DEV Community

NextTechWorld
NextTechWorld

Posted on

How GNSS Jamming Actually Works

How GNSS Jamming Actually Works

When four Ukrainian military drones turned up in Finland in March and April, the strange part was not simply that unmanned aircraft had crossed into NATO airspace. Drones have been spilling across borders throughout the war in Ukraine, sometimes because of malfunction, sometimes because of interception, sometimes because long-range one-way systems are launched into a battlespace where weather, electronic warfare, and imperfect autonomy all collide. What made the Finnish incidents technically revealing was the explanation given by Finnish police and border authorities after their investigation: satellite navigation interference, combined with wind, had helped push the aircraft away from their intended routes and into Finnish territory. Finnish authorities said the drones were not aimed at Finland, while Finland’s transport and communications regulator has separately reported continued GNSS and mobile communications interference, especially in border and maritime regions, with GNSS interference affecting aviation, maritime navigation, boating, and drones.


That detail matters because it turns GNSS jamming from an abstract electronic-warfare phrase into a mechanical fact of modern navigation. A drone does not need to be “hacked” in the Hollywood sense to be made unreliable. It does not need a hostile operator to take over its flight computer, rewrite its mission plan, or steer it with a joystick. It may be enough to damage the invisible measuring system on which the aircraft depends. Remove trustworthy satellite navigation, and a machine that was built to follow a neat line across a digital map suddenly has to infer where it is from inertial sensors, airspeed estimates, wind assumptions, magnetometers, terrain references, or whatever fallback system its designers could afford to install. In calm conditions over short distances, that may be survivable. Over long distances, in poor weather, under battlefield stress, with wind pushing the airframe sideways, and with an autopilot that was optimized for cost, endurance, payload, or manufacturability rather than perfect navigation resilience, small errors can grow into geopolitical incidents.


The same basic physics affects far more than military drones. Civil aircraft, ships in the Baltic Sea, agricultural machines, telecom base stations, container ports, power grids, financial trading systems, smartphones, autonomous vehicles, and emergency services all lean on Global Navigation Satellite Systems, or GNSS. GPS is the best-known member of that family, but modern receivers often listen simultaneously to the American GPS, Europe’s Galileo, Russia’s GLONASS, China’s BeiDou, and sometimes regional augmentation systems. The promise sounds robust: dozens of satellites, multiple constellations, global coverage, meter-class accuracy in a consumer device, centimeter-class accuracy with corrections. Yet the radio signals that make all of this possible arrive at Earth after a journey of roughly 20,000 kilometers or more, so weak that they are buried below the thermal noise floor before signal processing pulls them back into usefulness. That is GNSS’s miracle, and also its central vulnerability.


The Finnish drone incidents are therefore a good entry point into a larger question: how does GNSS jamming actually work? Not as a vague cloud of “interference,” but as a chain of RF events inside a receiver. What does a jammer transmit? Why can a small transmitter on the ground overpower satellites in orbit? What happens to C/N₀, the carrier-to-noise-density ratio that GNSS engineers watch like a vital sign? How does automatic gain control, or AGC, react when the front end is flooded with unwanted RF energy? Why does jamming differ from spoofing, and why do modern multi-constellation receivers sometimes degrade gracefully, sometimes fail abruptly, and sometimes report positions that look plausible until they are disastrously wrong?


The satellite signal that arrives almost as a whisper


GNSS begins with an engineering compromise that still feels audacious. A satellite carries an atomic clock, broadcasts a precisely timed signal, and tells receivers where the satellite was when the signal left. The receiver does not “see” the satellite in an optical sense; it measures how long the radio signal took to arrive. Multiply travel time by the speed of light, correct for clock errors and atmospheric delays, repeat the process with several satellites, and the receiver can solve for position and time. This is a ranging system disguised as a navigation system. The map display, the blue dot, the drone route, the ship’s electronic chart, and the timestamp in a cellular network all rest on radio time-of-flight measurements.


The most familiar civil GPS signal is L1 C/A, centered at 1575.42 MHz. It uses direct-sequence spread spectrum, meaning the transmitted signal is spread across a wider bandwidth by a pseudorandom code that the receiver knows in advance. Each GPS satellite uses a distinct PRN code, allowing a receiver to separate multiple satellites occupying the same frequency band. To a receiver that does not know the code, the signal resembles noise. To a receiver that does know the code, correlation processing concentrates the signal energy and reveals a timing peak. That peak is what the receiver tracks. The whole system depends on the receiver maintaining lock on code phase, carrier phase or frequency, navigation data, and time.


The brilliance of spread spectrum is that it lets GNSS function with extremely weak received power. The satellite does not need to blast Earth like a radar beam. Its signal can be below the noise floor at the antenna terminals, yet still recoverable because the receiver integrates energy over time using the known code. The weakness is that spread-spectrum processing gain is not magic. It improves the receiver’s ability to dig out the desired signal, but the front end still has finite dynamic range, the analog-to-digital converter still has limited bits, the tracking loops still need enough signal quality, and the acquisition engine still has to search code delays and Doppler bins against a noisy background. A hostile transmitter does not need to imitate GPS perfectly to cause trouble. It can simply raise the noise and distortion environment until the receiver can no longer maintain the delicate correlations it needs.


This is why GNSS jamming is technically different from most people’s intuition about radio range. A GPS satellite may transmit from orbit using substantial power, but by the time the signal reaches a small patch antenna on a drone or phone, it is extraordinarily faint. A jammer on or near the ground does not compete with the satellite at the satellite. It competes at the victim receiver’s antenna. A low-power transmitter a few kilometers away, or a higher-power transmitter tens of kilometers away from an aircraft at altitude, can create more received power at the receiver than all visible satellites combined. The geometry is brutal. The legitimate transmitter is far away; the jammer is nearby. Free-space path loss gives the local interferer an overwhelming advantage.


A simple personal privacy jammer in a car may be crude, illegal in many jurisdictions, and poorly filtered, but it illustrates the same principle. It emits RF energy around one or more GNSS bands and reduces the receiver’s ability to acquire or track satellites. A military jammer can be directional, frequency-agile, higher power, better synchronized, integrated with sensors, and deployed in networks. It may target GPS L1, GPS L2, GPS L5, Galileo E1, GLONASS L1, BeiDou B1, or several bands at once. It may use broadband noise, swept tones, pulsed interference, matched-spectrum noise, chirps, or deceptive waveforms. But the fundamental aim in jamming is usually denial. The receiver should lose confidence, lose lock, take too long to reacquire, or fall back to a degraded navigation mode.


The receiver’s first line of defense is not intelligence but RF plumbing. A GNSS antenna collects a mix of satellite signals, thermal noise, out-of-band transmitters, nearby electronics, harmonics, and whatever intentional interference is present. A low-noise amplifier boosts that tiny signal mixture. Filters try to reject energy outside the band of interest. A mixer converts the RF signal down to an intermediate frequency or directly to baseband. An analog-to-digital converter samples it. Digital signal processing then correlates the samples against local replicas of satellite codes. This chain is optimized for weak desired signals and low power consumption, especially in phones and small drones. It is not usually optimized to survive a nearby transmitter deliberately pouring energy into the passband.


Jamming is not spoofing, and the receiver knows the difference only sometimes


The popular vocabulary around navigation attacks often blurs two very different techniques. Jamming is denial: it makes the legitimate GNSS signals hard or impossible to use. Spoofing is deception: it feeds the receiver false GNSS-like signals so that the receiver computes the wrong position or time. Both can coexist, and both can produce similar symptoms at the application layer, such as a drone drifting off course or a ship appearing in the wrong place on a chart. At the RF and signal-processing level, however, they are different animals.


A basic jammer can be almost stupid. It may not know where the satellites are, what codes they use, what time it is, or which receiver it is attacking. It just transmits noise or tones in the GNSS band. If it raises the effective noise density enough, the receiver’s correlation peaks shrink relative to the background. Tracking loops begin to jitter. The navigation solution becomes noisier. Eventually satellites drop from the solution, dilution of precision worsens, and the receiver may output no fix. In some receivers, the transition is obvious: satellites disappear, C/N₀ collapses, and the device reports loss of GNSS. In others, especially those that blend GNSS with inertial sensors, barometers, wheel ticks, cameras, or maps, the user may see a position that continues moving smoothly even though satellite truth has been lost.


Spoofing requires more finesse. A spoofer must generate signals that resemble real GNSS signals closely enough for the receiver to acquire or track them. It may begin by aligning false signals with authentic ones, then slowly pull the receiver’s tracking loops away, a technique often called carry-off. If done well, spoofing can be subtler than jamming because the receiver still sees strong, apparently well-structured satellite signals. C/N₀ may even improve. The front end may not be overloaded. The navigation engine may compute a beautifully consistent but false solution. For timing receivers in telecom or power infrastructure, a spoofer may not need to move a position at all; shifting time by microseconds or milliseconds can be the attack.


Yet spoofing is harder to generalize because GNSS signals contain structure, geometry, and timing relationships. A spoofer that deceives one receiver may fail against another with a better oscillator, multi-frequency tracking, inertial cross-checks, encrypted military signals, antenna arrays, or receiver autonomous integrity monitoring. It must handle Doppler shifts, code phases, navigation data, satellite ephemerides, receiver motion, and often multiple constellations. Military receivers may use encrypted signals unavailable to a civil spoofer. Civil receivers increasingly look for impossible satellite geometries, suspiciously uniform signal powers, abnormal clock behavior, or disagreement between constellations. Spoofing can be powerful, but it is a crafted lie. Jamming is the thrown brick.


That distinction matters for drones. A jammed drone may know that GNSS has become unreliable and switch to inertial navigation, terrain matching, optical flow, dead reckoning, or a preprogrammed failsafe. A spoofed drone may believe it is still navigating normally while being led astray. A partially jammed receiver may behave in between: some satellites are lost, others remain; some constellations degrade while others continue; the navigation filter stretches its uncertainty model; the autopilot still receives position fixes, but their accuracy and continuity worsen. Many real incidents are messy because the RF environment is not a clean laboratory case. A receiver may encounter jamming from one direction, multipath from water or buildings, intermittent antenna shadowing, high aircraft dynamics, ionospheric disturbance, and software assumptions that were never tested under battlefield-grade interference.


For a long-range drone, the difference between “GNSS denied” and “GNSS misleading” can blur at the mission level. Suppose the aircraft is flying a route based on waypoints. The autopilot wants to minimize cross-track error: it compares the current estimated position with the desired path and commands bank, rudder, or control-surface changes accordingly. If GNSS drops out, the autopilot may propagate position using an inertial measurement unit. Low-cost MEMS gyros and accelerometers are remarkable devices, but their errors accumulate. Biases, scale-factor errors, vibration, temperature drift, and imperfect alignment turn into growing position uncertainty. Wind makes it worse because the aircraft’s heading is not the same as its ground track. Without a trustworthy external position update, the drone can fly the right attitude and airspeed while the moving air mass carries it somewhere else.


This is one reason GNSS interference becomes geopolitically visible around borders. A small navigation error over a short flight might be unremarkable. A sustained error over tens or hundreds of kilometers can move an aircraft across a national boundary. The machine may not be trying to violate airspace. It may simply be following a corrupted estimate of itself. Electronic warfare does not merely break electronics; it reshapes the map inside the machine.


C/N₀, AGC, and the anatomy of receiver failure


GNSS engineers often diagnose jamming through C/N₀, usually expressed in dB-Hz. The term means carrier power divided by noise power spectral density. In ordinary language, it is a measure of how clearly the receiver can observe a satellite signal relative to the noise environment after accounting for bandwidth. A strong, clean GNSS signal might appear to a receiver with a C/N₀ in the high 40s or low 50s dB-Hz under good open-sky conditions. Signals lower on the horizon, blocked by foliage, reflected by buildings, or degraded by interference may sit much lower. When jamming begins, C/N₀ values across many satellites often drop together because the receiver’s noise floor has effectively risen.


The important point is that the satellite did not become weaker. The receiver’s environment became louder. Imagine trying to hear several people whispering different known phrases from across a room. Under normal conditions, you can pick out each whisper because you know what to listen for. If someone turns on a vacuum cleaner next to your ear, the whispers are still there, but your ability to correlate sound with the expected phrases collapses. GNSS spread spectrum works better than human hearing, but the metaphor is useful. Jamming is not always a single overpowering tone. Often it is a deliberate increase in the apparent noise density around the signals the receiver must track.


C/N₀ degradation appears first as reduced margin. The receiver can still track satellites, but the code tracking loop becomes noisier. Pseudorange measurements wander. Carrier tracking may slip. Velocity estimates derived from Doppler become less stable. The navigation filter may continue to output positions, but estimated accuracy grows. If enough satellites remain above threshold, the user may see only degraded precision. If satellites drop below threshold one by one, the position solution may become geometrically weak. The receiver needs at least four satellites for a basic three-dimensional position and clock solution, but “four satellites” is not the same as “good navigation.” If the remaining satellites cluster in one part of the sky, vertical error may explode. If the receiver excludes inconsistent measurements, it may suddenly lose the fix even though some signal bars remain.


AGC tells a different but complementary story. Automatic gain control exists because a receiver front end must keep signal levels within the usable range of its analog and digital stages. Too little gain and the ADC quantizes mostly noise with insufficient resolution. Too much gain and the ADC saturates, clipping the waveform. GNSS receivers normally expect a relatively stable noise-like input at very low power. When a jammer enters the passband, total received power can rise sharply. The AGC responds by reducing gain to prevent overload. That protects the ADC from saturation, but it also reduces the gain applied to the legitimate satellite signals. If the jammer dominates the input power, the receiver has effectively adjusted itself around the jammer rather than the satellites.


This is why AGC readings can be useful for interference detection. A sudden AGC drop, especially when accompanied by simultaneous C/N₀ declines across multiple satellites and constellations, is a strong hint that the front end is seeing abnormal RF power. Some receivers expose AGC values to developers; others hide them. Professional monitoring stations often log AGC, C/N₀ by satellite and frequency, raw measurements, spectrum snapshots, and navigation residuals. From those traces, analysts can distinguish a local antenna problem from broad interference, identify whether L1 alone or multiple bands were affected, and sometimes infer the jammer type. A narrowband tone, a swept chirp, and broadband noise do not leave identical fingerprints.


The receiver’s failure mode depends heavily on the jammer waveform. A continuous-wave tone near the GNSS band may desensitize parts of the front end or create intermodulation products, but a well-filtered receiver may tolerate some narrowband energy better than broadband noise. A chirp jammer sweeps across the band, briefly disrupting many code frequencies and confusing acquisition and tracking loops. Pulsed jamming can be efficient because it exploits receiver dynamics and AGC response: high peak power bursts may drive gain changes, clipping, or loop disturbances even when average power is moderate. Matched-spectrum jamming shaped to resemble GNSS signal bandwidth can be harder for simple filters to reject. A sophisticated system may choose waveforms based on the target: denying consumer navigation is easier than degrading a hardened airborne receiver, and preventing acquisition may require less power than breaking an already stable tracking lock in some scenarios, while in others tracking loops can be more vulnerable to specific dynamics.


GPS L1 is the classic target because it is ubiquitous. The L1 C/A signal is used by an enormous installed base of civil receivers, and many low-cost drones still rely heavily on L1-band GNSS even when they advertise multi-constellation support. But multi-constellation does not automatically mean multi-band, and multi-band does not automatically mean jam-proof. A receiver that tracks GPS L1, Galileo E1, BeiDou B1, and GLONASS L1 is still concentrating much of its dependence in a crowded portion of the L-band near 1.57 GHz or nearby allocations. A jammer with enough bandwidth or multiple transmit channels can degrade several constellations together.

Top comments (0)