A method for calculating monitoring thresholds for differential satellite guidance performance evaluation of dual-motion platforms
By identifying the risk sources of the dual-action platform differential satellite guidance system, setting a risk budget and calculating the protection level, the problem of unreasonable traditional alarm thresholds is solved, the system's dynamic risk allocation and closed-loop verification are realized, and navigation safety and reliability are improved.
Patent Information
- Application Number
- CN202510553160.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-04-29
AI Technical Summary
In the traditional dual-action platform differential satellite guidance system, the alarm threshold is set through the empirical value, resulting in the system alarms being too frequent or not, and there is a lack of quantification methods.
By identifying the risk sources in the dual-action platform differential satellite guidance system, setting the total integrity and continuity risk budget, dynamically allocating the risk budget, and calculating the protection level through standard normal distribution, finally taking the maximum value as the alarm threshold, and risk sources are allocated in combination with the use scenarios of the dual-action platform.
The real-time monitoring capabilities in complex environments are optimized, frequent alarms or insufficient alarms are avoided, and the system's navigation security and reliability are improved.
Smart Images

Figure CN120065258B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of aviation satellite navigation technology, and in particular relates to a method for calculating a monitoring threshold for evaluating the performance of differential satellite guidance of a dual-motion platform. Background Art
[0002] The dual-motion platform consists of a flight terminal and a ground-based mobile terminal that provides a landing platform for the flight terminal. The dual-motion platform's differential satellite guidance system supports approach guidance from both terminals and provides real-time alerting capabilities, effectively improving navigation safety and meeting the high-precision and high-reliability requirements of dual-motion platform guidance equipment. Alert capability is related to the alarm threshold. Traditionally, the alarm threshold has been directly set based on empirical values, resulting in excessively frequent or no alarms. A quantitative method is needed to set the corresponding alarm threshold. Summary of the Invention
[0003] To solve the above problems, the present application provides a method for calculating a monitoring threshold for evaluating the performance of differential satellite guidance of a dual-motion platform, including:
[0004] Step S1: Identify risk sources that affect the performance of the dual-motion platform differential satellite guidance system, including risk sources that affect the flight end and risk sources that affect the ground mobile end;
[0005] Step S2: Set the total integrity risk budget, total continuity risk budget, and reserve budget, with the reserve budget serving as a buffer for unknown risks;
[0006] Step S3: Obtain the priori failure probability of each risk source respectively, calculate the ratio of the priori failure probability of each risk source to the sum of the prior failure probabilities of all risk sources, allocate the remaining total integrity risk budget and total continuity risk budget to each risk source according to the ratio, and obtain the probability value of the integrity risk and the probability value of the continuity risk of each risk source;
[0007] Step S4: Input the probability value of the continuity risk into the inverse function of the standard normal distribution for calculation, multiply the calculation result by the standard deviation of the nominal condition error to obtain the nominal error, divide the probability value of the integrity risk by the prior failure probability of the risk source to obtain the probability of the system not detecting a fault, and substitute the probability of the undetected fault into the inverse function of the standard normal distribution for calculation, and multiply the calculation result by the standard deviation of the error under the condition of the risk source causing the fault to obtain the fault error;
[0008] Step S5: summing the nominal error and the fault error to obtain the protection level;
[0009] Step S6: Take the maximum value of the protection levels of all risk sources as the final protection level of the system;
[0010] Step S7: The final system protection level is used as the alarm threshold.
[0011] Preferably, the risk sources affecting the flight end include: multipath interference, electromagnetic interference and cycle slips; the risk sources affecting the ground mobile end include: baseline deformation, electromagnetic interference, ephemeris error, ionospheric gradient anomaly, receiver failure and multipath interference.
[0012] Preferably, a common risk source of the risk source affecting the flight terminal and the risk source affecting the ground mobile terminal is found, and the priori failure probability of the common risk source is adjusted. The adjustment method includes:
[0013] When the two risk sources of a common risk source are completely correlated, the maximum prior failure probability of the two risk sources is taken as the prior failure probability of the common risk source;
[0014] When two risk sources of a common risk source are partially correlated, the difference between the sum of the prior failure probabilities of the two risk sources and the product of the prior failure probabilities of the two risk sources is taken as the prior failure probability of the common risk source.
[0015] Preferably, the method further includes: step S8: testing the alarm threshold, and when the alarm frequency is higher than the set frequency upper limit or lower than the set frequency lower limit, jumping to step S2.
[0016] Preferably, both the standard deviation of the error under nominal conditions and the standard deviation of the error under the condition of a fault caused by a risk source need to be determined through a fault injection experiment or simulation.
[0017] Preferably, the a priori failure probability of the risk source is obtained through a historical failure data statistics method or an equipment operation parameter modeling method.
[0018] The advantages of this application include: this application improves the traditional protection level calculation method, dynamically allocates integrity risk and continuity risk, and gives priority to high-probability or high-impact risk sources.
[0019] This application considers the risks of both the ground-based and flying terminals, taking into account the use cases of dual-motion platforms. It also allocates risks based on the shared risk sources of both the ground-based and flying terminals. It introduces dynamic risk allocation and closed-loop verification for the dual-motion platform differential system, optimizing real-time monitoring capabilities in complex environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 This is an example diagram of the allocation of risk source indicators affecting the flight end and the ground mobile end in a preferred embodiment of the present application. DETAILED DESCRIPTION
[0021] To make the technical solution and its advantages of the present application clearer, the technical solution of the present application will be described in further detail below in conjunction with the accompanying drawings. It should be understood that the specific embodiments described herein are only some embodiments of the present application and are only used to explain the present application, not to limit the present application. It should be noted that, for ease of description, only the parts related to the present application are shown in the accompanying drawings, and other related parts can refer to the general design. In the absence of conflict, the embodiments of the present application and the technical features in the embodiments can be combined with each other to obtain new embodiments.
[0022] like Figure 1 As shown, the present application provides a dual-motion platform differential satellite guidance performance evaluation monitoring threshold calculation method, including:
[0023] Step S1: Identify risk sources that affect the performance of the dual-motion platform differential satellite guidance system, including risk sources that affect the flight end and risk sources that affect the ground mobile end;
[0024] Step S2: Set the total integrity risk budget, total continuity risk budget, and reserve budget, with the reserve budget serving as a buffer for unknown risks;
[0025] Step S3: Obtain the priori failure probability of each risk source respectively, calculate the ratio of the priori failure probability of each risk source to the sum of the prior failure probabilities of all risk sources, allocate the remaining total integrity risk budget and total continuity risk budget to each risk source according to the ratio, and obtain the probability value of the integrity risk and the probability value of the continuity risk of each risk source;
[0026] Step S4: Input the probability value corresponding to the continuity risk into the inverse function of the standard normal distribution for calculation, and multiply the calculation result by the standard deviation of the error under nominal conditions to obtain the nominal error; divide the probability value corresponding to the integrity risk by the prior failure probability of the risk source to obtain the probability that the system has not detected a fault, and substitute the probability of undetected fault into the inverse function of the standard normal distribution for calculation, and multiply the calculation result by the standard deviation of the error under the condition of failure caused by the risk source to obtain the fault error; among which, the standard deviation of the error under nominal conditions and the standard deviation of the error under the condition of failure caused by the risk source must both be determined through fault injection experiments or simulations.
[0027] The standard deviation of the nominal condition error is the positioning error under normal system operation. Dividing the probability value corresponding to the integrity risk by the prior failure probability of the risk source yields the probability of the system not detecting a fault, which represents the system's tolerance for continuous risk. Substituting the probability of undetected faults into the inverse function of the standard normal distribution and multiplying it by the standard deviation of the error under the risk source-induced fault condition yields the fault error. This converts the probability of undetected faults into a multiple of the corresponding standard deviation, reflecting the potential impact of the fault on the positioning results.
[0028] Among them, the inverse function of the standard normal distribution converts the abstract risk probability into a specific error boundary. The standard deviation of the error under nominal conditions and the standard deviation of the error under the condition of failure caused by the risk source must be determined through fault injection experiments or simulations.
[0029] Step S5: sum the nominal error and the fault error to obtain the protection level; that is, the protection level is a conservative upper limit of the positioning error of the system under both normal operation and specific fault scenarios.
[0030] Step S6: Take the maximum value of the protection levels of all risk sources as the final system protection level. In other words, the final system protection level is also the final global protection level, ensuring that the worst case scenarios of all risk sources are covered.
[0031] Step S7: The final system protection level is used as the alarm threshold.
[0032] Step S8: Test the alarm threshold. When the alarm frequency is higher than the set frequency upper limit or lower than the set frequency lower limit, jump to step S2.
[0033] In some optional embodiments, the risk sources affecting the flight end include: multipath interference, electromagnetic interference and cycle slips; the risk sources affecting the ground mobile end include: baseline deformation, electromagnetic interference, ephemeris error, ionospheric gradient anomaly, receiver failure and multipath interference.
[0034] Identify performance-affecting risk sources in the dual-motion platform differential satellite guidance system, including:
[0035] Sources of space segment risk include: 1) Satellite ephemeris failure: Incorrect ephemeris or undeclared satellite maneuvers may cause the satellite ephemeris to fail to truly represent the satellite orbital position; 2) Low satellite signal power: Excessively low signal power may cause the receiver to lose satellite signal lock or be unable to track; 3) Inter-frequency deviation: Due to the use of dual-frequency differential mode, the inconsistency of clock deviation between different frequency points introduces inter-frequency deviation.
[0036] Risk sources in the atmospheric segment include: 1) Tropospheric storms: Tropospheric storms will introduce spatial signal anomalies, usually occurring in thunderstorms, and introduce large changes in observation errors. The introduced tropospheric delay gradient can be as high as 10 mm / km; 2) Ionospheric gradient anomalies: Solar activity causes ionospheric electron storms. Under severe ionospheric anomaly conditions, the ionospheric second-order terms between the code and carrier, and between different frequencies will introduce nonlinear relationships. The introduced ionospheric delay gradient can be as high as 400 mm / km; 3) Ionospheric scintillation: Ionospheric scintillation events often occur in high latitudes or near the magnetic equator, causing abnormal ionospheric refraction, reducing the signal-to-noise ratio, and sometimes leading to rapid recombination, resulting in a sharp decrease in ionospheric delay; 4) Data transmission deception: Communication links used for data transmission may be attacked and subjected to deceptive interference.
[0037] Risk sources generated at the flight and ground ends include: 1) Baseline deformation: Due to the deformation of the antenna support structure, the movement of the reference receiver antenna introduces a position error relative to the final contact point; 2) Electromagnetic signal interference: Due to the interference signal generated by the electromagnetic radiation source, the signal integrity is reduced; 3) Power interruption: Due to the power interruption of the data transmission equipment, the navigation service will be interrupted; 4) Antenna calibration deviation: Satellite signal switching between different antennas, antenna corrosion or array element damage will introduce antenna calibration error; 5) Receiver failure: Failure of the receiver antenna, low noise amplifier or other modules will cause the receiver measurement error to increase; 6) Multipath: In the case of severe multipath, the reflected signal will cause the direct signal correlation peak to distort and introduce deviation; 7) Cycle slip: Satellite signal obstruction, receiver movement or too low satellite signal-to-noise ratio will cause the signal to lose lock, which in turn causes integer jumps in the carrier phase observation value.
[0038] Because the integrity monitoring fault tree model for dual-motion platform scenarios incorporates multiple risk sources at the signal, data, and information levels, originating from the space and atmospheric segments, as well as the flight / ground side. Hardware technology can be leveraged to mitigate some of these risks, including low signal power, power outages, and data transmission spoofing, within the architecture design of the dual-motion platform differential satellite guidance system. Similarly, software algorithms, such as the wide-narrow lane carrier phase differential two-step relative navigation algorithm, can eliminate nearly all observation errors, with the exception of antenna calibration errors. In summary, while system architecture, hardware design, and navigation algorithm design can eliminate most risk sources for dual-motion platform differential satellite guidance, some remain unavoidable and require real-time assessment and monitoring, including ephemeris failures, ionospheric storms, reference receiver failures, cycle slips, baseline deformation, and electromagnetic signal interference. Differences in the distribution of false alarms and missed detections due to varying prior failure rates of each risk source must be fully considered to optimize this distribution and enable real-time assessment and monitoring.
[0039] In some optional implementations, the method for adjusting the prior failure probability of a common risk source is as follows:
[0040] When the two risk sources of a common risk source are completely correlated, the maximum prior failure probability of the two risk sources is taken as the prior failure probability of the common risk source;
[0041] When two risk sources of a common risk source are partially correlated, the difference between the sum of the prior failure probabilities of the two risk sources and the product of the prior failure probabilities of the two risk sources is taken as the prior failure probability of the common risk source.
[0042] The advantages of this application include: this application optimizes the traditional protection level calculation method, dynamically allocates integrity risk and continuity risk, and gives priority to high-probability or high-impact risk sources.
[0043] This application considers the risks of both the ground-based and flying terminals, taking into account the use cases of dual-motion platforms. It also allocates risks based on the shared risk sources of both the ground-based and flying terminals. It introduces dynamic risk allocation and closed-loop verification for the dual-motion platform differential system, optimizing real-time monitoring capabilities in complex environments.
[0044] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A dual-motion platform differential satellite guidance performance evaluation and monitoring threshold calculation method, characterized in that: include: Step S1: Identify risk sources that affect the performance of the dual-motion platform differential satellite guidance system, including risk sources that affect the flight end and risk sources that affect the ground mobile end; Step S2: Set the total integrity risk budget, total continuity risk budget, and reserve budget, with the reserve budget serving as a buffer for unknown risks; Step S3: Obtain the priori failure probability of each risk source respectively, calculate the ratio of the priori failure probability of each risk source to the sum of the prior failure probabilities of all risk sources, allocate the remaining total integrity risk budget and total continuity risk budget to each risk source according to the ratio, and obtain the probability value of the integrity risk and the probability value of the continuity risk of each risk source; Step S4: Input the probability value of the continuity risk into the inverse function of the standard normal distribution for calculation, and multiply the calculation result by the standard deviation of the nominal condition error to obtain the nominal error; divide the probability value of the integrity risk by the prior failure probability of the risk source to obtain the probability of the system not detecting a fault, and substitute the probability of the undetected fault into the inverse function of the standard normal distribution for calculation, and multiply the calculation result by the standard deviation of the error under the condition of the risk source causing the fault to obtain the fault error; Step S5: summing the nominal error and the fault error to obtain the protection level; Step S6: Take the maximum value of the protection levels of all risk sources as the final protection level of the system; Step S7: The final system protection level is used as the alarm threshold.
2. The dual-motion platform differential satellite guidance performance evaluation and monitoring threshold calculation method according to claim 1, characterized in that: Risk sources affecting the flight end include: multipath interference, electromagnetic interference, and cycle slips; risk sources affecting the ground mobile end include: baseline deformation, electromagnetic interference, ephemeris error, ionospheric gradient anomaly, receiver failure, and multipath interference.
3. The dual-motion platform differential satellite guidance performance evaluation and monitoring threshold calculation method according to claim 2, characterized in that: Find the common risk sources that affect the flight side and the ground mobile side, and adjust the prior failure probability of the common risk sources. The adjustment methods include: When the two risk sources of a common risk source are completely correlated, the maximum prior failure probability of the two risk sources is taken as the prior failure probability of the common risk source; When two risk sources of a common risk source are partially correlated, the difference between the sum of the prior failure probabilities of the two risk sources and the product of the prior failure probabilities of the two risk sources is taken as the prior failure probability of the common risk source.
4. The dual-motion platform differential satellite guidance performance evaluation and monitoring threshold calculation method according to claim 1, characterized in that: The method further includes: Step S8: testing the alarm threshold, and when the alarm frequency is higher than the set frequency upper limit or lower than the set frequency lower limit, jumping to Step S2.
5. The dual-motion platform differential satellite guidance performance evaluation and monitoring threshold calculation method according to claim 1, characterized in that: The standard deviation of the error under nominal conditions and the standard deviation of the error under the condition of failure caused by the risk source are both determined through fault injection experiments or simulations.
6. The dual-motion platform differential satellite guidance performance evaluation and monitoring threshold calculation method according to claim 1, characterized in that: The priori failure probability of the risk source is obtained through historical failure data statistics or equipment operation parameter modeling.
Citation Information
Patent Citations
Threshold determination device, threshold determination method, and program
JP2012103229A
Method for maintaining integrity against erroneous ephemeris for a differential GPS based navigation solution supporting fast system startup
US20140070988A1