vehicle’s velocity vector. Tracking δcone over the course of a short drive, as the heading changes (the vehicle turns) and the geometry shifts, separates the meaconed signals from the authentic signals.

Skyscans with even better geometry

As mentioned previously, the geometry of the synthetic aperture strongly affects Skyscan’s ability to determine a direction of arrival at any given epoch. To show Skyscan more precisely locating the signal origin, we combine consecutive epochs while the vehicle turns a corner (Figure 4).

Figure 4: Combined Skyscan formed from ten consecutive one-second Skyscans during a turn. Top row: meaconed E1C signals. Bottom row: authentic E5Q signals. Maxima are shown in green and blue dots show actual satellite locations.

As the heading changes, the synthetic aperture rotates with it, and so does the stripe in each individual Skyscan. Their common intersection does not move, so summing ten consecutive one-second Skyscans and renormalising therefore reinforces the true signal direction while the stripes themselves wash out. While this is not the same as a single ten-second coherent integration, it resolves the ambiguity of the individual stripes and localises the signal power to a small region of sky.

The maxima of the authentic E5Q Skyscans sit on their respective satellites. The maxima of the meaconed E1C Skyscans converge on a single point, consistent with the approximate meaconer location.

Conclusions and what’s next

Spatial processing is widely regarded as among the most effective approaches to spoofing and meaconing detection. It exploits a fundamental physical property of authentic GNSS signals: each satellite signal should arrive from a distinct and predictable location in the sky. Bad actors cannot reproduce that spread across the constellation, so estimating the direction of arrival reveals which signals did not come from the satellite they claim to.

Until now, that kind of spatial discrimination has required extra hardware and with it an increase in cost, size, weight and power that keeps such systems out of mass-market platforms. Skyscan provides the same spatial authentication using a single element antenna and RF front end.

To learn more, contact us.

Cover pic taken at Jammertest 2025, Andoya, Norway. © Laurence Bennett. 

Leave a Reply

Your email address will not be published. Required fields are marked *

Join our community and stay up to date

We are in a rapidly evolving industry. To be among the first hear about our product developments, upcoming webinars and events, and industry news, join our community. We respect your time and privacy, so we'll only send you relevant, valuable content, and your data won't be shared with any third parties.

Join us