METHOD FOR DETERMINING THE PROTECTION LEVEL OF A GNSS-SUPPORT POSITIONING SYSTEM OF A VEHICLE USING A Bayesian FRAMEWORK

Through the Bayesian framework and the probability distribution of training data, the protection level is updated epoch by epoch, which solves the robustness problem of the positioning system under multi-frequency and multi-constellation reception conditions and improves the positioning accuracy and safety of autonomous driving.

CN120671010APending Publication Date: 2025-09-19ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510310011.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-18
Filing Date
2025-03-17
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing methods have difficulty in effectively determining the protection level of vehicle positioning systems under multi-frequency and multi-constellation reception conditions, especially in autonomous driving environments, and cannot meet strict integrity and accuracy requirements. Existing methods also suffer from large position uncertainty and high computational complexity in urban environments.

Method used

A Bayesian framework is adopted to preset the probability distribution of GNSS quality indicators using training data. The protection level is determined epoch by epoch through online processing. Combining the Bayesian theorem and the measured values ​​of GNSS quality indicators, the protection level is gradually updated, reducing dependence on observation errors and increasing signal utilization.

Benefits of technology

Robust protection level determination is achieved under multi-frequency and multi-constellation reception conditions, which reduces computational complexity, improves the safety and accuracy of the positioning system, and adapts to the stringent requirements of autonomous driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671010A_ABST
    Figure CN120671010A_ABST
Patent Text Reader

Abstract

The invention relates to a method for determining a protection level of a GNSS-supported positioning system of a vehicle using a Bayesian framework, comprising the following steps: a) providing at least one first probability distribution of safety-related errors as a function of a GNSS quality indicator by means of training data, the GNSS quality index is specified on the basis of the training data as a random variable of at least one first probability distribution, the values of which can be ascertained epochwise during the travel of the vehicle, the at least one first probability distribution having been stored in advance and can be used to determine a protection level during the travel of the vehicle. And b) determining the protection level during the travel of the vehicle using the following sub-steps: i) ascertaining a value of the respective GNSS quality indicator of the current epoch, ii) ascertaining a posterior distribution from the at least one first probability distribution using the ascertained value of the respective GNSS quality indicator on the basis of the Bayesian theorem; iii) determining a protection level from the posterior distribution of the current epoch; and iv) repeating the sub-steps i) to iii) to determine the protection level of the next epoch.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for determining a protection level for a GNSS-supported positioning system of a vehicle using a Bayesian framework. Furthermore, a control device, a computer program, a machine-readable storage medium, and a positioning system are described. The present invention is particularly applicable to GNSS-supported positioning systems for automated or autonomous driving. Background Art

[0002] It is known that position determination and navigation on Earth and in space can be achieved using the Global Navigation Satellite System (GNSS) by receiving navigation satellite signals. Multi-frequency and multi-constellation reception allows positions on Earth to be determined with centimeter accuracy. The quality of these positions is determined by whether the requirements imposed on them are met, in particular, accuracy, continuity, availability, and integrity.

[0003] What is certain is that integrity and positioning accuracy play an extremely important role in safety-related autonomous driving, as integrity ensures the reliability of positioning accuracy, while imperfect integrity monitoring may lead to catastrophic consequences in safety-related environmental scenarios.

[0004] The term "integrity" was originally introduced for position determination and navigation in air and can be described with respect to position error using the following parameters:

[0005] -AL (Alarm Limit) describes the position tolerance which must not be exceeded. Otherwise a warning message is triggered.

[0006] - TTA (Time to Alarm) describes the maximum allowed time interval that can elapse from exceeding AL to triggering a warning message.

[0007] - IR (Integrity Risk) describes the probability that the position error exceeds AL.

[0008] - PE (position error) describes the deviation between the specified position and the actual position.

[0009] The PL (protection level) describes the position error, wherein the algorithm ensures that this position error is not exceeded without detection.

[0010] - FA (False Alarm) describes an event that triggers a warning message without exceeding AL.

[0011] - MI (Misleading Information) describes the event where PL is less than the position error and PL and position error are less than AL.

[0012] - HMI (Hazardous Misleading Information) describes the event that PL is less than the position error and AL and the position error exceeds AL.

[0013] The parameter “Protection Level” (PL) is the core for integrity monitoring. It can be output together with the position of the positioning system and ensures that the overall system is safe if the position error is below a specified AL.

[0014] Known methods for determining protection levels are typically developed within the ABSA, GBAS, or SBAS concepts, specifically for positioning and navigation in the air (e.g., Greer et al., 2007, Gratton et al., 2010, Zhu et al., 2018). These standardized integrity algorithms are typically defined with consideration given to the reception conditions of flying aircraft and are therefore targeted at autonomous driving. Due to many critical environmental conditions (e.g., in urban environments) and reception conditions (e.g., multipath reception), they are not suitable for positioning and navigation on Earth. Furthermore, the methods developed within the ABSA, GBAS, or SBAS concepts typically refer to single-frequency reception. In contrast, as mentioned at the outset, autonomous driving requires multi-frequency and multi-constellation reception.

[0015] Although the known ARAIM concept (Blanch et al., 2007) has been developed to provide information about failed GNSS satellites, taking into account multi-frequency and multi-constellation reception, and is more robust than ABSA, GBAS, or SBAS concepts due to lower ionospheric transit time delays due to multi-frequency reception and higher measurement redundancy due to multi-constellation reception, it is difficult to use this concept for positioning and navigation on Earth in a method for determining a protection level. In this case, the following challenges exist in particular:

[0016] It is well known that using non-ionospheric (IF) measurements increases the magnitude of uncorrelated errors between frequencies, such as thermal noise, multipath effects or certain distortions. In a typical road environment, this can lead to large position uncertainties.

[0017] Furthermore, GNSS receivers in aviation typically perform phase smoothing in pseudo-regions within 100 seconds to reduce noise and multipath effects. This approach cannot be used in automotive applications, as carrier phase tracking may not be reliably maintained for very long periods of time due to environmental conditions.

[0018] Furthermore, for most planned applications in the automotive industry, stricter AL and TTA are expected than in aviation (typically, AL is in the range of 0.5 to 10 meters and TTA is in the range of 1 second), without necessarily requiring less stringent integrity risk (IR). This means that the typical specifications of the ARAIM concept may result in an overly large PL.

[0019] It is therefore desirable to provide a method for determining a protection level in the context of terrestrial positioning and navigation that can be used not only for multi-frequency and multi-constellation reception but also for determining a robust protection level under critical environmental conditions. This is particularly important for autonomous driving, which places particularly high demands on the security, integrity, or correctness of the positioning information in addition to position accuracy. Summary of the Invention

[0020] To this end, a method for determining a protection level of a GNSS-supported positioning system of a vehicle is proposed, comprising the following steps:

[0021] a) providing at least one first probability distribution of safety-related errors as a function of a GNSS quality indicator using training data, such that the GNSS quality indicator is predefined as a random variable of the at least one first probability distribution based on the training data, and the value of the GNSS quality indicator can be determined epoch by epoch while the vehicle is traveling, wherein the at least one first probability distribution is stored in advance and can be used to determine the protection level while the vehicle is traveling, and

[0022] b) Determine the level of protection while the vehicle is in motion using the following sub-steps:

[0023] i) Obtain the value of the corresponding GNSS quality indicator for the current epoch,

[0024] ii) determining a posterior distribution from at least one first probability distribution using the determined value of the corresponding GNSS quality indicator based on Bayes' theorem;

[0025] iii) determining the protection level from the posterior distribution of the current epoch; and

[0026] iv) Repeat sub-steps i) to iii) to determine the protection level for the next epoch.

[0027] The described method is particularly suitable for autonomous driving. Autonomous driving is understood here to mean, in particular, the forward movement of a vehicle that operates largely autonomously with the aid of a positioning system based on a global navigation satellite system (GNSS). The vehicle can be a motor vehicle, such as a passenger car, a truck or other commercial vehicle, a robot, or the like. It is particularly advantageous if the autonomously driven motor vehicle is equipped with a positioning system for performing the method. The positioning system can be a GNSS-based positioning system or a GNSS- and INS-based positioning system.

[0028] The described method essentially comprises an offline processing part according to step a) and an online processing part according to step b).

[0029] In the offline processing part, according to step a), with the help of training data, at least one first probability distribution of safety-related errors is pre-provided according to the GNSS quality indicator, so that the GNSS quality indicator has been preset as a random variable of the at least one first probability distribution based on the training data, and the value of the GNSS quality indicator can be obtained epoch by epoch during vehicle driving, wherein the at least one first probability distribution has been pre-stored and can be used to determine the protection level during vehicle driving.

[0030] In this context, the probability distribution previously provided using the training data in step a) is referred to as a first probability distribution in order to distinguish it from the probability distribution newly generated later in the online processing portion. Advantageously, the at least one first probability distribution in the form of a software product can be stored in a memory and thus in the online processing portion, i.e., can be read from the memory while the vehicle is traveling and used to determine the protection level.

[0031] Safety-relevant errors can be measurement errors of a GNSS-supported positioning system that must be monitored, such as position errors, velocity errors, or orientation errors. Therefore, the protection level defines error limits, which the GNSS-supported positioning system ensures do not exceed without being detected. When these error limits are exceeded, at least one warning message must be triggered. Therefore, determining the protection level essentially means determining the aforementioned error limits.

[0032] The at least one first probability distribution of the safety-related error can be provided in the form of a multivariate, bivariate and / or univariate conditional distribution. In this case, the GNSS quality indicator can be used as a random variable to provide the at least one first probability distribution.

[0033] GNSS quality indicators are key signals or key quantities of a GNSS system, which can be measured and / or calculated, for example, during vehicle motion using a GNSS-supported positioning system. GNSS quality indicators characterize the quality of the position estimate used for positioning algorithms. Typical GNSS quality indicators are, for example, the Dilution of Precision (DOP). DOP is a measure of the quality of the GNSS signals available under visual conditions and describes the extent to which the GNSS satellites are suitable for position determination in their relative positions. Another typical GNSS quality indicator is, for example, the number of GNSS signals available in the field of view. Since typically at least four GNSS signals are required for position determination, at least five GNSS signals are required for integrity monitoring, and at least six GNSS signals are required to identify defective GNSS satellites, the number of available GNSS signals is also important for positioning quality.

[0034] The type and number of GNSS quality indicators can be preset or predefined in the offline processing portion, for example, IQ1 represents the Dilution of Precision (DOP), IQ2 represents the number of available GNSS signals, and so on. Presetting the GNSS quality indicators is possible because each GNSS system has a plurality of GNSS satellites (e.g., GPS may have 24 GPS satellites) distributed across the sky and moving according to a specific motion pattern. This means that at a specific location, only specific GNSS signals from specific GNSS satellites can be received during a specific time interval. To this end, the motion pattern (e.g., in the form of an almanac and / or ephemeris) is publicly accessible and can be downloaded (e.g., from the International GNSS Service (ISG)).

[0035] Additional environment-related training data (which can be collected, for example, through test drives) can also be used to predefine further GNSS quality indicators, such as the carrier-to-noise ratio. It is advantageous to provide sufficient training data so that it can be aligned with the real data during vehicle driving. In other words, the training data should have the same statistical population as the real data. Furthermore, it should be ensured that the training data is free of reference issues. Based on this training data, the most relevant GNSS quality indicators should be determined.

[0036] The values ​​of the GNSS quality indicators can be measured and / or calculated online in a known manner, for example, using a GNSS-supported positioning system, during the online processing according to step b), i.e., while the vehicle is traveling. Thus, when the corresponding GNSS quality indicator is used as a random variable of at least one first probability distribution in step a), it is possible to convert the at least one first probability distribution into an error conditional distribution using the measured and / or calculated values ​​of the corresponding GNSS quality indicator. Using the newly formed error conditional distribution and based on Bayes' theorem, the protection level can be repeatedly determined epoch by epoch according to step b) and using substeps i) to iv).

[0037] According to sub-step i), the values ​​of the corresponding GNSS quality indicators of the current epoch are obtained. These values ​​can be measured and / or calculated based on the current navigation data and the current sensor data and with the help of filters in the GNSS positioning system.

[0038] According to step ii), based on Bayes' theorem, a posterior distribution is determined from the at least one first probability distribution using the determined values ​​of the corresponding GNSS quality indicators.

[0039] Generally speaking, Bayes' theorem can be described by the following formula:

[0040]

[0041] According to Bayes' theorem, the posterior distribution can be derived by multiplying the likelihood function by the prior distribution. The likelihood function can be derived from one or more error conditional distributions, which can be derived from at least one first probability distribution when determining and specifying the value of the corresponding GNSS quality indicator. The prior distribution can be explicitly assumed using general basic knowledge or reasonable assumptions about symmetric properties. The prior distribution can be defined based on training data and using a parametric distribution.

[0042] According to step iii), the protection level is determined from the posterior distribution of the current epoch. Here, the protection level can be calculated according to the following formula:

[0043]

[0044] Here, PL1 and PL2 are the protection levels to be determined, f(PE) is the posterior distribution determined in substep ii), and IR is the integrity risk. Using the determined integrity risk, namely the target integrity risk (TIR), upper and lower bounds for the posterior distribution f(PE) can be determined according to the above formula. The upper bound corresponds to PL2 and the lower bound corresponds to PL1. Safety-related errors must not exceed these upper and lower bounds undetected. Exceeding these upper and lower bounds must trigger at least one warning message.

[0045] According to step iv), sub-steps i) to iii) are repeated epoch by epoch for determining the protection level.

[0046] Here, an epoch can be understood as the time step in which the position estimated by the GNSS positioning system via GNSS signal reception is updated once. This may mean that substeps i) to iii) are performed once for each position update, so that the currently determined protection level can be output along with the updated position. This may also mean that all parameters relevant to position determination are updated once per epoch. These relevant parameters include GNSS quality indicators, such as the Dilution of Precision (DOP) or the number of GNSS signals available in the field of view.

[0047] Using the method described herein, the protection level of a GNSS-supported positioning system for a vehicle is determined not using a single GNSS signal, as in known methods, but rather, according to the present invention, using multiple GNSS quality indicators. Furthermore, the method described herein is essentially based solely on assumptions about the state error distribution using training data, which has the same statistical population as real data during vehicle operation and can be obtained, for example, through test drives. Therefore, the described method no longer requires theoretical assumptions about the observation error distribution, as is done in the prior art. This means that the protection level is determined using the described method not at the observation level, but at the state level. This has the advantage that more GNSS signals can be used in the state-level analysis using GNSS quality indicators. It also has the advantage that the state errors can be derived more easily and with less uncertainty than the observation errors. Furthermore, the computational effort can be reduced because complex model parameterizations are not required to analyze the observation errors.

[0048] Preferably, in step a), at least one first probability distribution in the form of a multivariate distribution with n+1 random variables is provided, where n is the number of GNSS quality indicators and +1 is the error to be limited. The multivariate distribution is denoted by f(Error, Oi1, Oi2, ... Oin). If the values ​​of the corresponding GNSS quality indicators for the current epoch are determined in substep i), a conditional error distribution f(Error|(Qi1, Qi2 ... Qin)) can be derived. From this conditional error distribution, a likelihood function can be derived, which can then be used to determine the posterior distribution using Bayes' theorem.

[0049] Preferably, at least one first probability distribution in the form of n bivariate distributions is provided in step a), where n is the number of GNSS quality indicators. The bivariate distributions are represented by f1(Error, Qi1), f2(Error, Qi2), ..., fn(Error, Qin). If the value of the corresponding GNSS quality indicator for the current epoch is determined in substep i), the posterior distribution f(Error|Qi1, Qi2...Qin) can be derived according to Bayes' theorem by multiplying n likelihood functions and dividing by the prior probability. The n likelihood functions can be derived from the n bivariate distributions with known values ​​of the corresponding GNSS quality indicators.

[0050] Preferably, at least one first probability distribution in the form of n*q univariate conditional distributions has been provided in step a), where n is the number of GNSS quality indicators and q is the number of bins.

[0051] The univariate conditional distribution is denoted here by f1_q(Error|Qi1∈q), f2_q(Error|Qi2∈q), . . . , fn_q(Error|Qin∈q), where n is the number of GNSS quality indicators and q is the number of bins for the discretization of the corresponding GNSS quality indicator.

[0052] Univariate conditional distributions can be provided using a binning process. Binning is generally understood as dividing the data value range into intervals of equal size, where the intervals can be determined based on specific criteria. Each interval corresponds to a bin. Data points that fall within a specific interval are assigned to the corresponding bin. This classification facilitates analysis and interpretation of the data.

[0053] Using a binning process, the continuous value range of the GNSS quality indicator is discretized into a predetermined number of bins, where the number of bins is denoted by q. Thus, a univariate conditional distribution is derived for each bin. In other words, this means that q univariate conditional distributions f1_q(Error|Qi1∈q) are formed for each GNSS quality indicator, resulting in n*q univariate conditional distributions fn_q(Error|Qin∈q) for each of the n GNSS quality indicators. According to Bayes' theorem, the posterior distribution can be derived by multiplying the likelihood function and dividing it by the prior probability. The likelihood function can be derived from the univariate conditional distributions f1_q(Error|Qi1∈q), f2_q(Error|Qi2∈q), ..., fn_q(Error|Qin∈q).

[0054] Preferably, in step a), the protection level is calculated in advance for each univariate conditional distribution with a given integrity risk and stored. The values ​​of the protection level are then forwarded to the online processing part, where they are combined into the final value of the protection level.

[0055] Preferably, the training data has been tested through test measurements and / or simulations. The training data can be obtained from actual field measurements and / or simulated test data. The simulated test data can be generated, for example, by a GNSS signal generator that can account for various environmental conditions, such as multipath propagation.

[0056] Preferably, the prior distribution is based on training data and is predefined in case a parametric distribution is used.

[0057] Preferably, the safety-relevant error is a position error, a velocity error or an orientation error.

[0058] Preferably, a control device for a GNSS receiver is designed to carry out the method.

[0059] It is also preferred that a computer program is used to execute the method described herein. In other words, this particularly relates to a computer program (product) comprising instructions which, when executed by a computer, cause the computer to execute the method described herein.

[0060] Furthermore, it is preferred to use a machine-readable storage medium on which the computer program proposed here is stored. Typically, a machine-readable storage medium is a computer-readable data carrier.

[0061] Particularly preferably, a positioning system of the vehicle is designed to carry out the method described here. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] The solution proposed here and its technical environment are subsequently explained in detail with the aid of the accompanying drawings. It should be noted that the present invention is not limited to the exemplary embodiments shown. In particular, unless explicitly stated otherwise, partial aspects of the facts illustrated in the drawings can also be extracted and combined with other components and / or findings from other drawings and / or the present description. Schematically and exemplarily:

[0063] Figure 1 shows a graph of the function used for Bayes' theorem,

[0064] Figure 2 a functional graph showing at least one first probability distribution in the form of a bivariate distribution,

[0065] Figure 3 a functional graph showing at least one first probability distribution in the form of a univariate conditional distribution, and

[0066] Figure 4 A block diagram of the described method is shown. DETAILED DESCRIPTION

[0067] Figure 1 A function graph for Bayes' theorem is schematically and exemplarily shown, illustrating the relationship between the error conditional distribution f(PE|Qi1) associated with a specific GNSS quality indicator Qi1, the error conditional distribution f(PE|Qi2) associated with a specific GNSS quality indicator Qi2, the error conditional distribution f(PE|Qi3) associated with a specific GNSS quality indicator Qi3, and the error conditional distribution f(PE|Qi1Qi2Qi3) associated with the GNSS quality indicators Qi1, Qi2, and Qi3. The above-mentioned error conditional distributions and their relationship can also be expressed by the following formula:

[0068]

[0069] Figure 2Three function diagrams of at least one first probability distribution in the form of three bivariate distributions are schematically and exemplarily shown.

[0070] exist Figure 2 It can be seen that three GNSS quality indicators Qi1, Qi2, and Qi3 are preset in the offline processing part, so that a two-variable distribution can be provided for each GNSS quality indicator, namely f(PEx, Qi1)9, f(PEx, Qi2)10, and f(PEx, Qi3)11. Figure 2 The number of GNSS quality indicators in is only an example. When applying the method, less than or more than three GNSS quality indicators may be preset.

[0071] exist Figure 2 It can also be seen that each bivariate distribution 9, 10, 11 has two random variables, namely the error to be limited and the predefined GNSS quality indicator. Therefore, the error probability 13 is distributed two-dimensionally over the error value range 14 and the GNSS quality indicator value range 15.

[0072] Figure 3 A functional diagram of at least one first probability distribution in the form of a univariate conditional distribution is schematically and exemplarily shown.

[0073] exist Figure 3 As can be seen in the figure, starting from the two-variable distribution f(PEx,Qi1)9, multiple univariate conditional distributions f are formed with the help of the binning process. i (PEx|Qi1) 12, where q is the number of bins 16. The continuous GNSS quality indicator value range 15 is discretized into q bins, thereby deriving a univariate conditional distribution 17 for each bin and forming a total of q univariate conditional distributions for the GNSS quality indicator Qi1. For example, for the GNSS quality indicator Qi1, Figure 3 21 univariate conditional distributions are shown (ie, q = 21).

[0074] Figure 4 The data flow of the method is shown schematically and exemplarily. The shown order of method steps a) and b) with blocks 110 and 120 and the shown order of substeps i), ii) and iii) with blocks 210, 220 and 230 is merely exemplary.

[0075] In block 110 , at least one first probability distribution 3 of a safety-related error is provided as a function of the GNSS quality indicator 2 with the aid of the training data 3 , so that the GNSS quality indicator 2 is preset as a random variable of the at least one first probability distribution 3 based on the training data 2 , and the value of the GNSS quality indicator can be determined epoch by epoch during vehicle travel, wherein the at least one first probability distribution 3 has been stored in advance and can be used to determine the protection level during vehicle travel.

[0076] At least one first probability distribution 3 may be provided in one of the following embodiments:

[0077] 1) Multivariate distribution f(Error,Oi1,Oi2,...Oin), where n is the number of GNSS quality indicators and 1 is the error to be constrained,

[0078] 2) n bivariate distributions f1(Error,Qi1), f2(Error,Qi2), ..., fn(Error,Qin), where n is the number of GNSS quality indicators; or

[0079] 3) n*q univariate conditional distributions f1_q(Error|Qi1∈q), f2_q(Error|Qi2∈q), …, fn_q(Error|Qin∈q), where n is the number of GNSS quality indicators and q is the number of bins.

[0080] In block 120 , a protection level is determined during vehicle travel. Substeps i) through iii) may be performed for epoch t to determine the protection level for that epoch. Substeps i) through iii) may also be repeated to determine the protection level for the next epoch t+1.

[0081] In block 210 , sub-step i) is implemented, namely determining a GNSS quality indicator value 4 for epoch t. The value may be measured and / or calculated using a filter in a positioning system supported by the GNSS.

[0082] If at least one first probability distribution is implemented in embodiments 1) and 2), the determined GNSS quality indicator value 4 can be used directly to derive the error condition distribution 6 or the likelihood function.

[0083] If at least one first probability distribution is implemented in embodiment 3), then in block 310, according to additional step α), the GNSS quality indicator value 4 is discretized into a plurality of Qin_BinIDs 5, such as Qi1_BinID, Qi2_BinID, and Qi3_BinID, using bin edges. After the discretization of the GNSS quality indicator value 4, a corresponding likelihood function can be derived for each discretized GNSS quality indicator value 4. This likelihood function is then used to derive a posterior distribution and, therefore, to calculate the protection level in blocks 220 and 230 according to sub-steps ii) and iii).

[0084] Preferably, when performing at least one first probability distribution in embodiment 3), the binning margins may be provided in advance and stored in the first lookup table 7. Therefore, the first lookup table 7 with binning margins can be used to provide at least one first probability distribution 3 in the form of a univariate conditional distribution and also to discretize the GNSS quality indicator value 4 measured online.

[0085] More preferably, when at least one first probability distribution is performed in embodiment 3), n*q univariate conditional distributions may be stored in a second lookup table 8. Therefore, in block 320, according to an additional step β), the error conditional distribution 6, e.g., fi(PEx|Qi1), fi(PEx|Qi2), fi(PEx|Qi3), may be obtained from the second lookup table 8.

Claims

1. A method for determining a protection level of a GNSS-supported positioning system of a vehicle, comprising the following steps: a) providing at least one first probability distribution (3) of a safety-related error as a function of a GNSS quality indicator (2) with the aid of training data (1), such that the GNSS quality indicator (2) is predefined as a random variable of the at least one first probability distribution (3) based on the training data (1), and a value (4) of the GNSS quality indicator can be determined epoch by epoch during the driving of the vehicle, wherein: The at least one first probability distribution (3) has been previously stored and can be used to determine the protection level during driving of the vehicle, and b) determining a protection level during driving of the vehicle using the following sub-steps: i) Obtain the value of the corresponding GNSS quality indicator (4) for the current epoch, ii) determining a posterior distribution from the at least one first probability distribution (3) using the determined value (4) of the corresponding GNSS quality indicator based on Bayes' theorem; iii) determining a protection level from the posterior distribution of the current epoch; as well as iv) Repeating sub-steps i) to iii) to determine the protection level of the next epoch.

2. The method according to claim 1, wherein In step a), the at least one first probability distribution (3) in the form of a multivariate distribution with n+1 random variables has been provided, where n is the number of the GNSS quality indicators (2) and +1 is the error to be limited.

3. The method according to claim 1, wherein In step a), the at least one first probability distribution (3) in the form of n bivariate distributions (9, 10, 11) has been provided, wherein n is the number of the GNSS quality indicators (2).

4. The method according to claim 1, wherein In step a), the at least one first probability distribution (3) in the form of n*q univariate conditional distributions (12, 17) has been provided, wherein n is the number of the GNSS quality indicators (2) and q is the number of bins (16).

5. The method according to claim 4, wherein In step a), the protection level is calculated in advance for each univariate conditional distribution (17) with a given integrity risk and stored.

6. A method according to any one of the preceding claims, wherein The training data (1) has been tested by test measurements and / or simulations.

7. A method according to any one of the preceding claims, wherein The prior distribution is based on the training data (1) and is predefined in case a parametric distribution is used.

8. A method according to any one of the preceding claims, wherein The safety-relevant errors are position errors, speed errors or orientation errors.

9. A control device designed to carry out the method according to any of the preceding claims.

10. A computer program for executing the method according to any one of claims 1 to 8.

11. A machine-readable storage medium having stored thereon the computer program according to claim 10.

12. A positioning system for a vehicle, configured to perform the method according to any one of claims 1 to 8.