Positioning, navigation, and timing (PNT) system failure detection, containment, isolation, and response architecture

By grouping the sensors in the PNT system and implementing fault detection, containment, and isolation mechanisms, the problems of inertial navigation errors and signal interference were solved, enabling reliable navigation and timing capabilities in complex environments.

CN114089383BActive Publication Date: 2026-05-01THE BOEING CO
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
THE BOEING CO
Filing Date
2021-07-06
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing positioning, navigation, and timing (PNT) systems suffer from increasing errors over time in inertial navigation algorithms and are susceptible to low-power interference from GPS/GNSS signals, leading to navigation errors and signal blocking or spoofing, which affects the availability and reliability of the system.

Method used

Multiple sensors are grouped into subsets, and potential faults are addressed through first-level and second-level fault detection, containment, and isolation mechanisms. Replacement values ​​and redundant or combined sensors are used to resolve potential faults. Navigation correction is performed by combining inertial navigation and Kalman filters, and external GNSS signal interference is detected and isolated.

Benefits of technology

Effective detection and isolation of sensor faults ensures that the PNT system provides a reliable navigation solution in harsh environments, improving the system's anti-interference capability and navigation accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114089383B_ABST
    Figure CN114089383B_ABST
Patent Text Reader

Abstract

This application relates to a failure detection, containment, isolation, and response architecture for a positioning, navigation, and timing (PNT) system. A PNT system for a user includes a plurality of sensors configured to collect measurements, where the sensors are grouped into a plurality of subsets of sensors. The PNT system individually compares a measurement value collected by each of the plurality of sensors to a corresponding threshold value. When the measurement value exceeds the corresponding threshold value, the PNT system determines that there is a potential failure condition for the particular sensor. In response to detecting the potential failure condition, the PNT system contains the potential failure condition by determining a replacement value. In response to determining that a number of times the potential failure condition is detected exceeds a predetermined value, the PNT system determines a confirmed failure condition with respect to the particular sensor and regroups the plurality of subsets of sensors. The PNT system proceeds to a second level of failure detection to determine a plurality of individual navigation solutions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a positioning, navigation, and timing (PNT) system. More specifically, this disclosure relates to a fault detection, containment, isolation, and response architecture for multiple sensors that are part of a PNT system. Background Technology

[0002] Positioning, navigation, and timing (PNT) systems can determine navigation and timing solutions based on measurements from an inertial measurement unit (IMU). However, due to integration within the IMU's algorithms, navigation errors caused by IMU errors increase over time. Therefore, PNT systems can combine navigation solutions based on IMU measurements with data collected from the Global Positioning System (GPS) and Global Navigation Satellite System (GNSS). However, GPS and other GNSS signals have low power, making them susceptible to interference even from very low-power sources. For example, GPS rejection can be caused by unintentional or intentional interference, known as jamming. Therefore, a guaranteed PNT (A-PNT) system can be provided instead, as it can deliver reliable PNT information even under conditions where GPS / GNSS may be restricted, blocked, or rejected. Military applications, as well as some commercial applications, require A-PNT systems. Finally, A-PNT systems provide availability, access, and integrity of the PNT solution under various threat and failure conditions. Summary of the Invention

[0003] According to several aspects, a positioning, navigation, and timing (PNT) system for a user is disclosed. The PNT system includes multiple sensors configured to collect user-related measurements, wherein the multiple sensors are grouped into multiple subsets of sensors. The PNT system also includes one or more processors in electrical communication with the multiple sensors and a memory coupled to the one or more processors. The memory stores data in one or more databases and program code, which, when executed by the one or more processors, causes the PNT system to individually compare each collected measurement from the multiple sensors with a corresponding threshold, wherein the measurement is compared individually in a first-level fault detection. When a measurement exceeds the corresponding threshold, the PNT system also determines a potential fault condition for a particular sensor. In response to detecting a potential fault condition, the PNT system suppresses the potential fault condition by determining a replacement value. The PNT system counts the number of times potential fault conditions are detected. The PNT system also compares the number of potential fault condition detections with a predetermined value. In response to determining that the number of potential fault condition detections exceeds the predetermined value, the PNT system determines a confirmed fault condition for a particular sensor. In response to determining a confirmed fault condition for a particular sensor, the PNT system regroups the multiple subsets of sensors. The PNT system proceeds to the second level of fault detection, which involves identifying multiple individual navigation solutions corresponding to each of multiple subsets of sensors, with each individual navigation solution based on the corresponding subset of sensors.

[0004] On the other hand, a method for managing fault conditions for a PNT system is disclosed. The method includes individually comparing measurements collected from each of a plurality of sensors with a corresponding threshold, wherein the individual comparison of measurements is performed in a first-level fault detection. The plurality of sensors are grouped into a plurality of subsets of sensors. The method includes determining a potential fault condition for a particular sensor when a measurement exceeds a corresponding threshold. In response to detecting a potential fault condition, the method suppresses the potential fault condition by determining a replacement value. The method also includes counting the number of times potential fault conditions are detected and comparing the number of potential fault condition detections with a predetermined value. In response to determining that the number of potential fault condition detections exceeds the predetermined value, the method determines a confirmed fault condition for a particular sensor. In response to determining a confirmed fault condition for a particular sensor, the method regroups the plurality of subsets of sensors. Finally, the method includes proceeding to a second-level fault detection, wherein the second-level fault detection includes determining a plurality of individual navigation solutions corresponding to each of the plurality of subsets of sensors, and each individual navigation solution is based on the corresponding subset of sensors.

[0005] The features, functions, and advantages already discussed can be implemented independently in various embodiments or combined in other embodiments, further details of which can be seen in the following description and figures. Attached Figure Description

[0006] The accompanying drawings described herein are for illustrative purposes only and are not intended to limit the scope of this disclosure in any way.

[0007] Figure 1 This is a schematic diagram of a fault detection, containment, isolation, and response architecture for a disclosed location, navigation, and timing (PNT) system for a user, according to an exemplary embodiment.

[0008] Figure 2 According to the exemplary embodiments, for Figure 1 The diagram shows the first-level fault detection, containment, isolation, and response of the sensor.

[0009] Figure 3 This illustrates a subset of sensors grouped according to an exemplary embodiment. Figure 1 A schematic diagram of the sensor shown;

[0010] Figure 4 This is a schematic diagram illustrating second-level fault detection, containment, isolation, and response for a sensor, according to an exemplary embodiment.

[0011] Figure 5 This is a schematic diagram of a fourth-level fault detection according to an exemplary embodiment;

[0012] Figures 6A-6C A process flowchart illustrating a method for managing fault conditions in a PNT system according to an exemplary embodiment is shown; and

[0013] Figure 7 It is a computing system for the disclosed PNT system according to an exemplary embodiment. Detailed Implementation

[0014] This disclosure relates to a fault detection, containment, isolation, and response architecture for multiple sensors that are part of a positioning, navigation, and timing (PNT) system for a user. Specifically, the fault management architecture is configured to detect, contain, isolate, and respond to fault conditions in one or more sensors. For the purposes of this disclosure, a fault condition represents when one or more sensors output incorrect values, when one or more sensors do not output values, and processing and software errors. The fault management architecture identifies the specific sensor that creates the fault condition and isolates the specific sensor to prevent the fault from propagating through the PNT system. The fault management architecture also determines whether a specific external auxiliary source, such as a satellite that is part of a Global Navigation Satellite System (GNSS) system that communicates wirelessly with the PNT system, has been damaged. A damaged satellite indicates an external fault, indicates that the satellite's transmitted signal has been blocked, or indicates that the satellite's transmitted signal has been spoofed. In response to determining that one or more satellites have been damaged, the fault management architecture performs one or more corrective actions.

[0015] The following description is merely illustrative in nature and is not intended to limit this disclosure, its application, or its uses.

[0016] refer to Figure 1 An exemplary positioning, navigation, and timing (PNT) system 10 for user 12 is illustrated. The PNT system 10 includes multiple sensors 20, 30 configured to collect measurements related to user 12. Specifically, the multiple sensors 20, 30 are configured to collect measurements related to user 12's position, velocity, attitude, or time. The disclosed PNT system 10 includes multiple propagation sensors 20 and multiple update sensors 30, each propagation sensor electrically communicating with a corresponding sensor extraction / processing module 22, and each update sensor electrically communicating with a corresponding sensor extraction / processing module 32. The PNT system 10 further includes multiple navigation modules 34 electrically communicating with the sensor extraction / processing modules 22, 32. As described below, each of the multiple navigation modules 34 is based on a corresponding subset 28 of the sensors 20, 30 that are part of the PNT system 10. Figure 3 (As shown in the diagram) Individual navigation solutions 36 are determined for user 12. Each individual navigation solution 36 indicates the user 12's position, velocity, and attitude. The PNT system 10 also includes a voting module 38, a fault analysis module 41, and a network monitoring module 42. Figure 5 As seen, the network monitoring module 42 communicates wirelessly with one or more monitoring systems 44 via a communication network 46. As described below, the monitoring system 44 is configured to determine the integrity of Global Navigation Satellite System (GNSS) signals and augmentation signals.

[0017] refer to Figure 1In one embodiment, user 12 is an individual, such as a soldier carrying the corresponding PNT system 10. In another embodiment, user 12 is a vehicle, such as, but not limited to, a car, aircraft, unmanned aerial vehicle (UAV), helicopter, missile, marine vehicle, unmanned underwater vehicle (UUV), or unmanned ground vehicle (UGV). PNT system 10 includes a fault management architecture configured to detect, contain, isolate, and respond to fault conditions within PNT system 10. Fault conditions occur with respect to one or more sensors 20, 30. Alternatively, PNT system 10 detects fault conditions with respect to communication network 46 (…). Figure 1 The PNT system 10 transmits information on the external fault status of resources. Specifically, the PNT system 10 includes four levels of fault management: Level 1, Level 2, Level 3, and Level 4. Level 4 monitors the integrity of GNSS and augmentation system signals, collects information on the status, availability, and integrity of other PNT resources, and provides network-level assistance to the PNT system 10 in fault management-related decisions and resource management transmitted via the communication network 46.

[0018] The PNT system 10 includes Np propagation sensors 20, each configured to collect measurements for determining a corresponding propagation solution for user 12, where Np can be any integer greater than 1. Examples of propagation sensors 20 include, but are not limited to, inertial measurement units and clocks for time propagation. The PNT system 10 also includes Nu update sensors 30, configured to collect measurements for determining updates that correct the propagation solution. Examples of update sensors 30 include, but are not limited to, Global Positioning System (GPS), gravity sensors, altimeters, cameras, star trackers, opportunistic signal receivers, radar, lidar, and magnetometers. The propagation solutions form one or more propagation navigation solutions. The navigation module 34 determines a corresponding individual navigation solution 36 based on a combination of the updated and propagation navigation solutions determined from the measurements collected from the update sensors 30. It should be understood that, for the purposes of this disclosure, in one embodiment, the propagation sensors 20 are represented by free information sources (such as mathematical models) rather than actual physical sensors. Similarly, in one embodiment, the update sensors 30 are represented by free information sources (such as mathematical models) rather than physical sensors.

[0019] Multiple propagation sensors 20 are each configured to collect measurements 60 associated with changes in the position, velocity, or attitude of the user 12. Each propagation sensor 20 generates a time series of the measurements 60, which is sent to a corresponding propagation sensor processing / extraction module 22. Each propagation sensor processing / extraction module 22 is configured to process and encode the measurements 60 generated by the corresponding propagation sensor 20. The measurements 60 collected by each propagation sensor 20 are then sent to one or more navigation modules 34. Similarly, update sensors 30 are each configured to collect measurements 70, which are functions of the user 12's current position, velocity, attitude, or some combination of current position, velocity, and attitude. Specifically, each update sensor 30 generates a time series of the measurements 70, which is sent to a corresponding update sensor processing / extraction module 32. Each update sensor processing / extraction module 32 is configured to process and encode the measurements 70 generated by the corresponding update sensor 30. The measurements 70 collected by each updated sensor 30 are then sent to one or more navigation modules 34.

[0020] Level 1 fault detection occurs at individual sensor processing / extraction modules 22 and 32. Each of the individual sensor processing / extraction modules 22 and 32 is configured to detect potential fault conditions occurring with respect to a single corresponding sensor 20 or 30, contain potential fault conditions, isolate potential fault conditions, and respond to confirmed fault conditions. For the purposes of this disclosure, a fault condition refers to when one or more sensors 20 or 30 outputs an incorrect value, when one or more sensors 20 or 30 does not output a value, and processing and software errors. In response to determining that a fault condition exists for a particular sensor 20 or 30, sensor processing / extraction modules 22 and 32 determine corresponding replacement values ​​160 and 170 to replace the corresponding measured values ​​60 and 70. Figure 2 It should be understood that Level 1 (Level 1) fault detection is performed separately and independently for each individual sensor 20, 30, which is part of the PNT system 10.

[0021] Figure 2 This shows the requirements for Level 1 fault detection. Figure 1 An exemplary fault detection, containment, isolation, and response block diagram of one of the sensors 20 and 30 shown. (Reference) Figure 1 and Figure 2Each sensor processing / extraction module 22 includes a corresponding comparator 74, a corresponding persistence counter 76, a corresponding containment block 78, and a corresponding response block 82. Similarly, each sensor processing / extraction module 32 also includes a corresponding comparator 74, a corresponding persistence counter 76, a corresponding containment block 78, and a corresponding response block 82. In other words, the same fault detection structure is used regardless of the type of sensor used. The comparator 74 receives a measurement value 60 from one of the propagating sensor processing / extraction modules 22, or alternatively, from one of the updating sensor processing / extraction modules 32. The comparator 74 also receives a threshold 80 as input, where exceeding the corresponding threshold 80 indicates a potential fault condition for the specific sensor 20, 30 being monitored. For the purposes of this disclosure, a potential fault condition is created when the measurement value 60, 70 exceeds the corresponding threshold 80 but no actual fault condition has been confirmed for that specific sensor 20, 30. The threshold 80 depends on the specific variable being monitored by the specific sensor 20, 30 and the specific application. Comparator 74 is configured to compare a corresponding measurement 60 from a specific sensor 20 (or a corresponding measurement 70 from a specific sensor 30) with a corresponding threshold 80. In response to determining that the measurement 60 (or measurement 70) exceeds the corresponding threshold 80, comparator 74 generates a signal 84. Signal 84 indicates a potential fault condition occurring with respect to the specific sensor 20, 30.

[0022] The signal 84 generated by comparator 74 is sent to containment block 78. For the purposes of this disclosure, a potential fault condition is contained after individual sensor processing / extraction modules 22, 32 detect a potential fault condition, but before the persistence counter 76 determines that the potential fault condition is persistent and isolates and responds to the confirmed fault condition. Containment block 78 is configured to contain potential fault conditions generated by specific sensors 20, 30 throughout the PNT system 10 by determining corresponding replacement values ​​160, 170. Figure 1 The data is propagated in the sensor 20. Replacement values ​​160 and 170 replace measurements 60 and 70 generated by specific sensors 20 and 30 that exceed the corresponding threshold 80. The replacement value 160 corresponding to one of the propagation sensors 20 is determined based on interpolation, extraction, or prediction using a model. The replacement value 170 corresponding to one of the update sensors 30 is a skipped sample.

[0023] It should be understood that when a potential failure condition is detected but containment is performed before the persistence counter 76 is persistently triggered, the potential failure condition is confirmed. Isolation and response are now described. (Continue to refer to...) Figure 2The signal 84 generated by comparator 74 is sent to persistence counter 76 and response block 82. Persistence counter 76 is configured to count the number of times comparator 74 generates signal 84 and to identify when a potential fault condition becomes persistent. When the number of times signal 84 has been generated exceeds a predetermined value, the potential fault condition is persistent, and comparator 74 generates signal 86. Signal 86 provides confirmation that a confirmed fault condition has occurred for a specific sensor 20, 30. In other words, when the measured values ​​60, 70 persistently exceed the predetermined value, persistence counter 76 then confirms the existence of a potential fault condition for the corresponding sensor 20, 30. The predetermined value is determined based on the specific application and confirms the existence of a potential fault condition for the corresponding sensor 20, 30. In other words, persistence counter 76 is configured to count the number of times signal 84 is generated, wherein when the number of times the corresponding measured values ​​60, 70 exceed the corresponding threshold 80, persistence counter 76 generates signal 86.

[0024] Signal 86 is then sent to response block 82. Response block 82 is configured to determine fault response actions 260 and 270 for specific sensors 20 and 30. In one exemplary embodiment, fault response actions 260 and 270 represent a reconfiguration of a subset 28 of sensors 20 and 30 used by each navigation module 34. For example, if redundant sensors are present, redundant sensors can be used to replace sensors 20 and 30 that have gone offline due to a fault. Alternatively, if redundant sensors are not present, in another embodiment, a combination of sensors 20 and 30 configured to determine individual navigation solutions is used instead. As described above, fault response action 260 corresponding to one of the propagation sensors 20 is determined based on interpolation, extraction, or prediction using a model, and fault response action 270 corresponding to one of the update sensors 30 is a skipped sample.

[0025] The second level (Level 2) of fault management will now be described. (Return to reference) Figure 1 Each navigation module 34 is a subset 28 of sensors 20 and 30. Figure 3 One of the corresponding ones in ), and configured to detect faulty sensors based on Level 2 (Level 2) fault detection. (See reference) Figure 1 and Figure 3 In one embodiment, each subset 28 of sensors 20, 30 excludes any individual sensor 20, 30 that is part of the PNT system 10, and each sensor 20, 30 that is part of the PNT system 10 is excluded from one of the subsets 28. Figure 3In the exemplary embodiment shown, the PNT system 10 includes five sensors 20 and 30 labeled 1, 2, 3, 4, and 5. Therefore, there are five subsets 28 of sensors 20 and 30. The first subset 28 includes sensors 1, 2, 3, and 4; the second subset 28 includes sensors 1, 2, 3, and 5; the third subset 28 includes sensors 1, 2, 4, and 5; the fourth subset 28 includes sensors 1, 3, 4, and 5; and the fifth subset 28 includes sensors 2, 3, 4, and 5. In other words, if the PNT system 10 includes x sensors, then each subset 28 of sensors 20 and 30 will include (x-1) sensors 20 and 30.

[0026] Back Figure 1 Each of the navigation modules 34 is configured to detect a corresponding subset 28 of sensors 20 and 30. Figure 3 The fault status of ) is now referenced. Figure 4 Regarding Level 2 fault management, specifically... Figure 1 An exemplary fault detection, containment, isolation, and response block diagram of one of the navigation modules 34 shown. (Reference) Figure 1 and Figure 4 Each navigation module 34 includes an inertial navigation block 88, a prediction block 90, a residual block 92, a residual covariance block 94, a Kalman filter 96, a covariance boundary block 98, a persistent counter 100, and an isolation and response block 102.

[0027] The inertial navigation block 88 receives measurements 60 from a specific propagation sensor 20 and determines a corresponding propagation navigation solution 40 based on the measurements 60. The propagation navigation solution 40 is a time series representing the user 12's changing position, changing velocity, and changing attitude, based on the measurements 60 from the corresponding propagation sensor 20. The prediction block 90 receives the propagation navigation solution 40 as input and predicts a predicted value 172 for the updated sensor 20 based on the propagation navigation solution 40 and a mathematical model. The predicted value 172 is determined using any number of methods. The prediction block 90 sends the predicted value 172 to the residual block 92. The residual block 92 compares the measurements 70 from the updated sensor 30 with the predicted value 172 from the prediction block 90 to determine multiple pre-Kalman filtered values ​​for corresponding subsets 28 of sensors 20 and 30, where the multiple pre-Kalman filtered values ​​include the residual r, the measurement sensitivity matrix H(k), and the measurement variance matrix R(k). The residual r represents the difference between the estimated measurement 172 and the measurement 70, the measurement sensitivity matrix H(k) indicates how the error in the propagating navigation solution 40 and the state in the Kalman filter affect the estimated measurement 172, and the measurement variance matrix R(k) indicates the level of uncertainty or variance of the measurement 70 collected by the corresponding updated sensor 30.

[0028] The pre-Kalman filter value 104 is sent to the Kalman filter 96. The Kalman filter 96 is configured to determine navigation corrections for the propagating navigation solution 40 and sensor corrections for the corresponding updated sensor 30 based on the pre-Kalman filter value 104. The navigation corrections include position, velocity, and attitude corrections for the user 12, as well as corrections for sensor calibration parameters. The Kalman filter 96 then determines the individual navigation solution 36 by correcting the corresponding propagating navigation solution 40 with the navigation corrections and sensor corrections.

[0029] The pre-Kalman filtered value 104 is also sent to the residual covariance block 94. The residual covariance block 94 uses any number of methods to determine the error covariance matrix P corresponding to the residual r based on the measurement variance matrix R(k). The residual covariance matrix P represents the uncertainty of the residual r. The covariance boundary block 98 determines whether the residual r is consistent with the remaining data points collected by the corresponding updated sensor 30. Specifically, the residual covariance block 98 predicts the range of variance values ​​based on the error covariance matrix P and compares the residual r with the range of variance values ​​predicted by the error residual covariance matrix P. The range of variance values ​​is inversely proportional to the uncertainty of the residual r. Specifically, a smaller variance indicates smaller uncertainty, while a higher variance indicates larger uncertainty. The range of variance values ​​for the residual r is expressed in Equations 1 and 2 as follows:

[0030] |Residual r k |<Factor*√(Residual r) k (variance) Formula 1

[0031] (residual r) k ) 2 <Factor> 2 *(residual r) k (variance) Formula 2

[0032] Where k is the index of the residual vector, Equation 1 is equivalent to Equation 2, and this factor represents a confidence factor with a value greater than 3. This factor is greater than 3 because if the residual value r is Gaussian distributed, the probability that the residual r is less than three times the square root of the variance of the residual r is 99.73%. However, it can be based on the PNT system 10 ( Figure 1 The distribution of random variables in the model is used to select the value of the factor.

[0033] Covariance boundary block 98 compares the residual r with the corresponding range of variance values ​​predicted by the error covariance matrix P. In response to determining that the residual r does not fall within the corresponding range of variance values, residual covariance boundary block 98 generates an indicator 105, which is sent to persistence counter 100 and isolation and response block 102. In other words, indicator 105 is generated in response to detecting a fault condition for a specific subset 28 of sensors 20, 30. Residual covariance boundary block 98 is configured to prevent yet-to-be or potential fault conditions generated by the corresponding sensors 20, 30 from occurring throughout the PNT system 10. Figure 1 The fault condition is propagated within the range of sensors 20 and 30. Therefore, it should be understood that fault condition containment is achieved while the persistence counter 100 is still running and no fault condition has yet been declared for a specific subset 28 of sensors 20 and 30. Specifically, fault containment is performed by omitting or skipping measurements 60 and 70 for specific sample times.

[0034] It should be understood that when a fault condition is detected but before the persistence counter 100 is persistently triggered to confirm the fault condition, containment is performed. Isolation and response are now described. The persistence counter 100 is configured to maintain a count of the number of times an indicator 105 is generated. When the number of times indicator 105 has been generated exceeds a preselected value, a separate indicator 106 is then generated. The separate indicator 106 confirms one or more corresponding subsets 28 of sensors 20, 30 that are part of the PNT system 10. Figure 3 There is a malfunction.

[0035] A separate indicator 106 is sent to the isolation and response block 102. If the isolation and response block 102 determines a specific sensor 20, 30 as the source of the fault condition, isolation is performed to determine which sensor 20, 30 caused the fault condition. In one embodiment, the response is to take the faulty sensor 20, 30 offline. However, isolation of a specific sensor 20, 30 in Level 2 fault detection may not always be possible. If the fault condition cannot be isolated or traced back to a specific sensor 20, 30, Level 3 fault detection management is performed. That is, in some cases, the navigation module 34 cannot identify the specific faulty sensor 20, 30 as the source of the fault condition. As described below, if the navigation module 34 cannot identify the specific faulty sensor 20, 30, then Level 3 fault detection is performed. It should be understood that Level 2 detection, containment, isolation, and response are performed independently for each individual navigation solution 36, where each navigation module 34 determines the corresponding individual navigation solution 36 in parallel. Therefore, in Level 3, the individual Level 2 results are combined to isolate fault conditions that are impossible in Level 2.

[0036] Return to reference Figure 1The third level (Level 3) fault management will now be described. Level 3 fault management involves a voting process to isolate a fault condition to one or more specific sensors 20, 30. This voting process is performed when one or more sensors 20, 30 that are the source of a fault condition are not isolated at the Level 2 (Level 2) fault detection point. Therefore, Level 3 fault management only involves the isolation and response to fault conditions and does not involve detection or containment. Multiple individual navigation solutions 36 and indicators 105, determined by each navigation module 34, are sent to the voting module 38. The voting module 38 is configured to perform Level 3 fault isolation to determine the faulty sensors 20, 30 based on the voting process. Specifically, the voting module 38 is configured to compare the individual indicators 105 corresponding to each subset 28 of sensors 20, 30 and isolate the fault condition based on the comparison of the individual indicators. Specifically, the voting module 38 isolates the fault condition by identifying the faulty sensor 20, 30 from which the fault condition originates. The voting module 38 determines the faulty sensors 20 and 30 based on the comparison of individual indicators 105, wherein each sensor 20 and 30 is excluded from only one of the subsets 28 of sensors 20 and 30.

[0037] For example, refer to Figure 1 and Figure 3 In one embodiment, each sensor 20, 30, which is part of the PNT system 10, is excluded from one of the subsets 28 of sensors 20, 30. Therefore, when the voting module 38 selects from each subset 28 of sensors 20, 30... Figure 3 When comparing indicator 105 between sensors 20 and 30, all subsets except one of the subsets 28 of sensors 20 and 30 indicate a fault condition. Specifically, the subset 28 of sensors 20 and 30 that eliminates the faulty sensor is the only subset 28 of sensors 20 and 30 that does not include indicator 105. For example, in... Figure 3 In the illustrated embodiment, if a fault condition exists with respect to sensor 1, then each subset 28 of sensors 20 and 30, except for the fifth subset 28 of sensors 20 and 30, will indicate a fault condition. Therefore, the voting module 38 generates a fault signal 112 identifying the faulty sensors 20 and 30.

[0038] refer to Figure 1 The voting module 38 sends a fault signal 112 to the fault analysis module 41. The fault analysis module 41 also communicates electrically with the network monitoring module 42. As described below, the network monitoring module 42 detects one or more GNSS satellites 130, 132 (which communicate wirelessly with the PNT system 10) Figure 5External faults trigger Level 4 (Level 4) fault management. Level 4 (Level 4) fault detection is performed independently of the other three levels of fault detection and is often performed by a geographically distributed external entity that communicates with the exposed PNT system 10 or, alternatively, with another interested PNT user via a network.

[0039] refer to Figure 1 and Figure 5 The fourth level (Level 4) of fault detection management will now be described. Figure 5 As seen, the network monitoring module 42 of the PNT system 10 communicates wirelessly with one or more monitoring systems 44 via the communication network 46. In such a way... Figure 5 In the non-limiting embodiment shown, three monitoring systems 44A, 44B, and 44C are illustrated; however, it should be understood that the network monitoring module 42 can wirelessly communicate with any number of monitoring systems 44. As described below, the disclosed network module 42 determines whether one or more external sources 128 have been compromised. Figure 5 In the illustrated embodiment, one or more external sources 128 include satellites 130, 132. One or more external sources 128 may be compromised in response to one or more of the following: external malfunction, obstruction of signals transmitted or received by one or more satellites, and spoofing of signals transmitted or received by one or more satellites.

[0040] It should be understood that monitoring system 44 can be located remotely from PNT system 10. Each monitoring system 44 is located at a known position at a specific time and includes a corresponding GNSS receiver 124. Furthermore, each monitoring system 44 wirelessly communicates with one or more satellites 130, 132, including GNSS satellites 130 and pseudo-satellites 132. Therefore, PNT system 10 wirelessly communicates with one or more satellites 130 via communication network 46. Each monitoring system 44 is configured to determine a measured pseudorange for each satellite 130, 132, where the measured pseudorange represents the distance between the corresponding monitoring system 44 and a particular satellite 130, 132. Specifically, the corresponding monitoring system 44 determines the measured pseudorange for a particular satellite 130, 132 based on the known position of the corresponding monitoring system 44 at a specific time and ephemeris data associated with the particular satellite 130, 132. The ephemeris data indicates the trajectory of the particular satellite 130, 132, represented as its position changing over time. Ephemeris data is transmitted from specific satellites 130 and 132 to monitoring system 44 via communication network 46.

[0041] The specific monitoring system 44 also receives data representing the actual pseudorange between the monitoring system 44 and specific satellites 130 and 132 from one or more external sources (not shown). It should be understood that the actual pseudorange represents the actual distance between the corresponding monitoring system 44 and the specific satellites 130 and 132. The monitoring system 44 transmits the measured pseudorange determined based on ephemeris data from the specific satellites 130 and 132 and the actual pseudorange determined by one or more external sources to the network monitoring module 42 via the communication network 46. The network monitoring module 42 receives the measured pseudorange and the actual pseudorange as input and determines the difference between the measured pseudorange and the actual pseudorange. The network monitoring module 42 compares the difference between the measured pseudorange and the actual pseudorange with a predetermined maximum error value.

[0042] In response to determining that the difference between the measured pseudorange and the actual pseudorange is greater than a predetermined maximum error value, the network monitoring module 42 determines that a specific satellite 130, 132 has experienced an external fault. An external fault can be caused by any number of problems. For example, an external fault can be caused by errors in ephemeris data, errors in time data, or because the ephemeris data is related to another satellite 130, 132. In another embodiment, an external threat of an external fault represents a blockage or spoofing of GNSS signals, which results in inaccurate data indicated by the GNSS signals. In response to determining that a specific satellite 130, 132 has experienced an external fault, the network monitoring module 42 then sends a message 50 to various platforms 52 that are part of user 12. The various platforms 52 then determine whether to utilize certain resources. For example, in one embodiment, one resource that can be used is a cooperative PNT. That is, in one embodiment, the PNT system 10 is part of a cooperative PNT system 120 that includes two or more cooperative PNTs communicating wirelessly with each other.

[0043] When signals transmitted or received by satellites 130 and 132 are blocked or spoofed, the network module 42 is notified, and this notification may be sent by one of the monitoring systems 44, which is part of the communication network 46. Blocking refers to intentional interference, i.e., the deliberate radiation of electromagnetic signals at GNSS frequencies. In contrast, spoofing refers to the generation and transmission of false GNSS signals with the aim of misleading the GNSS receiver, which may not be aware of the attack.

[0044] In one embodiment, network module 42 also receives advisory information related to communication network 46. For example, the advisory information indicates the presence and resource level of nearby potential network-cooperative PNT systems 120. The resource level indicates the availability of other supplementary sources. Therefore, in response to determining that specific satellites 130, 132 have been damaged, network module 42 performs one or more corrective actions. Corrective actions include, but are not limited to, causing the PNT system 10 ( Figure 1The specific sensors 20 and 30 are taken offline as part of the sensor combination of one or more subsets of the sensors 28, network cooperative PNT is enabled, specific GNSS sources are identified and marked as invalid, and specific PNT resources that may be too costly to operate are disabled or shut down.

[0045] Figures 6A-6C An exemplary process flowchart is shown, illustrating the process for managing [specific processes]. Figure 1 Method 200 for diagnosing fault conditions in the PNT system 10 shown. General Reference Figure 1 , Figure 2 and Figure 6A The method begins at box 202, which starts with Level 1 (Level 1) fault detection. In box 202, sensor extraction / processing modules 22, 32 process the measurements 60, 70 collected by each of the multiple sensors 20, 30 with the corresponding threshold 80 (see...). Figure 2 Individual comparisons are performed to detect fault conditions for specific sensors 20 and 30, wherein measured values ​​60 and 70 are compared individually in the first-level fault detection. Then, method 200 can proceed to block 204.

[0046] In box 204, when the measured values ​​60 and 70 exceed the corresponding threshold 80 ( Figure 2 When a sensor extraction / processing module 22 or 32 determines that a potential fault condition exists for a specific sensor 20 or 30, specifically, as shown in the example... Figure 2 As seen, in response to determining that the measured values ​​60 and 70 exceed the corresponding threshold 80, the comparator 74 generates signal 84. Then, method 200 can proceed to block 206.

[0047] In box 206, in response to the detection of a potential fault condition, containment block 78 ( Figure 2 Potential failure conditions are contained by determining replacement values ​​160 and 170. Then, method 200 can proceed to box 208.

[0048] In box 208, persistence counter 76 ( Figure 2 The number of times a potential fault condition is detected is counted. Then, method 200 can proceed to block 210.

[0049] In block 210, persistence counter 76 compares the number of times a potential fault condition is detected with a predetermined value. When the number of times signal 84 is generated exceeds the predetermined value, the potential fault condition is persistent. Method 200 can then proceed to block 212.

[0050] In decision block 212, if the number of times a potential fault condition is detected does not exceed a predetermined value, method 200 can proceed to block 218. However, in response to determining that the number of times a potential fault condition is detected exceeds the predetermined value, method 200 proceeds to block 214. In block 214, persistence counter 76 determines that a confirmed fault condition exists for a specific sensor 20, 30. Specifically, as... Figure 2 As seen, the persistence counter 76 generates signal 86, which provides persistent confirmation of a potential fault condition. Method 200 can then proceed to block 216.

[0051] In box 216, in response to determining a confirmed fault condition for a particular sensor 20, 30, multiple subsets 28 of sensors 20, 30 are regrouped. As described above, in one example, if redundant sensors exist, they can be used instead of faulty sensors 20, 30. Alternatively, if redundant sensors do not exist, a combination of sensors 20, 30 configured to determine individual navigation solutions 36 is used instead. Method 200 can then proceed to box 218, which... Figure 6B As shown in the image.

[0052] In block 218, method 200 proceeds to a second-level fault detection, which includes determining a plurality of individual navigation solutions 36 corresponding to each of a plurality of subsets of sensors 20, 30, wherein each individual navigation solution 36 is based on a corresponding subset 28 of sensors 20, 30. As described above, each navigation module 34 (see Figure 1 This corresponds to a subset 28 of sensors 20 and 30. Therefore, the number of navigation modules 34 is equal to the number of individual navigation solutions 36. Then, method 200 can proceed to block 220.

[0053] In box 220, as each navigation module 34 ( Figure 1 Part of the inertial navigation block 88 ( Figure 4 The propagation navigation solution 40 is determined based on measurements 60 from a specific propagation sensor 20. As described above, the specific propagation sensor 20 is part of a plurality of sensors 20, 30 corresponding to a specific subset 28 of sensors 20, 30 and a specific navigation module 34. Method 200 can then proceed to block 222.

[0054] In box 222, prediction block 90 ( Figure 4 The propagation-based navigation solution 40 and mathematical model determine the predicted value 172 for the updated sensor 30. As mentioned above, the updated sensor 30 is associated with the specific navigation module 34. Figure 1 This corresponds to a specific subset 28 of the sensors. Then, method 200 can proceed to block 224.

[0055] In box 224, residual block 92 ( Figure 4 The measured value 60 of a specific updated sensor 30 is compared with the predicted value 172 to determine the residual r. The residual block 92 also determines multiple pre-Kalman filtered values ​​corresponding to a specific subset 28 of sensors 20, 30. Method 200 can then proceed to block 226.

[0056] In box 226, Kalman filter 96 ( Figure 4 Based on the pre-Kalman filter processing values, navigation corrections and sensor corrections are determined for the propagation sensor 20 and the updated sensor 30. The Kalman filter 96 determines individual navigation solutions 36 corresponding to specific subsets 28 of sensors 20 and 30 by updating the propagation navigation solution 40 using the navigation corrections and sensor corrections. Method 200 can then proceed to block 228.

[0057] In block 228, residual covariance block 94 determines the residual covariance matrix P corresponding to the residual r. Then, method 200 can proceed to block 230.

[0058] In box 230, residual covariance boundary block 98 predicts the range of variance values ​​based on the measurement variance matrix R(k). As mentioned above, the measurement variance matrix R(k) is one of the values ​​from the pre-Kalman processing. Method 200 can then proceed to box 232.

[0059] In box 232, residual covariance boundary block 98 compares the residual r with the range of variance values. Method 200 can then proceed to decision box 234.

[0060] In decision box 234, if the residual r falls within the range of the variance value, then method 200 proceeds to... Figure 6B Box 252. However, in response to determining that the residual r falls outside the range of the variance value, method 200 proceeds to box 236. In box 236, fault conditions corresponding to a specific subset 28 of sensors 20, 30 are contained. Method 200 can then proceed to box 238, which... Figure 6C As shown in the image.

[0061] In box 238, persistence counter 100 (e.g.) Figure 4 (As shown) The number of times a fault condition is detected is counted. The method then proceeds to box 240.

[0062] In block 240, persistence counter 100 compares the number of times a failure condition has occurred with a pre-selected value. Method 200 can then proceed to decision block 242.

[0063] In decision block 242, persistence counter 100 determines whether the number of times a fault condition has occurred exceeds a preselected value. If the answer is no, method 200 proceeds to block 250. In response to determining that the number of times a fault condition corresponding to a specific subset of sensors has been detected exceeds the preselected value, the method proceeds to block 244. In block 244, persistence counter 100 confirms that the fault condition corresponding to a specific subset 28 of sensors 20, 30 is persistent. Method 200 can then proceed to decision block 246.

[0064] In decision block 246, if isolating the fault condition is possible, method 200 proceeds to block 248. In block 248, isolation and response block 102 isolates one or more sensors 20, 30 that are sources of fault conditions for a specific subset 28 of sensors 20, 30. However, sometimes it may not be possible to isolate the fault condition. Therefore, method 200 may proceed to block 250.

[0065] In block 250, in response to determining that a fault condition corresponding to a specific subset 28 of sensors 20 is persistent, method 200 proceeds to third-level (level 3) fault detection. As described above, third-level (level 3) fault detection involves a voting process for isolating the fault condition to one or more sensors 20, 30. Method 200 can then proceed to block 252, which illustrates fourth-level (level 4) fault detection.

[0066] It should be understood that Level 4 fault detection can be performed separately and independently from the other three remaining levels of fault detection. In block 252, network monitoring module 42 identifies one or more external sources 128 ( Figure 5 Damaged. Figure 5 In the illustrated embodiment, the external sources include satellites 130 and 132. As described above, external source 128 is compromised in response to one of the following: external malfunction, blockage of signals transmitted or received by one or more external sources, and spoofing of signals transmitted or received by one or more external sources. Method 200 can then proceed to block 254.

[0067] In block 254, in response to determining that one or more external sources 128 are damaged, one or more corrective actions are performed. As described above, the corrective actions include making the PNT system 10 ( Figure 1 The specific sensors 20 and 30 are taken offline, the sensor combination of one or more subsets 28 of the sensors is modified, network cooperative PNT is enabled, the specific GNSS source is identified and marked as invalid, and the specific PNT resources that may be too costly to operate are disabled or shut down. Then, method 200 can terminate.

[0068] Referring generally to the accompanying drawings, this disclosure provides various technical effects and benefits. Specifically, this disclosure relates to a PNT system comprising a separate four-level fault management architecture that allows for the detection, containment, isolation, and response to fault conditions. Thus, if one or more sensors malfunction, the disclosed fault architecture prevents the fault condition from propagating throughout the PNT system. In addition to preventing the propagation of fault conditions originating from one or more sensors throughout the PNT system, this disclosure also provides a method for detecting external faults, which may be caused by jamming, spoofing, or errors in data originating from GNSS signals.

[0069] refer to Figure 7 The PNT system 10 is implemented on one or more computer devices or systems, such as the exemplary computer system 1030. The computer system 1030 includes a processor 1032, memory 1034, mass storage device 1036, input / output (I / O) interface 1038, and human-machine interface (HMI) 1040. The computer system 1030 is operatively coupled to one or more external resources 1042 via a network 1026 or I / O interface 1038. External resources may include, but are not limited to, servers, databases, mass storage devices, peripheral devices, cloud-based network services, or any other suitable computer resources that can be used by the computer system 1030.

[0070] Processor 1032 includes one or more devices selected from the following: microprocessor, microcontroller, digital signal processor, microcomputer, central processing unit, field-programmable gate array, programmable logic device, state machine, logic circuit, analog circuit, digital circuit, or any other device that manipulates signals (analog or digital) based on operating instructions stored in memory 1034. Memory 1034 includes a single memory device or multiple memory devices, including but not limited to read-only memory (ROM), random access memory (RAM), volatile memory, non-volatile memory, static random access memory (SRAM), dynamic random access memory (DRAM), flash memory, cache memory, or any other device capable of storing information. Mass storage device 1036 includes data storage devices such as hard disk drives, optical disk drives, magnetic tape drives, volatile or non-volatile solid-state devices, or any other device capable of storing information.

[0071] Processor 1032 operates under the control of operating system 1046 residing in memory 1034. Operating system 1046 manages computer resources so that computer program code implemented as one or more computer software applications (such as application 1048 residing in memory 1034) can have instructions executed by processor 1032. In an alternative example, processor 1032 may directly execute application 1048, in which case operating system 1046 can be omitted. One or more data structures 1049 also reside in memory 1034 and can be used by processor 1032, operating system 1046, or application 1048 to store or manipulate data.

[0072] I / O interface 1038 provides a machine interface that operatively couples processor 1032 to other devices and systems, such as network 1026 or external resource 1042. Application 1048 thereby communicates via I / O interface 1038 to work in concert with network 1026 or external resource 1042 to provide various features, functions, applications, processes, or modules, including those exemplified by this disclosure. Application 1048 also includes program code executed by one or more external resources 1042, or otherwise dependent on functionality or signals provided by other system or network components outside of computer system 1030. In fact, given the virtually limitless possible hardware and software configurations, those skilled in the art will understand that examples of this disclosure may include applications located outside of computer system 1030, applications distributed across multiple computers or other external resources 1042, or applications provided by computing resources (hardware and software) offered as services (such as cloud computing services) via network 1026.

[0073] HMI 1040 is operably coupled to processor 1032 of computer system 1030 in a known manner to allow a user to interact directly with computer system 1030. HMI 1040 may include a video or alphanumeric display, a touchscreen, speakers, and any other suitable audio and visual indicators capable of providing data to the user. HMI 1040 also includes input devices and controls, such as an alphanumeric keypad, a pointing device, a keypad, buttons, control knobs, a microphone, etc., capable of accepting commands or input from the user and transmitting incoming input to processor 1032.

[0074] Database 1044 may reside on mass storage device 1036 and may be used to collect and organize data used by the various systems and modules described herein. Database 1044 may include data and supporting data structures for storing and organizing the data. In particular, database 1044 may be arranged with any database organization or structure, including but not limited to relational databases, hierarchical databases, network databases, or combinations thereof. A database management system in the form of computer software applications whose instructions are executed on processor 1032 may be used to access information or data stored in records in database 1044 in response to queries, wherein the queries may be dynamically determined and executed by operating system 1046, other applications 1048, or one or more modules.

[0075] Furthermore, this disclosure includes embodiments pursuant to the following provisions:

[0076] Clause 1. A positioning, navigation, and timing (PNT) system (10) for a user (12), comprising:

[0077] Multiple sensors (20, 30) are configured to collect measurement results related to the user (12), wherein the multiple sensors (20, 30) are grouped into multiple subsets of sensors (20, 30);

[0078] One or more processors (1032) that communicate electrically with the plurality of sensors (20, 30); and

[0079] A memory (1034) coupled to the one or more processors (1032) stores data in one or more databases (1044) and program code, which, when executed by the one or more processors (1032), causes the PNT system (10) to perform the following operations:

[0080] The measured values ​​(60, 70) collected by each of the plurality of sensors (20, 30) are compared individually with the corresponding threshold (80), wherein the measured values ​​(60, 70) are compared individually in the first-level fault detection.

[0081] When the measured values ​​(60, 70) exceed the corresponding threshold (80), it is determined that there is a potential fault condition for a specific sensor (20, 30);

[0082] In response to the detection of the potential fault condition, the potential fault condition is contained by determining replacement values ​​(160, 170);

[0083] The number of times the potential fault condition is detected is counted;

[0084] The number of times the potential fault condition is detected is compared with a predetermined value;

[0085] In response to determining that the number of times the potential fault condition is detected exceeds the predetermined value, a confirmed fault condition is determined for the specific sensor (60, 70);

[0086] In response to determining the confirmed fault condition for the specific sensor (60, 70), a plurality of subsets (28) of the sensors (20, 30) are regrouped; and

[0087] A second-level fault detection is performed, wherein the second-level fault detection includes determining a plurality of individual navigation solutions (36) corresponding to each of a plurality of subsets of the sensors (20, 30), wherein each individual navigation solution (36) is based on a corresponding subset (28) of the sensors (20, 30).

[0088] Clause 2. The PNT system (10) according to Clause 1, wherein the one or more processors (1032) execute instructions to:

[0089] A propagation navigation solution (40) is determined based on the measurement values ​​(60) from a specific propagation sensor (20), wherein the specific propagation sensor (20) is part of the plurality of sensors (20, 30) corresponding to a specific subset (28) of sensors (20, 30);

[0090] The navigation solution (40) based on the propagation determines a propagation value (172) for an updated sensor (30), wherein the updated sensor (30) is part of a specific subset (28) of the sensors (20, 30); and

[0091] The measured value (70) of the updated sensor (30) is compared with the propagation value (172) to determine the residual.

[0092] Clause 3. The PNT system (10) according to Clause 2, wherein the one or more processors (1032) execute instructions to:

[0093] Determine multiple pre-Kalman filter values ​​(104) corresponding to a specific subset (28) of the sensors (20, 30);

[0094] Based on the multiple pre-Kalman filter values ​​(104), navigation correction and sensor correction are determined for the updated sensor (30) and the propagation sensor; and

[0095] By updating the propagated navigation solution (40) using the navigation correction and the sensor correction, a separate navigation solution (36) corresponding to a specific subset (28) of the sensors (20, 30) is determined.

[0096] Clause 4. The PNT system (10) pursuant to Clause 3, wherein the one or more processors (1032) execute instructions to:

[0097] Determine the residual covariance matrix corresponding to the residual;

[0098] The range of variance values ​​is predicted based on the measurement variance matrix, wherein the measurement variance matrix is ​​one of the plurality of pre-Kalman filter values ​​(104);

[0099] Compare the residual with the range of the variance value; and

[0100] In response to determining that the residual falls outside the range of the variance value, a fault condition corresponding to a specific subset (28) of the sensors (20, 30) is suppressed.

[0101] Clause 5. The PNT system (10) according to Clause 4, wherein suppressing the fault condition corresponding to a specific subset (28) of the sensors (20, 30) includes skipping the measurements (60, 70) for a specific sample time.

[0102] Clause 6. The PNT system (10) pursuant to Clause 4, wherein the one or more processors (1032) execute instructions to:

[0103] The number of times the fault condition is detected is counted;

[0104] Compare the number of times the fault condition corresponding to a specific subset (28) of the sensors (20, 30) is generated; and

[0105] In response to determining that the number of times the fault condition corresponding to a specific subset (28) of the sensors (20, 30) is detected exceeds a preselected value, it is confirmed that the fault condition corresponding to the specific subset (28) of the sensors (20, 30) is persistent.

[0106] Clause 7. The PNT system (10) pursuant to Clause 6, wherein the one or more processors (1032) execute instructions to:

[0107] One or more sensors (20, 30) that are the source of the fault condition for a specific subset (28) of the sensors (20, 30) will be isolated.

[0108] Clause 8. The PNT system (10) pursuant to Clause 6, wherein the one or more processors (1032) execute instructions to:

[0109] In response to determining that the fault condition corresponding to a specific subset (28) of the sensors (20, 30) is persistent, a third-level fault detection is performed, wherein the third-level fault detection involves a voting process for isolating the fault condition to one or more sensors (20, 30).

[0110] Clause 9. The PNT system (10) as described in Clause 8, wherein in the second-level fault detection, one or more sensors (20, 30) that are the source of the fault condition are not isolated.

[0111] Clause 10. The PNT system (10) as described in Clause 1, wherein the PNT system (10) is wirelessly connected to one or more external sources (128).

[0112] Clause 11. The PNT system (10) pursuant to Clause 10, wherein the one or more external sources (128) include at least one of the following: GNSS satellites (130) and pseudo-satellites (132).

[0113] Clause 12. The PNT system (10) pursuant to Clause 10, wherein the one or more processors (1032) execute instructions to:

[0114] The one or more external sources (128) are determined to be damaged in response to one of the following: external failure, blockage of a signal transmitted or received by one of the external sources (128), and spoofing of the signal transmitted or received by the one or more external sources (128).

[0115] Clause 13. The PNT system (10) pursuant to Clause 12, wherein the one or more processors (1032) execute instructions to:

[0116] In response to determining that the one or more external sources (128) are damaged, one or more corrective actions are performed.

[0117] Clause 14. The PNT system (10) pursuant to Clause 13, wherein the PNT system (10) is part of a cooperative PNT system (120) comprising two or more cooperative PNTs that communicate wirelessly with each other.

[0118] Clause 15. The PNT system (10) as described in Clause 14, wherein the correction action includes one or more of the following: taking a specific sensor that is part of the PNT system (10) offline, modifying a sensor combination of one or more subsets of the sensors (20, 30), enabling network cooperative PNT, identifying a specific Global Navigation Satellite System (GNSS) source and marking it as invalid, and disabling and shutting down a specific PNT resource.

[0119] Clause 16. A method (200) for managing fault conditions of a PNT system (10), the method (200) comprising:

[0120] The computer (1030) individually compares the measured values ​​(60, 70) collected by each of the plurality of sensors (20, 30) with the corresponding threshold (80), wherein the measured values ​​(60, 70) are individually compared in the first-level fault detection, and wherein the plurality of sensors (20, 30) are grouped into a plurality of subsets (28) of the sensors (20, 30);

[0121] When the measured values ​​(60, 70) exceed the corresponding threshold (80), the computer (1030) determines that there is a potential fault condition for a specific sensor (20, 30);

[0122] In response to the detection of the potential fault condition, the potential fault condition is contained by determining replacement values ​​(160, 170);

[0123] The number of times the potential fault condition is detected is counted;

[0124] The number of times the potential fault condition is detected is compared with a predetermined value;

[0125] In response to determining that the number of times the potential fault condition has been detected exceeds the predetermined value, a confirmed fault condition is determined for the specific sensor (20, 30);

[0126] In response to determining the confirmed fault condition for the specific sensor (20, 30), a plurality of subsets (28) of the sensors (20, 30) are regrouped; and

[0127] A second-level fault detection is performed, wherein the second-level fault detection includes determining a plurality of individual navigation solutions (36) corresponding to each of a plurality of subsets (28) of the sensors (20, 30), and wherein each individual navigation solution (36) is based on the corresponding subset (28) of the sensors (20, 30).

[0128] Clause 17. The method (200) described in accordance with Clause 16 further includes:

[0129] A propagation navigation solution (40) is determined based on the measurement values ​​(60) from a specific propagation sensor (20), wherein the specific propagation sensor (20) is part of the plurality of sensors (20, 30) corresponding to a specific subset (28) of sensors (20, 30);

[0130] The navigation solution (40) based on the propagation determines a propagation value (172) for an updated sensor (30), wherein the updated sensor (30) is part of a specific subset (28) of the sensors (20, 30); and

[0131] The measured value (70) of the updated sensor (30) is compared with the propagation value (172) to determine the residual.

[0132] Clause 18. The method (200) described in accordance with Clause 17 further includes:

[0133] Determine multiple pre-Kalman filter values ​​(104) corresponding to a specific subset (28) of the sensors (20, 30);

[0134] Based on the multiple pre-Kalman filter values ​​(104), navigation correction and sensor correction are determined for the updated sensor (30) and the propagation sensor (20); and

[0135] By updating the propagated navigation solution (40) using the navigation correction and the sensor correction, a separate navigation solution (36) corresponding to a specific subset (28) of the sensors (20, 30) is determined.

[0136] Clause 19. The method (200) described in accordance with Clause 18 further includes:

[0137] Determine the residual covariance matrix corresponding to the residual;

[0138] The range of variance values ​​is predicted based on the measurement variance matrix, wherein the measurement variance matrix is ​​one of the plurality of pre-Kalman filter values ​​(104);

[0139] Compare the residual with the range of the variance value; and

[0140] In response to determining that the residual falls outside the range of the variance value, a fault condition corresponding to a specific subset (28) of the sensors (20, 30) is suppressed.

[0141] Clause 20. The method (200) according to Clause 19, wherein containing the fault condition corresponding to a specific subset (28) of the sensors (20, 30) includes skipping the measurements (60, 70) for a specific sample time.

[0142] Clause 21. The method (200) described pursuant to Clause 19 further includes:

[0143] The number of times the fault condition is detected is counted;

[0144] Compare the number of times the fault condition corresponding to a specific subset (28) of the sensors (20, 30) is generated; and

[0145] In response to determining that the number of times the fault condition corresponding to a specific subset (28) of the sensors (20, 30) is detected exceeds a preselected value, it is confirmed that the fault condition corresponding to the specific subset (28) of the sensors (20, 30) is persistent.

[0146] Clause 22. The method (200) described in accordance with Clause 21 further includes:

[0147] One or more sensors (20, 30) that are the source of the fault condition for a specific subset (28) of the sensors (20, 30) will be isolated.

[0148] Clause 23. The method (200) described in accordance with Clause 21 further includes:

[0149] In response to determining that the fault condition corresponding to a specific subset (28) of the sensors (20, 30) is persistent, a third-level fault detection is performed, wherein the third-level fault detection involves a voting process for isolating the fault condition to one or more sensors (20, 30).

[0150] Clause 24. The method (200) described in accordance with Clause 16 further includes:

[0151] One or more external sources (128) that are communicating wirelessly with the PNT system (10) are compromised in response to one of the following: external fault, blockage of a signal transmitted or received by one or more external sources, and spoofing of the signal transmitted or received by the one or more external sources (128).

[0152] Clause 25. The method (200) described in accordance with Clause 24 further includes:

[0153] In response to determining that the one or more external sources (128) are damaged, one or more corrective actions are performed.

[0154] Clause 26. The method (200) according to Clause 25, wherein the correction action includes one or more of the following: taking a specific sensor that is part of the PNT system (10) offline, modifying a sensor combination of one or more subsets of the sensors (20, 30), enabling network cooperative PNT, identifying a specific Global Navigation Satellite System (GNSS) source and marking it as invalid, and disabling and shutting down a specific PNT resource.

[0155] The description in this disclosure is exemplary in nature only, and therefore variations without departing from the spirit and scope of this disclosure are intended to fall within its scope. Such variations should not be considered as departing from the spirit and scope of this disclosure.

Claims

1. A positioning, navigation, and timing system (PNT) for users, comprising: Multiple sensors are configured to collect measurements related to the user, wherein the multiple sensors are grouped into multiple subsets of sensors, each subset of sensors including multiple propagation sensors, each propagation sensor including an inertial measurement unit, wherein each of the multiple propagation sensors is configured to collect a measurement associated with one of the following user variables: changes in the user's position, changes in the user's velocity, and changes in the user's attitude. One or more processors, which communicate electrically with the plurality of sensors; as well as A memory coupled to the one or more processors, the memory storing data in one or more databases and program code, the program code causing the PNT system to perform the following operations when executed by the one or more processors: In response to a measurement value collected by a specific propagation sensor exceeding a corresponding threshold, a potential fault condition for the specific propagation sensor among the plurality of propagation sensors is detected in a first-level fault detection, wherein the corresponding threshold depends on the user's user type and the user variable associated with the measurement value of the specific propagation sensor; In response to detecting a potential fault condition of the specific propagation sensor, the potential fault condition is contained by determining a replacement value; The measured value exceeding the corresponding threshold is replaced with the replacement value to prevent the potential fault condition from spreading throughout the PNT system; The number of times the specific propagation sensor detects the potential fault condition is counted; In response to the number of times the potential fault condition is detected exceeding a predetermined value, a confirmed fault condition is determined for the specific propagation sensor; In response to determining the confirmed fault condition for the specific propagation sensor, a plurality of subsets of the sensors are regrouped; as well as A second-level fault detection is performed, wherein the second-level fault detection includes determining a plurality of individual navigation solutions corresponding to each of a plurality of subsets of the sensors, wherein each individual navigation solution is based on the corresponding subset of the sensors.

2. The PNT system of claim 1, wherein each subset of sensors further includes at least one update sensor configured to collect measurements to the user, and wherein the one or more processors execute instructions to: A propagation navigation solution is determined based on the measurements from a first propagation sensor, which is a specific subset of the sensors. The navigation solution based on the propagation determines the first updated sensor prediction for a specific subset of the sensors; as well as The measured value from the first updated sensor is compared with the predicted value to determine the residual.

3. The PNT system of claim 2, wherein the one or more processors execute instructions to: Determine multiple pre-Kalman filter values ​​corresponding to a specific subset of the sensor; Based on the multiple pre-Kalman filter values, navigation correction and sensor correction are determined for at least one updated sensor and the multiple propagation sensors for a specific subset of the sensors; and By updating the propagated navigation solution using the navigation correction and the sensor correction, a separate navigation solution corresponding to a specific subset of the sensors is determined.

4. The PNT system of claim 3, wherein the one or more processors execute instructions to: Determine the residual covariance matrix corresponding to the residual; The range of variance values ​​is predicted based on the measurement variance matrix, wherein the measurement variance matrix is ​​one of the plurality of pre-Kalman filter values; Compare the residual with the range of the variance value; and In response to determining that the residual falls outside the range of the variance value, a fault condition corresponding to a specific subset of the sensor is suppressed.

5. The PNT system of claim 4, wherein the one or more processors execute instructions to: The number of times the fault condition is detected is counted; Compare the number of times the fault condition corresponding to a specific subset of the sensor occurs; In response to determining that the number of times the fault condition corresponding to a specific subset of the sensors is detected exceeds a preselected value, it is confirmed that the fault condition corresponding to the specific subset of the sensors is persistent.

6. The PNT system of claim 5, wherein in the second-level fault detection, one or more sensors that are the source of the fault condition are not isolated.

7. The PNT system according to any one of claims 1 to 6, wherein the PNT system communicates wirelessly with one or more external sources.

8. The PNT system of claim 7, wherein the one or more external sources include at least one of the following: GNSS satellites and pseudo-satellites.

9. The PNT system of claim 7, wherein the one or more processors execute instructions to: The impairment of the one or more external sources is determined in response to one of the following: an external fault, a blockage of a signal transmitted or received by one of the external sources, and spoofing of the signal transmitted or received by the one or more external sources; and wherein the one or more processors execute instructions to: In response to determining that one or more external sources are damaged, one or more corrective actions are performed.

10. The PNT system of claim 9, wherein the PNT system is part of a cooperative PNT system comprising two or more cooperative PNTs that communicate wirelessly with each other; and the correction action comprises one or more of the following: taking a specific sensor that is part of the PNT system offline, modifying a sensor combination of one or more subsets of the sensors, enabling network cooperative PNT, identifying a specific Global Navigation Satellite System source, i.e., a GNSS source, and marking it as invalid, and disabling and shutting down specific PNT resources.

Citation Information

Patent Citations

  • System and method for compensating for faulty measurements

    CN102597701A

  • Fault detection and reconfiguration of an automated refueling boom

    US20080270027A1