
The current state of GPS following OCX with Dr. Sean Gorman, CEO of Zephr.xyz.
Sean Gorman: One of the really interesting facets on this is beginning to understand how the specific jamming and spoofing attacks on the cybersecurity and kind of RF security side are growing and evolving because, you know, even a few years ago, jamming and spoofing were kind of one-off events that might impact something directly on a military conflict, but wasn't something that most of us saw on a day-to-day basis, but the current landscape of jamming and spoofing that we're seeing these activities persist over geographies long term.
Maria Varmazis: Welcome. I'm Maria Varmazis and you're listening to "T-Minus: Space-Cyber Briefing." In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects, and connects our lives. Hello and thanks for joining me today. It is inevitable and inescapable that a show like ours about cybersecurity and space is going to talk quite a bit about the global navigation satellite systems, especially the United States' Global Positioning System, or GPS, it is the backbone for so much of how our modern world works. And it has been around for quite some time. An initiative to modernize GPS operations in cybersecurity called the Next Generation Operational Control System, or OCX, was cancelled by the U.S. Space Force for being over budget and behind schedule. So what does this cancellation mean for GPS and how we use it? Well, in today's episode, I am speaking with Dr. Sean Gorman, who is the CEO of Zephr, to discuss all of these and other concerns about the secure future of GPS. Here's our conversation.
Sean Gorman: I am Sean Gorman. I'm one of the founders of Zephr. We do navigation-powered artificial intelligence. And that combines positioning, localization, understanding where a user is and what they're looking at. And, as part of that work, we have gotten pretty involved in understanding ENT from a low level, including some defense work which has brought us over into the world of jamming and spoofing, and also a bit of my background over the years working for a couple different startups that have built within stack, mostly in the geospatial mapping and positioning space.
Maria Varmazis: Thank you so much for joining me today. A lot of folks, I think they think they know a lot about GPS and how it works, and also how it can potentially be monkeyed with. And I find often that there are a lot of perceptions that have to get busted just when starting a conversation like this. I imagine you have - you have found the same. Maybe we just start real simple right there before we dive in too much deeper on what exactly - when we're talking about GPS jamming and spoofing, there are lots of different things that can happen there. Can you walk us through that just to start?
Sean Gorman: Yeah, definitely. I think, you know, one of the big misnomers is that there's just one constellation that is GPS that runs positioning on your smartphone, let's say. And, typically, GPS is just one constellation of a much larger set of constellations that are called GNSS, or Global Navigation Systems. And that includes the U.S.' GPS constellation, the Europeans also have a Galileo constellation, the Chinese have a constellation called BeiDou, the Russians have a constellation called GLONASS. There's also regional constellations that Japan and India run. So there's a whole bunch of satellites up in the sky. Sate - GPS itself is about 32 constellations. And, across all of those constellations, they're all a trusted network. Right? You know, we interconnect with Russian and Chinese constellations on our smartphones and we trust the signals across those different constellations. But that doesn't mean that there aren't bad actors out there. Typically, that doesn't happen at the satellite level where the satellites are causing problems, but there are bad actors at the terrestrial levels. There's GPS jammers which send out big, disruptive, high-frequency jamming signals that disrupt the very weak signals that come from the satellites way up in space. Those are pretty weak and so, if you have a really high-powered disruptor that's operating at the same frequency as those GPS and GNSS signals, it can disrupt it and make it impossible to position with your phone. And then the other attack that we see commonly is spoofing where, instead of trying to disrupt that signal, it's trying to fake a signal and put an artificial signal into your receiver that's much more high powered than what's coming from the satellite with a fake location. And so, instead of showing, you know, I'm in Boulder, Colorado right now, they might fake it and show me somewhere else. Like showing that I'm at the airport, for instance, is a really common thing because if drones, for instance, are - find themselves thinking they're at an airport, they immediately land and disable themselves because they don't want to enter airspace. So you see a variety of these kind of spoofing things happening along with jamming things. But that's kind of a high-level breakdown of kind of how these constellations work together and then how bad actors try to disrupt those constellations.
Maria Varmazis: Yeah. So I wanted to ask - so this is something I actually wasn't entirely aware of, to be honest, something called OCX. Can you tell me a little bit about what that is and how that relates to GPS? Or, "what it was" maybe is really more the question that I should be asking.
Sean Gorman: Yeah. So OCX was the next-generation ground station that connects to the satellites up in space. So when you think of the GPS satellites, you know, the 32 of them revolving around the Earth, but you need to get the data from those satellites or, more accurately, the ephemeris for where they're located at in space down to these ground stations. So the ground stations track where the satellites are. And, in order for, you know, GPS positioning to work in general, you need to not only know - you know, you're trying to figure out where the receiver is on the ground, but, to do that, you need to know where the satellites are within a high level of accuracy. So in order to track where those satellites are where you have a sophisticated set of ground stations that track the exact location within a meter or two of where that satellite is in space. And so those ground stations become really critical. So the old ground station system was built in the 1990s, it was called AEP, but it was this monolithic structure that was built to track all of these satellites. But, as we've been modernizing and putting up the new GPS III Satellites, there's a lot of things that people wanted to do with a more modern ground station system. And so OCX was this next-generation ground system that they'd spent six or seven billion dollars on to replace the 1990s AEP system with a much more robust, sophisticated set of ground stations to track these satellites up in space.
Maria Varmazis: Hmm. And yet it - so - but it got cancelled? Is that my understanding? What happened there?
Sean Gorman: Yeah. Well, it ends up it's really hard to upgrade a massive monolithic system all in one go and make it completely backwards compatible with the system that was there before. And so that, you know, largely became the problem. And, you know, you have billions of devices that rely on this system and we can't just take all of GPS down to do an upgrade. So you have to figure out how to upgrade that entire system in place and make it 100% backwards compatible to all of these devices that are already out there running on it. And I think that it's ended up being too Herculean of a lift to figure out, and they kind of came to a dead end on it. And, unfortunately, it got cancelled so now they're trying to figure out how to manage that with the existing AEP system. But it definitely kind of put an upward bound on how much we can modernize the current GPS system.
Maria Varmazis: So that's all well and good, but what's next then? What do we see for the future of GPS? Well, we're going to take a quick break and we'll get back into our discussion with Dr. Sean Gorman after this. So questions abound there certainly. And I'm wondering especially on the resiliency of how we are able to, for lack of better words, use and digest the signals that we're getting from GPS satellites. It sounds like we kind of avoided a solution. So what do we do now?
Sean Gorman: Yeah, I think that's an open question for a lot of people right now that people are trying to wrap their hands around. I think there is - you know, obviously, we've been patching and upgrading in dealing with the current architecture for quite a while. And, you know - and it is still a robust system that the globe depends on and operates quite well. But the extent to which we can modernize that to increase cybersecurity across our GPS system is going to be hampered by the fact that we can't modernize that ground segment. And then there's also soft power implications in that, you know, these - there is - there's GNSS positioning systems offered from a lot of countries. And it's a big soft power lever for the more countries and industries and technologies you can get dependent on your positioning system versus a rival's positioning system, the more soft power you have across the economic and military landscape. And China's system is much more modern and recent than ours with much more modern ground segment and more sophisticated satellites and signals. And so that's something that's been a concern on the American side for a while of BeiDou's growing advantages within PNT and how we can modernize GPS to keep up and ideally move ahead.
Maria Varmazis: Yeah, so that's a great point there. I mean, GPS was presumably the first to attempt what, you know, GNSS. I think that's correct. I'm not sure if that's -
Sean Gorman: Uh-huh -
Maria Varmazis: - true.
Sean Gorman: - yeah.
Maria Varmazis: But - yeah.
Sean Gorman: We invented it.
Maria Varmazis: Yeah, we invented it, it's ours, great. So - but, yeah, we are heavily constrained by '90s-era ground station technology, which is quite a constraint. Although my understanding is it's sort of a patchwork of solutions for trying to ensure resilience of the fidelity of the signal that you are receiving, that what you're getting is actually correct and hasn't been spoofed or otherwise messed with. Is that a correct read of the situation that we're - you know, we're going to have to sort of pull together a bunch of different solutions to ensure that sort of fidelity? Or is there maybe something else coming down the line that may fix a lot of our problems?
Sean Gorman: Yeah, I think that's correct, it is a patchwork. Although I think it really highlights and probably moves even more weight to a trend that was already happening, that there is not a silver bullet for having assured PNT globally, both from a defense and a commercial perspective, that, you know, we - it probably doesn't make the most sense to look at one single constellation as the path forward. And we already kind of see that with multi-constellation GNSS. But, even domestically within the U.S., I think increasingly we're looking at alternative constellations that could be leveraged. So Starlink has an amazing constellation up. It is already used effectively for positioning and that - within Starlink receivers. Actually, this is just getting turned off I think like May 20th. But you could use like a gRPC call to get the position for your satellite receiver as determined by Starlink and their constellations using Doppler shift and RTT.
Maria Varmazis: Wow.
Sean Gorman: Uh-huh. And -
Maria Varmazis: And they're turning that off?
Sean Gorman: Well, they're putting it behind a telemetry API. It used to be open to anybody, and so like the -
Maria Varmazis: Oh.
Sean Gorman: - the Iranians were hacking this to the Gui - drone attacks and also to find dissidents. So it's definitely being exploited in bad ways. So it's a good thing it's being secured. But it's also testament to the efficacy of an alternative constellation, or what they sometimes called signals of opportunity, to provide positioning. And so that's generally accurate I think within, you know, 20 meters, but probably can do even better than that with some dedicated use. So, you know, kind of the rudiment is that, you know, Starlink and SpaceX are working on a positioning system that can be directly leveraged against their constellation. And this telemetry API, well, my assumption is would be a first step in that direction.
Maria Varmazis: That's fascinating.
Sean Gorman: So you - yeah. So you have existing constellations, like Starlink, which are, you know, impressive in their scale and scope that potentially could provide positioning technologies that are resilient and separate from GPS. And then you also have dedicated constellations, like Xona, that are being built and funded to provide a Low Earth Orbit GNSS constellation that is, you know, completely separate, but operates on the same frequencies. And we'll have the ability, if it all works out, to connect to existing GNSS receivers and provide their signals as a - as an augmentation or an alternative to GPS.
Maria Varmazis: So do we think that the future of GNSS is going to be completely shifting to LEO? Or is it always going to be a multi-orbit solution?
Sean Gorman: I think it will always be a multi-orbit solution. I mean, there has a lot of good reasons to have GPS and GNSS satellites in Middle Earth Orbit because you need a lot fewer of them to give the position. And, you know, you can - 32 satellites can cover, you know, the Earth really quite well. When you start looking at a Low Earth Orbit, you know, and I'm not sure what zone this latest numbers are of, but, at least early on, it was like 360 satellites are going to be needed to provide global coverage. So you need a much larger footprint to cover that. And I think, you know, Galileo has plans for a combination of LEO and BEO satellites for their constellation. Chine - China with BeiDou is doing something similar. So these things do the - the multi-orbit approach complements itself quite well. And I think we'll see that happening going forward in the future as well, these blended hybrids won't be constellation approaches. And that's the wonderful thing with GNSS writ large is it's an open interoperable system that works quite well even with, you know, global powers that are oftentimes at odds with each other, yet we still are able to create these constellations that work seamlessly together across, you know, devices we all have in our pockets. We'll have - we'll - our multi-constellation whether it's your smartphone or your smartwatch or your wearable smart glasses, all of those things that are generally using multi-constellation technologies. One of the really interesting facets on this is beginning to understand how the specific jamming and spoofing attacks on the cybersecurity and kind of RF security side are growing and evolving because, you know, even a few years ago, jamming and spoofing were kind of one-off events that might impact something directly on a military conflict, but wasn't something that most of us saw on a day-to-day basis with the current landscape of jamming and spoofing, you know, we're seeing these activities persistent - persist over geographies long term. You know, whether it's the Baltics with the Russians jamming Northern Europe; or, in Ukraine, there's an ongoing conflict with jamming on both sides; in the Middle East, there's persistent jamming happening all along, you know, the areas around Israel and Iran and the Persian Gulf now up into Turkey. We see, you know, persistent activity oftentimes in Asia as well, especially in Myanmar. And these things are impacting global aviation, global maritime, as well as just people's day-to-day activities, you see these kind of funny/not funny stories of spoofing happening in Israel and Lebanon where, as I said before, were local - spoof locations to airports to defeat drone attacks. And so, you know, people will be on their driving apps or their dating apps and, all of a sudden, they're getting, you know, matched with somebody in a different country because their location's being spoofed to an entirely different place, oftentimes the Beirut or Cairo airports. So these - you know, these kinds of cyber and RF incidents are no longer contained to just military operations, they're rapidly bleeding into our day-to-day lives. And whether that's impacting summer travel because of what's happening in the Persian Gulf currently, or you get these weird wonky behaviors on your mobile phone, if you're in a geography that happens to be adjacent to a conflict and you're traveling through it.
Maria Varmazis: Well, this is super fascinating stuff. And I greatly appreciate your expertise today and speaking with me.
Sean Gorman: Yeah, definitely. Thanks for having me. And it was lovely getting to share the work the team's been plugging away with at Zephr.
Maria Varmazis: And that's "T-Minus: Space-Cyber Briefing" brought to you by N2K CyberWire. If you like what you heard today, you will also enjoy our newsletter, Signals and Space. You'll get research and notes pulled together by our producer, Ethan Cook, and me, along with this week's top space cyber news stories. Subscribe to it by visiting thecyberwire.com/newsletters and look for Signals and Space. You know, we'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like the show, please share a rating and review in your podcast app. You can also fill out the survey in the show notes or send us an email. Space@n2k.com is that email. We're proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn, and stay informed. As the nexus for discovery and connection, we bring you the people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com. Thanks for listening to "T-Minus." I am your host Maria Varmazis. The show is produced by Ethan Cook and Liz Stokes. We're mixed by Elliot Peltzman and Tré Hester, with original music by Elliot Peltzman. Our executive producer is Jennifer Eiben with content strategy by Ma'ayan Plaut. Peter Kilpe is our publisher. See you next week.
