Integrity and interferenceEdit on GitHubSource: docs/ARAIM_REFERENCE.md

ARAIM reference — advanced RAIM protection levels in Kshana

This note documents Kshana's open implementation of Advanced Receiver Autonomous Integrity Monitoring (ARAIM): the algorithm, every assumption, the integrity support message it consumes, and the validation status. The implementation lives in src/raim.rs; this document is the prose companion that an auditor (or a procurement reviewer) can read alongside the code.

ARAIM is the dual-constellation, multi-frequency successor to classic RAIM that the GPS (Global Positioning System)–Galileo Working Group C (WG-C) defined to support horizontal and vertical guidance down to LPV-200 (LPV: localizer performance with vertical guidance). It answers a single question for every epoch:

How large must the position-error bound (the protection level) be so that the residual probability of hazardously misleading information — an error larger than the bound while the bound is still inside the alert limit — stays under the integrity risk budget P_HMI?

1. The integrity support message (ISM)#

The ISM is the per-constellation parameter set the user applies. It is modelled explicitly by IntegritySupportMessage:

Field Symbol Meaning
sigma_ure_m σ_URE / SISE (signal-in-space error) range-error RMS (root mean square) used for accuracy and continuity
sigma_ura_m σ_URA / SISA (signal-in-space accuracy) range-error bound used for integrity (≥ σ_URE)
b_nom_m b_nom maximum nominal range bias folded one-sided into the integrity bound (b_k = Σ_i |s_i|·b_nom); see §3
p_sat P_sat prior probability of an undetected single-satellite fault
p_const P_const prior probability of a constellation-wide fault

IntegritySupportMessage::gps_galileo_reference() returns the published WG-C reference values: σ_URA = 0.75 m, σ_URE = 0.67 m, b_nom = 0.75 m, P_sat = 1×10⁻⁵, P_const = 1×10⁻⁴ over the exposure interval. These are the values used to size ARAIM availability in the reference literature; the operational ISM is broadcast/ground-assembled and is configurable per constellation. The distinction between σ_URA (integrity) and σ_URE (accuracy) is deliberate and is the defining feature of the ISM concept.

.fault_priors() and .dual_fault_priors() hand these straight to the two engines.

2. Fault hypotheses#

ARAIM is a multiple hypothesis solution separation (MHSS) method. For each fault hypothesis H_k it forms the all-in-view solution and the sub-solution that excludes the faulted set, and bounds the position error under that hypothesis:

  • Fault-free H_0 (prior ≈ 1): the full all-in-view least-squares fix.
  • Single-satellite faults H_i (prior P_sat each): every one-satellite exclusion sub-solution. This is the classic single-fault ARAIM baseline, araim_raim.
  • Constellation-wide faults H_c (prior P_const each): the sub-solution that removes all satellites of one constellation at once, the EU (European Union) ARAIM TN (technical note) / DO-316 extension implemented in araim_dual_raim. With P_const = 0 this reduces bit-for-bit to araim_raim.

3. Protection levels#

For each axis (vertical, horizontal) and each hypothesis the engine builds a mode (p_fault, threshold, σ) where the threshold is the solution-separation detection limit at the false-alert multiplier K_fa = Φ⁻¹(1 − P_fa / 2N) (a Bonferroni split of the continuity budget over the N hypotheses). The protection level is the smallest bound PL whose summed integrity risk

Σ_k p_fault,k · Q( (PL − b_k − T_k) / σ_k )  ≤  P_HMI

Implementation note. b_k = Σ_i |s_{axis,i}|·b_nom is the one-sided nominal-bias projection onto the axis — the worst-case sum of per-satellite gain magnitudes (axis_bias_sum/horiz_bias_sum) — sourced from the ISM's b_nom_m. The WG-C reference ISM uses b_nom = 0.75 m; with b_nom = 0 the bound reduces to the zero-nominal-bias MHSS form. The runnable integrity scenario exposes sigma_ura_m (the integrity bound used for the protection level, clamped to ≥ sigma_uere_m and defaulting to it) and b_nom_m (defaulting to 0), so the protection level is always sized with the integrity bound σ_URA, never the smaller accuracy σ_URE. This remains a modelled, non-certified ARAIM implementation — see INTEGRITY.md.

meets the allocated budget ([araim_protection_level] / araim_integrity_risk). VPL (vertical protection level) and HPL (horizontal protection level) are the vertical and horizontal answers. The result also reports the integrity risk actually achieved (≤ the allocation) and whether a sub-solution separated beyond its threshold.

This is the explicit ARAIM contract — "how large must the bound be?" — rather than the implicit, geometry-dependent risk of a fixed-multiplier classic RAIM.

4. Stanford diagram#

StanfordDiagram accumulates (error, PL) per epoch against a fixed alert limit (AL) and classify_stanford sorts each into available, system-unavailable (PL > AL, conservative), misleading information (PL < error ≤ AL) or hazardously misleading information (error > AL and > PL). stanford_svg renders the classic scatter — the PL = error integrity boundary, the alert-limit guides, and one colour-coded marker per epoch — as a self-contained SVG (Scalable Vector Graphics).

5. The dual-constellation benefit#

Two effects are demonstrated in raim::tests::dual_constellation_improves_geometry_and_tolerates_a_constellation_fault:

  1. Geometry / redundancy — pooling a second constellation's satellites tightens the single-fault HPL: more measurements and a larger single-SV (SV: space vehicle, that is a satellite) sub-solution set give a strictly smaller bound.
  2. Constellation-fault tolerance — with P_const active, the dual user stays available when a whole constellation can fail (satellites of the other constellation survive), whereas a single-constellation user provably cannot be protected against its own constellation fault (araim_dual_raim returns None).

A subtlety worth stating honestly: because the constellation-fault hypothesis requires surviving the loss of an entire constellation, the dual-constellation snapshot protection level is bounded below by the residual single-constellation geometry — it is not automatically smaller than the GPS-only PL at every instant. The headline EU ARAIM TN result that GPS+Galileo gives a 15–25 % smaller HPL is an availability result accumulated over realistic constellations and user locations, not a per-snapshot guarantee.

6. Validation status#

  • In-repo, automated: the MHSS algebra (P_const = 0 ⇒ bit-for-bit single-fault; constellation-fault widens the PL; budget never exceeded), the geometry and constellation-fault benefits above, and exercise on real IGS (International GNSS Service; GNSS = global navigation satellite system) precise-orbit (SP3, Standard Product 3) geometry (tests/igs_real_data.rs), not only synthetic constellations.
  • External oracle — the published WG-C worked example: the protection levels are checked against the ARAIM Technical Subgroup's own numerical example, in src/araim_reference.rs, tests/araim_reference_vectors.rs and the committed fixture tests/fixtures/araim_reference/wgc_araim_reference_vectors.txt (each vector carries its retrieval URL (web address), retrieval date, source-file SHA-256 (SHA: Secure Hash Algorithm) and page). The acceptance tolerance is the reference's own TOL_PL = 5 × 10⁻² m. Against the Reference Airborne Algorithm Description Document v3.1 (2019), Appendix D: VPL 18.2926 m vs 18.3 m published (Δ 0.0074 m), HPL 13.4063 m vs 13.45 m (Δ 0.0437 m), EMT (effective monitor threshold) 7.2997 m vs 7.2998 m, σ_v,acc 1.3694 m vs 1.3694 m, and all six published constellation-fault intermediates (σ₃⁽ᵏ⁾, σ_ss,3⁽ᵏ⁾, b₃⁽ᵏ⁾) to within half a unit in their last printed decimal. The 2016 Milestone 3 Report states the same example but carries two internal defects — a sign typo in row 3 of G, and a K_fa,3 evaluated at 57 fault modes while the document states N_fault,max = 1 (12 modes) — so its geometry intermediates reproduce exactly while its protection levels are recorded as measured discrepancies (VPL Δ 0.0171 m, HPL Δ 0.0842 m, EMT Δ 0.4806 m) and excluded from the acceptance figure. The check is reachable as the araim-reference-check scenario kind.
  • Honest residual (external / pending review): the 15–25 % availability figure against a version-locked real Celestrak TLE (two-line element set) snapshot, and depositing the ARAIM test fixtures as a citable Zenodo record. The reference check above covers N_fault,max = 1 (single-satellite and single-constellation fault modes) only; simultaneous multi-event fault subsets, fault exclusion, the χ² consistency check and the double-counting re-allocation step of the reference algorithm are not implemented, and a case whose priors would need them is refused rather than truncated.
  • Scenario-file reach: the integrity scenario kind runs araim_dual_raim at every epoch when its TOML (Tom's Obvious Minimal Language) file sets araim_dual = true (optional p_hmi); the bundled scenarios/araim-gps-galileo.toml does so over a pooled GPS + Galileo geometry, and tests/araim_dual_real_data.rs runs the same engine on real Celestrak GPS and Galileo TLEs propagated to one common epoch. Without the flag the runner uses classic solution-separation RAIM.

References#

  • EU–U.S. Cooperation on Satellite Navigation, Working Group C, ARAIM Technical Subgroup, Milestone 3 Report, Final Version, 25 February 2016 — Annex A (reference user algorithm) and §A.IX (numerical example). https://www.gps.gov/sites/default/files/2025-09/ARAIM-milestone-3-report.pdf
  • EU–U.S. Cooperation on Satellite Navigation, Working Group C, ARAIM Technical Subgroup, Reference Airborne Algorithm Description Document, Version 3.1, 20 June 2019 — Appendix D (numerical example for LPV-200). https://web.stanford.edu/group/scpnt/gpslab/website_files/maast/ARAIM_TSG_Reference_ADD_v3.1.pdf
  • EU–US (United States) Cooperation on Satellite Navigation, ARAIM Technical Note.
  • RTCA (formerly the Radio Technical Commission for Aeronautics) DO-316 / DO-229 MOPS (minimum operational performance standards); DO-316 ARAIM MASPS (minimum aviation system performance standards) material.
  • Blanch et al., Baseline Advanced RAIM User Algorithm and Possible Improvements, IEEE (Institute of Electrical and Electronics Engineers) TAES (Transactions on Aerospace and Electronic Systems) / ION (Institute of Navigation) ITM (International Technical Meeting).
  • Walter, Enge, Blanch, Pervan, Worldwide Vertical Guidance of Aircraft Based on Modernized GPS and New Integrity Augmentations (Stanford-diagram methodology).