<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>receiver Archives - Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</title>
	<atom:link href="https://insidegnss.com/category/main-categories/receiver/feed/" rel="self" type="application/rss+xml" />
	<link>https://insidegnss.com/category/main-categories/receiver/</link>
	<description>Global Navigation Satellite Systems Engineering, Policy, and Design</description>
	<lastBuildDate>Wed, 10 Feb 2021 20:27:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://insidegnss.com/wp-content/uploads/2017/12/site-icon.png</url>
	<title>receiver Archives - Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</title>
	<link>https://insidegnss.com/category/main-categories/receiver/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>SDX 18.10 Now Available From Skydel</title>
		<link>https://insidegnss.com/sdx-18-10-now-available-from-skydel/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Tue, 23 Oct 2018 16:32:58 +0000</pubDate>
				<category><![CDATA[commercial]]></category>
		<category><![CDATA[New Builds]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[Anti-jamming]]></category>
		<category><![CDATA[GNSS]]></category>
		<category><![CDATA[gnss antenna]]></category>
		<category><![CDATA[GPS]]></category>
		<category><![CDATA[Industry View]]></category>
		<category><![CDATA[Skydel]]></category>
		<guid isPermaLink="false">http://insidegnss.com/?p=178752</guid>

					<description><![CDATA[<p>Skydel Solutions’ SDX 18.10, a new version of the company’s GNSS simulator that features improvements to receiver antenna management and a new advanced...</p>
<p>The post <a href="https://insidegnss.com/sdx-18-10-now-available-from-skydel/">SDX 18.10 Now Available From Skydel</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Skydel Solutions’ SDX 18.10, a new version of the company’s GNSS simulator that features improvements to receiver antenna management and a new advanced jammer type, is now available.</p>
<p>Starting with this SDX update is an upgraded paradigm for managing receiver antennas: SDX now supports the management of multiple vehicle antennas within a single scenario. Antennas can now be defined, named, and exported as antenna files that can be re-imported back into other scenarios. This handy feature will speed up antenna reuse and multi-scenario workflows for users managing numerous antenna models in GNSS simulation scenarios.</p>
<p><span id="more-178752"></span>The new antenna model UI maintains the previous SDX paradigm whereby antenna patterns can be defined for gain and phase offsets.</p>
<p>Moreover, SDX now provides a simple and powerful sequencer for switching from one antenna pattern to another at specific times during a scenario. The antenna sequencer is said to be simple to use and will be useful for those who need to toggle antennas at various points in the simulation to replicate a real-world scenario.</p>
<p>As with all new features added by Skydel, the SDX API is updated—and documented—to reflect these latest changes, and these new features can be used in the programming of your automated scenarios.</p>
<p><strong>IQ File as a Jammer Type<br />
</strong>In addition, with release 18.10, users can now add IQ File playback as a jammer type in SDX. This feature, combined with the IQ File generation capability already available in SDX, opens a new range of possibilities.Users who already have the advanced jamming option installed and are eligible for this SDX upgrade can benefit from this new feature immediately by upgrading to SDX release 18.10.</p>
<p><strong>Just One of Many Releases<br />
</strong>So far in 2018, SDX has seen the support of anechoic chambers, the support for multiple GPUs, the addition of SBAS support among many other new features in the summer release, and now SDX release 18.10 that brings a new way to manage and sequence vehicle antennas.</p>
<p>According to Skydel, more announcements are just around the corner. New custom simulation solutions based on SDX are coming soon, along with new features and GNSS constellation support.</p>
<p>The post <a href="https://insidegnss.com/sdx-18-10-now-available-from-skydel/">SDX 18.10 Now Available From Skydel</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What is navigation message authentication?</title>
		<link>https://insidegnss.com/what-is-navigation-message-authentication/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Mon, 01 Jan 2018 12:20:54 +0000</pubDate>
				<category><![CDATA[Column]]></category>
		<category><![CDATA[Galileo]]></category>
		<category><![CDATA[GNSS (all systems)]]></category>
		<category><![CDATA[GNSS Solutions]]></category>
		<category><![CDATA[GPS]]></category>
		<category><![CDATA[Magazine Department]]></category>
		<category><![CDATA[Magazine Section]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[signal]]></category>
		<guid isPermaLink="false">http://insidegnss.com/?p=171202</guid>

					<description><![CDATA[<p>Q: What is navigation message authentication?   A: As of today, all open civil GNSS signals are transmitted in the clear, conforming to...</p>
<p>The post <a href="https://insidegnss.com/what-is-navigation-message-authentication/">What is navigation message authentication?</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>
<strong>Q: What is navigation message authentication?  </p>
<p>A: </strong>As of today, all open civil GNSS signals are transmitted in the clear, conforming to interface specifications that are fully available in the public domain. Receivers will accept any input that conforms to the specifications and treat it as if it came from a GNSS satellite. Combined with the extremely low power levels of GNSS signals this makes it almost trivially simple to spoof a GNSS receiver.
</p>
<p><span id="more-171202"></span></p>
<p>
As early as 2003, Logan Scott proposed a number of techniques that could be implemented at the satellite level to “harden” the civil GNSS signals against spoofing attacks. The first and most straightforward amongst these was NMA.
</p>
<p>
Message Authentication is a concept that has a long history in digital communications, the basic idea being that the receiver of a message would like to ensure that the message they receive: 1) is identical to the message that was transmitted; 2) was generated by a trusted source. NMA is, unsurprisingly, the application of the Message Authentication concept to the navigation messages generated by GNSS satellites.
</p>
<p>
<strong>So How Does NMA Work? </strong><br />
Message authentication has been referred to as the “second face” of cryptology, and it uses many of the same tools and techniques as the more well-known first face of cryptology: cryptography, or data secrecy. In message authentication the sender uses a secret key to generate an authentication signature from the original message. Both message and signature are then transmitted to the receiver, which uses a key (potentially different to that used by the transmitter) to verify that the message and authentication signature correspond.
</p>
<p>
When the received message is authenticated the receiver can conclude that:
</p>
<p>
1. The transmitted and received message are the same
</p>
<p>
2. Only someone with access to the transmitter’s secret key could have generated the authentication message
</p>
<p>
There are two different ways to generate authentication signatures:
</p>
<p>
1. Using symmetric key techniques in which both transmitter and receiver share a secret key
</p>
<p>
2. Using asymmetric key techniques in which the secret key is split into two parts, a “private” key, known only to the transmitter, and a public key which can be distributed publicly. The private key is used to generate the authentication message, while the public key is used in the verification step.
</p>
<p>
There are some issues associated with each of the two techniques. In the symmetric key case the most difficult issue is how to distribute the “private” key to all users, without also giving the spoofer access to this key. Similarly, for the asymmetric case, the receiver needs some mechanism to ensure that the “public” key does indeed come from the trusted transmitter (the GNSS system operator in the case of NMA). This problem is usually solved using a Public Key Infrastructure (PKI) consisting of a trusted authority that manages the certification that public keys do indeed belong to the organization that claims them.
</p>
<p>
So it would appear that the asymmetric approach is superior, as the infrastructure is simplified and the “secret” key can remain secret. However, asymmetric encryption has two major drawbacks: firstly, it is much more computationally intensive than symmetric key encryption; secondly, much longer keys are required for the same level of security.
</p>
<p>
Interestingly, both symmetric and asymmetric NMA approaches have been proposed for GPS (on the new L1C signal) and Galileo (on the E1 Open Service signal), as discussed below.
</p>
<p class="text-center"><img decoding="async" src="https://insidegnss.com/wp-content/uploads/2018/04/GNSS-Sol-Header_6.jpg" /></p>
<p>
<strong>The GPS Approach – Asymmetric NMA </strong><br />
The Chips-Message Robust Authentication (Chimera) is a hybrid NMA and spreading code authentication technique proposed for use with the GPS L1C signal. The NMA portion of this scheme is based on the asymmetric elliptic curve digital signature algorithm (ECDSA) P-224, which is a well-established standard. The public key is 448-bits long for an equivalent security of about 112 bits (i.e., it is equivalent to a 112-bit symmetric key system).
</p>
<p>
The Chimera proposal uses two Subframe 3 pages of the C/NAV message to transmit each digital signature, with a repetition rate of at most once every three minutes. In this way a receiver can verify that the navigation message is authentic every three minutes.
</p>
<p>
The ECDSA scheme is a well-established Federal Information Processing Standard (FIPS) standard and is implemented in most Open Source and commercially available cryptographic libraries, which simplifies the integration of the scheme into existing GNSS receivers.
</p>
<p>
Chimera requires receivers to have occasional access, via non-GPS channels, to infrastructure to provide authenticated GPS system public keys. This Public Key Infrastructure (PKI) is essential to any asymmetric crypto-system, including the Transport Layer Security (TLS) system used in securing websites. In this system, each entity that wishes to provide an authenticated public key obtains a signed certificate from a trusted Certification Authority (CA). A user can then verify that the public key provided corresponds to that in the signed certificate. Reusing this certification process should be straightforward in the GNSS context.
</p>
<p>
<strong>The Galileo Approach – Hybrid Symmetric/Asymmetric NMA </strong><br />
The proposal for Galileo Open Service Navigation Message Authentication (OSNMA) differs from Chimera in that it is based on a hybrid symmetric/ asymmetric key approach known as the Timed Efficient Streamed Loss-Tolerant Authentication (TESLA) scheme.
</p>
<p>
TESLA addresses the issue of symmetric key distribution as follows. First, a Message Authentication Code (MAC) is generated using the message and the private key. Both the message and the MAC are transmitted and then, sometime later, the private key is broadcast. This delayed release mechanism should ensure that the key used to generate the MAC is not known until after the message and MAC are already received. However, this does not prevent a spoofer from simply generating their own messages, keys <em>and</em> MACs and broadcasting them in a manner compliant with the specifications.
</p>
<p>
To address this latter issue, TESLA uses the concept of a <em>chain</em> of keys. An initial key <em>K</em><sub>0</sub> is randomly selected. Each subsequent key in the chain <em>K<sub>i</sub></em><sub>+1</sub> is generated from the previous key <em>K<sub>i</sub></em> using a one way function: <em>K<sub>i</sub></em><sub>+1</sub> = <em>f(K<sub>i</sub>)</em>. A one way function is a mathematical transformation that is easy to compute but very difficult to invert. Thus, given <em>K<sub>i</sub></em> it is easy to compute <em>K<sub>i</sub></em><sub>+1</sub>, but given <em>K<sub>i</sub></em><sub>+1</sub> it is computationally infeasible to establish <em>K<sub>i</sub></em>. In TESLA the system generates a chain of length N, then transmits the Nth key (called the root key) along with a digital signature generated using a standard asymmetric scheme, such as ECDSA. The chain keys are then used in reverse order to generate the MACs. Knowing the one-way function, the receiver can verify that each chain key is from the same chain as the digitally signed root key, but cannot predict “future” chain keys.
</p>
<p>
Once a TESLA chain has been established by asymmetric cryptographic means, the satellites begin transmitting messages, MACs and keys using the delayed release mechanism. The receiver extracts the messages and MACs and stores them until the key is received. The key is first checked to ensure that it is part of the TESLA chain in force using the known one way function. If the key passes this test, it is then used to verify that the MAC and the message correspond.
</p>
<p>
There is one absolutely critical assumption that <em>must</em> be made for the TESLA-based scheme to work: the receiver must have an authenticated time synchronization that is at least better than the key delay (in TESLA nomenclature this is referred to as the security condition). Without this assurance, the receiver cannot be certain that the navigation message has not been generated by a spoofer that has already received the perfectly valid signing key from a live satellite signal. This naturally raises the question as to how the receiver can “bootstrap” — if it does not have authenticated coarse synchronization how does it go about achieving it?
</p>
<p>
The OSNMA proposal is currently in draft form and subject to change. As it stands it uses 40 bits every two seconds of the Galileo E1b I/NAV message. The data are grouped into subframes of 30 seconds duration, and each MAC is only 10 to 32 bits in length, while key sizes range from 80 to 256 bits. This enables OSNMA to sign many more messages per second than Chimera, enabling such features as cross-satellite and even cross-system authentication. The receiver side computation cost of this high authentication rate remains to be seen, as it includes both MAC computation and key validation through the evaluation of the one way function. Similar to Chimera, the OSNMA scheme is built from a number of standard cryptographic building blocks, facilitating its implementation in receivers. However, unlike ECDSA the TESLA scheme itself is not a standard implementation and therefore will require more effort to integrate into GNSS receivers.
</p>
<p>
As with Chimera, the problem of Public Key Infrastructure (PKI) arises for OSNMA. In this case, the receiver must have access to known, trusted public keys in order to authenticate the digitally signed root keys. At present the OSNMA proposal envisages two public key distribution mechanisms: 1) the receiver can be initialized with a valid Galileo system public key in the factory; 2) new public keys can be transmitted over the E1b navigation message, a process known as Over the Air Rekeying (OTAR). In the current draft neither of these techniques are defined, though signal bandwidth is available for the OTAR mechanism. Of course, with OTAR new higher level public keys are required in order to authenticate the root key signing public keys broadcast from the satellites. Ultimately a PKI similar to that used for authenticating public keys used by commercial websites must be put in place to support public key distribution for both OSNMA and Chimera.
</p>
<p>
<strong>What Does This Mean For Users? </strong><br />
NMA is not a panacea, and by itself does not solve the spoofing problem. In Scott’s terminology, this is but Level 1 of a series of three system-side, signal level defenses. On the other hand, an NMA scheme that is correctly implemented in the receiver does constrain the spoofer’s “attack space” — essentially the spoofer is constrained to only broadcast valid navigation messages.
</p>
<p>
From the user’s perspective, the desired outcome is most likely to obtain an authenticated PVT, or at the very least, to be able to detect a spoofing attack. NMA on its own is insufficient for PVT authentication since this requires both the navigation message and range measurements from each satellite, and NMA does not authenticate the range. However, certain types of spoofing attack are detectable when NMA is implemented.
</p>
<p>
Over the last number of months two different “spoofing” attacks have been reported in this magazine (see Additional Resources). The first, almost certainly a repeater, affected a number of ships in the Black Sea in June 2017. The second, not technically spoofing as it was unintentional, was due to a GNSS simulator operating in the exhibition hall at the ION GNSS+ 2017 conference in Portland, Oregon in September 2017.
</p>
<p>
NMA on its own would have been of no assistance whatsoever in the Black Sea case, assuming that this was in fact a repeater, as this simple attack involves re-broadcast of live GNSS signals in near real-time. The navigation message broadcast by the spoofer would have been identical to that broadcast by the satellites, and hence would have passed the authentication verification step. Such an attack can only be detected by careful monitoring of various signal parameters and looking for sudden, physically impossible jumps, a process known as consistency checking.
</p>
<p>
The simulator incident is an interesting case, as it shows really how vulnerable many receivers are to spoofing. The cause of the incident appears to have been an improperly terminated output port on a GNSS simulator that was running a demonstration in the exhibition hall. The energy radiated from this port was sufficient to capture the GNSS receivers in many attendees’ smartphones. The simulated scenario was located somewhere in Europe and set in January 2014. Clearly, again simply monitoring the existing signal parameters available in the receivers should have provided some indication that there was a problem; jumping across continents or back in time is not something most receivers are capable of. But could NMA have helped in this situation? The short answer is yes, as the simulator would either have generated invalid signatures, or re-used out of date messages. However, in truth, the onus should really be on the receiver to detect sudden, physically impossible jumps in space or time.
</p>
<p>
In short, for the scenarios considered above, the most reliable test for spoofing is the receiver consistency check.
</p>
<p>
<strong>Summary </strong><br />
Navigation Message Authentication is coming to both Galileo and GPS in the next few years, which demonstrates that the system operators are serious about the civil spoofing threat. Other system level protection measures are also under development: Chimera implements secure spreading sequences for some signal level protection, while Galileo provides fully encrypted spreading codes in its Commercial Service.
</p>
<p>
NMA is but one tool in the arsenal that GNSS receivers can deploy against spoofing, but is certainly a step in the right direction. However, such efforts on the part of the system providers must be matched by the receiver manufacturers for there to be any benefit to the end user. Many receiver level defenses can, and should, be implemented today without waiting for the arrival of NMA.
</p>
<p>
<span style="color: #993300"><strong>Further Reading </strong></span><em><strong><br />
Logan Scott’s paper on how to harden GNSS receivers: </strong></em>
</p>
<ul>
<li>Scott, L. (2003) “Anti-Spoofing &amp; Authenticated Signal Architectures for Civil Navigation Systems”, <em>ION GNSS 2003</em>. </li>
</ul>
<p>
<em><strong>Details about the proposed GPS and Galileo NMA proposals:</strong></em>
</p>
<ul>
<li>Anderson, J. L.; Carroll, K. L.; DeVilbiss, N. P.; Gillis, J. T.; Hinks, J. C.; O’Hanlon, B. W.; Rushanan, J. J; Scott, L.; Yazdi, R.A (2017) “Chips-Message Robust Authentication (Chimera) for GPS Civilian Signals”, <em>ION GNSS+ 2017</em>. </li>
</ul>
<ul>
<li>Fernandez, I; Rijmen, V.; Ashur, T.: Walker, P.; Seco, G.; Simon, J.; Sarto, C.; Burkey, D.; Pozzobon, O., <a href="https://www.gsa.europa.eu/development-supply-and-testing-galileo-open-service-authentication-user-terminal-os-nma-gsa" target="_blank">“Galileo Navigation Message Authentication Specification for Signal-In-Space Testing”</a>, Version 1.0, November 2016.</li>
</ul>
<p>
<em><strong>Additional Reading on the TESLA Scheme: </strong></em>
</p>
<ul>
<li>Perrig, A.; Canetti, R.; Tygar, J.D.; Song, D., “Efficient Authentication and Signing of Multicast Streams over Lossy Channels”, <em>Proceedings of the IEEE Symposium on Security and Privacy, 2000</em>. </li>
</ul>
<p>
<span style="color: #993300"><strong>Additional Resources </strong></span><span style="color: #ff0000"><strong><br />
[1] </strong></span>Goff, S. <a href="http://insidegnss.com/reports-of-mass-gps-spoofing-attack-in-the-black-sea-strengthen-calls-for-pnt-backup/">“Reports of Mass GPS Spoofing Attack in the Black Sea Strengthen Calls for PNT Backup”</a>, <em>Inside GNSS</em>, 24 July 2017. <strong><span style="color: #ff0000"><br />
[2]</span></strong> Scott, L.<a href="http://insidegnss.com/spoofing-incident-report-an-illustration-of-cascading-security-failure/"> “Spoofing Incident Report: An Illustration of Cascading Security Failure”</a> <em>Inside GNSS</em>, 9 October 2017.
</p>
<div class="pdfclass"><a target="_blank" class="specialpdf" href="http://insidegnss.com/wp-content/uploads/2018/04/janfeb18-SOLUTIONS.pdf">Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/what-is-navigation-message-authentication/">What is navigation message authentication?</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Do modern multi-frequency civil receivers eliminate the ionospheric effect?</title>
		<link>https://insidegnss.com/do-modern-multi-frequency-civil-receivers-eliminate-the-ionospheric-effect/</link>
		
		<dc:creator><![CDATA[Mark Petovello]]></dc:creator>
		<pubDate>Mon, 27 Nov 2017 23:08:55 +0000</pubDate>
				<category><![CDATA[201710 November/December 2017]]></category>
		<category><![CDATA[Column]]></category>
		<category><![CDATA[engineering]]></category>
		<category><![CDATA[Environment]]></category>
		<category><![CDATA[GNSS Solutions]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Technical Article]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Working Papers]]></category>
		<category><![CDATA[article]]></category>
		<category><![CDATA[civil receivers]]></category>
		<category><![CDATA[ionospheric effect]]></category>
		<category><![CDATA[Multi-frequency GNSS]]></category>
		<category><![CDATA[technical article]]></category>
		<category><![CDATA[working paper]]></category>
		<guid isPermaLink="false">http://insidegnss.com/2017/11/27/do-modern-multi-frequency-civil-receivers-eliminate-the-ionospheric-effect/</guid>

					<description><![CDATA[<p>Figures 1 &#8211; 10 Q: Do modern multi-frequency civil receivers eliminate the ionospheric effect? Q: Do modern multi-frequency civil receivers eliminate the ionospheric...</p>
<p>The post <a href="https://insidegnss.com/do-modern-multi-frequency-civil-receivers-eliminate-the-ionospheric-effect/">Do modern multi-frequency civil receivers eliminate the ionospheric effect?</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class='special_post_image'><img decoding="async" class='specialimageclass img-thumbnail' src="https://insidegnss.com/wp-content/uploads/2018/01/SolFigs_0.jpg" ><span class='specialcaption'>Figures 1 &#8211; 10</span></div>
<p>
<strong>Q: Do modern multi-frequency civil receivers eliminate the ionospheric effect? </strong>
</p>
<p><span id="more-22951"></span></p>
<p>
<strong>Q: Do modern multi-frequency civil receivers eliminate the ionospheric effect? </strong>
</p>
<p>
<strong>A: </strong>It is common knowledge in the GNSS community that the ionosphere is dispersive in the L-band, meaning the refractive effects on the carrier phases are proportional to the wavelengths of the carriers, in turn causing differential variation in the measured codes and phases of the various navigation signals transmitted by the satellites. Use of multiple signals of distinct center frequency transmitted from the same GNSS satellite allows direct observation and removal of the great majority of the ionospheric delay, and gives the impression to users that the ionosphere may not be a problem for modernized receivers. While the general assumption of nearly perfect correlation between the effects measured on multiple independent signals is correct in normal conditions, it does not appear to hold in the presence of ionospheric scintillation.
</p>
<p>
<strong>High and Low Latitude Scintillation Effects </strong><br />
Scintillation refers to random fluctuations in the received wave field strength (“signal fading”), as well as phase and group delay caused by the irregular structure of the propagation medium. Ionospheric scintillations are random rapid variations in the intensity and phase of the received signals resulting from plasma density irregularities in the ionosphere.
</p>
<p>
Many of the important contributors to ionospheric scintillation are already known, such as the variation of scintillation activity with magnetic activity, geographic location, local time, season, and the 11-year solar cycle.
</p>
<p>
The most significant and frequent scintillation activity including both phase and amplitude variations is observed in low latitude regions within about 15° of the Earth’s magnetic equator, particularly in the hours after local sunset. In high latitude regions scintillation is frequent but generally less severe in terms of signal tracking disruptions than that in the equatorial regions. The high-latitude environment can be divided into two subregions, the polar caps (regions around the magnetic poles) and the auroral zones (approximately circular regions around the two geomagnetic poles located at about 67° north and south geographic latitudes, and about 3° to 6° wide). Of these, the polar cap experiences both amplitude as well as phase scintillation activity, while mainly phase scintillation is observed at high latitude auroral regions.
</p>
<p>
In mid-latitude regions scintillation is rarely observed, but during intense ionospheric storm conditions phenomena can extend into the mid-latitudes.
</p>
<p>
<strong>Figures 1 and 2</strong> <em>(see inset photo, above right, for all figures) </em>show examples of ionospheric scintillation as observed on the detrended signal intensity (effectively power) and detrended carrier phase measurements at 69.5° latitude (Tromsø, Norway) and 21° latitude (Hanoi, Vietnam), respectively. In the particular event shown in Figure 2 the depth of fades reaches 43 decibels (dB) on L1CA which is severe by any metric, and is a substantial qualitative difference from the high-latitude phase scintillation events where only very weak fading activity is typically observed. It should be noted that ionospheric activity is more dependent on the geomagnetic latitude of the user than the geographic latitude. While it might be clear that Tromsø station is located in the auroral region, the Hanoi station has somewhat lower geomagnetic latitude than geographic latitude and is in fact located within the equatorial zone.
</p>
<p>
Since ionospheric scintillation is essentially a rapid variation in the apparent ionosphere it is easy to assume that the typical approaches applied for removing ionospheric influence will be effective during scintillation.
</p>
<p>
<strong>Ionosphere-Free Combination </strong><br />
The advantage of multi-frequency GNSS receivers in terms of handling the ionospheric error is that they can combine carrier phase measurements at different frequencies to cancel out the first order effect due to ionospheric refraction. The receiver does not typically measure the ionospheric delay directly, but is using the so-called ionosphere-free linear combination of the observables. Consider generalized versions of carrier phase measurements on two frequencies, <em>i</em> and <em>j</em>, expressed in meters:
</p>
<p>
Φ<sub><em>L<sub>i</sub></em></sub> = <em>ρ + </em><em>λ<sub>i</sub></em><em>N<sub>i</sub> − </em><em>I<sub>i</sub>     </em><span style="color: #ff0000"><strong>(1)<br />
</strong></span>Φ<sub><em>L<sub>j</sub></em></sub> = <em>ρ + </em><em>λ<sub>j</sub></em><em>N<sub>j</sub> − </em><em>I<sub>j</sub></em>
</p>
<p>
where <em>ρ</em> is the geometric range between the satellite and the receiver; <em>λ<sub>i</sub></em> and <em>λ<sub>j</sub></em> are the wavelengths, <em>N<sub>i</sub> </em>and <em>N<sub>j</sub></em> are the integer ambiguity terms, <em>I<sub>i</sub></em> and <em>I<sub>j</sub></em> are the ionospheric propagation delay errors. For simplicity, the receiver noise and multipath errors are not included. The expression for an arbitrary linear combination of two carrier phase measurements can be written as follows: (For more on this topic, read the <a href="http://insidegnss.com/what-about-gps-jamming-and-maritime-safety-and-linear-carrier-phase-combinations/">GNSS Solutions column from January/February 2009</a>).
</p>
<p>
Φ<em><sub>ij</sub></em> = <em>α</em>Φ<sub><em>L<sub>i</sub></em></sub> + <em>β</em>Φ<sub><em>L<sub>j</sub></em></sub>     <strong><span style="color: #ff0000">(2)</span></strong>
</p>
<p>
where <em>α</em> and <em>β</em> are constants. This allows one to model a linear combination of phases in the same way as the individual observables:
</p>
<p>
Φ<em><sub>ij</sub></em> = <em>ρ</em> + <em><em>λ<sub>ij</sub></em><em>N<sub>ij</sub></em></em> − <em>I<sub>ij</sub></em><em>η</em>     <strong><span style="color: #ff0000">(3) </span></strong>
</p>
<p>
In (3), <em>λ<sub>ij</sub></em> is the wavelength, <em>N<sub>ij</sub></em> is the integer ambiguity term, and <em>I<sub>ij</sub></em> is the ionospheric propagation delay error for the linear combination. In order to remove the ionospheric error (<em>η</em> = 0), but leave the geometric portion unchanged and the resulting ambiguity still an integer, the ionosphere-free combination has been proposed:
</p>
<p>
<span style="color: #ff0000"><span style="color: #000000">Φ</span></span><em><span style="color: #ff0000"><em><span style="color: #000000"><sub>IFree</sub></span></em><span style="color: #000000"> = </span></span>f<sub>i</sub></em><sup><em>2</em></sup>Φ<sub><em>L<sub>i</sub></em></sub> − <em>f<sub>j</sub><sup>2</sup></em>Φ<sub><em>L<sub>j</sub></em></sub><span style="font-size: x-large">  ∕ </span><em>f<sub>i</sub></em><sup><em>2</em></sup> − <em>f<sub>j</sub><sup>2</sup><sub>     </sub></em><span style="color: #ff0000"><span style="color: #000000"><span style="color: #ff0000"><strong>(4)</strong></span></span></span>
</p>
<p>
where <em>f<sub>i</sub></em> and <em>f<sub>j</sub></em> are the carrier frequencies expressed in hertz. The phase scintillation is, however, caused by both refractive and diffractive effects. The diffractive effects cause rapid transitions in the phase which do not scale with the carrier wavelength resulting in a residual error in the ionosphere-free linear combination (4) of phase measurements.
</p>
<p>
While this correction term is for most purposes considered complete, there are factors that can cause apparent deviation between the two carriers including multipath, receiver noise, and un-modelled terms in (4). Corrections produced using (4) will have a residual error due to second and third order dispersion effects, which are conservatively bounded to 0–2 centimeters and 0–2 millimeters at zenith respectively, under an assumption of a 100 TECU (total electron content unit; 1 TECU ≈ 16 cm at GPS L1) background ionosphere. Since 100 TECU is a high value for zenith ionosphere the value of the higher order terms will often be well below 2 centimeters instantaneously, and will vary by only a small fraction of this amount over short time periods.
</p>
<p>
Although some recent findings have shown that magnitudes of 3 centimeters referenced to L1 are possible due to the higher order terms, it has also been shown that the variation rate is typically limited to the level of centimeters per hour.
</p>
<p>
During phase scintillation events it is possible that the multiple carriers of a given satellite will (when scaled for frequency as in <strong>Figure 3</strong>) track each other within the margins of error expected when accounting for thermal and oscillator phase noise on each channel. However, it is also possible that near total de-correlation of the phases will occur during phase scintillation accompanied by fading events as is depicted in <strong>Figure 4</strong> where the detrended scaled carrier phase observables from L1, L2 and L5 transmitted by a block IIF GPS satellite visibly deviate from one another. Even the closely-spaced L2 and L5 carriers exhibit substantial decorrelation, equivalent at times to a full L1 carrier cycle of nearly 20 centimeters, well outside of the level which could be plausibly attributed to higher order terms ignored by (4).
</p>
<p>
On close inspection, the data shown in Figure 4 does not appear to contain any stepwise transitions of a magnitude commensurate with a full or half cycle slip on any of the carriers, meaning that this decorrelation is unlikely to be a signal tracking error. Unlike static group delay errors, it is not possible to measure and estimate this error contribution a priori. It is effectively an additional noise source present only during scintillation. Since it will influence the magnitude of the residual error in the case of multi/dual frequency processing it is interesting to analyze this phenomena and attempt to quantify its expected magnitude by considering the level of correlation between carriers during a cross section of scintillation events affecting modernized civil signals believed to be free of cycle slips.
</p>
<p>
To quantify the correlation level between the scintillation effects on GNSS frequencies, the phase correlation coefficient can be calculated for the observed scintillation events according to the following relationship:
</p>
<p>
<em>ρ<sub>δφ</sub></em> = ⟨<em>δφ<sub>1</sub>δφ<sub>2</sub></em>⟩/(⟨<em>δφ<sub>1</sub><sup>2</sup>δφ<sub>2</sub><sup>2</sup></em>⟩)<sup>1/2</sup><em>, </em>−1 &lt;<em> <em>ρ<sub>δφ</sub> </em></em>&lt; 1<em>     </em><span style="color: #ff0000"><strong>(5)</strong></span>
</p>
<p>
where the terms <em>δφ<sub>1</sub></em> and <em>δφ<sub>2</sub></em> represent epoch to epoch changes in the detrended phases. <strong>Figures 5 and 6</strong> show the results for the events observed at 69.5° latitude (Tromsø, Norway) and 21° latitude (Hanoi, Vietnam). In Figure 6 the level of correlation versus the intensity of the phase variation is plotted for L1CA vs. L2CM, and in contrast to the high latitude example shown in Figure 5, where increasing phase instability leads to an increasing level of phase correlation between the two carriers, for the Hanoi data the outcome is entirely different. Indeed, the phase correlation between the two carriers appears to be nearly non-existent on average, as the distribution of correlation measures is bifurcated with half the distribution tending towards higher positive correlation levels, while the other half of the sampled distribution tends towards anti-correlated results.
</p>
<p>
<strong>Ionosphere-free Residual </strong><br />
When scaled by their wavelengths, the carrier phase measurements on different GNSS frequencies appear to match closely when the scintillation effect is weak or moderate, but diverge from one another when the scintillation effect is strong regardless of whether the dominant scintillation effect is on the phase or amplitude of the signal. It is believed that these divergences occur when diffraction alters the phases by a factor that is not proportional to the wavelengths of their carriers leading to a residual in the ionosphere-free phase combination. An example of this phenomena is the so-called “canonical fade”, which may be the cause of the decorrelation events presented here. <strong>Figure 7</strong> shows the average absolute L1/L2 ionosphere-free combination residual from Tromsø (69.5° N) observations, whereas results generated based on the data from Hanoi (21° N) are illustrated in <strong>Figures 8, 9 and 10</strong>.
</p>
<p>
Noting that the range of carrier phase standard deviation considered in Figures 8, 9 and 10 is smaller than that considered in the high latitude plot, it is clear that the level of ionosphere-free residual present in the Hanoi data increases much more rapidly with rising phase standard deviation than was the case with the high latitude observations.
</p>
<p>
While it is not unexpected that the L1/L5 combination residual is also substantial, as indicated in Figure 9, the more interesting observation is that the L2C and L5 signals also have considerable levels of decorrelation despite their relatively small 51 megahertz of spectral separation, compared to the nearly 350 megahertz of spectral separation between L1 and L2. In Figure 10, it is seen that for one of the tracked satellites during this event, the level of ionosphere-free residual in the L2CM/L5Q combination seems to exceed one meter even while the underlying data shows no signs of cycle slips.
</p>
<p>
<strong>Conclusion </strong><br />
To summarize, it has been demonstrated that ionospheric scintillation phenomena tend to cause an additional measurement residual in the nominal ionosphere-free combinations that greatly exceeds the expected value of the neglected higher order terms and may be a substantial or dominant nuisance term in some applications. While the residual is present with both phase and amplitude scintillation, and is more pronounced with strong scintillation to a point, the relationship appears stochastic and not deterministic.
</p>
<p>
It is tempting to assume that concerns about ionospheric effects during all but deep amplitude fades would disappear when users had switched from semi-codeless multi-frequency observables to the use of modernized civil signals due to their much higher tracking robustness. Instead, it seems that even with the modernized signals there is a measurable and occasionally meter level sense in which the ionosphere-free observables are not at all free of ionospheric influence.
</p>
<p>
<span style="color: #993300"><strong>Additional Resources </strong></span>
</p>
<p>
<em>For additional information about ionospheric scintillation: </em><strong><span style="color: #ff0000"><br />
[1] </span></strong>Conker, R.S., M.B. El-Arini, C.J. Hegarty and T. Hsiao (2003) “Modelling the effects of ionospheric scintillation on GPS/Satellite-Based Augmentation System Availability”, <em>Radio Science</em>, vol.38, no.1. <strong><span style="color: #ff0000"><br />
[2] </span></strong>Carrano, C. S., K. M. Groves, W. J. McNeil, and P. H. Doherty (2013), Direct measurement of the residual in the ionosphere-free linear combination during scintillation, <em>Proceedings of the 2013 Institute of Navigation ION NTM meeting</em>, San Diego, CA, January 28-30, 2013.
</p>
<p>
<em>For additional information on higher-order ionospheric effects: </em><strong><span style="color: #ff0000"><br />
[3]</span></strong> Hoque, M.M., and N. Jankowski (2007), “Higher order ionospheric effects in precise GNSS positioning,” <em>Journal of Geodesy</em> number 81, pp 259-268 <strong><span style="color: #ff0000"><br />
[4]</span></strong> Liu, Z., Y. Li, J. Guo, and F. Li (2016) “Influence of higher-order ionospheric delay correction on GPS precise orbit determination and precise positioning,” <em>Geodesy and Geodynamics</em>, Volume 7, Issue 5, September 2016, pp 369-376
</p>
<p>
<em>For information about canonical fades: </em><span style="color: #ff0000"><strong><br />
[5] </strong></span>Liu, Z., Y. Li, J. Guo, and F. Li (2016) “Influence of higher-order ionospheric delay correction on GPS precise orbit determination and precise positioning,” <em>Geodesy and Geodynamics</em>, Volume 7, Issue 5, September 2016, pp 369-376.
</p>
<div class='pdfclass'><a target='_blank' class='specialpdf' href='http://insidegnss.com/wp-content/uploads/2018/01/novdec17-SOLUTIONS.pdf'>Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/do-modern-multi-frequency-civil-receivers-eliminate-the-ionospheric-effect/">Do modern multi-frequency civil receivers eliminate the ionospheric effect?</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>GNSS SDR Metadata Standard</title>
		<link>https://insidegnss.com/gnss-sdr-metadata-standard/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Mon, 27 Nov 2017 23:06:25 +0000</pubDate>
				<category><![CDATA[201710 November/December 2017]]></category>
		<category><![CDATA[Article]]></category>
		<category><![CDATA[engineering]]></category>
		<category><![CDATA[Galileo]]></category>
		<category><![CDATA[GNSS (all systems)]]></category>
		<category><![CDATA[GPS]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[Survey and Mapping]]></category>
		<category><![CDATA[Technical Article]]></category>
		<category><![CDATA[timing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">http://insidegnss.com/2017/11/27/gnss-sdr-metadata-standard/</guid>

					<description><![CDATA[<p>Figures 1 &#8211; 6 GNSS SDRs are a rapidly advancing area in GNSS receiver research and design. The last few years have brought...</p>
<p>The post <a href="https://insidegnss.com/gnss-sdr-metadata-standard/">GNSS SDR Metadata Standard</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class='special_post_image'><img class='specialimageclass img-thumbnail' src='https://insidegnss.com/wp-content/uploads/2018/01/SDRFigs.jpg' ><span class='specialcaption'>Figures 1 &#8211; 6</span></div>
<p>
<span id="more-22948"></span></p>
<p>
GNSS SDRs are a rapidly advancing area in GNSS receiver research and design. The last few years have brought tremendous growth in this field. Universities and other research institutions have developed and demonstrated advanced capabilities, particularly with respect to multi-constellation GNSS and GNSS-plus-multi-sensor navigation processing for challenging environments. The recent commercial availability of multi-sensor data collection equipment, development platforms and open-source software projects have catalyzed this rapid pace of innovation. Indeed, SDR will likely become a significant commercial GNSS receiver architecture by the end of this decade due to today’s ongoing deployment of multiple global and regional satnav constellations with their diverse signal structures, and rapid advancements in parallel low-power processors and inexpensive sensors.
</p>
<p>
Non-realtime SDR operational scenarios involve storage and post-processing of samples. These sampled data files can also be used in radio frequency (RF) playback systems for GNSS receiver test and evaluation in the lab. Post-processing and/or playback requires several generic front-end parameters such as RF and intermediate frequency (IF) center frequencies, sample rate, file format, as well as GNSS-specific information such as antenna location and type. We define this information as GNSS SDR metadata. Manual transfer of metadata is the method predominantly used today – a process that is cumbersome and error prone to say the least. No established method exists to exchange this metadata automatically.
</p>
<p>
During the ION GNSS+ 2013 conference, a group of attendees discussed the need for a formal standard for the exchange of GNSS SDR metadata. This group identified the following benefits of engaging in this activity at the present:
</p>
<ul>
<li>It identifies and brings the international GNSS SDR community together as a working group. This collaboration is critical in order to get broad acceptance and usage.</li>
<li>Standardization will help to avoid technology segmentation issues while promoting the pace of innovation by standard practices and compliant tools. </li>
<li>The formal standard, if widely adopted, will help ensure compatibility and interoperability of future GNSS SDRs. Specifically, front-end agnostic “plug-and-play” SDRs are envisioned. These have the potential for revolutionizing positioning, navigation, and timing (PNT) systems of the future. </li>
</ul>
<p>
Most authors of significant GNSS SDR publications and contributions over the past two decades are ION members and frequent meeting attendees. Hence, we decided to pursue this standard through ION sponsorship. During the January 2014 Council Meeting in San Diego, ION approved the process for establishing a formal standard. The ION GNSS SDR Metadata Working Group (WG) was formed in April 2014. Membership represents academia, industry (including GNSS SDR product vendors as well as traditional GNSS equipment manufacturers), non-profit research entities, and government agencies spanning countries in America, Europe, Asia and Australia.
</p>
<p>
<strong>Justification for GNSS Metadata Standardization </strong><br />
<strong>Figure 1</strong> <em>(see inset photo, above right, for all figures) </em>shows the metadata transfer scheme mainly used in today’s GNSS SDR systems. The top row depicts data collection system (DCS) <em>A</em>, producing an SDR file of format <em>A</em>, consumed by SDR processor <em>A</em>. This may represent an end-to-end solution provided by a vendor or a system that was initially developed around a specific hardware platform. In any case, assume that the metadata for decoding Format <em>A</em> is hard-coded into the processor. Consequently, supporting other file formats involves extensive software revisions on a case-by-case basis. One group may want to share SDR files from DCS <em>A</em> with other groups using SDRs <em>X</em> and<em> Y</em> for research collaboration. This involves conveying the file format and other relevant information accurately to these other groups. Today, this metadata transfer occurs in an ad-hoc way that is prone to interpretation errors.
</p>
<p>
The second row depicts multi-stream DCS <em>B</em> that produces files with a more complicated format. SDR processors <em>X</em> and <em>Y</em> represents more flexible SDRs that are able to support multiple file formats. However, the data/metadata association requires manual intervention.
</p>
<p>
DCS <em>C</em> multiplexes other data (such as sensor data) along with multiple GNSS sample streams in the same file. This type of multiplexed collection has the potential to become more common with emerging SDR-related data streaming standards such as VITA-49 (See T. Cooklev et alia, Additional Resources). In this case, custom-designed processor <em>C</em> represents an SDR that fully supports multi-sensor integration capabilities. Because DCS <em>C</em>’s GNSS stream parameters are open, SDR <em>Y</em> is also able to support GNSS-only processing using an ad-hoc metadata transfer scheme. The sensor data parameters in Format <em>C</em> may or may not be open.
</p>
<p>
As clear from Figure 1, today’s ad hoc methods of metadata exchange do not encourage interoperability and instead cultivates potential for technology segmentation (i.e., various groups developing their own stove-piped solutions and technologies).
</p>
<p>
<strong>Figure 2</strong> shows the same systems of Figure 1 that have adopted a metadata standard. As shown, each DCS produces a compliant metadata file along with the SDR file. The metadata file is read-in by the compliant SDR processor to correctly decode and process files seamlessly.
</p>
<p>
Adoption of a metadata standard benefits DCS developers because their systems become applicable to a much wider group of users. Similarly, an SDR processor’s utility is extended when it is capable of supporting many file formats from multiple sources seamlessly. Thus, metadata standardization promotes interoperability of GNSS SDR systems and greatly simplifies the exchange of files between groups.
</p>
<p>
Metadata standardization also benefits other use cases beyond post-processing GNSS SDRs. For example, consider the use of the metadata specification to synthesize compliant SDR files for use in RF playback systems. Additionally, libraries of compliant SDR file sets containing various real-world scenarios could be used interchangeably in compliant RF playback simulators for repeatable and consistent testing of GNSS receivers.
</p>
<p>
<strong>SDR Data Collection Topologies </strong><br />
The ION Executive Committee stipulated that this standardization activity shall not create an unfair advantage or disadvantage to any entity. Specifically, the standard shall not require any existing system to undergo data format changes to achieve compliance. This “do no harm” stipulation implies that the standard be designed such that it supports all current and future SDR file formats. This also means that the WG must “get it right the first time” since major revisions to the standard would be undesirable and adverse to the goal of widespread adoption. Hence, we considered the entire space of possible GNSS SDR data collection topologies. <strong>Figure 3</strong> illustrates these topologies.
</p>
<p>
Figure 3.a illustrates the simplest data collection topology that can exist. This is when a single swath of RF spectrum (referenced henceforth as a “band”) is down-converted and sampled to produce a single data stream. The stream, which may be IF sampled (real samples) or baseband sampled (complex samples) is written to disk as a single file.
</p>
<p>
Figure 3b represents a DCS that writes parts of a single data stream across multiple files. This may be done to reduce the sustained write performance requirement of storage drives (similar to striping mode in RAID systems).
</p>
<p>
Figure 3.c is similar to Figure 3.a, except that the data stream represents more than one RF band. An example of this topology is a direct RF sampling front-end architecture that intentionally aliases multiple bands to fall next to each other at baseband. Some bands may be spectrally inverted as a result of the digital down-conversion process.
</p>
<p>
A DCS may produce multiple data streams. Each stream may contain information from one of many antenna elements (as shown in Figure 3.d, where each stream may also encompass multiple bands as in Figure 3.c). Alternatively, a stream may be sampling one of several bands received by a single wideband antenna, where the multiplexed streams written to file represents channelized samples. Combinations of the above are also possible.
</p>
<p>
Each stream may also be sampled at different rates and bit depths. For example, consider a civilian GPS L1, L2, L5 system. In this case, the L1 and L2 streams may be sampled at rate <em>f<sub>0</sub></em> and the L5 stream at 10·<em>f<sub>0</sub></em> (since the L5 signal’s null-to-null bandwidth is 10 times wider than L1 C/A and L2C), where <em>f<sub>0</sub></em> represents the base sample rate. Figure 3.d may also represent how these multiple streams are multiplexed into a single lane of packed binary data and written to a single file.
</p>
<p>
Similar to Figure 3.d, Figure 3.e illustrates a GNSS data stream multiplexed with other data that is written to a single file. This non-GNSS SDR data may be from additional sensors (as shown), and may be written in a proprietary format that may or may not be known.
</p>
<p>
The specification of metadata parameters for non-GNSS data is outside the scope of the present standardization effort. However, the standard must support adequate information to skip over such non-GNSS data bytes. Since the metadata schema is extensible, it can cover the description of non-GNSS SDR data as needed by specific users.
</p>
<p>
It is important to note that although we use the term “GNSS SDR data” in this article to generally refer to the type of sampled data for which metadata parameters are defined in the standard, the samples need not correspond to GNSS frequency bands. For example, frequency bands containing RF signals of opportunity are supported as long as they can be represented by the standard’s metadata parameters.
</p>
<p>
Due to the typically high data rate of GNSS SDRs, some DCSs write data as temporally split files, as illustrated in Figure 3.f. This allows for efficient data management through multiple smaller files compared to a single large file. The metadata for each file must associate the previous and next files in order to represent the sequence. Note that the DCS block shown in Figure 3.f could represent any of those described in topologies a, c, d, and e of Figure 3.
</p>
<p>
Figure 3.g illustrates spatial splitting of files. Here, the binary data lanes from two or more DCSs are written to separate files. These files may be written by different computer systems. In this case, a non-zero inter-system timing offset, <em>Δt</em>, may exist and must be supported in the standard. Since <em>Δt</em> may or may not be known at time of collection, it represents an example metadata parameter that may be back-annotated into the metadata file after an initial pass of SDR data processing.
</p>
<p>
Multi-lane DCSs that write each lane to a separate file may also implement temporal file splitting according to 3.f. We call this “spatial-temporal splitting”, and is illustrated in Figure 3.h.
</p>
<p>
Since multi-stream-multi-file data collection topologies (i.e., (g) and (h) in Figure 3) produce multiple data files applicable to a given time interval, the SDR processor must be “introduced” to the full or partial set of lanes associated with the topology. This is covered by lane selection parameters in the standard.
</p>
<p>
<strong>Metadata Parameters </strong><br />
The metadata standard enables a user to specify a wide range of properties of the binary data file. Some of these properties relate to the data collection scenario itself, such as the time and location, and the type of scenario. Other properties of the dataset relate to the particular RF data that is captured as IF samples, including center frequency and bandwidth. Yet other details such as the IF digitization configuration and data packing can be specified. These are briefly summarized below. Some of the parameters are free-form text, others are integer or floating point variables, and others are enumerations. The primary classes are shown in <strong>Figure 4</strong>.
</p>
<p>
The metadata “session” class holds details such as the time, the position, the measurement campaign, and the type of scenario. The “file” class contains a path to the corresponding binary data file, time-stamp info, and a reference to the contained “lane” (described below). A “system” class contains details of the data recording equipment, such as the equipment name, the reference clock frequency, and the antenna details/specifications. The metadata standard allows for the specification of a variety of RF bands, each “band” class includes details of the band’s center frequency, intermediate frequency, bandwidth and group-delay bias.
</p>
<p>
The actual format of the binary data is detailed in the “lane” class, which allows for the specification of a hierarchy of binary data packing patterns, entitled “blocks”, “chunks” and “lumps”. These classes specify the arrangement of the packed IF data and optional additional data such as sensor measurements or configuration information, and further specify the arrangement of data relative to the standard word-sizes (arrays of byte, short integers, integers, long integers, etc.). The arrangement of the raw IF samples within these blocks is specified by the “stream” class. This class specifies the associated RF band, the sample rate, the quantization, the sample format (real/complex), the encoding of the binary data and the arrangement/alignment of the samples. Together these classes contain sufficient information to unambiguously interpret the packed binary data.
</p>
<p>
<strong>Normative Reference Software </strong><br />
The primary responsibilities of the Normative Reference Implementation Subcommittee are to reduce to practice the conceptual design developed through consensus by the WG into an appropriate set of schema (according to industry best practices) and to develop a compliant software library implementation. The WG was fortunate to receive voluntary participation for this task from individuals representing established commercial GNSS SDR vendors.
</p>
<p>
The WG decided to work on a publicly available reference software library to be released with the standard. The goal of this effort is to promote early and widespread adoption of the standard by making it easy for vendors and researchers to integrate standard-compliance by integrating the library into their existing software. The scope of this effort is twofold, to develop a metadata interpreter, and to develop a binary data converter using this metadata interpreter.
</p>
<p>
The first contribution was a library that would produce standard-compliant metadata files from an appropriately-populated data structure, a library capable of reading the content of such files back to a data structure. The second contribution was in the form of a library capable of parsing and converting binary IF data based on an associated metadata description. When combined, it is hoped that these two libraries offer sufficient functionality to enable adoption of the metadata standard in SDRs, or to serve as a benchmark against which implementations of the standard can be validated.
</p>
<p>
The software is written in C++ and managed using CMake. It has been divided into two libraries, “apilib” implementing the Metadata Interpreter and “converterlib” implementing the binary data conversion, and is accompanied by a selection of utilities, including a data-converter application and a simple test application. The software is available on the Institute of Navigation’s GitHub account <a href="https://github.com/IonMetadataWorkingGroup/GNSS-Metadata-Standard" target="_blank">here</a>.
</p>
<p>
The Metadata Interpreter library includes a reader functionality that can parse a metadata file and populate a corresponding metadata object that can then be queried through a selection of member-function calls. Similarly, a metadata object can be instantiated and configured through a selection of member functions and, subsequently, it can be instructed to write a corresponding metadata file.
</p>
<p>
The converter library can be used for parsing binary data files and interpreting the data according to a metadata file. The basic converter can be adapted to support processing of the converted data streams, and two such adaptations have been implanted in the reference software. The first functionality is depicted in <strong>Figure 5</strong>, where the data-converter is embedded in a file-converter. The file-converter configures the embedded data-converter using a Metadata Interpreter object, and is capable of parsing a packed binary input file and producing one file per IF data stream in a user-specified data type (int8, int16, float, double, etc.).
</p>
<p>
A second functionality has been implemented by embedding the data converter in a “front-end”, as depicted in <strong>Figure 6</strong>. This front-end offers a means of loading short portions of the binary data file and converting them to a user-specified data type (int8, int16, float, double, etc.) while handling details such as sample alignment, when different streams are sampled at different rates.
</p>
<p>
The software suite includes a selection of example binary datasets and associated metadata files along with a simple MATLAB/Octave script to test the build against reference datasets. To date five different file formats have been included in the repository including a wide range of front-end configurations and data packing variations.
</p>
<p>
A number of working group members volunteered to perform “blind testing” of SDR data files against draft specifications. This involves exchanging SDR data files and associated metadata specifications among parties and verifying that the files can be fully decoded without additional information. Working group members participating in this activity will comprise the Compliance Verification Subcommittee.
</p>
<p>
<strong>SDR Data Repository </strong><br />
As with most standards and programming projects, they are best understood through good examples. Thus, <a href="http://sdr.ion.org/api-sample-data.html" target="_blank">this page</a> has been created and contains several binary sample files together with metadata files. All file sets have been tested to follow the standard and to be readable by the normative reference software. The binary files typically contain samples over a duration of more than 60 seconds and position fixes have been obtained by at least one software receiver implementation.
</p>
<p>
Further examples will be added, not only emphasizing new data recording systems but also illustrating different SDR applications such as antenna arrays, reflectometry or ionospheric scintillation analysis. Further, data from GNSS seen only at certain locations of the Earth (e.g., Quasi-Zenith Satellite System [QZSS]) are being considered.
</p>
<p>
Organizations are encouraged to contact the working group if they have files with formats that are currently not adequately represented in the repository or represent use cases so far not considered. The respective point of contact is given on the web page. The working group will then take care of creating a metadata file (if not yet available), check the correctness and organize the upload.
</p>
<p>
<span style="color: #993300"><strong>Additional Resources </strong></span><strong><span style="color: #ff0000"><br />
[1]</span></strong> Cooklev, T., R. Normoyle, and D. Clendenen, “The Vita49 Analog RF-Digital Interface,” <em>IEEE Circuits and Systems Magazine</em>, Q4 2012. <strong><span style="color: #ff0000"><br />
[2] </span></strong>Favenza, A., and N. Linty, “Exploiting Standardized Metadata for GNSS SDR Remote Processing: a Case Study”, ION GNSS+ 2016, Portland, Oregon (USA), 09/2016. <strong><span style="color: #ff0000"><br />
[3] </span></strong>Lucas-Sabola, V., G. Seco-Granados, J. A. López-Salcedo, J. A. García-Molina, M. Crisci, “Cloud GNSS receivers: New advanced applications made possible”, <em>Proc. Int. Conf. Localization GNSS (ICL-GNSS)</em>, pp. 1-6, 2016. <span style="color: #ff0000"><strong><br />
[4] </strong></span>Lucas-Sabola, V., Seco-Granados, G., López-Salcedo, J.A., García-Molina, J.A., Crisci, M., “Demonstration of Cloud GNSS Signal Processing,” <em>Proceedings of the 29th International Technical Meeting of The Satellite Division of the Institute of Navigation (ION GNSS+ 2016)</em>, Portland, Oregon, September 2016, pp. 34-43.
</p>
<div class='pdfclass'><a target='_blank' class='specialpdf' href='http://insidegnss.com/wp-content/uploads/2018/01/novdec17-STANDARDS.pdf'>Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/gnss-sdr-metadata-standard/">GNSS SDR Metadata Standard</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Towards Navigation Safety for Autonomous Cars</title>
		<link>https://insidegnss.com/towards-navigation-safety-for-autonomous-cars/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Mon, 27 Nov 2017 23:04:07 +0000</pubDate>
				<category><![CDATA[201710 November/December 2017]]></category>
		<category><![CDATA[Autonomous Vehicles]]></category>
		<category><![CDATA[civil]]></category>
		<category><![CDATA[commercial]]></category>
		<category><![CDATA[Cover Story]]></category>
		<category><![CDATA[engineering]]></category>
		<category><![CDATA[GNSS (all systems)]]></category>
		<category><![CDATA[high precision positioning]]></category>
		<category><![CDATA[integration/integrated system]]></category>
		<category><![CDATA[legacy-application]]></category>
		<category><![CDATA[mapping/GIS]]></category>
		<category><![CDATA[product design]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[Roads and Highways]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Survey and Mapping]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">http://insidegnss.com/2017/11/27/towards-navigation-safety-for-autonomous-cars/</guid>

					<description><![CDATA[<p>Figures 1 &#8211; 6, Table 1 There are many good reasons for getting excited about highly automated vehicles, or HAVs, which is the...</p>
<p>The post <a href="https://insidegnss.com/towards-navigation-safety-for-autonomous-cars/">Towards Navigation Safety for Autonomous Cars</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class='special_post_image'><img class='specialimageclass img-thumbnail' src='https://insidegnss.com/wp-content/uploads/2018/01/CoverFigs.jpg' ><span class='specialcaption'>Figures 1 &#8211; 6, Table 1</span></div>
<p>
There are many good reasons for getting excited about highly automated vehicles, or HAVs, which is the acronym used by the National Highway Traffic Safety Administration (NHTSA). HAVs can make driving more fuel- and time-efficient. They can significantly reduce traffic congestion and emissions by driving a precise speed, minimizing lane changes, and maintaining an exact distance to neighboring cars. They can also increase accessibility and mobility for disabled and elderly persons.
</p>
<p><span id="more-22947"></span></p>
<p>
There are many good reasons for getting excited about highly automated vehicles, or HAVs, which is the acronym used by the National Highway Traffic Safety Administration (NHTSA). HAVs can make driving more fuel- and time-efficient. They can significantly reduce traffic congestion and emissions by driving a precise speed, minimizing lane changes, and maintaining an exact distance to neighboring cars. They can also increase accessibility and mobility for disabled and elderly persons.
</p>
<p>
Sharing an HAV instead of owning is projected to dramatically reduce a household’s yearly transportation budget, which currently ranges between approximately $8,000 and $11,000 per car. HAVs carry promises not only in improved road mobility, and accessibility, but also in producing architectural and societal changes that can make mass parking spaces and personal car ownership obsolete in urban areas. Above all, HAVs can help improve road safety by preventing car accidents that cause more than 30,000 deaths/year in the United States alone, cost approximately $230 billion/year in medical and work loss costs, and are caused by humans 90% of the time.
</p>
<p>
Press articles in the 1950s and 1960s predicted that autonomous cars and “electronic highways” would become widely available by 1975. Major milestones in the use of new sensor, computation, and communication technology have recently reenergized the eagerness for HAVs. This first started with the 2005 “DARPA Grand Challenge”, where four different HAVs designed by teams of engineers from industry and academia completed a 132-mile trip across the Mohave desert in less than 7.5 hours with no human intervention. The 2007 DARPA “Urban Challenge” saw six teams autonomously complete a 60-mile course in an urban environment, while following traffic laws. Most teams used a combination of LiDAR, cameras, differential GPS, and computation power that is multiple orders of magnitude higher than what is typically needed for a commercial passenger vehicle. In 2009, Google (now Waymo) began designing and testing “self-driving” cars, which have since accumulated more than three million miles in autonomous mode.
</p>
<p>
Currently, most car manufacturers have HAV prototype systems and Google, Uber, NuTonomy have HAV pilot testing programs, including fully autonomous systems for public transportation, which, for now, are confined to segregated lanes and geo-fenced areas. Multiple Tier-2 supplier companies have emerged, which specialize in autonomous car technology. In early 2017, 36 companies were registered to test prototype HAV systems on public roads in the state of California.
</p>
<p>
However, in <strong>Figure 1</strong> <em>(for all figures, see inset photo, above right)</em>, Gartner’s “2016 Hype Cycle for Emerging Technologies” shows that HAV technology might be at the “peak of inflated expectations”, approaching the “trough of disillusionment”. Hype cycle curves are non-scientific tools that have been empirically verified for multiple example technologies over many years. Two example emerging technologies, commercial unmanned aircraft systems (UAS) and virtual reality, are included in Figure 1 for illustration purposes. The curve’s time scale may differ for each technology. One of many indicators of decreasing expectations on HAVs include a reduction in press coverage and the emergence of first negative news stories, in particular following the May 2016 crash of a Tesla Model S whose autopilot failed to distinguish a white trailer truck from the bright Florida sky. The Model S ran under the trailer causing its roof to be torn off and the operator to lose its life. The car kept going full speed on the side of the road through two fences until it hit a pole and came to a stop.
</p>
<p>
In parallel, until the end of 2016, Google was providing detailed reports of their self-driving car performance, which were designed to operate in real-world urban environments. These reports contain records of millions of miles driven autonomously, but also acknowledge “disengagements”, i.e., where the operator needed to take over control to avoid collisions. The data shows that HAVs are much more likely to be involved in collisions, even though these collisions are often of lower severity than in conventional human driving [HAVs typically get rear-ended because of their unusual road behavior] (see B. Schoettle, and M. Sivak, “A Preliminary Analysis of Real-World Crashes Involving Self-Driving Vehicles,” Additional Resources). Also, Uber’s autonomous taxis in Pittsburg have a reported rate of one disengagement per mile autonomously driven.
</p>
<p>
Moreover, the first fielded autonomous systems have revealed new safety threats. In particular, the technology’s functionality, as perceived by the human operator, does not always match the intended operational domain: for example, there have been cases of highway autopilots being used in urban areas and passing red lights without slowing down. In addition, human-machine interaction is at the heart of role confusion (is the operator or the HAV in charge?) of mode confusion (is the HAV in autonomous or manual mode?) and of the operator’s trust in this multimodal system. Misinterpretation may grow even wilder because a given functionality will not achieve the same level of performance across models and manufacturers, and operators may not be aware of the systems’ independently verified safety ratings. And, within the next few years, operators will be expected to anticipate hazardous situations and take over control. Thus, operating an HAV may require more education and different training than driving a car manually.
</p>
<p>
<strong>Current Safety Assessment Efforts </strong><br />
To focus this article, first consider the Society of Automotive Engineer (SAE) International’s classification of driving autonomy levels in <strong>Table 1</strong> <em>(see inset photo, above right)</em>. Under Levels 0 to 2, the human driver is responsible at all times, either for driving by himself, or for supervising the HAV in autonomous mode and taking control if needed. Under Levels 3 to 5, the system is self-monitoring and the driver is expected to take control, but only if requested by the system. Levels 0-4 provide partial automation under predefined driving modes and circumstances, whereas Level 5 is full autonomy.
</p>
<p>
The most advanced private car systems are currently Level 2, and pilot programs aim at achieving Level 3, although the mere presence of a kill-switch would imply that the system is actually Level 2. The transition from Level 2 to 3 is a remarkable leap that has significant implications on trust and comfort of human-machine interactions, on legal responsibility allocation between system and driver, and on technical challenges to overcome to guarantee passenger safety.
</p>
<p>
Over the past four years, the most publicized approaches to demonstrate Level 2 HAV safety have been experimental testing campaigns by Google, Tesla and Uber. Google’s approach to have HAVs drive millions of miles with minimal human intervention has been documented up until 2015. At this time, Google cars have autonomously travelled an impressive three million miles. Tesla’s autopilot is reported to have driven more than 130 million miles – on highways only – before it caused a fatality in May 2016.
</p>
<p>
In parallel, NHTSA reports about 3,000 billion miles travelled each year on U.S. highways by human drivers, with 30,000 deaths caused by traffic accidents; this corresponds to about one fatality in traffic accidents per 100 million miles driven in the U.S. But, this number accounts for incidents on all roads, in all weather conditions, and for all vehicle ages and types. Thus, a purely experimental, complete proof that HAVs match the level of safety of human driving would take about 400 years at Google’s current testing rate (of approximately 250,000 test miles per year), and would still take many decades if the testing rate increased exponentially. This is assuming that no fatalities occur during that time, that no major HAV upgrade is performed, and that the testing environment is representative of all U.S. roads. Thus, while an experimental proof is conclusive, it is not practical. Other, analytical, methods must be employed to ensure HAV safety.
</p>
<p>
<strong>Research Challenges In HAV Navigation Safety </strong><br />
Multiple technical aspects developed over decades for automated flying could serve as starting points for automated driving systems. <strong>Figure 2</strong> shows research areas with overlap between aircraft (in blue) and car (in yellow) applications. Figure 2 is not intended to give a comprehensive list of all aspects of automation, but instead, it shows example technical areas that can be addressed using similar methods in aviation and automotive applications (in the green area). For example:
</p>
<ul>
<li>performance standards set for software, communication, and electronic equipment are already being compared for aircraft versus cars in the NHTSA report by Q. D. Van Eikema Hommes, Additional Resources.</li>
<li>the design of aircraft cockpit has been continuously improved over the past few decades, especially for highly-automated Unmanned Air Systems (UAS) with a remote pilot “in-the-box”; few car manufacturers envision futuristic car interiors where humans do not participate in driving, but as long as human-machine interactions are needed, lessons learned in cockpit design to avoid information overload are key. </li>
<li>while Automatic Dependent Surveillance-Broadcast (ADS-B) will be mandatory on all aircraft by 2020, a petition for proposed rule making has been issued to mandate Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) by the same date. (ADS-B is a situational awareness system for collision avoidance, through which aircraft share their positions with Air Traffic Control and with other aircraft.) </li>
<li>GNSS/INS navigation systems, which are extensively used in safety-critical aircraft navigation, are also being investigated for HAVs.</li>
<li>overall safety standards also have similarities for aircraft and HAVs, which are discussed again below. </li>
</ul>
<p>
The focus of this article is on navigation safety. In aviation navigation, safety is assessed in terms of integrity (as well as accuracy, continuity, and availability, which are not discussed for brevity). Integrity is a measure of trust in sensor information: integrity risk is the probability of undetected sensor errors causing unacceptably large positioning uncertainty (See RTCA Special Committee 159, “Minimum Aviation System Performance Standards for the Local Area Augmentation System (LAAS), Additional Resources”). This top-level quantifiable performance metric is sensor- and platform-independent, and can thus be used to set certifiable requirements on individual system components to achieve and prove an overall level of safety.
</p>
<p>
The multiple separate efforts towards achieving Levels 3-to-5 HAVs reveal a compelling lack of coordination towards a common, uniform, quantifiable safety goal. Integrity can be used as an objective performance metric for open, transparent comparison and categorization across manufacturers. It can also provide a governmental regulating agency performance and testing standards for HAV certification, which would help accelerate the development, growth, and maturation of such HAVs, as displayed in <strong>Figure 3</strong>.
</p>
<p>
Moreover, the Federal Aviation Administration (FAA) has developed <em>analytical</em> methods to evaluate integrity. This provides the means to:
</p>
<ul>
<li>quantify safety of existing multi-sensor systems under a variety of operating environments, thereby reducing the need for experimental testing</li>
<li>allocate safety requirements to individual system components to achieve an overall target level of safety, thereby enabling design for safety </li>
<li>perform risk prediction, which is a key operational feature to enable hazard avoidance maneuvers </li>
</ul>
<p>
Several methods have been established to predict the integrity risk in GNSS-based aviation applications, which are instrumental in ensuring the safety of pilots and crew. As an example, <strong>Figure 4</strong> illustrates a simplified definition of the integrity risk for aircraft landing applications. The aircraft positioning prediction is uncertain because of sensor measurement noise. An alert limit (AL) requirement box is represented around the predicted aircraft position. This AL is set by the certification authority, i.e., by the FAA in this application. Simply put, the risk of the actual aircraft position being outside the AL box is the integrity risk. (In practice, the most challenging part of risk prediction is to account for potentially undetected sensor faults, such as excessive GNSS satellite clock drift.)
</p>
<p>
Unfortunately, the same methods do not directly apply to HAVs, because ground vehicles operate under sky-obstructed areas where GNSS signals can be altered or blocked by buildings and trees. In general, the HAV environment is much more unpredictable than the aircraft’s, for reasons that include:
</p>
<ul>
<li>a changing environment: traffic lights, construction, impact of rain on road adherence, sensor masking and occlusions,</li>
<li>environmental diversity: intersection topography, road conditions, markings on ground, various traffic signs </li>
<li>road users that may interfere with HAV motion: other cars, trucks, pedestrians, bicyclists, etc. </li>
<li>comparatively large number of car manufacturers, equipment suppliers, and vehicle models, as well as with shorter model cycles than aircraft, causing wide variations in vehicle age and maintenance levels </li>
<li>non-uniform vehicle and road regulations at both the state and federal levels in the U.S. coupled with different international standardization processes. </li>
</ul>
<p>
Thus, HAVs require sensors in addition to GNSS, including laser scanners, radars, cameras, and odometers.
</p>
<p>
The parallel between aircraft and car applications in Figure 4 illustrates the significant challenge that lies ahead when bringing aviation safety standards to HAVs. It took decades of research and considerable resources to bring the alert limit requirement box down to 10 meters above and below the aircraft using the FAA’s GPS augmentation systems (the Wide-Area Augmentation System and the Local Area Augmentation System). For a car to stay in its lane, the alert limit requirement box must be an order of magnitude smaller, and has to maintain this level of safety in a more dynamic and unpredictable environment.
</p>
<p>
<strong>HAV Taxonomy </strong><br />
Creating a path to successful automated navigation requires an overall methodology to prioritize on imminently achievable objectives, and then expand to more challenging missions. First in this HAV taxonomy, a classification using six SAE autonomy levels has been presented in Table 1. This classification is further refined by segmenting a car’s trip into basic driving competencies, and by specifying the conditions under which a given HAV shall achieve these competencies. A similar classification was made in the early days of GPS-based commercial aircraft navigation safety analysis, where distinctions were made between different phases of flight, weather conditions, vehicle equipment, and airport infrastructure capabilities.
</p>
<p>
For example, in the early 1990’s, 40% of aircraft accidents were occurring during final approach and landing, and 26% during take-off and initial climb, which only represented an average of 4% and 2% of flight time, respectively. The FAA therefore concentrated their efforts on improving safety during these phases of flight. GPS augmentation systems were designed, with varying capabilities depending on airborne equipment and airport infrastructure, to guide the aircraft under the cloud ceiling, or to bring it all the way to touch-down. Similarly, the “first and last mile” are identified as the most challenging parts of HAV operations, whereas highway auto-drive systems have already been developed and implemented. In its 2016 Federal Automated Vehicles Policy, NHTSA identifies 28 HAV behavioral competencies, which are particularly challenging to meet in the first and last miles of a typical trip. These competencies are basic abilities that an HAV must have to complete nominal driving tasks; they include, for example, lane keeping, obeying traffic laws, and responding to other road users.
</p>
<p>
To better describe an HAV’s ability, the Federal Automated Vehicles Policy further specifies that basic driving competencies should be available under an HAV’s predefined Operational Design Domain (ODD), described by its geographical location, road type and condition, weather and lighting condition, vehicle speed, etc. The ODD captures the circumstances under which an HAV is supposed to operate safely.
</p>
<p>
Such classification is key to safety analysis. It can allow HAVs at different stages of their development to be simultaneously fielded, and for them to evolve by expanding their ODDs. The classification can also help in identifying geographical areas where improved road infrastructure is needed for automated operation, similar to airports requiring equipment for instrument navigation to deal with higher traffic density.
</p>
<p>
Furthermore, standards for electronic equipment, measured by Automotive Safety Integrity Levels, have been issued and compared with the aviation’s Design Assurance Levels (DAL). And, overall system safety levels have been codified, which in aviation account for both the severity and probability of occurrence of an incident, and in automotive applications account, in addition, for “controllability”, which is a measure of how likely an average driver is to maneuver out of a given imminent danger.
</p>
<p>
All of the above elements: (a) HAV autonomy level, (b) basic driving competency, (c) operation design domain, (d) vehicle electronic equipment, and (e) overall safety risk requirement must be specified to carry out a formal HAV safety analysis. Still missing from the HAV documents are clear guidelines, or example methods, on how to implement these safety requirements.
</p>
<p>
<strong>A Path Towards HAV Navigation Safety </strong><br />
When quantifying the safety of HAV navigation systems, such as in the example displayed in <strong>Figure 5</strong>, every component of the system including raw sensors, estimator and integrity monitor, and safety predictor, can potentially introduce risk. Unlike aircraft, HAVs require multiple and varied sensors to compensate for GPS signal blockages caused by buildings and trees. These sensor types must be integrated, and new methods to evaluate the integrity of multi-sensor systems must be developed. Furthermore, HAVs must have the ability to continuously predict integrity in a dynamic HAV environment.
</p>
<p>
In general, research on analytical evaluation of HAV navigation safety is sparse. For example, J. Lee <em>et alia</em>, Additional Resources use the concept of a “safe driving envelope,” but the approach focuses mostly on collision avoidance. The paper by O. Le Marchand, <em>et alia</em>, evaluates ground vehicle navigation, but shows an “approximate radial-error” of tens of meters, far exceeding the necessary sub-meter alert limit. A multi-sensor augmented-GPS/IMU system is used in the paper by R. Toledo-Moreo, <em>et alia</em> with “horizontal trust levels” of 7 meters to 10 meters, still an order-of-magnitude higher than the required HAV alert limit.
</p>
<p>
Multi-sensor integrity is addressed by M. Brenner, Additional Resources, but for a sensor combination specific to aviation and insufficient for terrestrial mobile robots. Other approaches to multi-sensor integration show promise, but do not provide rigorous proof of integrity. In fact, most publications use pose estimation error covariance as a measure of performance, which is understood as not being sufficient, but is the only metric currently available. Most critically, the metric does not account for fault modes introduced by feature extraction and data association, two algorithms commonly used in mobile robot localization (and discussed again below).
</p>
<p>
Unlike GPS, which gives absolute position fixes, IMUs, LiDAR, radar, and cameras provide relative displacements with respect to a previous time-step, or with respect to a map. Thus, measurement time-filtering is required, which makes integrity risk evaluation more challenging since past-time sensor errors and undetected faults can now impact current-time safety.
</p>
<p>
<strong>Example LiDAR Navigation Safety Evaluation</strong> <br />
While safety quantification for GNSS and GNSS/INS has been rigorously performed for aviation applications, and is being researched for HAVs, navigation safety for LiDAR, radar, camera, and multi-sensor navigation is a widely unexplored research area. To provide a specific example on the research work that lies ahead, we have started developing safety risk evaluation methods for LiDARs. We selected LiDARs because of their prevalence in HAVs, of their market availability, and because of our prior experience. However, the techniques we are developing are general enough that radar, cameras, or any future sensor that returns range data can be substituted.
</p>
<p>
Raw range data must be processed before it can be used for navigation. One technique, visual odometry, establishes correlations between successive scans to estimate sensor changes in pose (i.e., position and orientation). These processes are highly computationally intensive, and have the same problems as other dead-reckoning techniques, such as wheel odometry over time. Thus, they can become inaccurate or cumbersome for HAVs moving over multiple time epochs. Although proprietary information regarding the use of visual odometry by HAV manufacturers is unavailable, the research literature suggests that it is only used for short time scale operations. A second class of algorithms provides sensor localization by extracting static features from the raw sensor data and associating those features to a map. This is typically done in two steps, as illustrated in <strong>Figure 6</strong>: feature extraction (FE) and data association (DA). The resulting information can then be iteratively processed using sequential estimators (e.g., Extended Kalman filter or EKF), which has been readily used in many practical applications.
</p>
<p>
There are several problems that the FE and DA algorithms are addressing. First, landmarks in the environment are unidentified, and their observations are not tagged in a manner similar to a GNSS satellite signal’s Pseudo Random Noise (PRN) number. Thus, the feature extraction algorithm must isolate the few most consistently identifiable, viewpoint-invariant landmarks in the raw sensor data. These features must be identifiable over repeated observations and distinguishable from one landmark to another. Features that are difficult to distinguish from each other can be found easily, but the possibility that the association is incorrect will greatly negatively impact the integrity risk.
</p>
<p>
Second, range data based on extracted features must match those features with those from a feature database or map. Data association algorithms accomplish this; however, incorrect associations commonly occur. These can lead to large navigation errors, as illustrated in Figure 6, thereby representing a threat to navigation integrity.
</p>
<p>
FE and DA can be challenging in the presence of sensor uncertainty. This is why many sophisticated algorithms have been devised. But, how can we prove whether these FE and DA methods are safe for life-critical HAV navigation applications, and under what circumstances? These research questions are currently unanswered. The most relevant publications on DA risk are found in literature on multi-target tracking. For example, in the paper Y. Bar-Shalom and T. E. Fortmann, an innovation-based nearest-neighbor DA criterion is introduced, which serves as basis in many practical implementations. The article by Y. Bar-Shalom, <em>et alia</em>, “The Probabilistic Data Association Filter,” provides a detailed derivation of the probability of correct association given measurements. However, this Bayesian approach is not well suited for safety-critical applications due to the lack of risk prediction capability, and to the problem of bounding the <em>a-posteriori</em> probability of association (a similar issue is encountered in the paper by F.C. Chan, <em>et alia</em>. Another insightful approach is followed in the paper by J. Areta, <em>et alia</em>). However, it makes approximations that do not necessarily upper-bound risks, hence do not guarantee safe operation, and it presents exact solutions that can only be evaluated using computationally expensive numerical methods, not adequate for real-time navigation. Also, the risk of FE is not addressed.
</p>
<p>
In response, we have been developing a new, computationally-efficient integrity risk prediction method to ensure safety of localization using LiDAR-based FE and DA. We have derived a multiple-hypothesis innovation-based DA method that provides the means to predict the probability of incorrect associations considering all potential landmark permutations. <em>(For more details on these methods, see the following four papers in Additional Resources, Nos. 31, 49, 50 and 51.) </em>We also determined a probabilistic lower bound on the minimum feature separation, which is guaranteed at FE, with pre-defined integrity risk allocation. The separation bound can be incorporated in an overall integrity risk equation. This new method was analyzed and tested to quantify the impact of incorrect associations on integrity risk. It showed that the positioning error covariance can be a misleading safety performance metric since cases were found where the contributions of incorrect associations to integrity risk far surpassed that of nominal errors accounted for in the positioning error covariance. In addition, the following key safety-tradeoff was illustrated: the more measurements are extracted, the lower the integrity risk contribution is under the correct association hypothesis, but the higher the other integrity risk contributions become because the risk of incorrect associations increases in the presence of cluttered, poorly-distinguishable landmarks. Finally, being surrounded by many landmarks increases the probability of continuous, uninterrupted navigation. The next step of this research aims at dealing with unmapped and non-static obstacles, and at quantifying the continuity risk of FE and DA.
</p>
<p>
<strong>Conclusion </strong><br />
Looking at the emergence of future HAV technology with the prior experience of aircraft navigation safety provides the means to scale up the challenges that lie ahead in the development of fully autonomous (Level 4 and 5) driverless cars. Many parallels can already be drawn between aviation safety requirements and early HAV standards and regulations. Still, the methods to fulfill these standards and regulations have to be established. If analytical methods are pursued, the following tasks need to be accomplished: (1) establish high-integrity raw sensor measurement error and fault models for non-GPS sensors; (2) develop analytical methods to quantify the safety risk of feature extraction and data association algorithms required in LiDAR, radar, and other pre-processing steps in camera-based localization; (3) design multi-sensor pose estimators and integrity monitors to evaluate the impact of undetected sensor faults on safety risk; and (4) derive, analyze, and experimentally implement integrity risk prediction in dynamic environments.
</p>
<p>
If these challenges are overcome, one will be able to quantify and prove the performance of an HAV’s navigation system — an essential part of safety. Proving navigation system integrity will also help give humans more confidence to trust HAVs, thus further developing the symbiotic relationship between humans and co-robots. Finally, as HAV technology progresses from driver’s aids such as active brake assist to full autonomous driving, this research is relevant now and will remain essential throughout the evolution of HAV technology.
</p>
<p>
<span style="color: #993300"><strong>Additional Resources </strong></span><strong><span style="color: #ff0000"><br />
[1]</span></strong> Abuhashim, T.S., M.F. AbdelHafez, and M.-A. AlJarrah. Building a robust integrity monitoring algorithm for a low cost gps-aided-ins system. <em>International Journal of Control, Automation, and Systems</em>, 8(5):11081122, 2010. <strong><span style="color: #ff0000"><br />
[2] </span></strong>Ackerman , E., “Self-Driving Cars Were Just Around the Corner—in 1960”, <em>IEEE Spectrum</em>, September 2016 <strong><span style="color: #ff0000"><br />
[3] </span></strong>Ackerman, E., “After Mastering Singapore’s Streets, NuTonomy’s Robo-taxis Are Poised to Take on New Cities,” <em>IEEE Spectrum</em>, 2016. <strong><span style="color: #ff0000"><br />
[4] </span></strong>Areta, J., Y. Bar-Shalom, and R. Rothrock, “Misassociation Probability in M2TA and T2TA,” <em>J. of Advances in Information Fusion</em>, Vol. 2, No. 2, 2007, pp. 113-127. <strong><span style="color: #ff0000"><br />
[5] </span></strong>Bailey, T., Mobile Robot Localization and Mapping in Extensive Outdoor Environments. PhD thesis, The University of Sydney, 2002. <strong><span style="color: #ff0000"><br />
[6] </span></strong>Bailey, T., and J. Nieto. Scan-slam: Recursive mapping and localization with arbitrary-shaped landmarks. In Workshop at the Institute of Electrical and Electronics Engineers Robotics Science and Systems (IEEE RSS), 2008. <strong><span style="color: #ff0000"><br />
[7] </span></strong>Bakhache, B., A Sequential RAIM Based on the Civil Aviation Requirements. In <em>Proceedings of the 12th International Technical Meeting of the Satellite Division of the Institute of Navigation (ION GPS 1999)</em>, pages 1201–1210, 1999. <strong><span style="color: #ff0000"><br />
[8] </span></strong>Basnayake, C., M. Joerger, and J. Aulde, <a href="http://insidegnss.com/webinar/safety-critical-positioning-for-automotive-applications/">“Safety-Critical Positioning for Automotive Applications”</a>, <em>Inside GNSS Webinar</em>, 2016. <strong><span style="color: #ff0000"><br />
[9] </span></strong>Bar-Shalom, Y., F. Daum, and J. Huang, “The Probabilistic Data Association Filter,” <em>IEEE Control Systems Magazine</em>, 2009, pp. 82-100. <strong><span style="color: #ff0000"><br />
[10] </span></strong>Bar-Shalom, Y., and T. E. Fortmann. <em>Mathematics in Science and Engineering</em>, chapter Tracking and Data Association. Academic Press, 1988. <strong><span style="color: #ff0000"><br />
[11]</span></strong> Bengtsson, O., and A.J. Baerveldt, “Robot localization based on scan-matching-estimating the covariance matrix for the IDC algorithm,” <em>Robotics and Autonomous Systems</em>, Vol. 44, 2003, pp. 29–40. <strong><span style="color: #ff0000"><br />
[12] </span></strong>Bonanni, R., “WAAS – LPV Airport and Aeronautical Surveys”, <em>ANM Airports Conference</em>, 2006. <strong><span style="color: #ff0000"><br />
[13]</span></strong> Bhuiyan, J., “Uber’s autonomous cars drove 20,354 miles and had to be taken over at every mile, according to documents,” available online <a href="#" target="_blank">here</a>, 2016 <strong><span style="color: #ff0000"><br />
[14] </span></strong>Blom, H.A.P., and Y. Bar-Shalom. The interacting multiple model algorithm for systems with markovian switching coefficients. <em>IEEE Transactions on Automatic Control</em>, 33(8):780783, 1988. <strong><span style="color: #ff0000"><br />
[15]</span></strong> Brenner, M., Integrated GPS/Inertial Fault Detection Availability. <em>NAVIGATION, Journal of The Institute of Navigation</em>, 43(2):111–130, 1996. <strong><span style="color: #ff0000"><br />
[16]</span></strong> Chan, F.C., M. Joerger, S. Khanafseh, and B. Pervan, “Bayesian Fault-Tolerant Position Estimator and Integrity Risk Bound for GNSS Navigation,” <em>Journal of Navigation of the RIN</em>, available on CJO2014, doi:10.1017/S0373463314000241, 2014. <strong><span style="color: #ff0000"><br />
[17]</span></strong> Chow, E., and A. Willsky. Analytical redundancy and the design of robust failure detection systems. <em>IEEE Transactions on Automatic Control</em>, 29(7):603614, 1984. <strong><span style="color: #ff0000"><br />
[18] </span></strong>Choukroun, D., and J. Speyer. Mode estimation via conditionally linear filtering: Application to gyro failure monitoring.<em> AIAA Journal of Guidance, Control, and Dynamics</em>, 65(2):632644, 2012.<strong><span style="color: #ff0000"><br />
[19]</span></strong> Clot, A., C. Macabiau, I. Nikiforov, and B. Roturier. Sequential RAIM Designed to Detect Combined Step Ramp Pseudo-Range Error. In <em>Proceedings of the 19th International Technical Meeting of the Satellite Division of the Institute of Navigation (ION GNSS 2006)</em>, page 26212633, 2006. <strong><span style="color: #ff0000"><br />
[20]</span></strong> ooper, A.J., <em>A Comparison of Data Association Techniques for Simultaneous Localization and Mapping</em>. PhD thesis, Massachusetts Institute of Technology, 2005. <strong><span style="color: #ff0000"><br />
[21] </span></strong>DARPA, “The Six Finishers of the DARPA Urban Challenge,” available online here, 2007. <strong><span style="color: #ff0000"><br />
[22]</span></strong> Defense Advanced Research Projects Agency (DARPA), “Robots conquer DARPA Grand Challenge,” Press Release, U.S. Department of Defense (DoD), 2005. <strong><span style="color: #ff0000"><br />
[23] </span></strong>Department of Transportation (DOT) National Highway Traffic Safety Administration (NHTSA) “Federal Automated Vehicles Policy: Accelerating the Next Revolution In Roadway Safety,” 2016 <strong><span style="color: #ff0000"><br />
[24]</span></strong> Diesel, J., and S. Luu. GPS/IRS AIME: Calculation of Thresholds and Protection Radius Using Chi-Square Methods. In <em>Proceedings of the 8th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GPS 1995)</em>, page 19591964, 1995. <strong><span style="color: #ff0000"><br />
[25]</span></strong> Dionne, D., Y. Oshman, and D. Shinar. Novel adaptive generalized likelihood ratio detector with application to maneuvering target tracking. <em>AIAA Journal of Guidance, Control, and Dynamics</em>, 29(2):465474, 2006. <strong><span style="color: #ff0000"><br />
[26] </span></strong>Diosi, A., and L. Kleeman, “Laser scan matching in polar coordinates with application to SLAM,” <em>Proc. IEEE/RSJ IROS</em>, 2005. <strong><span style="color: #ff0000"><br />
[27]</span></strong> Dissanayake, G., P. Newman, S. Clark, H. Durrant-Whyte, and M. Csorba. A Solution to the Simultaneous Localization and Map Building (SLAM) Problem. <em>IEEE Transactions on Robotics Automation</em>, 17(3):229–241, 2001. <strong><span style="color: #ff0000"><br />
[28] </span></strong>Dougherty, M., “Caltrans Leadership in Automated Vehicle Research,” <em>Automated Vehicles Symposium 2017 </em>(AVS2017), San Francisco, CA, 2017. <strong><span style="color: #ff0000"><br />
[29]</span></strong> Dragalin, V.P., A.G. Tartakovsky, and V.V. Veeravalli. The interacting multiple model algorithm for systems with markovian switching coefficients. <em>IEEE Transactions on Information Theory</em>, 45(7):24482461, 1999. <strong><span style="color: #ff0000"><br />
[30]</span></strong> Dragalin, V.P., A.G. Tartakovsky, and V.V. Veeravalli. Multihypothesis sequential probability ratio tests. ii. accurate asymptotic expansions for the expected sample size. <em>IEEE Transactions on Information Theory</em>, 46(4):13661383, July 2000. <strong><span style="color: #ff0000"><br />
[31]</span></strong> Duenas-Arana, G., M. Joerger, and M. Spenko, “Minimizing Integrity Risk via Landmark Selection in Mobile Robot Localization,” submitted to <em>IEEE TRA</em>, 2017. <strong><span style="color: #ff0000"><br />
[32]</span></strong> FAA, “System Design and Analysis,” <em>Advisory Circular AC 25.1309-1A</em>, 1988. <strong><span style="color: #ff0000"><br />
[33] </span></strong>FAA, “System Safety Design and Analysis for Part 23 Airplanes”, <em>Advisory Circular AC 23.1309-1E</em>, 2011. <strong><span style="color: #ff0000"><br />
[34] </span></strong>fars.NHTSA.dot.gov, “Fatality analysis reporting system,” Technical report, <em>NHTSA</em>, 2014. <strong><span style="color: #ff0000"><br />
[35]</span></strong> Federal Aviation Administration (FAA), “Automatic Dependent Surveillance-Broadcast Operations,” <em>Advisory Circular AC No: 90-114A</em>, DoT FAA, 2016. <strong><span style="color: #ff0000"><br />
[36]</span></strong> Federal Highway Administration (FHWA), “Vehicle Positioning Trade Study for ITS Applications”, <em>FHWAJPO-12-064</em>, 2012. <strong><span style="color: #ff0000"><br />
[37]</span></strong> Fenton, R. E., and K. W. Olson “The electronic highway” <em>IEEE Spectrum</em>, 1969. <strong><span style="color: #ff0000"><br />
[38] </span></strong><a href="http://www.forsbergservices.co.uk" target="_blank">Forsberg</a>, “NovAtel Establishes Advanced Research Partnership with Illinois Institute of Technology and the University of Arizona,” press release, 2016, available <a href="http://www.forsbergservices.co.uk/index.php/2016/11/16/novatel-establishes-advanced-research-partnership-with-illinois-institute-of-technology-and-the-university-of-arizona/" target="_blank">here</a>.<strong><span style="color: #ff0000"><br />
[39]</span></strong> Gartner’s “2016 Hype Cycle for Emerging Technologies” available online <a href="http://www.gartner.com/newsroom/id/3412017" target="_blank">here</a>. <strong><span style="color: #ff0000"><br />
[40]</span></strong> Gertler, J., A survey of model based failure detection and isolation in complex plants. <em>IEEE Control Systems Magazine</em>, 8(6):3–11, 1988. <strong><span style="color: #ff0000"><br />
[41] </span></strong>Gitlin, J., “Prepare for the part-time self-driving car,” online at <a href="https://arstechnica.com/" target="_blank"><em>arstechnica.com</em></a>, 2014. <strong><span style="color: #ff0000"><br />
[42]</span></strong> Google, “Google self-driving car testing report on disengagements of autonomous mode”, available online <a href="https://www.dmv.ca.gov/portal/wcm/connect/dff67186-70dd-4042-bc8c-d7b2a9904665/GoogleDisengagementReport2014-15.pdf?MOD=AJPERES" target="_blank">here</a>, December 2015. <strong><span style="color: #ff0000"><br />
[43]</span></strong> Greenblatt, J. B., and S. Saxena, “Autonomous taxis could greatly reduce greenhouse-gas emissions of us light-duty vehicles,” <em>Nature Climate Change</em>, 5:860–863, 2015. <strong><span style="color: #ff0000"><br />
[44]</span></strong> Greiling Keane, A., “U.S. highway deaths decline for a fifth year, longest streak since 1899,” <em>Bloomberg</em>, Published December 08, 2011. <strong><span style="color: #ff0000"><br />
[45]</span></strong> Halsey III, A., and M. Laris, “Blind man sets out alone in Google’s driverless car,” <em>The Washington Post</em>, 2016. <strong><span style="color: #ff0000"><br />
[46]</span></strong> Hewitson, S., and J. Wang. Extended Receiver Autonomous Integrity Monitoring (eRAIM) for GNSS/INS Integration. <em>Journal of Surveying Engineering</em>, 136(1):13–22, 2010. <strong><span style="color: #ff0000"><br />
[47] </span></strong>Hype cycle curves available online <a href="https://en.wikipedia.org/wiki/Hype_cycle" target="_blank">here</a>. <strong><span style="color: #ff0000"><br />
[48]</span></strong> International Organization for Standardization (ISO), “Road vehicles &#8211; Functional safety”, <em>ISO 26262</em>, 2011. <strong><span style="color: #ff0000"><br />
[49]</span></strong> Joerger, M., “Carrier Phase GPS Augmentation Using Laser Scanners and Using Low Earth Orbiting Satellites,” Ph.D. Dissertation, Illinois Institute of Technology, 2009. <strong><span style="color: #ff0000"><br />
[50] </span></strong>Joerger, M., M. Jamoom, M. Spenko, and B. Pervan, “Integrity of Laser-Based Feature Extraction and Data Association,” <em>Proc. IEEE/ION PLANS 2016</em>, Savannah, GA, 2016, pp. 557-571. <strong><span style="color: #ff0000"><br />
[51]</span></strong> Joerger, M., B. Pervan, “Continuity Risk of Feature Extraction for Laser-Based Navigation,” <em>Proceedings of the 2017 International Technical Meeting of The Institute of Navigation</em>, Monterey, California, January 2017, pp. 839-855. <strong><span style="color: #ff0000"><br />
[52]</span></strong> Joerger, M., and B. Pervan, “Quantifying Safety for Laser-based Navigation,” submitted to <em>IEEE TAES</em>, 2017. <strong><span style="color: #ff0000"><br />
[53]</span></strong> Kalra, N., and S. Paddock, “Driving to safety: How many miles of driving would it take to demonstrate autonomous vehicle reliability?” <em>Technical Report RR-1478-RC</em>, Rand Corporation, 2016. <strong><span style="color: #ff0000"><br />
[54]</span></strong> Kavanaugh-Brown, J., “Where the Research Meets the Road: Automated Highway Passes the Test ”, <em>Government Technology</em>, 1997. available here.<strong><span style="color: #ff0000"><br />
[55]</span></strong> Kelly, R., and J. Davis, “Required Navigation Performance (RNP) for Precision Approach and Landing with GNSS Application,” <em>NAVIGATION</em>, 1994. <strong><span style="color: #ff0000"><br />
[56] </span></strong>Lee, Y.C., “Analysis of Range and Position Comparison Methods as a Means to Provide GPS Integrity in the User Receiver,” <em>Proc. of the 42nd Annual Meeting of The Institute of Navigation</em>, Seattle, WA, 1986. <strong><span style="color: #ff0000"><br />
[57] </span></strong>Lee, J., B. Kim, J. Seo, K. Yi, J. Yoon, and B. Ko. Automated driving control in safe driving envelope based on probabilistic prediction of surrounding vehicle behaviors. <em>Society of Automotive Engineers International Journal of Passenger Cars &#8211; Electronic and Electrical Systems</em>, 8(1):207–218, 2015. <span style="color: #ff0000"><strong><br />
[58]</strong></span> Le Marchand, O., Philippe Bonnifait, Javier Ibaez-Guzmn, and David Btaille. Vehicle Localization Integrity Based on Trajectory Monitoring. In <em>IEEE/RSJ International Conference on Intelligent Robots and Systems</em>, pages 3453–3458, 2009. <strong><span style="color: #ff0000"><br />
[59] </span></strong>Leonard, J., and H. Durrant-Whyte. <em>Directed Sonar Sensing for Mobile Robot Navigation</em>. Kluwer Academic Publishers, 1992. <strong><span style="color: #ff0000"><br />
[60] </span></strong>Li, Y., and Olson E.B. A general purpose feature extractor for light detection and ranging data. <em>Sensors</em>, 10(11), 2010. <strong><span style="color: #ff0000"><br />
[61]</span></strong> Lorden, G., Procedures for reacting to a change in distribution.<em> The Annals of Mathematical Statistics</em>, 42(6):18971908, 1971. <strong><span style="color: #ff0000"><br />
[62]</span></strong> Lu, F., and E. Milios, “Globally Consistent Range Scan Alignment for Environment Mapping,” <em>Autonomous Robots 4</em>, 1997, pp. 333-349. <strong><span style="color: #ff0000"><br />
[63]</span></strong> Madhavan, R., H. Durrant-Whyte, and G. Dissanayake. Natural landmark-based autonomous navigation using curvature scale space. In <em>Proceedings of the Institute of Electrical and Electronics Engineers International Conference on Robotics and Automation (IEEE ICRA)</em>, 2002. <strong><span style="color: #ff0000"><br />
[64] </span></strong>Malladi, D. P., and J. L. Speyer. A generalized shiryayev sequential probability ratio test for change detection and isolation. <em>IEEE Transactions on Automatic Control</em>, 44(8):1522–1534, 1999. <strong><span style="color: #ff0000"><br />
[65]</span></strong> Maksarov, D., and H. Durrant-Whyte. Mobile Vehicle Navigation in Unknown environments: a Multiple Hypothesis Approach. In <em>IEEE Proceedings on Control Theory Applications</em>, volume 142, pages 385–400, 1995. <strong><span style="color: #ff0000"><br />
[66] </span></strong>National Transport Safety Board (NSTB), “Preliminary Report, Highway HWY16FH018,” <em>Accident Report ID: HWY16FH018, 2016</em>. available online <a href="https://www.ntsb.gov/investigations/AccidentReports/Pages/HWY16FH018-preliminary.aspx" target="_blank">here</a>. <strong><span style="color: #ff0000"><br />
[67]</span></strong> Neville, K., and K. Williams, “Integrating Remotely Piloted Aircraft Systems into the National Airspace System,” <em>Remotely Piloted Aircraft Systems: A Human Systems Integration Perspective</em>, Wiley, 2017. <strong><span style="color: #ff0000"><br />
[68] </span></strong>Nguyen, V., A. Martinelli, N. Tomatis, and R. Siegwart. A comparison of line extraction algorithms using 2d laser rangefinder for indoor mobile robotics. In <em>Proceedings of the Institute of Electrical and Electronics Engineers/Robotics Society of Japan International Conference on Intelligent Robots and Systems (IEEE/RSJ IROS)</em>, 2005. <strong><span style="color: #ff0000"><br />
[69]</span></strong> NHTSA “National motor vehicle crash causation survey: Report to congress,” <em>Technical Report DOT HS 811 059</em>, U.S. Department of Transportation, 2008. <strong><span style="color: #ff0000"><br />
[70] </span></strong>NHTSA, “Federal Motor Vehicle Safety Standards; V2V Communications, Notice of Proposed Rulemaking (NPRM),” <em>DoT NHTSA, 49 CFR Part 571, RIN 2127-AL55</em>, 2016, available online <a href="http://www.safercar.gov/v2v/pdf/V2V%20NPRM_Web_Version.pdf" target="_blank">here</a>. <strong><span style="color: #ff0000"><br />
[71] </span></strong>NHTSA “Assessment of Safety Standards for Automotive Electronic Control Systems”, <em>DOT HS 812 285</em>, 2016. <strong><span style="color: #ff0000"><br />
[72] </span></strong>Nikiforov, I., New Optimal Approach to Global Positioning System/Differential Global Positioning System Integrity Monitoring. <em>AIAA Journal of Guidance, Control, and Dynamics</em>, page 10231033, 1996. <strong><span style="color: #ff0000"><br />
[73]</span></strong> Nunez, P., R. Vazquez-Martin, J.C. del Toro, and A. Bandera. Feature extraction from laser scan data based on curvature estimation for mobile robotics. In <em>Proceedings of the Institute of Electrical and Electronics Engineers International Conference on Robotics and Automation (IEEE ICRA)</em>, 2006. <strong><span style="color: #ff0000"><br />
[74]</span></strong> Othman, N.A., and H. Ahmad. The analysis of covariance matrix for kalman filter based slam with intermittent measurement. In <em>Proceedings of the 2013 International Conference on Systems, Control and Informatics</em>, 2013. <strong><span style="color: #ff0000"><br />
[75] </span></strong>Page, E.S., Continuous inspection schemes. <em>Biometrika</em>, 41(1-2):100–115, 1954. <strong><span style="color: #ff0000"><br />
[76]</span></strong> Parkinson, B.W., and P. Axelrad, “Autonomous GPS Integrity Monitoring Using the Pseudorange Residual,” <em>NAVIGATION</em>, Vol. 35, No. 2, 1988. <strong><span style="color: #ff0000"><br />
[77]</span></strong> Pfister, S.T., K.L. Kriechbaum, S.I. Roumeliotis, and J.W. Burdick. Weighted range sensor matching algorithms for mobile robot displacement estimation. In <em>Proceedings of the Institute of Electrical and Electronics Engineers International Conference on Robotics and Automation (IEEE ICRA)</em>, 2002. <strong><span style="color: #ff0000"><br />
[78] </span></strong>Pfister, S.T., S.I. Roumeliotis, and J.W. Burdick. Weighted line fitting algorithms for mobile robot map building and efficient data representation robotics and automation. In <em>Proceedings of the Institute of Electrical and Electronics Engineers International Conference on Robotics and Automation (IEEE ICRA)</em>, 2003. <strong><span style="color: #ff0000"><br />
[79] </span></strong>Radio Technical Commission for Aeronautics (RTCA), “Minimum Operating Performance Standards (MOPS) for Universal Access Transceiver (UAT) Automatic Dependent Surveillance – Broadcast (ADS-B),” <em>RTCA</em>, Washington DC, 2009. <strong><span style="color: #ff0000"><br />
[80]</span></strong> RTCA Special Committee 159, “Minimum Aviation System Performance Standards for the Local Area Augmentation System (LAAS),” <em>RTCA/DO-245</em>, 2004. <strong><span style="color: #ff0000"><br />
[81] </span></strong>RTCA Special Committee 159, “Minimum Operational Performance Standards for Global Positioning System/Wide Area Augmentation System Airborne Equipment,” <em>RTCA/DO-229C</em>, 2001. <strong><span style="color: #ff0000"><br />
[82] </span></strong>Reimer, B., “Revisiting the Topic – The Future is Autonomous Driving – But Are “We” on a Near Term Collision Course?” <em>Automated Vehicle Symposium 2017</em>, (AVS2017), San Francisco, CA, 2017. <strong><span style="color: #ff0000"><br />
[83]</span></strong> Röfer, T., “Using Histogram Correlation to Create Consistent Laser Scan Maps,” <em>Proc. IEEE IROS-2002</em>, Lausanne, Switzerland, 2002, pp. 625-630. <strong><span style="color: #ff0000"><br />
[84] </span></strong>Rogowsky, M., “The Truth About Tesla’s Autopilot Is We Don’t Yet Know How Safe It Is”, <em>Forbes</em>, 2016. <strong><span style="color: #ff0000"><br />
[85]</span></strong> SAE International, “Surface Vehicle Recommended Practice: Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles,” <em>SAE Standard J3016</em>, 2016. <strong><span style="color: #ff0000"><br />
[86]</span></strong> Schoettle, B., and M. Sivak, “A Preliminary Analysis of Real-World Crashes Involving Self-Driving Vehicles,” Report No. <em>UMTRI-2015-34</em>, October 2015. <strong><span style="color: #ff0000"><br />
[87] </span></strong>Sobel, M., and A.Wald. A sequential decision procedure for choosing one of three hypotheses concerning the unknown mean of a normal distribution. <em>The Annals of Mathematical Statistics</em>, 20(4):502522, 1949. <strong><span style="color: #ff0000"><br />
[88] </span></strong>Soloviev, A., D. Bates, and F. van Graas. Tight Coupling of Laser Scanner and Inertial Measurements for a Fully Autonomous Relative Navigation Solution. <em>NAVIGATION, Journal of The Institute of Navigation</em>, 54(3):189 – 205, 2007. <strong><span style="color: #ff0000"><br />
[89] </span></strong>Soloviev, A., Multi-Sensor Fusion for Navigation of Autonomous Vehicles. In <em>Proceedings of the 26th International Technical Meeting of The Satellite Division of the Institute of Navigation (ION GNSS+ 2013)</em>, pages 3615 – 3632, 2013. <strong><span style="color: #ff0000"><br />
[90]</span></strong> Soloviev, A., C. Yang, M. Veth, and C. Taylor. Assured Vision Aided Inertial Localization. In <em>Proceedings of the 27th International Technical Meeting of The Satellite Division of the Institute of Navigation (ION GNSS+ 2014)</em>, pages 2160 – 2173, 2014. <strong><span style="color: #ff0000"><br />
[91] </span></strong>Sukkarieh, S., E.M. Nebot, and H.F. Durrant-Whyte. A high integrity imu/gps navigation loop for autonomous land vehicle applications. <em>IEEE Transactions on Robotics and Automation</em>, 51(3):572578, 1999. <strong><span style="color: #ff0000"><br />
[92]</span></strong> Toledo-Moreo, R., M. A. Zamora-Izquierdo, B. beda Miarro, and A. F. Gmez-Skarmeta. High-Integrity IMMEKF-Based Road Vehicle Navigation With Low-Cost GPS/SBAS/INS. <em>IEEE Transactions on Aerospace and Electronic Systems</em>, 8(3):491–511, 2007. <strong><span style="color: #ff0000"><br />
[93] </span></strong>Tena Ruiz, I., Y. Petillot, D.M. Lane, and C. Salson. Feature extraction and data association for AUV concurrent mapping and localization. In <em>Proceedings of the Institute of Electrical and Electronics Engineers International Conference on Robotics and Automation (IEEE ICRA)</em>, 2001. <strong><span style="color: #ff0000"><br />
[94] </span></strong>Thrun, S., W. Burgard, and D. Fox. A probabilistic approach to concurrent mapping and localization for mobile robots. <em>Machine Learning and Autonomous Robots</em>, 31(5):1–25, 1998. <strong><span style="color: #ff0000"><br />
[95]</span></strong> Thrun, S., W. Burgard, and D. Fox. A real-time algorithm for mobile robot mapping with applications to multi-robot and 3d mapping. In <em>Proceedings of the Institute of Electrical and Electronics Engineers International Conference on Robotics and Automation (IEEE ICRA)</em>, 2000. <strong><span style="color: #ff0000"><br />
[96] </span></strong>Thrun, S., “Robotic Mapping: A Survey,” <em>Exploring Artificial Intelligence in the New Millenium</em>. Morgan Kaufmann Publishers Inc., 2003. <strong><span style="color: #ff0000"><br />
[97] </span></strong>Thrun, S., “National Highway Traffic Safety Administration (NHTSA),” keynote presentation,<em> ION GNSS 2007</em>, Fort Worth, TX, 2007. <strong><span style="color: #ff0000"><br />
[98]</span></strong> Van Eikema Hommes, Q. D., “Assessment of safety standards for automotive electronic control systems,” <em>NHTSA Report No. DOT HS 812 285</em>, Washington, DC, 2016. <strong><span style="color: #ff0000"><br />
[99] </span></strong>Waymo, “We’ve reached 3 million miles of selfdriving on public roads! That’s 1 million miles in just 7 months,” available online <a href="https://twitter.com/Waymo?lang=en" target="_blank">here</a>, 2017. <strong><span style="color: #ff0000"><br />
[100] </span></strong>White, N. A., P.S. Maybeck, and S.L. DeVilbiss. Detection of interference/jamming and spoofing in a dgps-aided inertial system. <em>IEEE Transactions on Aerospace and Electronic Systems</em>, 34(4):12081217, 1998. <strong><span style="color: #ff0000"><br />
[101] </span></strong>Wikipedia , “Automotive Safety Integrity Level,” 2017. available <a href="https://en.wikipedia.org/wiki/Automotive_Safety_Integrity_Level" target="_blank">here</a>.<strong><span style="color: #ff0000"><br />
[102] </span></strong>Williams, S.B., G. Dissanayake, and H. Durrant-Whyte. An efficient approach to the simultaneous localization and mapping problem. In <em>Proceedings of the Institute of Electrical and Electronics Engineers International Conference on Robotics and Automation (IEEE ICRA)</em>, 2002. <strong><span style="color: #ff0000"><br />
[103] </span></strong>Willsky, A. S., A Survey of Design Methods for Failure Detection in Dynamic Systems. <em>Automatica</em>, 12:601–611, 1976. <strong><span style="color: #ff0000"><br />
[104] </span></strong>Working Group C ARAIM Technical Subgroup, “Milestone 3 Report,” Technical report, <em>EU-US Cooperation on Satellite Navigation</em>, 2015. <span style="color: #ff0000"><strong><br />
[105] </strong></span>Yoshida, J., “Another Tesla Crash, What It Teaches Us,” <em>EE Times</em>, 2016.
</p>
<div class='pdfclass'><a target='_blank' class='specialpdf' href='http://insidegnss.com/wp-content/uploads/2018/01/novdec17-JOERGER.pdf'>Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/towards-navigation-safety-for-autonomous-cars/">Towards Navigation Safety for Autonomous Cars</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Ensuring PNT for All</title>
		<link>https://insidegnss.com/ensuring-pnt-for-all/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Tue, 26 Sep 2017 08:59:27 +0000</pubDate>
				<category><![CDATA[201708 September/October 2017]]></category>
		<category><![CDATA[civil]]></category>
		<category><![CDATA[Column]]></category>
		<category><![CDATA[GNSS (all systems)]]></category>
		<category><![CDATA[Military - Defense]]></category>
		<category><![CDATA[PNT]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[system infrastructure/technology]]></category>
		<category><![CDATA[Thinking Aloud]]></category>
		<guid isPermaLink="false">http://insidegnss.com/2017/09/26/ensuring-pnt-for-all/</guid>

					<description><![CDATA[<p>Today’s headlines frame my thoughts about securing GNSS assets, which one expert has characterized as our “least visible and most vulnerable infrastructure.” Today’s...</p>
<p>The post <a href="https://insidegnss.com/ensuring-pnt-for-all/">Ensuring PNT for All</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>
Today’s headlines frame my thoughts about securing GNSS assets, which one expert has characterized as our “least visible and most vulnerable infrastructure.”
</p>
<p><span id="more-22945"></span></p>
<p>
Today’s headlines frame my thoughts about securing GNSS assets, which one expert has characterized as our “least visible and most vulnerable infrastructure.”
</p>
<p>
In the Columbia River Gorge, a National Scenic Area spanning the Washington-Oregon border, a 15-year-old boy has been accused of intentionally tossing fireworks into tinder-dry grass thereby starting a (thus far) 33,000-acre forest fire that has devastated a natural treasure. Meanwhile, in the latest incident of large-scale identity theft, credit-rating agency Equifax has belatedly acknowledged a months-long breach of its database in which 143 million personal records were reportedly accessed.
</p>
<p>
In one case, an individual — obliviously or purposefully — creates outsized havoc, in the other, a skilled team of professional thieves disrupt a global enterprise and endanger the financial well-being of millions.
</p>
<p>
Of course, we have headlines closer to the point, such as <a href="http://insidegnss.com/news/reports-of-mass-gps-spoofing-attack-in-the-black-sea-strengthen-calls-for-pnt-backup/">“Reports of Mass GPS Spoofing Attack in the Black Sea,”</a> or <a href="http://insidegnss.com/news/south-korea-developing-an-eloran-network-to-protect-ships-from-cyber-attacks/">“South Korea developing eLoran Network to Protect Ships”</a> from North Korean GPS jamming.
</p>
<p>
These latter incidents, of course, arise from state-sponsored or –enabled actions. But, as with the Columbia gorge fire, personal behaviors — often harder to detect and prevent — can similarly afflict GNSS capabilities. In recent years, considerable attention has focused on the use of small GNSS jammers, also known as “personal privacy devices.” Perhaps the best-known case is that of a trucker trying to jam his vehicle’s own receiver who interrupted GPS-aided landing operations at Newark International Airport.
</p>
<p>
As the articles on jamming and spoofing mitigation in this issue of <em>Inside GNSS</em> reflect, the motives and methods of perpetrators vary. But, given the natural progression of information-sharing and widening expertise in GNSS — along with our cultural soft spot for making heroes out of rebels and outlaws — we can probably assume that the trend toward disruption will only get worse.
</p>
<p>
Some GNSS user groups have struck out on their own to ensure the security of their constituencies and their particular needs. Military users benefit from a variety of alternative PNT technologies such as geomagnetic mapping, vision- and image-based navigation, and chip-scale atomic clocks and inertial measurement units. The U.S. Federal Aviation Administration has decided to retain, for the time being, a minimum operational network of VHF omnidirectional range (VOR) facilities originally planned to be phased out with the introduction of GNSS.
</p>
<p>
Over time, some of these alternatives may migrate into the commercial and professional space — then again, they may not. And the vast majority of individual GNSS consumers have no organizations to advocate for their needs.
</p>
<p>
So, what is to be done? How can we ensure that the positioning, navigation, and timing (PNT) utility is available to all users, and not just those sectors with the resources to develop solutions for themselves? The future of location-based applications and enterprise — and the associated economic benefits — depend on a satisfactory answer to that question.
</p>
<p>
Multi-level threats clearly require multi-tiered responses that fit the corresponding scope and scale of different domains. At the system level, GNSS providers are exploring such measures as encryption, signal authentication, stronger signal power, and advanced signal designs.
</p>
<p>
National and international legal/initiatives include such efforts as regulating the sale and use of GNSS jammers and spoofers. Alternative PNT systems — for example, enhanced Loran (eLoran) — represent a potential multinational approach to the problem.
</p>
<p>
At the level of user equipment, several GNSS manufacturers are incorporating interference detection and mitigation (IDM) and antispoofing capabilities into proprietary products.
</p>
<p>
The variety of these initiatives and their advocates illustrates the breadth of concern about assured PNT, but also reflect the fractured nature of responses to the threats to GNSS. The situation calls for leadership with the expertise and stature to bring comprehensive solutions before the wider GNSS community.
</p>
<p>
The International Committee on GNSS has the membership and forum, if not yet the clear mandate, to impose such solutions globally. At the national level, the U.S. Space-Based PNT Executive Committee assisted by its expert advisory panel seems the most likely candidate for this role.
</p>
<div class='pdfclass'><a target='_blank' class='specialpdf' href='http://insidegnss.com/wp-content/uploads/2018/01/sepoct17-THINKING.pdf'>Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/ensuring-pnt-for-all/">Ensuring PNT for All</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How do you use GNSS to compute the attitude of an object?</title>
		<link>https://insidegnss.com/how-do-you-use-gnss-to-compute-the-attitude-of-an-object/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Tue, 19 Sep 2017 17:52:38 +0000</pubDate>
				<category><![CDATA[201708 September/October 2017]]></category>
		<category><![CDATA[Column]]></category>
		<category><![CDATA[Feature]]></category>
		<category><![CDATA[GNSS Solutions]]></category>
		<category><![CDATA[legacy-application]]></category>
		<category><![CDATA[receiver]]></category>
		<guid isPermaLink="false">http://insidegnss.com/2017/09/19/how-do-you-use-gnss-to-compute-the-attitude-of-an-object/</guid>

					<description><![CDATA[<p>Q: How do you use GNSS to compute the attitude of an object? A: GNSS technology is used to support a wide range...</p>
<p>The post <a href="https://insidegnss.com/how-do-you-use-gnss-to-compute-the-attitude-of-an-object/">How do you use GNSS to compute the attitude of an object?</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="special_post_image"><img decoding="async" class="specialimageclass img-thumbnail" src="https://insidegnss.com/wp-content/uploads/2018/01/SolFigs_0.jpg" /></div>
<p><strong>Q: How do you use GNSS to compute the attitude of an object? </strong></p>
<p><span id="more-22936"></span></p>
<p><strong>A: </strong>GNSS technology is used to support a wide range of position, velocity and time applications across numerous platforms. One of the lesser-known applications of GNSS is its ability to determine the attitude, or orientation, of an object. Such systems can be made to be quite small and can yield accurate solutions that operate in virtually any environment in which GNSS satellite visibility is reasonable. The only requirement from a GNSS receiver perspective is that the receiver be able to provide reliable carrier phase measurements.</p>
<p>This article begins with a brief summary of how the attitude of a vehicle is determined and then explains how GNSS can be used. It wraps up with a brief discussion about attainable accuracies.</p>
<p><strong>Attitude Determination </strong><br />
Attitude determination is the process of determining the rotation angles that relate two different coordinate frames. Although any two coordinate frames can be used, we herein consider the rotation between a local-level frame (e.g., North, East, Up or East, North, Down, etc.) and the body frame. The body frame is a frame attached to the object (“body”) whose attitude is desired (an example body frame is given later).</p>
<p>With this in mind, we present the following key relationship</p>
<p><em>r⃗<sup>l</sup></em> = <em>R<sup>l</sup><sub>b</sub></em><em>r⃗<sup>b</sup></em>     <span style="color: #ff0000;"><strong>(1) </strong></span></p>
<p>where <em>r⃗</em> is a vector parameterized in the local-level (superscript <em>l</em>) or body (superscript <em>b</em>) frame and <em>R<sup>l</sup><sub>b</sub></em> is the rotation matrix (or direction cosine matrix) from the body frame to the local-level frame.</p>
<p>The rotation matrix between any two frames can be defined using three consecutive rotations about the three coordinates axes — these are called Euler angles. For the case under consideration, since one of the frames is the local-level frame, the Euler angles can be expressed as familiar roll, pitch and azimuth angles.</p>
<p>To compute the rotation matrix, one needs to know or measure at least two vectors in each coordinate frame. These vectors could be anything including velocity, rotation rates, etc., as long as they are non-collinear (i.e., not parallel). It is possible to use a single vector, but then you cannot determine all three Euler angles; more on this later.</p>
<p><strong>GNSS Attitude System Setup </strong><br />
For GNSS attitude determination systems, the vectors used in equation (1) are <em>relative</em> position vectors. The question, of course, is: where do these come from?</p>
<p>Before answering this question, let’s clarify what constitutes a GNSS attitude system. To determine the full attitude, at least three GNSS receivers are needed. The only other requirement is some software to process the data from these receivers.</p>
<p>Returning to the question that opened this section, the body frame vectors are defined by the location of the receivers (actually the antennas; denoted <em>A</em> ‒ <em>C</em>) on the object whose attitude is desired. Assuming a three-antenna system, a common (if not easy to understand) configuration is to mount the antennas such that two antennas fall along the direction of travel, and the third one is 90 degrees offset. One possible setup is illustrated in <span style="color: #ff0000;"><strong>Figure 1</strong></span> <em>(see inset photo, above right) </em>for the case of a road vehicle.</p>
<p>Once installed, the body frame coordinates are defined by measuring the position of the antennas relative to the coordinate frame of the vehicle. The coordinate frame of the vehicle can be arbitrarily defined but is usually selected such that one axis is along the direction of travel, one lateral to the direction of travel, and the third axis completes on orthogonal frame (e.g., forward, right, down).</p>
<p>As might be expected, these same vectors in the local-level frame are determined from GNSS measurements. Once computed, the rotation matrix between the body and local-level frames can then be determined. Both of these steps are accomplished by the processing software and are discussed in the next section.</p>
<p><strong>Data Processing </strong><br />
As mentioned, the inter-antenna vectors in the local-level frame are computed from GNSS. For an N-antenna system, only N-1 independent vectors need to be solved. Although not required, this is commonly done by selecting one antenna/receiver as the “base” and then computing the vector to each of the other antennas/receivers in the system.</p>
<p>Continuing with the three-receiver example in Figure 1, we select antenna A as the base and compute vectors ray <em>AB</em> and ray <em>BC</em>. Of course, if there are other antennas, the vector from Point <em>A</em> to each point would also be computed.</p>
<p>To be more specific, the inter-receiver vectors are computed using standard differential carrier phase processing. Because the inter-antenna spacing is typically limited to a few meters, the spatially-correlated orbit, ionosphere and troposphere errors are virtually zero. This dramatically simplifies the ambiguity resolution process, since the only errors that need to be handled are multipath, noise and antenna phase center variation, which are generally small, as discussed later.</p>
<p>It is also possible to use the known baseline length between the receivers (as measured in the body frame), or any a priori attitude information to make the ambiguity resolution process even more robust.</p>
<p>Some of you might be wondering why I have not mentioned the requirement for a base station. The reason is precisely because we are estimating relative, not absolute, position vectors. By definition, differential data processing yields a relative position vector. If the location of the base station is known in an absolute sense — this is the most common use of a base station — then the resulting solution of the rover is also absolute.</p>
<p>For attitude determination, absolute location is not important. As such, the location of the base receiver (Point A in the above example) can be computed from a standalone (single point) solution. Even absolute positioning errors of 100 meters (which would be extremely large if the carrier phase data needed for attitude determination is still available) will be buried by the other errors in the system, and thus can be ignored.</p>
<p>The only other effect that might be important here is the timing accuracy of each receiver. As discussed in the March/April 2011 <strong>GNSS Solutions</strong> column, <a href="http://insidegnss.com/gnss-receiver-clocks/">“GNSS Receiver Clocks,”</a> a relative timing error of Δ<em>t</em> between the receivers will result in a relative position error of <em>s </em>· Δ<em>t</em>, where <em>s </em>is the speed of the vehicle. Assuming a timing error of 2 milliseconds (most receivers limit timing errors to ±1 milliseconds) and a vehicle traveling at 100 kilometers per hour, the relative positioning error would be approximately 5.6 centimeters. As discussed below, this would dominate the error budget and would therefore have to be properly accounted for.</p>
<p>The outputs of the GNSS processing are the vectors in the local-level frame; these can be computed directly in that frame or can be computed from vectors in an Earth-Centered Earth-Fixed (ECEF) frame. Mathematically, this is written as</p>
<p><em>r⃗<sup>GNSS </sup>= r⃗<sup>l</sup></em> + <em><em>n⃗<sup>GNSS<br />
</sup>=</em> </em><em><em>R<sup>l</sup><sub>b</sub></em></em><em><em><em>r⃗<sup>b</sup></em></em> + </em><em>n⃗<sup>GNSS</sup></em>     <strong><span style="color: #ff0000;">(2) </span></strong></p>
<p>where <em>r⃗<sup>GNSS</sup></em> is the GNSS-derived vector in the local-level frame, <em>n⃗<sup>GNSS</sup></em> is the measurement noise, and equation (1) was used to get from the first to second line. Equation (2) is written in parametric form and can thus be used as input to any standard least-squares or Kalman filtering estimation algorithm to estimate the Euler angles embedded in <em>R<sup>l</sup><sub>b</sub></em>.</p>
<p><strong>Two-Antenna Systems </strong><br />
Until now, we have only considered systems consisting of three or more receivers in order to estimate the full attitude of an object. However, two-receiver systems can be used to estimate rotations orthogonal to the vector connecting the two antennas.</p>
<p>The most common two-receiver system is one where the two receivers are set up parallel (or orthogonal) to the direction of travel. This allows for estimation of the azimuth and pitch (or roll) of the vehicle; the third angle is unobservable.</p>
<p><strong>Expected Accuracy </strong><br />
As discussed above, the GNSS measurement errors are limited to multipath (2‒3 centimeters), noise (less than 1 millimeter) and phase center variation (1‒2 centimeters or less) (all values quoted as one standard deviation values). Assuming the measurement geometry is reasonable (HDOP ≈ 1 and VDOP ≈ 1.5), the main factor affecting accuracy is the length of the inter-antenna vectors.</p>
<p>To illustrate, let’s consider a two-receiver system with the understanding that there is an analogous relationship for three-plus receiver systems. Specifically, for the setup in <span style="color: #ff0000;"><strong>Figure 2</strong></span> <em>(see inset photo, above right)</em>, for an inter-receiver separation of <em>d</em>, the pitch (ϕ) and azimuth (α) can be computed as</p>
<p><em>(see inset photo, above right for equations)</em></p>
<p>where σ<sub><em>EIN</em></sub> is the North/East relative positioning uncertainty, σ<sub><em>U</em></sub> is the vertical relative positioning accuracy, and <em>d<sub>h</sub></em> is the horizontal distance between the receivers. In other words, the longer the inter-receiver separation the better the attitude accuracy.</p>
<p>To give some numbers, for the lower- end measurement errors and DOP values listed at the start of this section, and nominal horizontal receiver separation of 1 meter, the pitch and azimuth accuracy would be 1.3 and 1.9 degrees, respectively. This is a one-off accuracy estimate and further filtering/ averaging would yield even better performance.</p>
<p><strong>Summary </strong><br />
This article has given an overview of how GNSS can be used to determine the attitude of an object. Although reliant on ambiguity resolution, the short baselines involved make the process quite robust. The result can be highly accurate attitude estimates that can be applied to a wide range of applications.</p>
<div class="pdfclass"><a class="specialpdf" href="http://insidegnss.com/wp-content/uploads/2018/01/sepoct17-SOLUTIONS.pdf" target="_blank" rel="noopener">Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/how-do-you-use-gnss-to-compute-the-attitude-of-an-object/">How do you use GNSS to compute the attitude of an object?</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Fresh Look at GNSS Anti-Jamming</title>
		<link>https://insidegnss.com/a-fresh-look-at-gnss-anti-jamming/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Tue, 19 Sep 2017 17:45:58 +0000</pubDate>
				<category><![CDATA[201708 September/October 2017]]></category>
		<category><![CDATA[Article]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Technical Article]]></category>
		<category><![CDATA[Anti-jamming]]></category>
		<guid isPermaLink="false">http://insidegnss.com/2017/09/19/a-fresh-look-at-gnss-anti-jamming/</guid>

					<description><![CDATA[<p>Equations GNSS is the technology of choice in most applications due to its dedicated infrastructure, Earth coverage, medium to high accuracy, and large...</p>
<p>The post <a href="https://insidegnss.com/a-fresh-look-at-gnss-anti-jamming/">A Fresh Look at GNSS Anti-Jamming</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="special_post_image"><img decoding="async" class="specialimageclass img-thumbnail" src="https://insidegnss.com/wp-content/uploads/2018/01/AntiJamEQ.jpg" /><span class="specialcaption">Equations</span></div>
<p>GNSS is the technology of choice in most applications due to its dedicated infrastructure, Earth coverage, medium to high accuracy, and large market penetration. Most of the applications, including those we download on our smartphones, are in the category of Location Based Services (LBS). However, there are many other services and businesses that rely heavily on GNSS performance and reliability. For instance, Intelligent Transportation Systems (ITS) make extensive use of GNSS technology and this dependence will only grow in the future.<br />
<span id="more-22932"></span><br />
It’s not just that GNSS has become ubiquitous in our daily life, but many critical infrastructures worldwide have some sort of reliance on it. In addition to the already mentioned transportation systems, GNSS plays a significant role in synchronization in the power grid, high frequency trading operations, and synchronization of distant wireless communications towers.</p>
<p>This growing dependence on GNSS within critical (and non-critical) infrastructures has posed some concerns on the potential vulnerabilities of GNSS (see Amin <em>et alia</em>, “Guest Editorial: Vulnerabilities, threats, and authentication in satellite-based navigation systems,” in Additional Resources). As a consequence, there is a need for protecting GNSS against intentional and unintentional interference sources since disruption of GNSS can lead to catastrophic consequences.</p>
<p>The jamming threat, a specific form of intentional interference, is real and its occurrence has been documented in many occasions. Jamming devices are illegal in most (not all) countries, yet they are very easy and cheap to buy. Simple jammers can disrupt GNSS-based services in wide geographical areas (even in several kilometers), a fact that has certainly triggered research into anti-jamming techniques. Not only is jamming a threat, but other sources of unintentional interference can severely compromise GNSS performance.</p>
<p>This article aims at providing a discussion of classical mitigation techniques, while providing links to the field of robust statistics. This link provides a principled way of analyzing existing mitigation techniques, as well as conceiving new methodologies that rely on solid statistical principles. Purposely, we do not discuss interference detection techniques, leaving all the discussion to interference mitigation. Finally, the article introduces Transform Domain (TD) techniques and their robust versions, which are compared against time domain techniques using real data gathered in an experimental test.</p>
<p><strong>The IC Principle </strong><br />
In this article, we are interested in both intentional and unintentional interference and, in either situations, the signal at the receiver antenna can be modeled as</p>
<p><em>y</em>(<em>t</em>) = <em>x<sub>θ</sub></em>(<em>t</em>) + <em>i</em>(<em>t</em>) + <em>w</em>(<em>t</em>) <span style="color: #ff0000;"><span style="color: #000000;">  </span><strong>   (1) </strong></span></p>
<p>where <em>x<sub>θ</sub></em>(<em>t</em>) is the legitimate signal, made of different components coming from the visible GNSS satellites, <em>i</em>(<em>t</em>) represents the interference signal, and <em>w</em>(<em>t</em>) is the random contribution of the thermal noise. Notice that <em>x<sub>θ</sub></em>(<em>t</em>) is parameterized by <em>θ</em>, a vector containing the unknown parameters of the received signals such as their amplitude, time-delay, Doppler-shift, or carrierphase. For the <em>i</em>-th satellite signal, we define the parameters as <em>A<sub>i</sub></em>, <em>τ<sub>i</sub></em>, <em>f<sub>d,i</sub></em>, and <em>φ<sub>i</sub></em> respectively. Roughly speaking, the estimates of <em>θ</em> are used to solve for the position at the receiver side. Most of the <em>commercial</em> jamming devices transmit rather simple periodic signals whose frequency is time-varying, <em>f<sub>I</sub></em>(<em>t</em>). Therefore, a rather simple but general model is</p>
<p><em>i</em>(<em>t</em>) = <em>A<sub>I </sub></em>cos(2<em>π</em>(<em>f<sub>RF</sub></em> + <em>f<sub>I</sub></em>)<em>t + </em><em>φ<sub>I</sub></em>)<strong><span style="color: #ff0000;">     (2) </span></strong></p>
<p>where <em>A<sub>I</sub></em> is the amplitude of the interfering signal, <em>f<sub>RF</sub></em> is the central Radio Frequency (RF), <em>f<sub>I</sub></em>(<em>t</em>) is the time-varying interference frequency, and <em>φ<sub>I</sub></em> represents its phase. Depending on the behavior of <em>f<sub>I</sub></em>(<em>t</em>) different jamming signals can be conceived such as Continuous Wave (CW) jammers when <em>f<sub>I</sub></em>(<em>t</em>) = <em>f<sub>I</sub></em> is a constant, or chirp-like jamming signals when <em>f<sub>I</sub></em>(<em>t</em>) evolves over time following a saw-tooth pattern. Intuitively, the faster the variability and transitions of <em>f<sub>I</sub></em>(<em>t</em>), the harder it is to mitigate interference at the receiver side. At the receiver, we are interested in digital signal processing methods to counteract interferences, therefore we assume that <em>y</em>(<em>t</em>) is sampled at a rate (<em>f<sub>s</sub></em> = 1/<em>T<sub>s</sub></em>) satisfying the Nyquist criterion to yield its discrete-time version:</p>
<p><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #000000;"><em><em>y</em></em></span></span><span style="color: #ff0000;"><span style="color: #000000;"><em><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>]</span></span> = x<sub>θ</sub></em></span></span><span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>]</span></span> + </span></span></span><em>i</em><span style="color: #000000;"><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>]</span></span> </span></span></span>+ <span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #000000;"><em>w</em>[<em>n</em>]  </span></span><strong>   </strong></span><strong><span style="color: #ff0000;">(3)</span></strong></p>
<p>A common approach to interference mitigation is to formulate it, statistically speaking, as an estimation problem. After detecting the interference, the set of unknown parameters characterizing the interfering signal needs to be estimated to enable Interference Cancellation (IC) at the receiver. A reconstructed version of the interference term,<em> î</em>[<em>n</em>], is subtracted from the observations such that a<em> clean</em> signal version is used afterwards by the receiver, <em>ỹ</em>[<em>n</em>] = <em>y</em>[<em>n</em>] &#8211; <em>î</em>[<em>n</em>]. The principle is depicted in <a href="http://insidegnss.com/figures-1-2-3-4-a-fresh-look-at-gnss-anti-jamming/"><strong>Figure 1</strong></a>.</p>
<p>In the context of the standard operations of a GNSS receiver, IC can be better understood as the modification of the objective function in acquisition and tracking. Typically, GNSS receivers estimate the parameters of the received signals using a variety of methods that implement a Least Squares (LS) solution, where the input samples are compared with locally generated signal replicas. In particular, code delay, Doppler frequency and carrier phase are estimated as:</p>
<p>Equation<span style="color: #ff0000;"> (4)</span> <em>(see inset photo, above right, for equations)</em><br />
<em><br />
Equation <span style="color: #ff0000;">(5)</span></em></p>
<p>Notice that the subindex <em>i</em> denoting the satellite signal is hereafter omitted since we consider independent acquisition/tracking among satellites. <em>c</em>(·) denotes the spreading sequence for the satellite of interest and<em> N</em> the total number of samples used in the process. Cost function (5) can be minimized independently from <em>A</em> which can be estimated in a separate step. For this reason, the determination of <em>A</em> is not explicitly indicated in (4). In particular, it is possible to show that the minimization of (5) is equivalent to the maximization of the absolute value of the Cross-Ambiguity Function (CAF) defined as</p>
<p><em>Equation <span style="color: #ff0000;">(6)  </span></em></p>
<p>In the IC case, the cost function is modified after gaining knowledge of the interference. More precisely, the signal model is extended in order to account for the interference term and the cost function is rewritten as</p>
<p><em>Equation <span style="color: #ff0000;">(7) </span></em></p>
<p>where <em>î</em>[<em>n</em>] is the reconstructed version of the interference, which requires detection and estimation as for Figure 1.</p>
<p>Using these definitions, the main IC techniques can be defined. For instance, a popular method for pulsed interference mitigation, due its simplicity, is pulse blanking (see article by Borio, 2016, Additional Resources). At a glance, pulse blanking detects the presence of interference by identifying abnormally large values in the pre-correlation samples. This can be easily achieved by comparing |<em>y</em>[<em>n</em>]| to a predefined threshold <em>T</em><sub>PB</sub>. Then, the interfered samples are set to zero such that they are not used throughout the receiver. Mathematically, the estimated interference is</p>
<p><em>Equation <span style="color: #ff0000;">(8) </span></em></p>
<p>which can be plugged in cost function (7) to understand how pulse blanking operates.</p>
<p><strong>Robust Estimation </strong><br />
When the IC principle is used, the interfering term is treated as a signal component whose parameters should be estimated. A different approach for the design of interference mitigation techniques can be derived from the theory of robust statistics (see, for example, Huber and Ronchetti, Additional Resources). In this case, the receiver does not try to estimate the jamming signal but adopts processing strategies which can produce reasonable results even in the presence of interference.</p>
<p>The term “robust” is often used in the literal sense, in many cases just according to the definition provided by the dictionary. This has often generated confusion and algorithms defined as “robust” are not actually “statistically robust”. Robustness has to be intended here as a mathematical property of a system and can be assessed using rigorous criteria. An analogy can be made with the concept of Bounded Input Bounded Output (BIBO) stability: a system is BIBO stable if a bounded output is obtained for every bounded input. In a similar way, <em>Qualitative Robustness</em> states that a robust estimator is such that bounded departures from the assumed model do not cause it to provide aberrant results (see Hampel in Additional Resources). For instance, if an estimator assumes a Gaussian model for the observations, but outliers — which break the Gaussian assumption — are received and used, we expect the estimator to be relatively insensitive to them if claimed to be robust. For location estimators of the type</p>
<p><em>Equation <span style="color: #ff0000;">(9) </span></em></p>
<p>i.e. that depend on a linear combination of input samples, <em>y</em>[<em>n</em>], processed by the non-linearity, <em>ρ</em>(·), robustness is obtained when <em>ρ</em>(·) is bounded. When pulse blanking is used, the CAF of the input samples is computed as:</p>
<p><em>Equation <span style="color: #ff0000;">(10) </span></em></p>
<p>where, in accordance to (8), the non-linearity is</p>
<p><em>Equation <span style="color: #ff0000;">(11) </span></em></p>
<p>is clearly a bounded function of the input samples. In this way, pulse blanking is not only a form of IC but is also a robust estimator for the CAF.</p>
<p>Although techniques implementing the IC principle can be robust, robust statistics provides, in general, a shift in the design paradigm for interference/jamming mitigation techniques. In particular, the focus is no longer in the definition of the most appropriate model for the interfering term, <em>i(t)</em>, but on the search for robust procedures that allow the estimators to combat <em>i(t)</em> without actually estimating (or even detecting) it. A possible design strategy is to reformulate model (3) as</p>
<p><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #ff0000;"><span style="color: #000000;"><em><em>y</em></em></span></span><span style="color: #ff0000;"><span style="color: #000000;"><em><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>]</span></span> = x<sub>θ</sub></em></span></span><span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>]</span></span> + </span></span></span></span><em>w′</em><span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>]</span></span></span></span></span><span style="color: #ff0000;"><span style="color: #000000;">     </span></span></span><strong><span style="color: #ff0000;">(12)</span></strong></p>
<p>where interference and noise are grouped together, with</p>
<p><em>w′</em><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>] =</span></span></span></span></span></span> <em>i</em><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>] + </span></span></span></span></span></span><em>w</em><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #000000;"><span style="color: #ff0000;"><span style="color: #ff0000;"><span style="color: #000000;">[<em>n</em>]</span></span></span></span></span></span></p>
<p>In the robust estimation framework the goal is to adopt models for the aggregate term, <em>w′</em>{<em>n</em>}, which lead to robust estimators. In robust statistics, a model is considered as well, but its statistical assumptions are relaxed such that the estimators have some flexibility to process outlier measurements, which otherwise would make non-robust estimators diverge. In this respect, there exist several noise models which lead to robust estimators in classical robust statistical problems. It turns out that these models are also effective in the context of jamming mitigation in GNSS receivers. These models, which mainly characterize the statistics of <em>w′</em>{<em>n</em>}, include:</p>
<ul>
<li><span style="color: #993300;"><strong>Laplacian model:</strong></span> the aggregate noise term is assumed to follow a Laplace distribution.</li>
<li><strong><span style="color: #993300;">Cauchy model:</span></strong> the aggregate noise term is assumed to follow a Cauchy distribution.</li>
<li><strong><span style="color: #993300;">Student’s t model:</span></strong> the aggregate noise term is assumed to follow a t-distribution.</li>
</ul>
<p>Other noise models could be considered for the design of different jamming mitigation techniques. Notice that, typically these distributions exhibit heavy-tail behavior, as opposite to the standard Gaussian assumption. From the aggregate noise model, robust mitigation techniques are finally obtained. We recently considered (see the paper presented by one of the authors at the <em>2017 European Navigation Conference</em> and listed in Additional Resources):</p>
<ul>
<li>The usage of <strong>Zero-Memory Non-Linear (ZMNL)</strong> functions to pre-process the input samples.</li>
<li><strong>Non-linear correlators</strong> based, for example, on the median (which results from the Laplace noise assumption) and on the sample myriad (from the assumption of Cauchy noise).</li>
</ul>
<p>The sample myriad is a location estimator, as the mean and the median, and it is defined, for real input samples, as</p>
<p><em>Equation <span style="color: #ff0000;">(13) </span></em></p>
<p>where <em>K</em> is the linearity parameter of the Cauchy distribution (this is better explained in the following). A clear parallelism with the sample mean can be made: the mean is the argument which minimizes the sum of squares of the residuals, <em>y</em>[<em>n</em>]-<em>μ</em>. Additional details on the sample myriad can be found, for example, in the book by G. R. Arce listed in Additional Resources.</p>
<p>ZMNL functions can be directly obtained from the aggregate noise model as</p>
<p><em>ρ</em>(<em>y</em>[<em>n</em>]) = –log <em>f</em>(<em>y</em>[<em>n</em>])<strong>     </strong><span style="color: #ff0000;"><strong>(14) </strong></span></p>
<p>where <em>f</em>(<em>y</em>) is the probability density function (pdf) adopted to describe <em>w′</em>{<em>n</em>}. In this case, alternative versions of (10) are obtained by replacing <em>ρ</em><sub>PB</sub>(·) with <em>ρ</em>(·). In the ZMNL function case, the input samples are simply pre-processed using <em>ρ</em>(·) before being used by the standard correlator blocks. In this way, a robust CAF similar to (10) is obtained. In the second approach, it is recognized that the CAF is a weighted mean. The mean is inherently non-robust and thus, it can be replaced by robust operators such as the median and the myriad. For example, in the median case, the CAF in (6) becomes:</p>
<p><em>C<sub>R</sub></em>(<em>τ</em>,<em>f<sub>d</sub></em>) = MEDIAN(<em>y</em>[<em>n</em>]<em>c</em>(<em>nT<sub>s</sub></em> – <em>τ</em>)<em>e</em><sup>–<em>j2</em><em>πf</em><em><sub>d</sub>nT<sub>s</sub></em></sup>|<em>n</em>=0,1,&#8230;,<em>N</em> – 1).<strong>     <span style="color: #ff0000;">(15) </span></strong></p>
<p>Note that the samples at the input of the MEDIAN operator in (15) are complex. In this case, it is assumed that two independent medians are computed on the real and imaginary parts of the samples. These approaches introduce significant robustness in the case of pulsed jamming and allow receiver operations even in the close proximity of a jammer.</p>
<p><strong>Time, Frequency, Scale and All the Others </strong><br />
By representing the input samples in a different domain, an advanced class of interference mitigation techniques arises. A classic example is the usage of the Discrete Fourier Transform (DFT) and its fast implementation, the Fast Fourier Transform (FFT), to project the input samples, <em>y</em>[<em>n</em>], into the frequency domain. In this way, a new set of samples, <em>Y</em>(<em>k</em>), is obtained. Here, the index, <em>k</em>, is used to denote the set of discrete frequencies. The rationale of operating in a different domain is that, in such domain, the interfering term, <em>i</em>[<em>n</em>], admits a<em> sparse representation</em>. This implies that, <em>I(k)</em>, the TD representation of <em>i</em>[<em>n</em>], is significantly different from zero only for a relatively small number of values of <em>k</em>. <em>I(k)</em> will thus appear as a set of pulses which can be easily<em> blanked</em> in the TD.</p>
<p>Depending on the domain of the transformation, it is possible to classify the different interference mitigation techniques as in <a href="http://insidegnss.com/figures-1-2-3-4-a-fresh-look-at-gnss-anti-jamming/"><strong>Figure 2</strong></a>. The figure also takes into account the receiver stages where the techniques are actually implemented. In particular, interference mitigation techniques are classified according to their implementation with respect to the correlation operation as</p>
<ul>
<li><span style="color: #993300;"><strong>Pre-correlation: </strong></span>the algorithm operates before the correlation process takes place. In this way, mitigation is performed for all the processing channels at once and the characteristics of the useful received signals are not taken into account.</li>
<li><strong><span style="color: #993300;">In-correlation:</span></strong> mitigation is performed by modifying the standard correlation process.</li>
<li><strong><span style="color: #993300;">Post-correlation: </span></strong>mitigation is applied at the output of the correlators. In this case, different processing can be applied to the signals from different channels.</li>
</ul>
<p>Time domain techniques are those that do not require a preliminary transformation to bring the input samples in a different domain. In this respect, adaptive notch filtering and pulse blanking are time domain techniques commonly used for interference mitigation, both implementing the IC principle. Adaptive notch filtering is an effective technique where the instantaneous frequency of the jamming signal is continuously estimated. The region of the spectrum occupied by the jamming signal is then removed through filtering. Although notch filtering performs the excision of a narrow frequency band, it is implemented using a recurrence equation in the time domain and thus it does not require a signal transformation. Alternative classifications can be adopted. Pulse blanking can be seen as a robust technique (as discussed earlier), whereas notch filtering is very sensitive to model mismatches. The notch filter can only operate if the interfering signal is instantaneously narrowband and if its center frequency is slowly varying with time. Other examples of time domain approaches used for interference mitigation are the usage of ZMNL functions, as described above, and the adoption of a Kalman Filter (see Mitch <em>et alia</em> in Additional Resources) to track and reconstruct the jamming signal. This latter approach is, in general, non-robust and sensitive to deviations from the model adopted for the design of the Kalman Filter.</p>
<p>Time domain pre-correlation techniques are, in general, low-complexity and approaches such as pulse blanking and notch filtering are now commonly implemented in professional and mass-market receivers. Time domain processing can be integrated with the correlator and, for example, robust correlators discussed in the previous section can be adopted. The complexity depends on the approach adopted. The median can be implemented in a quite efficient way and its complexity is comparable with that of the mean performed in standard correlators. The computation of the sample myriad requires an iterative procedure which can be computationally expensive.</p>
<p>Post-correlation mitigation techniques are not explicitly indicated in Figure 2. Techniques operating at this stage tend to be “mixed” in the sense that post-correlation information is used to drive pre-correlation processing. Moreover, after correlation, the input samples are significantly down-sampled and, for this reason, adoption of different domains is usually not considered. Remarkably, post-correlation techniques are typically ineffective in terms of jamming suppression, the main reason being that correlation with the local code causes a spread out of the (uncorrelated) interference, which makes it harder to be mitigated. Degradations in post-correlation products, such as the estimated Carrier-to- Noise power spectral density ratio (C/N<sub>0</sub>), can, however, be exploited for jamming detection.</p>
<p>In TD approaches, considered in the bottom row of Figure 2, the input signal, <em>y</em>[<em>n</em>], is projected into a different domain in the first place. These domains include frequency, with the usage of the DFT/FFT; joint time-frequency representations based, for example, on the Short Time Fourier Transform (STFT) or on the Wigner- Ville distribution; and joint timescale representations based on the Discrete Wavelet Transform (DWT). The Karhunen-Loeve Transform (KLT) has also been considered as a possible tool to obtain TD representations of the received GNSS signal, <em>y</em>[<em>n</em>]. Once in the TD, it is possible to apply techniques similar to those adopted in the time domain. TD excision is probably the most commonly adopted approach and it operates in a way analog to pulse blanking. If the absolute value of a sample in the TD is larger than a threshold, it is blanked and set to zero. Robust techniques can be also implemented in the TD, both at the pre- and in-correlation level. This topic is discussed in more detail in the next section. Although TD techniques are usually computationally demanding, several high-end professional receivers implement FFT-based algorithms and are able to perform interference detection and mitigation in the frequency domain.</p>
<p>In hybrid approaches the complexity of TD techniques is reduced using, for example, a bank of filters. The time domain signal is not transformed but split into several streams. Each stream is obtained using a separate filter which captures the content of the original signal on a specific frequency sub-band. This is a hybrid approach in the sense that each stream is a time domain representation of the frequency content of the original signal on a specific sub-band. Here, we referred to “frequency”, but other representation domains such as scale can be adopted for the design of the filter bank used for the signal decomposition. Approaches such as pulse blanking and the usage of ZMNL functions can then be implemented on the individual streams.</p>
<p>Finally, we would like to comment on spatial domain techniques, which can be used complementarily to the previously mentioned approaches. In this case, the time domain signal is not explicitly transformed but, instead, the signal is recorded using a multi-antenna receiver, which confers it with spatial discrimination capabilities. Conceptually, one can point to desired directions-of-arrival, while nulling the radiation pattern of the antenna at directions where an interference is detected. A detailed discussion is out of the scope of this article, but it suffices to say that pre- and postcorrelation techniques can be considered. Beamforming design can follow a plethora of options, being classified into temporal-, spatial-, or hybrid-reference beamforming techniques depending on the knowledge assumed for the desired and interfering signals. Typically, array processing techniques involve demanding computational resources and precise hardware designs.</p>
<p>Some general considerations on the properties of interference mitigation techniques are provided in <a href="http://insidegnss.com/figures-1-2-3-4-a-fresh-look-at-gnss-anti-jamming/"><strong>Figure 3</strong></a>. In particular, the impact of model specification is analyzed. Strong model specifications reduce, in general, the flexibility and robustness of estimation methods to cope with (non-nominal) interference situations. This is the case of adaptive notch filters which can only deal with frequency modulated signals with slowly varying central frequencies. On the other hand, precise model specifications can significantly reduce the computational complexity of the technique and lead to optimal performance when the design conditions are met. For instance, notch filtering is computationally efficient and achieves performance comparable to that of TD techniques when dealing, for example, with CW interference.</p>
<p>TD techniques usually make only weak assumptions on the interference model. In particular, the underlying assumption is that the interfering signal admits a sparse representation in the TD. This corresponds to assuming that the interfering signals can be effectively described by a linear combination of few functions from a basis of the TD. For example, when the FFT/DFT is adopted, it is implicitly assumed that the interfering signal can be effectively described as the linear combination of few complex sinusoids. In general, weak assumptions on the interference model lead to flexible techniques which can operate in a wide range of conditions.</p>
<p>As a general principle, the increase of computational load should yield to performance improvements. When this improvement does not occur or it is limited, the mitigation technique should be re-considered. This phenomenon may occur for example when considering new TDs: the computational load of the transform required to project the input signal in the new TD might not be justified by the improvement of performance, for example, with respect to other TD techniques which can be implemented using fast algorithms such as the FFT.</p>
<p><strong>Robust TD Approaches </strong><br />
Finally, we consider a new class of TD approaches which is based on the usage of ZMNL functions in the TD. More specifically, we assume that a linear transform, such as the DFT and the DWT, has been applied to the input signal and that the following TD samples have been obtained:</p>
<p><em>Y</em>(<em>k</em>) = <em>X</em><span style="color: #ff0000;"><span style="color: #ff0000;"><span style="color: #000000;"><em><sub>θ</sub></em></span></span></span>(<em>k</em>) + <em>I</em>(<em>k</em>) + <em>W</em>(<em>k</em>) = <em>X</em><span style="color: #ff0000;"><span style="color: #ff0000;"><span style="color: #000000;"><em><sub>θ</sub></em></span></span></span>(<em>k</em>) + <em>W′</em>(<em>k</em>)     <span style="color: #ff0000;"><strong>(16) </strong></span></p>
<p>Since linear transforms are used, the superposition principle applies and the different components in (12) have a corresponding term in (16). In particular, it is possible to identify the useful signal components, the interference term and the noise term. In this approach, we propose to model the received signal directly in the TD rather than in the time domain. In particular, we focus on different noise models for the aggregate TD noise term, <em>W′</em>(<em>k</em>). As discussed in the section on robust estimation, the model does not need to be accurate but should be selected in order to obtain robustness. In other words, in robust statistics, optimality is sacrificed in favor of robustness. In this case, we considered two non-Gaussian noise models: the complex Laplace and the complex Cauchy distributions for <em>W′</em>(<em>k</em>).</p>
<p>Following an approach similar to that developed for the time domain (see article by Borio, 2017, in Additional Resources), robust TD interference mitigation techniques can be obtained by processing the TD samples using a ZMNL function. <strong><a href="http://insidegnss.com/figures-1-2-3-4-a-fresh-look-at-gnss-anti-jamming/">Figure 4</a><a href="http://insidegnss.com/figures-1-2-3-4-a-fresh-look-at-gnss-anti-jamming/">.a</a></strong> provides a schematic representation of TD approaches implemented at the pre-correlation level. The input samples are projected into the TD, processed and used to reconstruct a clean version of the time domain input signal, <em>y′</em>[<em>n</em>]. In the approach proposed here, the processed samples, <em>Y′</em>(<em>k</em>), are given by</p>
<p><em>Y′</em>(<em>k</em>) = <em>ρ</em>(<em>Y</em>(<em>k</em>))     <strong><span style="color: #ff0000;">(17) </span></strong></p>
<p>where <em>ρ</em>(·) is the non-linearity defined by (14). In this case, <em>f</em>(<em>y</em>) has to be interpreted as the pdf of the aggregate noise in the TD. If a Laplacian model is adopted, the following non-linearity is obtained:</p>
<p><em>Equation <span style="color: #ff0000;">(18) </span></em></p>
<p>This implies that the TD components of the input signal are normalized by their amplitude and only the phase information is retained. Eq. (18) leads to a normalization of the different TD components: when frequency is considered, the spectrum of the output signal, <em>Y′</em>(<em>k</em>), has a constant unit amplitude. In this respect, the ZMNL function defined by (18) acts as a Zero-Forcing (ZF) equalizer. In common ZF equalizer implementations, however, several time samples are used to estimate the signal spectrum and determine the impulse response of the equalizer. In this case, a direct normalization is implemented in the TD. This, apparently simple processing, provides the receiver with remarkable interference mitigation capabilities.</p>
<p>Alternatively, if a Cauchy model is considered, the following processed signal is obtained:</p>
<p><em>Equation <span style="color: #ff0000;">(19) </span></em></p>
<p>where <em>K</em> is the<em> linearity parameter</em> introduced in the robust estimation section when defining the sample myriad. This name is justified by the fact that <em>K</em> controls the “linearity” of (19): as<em> K</em> goes to infinity, non-linearity (19) becomes the identity. <em>K</em> should be set as a function of the variance of the non-interfered input noise. The determination of <em>K</em> is out of the scope of this paper.</p>
<p><strong><a href="http://insidegnss.com/figures-1-2-3-4-a-fresh-look-at-gnss-anti-jamming/">Figure 4.b</a></strong> shows the in-correlator implementation of the TD processing. In particular, due to the Plancherel theorem, it is possible to show that unitary transforms preserve the scalar product and correlation operations. Examples of unitary transforms are the DFT and DWT (when properly scaled). In these cases, it is possible to compute the correlator directly in the TD. In some cases, this design choice allows significant computational load reduction. A well-known approach is, for example, the parallel code acquisition algorithm based on the usage of the FFT. In the parallel code acquisition algorithm, the FFT is already used for the computation of the correlators: the usage of nonlinearities in the frequency domain can be efficiently adopted without requiring additional operations.</p>
<p>A schematic representation of the parallel code acquisition algorithm is shown <a href="http://insidegnss.com/figures-5-6-7-8-a-fresh-look-at-gnss-anti-jamming/"><strong>Figure 5</strong></a>. As already mentioned, the algorithm foresees the transposition in the frequency domain of the input signal, <em>y</em>[<em>n</em>], thus it can be easily modified by introducing an additional processing block. This block is the light green box labelled “Additional Processing” in Figure 5. This block simply implements the ZMNL functions in Eqs. (18) and (19). In this case, robustness can be introduced with limited additional computational requirements.</p>
<p>In order to demonstrate the effectiveness of RTD approaches, we used the data available <strong>here</strong> and previously used to evaluate the behavior of an adaptive notch filter. The data contain a short dataset with GNSS data affected by jamming. In the archive, basic code allowing the acquisition of the GNSS signals present in the dataset is also provided. Without interference mitigation, it is not possible to detect the useful signal and the CAF shown in <a href="http://insidegnss.com/figures-5-6-7-8-a-fresh-look-at-gnss-anti-jamming/"><strong>Figure 6</strong></a> is obtained. Secondary peaks caused by the jamming signal are clearly present. RTD has been implemented by modifying the parallel code acquisition algorithm as indicated in Figure 5. Parallel code acquisition is implemented in the “DftParallelCodePhaseAcquisition.m” Matlab function and it is included in the archive indicated above.</p>
<p>Significant robustness can be introduced by adding a single line of code which implements normalization (18). We invite the readers to experiment with the code and add the following line of code</p>
<p>X = X ./ ( abs( X ) );</p>
<p>in the “DftParallelCodePhaseAcquisition.m” script. This line should be inserted in the “for” loop, before the computation of the inverse IFFT. With this modification, the impact of jamming is significantly reduced and it is possible to effectively acquire the useful GNSS signal. In particular, the CAF shown in <a href="http://insidegnss.com/figures-5-6-7-8-a-fresh-look-at-gnss-anti-jamming/"><strong>Figure 7</strong></a> is obtained: the signal peak clearly emerges from the noise floor and the secondary peaks due to the jamming signal are strongly attenuated.</p>
<p>The effectiveness of the proposed approach is further analyzed in <a href="http://insidegnss.com/figures-5-6-7-8-a-fresh-look-at-gnss-anti-jamming/"><strong>Figure 8</strong></a> which shows the C/N<sub>0</sub> estimated for a signal affected by jamming under different conditions. In this experiment, the jammer was connected to a variable attenuator. The attenuation was progressively reduced leading to an increasing jamming power. In particular, the received jamming power was increased with steps of 2 decibels. This fact is reflected by the C/N<sub>0</sub> values shown in Figure 8. After 1,200 seconds, the attenuation reaches its minimum value before being increased again. TD processing was implemented using the architecture depicted in Figure 4a and non-linearity (18) was adopted. TD processing significantly outperforms the notch filter used in Figure 8 for comparison. More specifically, a gain of more than 5 decibels is achieved for strong jamming signals. The considered notch filter implements interference detection and it is activated only when significant jamming power is sensed.</p>
<p><strong>Conclusions and the Future of (Anti-) Jamming </strong><br />
Interference mitigation, in the context of GNSS receiver design, has been an active topic for research for several lustrums. It is likely to keep its good pace towards securing GNSS receivers — and the growing list of facilities and infrastructures depending on GNSS — from malicious jamming or unintentional interference. The field has indeed made substantial progress, mainly leveraging on advanced signal processing techniques. In this article we have covered <em>classical</em> time domain methods, but also discussed TD techniques that exploit sparsity of interference in other domains besides time. Additionally, the use of robust statistics was seen to provide interesting results and is a way forward for research. Anti-jamming is advancing, so are the capabilities of jammers to cause damage to GNSS receivers. Besides spoofing — which is probably one of the most complicated interference signals to generate — and jamming — probably the simplest — there is a middle ground. For instance, <em>deceptive jamming</em>, where a simple pulsed-jamming signal is disciplined to target specific parts of the navigation message. It was shown (see Curran<em> et alia</em>, “On the Threat of Systematic Jamming of GNSS”, Additional Resources) that deceptive jamming is not only feasible, but hardly detectable. It is foreseen that this, and other threats, will spur research in the area of antijamming.</p>
<p><span style="color: #993300;"><strong>Additional Resources </strong></span><strong><span style="color: #ff0000;"><br />
[1]</span></strong> Amin, M. G., P. Closas, A. Broumandan, J. Volakis, “Guest Editorial: Vulnerabilities, threats, and authentication in satellite-based navigation systems,” <em>Proceedings of the IEEE</em>, 104(6), pp. 1302-1317, 2016. <strong><span style="color: #ff0000;"><br />
[2] </span></strong>Amin, M. G., X. Wang, Y.D. Zhang, F. Ahmad, and E. Aboutanios, “Sparse arrays and sampling for interference mitigation and DOA estimation in GNSS,” <em>Proceedings of the IEEE</em>, 104(6), pp. 1169-1173, 2016. <strong><span style="color: #ff0000;"><br />
[3]</span></strong> Arce, G. R., <em>Nonlinear Signal Processing: A Statistical Approach</em>. Wiley-Interscience, Nov. 2004. <strong><span style="color: #ff0000;"><br />
[4] </span></strong>Borio, D., “Swept GNSS Jamming Mitigation through Pulse Blanking” <em>Proc. of the 2016 European Navigation Conference (ENC)</em>, Helsinki, Finland, June 2016, pp. 1-8. <strong><span style="color: #ff0000;"><br />
[5]</span></strong> Borio, D., “Robust Signal Processing for GNSS,” <em>Proc. of the 2017 European Navigation Conference (ENC)</em>, Lausanne, Switzerland, May 2017, pp. 150- 158. <strong><span style="color: #ff0000;"><br />
[6]</span></strong> Curran, J. T., M. Bavaro, P. Closas, M. Navarro, “On the Threat of Systematic Jamming of GNSS,” <em>Proceedings of the 29th International Technical Meeting of The Satellite Division of the Institute of Navigation (ION GNSS+ 2016)</em>, Portland, OR, September 2016. <strong><span style="color: #ff0000;"><br />
[7]</span></strong> Fernández-Prades, C., J. Arribas, P. Closas, “Robust GNSS receivers by array signal processing: theory and implementation,” <em>Proceedings of the IEEE</em>, 104(6), pp.1207-1220, 2016. <strong><span style="color: #ff0000;"><br />
[8] </span></strong>Hampel, F. R., “A general definition of qualitative robustness,” <em>The Annals of Mathematical Statistics</em>, vol. 42, pp. 1887-1896, 1971. <span style="color: #ff0000;"><strong><br />
[9] </strong></span>Huber, P. J., and E. M. Ronchetti,<em> “Robust Statistics,”</em> Wiley, second edition, February 2009.</p>
<div class="pdfclass"><a class="specialpdf" href="http://insidegnss.com/wp-content/uploads/2018/04/sepoct17-BORIO_0.pdf" target="_blank" rel="noopener">Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/a-fresh-look-at-gnss-anti-jamming/">A Fresh Look at GNSS Anti-Jamming</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Systemic Jamming</title>
		<link>https://insidegnss.com/systemic-jamming/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Tue, 19 Sep 2017 17:43:24 +0000</pubDate>
				<category><![CDATA[201708 September/October 2017]]></category>
		<category><![CDATA[Cover Story]]></category>
		<category><![CDATA[jamming]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[systemic jamming]]></category>
		<guid isPermaLink="false">http://insidegnss.com/2017/09/19/systemic-jamming/</guid>

					<description><![CDATA[<p>The vulnerability of GNSS to various forms of malicious interference have been widely discussed in recent years...</p>
<p>The post <a href="https://insidegnss.com/systemic-jamming/">Systemic Jamming</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class='special_post_image'><img class='specialimageclass img-thumbnail' src='https://insidegnss.com/wp-content/uploads/2018/01/CoverFigs.jpg' ><span class='specialcaption'>Figures 1 &#8211; 8, Tables 1 &#038; 2, Equation 3</span></div>
<p>
The vulnerability of GNSS to various forms of malicious interference have been widely discussed in recent years, and have considered a wide range of both real and potential attacks. Some of these have included extensive studies of commercially available jamming devices, while others have considered the more comprehensive case of spoofing, where the interference takes the form of genuine GNSS signals (For details, see papers listed in Additional Resources, including M. G. Amin <em>et alia</em>).
</p>
<p><span id="more-22930"></span></p>
<p>
The vulnerability of GNSS to various forms of malicious interference have been widely discussed in recent years, and have considered a wide range of both real and potential attacks. Some of these have included extensive studies of commercially available jamming devices, while others have considered the more comprehensive case of spoofing, where the interference takes the form of genuine GNSS signals (For details, see papers listed in Additional Resources, including M. G. Amin <em>et alia</em>).
</p>
<p>
Studies of simple jamming attacks have demonstrated that it is relatively easy, given sufficient broadcast power, to deny the use of GNSS to many commercial receivers (For details, see papers listed in Additional Resources, including M. Johnson and R. Erlandson). However, it has also been shown that given the easily identifiable or periodic nature of simple jamming signals, a receiver can often mitigate the threat, for example, via the use of adaptive filtering or pulse blanking (F. Dovis, Additional Resources). Furthermore, it has been demonstrated that the jamming signal itself can be readily exploited to identify and locate the jamming source. On the other hand, recent work on GNSS spoofing has shown that current receivers are vulnerable to a well calibrated spoofing attack (T. E. Humphreys, <em>et alia</em>), and it is clear that many receivers can be manipulated without arousing any suspicion. However, such attacks are highly complicated and require knowledge of the GNSS signals, and the attack scenario, including precise timing and positioning.
</p>
<p>
It is highlighted here that a middle ground exists between the simple jammer and the spoofer, and it is the most likely “next step” for the malicious adversary. A typical jammer is blind to the GNSS signals it overwhelms, and simply relies on power and spectral occupation to deny the GNSS signals. In contrast, a spoofing device must faithfully replicate the characteristics of genuine GNSS signals. As such, spoofing is highly sensitive to alignment of time, phase and power of the spoofing signals with respect to the genuine signals. It is suggested that it is possible to create a device, only slightly more complex than a simple jammer, that can increase the efficiency of a jamming-based denial-of-service (DOS) attack.
</p>
<p>
Specifically, this work introduces the concept of systematic jamming: where a simple jammer might be combined with information of the GNSS signals to produce a more sophisticated jamming signal. For example, a jammer may be equipped with a simple low-cost commercial GNSS receiver, providing accurate position, time and satellite ephemerides. With this information, it might be possible to trigger short and sparse bursts of interference, such as to deny GNSS to a nearby receiver with a very low average power. In this manner, a receiver might be unable to: reliably detect that a jamming attack was ongoing; to effectively mitigate the jamming attack; or to identify or localize the jamming source. In the work that follows, we consider what form such a jammer might take, what the implications for the nearby target receiver might be, and how a target receiver might be equipped to thwart such an attack.
</p>
<p>
The basic principle is that for standalone GNSS, the position, velocity and time (PVT) can be denied by either: denying the physical layer, on which the ranging measurements are made; or by denying the data layer, prohibiting the recovery of ephemeris or transmit time; or both. Because the data layer need only be sporadically interrupted to completely deny the message recovery, it represents the weakest link in the PVT generation. It is therefore the obvious target, particularly when channel coding is not present in the jammed signal.
</p>
<p>
<strong>Problem Definition </strong><br />
This work considers the threat that might be posed if a malicious adversary were to add a small amount of added complexity to the typical GNSS jammer, with the intention of providing bursts of interference at specific epochs. A modification to the typical GNSS jammer is envisaged, which includes an on/ off keying driven by a micro-controller, as depicted in <span style="color: #ff0000"><strong>Figure 1</strong><em><span style="color: #000000"> (for all figures, tables and equations, please see inset photo, above right)</span></em></span>. The algorithm controlling the keying employs position and timing information sourced from a simple, low-cost GNSS consumer-grade receiver (naturally, care must be taken to avoid self-interference). Using the GNSS measurements, accurate estimates of the transmit-time observed on GNSS signals seen in the vicinity of the jammer can be computed.
</p>
<p>
It is proposed that this information might be exploited by an adversary to trigger short pulses of interference which are tightly aligned with specific portions of the navigation message of each satellite. Previous work has demonstrated that a low duty-cycle pulsed interference, appropriately synchronized with the navigation message, can cause disruption to the receiver data recovery process, equivalent to that of an always-on interference (J. Curran <em>et alia</em>, Additional Resources). This process requires that the pulse pattern be designed to specifically target weaknesses in the navigation message coding scheme, and it has been shown that a malicious adversary might inflict a DOS upon a naïve receiver, using an average interference power 10 to 20 decibels lower than continuous interference.
</p>
<p>
Naturally, this offers some distinct advantages to the adversary: a given broadcast power might impose a DOS over a wider geographical area; by broadcasting short sporadic bursts of interference, it may be more difficult for an authority to detect or locate the jamming source; it may also be possible that the interference pattern can be made sufficiently sparse that the target receiver, although experiencing a DOS, might not reliably assert that it is experiencing interference.
</p>
<p>
Here, the current Galileo E1BC and GPS L1C/A signals are studied, seeking to identify how the adversary might target these signals, and will then analyze to what extent a DOS might be conducted.
</p>
<p>
<strong>Systematic Interference and Denial of Service Attacks</strong><br />
The methodology chosen for the generation of harmful pulse-patterns is based on denying navigation capability of the receiver, rather than denying the signal itself. To produce a PVT solution, a receiver generally needs to extract the ephemeris from each satellite and the time-of-week (TOW) from at least one satellite. This work examined the design of interference pulse patterns which might disrupt this process.
</p>
<p>
<strong>Sensitive navigation data</strong><br />
A TOW message is broadcast by all GNSS signals at regular intervals, and generally occupies a very small portion of the overall navigation message. In the case of GPS L1 C/A the TOW is broadcast in an unencoded form once per subframe, whereas for Galileo E1B, it is encoded, and broadcast once per pair of pages. Thus, the denial of TOW for the GPS L1 C/A signals requires either the denial of the subframe synchronization, or denial of the raw data itself. In the case of Galileo, the TOW might be denied by either denying page synchronization, or by inducing errors in the symbol decoding process. The basic details of the navigation messages, as shown in <span style="color: #ff0000"><strong>Figure 2</strong></span>, are as follows.
</p>
<p>
<span style="color: #993300"><strong>GPS:</strong></span> The L1 C/A preamble is an 8 bit sequence (160 milliseconds) transmitted every 6 seconds. The GPS parity is composed of 6 bit (120 milliseconds) transmitted every 600 milliseconds (navigation data word). Checking the consistency of two subsequent preambles, as well as the 10 parity checks in between, is a commonly accepted mean of synchronizing to the 6 seconds boundary.
</p>
<p>
<span style="color: #993300"><strong>Galileo: </strong></span>The E1B signal transmits a plain 10 symbol synchronization sequence (40 milliseconds) every second. It is interesting to see that GPS and Galileo synchronization sequences hardly overlap in time. The Galileo message CRC is FEC encoded and then spread by an interleaver. The E1B receiver deinterleaves the data and runs a Viterbi decoder to retrieve the 120 bit/sec of I/ NAV. The identification of a word results in resolving a 2 seconds time ambiguity, where certain words contain the time of week and/or week number.
</p>
<p>
<span style="color: #993300"><strong>Considerations for Navigation Message Authentication:</strong></span> Although the example examined here is that of denial of the PVT through the denial of the TOW, there are many other parts of the navigation message that could be targeted. In particular, it is worth mentioning the recent interest in the use of cryptographic methods for the protection of the navigation data. These methods typically require the inclusion of a significant number of cryptographic data bits in the navigation message, either as additional navigation data words or pages. This cryptographic data can be the order of several hundred bits, and generally has an all-or-nothing property, where any single bit error can render the entire message useless. For example, cryptographic keys can be several hundred bits in length, and digital signatures can be 300 to 600 bits in length. In both these cases, a single bit error is sufficient to corrupt them.
</p>
<p>
At present, data such as the ephemeris is broadcast piecewise, in short packets (words or pages), and repeated very frequently. Each ephemeris can be recovered piece-by-piece over time. In contrast, many proposals for GNSS message authentication have suggested that the cryptographic data be nonrepeating, in order that it provide some secondary spoofing-detection, or “carry-off” protection. Following these recommendations might render the message authentication data highly sensitive to systematic-jamming, where even very sparse interference might render the authentication function unavailable. If the availability or validity of the PVT is then associated with, or conditioned upon the correct verification of the navigation message authenticity, then this PVT might be denied quite easily, and covertly. This might compare very poorly with the resilience enjoyed by current receivers, especially those that utilize extended ephemeris or assistance data.
</p>
<p>
<strong>Design of Interference Pulse Patterns </strong><br />
The object of this section is to identify an interference signal that will deny the extraction of the TOW from the above signals using the least amount of energy possible such that the target receiver either remain unaware of the jamming attack; might be unable to effectively mitigate the jamming signal. To simplify the problem somewhat, the jamming signal is restricted to be an on-off-keying of a chirp interference signal, transmitting pulses of fixed duration equal to some integer milliseconds.
</p>
<p>
Two particular examples are explored here: GPS L1 C/A which is subjected to pulsed interference across the broadcast TOW, and the case of Galileo E1B, which is subject to pulsed interference across a series of symbols spaced according to the symbol interleaver, and are depicted in <span style="color: #ff0000"><strong>Figure 3</strong></span>. The GPS pulse pattern has been aligned with the 17-bit TOW and consists of six 20-millisecond pulses evenly spaced across a period of 240 milliseconds. The Galileo pulse pattern consists of fifteen 4-millisecond pulses, spaced according to the Galileo 8 °— 30 block interleaver, such that all 12 pulses appear consecutively once the received symbol stream has been deinterleaved.
</p>
<p>
This particular choice of pulse patterns is somewhat arbitrary, and has been selected based on some simple experiments. A more thorough design might carefully weigh the choice of number of pulses, pulse duration, and instantaneous interference power, to find a pattern which provides the highest probability of inducing bit errors, with the minimum probability of being detected. This will depend on the monitoring techniques of the receiver &#8211; including the carrier-to-noise density (C/N<sub>0</sub>) estimator and tracking loop design.
</p>
<p>
To align these pulse patterns with the received GNSS signals, they are broadcast with a delay relative to the edge of a GPS 6 second boundary. All GNSS satellites broadcast their messages in synchronous, and all have a range between 18,000 and 24,000 kilometers, depending azimuth and elevation, this fixed delay was set to 67 milliseconds, or approximately 20,000 kilometers.
</p>
<p>
Note that the maximum variation between nearest and furthest satellite results in a misalignment of less than 20 milliseconds, and so the pulse pattern applied to the GPS L1 C/A message will still overlap completely with the 17 bit TOW message. Similarly, owing to the nature of the block interleaver used for Galileo E1B, when the pulse pattern is shifted relative to the encoded symbols, provided they still overlap with a single page, the receiver will deinterleave to a continuous stream.
</p>
<p>
<strong>Anatomy of a Systematic Jammer </strong><br />
Central to any jamming device is the interference generator. In the systematic jamming device envisaged here, the key to its effectiveness is the interference pulse pattern, rather than the modulation of the interference signal itself, and so it is assumed that the source is similar to a typical chirp jammer, as depicted in <span style="color: #ff0000"><strong>Figure 4</strong></span>. These devices are remarkably simple, consisting of little more than a crystal, a VCO and a power amplifier. As can be seen from the exploded view in Figure 4, the device comprises only a handful of discrete components. Elaboration to a systematic jammer would involve on-off-keying the output of such a device. This suggests that the cost and complexity of a systematic-jammer would be driven by the inclusion of a GNSS receiver, rather than the actual generation of interference.
</p>
<p>
<span style="color: #ff0000"><strong>Figure 5</strong></span> shows the measured spectrum of the jammer depicted in Figure 4. The interference signal has a chirp modulation with a bandwidth of approximately 40 megahertz centered at L1. The amplitude varies slightly with frequency such that the chirp period can be clearly identified as approximately 20 microseconds. Even a very small device such as this is capable of creating a powerful wideband interference that poses a significant threat to typical GNSS receivers.
</p>
<p>
Until very recently, the only widely available transceiver option existing for radio amateurs and navigation/telecommunication engineers was the Ettus product line: the USRPs. More recently the technological advances in the integration of RF components into single multi-modal chips (mostly driven by the 3G/4G and DTV market) have enabled the design of relatively simple, highly versatile low cost SDR peripherals. A comprehensive review of such hardware is not appropriate here. Two commercially available transceivers were used in laboratory experiments. The most relevant specifications for these two devices are presented in <span style="color: #ff0000"><strong>Table 1</strong></span>.
</p>
<p>
Rather than develop and integrate the hardware required for a systematic- jammer, an equivalent model was developed based on the PPS-triggered broadcast of a pre-generation of an intermediate- frequency dataset containing the required pulse-patterns. This offered a very simple means of experimenting with the concept, however a practical device would simply implement an on-off- keying of a jammer similar to that shown in Figure 4.
</p>
<p>
<strong>Synchronization of the Jammer with GNSS-Time </strong><br />
A trigger for transceiver two was added to the stock firmware released on June 2016. At the time of writing, however, transceiver one did not support triggering but, as it is an open hardware and software design, this feature was implemented. Testing for synchronization of two transmitters was performed by generating a simulated single GPS L1 C/A signal (for a satellite that was not visible at the time), and triggering its broadcast using a PPS edge, as shown in <span style="color: #ff0000"><strong>Figure 6</strong></span>. This simulated signal was then combined with live signals from the rooftop antenna and processed by a GNSS receiver. By examining the pseudorange difference between the simulated and live GNSS signals it was possible to assess the accuracy of the PPS-triggered broadcast. It was observed that the start of the broadcast was accurate to within a few hundred microseconds, but the range diverged rapidly due to the poor clock quality of the transmitter. This indicated that it would be necessary to periodically re-synchronize the transmission with GPS time.
</p>
<p>
<strong>Live Testing with a COTS Receiver </strong><br />
This section briefly describes results of a simple systematic interference test conducted on a COTS GNSS receiver. The prototype systematic jammer was constructed using a single open source SDR platform, which derived synchronization with GPS time via a timing receiver, which delivered a rising edge on a trigger once every 30 seconds, as depicted in Figure 6. Note that although this device delivered a very precise timing reference, the systematic jamming attack does not necessarily require such accuracy, indeed the GNSS propagation delay is approximated with an error of up to 10 milliseconds. Therefore, a 1 to 10 millisecond accurate reference derived from a wired or wireless network, being WiFi or a 3G mobile network, would suffice. The test consisted of a conductive combination of a live GNSS feed from a roof mounted antenna with a systematic interference signal. The receiver under test was configured to deliver raw observations to a host PC for post processing.
</p>
<p>
<strong>Denial of GPS L1 C/A PVT </strong><br />
In the first test, the ability of the systematic jammer to deny observations and a PVT from GPS L1 C/A was examined. The experimental setup described above was used, and the pulse pattern depicted in Figure 3 (top) was used. The prototype jammer was powered up and allowed to initialize and align with GNSS time. Next the receiver under test was issued a cold-start command and its behavior was observed. The test was repeated with progressively increasing interference power until a power level was established at which the receiver was unable to produce a PVT, which was observed to occur at an instantaneous interference to noise floor level of approximately 30 decibels.
</p>
<p>
A trace of the 11 GPS satellites being tracked by the receiver are shown in <span style="color: #ff0000"><strong>Figure 7</strong></span>, where it can be seen that the received C/N<sub>0</sub> for the L1 C/A signal ranges from 49 to 35 decibel-hertz, but experiences brief reductions in power of approximately 6 decibels. During the entire test, the receiver was unable to provide a sufficient set of observations and ephemerides such that a PVT could be computed. Unfortunately, it was not possible to gain enough visibility into the internal receiver functionality to determine exactly which information was successfully extracted. It would have been helpful to understand whether ephemeris, almanac, health status and other variables were available, or whether the annihilation of the TOW and subsequent CRC failure rendered all data unavailable. Nonetheless, the results confirm that it is possible to deny a GPS L1 C/A based PVT via the targeted jamming of just a small portion of the navigation message. Beyond the results presented here, a similar systematic interference test was conducted and configured to run continuously over a 24-hour period, such that the receiver experienced a complete change in the visible constellation. Again, it was found that the receiver was unable at any point to provide a PVT despite the fact that the receiver was capable of acquiring and tracking all signals visible with only a minor degradation to the C/N<sub>0</sub>.
</p>
<p>
<strong>Denial of Galileo E1B PVT </strong><br />
The second test conducted was designed to assess the ability of the systematic jammer to deny observations and a PVT from the Galileo E1B signals. The pulse pattern was further changed to that of Figure 3 (bottom) and an experimental setup similar to the GPS case was used. However, due to the low availability of healthy Galileo satellites, the live GNSS feed from the roof antenna was replaced with a simulated signal sourced from a multi-constellation simulator. In this case the pulse pattern significantly more distributed in time, being spread relatively evenly across the I/NAV odd page. This particular pulse pattern was shaped according to the interleaving pattern, rather than being aligned with a particular data word, with the intention that once it is deinterleaved, it will appear as a continuous stream of symbol errors arriving at the decoder.
</p>
<p>
Interestingly, the ability of this approach to deny the navigation message is relatively insensitive to its alignment with the beginning of the page. Provided the complete set of pulses are received within one page, they will be de-interleaved into a continuous stream.
</p>
<p>
A screenshot from one of the tests is shown in <span style="color: #ff0000"><strong>Figure 8</strong></span> which includes a trace from eight Galileo and nine GPS satellites. As expected, the Galileo E1B message has been denied by the systematic interference, as indicated by the blue color-coding of the figure. Two interesting observations were made during this test. First, it was noted that the reception of the GPS L1 C/A signal was relatively unaffected. Eight of the nine GPS satellites report useful observations, and the receiver steadily provided a GPS-based PVT. The second particularly striking observation is that the C/N<sub>0</sub> reported by the receiver under test does not exhibit any significant variation either for GPS or for the Galileo satellites. A C/N<sub>0</sub> in the range of 48 to 49 decibel-hertz was reported for all Galileo satellites, yet the receiver was unable to extract navigation data from any of them. One reason for this is that the interference is relatively sparse in time and its effect is smoothed by the C/N<sub>0</sub> estimation process.
</p>
<p>
A few interesting conclusions are drawn from these results. We note that is possible to deny the use of one kind of GNSS signal, in this case, Galileo E1B, while leaving the other, in this case GPS L1 C/A, relatively unaffected, even when they occupy the same RF band. This appears to be due to the relative orthogonality of the navigation message structures, owing to their significantly different symbol periods, 4 milliseconds and 20 milliseconds, and the fact that one employs FEC while the other does not. It is also clear that the observation of C/N<sub>0</sub> may not be a useful means of interference detection, given that the C/N<sub>0</sub> level observed on the GPS and Galileo signals was virtually identical, yet the impact of the interference on the receiver’s ability to process the signal is drastically different.
</p>
<p>
<strong>Power, Energy and Synchronization </strong><br />
The probability of a bit or symbol error occurring is a very nonlinear function of the instantaneous interference power, however this probability of error saturates at 0.5. To achieve a more reliable denial of the navigation message, more symbols must be targeted, where the probability that the message is corrupted is given by:
</p>
<p>
<span style="color: #ff0000"><em><span style="color: #000000">P</span></em><span style="color: #000000"><sub>Err</sub> = 1 − 0.5</span></span><sup><em>N<sub>Pulse</sub></em></sup><strong><span style="color: #ff0000">     (1) </span></strong>
</p>
<p>
where N<sub>Pulse</sub> denotes the number of corrupted symbols. This probability tends to unity quite rapidly. Naturally, the total interference energy required increases as a linear function of the number of symbols:
</p>
<p>
<span style="color: #ff0000"><em><span style="color: #000000">E</span></em><span style="color: #000000"><sub>Int</sub> = </span></span><span style="color: #ff0000"><span style="color: #000000"><span style="color: #ff0000"><em><span style="color: #000000">P</span></em><span style="color: #000000"><sub>Ind</sub></span></span></span></span><em><span style="color: #ff0000"><span style="color: #000000"> N</span></span></em><span style="color: #ff0000"><span style="color: #000000"><sub>Pulse</sub></span></span><span style="color: #ff0000"><span style="color: #000000"><em> T</em><sub>Pulse</sub></span></span><strong><span style="color: #ff0000">     (2) </span></strong>
</p>
<p>
where T<sub>Pulse</sub> the pulse periods, being equal to the symbol or bit period. An astute adversary will tune this energy effecting a trade-off between the probability that the navigation message is denied, and the probability that the interference power will alert the receiver to the attack. In effect, by using a systematic interference, an adversary can reduce the total interference energy, or average interference power required to render the PVT unavailable. The reduction can be computed relative to a continuous interference signal, by expressing the average duty-cycle of the interference:
</p>
<p>
<strong>Equation</strong> <span style="color: #ff0000"><strong>(3) </strong><span style="color: #000000"><em>(see inset photo, above right)</em></span><br />
</span>
</p>
<p>
where T<sub>Patt</sub> is the repetition period of the interference pattern, being 6 seconds for GPS L1 C/A and 2 seconds for Galileo E1 B. The interference configuration for both the GPS L1 C/A and Galileo E1B are summarized in <span style="color: #ff0000"><strong>Table 2</strong></span>, where it is suggested that the effective gain of applying systematic jamming, as opposed to continuously broadcast jamming, is in the region of 15 to 17 decibels. Moreover, although the results here have been generated using a tightly synchronized transmitter, the principle of operation of the systematic jammer would permit synchronization errors in the region of 1 to 10 milliseconds. Notably, at this level of timing error, the jammer may no longer need to avail of position information.
</p>
<p>
<strong>Conclusion </strong><br />
The literature to date has primarily considered the two extremes of GNSS vulnerability, being either a very simple jamming attack, or a very complicated spoofing attack. Simple jamming, as we know it today, is a very easy attack to launch, but it is also very easily detected, readily localized, and often relatively easily mitigated. Spoofing, although very possible, and not necessarily difficult, is considerably more difficult than jamming. In the short term, if denial of service through simple jamming becomes non-viable, it is not unreasonable to expect this threat to evolve. There appears to be a middle-ground between jamming and spoofing, that might thwart current detection, localization and mitigation techniques. It appears to be very accessible to a malicious attacker, as it only requires commercial, off-the-shelf components, and some basic integration; yet it can pose a significant threat to a naïve receiver implementation. This increased threat comes at a very small increased attack cost and complexity, and has the potential to disrupt many location-based services, by imposing an undetectable partial (data recovery) or full (position and timing) denial-of-service. Preliminary results suggest that this attack methodology is feasible and, under certain conditions, may be quite effective when targeting a naïve receiver.
</p>
<p>
It is interesting to note that through interference signal design, it is possible to deny signals from one constellation why not negatively impacting signals from another, even when these signals share the same spectrum. Because this is achieved by carefully choosing the on-off-keying pattern, it is likely that this technique can be extended to target specific satellites from a given constellation.
</p>
<p>
This work represents only a very preliminary examination of the concept, but does seem to highlight the fact that it may be naïve to assume that the jamming threat will not evolve in reaction to anti-jamming technology. The notion that jamming devices might be designed in direct response to anti-jamming techniques might open a new avenue of research into the more game-theoretic aspects of resilient GNSS receivers. It might further invigorate the use of technologies such as antenna diversity, or synthetic aperture antennas, or adaptive interference mitigation techniques.
</p>
<p>
<span style="color: #993300"><strong>Additional Resources </strong></span><strong><span style="color: #ff0000"><br />
[1]</span></strong> Amin, M. G., and P. Closas, A. Broumandan, and J. L. Volakis. “Vulnerabilities, threats, and authentication in satellite-based navigation systems [scanning the issue].”<em> Proceedings of the IEEE</em>, 104(6):1169- 1173, 2016. <strong><span style="color: #ff0000"><br />
[2]</span></strong> Curran, J., M. Navarro, M. Anghileri, P. Closas, and S. Pfletschinger. “Coding aspects of secure GNSS receivers.” <em>Proceedings of the IEEE</em>, 104(6):1271- 1287, 2016. <strong><span style="color: #ff0000"><br />
[3]</span></strong> Dovis, F., “GNSS Interference Threats and Countermeasures.” Artech House, Boston, 2015. <strong><span style="color: #ff0000"><br />
[4] </span></strong>Fontanella, D., R. Bauernfeind, and B. Eissfeller. “In-car GNSS jammer localization with a vehicular ad-hoc network.” In <em>Proceedings of the 25th International Technical Meeting of The Satellite Division of the Institute of Navigation</em>, pages 2885-2893, September 2012. <strong><span style="color: #ff0000"><br />
[5] </span></strong>Humphreys, T. E., J. Bhatti, D. Shepard, and K. Wesson. “The Texas spoofing test battery: Toward a standard for evaluating GPS signal authentication techniques.” In <em>Proceedings of the 25th International Technical Meeting of The Satellite Division of the Institute of Navigation</em>, pages 3569-3583, September 2012. <strong><span style="color: #ff0000"><br />
[6] </span></strong>Humphreys, T. E., B. M. Ledvina, M. L. Psiaki, B. W. O’Hanlon, and P. M. Kintner. “Assessing the spoofing threat: Development of a portable GPS civilian spoofer.” In <em>Proceedings of the 21st International Technical Meeting of the Satellite Division of The Institute of Navigation</em>, pages 2314-2325, September 2008. <strong><span style="color: #ff0000"><br />
[7]</span></strong> Johnson, M., and R. Erlandson. “GNSS receiver interference: Susceptibility and civil aviation impact.” In <em>Proceedings of the 8th International Technical Meeting of the Satellite Division of The Institute of Navigation</em>, pages 781-791, September 1995. <strong><span style="color: #ff0000"><br />
[8]</span></strong> Kraus, T., R. Bauernfeind, and B. Eissfeller. “Survey of in-car jammers &#8211; analysis and modeling of the RF signals and IF samples (suitable for active signal cancellation).” In <em>Proceedings of the 24th International Technical Meeting of The Satellite Division of the Institute of Navigation</em>, pages 430-435, September 2011. <strong><span style="color: #ff0000"><br />
[9]</span></strong> Mitch, R. H., R. C. Dougherty, M. L. Psiaki, S. P. Powell, B. W. O’Hanlon, B. W. Bhatti, and T. E. Humphreys. “Signal characteristics of civil GPS jammers.” In <em>Proceedings of the 24th International Technical Meeting of The Satellite Division of the Institute of Navigation</em>, pages 1907-1919, September 2011. <strong><span style="color: #ff0000"><br />
[10] </span></strong>Motella, B., S. Savasta, D. Margaria, and F. Dovis. “An interference impact assessment model for GNSS signals.” In <em>Proceedings of the 21st International Technical Meeting of the Satellite Division of The Institute of Navigation</em>, pages 900-908, September 2008. <strong><span style="color: #ff0000"><br />
[11]</span></strong> NSL, Spirent, “<a href="http://www.spirent.com/Products/GSS200D-Detector" target="_blank">Detector</a>”, Accessed 2016. [12] Psiaki, M. L., and T. E. Humphreys. “GNSS Spoofing and Detection.” <em>Proceedings of the IEEE</em>, 104(6):1258-1270, 2016. <strong><span style="color: #ff0000"><br />
[13]</span></strong> Pozzobon, O., C. Sarto, A. Dalla Chiara, S. Pozzobon, G. Gamba, M. Crisci, and R. T. Ioannides. <a href="http://insidegnss.com/developing-a-gnss-position-and-timing-authentication-testbed/">“Developing a GNSS position and timing authentication testbed GNSS vulnerability and mitigation techniques.”</a> In <em>Inside GNSS</em> article, January 2013. <strong><span style="color: #ff0000"><br />
[14] </span></strong>Samson, J., L. Musumeci, and F. Dovis. “Performance assessment of pulse blanking mitigation in presence of multiple distance measuring equipment/ tactical air navigation interference on global navigation satellite systems signals.” <em>IET Radar, Sonar and Navigation</em>, 8(6):647-657, July 2014. <strong><span style="color: #ff0000"><br />
[15] </span></strong>Spirent, “<a href="http://www.spirent.com/Products/simsafe" target="_blank">Simsafe</a>”, Accessed 2016. <strong><span style="color: #ff0000"><br />
[16] </span></strong>Wildemeersch M., and J. Fortuny-Guasch. “A laboratory testbed for GNSS interference impact assessment.” In <em>Proceedings of the 22nd International Technical Meeting of The Satellite Division of the Institute of Navigation</em>, pages 49-54, September 2009. <span style="color: #ff0000"><strong><br />
[17] </strong></span>Curran, James T., Bavaro, Michele, Closas, Pau, Navarro, Monica, “On the Threat of Systematic Jamming of GNSS,” <em>Proceedings of the 29th International Technical Meeting of The Satellite Division of the Institute of Navigation (ION GNSS+ 2016)</em>, Portland, Oregon, September 2016, pp. 313-321.
</p>
<div class='pdfclass'><a target='_blank' class='specialpdf' href='http://insidegnss.com/wp-content/uploads/2018/01/sepoct17-CURRAN.pdf'>Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/systemic-jamming/">Systemic Jamming</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>GSA&#8217;s GNSS Opinion Leaders for August 2017</title>
		<link>https://insidegnss.com/gsas-gnss-opinion-leaders-for-august-2017/</link>
		
		<dc:creator><![CDATA[Inside GNSS]]></dc:creator>
		<pubDate>Thu, 10 Aug 2017 05:41:56 +0000</pubDate>
				<category><![CDATA[201706 July/August 2017]]></category>
		<category><![CDATA[Aerospace and Defense]]></category>
		<category><![CDATA[GNSS (all systems)]]></category>
		<category><![CDATA[legacy-application]]></category>
		<category><![CDATA[receiver]]></category>
		<category><![CDATA[Series]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[GSA]]></category>
		<guid isPermaLink="false">http://insidegnss.com/2017/08/10/gsas-gnss-opinion-leaders/</guid>

					<description><![CDATA[<p>Bernhard Richter, Leica Geosystems GNSS business director Enrico Salvatori, Qualcomm Europe Carlo Bagnoli, STMicroelectronics Carlo Bagnoli is Director of Infotainment BU System and...</p>
<p>The post <a href="https://insidegnss.com/gsas-gnss-opinion-leaders-for-august-2017/">GSA&#8217;s GNSS Opinion Leaders for August 2017</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="special_post_image"><img decoding="async" class="specialimageclass img-thumbnail" src="https://insidegnss.com/wp-content/uploads/2018/01/Richter.jpg" /><span class="specialcaption">Bernhard Richter, Leica Geosystems GNSS business director</span></div>
<div class="special_post_image"><img decoding="async" class="specialimageclass img-thumbnail" src="https://insidegnss.com/wp-content/uploads/2018/01/Salvatori.jpg" /><span class="specialcaption">Enrico Salvatori, Qualcomm Europe</span></div>
<div class="special_post_image"><img decoding="async" class="specialimageclass img-thumbnail" src="https://insidegnss.com/wp-content/uploads/2018/01/Bagnoli.jpg" /><span class="specialcaption">Carlo Bagnoli, STMicroelectronics</span></div>
<p>Carlo Bagnoli is Director of Infotainment BU System and Applications at STMicroelectronics. The company is a global semiconductor leader focusing on smart driving and the internet of things, creating intelligent and energy-efficient products that enable intelligent transport as well as smarter factories, cities and homes.</p>
<p>Within the infotainment business unit, Bagnoli and his team work to develop positioning receivers, broadcast receivers and communication processors for the automotive market. Doing so means gathering GNSS signals from far and wide.</p>
<p><span id="more-22928"></span></p>
<p>Carlo Bagnoli is Director of Infotainment BU System and Applications at STMicroelectronics. The company is a global semiconductor leader focusing on smart driving and the internet of things, creating intelligent and energy-efficient products that enable intelligent transport as well as smarter factories, cities and homes.</p>
<p>Within the infotainment business unit, Bagnoli and his team work to develop positioning receivers, broadcast receivers and communication processors for the automotive market. Doing so means gathering GNSS signals from far and wide.</p>
<p>Once upon a time, Bagnoli says, “everybody thought GPS was enough. Now it’s the multi-constellation system that is a sort of de facto requirement.”</p>
<p><strong>Coming Up </strong><br />
Early believers in the power of multiconstellation in situations such as urban canyons STMicroelectronics beat all major competitors to the punch when it unveiled its dual-constellation, GPS+Glonass receiver in 2011. But in fact the company had already been working for years on blending GPS+Galileo signals.</p>
<p>“We started in 2004 with some high-level exploratory work,” Bagnoli explained, “ and then we did our first funded research under the European Union’s FP7 Program, working to develop a Galileo-ready positioning terminal. Based on the outcome of that research we created the navigation CPU CartesioPlus product.”</p>
<p>So Galileo was already present in ST’s GPS/GNSS receiver hardware by the mid-2000s, with a new RF and an FPGA-based baseband. A production version of CartesioPlus followed in high volume from 2009, but it was in reality still a GPS-only chipset, because there were not yet any operational Galileo satellites in orbit.</p>
<p>“We were still looking into increasing the number of supporting constellations,” Bagnoli said, “So with Galileo still under development, we began working on a new product that could also support Glonass, called ‘Teseo’, which we completed and launched in 2011.”</p>
<p>By then, he said, the rest of the mobile industry had already understood that Glonass was quite relevant for improving the user experience in urban canyons. However, he said, the rest of the automotive mission-critical industry was late: “With Teseo, putting together the first multi-constellation chip, we anticipated the work of the others by 12-24 months.”</p>
<p>Today, Bagnoli says, the accuracy of Glonass has improved, through better geometry, but not because of the accuracy of the actual signal, which is still a problem.</p>
<p><strong>Galileo is Born </strong><br />
For STMicroelectronics, the launch of Galileo initial services in December 2016 was a real breakthrough, Bagnoli said: “For a GNSS receiver company, the birth of any new Open Service GNSS system has to be considered an opportunity for new integration as it improves the user experience with no major steady-state cost added.”</p>
<p>The case for Galileo, he said, was a no-brainer. “ST decided to include Galileo from its inception and we have had it both in our CartesioPlus navigation CPUs and in our dedicated standalone Teseo receivers. And we are completely committed to including it on our next-generation multi-band precise positioning platforms.</p>
<p>“With Galileo there is no major cost of development; the development applies to multiple system-on-chip platforms, so the relative effort of adding Galileo to a set of already -supported constellations is very manageable.”</p>
<p>Bagnoli said the his company definitely made the right decision in preparing for Galileo early: “ST is focused on automotive and ITS and in these markets research and development cycles take significant time. Thanks to foresight, we now have two mature product families and we are looking forward to the business development of our Galileo-capable receivers.”</p>
<p><strong>Multi, Multi, Multi&#8230; </strong><br />
Everyone seems to agree; a new type of mission-critical GNSS receiver is now needed, one that can work in conjunction with correction data available from multiple sources, ultimately providing sub-meter accuracy.</p>
<p>To this end, Bagnoli said, STMicroelectronics is looking at ways to combine all the functional GNSS constellations: “Finally, as we have more and more automotive ITS, integrity is becoming more and more important, so redundancy is useful and, for example, cooperative multi-constellation anti-spoofing is something that we have already worked on.</p>
<p>“We now have a solution where we do very fine monitoring of the different systems in order to provide more integrity beyond the accuracy dimension, and this is going to be particularly relevant for regulated services and so on.”</p>
<p>Indeed, while these single- frequency, multi-constellation GNSS solutions are still viable for traditional Infotainment applications, emerging intelligent transportation systems (ITS) and liability- and safety-critical applications such as advanced driver assistance systems (ADAS) are raising performance and integrity requirements for GNSS receivers, creating demand for new and even more advanced GNSS solutions.</p>
<p>Bagnoli describes the clear advantages of a rapidly maturing Galileo system in terms of its high accuracy and high integrity, the latter of which he says has been an overlooked aspect in many markets. “If your aim is to increase accuracy, augmenting GPS through a multi-constellation configuration, then Galileo is really the best way to go, particularly for automotive and ITS systems; And its integrity features will serve well in support of regulated services.</p>
<p>“Right now, with Beidou3 still under construction, GPS+Galileo is going to be a very solid mode, and this is the only harmonized pure L1 receiver combination available.”</p>
<p>Again, Bagnoli says, for his company the key market for the Galileo open service is ITS, including liability- and safety-critical applications. “STMicroelectronics is focusing to this market and aiming to be a key player there,” he said. “Further, we expect that this will become a multi-frequency as well as a multi-constellation equation, as more augmented driving applications arrive, and we are excited by the challenge and the business opportunity.”</p>
<div class="pdfclass"><a class="specialpdf" href="http://insidegnss.com/wp-content/uploads/2018/01/IGM_GSA.pdf" target="_blank" rel="noopener">Download this article (PDF)</a></div>
<div class="pdfclass"><a class="specialpdf" href="http://insidegnss.com/wp-content/uploads/2018/01/sepoct17-GNSSOPINION.pdf" target="_blank" rel="noopener">Download this article (PDF)</a></div>
<div class="pdfclass"><a class="specialpdf" href="http://insidegnss.com/wp-content/uploads/2018/01/novdec17-GNSSOpinion.pdf" target="_blank" rel="noopener">Download this article (PDF)</a></div>
<p>The post <a href="https://insidegnss.com/gsas-gnss-opinion-leaders-for-august-2017/">GSA&#8217;s GNSS Opinion Leaders for August 2017</a> appeared first on <a href="https://insidegnss.com">Inside GNSS - Global Navigation Satellite Systems Engineering, Policy, and Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
