“We Need More Than GPS” – New NIST Efforts

October 26, 2020

Written by Editor

RNT Foundation Image: Historic High Accuracy Clock on Display at NIST

Blog Editor’s Note: Interesting two-in-one press release from NIST.  

First they are looking for comment on their draft cyber security profile for PNT users. This document seeks to identify:

  • Gaps in existing standards, guidelines and practices associated with the responsible use of PNT services.
  • Additional guidance on the application of the Cybersecurity Framework that can be provided as examples in the Appendix.
  • The degree to which the Cybersecurity Framework functions, categories, and subcategories adequately address the broad scope of cybersecurity concerns regarding the responsible use of PNT services.
  • Additional informative references such as standards and guidance documents that can be implemented into the core.
  • Whether the controls and informative references are adequate and appropriate.

So, comments on a document that will tell you how to protect yourself.

Second they seem to be announcing an new system for distributing time without GPS.  When you click further to the root documents, though, they are really announcing a special test program that will be reevaluated in six months. The program would allow companies to connect by fiber “at cost”  to NIST at a 1 microsecond level of accuracy relative to UTC, with the eventual goal of 100 ns accuracy. 

These efforts are in response to the the Feb. 12, 2020, Executive Order 13905, Strengthening National Resilience Through Responsible Use of Positioning, Navigation, and Timing Services

As we have mentioned before, the taskings in the Executive Order were “necessary, but not sufficient” to protect the nation. 

RNT Foundation urges the government to adopt, lead, and sponsor as needed a Resilient National Timing Architecture that provides multiple paths to UTC for fixed and mobile users.  See our recent white paper.  Doing so will make timing users virtually bullet-proof.

Of course, that could involve spending some money.

Good on NIST for doing what they can without an appropriation for this.

 

Safeguarding Critical Infrastructure: NIST Releases Draft Cybersecurity Guidance, Develops GPS-Free Backup for Timing Systems

NIST responds to recent Executive Order on strengthening U.S. technological resilience.

Share

NIST’s new cybersecurity profile is designed to help mitigate risks to systems that use positioning, navigation and timing (PNT) data, including systems that underpin modern finance, transportation, energy and other critical infrastructure. While its scope does not include ground- or space-based PNT source signal generators and providers (such as satellites), the profile still covers a wide swath of technologies.

Taking another step toward strengthening the nation’s critical infrastructure, the National Institute of Standards and Technology (NIST) has drafted guidelines for applying its Cybersecurity Framework to critical technologies such as the Global Positioning System (GPS) that use positioning, navigation and timing (PNT) data. Part of a larger NIST effort to implement a recent Executive Order to safeguard systems that rely on PNT data, these cybersecurity guidelines accompany recent NIST efforts to provide and test a resilient timekeeping signal that is independent of GPS.

Formally titled the Cybersecurity Profile for the Responsible Use of Positioning, Navigation and Timing (PNT) Services (NISTIR 8323), the new guidelines are designed to help mitigate cybersecurity risks that endanger systems important to national and economic security, including those that underpin modern finance, transportation, energy and additional economic sectors. The agency is requesting public comment on the draft by Nov. 23, 2020.

The draft profile is part of NIST’s response to the Feb. 12, 2020, Executive Order 13905, Strengthening National Resilience Through Responsible Use of Positioning, Navigation, and Timing Services. Earlier this year, NIST sought public input regarding the general use of PNT data.

Do you know what PNT stands for? There are billions of devices around the world that rely on these services, and our economy depends on them. Learn how it affects you in this explainer video. For more information, go to www.nist.gov/pnt.

The PNT profile will join the growing list of profiles created to help apply the NIST Cybersecurity Framework to particular economic sectors, such as manufacturing, the power grid and the maritime industry. The scope of the profile includes any system, network or other asset that uses PNT services, including systems that receive and rebroadcast PNT data.

While its scope does not include ground- or space-based source PNT signal generators and providers (such as satellites), the profile still covers a wide swath of technologies. Partly for this reason, NIST’s Jim McCarthy said that it is intended to be a foundational set of guidelines that PNT users can customize.

“The profile is meant to help a broad set of users address their cybersecurity needs,” said McCarthy, one of the draft’s authors. “Rather than focus on a single economic sector, we designed it to apply to all users of PNT. Agencies and companies can tailor it to their needs based on their particular cybersecurity risk and other sector-specific factors.”

As directed by the Executive Order, the profile can help organizations accomplish four tasks:

  • Identify systems that use PNT data, and/or that propagate this data based on a source signal.
  • Identify PNT data sources, such as a GPS signal.
  • Detect disturbance to and manipulation of systems that use PNT services.
  • Manage the risks that come with responsible use of these PNT services.

“Our premise is that there are organizations that may not realize they are using PNT data, or know how they are using it,” McCarthy said. “Part of our goal is to help them make these connections so they can protect their operations more effectively.”

The Executive Order also delegates to the Department of Commerce the critical task of providing a source of Coordinated Universal Time (UTC) that is independent of GPS. To this end, NIST also recently conducted initial tests of a special calibration service for companies, utilities or other organizations that wish to receive NIST’s version of the global time standard, UTC(NIST), through commercial fiber-optic cable. The service aims to provide a time reference directly traceable to UTC(NIST) with an accuracy of 1 microsecond — good enough for telecom networks, the power grid and financial markets, and thereby boosting the resilience of accurate time distribution and the infrastructure sectors and subsectors that use timing services.

The initial link is a collaboration between NIST and OPNT, a commercial time-service provider based in Amsterdam, the Netherlands. While the work was led by researchers at NIST’s Boulder, Colorado, campus, the dedicated optical fiber connects the reference time scale at NIST headquarters in Gaithersburg, Maryland, to a facility in McLean, Virginia, that will ultimately serve as the hub for East Coast distribution of timing data.

OPNT has extended the initial fiber link to Atlanta, Georgia, about 800 kilometers from McLean. Preliminary data suggest that this link will be able to support the requirements of the Executive Order. NIST and OPNT have also begun a study of a West Coast link that will provide similar fiber-based time service to San Jose, California, and other locations in Silicon Valley from the NIST time scale in Boulder, Colorado.

Any extensive disruption to GPS signals would be highly disruptive to critical infrastructure in the United States, as would the sort of spoofing and manipulation of timing data that the PNT profile is designed to mitigate. As technologies that depend on trustworthy location and timing data grow more commonplace — such as interconnected Internet of Things devices and automated transportation — identifying and protecting these systems and data from cyber threats will only grow in importance.

“The ultimate goals are to identify systems that use PNT data and to detect disturbances to it,” McCarthy said. “Doing so can help mitigate the risk of misuse of PNT data affecting our critical infrastructure, public health and national security.”

NIST is accepting comments on the draft profile via email no later than Nov. 23, 2020. Submission details are available at the profile website.

What Can YOU Do? How Can YOU Help?

PNT is the quiet backbone of everything but too many leaders still don’t see the risk.

But you do. You understand the systems, the dependencies, the failure chains. That insight is rare — and it’s exactly what your country needs right now. Contact your government leaders and industry decision-makers and tell them resilient PNT isn’t a feature — it’s the foundation everything else depends on.

Start the Conversation

Use our Resilient PNT Key Talking Points to make the case.

U.S. Advocates

Find your representatives at Congress.gov, then use our email template to reach them in minutes.

When you get a response, let us know. Every conversation strengthens the mission.

More PNT News

“We can track Starlink users…” – Fast Company

“We can track Starlink users…” – Fast Company

Image: Shutterstock What's new: A report that multiple companies are offering governments the ability to geolocate Starlink terminals.  Why it's important: Security concerns - an adversary could target, kidnap, kill, etc. users. Privacy concerns - user location data...

Honeybees teach drones how to navigate without GPS – Cybernews

Honeybees teach drones how to navigate without GPS – Cybernews

Image: Shutterstock What's new: An interesting form of autonomous navigation based on nature. Why it's important: Autonomous systems have an important place in an overall PNT architecture. For some applications they are the best/only method. This system uses just 42...

PNT cyber guidance update – NIST wants your input

PNT cyber guidance update – NIST wants your input

Image: RNT Foundation What's new: Draft updated PNT cyber guidance from NIST. They are seeking public comment and input. Why it's important: PNT and cyber are well intertwined. PNT is an essential tech infrastructure so protecting it from malicious cyber effects is...

GPS Is Not Guaranteed: Impact on ports (Webinar 21 May)

GPS Is Not Guaranteed: Impact on ports (Webinar 21 May)

Image: Shutterstock What's new: A webinar featuring our colleague Matt Shirley. Matt is a professional port pilot and has some interesting insights on maritime reliance on GPS/GNSS, how things could go wrong without resilient PNT, and how things could go better with...

Intl Airline Pilots Assn calls for changes & GPS backup

Intl Airline Pilots Assn calls for changes & GPS backup

Image: Aircraft near Delhi, India being spoofed 5 Nov 2025 - GPSWise What's new: The International Federation of Air Line Pilots’ Associations (IFALPA) called for actions to combat GNSS disruption from ICAO, nations, air navigation service providers, manufacturers,...

Get PNT News in Your Inbox