ARAIM reference — advanced RAIM protection levels in Kshana
This note documents Kshana's open implementation of Advanced Receiver Autonomous
Integrity Monitoring (ARAIM): the algorithm, every assumption, the integrity
support message it consumes, and the validation status. The implementation lives in
src/raim.rs; this document is the prose companion that an
auditor (or a procurement reviewer) can read alongside the code.
ARAIM is the dual-constellation, multi-frequency successor to classic RAIM that the GPS (Global Positioning System)–Galileo Working Group C (WG-C) defined to support horizontal and vertical guidance down to LPV-200 (LPV: localizer performance with vertical guidance). It answers a single question for every epoch:
How large must the position-error bound (the protection level) be so that the residual probability of hazardously misleading information — an error larger than the bound while the bound is still inside the alert limit — stays under the integrity risk budget
P_HMI?
1. The integrity support message (ISM)#
The ISM is the per-constellation parameter set the user applies. It is modelled
explicitly by IntegritySupportMessage:
| Field | Symbol | Meaning |
|---|---|---|
sigma_ure_m |
σ_URE / SISE (signal-in-space error) | range-error RMS (root mean square) used for accuracy and continuity |
sigma_ura_m |
σ_URA / SISA (signal-in-space accuracy) | range-error bound used for integrity (≥ σ_URE) |
b_nom_m |
b_nom | maximum nominal range bias folded one-sided into the integrity bound (b_k = Σ_i |s_i|·b_nom); see §3 |
p_sat |
P_sat | prior probability of an undetected single-satellite fault |
p_const |
P_const | prior probability of a constellation-wide fault |
IntegritySupportMessage::gps_galileo_reference() returns the published WG-C
reference values: σ_URA = 0.75 m, σ_URE = 0.67 m, b_nom = 0.75 m,
P_sat = 1×10⁻⁵, P_const = 1×10⁻⁴ over the exposure interval. These are the
values used to size ARAIM availability in the reference literature; the operational
ISM is broadcast/ground-assembled and is configurable per constellation. The
distinction between σ_URA (integrity) and σ_URE (accuracy) is deliberate and is the
defining feature of the ISM concept.
.fault_priors() and .dual_fault_priors() hand these straight to the two engines.
2. Fault hypotheses#
ARAIM is a multiple hypothesis solution separation (MHSS) method. For each fault
hypothesis H_k it forms the all-in-view solution and the sub-solution that
excludes the faulted set, and bounds the position error under that hypothesis:
- Fault-free
H_0(prior≈ 1): the full all-in-view least-squares fix. - Single-satellite faults
H_i(priorP_sateach): every one-satellite exclusion sub-solution. This is the classic single-fault ARAIM baseline,araim_raim. - Constellation-wide faults
H_c(priorP_consteach): the sub-solution that removes all satellites of one constellation at once, the EU (European Union) ARAIM TN (technical note) / DO-316 extension implemented inaraim_dual_raim. WithP_const = 0this reduces bit-for-bit toaraim_raim.
3. Protection levels#
For each axis (vertical, horizontal) and each hypothesis the engine builds a mode
(p_fault, threshold, σ) where the threshold is the solution-separation detection
limit at the false-alert multiplier K_fa = Φ⁻¹(1 − P_fa / 2N) (a Bonferroni split
of the continuity budget over the N hypotheses). The protection level is the
smallest bound PL whose summed integrity risk
Σ_k p_fault,k · Q( (PL − b_k − T_k) / σ_k ) ≤ P_HMI
Implementation note.
b_k = Σ_i |s_{axis,i}|·b_nomis the one-sided nominal-bias projection onto the axis — the worst-case sum of per-satellite gain magnitudes (axis_bias_sum/horiz_bias_sum) — sourced from the ISM'sb_nom_m. The WG-C reference ISM usesb_nom = 0.75 m; withb_nom = 0the bound reduces to the zero-nominal-bias MHSS form. The runnableintegrityscenario exposessigma_ura_m(the integrity bound used for the protection level, clamped to ≥sigma_uere_mand defaulting to it) andb_nom_m(defaulting to 0), so the protection level is always sized with the integrity bound σ_URA, never the smaller accuracy σ_URE. This remains a modelled, non-certified ARAIM implementation — seeINTEGRITY.md.
meets the allocated budget ([araim_protection_level] /
araim_integrity_risk). VPL (vertical protection level) and HPL (horizontal protection level) are the vertical and
horizontal answers. The result also reports the integrity risk actually achieved
(≤ the allocation) and whether a sub-solution separated beyond its threshold.
This is the explicit ARAIM contract — "how large must the bound be?" — rather than the implicit, geometry-dependent risk of a fixed-multiplier classic RAIM.
4. Stanford diagram#
StanfordDiagram accumulates (error, PL) per epoch against a
fixed alert limit (AL) and classify_stanford sorts each into
available, system-unavailable (PL > AL, conservative), misleading
information (PL < error ≤ AL) or hazardously misleading information (error > AL
and > PL). stanford_svg renders the classic scatter — the
PL = error integrity boundary, the alert-limit guides, and one colour-coded
marker per epoch — as a self-contained SVG (Scalable Vector Graphics).
5. The dual-constellation benefit#
Two effects are demonstrated in
raim::tests::dual_constellation_improves_geometry_and_tolerates_a_constellation_fault:
- Geometry / redundancy — pooling a second constellation's satellites tightens the single-fault HPL: more measurements and a larger single-SV (SV: space vehicle, that is a satellite) sub-solution set give a strictly smaller bound.
- Constellation-fault tolerance — with
P_constactive, the dual user stays available when a whole constellation can fail (satellites of the other constellation survive), whereas a single-constellation user provably cannot be protected against its own constellation fault (araim_dual_raimreturnsNone).
A subtlety worth stating honestly: because the constellation-fault hypothesis requires surviving the loss of an entire constellation, the dual-constellation snapshot protection level is bounded below by the residual single-constellation geometry — it is not automatically smaller than the GPS-only PL at every instant. The headline EU ARAIM TN result that GPS+Galileo gives a 15–25 % smaller HPL is an availability result accumulated over realistic constellations and user locations, not a per-snapshot guarantee.
6. Validation status#
- In-repo, automated: the MHSS algebra (
P_const = 0⇒ bit-for-bit single-fault; constellation-fault widens the PL; budget never exceeded), the geometry and constellation-fault benefits above, and exercise on real IGS (International GNSS Service; GNSS = global navigation satellite system) precise-orbit (SP3, Standard Product 3) geometry (tests/igs_real_data.rs), not only synthetic constellations. - External oracle — the published WG-C worked example: the protection levels
are checked against the ARAIM Technical Subgroup's own numerical example, in
src/araim_reference.rs,tests/araim_reference_vectors.rsand the committed fixturetests/fixtures/araim_reference/wgc_araim_reference_vectors.txt(each vector carries its retrieval URL (web address), retrieval date, source-file SHA-256 (SHA: Secure Hash Algorithm) and page). The acceptance tolerance is the reference's ownTOL_PL = 5 × 10⁻² m. Against the Reference Airborne Algorithm Description Document v3.1 (2019), Appendix D: VPL 18.2926 m vs 18.3 m published (Δ 0.0074 m), HPL 13.4063 m vs 13.45 m (Δ 0.0437 m), EMT (effective monitor threshold) 7.2997 m vs 7.2998 m, σ_v,acc 1.3694 m vs 1.3694 m, and all six published constellation-fault intermediates (σ₃⁽ᵏ⁾, σ_ss,3⁽ᵏ⁾, b₃⁽ᵏ⁾) to within half a unit in their last printed decimal. The 2016 Milestone 3 Report states the same example but carries two internal defects — a sign typo in row 3 ofG, and aK_fa,3evaluated at 57 fault modes while the document statesN_fault,max = 1(12 modes) — so its geometry intermediates reproduce exactly while its protection levels are recorded as measured discrepancies (VPL Δ 0.0171 m, HPL Δ 0.0842 m, EMT Δ 0.4806 m) and excluded from the acceptance figure. The check is reachable as thearaim-reference-checkscenario kind. - Honest residual (external / pending review): the 15–25 % availability figure
against a version-locked real Celestrak TLE (two-line element set) snapshot, and depositing the
ARAIM test fixtures as a citable Zenodo record. The reference check above
covers
N_fault,max = 1(single-satellite and single-constellation fault modes) only; simultaneous multi-event fault subsets, fault exclusion, the χ² consistency check and the double-counting re-allocation step of the reference algorithm are not implemented, and a case whose priors would need them is refused rather than truncated. - Scenario-file reach: the
integrityscenario kind runsaraim_dual_raimat every epoch when its TOML (Tom's Obvious Minimal Language) file setsaraim_dual = true(optionalp_hmi); the bundledscenarios/araim-gps-galileo.tomldoes so over a pooled GPS + Galileo geometry, andtests/araim_dual_real_data.rsruns the same engine on real Celestrak GPS and Galileo TLEs propagated to one common epoch. Without the flag the runner uses classic solution-separation RAIM.
References#
- EU–U.S. Cooperation on Satellite Navigation, Working Group C, ARAIM Technical Subgroup, Milestone 3 Report, Final Version, 25 February 2016 — Annex A (reference user algorithm) and §A.IX (numerical example). https://www.gps.gov/sites/default/files/2025-09/ARAIM-milestone-3-report.pdf
- EU–U.S. Cooperation on Satellite Navigation, Working Group C, ARAIM Technical Subgroup, Reference Airborne Algorithm Description Document, Version 3.1, 20 June 2019 — Appendix D (numerical example for LPV-200). https://web.stanford.edu/group/scpnt/gpslab/website_files/maast/ARAIM_TSG_Reference_ADD_v3.1.pdf
- EU–US (United States) Cooperation on Satellite Navigation, ARAIM Technical Note.
- RTCA (formerly the Radio Technical Commission for Aeronautics) DO-316 / DO-229 MOPS (minimum operational performance standards); DO-316 ARAIM MASPS (minimum aviation system performance standards) material.
- Blanch et al., Baseline Advanced RAIM User Algorithm and Possible Improvements, IEEE (Institute of Electrical and Electronics Engineers) TAES (Transactions on Aerospace and Electronic Systems) / ION (Institute of Navigation) ITM (International Technical Meeting).
- Walter, Enge, Blanch, Pervan, Worldwide Vertical Guidance of Aircraft Based on Modernized GPS and New Integrity Augmentations (Stanford-diagram methodology).