METHOD FOR MONITORING AND CONSOLIDATION OF A SATELLITE NAVIGATION SOLUTION

DE602021043790T2Active Publication Date: 2025-12-03THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602021043790
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-17
Filing Date
2021-12-14
Publication Date
2025-12-03
Estimated Expiration
2041-12-14
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to the field of satellite navigation applied to aeronautics. More specifically, the invention relates to a method and a device for monitoring the position of an aircraft in real time and consolidating this position by means of satellite navigation.

[0002] Current GNSS (Global Navigation Satellite System) systems (GPS Navstar, GLONASS, GALILEO, Beidou, etc.) can determine an aircraft's position with an accuracy level on the order of approximately one meter, but they cannot guarantee the accuracy of the calculated position. For example, if a GNSS receiver uses information from a faulty satellite, the calculated position can deviate from a few meters to several kilometers from the aircraft's actual position, potentially leading to dangerous situations. Typically, this can occur during Precision Approach (PA) operations, such as approach phases for a close landing, in which the aircraft uses lateral and vertical guidance based on GNSS data. During these PA operations, the aircraft therefore requires increased accuracy.Thus, an error in the positioning of the aircraft during these critical phases of flight can lead to dangerous situations.

[0003] It may then be decided to combine GNSS systems with an augmentation system. The augmentation system ensures the integrity of the information. There are currently three principles of GNSS augmentation: The ABAS (Airborne Based Augmentation System). The SBAS (Space Based Augmentation System). The GBAS (Ground Based Augmentation System).

[0004] A GNSS system calculates a three-dimensional position from satellite measurements, which can be used for aeronautical navigation and / or approach operations. Typically, the GNSS system associates this position with accuracy and integrity ranges that allow the navigation system to determine the feasibility of the operation by comparing these indicators to limit values. Thus, the integrity limit values ​​are called alert limits (AL), and the integrity ranges are called protection levels (PL). These are determined by taking into account a number of parameters, such as the Signal-in-Space (SIS) integrity allocation for the operation and the failure rates of the satellites used by the GNSS system.

[0005] The Signal In Space (SIS) standards thus characterize the performance requirements for each civil operation along different paths: Continuity refers to the ability of the onboard system to operate without unplanned interruption throughout the entire study period. More precisely, this parameter can be understood as the probability that the system's performance will be maintained throughout the entire flight phase. Integrity corresponds to the measure of confidence that can be placed in the positioning information provided by the navigation system. Integrity requirements are characterized by the following parameters: a horizontal alert limit (HAL), which corresponds to the maximum horizontal position error beyond which the navigation system must be considered unusable; a vertical alert limit (VAL), which corresponds to the maximum vertical position error beyond (above or below) which the navigation system must be considered unusable; and an integrity risk. P HMI which corresponds to the probability that the error in the aircraft's positioning will exceed horizontal and / or vertical protection levels without the navigation system user being alerted. For example, the integrity risk P HMI may be equivalent to a probability of 10-7 representing the probability of a random event in aeronautics.

[0006] All these parameters are defined according to the operation in progress, such as aircraft landing or en-route navigation. All these operations are classified, and many design constraints on the onboard equipment depend on this classification. Therefore, a second classification of requirements related to GNSS equipment can be introduced, where the criticality level takes precedence. This second classification, or FDAL (Functional Development Assurance Level), specifies the development constraints related to obtaining a certified avionics component. This FDAL classification consists of five criticality levels, rated from A (most critical) to E (least critical).

[0007] Thus, GNSS equipment combined with an ABAS system intended for lateral navigation operations where the criticality of integrity failure is considered major can be associated with a Level C FDAL. GNSS equipment used for Category I approach operations where the criticality of integrity failure is considered hazardous can be associated with a Level B FDAL. Finally, GNSS equipment used for Category III approach operations where the criticality of integrity failure is considered catastrophic can be associated with a Level A FDAL.

[0008] However, the cost associated with designing an aeronautical component that meets the FDAL (criticality level) for which the component must be certified increases with the criticality level. Thus, an aeronautical component defined by a level D FDAL is less expensive to design compared to a component defined by a level A FDAL.

[0009] Furthermore, it is not always possible to develop an aeronautical component at the FDAL level required for the operation. However, it is possible to combine several components of a lower FDAL level to replace a component of a higher FDAL level, thus enabling the operation to be performed by implementing a monitoring system for one component using another component.

[0010] Thus, as an example of a possible application, for a function requiring an avionics component whose criticality requires a level C FDAL, a person skilled in the art may choose to use the measurement of a second component or sensor whose criticality level is a level D FDAL and compare the data obtained from this second component to the measurement of a third component or sensor of different design than the second component, i.e. that the third avionics component receives different data from the data received by the second component and works differently compared with the second avionics component while transferring a measurement equivalent to the measurement determined by the second avionics component, and of equivalent design or criticality level, i.e. a level D FDAL.And so, the person skilled in the art can decide to interrupt the operation of the avionics equipment based on the measurements determined by the second and third components if the two measurements obtained are not consistent with each other.

[0011] However, this solution cannot always be implemented, for example when it is not possible to equip an aircraft with GNSS receivers of a different design. This is particularly the case for a receiver using data from satellites of a second constellation, such as Glonass or Galileo, which, compared to GPS satellites, does not provide horizontal and vertical protection levels equivalent to the protection levels obtained by a sensor using data from GPS satellites augmented by an ABAS, SBAS, or GBAS system.

[0012] Document FR 3 006 771 A1 discloses a method for consolidating the solution of a navigation system using two sensors exploiting signals from two distinct satellite constellations (GPS, GLONASS, GALILEO...) and involving a first level of single-constellation consolidation, and a second level of inter-constellation consolidation.

[0013] The invention aims to overcome all or part of the problems mentioned above by proposing a method for consolidating an aircraft's position using satellite navigation. This method provides a robust second level of horizontal and vertical protection against any erroneous data provided by an avionics sensor. Through this mechanism, it is possible to claim an increased level of assurance in the functional development of avionics sensors for position and the associated protection levels.

[0014] The invention also makes it possible to consolidate the level of protection of a first avionics sensor, even if the failure rates of the satellites used by the second sensor do not allow the calculation of autonomous protection levels for the measurement provided by the second sensor.

[0015] To this end, the invention relates to a method for consolidating a satellite navigation solution for an aircraft implementing: a first sensor, including an augmentation system, capable of determining a calculated position x̂ (1) of the aircraft, a characterization of the positioning error of the calculated position x̂ (1) and a horizontal protection level HPL (1)< of the calculated position x̂ (1) , a second sensor, of a different design from the first sensor and of equivalent design level to the first sensor, capable of determining a second position x̂ (2) of the aircraft and a characterization of the second positioning error x̂ (2)< , The consolidation process includes the following steps: Estimating a horizontal gap between the calculated position x̂ (1)< of the aircraft and the second position x̂ (2) of the aircraft, Comparison of the horizontal deviation to a predefined detection threshold, If the horizontal deviation is less than the detection threshold, calculation of an additional horizontal protection level HPL ( MON )< of the calculated position x̂ (1)< from the second position x̂ (2)< , Estimation of a consolidated horizontal protection level HPL ( CON )< depending on the level of additional horizontal protection HPL ( MON )< and the horizontal protection level HPL (1)< ,Comparison of the consolidated horizontal protection level HPL ( CON )< and a previously defined horizontal alert limit HAL, If the consolidated horizontal protection level HPL ( CON )< is less than the horizontal alert limit HAL, horizontal confirmation of the calculated position x̂ (1)< of the aircraft.

[0016] According to one aspect of the invention, the consolidation process comprises an additional step following the horizontal confirmation step of the first position x̂ (1)< , validation of the calculated position x̂ (1)< of the aircraft as consolidated position of the aircraft.

[0017] According to one aspect of the invention, the additional horizontal protection level HPL ( MON )< is calculated from the horizontal gap between the calculated position x̂ (1)< of the aircraft and the second position x̂ (2)< of the aircraft and / or the detection threshold for a positioning anomaly in the horizontal plane, and the characterization of the second positioning error x̂ (2)< .

[0018] According to one aspect of the invention, the augmentation system of the first sensor is an aerial augmentation system (ABAS).

[0019] According to one aspect of the invention, the augmentation system of the first sensor is a Space Augmentation System (SBAS) or a Ground Augmentation System (GBAS).

[0020] According to one aspect of the invention, the first sensor is capable of determining a vertical protection level VPL (1)< .

[0021] According to one aspect of the invention, the consolidation process includes an additional step of calculating an additional level of vertical protection VPL ( MON )< from a vertical difference between the calculated position x̂ (1) of the aircraft and the second position x̂ (2)< of the aircraft and / or the detection threshold for a vertical positioning anomaly, and the characterization of the second positioning error x̂ (2)< following the step of calculating the additional horizontal protection level HPL ( MON )< .

[0022] According to one aspect of the invention, the consolidation process includes an additional step of estimating a consolidated vertical protection level VPL ( CON )< depending on the level of additional vertical protection VPL ( MON )< and the level of vertical protection VPL (1)< following the step of estimating the consolidated horizontal protection level HPL ( CON )< , The consolidation process includes an additional step of comparing the consolidated vertical protection level VPL ( CON and a vertical alert limit VAL previously defined following the comparison step of the consolidated horizontal protection level HPL ( CON )< and the previously defined horizontal alert limit HAL.

[0023] According to one aspect of the invention, the consolidation process includes an additional step of vertical confirmation of the first position x̂ (1)< if the consolidated vertical protection level VPL ( CON )< is less than the vertical alert limit VAL following the horizontal confirmation step.

[0024] According to one aspect of the invention, the detection threshold is calculated based on a continuity allocation.

[0025] The invention also relates to a computer program product, said computer program comprising code instructions enabling the steps of the consolidation process to be carried out when said program is executed on a computer.

[0026] The invention also relates to a processor-readable recording medium on which is recorded a program containing instructions for executing the consolidation process when the program is executed by a processor.

[0027] The invention also relates to a device for consolidating a satellite navigation solution capable of implementing the consolidation process, comprising the first sensor with an augmentation system, capable of determining a calculated position x̂ (1) of the aircraft, a characterization of the positioning error of the calculated position x̂ (1) and a horizontal protection level HPL (1) and the second sensor, of a different design from the first sensor and of equivalent design level to the first sensor, capable of determining a second position x̂ (2) of the aircraft and a characterization of the second positioning error x̂ ( 2 )< .

[0028] The invention will be better understood and other advantages will become apparent upon reading the detailed description of an embodiment given by way of example, a description illustrated by the accompanying drawing in which: [ Fig.1 ] there figure 1 represents a method for consolidating a satellite navigation solution for an aircraft according to the invention; [ Fig.2 ] there figure 2 represents the method for consolidating a satellite navigation solution for an aircraft according to a variant of the invention; [ Fig.3 ] there figure 3 represents a device for consolidating a satellite navigation solution according to the invention;

[0029] For the sake of clarity, the same elements will carry the same markers in the different figures.

[0030] There figure 1 represents a consolidation method for a satellite navigation solution for an aircraft according to the invention. More specifically, the consolidation method for the position of an aircraft is applicable in the context of three-dimensional aircraft position detection operations.

[0031] During an operation using three-dimensional positioning from GNSS satellite measurements, an aircraft may include a first GNSS sensor and a second GNSS sensor of different design and having an identical FDAL level allowing monitoring of the measurements made by the first GNSS sensor by comparing, for example, the measurements obtained in terms of position and / or deviation from trajectory.

[0032] Both the first and second sensors must comply with the integrity risk standard. P HMI , that is to say, having a positioning error rate exceeding the protection levels of the first and second sensors below the required rate.

[0033] Thus, the first sensor is able to associate with a calculated position x̂ (1)< a covariance matrix C (1)< characterizing the positioning error of the calculated position x̂ (1)< associated with the Signal In Space standards stated, a level of horizontal protection ( HPL (1)< ) representing the horizontal insurance space in which the calculated position is included x̂ (1)< for a probability of 1 - P HMI . The horizontal protection level ( HPL (1)< ) spatially represents the radius of a circle on the horizontal plane including the calculated position x̂ (1)< according to a probability of approximately 1 - 10 - 7< . The first sensor includes an ABAS-type augmentation system. However, the first sensor may also include an SBAS or GBAS-type augmentation system.

[0034] The first sensor may possibly be capable of providing a vertical level of protection ( VPL (1)< ) representing the vertical insurance space in which the calculated position is included x̂ (1)< for a probability close to one hundred percent using the augmentation system that complies with the integrity risk standard P HMI .

[0035] The second sensor is capable of providing an estimate of a second position x̂ (2)< as well as a covariance matrix C (2)< characterizing the positioning error of the second position x̂ (2)< associated according to the stated Signal In Space standards.

[0036] The second sensor is not necessarily capable of associating with the estimation of the second position x̂ (2)< horizontal and vertical levels of protection due, for example, to the impossibility of implementing an augmentation system guaranteeing integrity allocation P HMI . However, the second sensor may be capable of providing these levels of protection if it can do so in compliance with Signal In Space standards and, more specifically, by respecting the integrity risk. P HMI .

[0037] As an example, the first GNSS sensor could be a GPS sensor communicating exclusively with the GPS satellite constellation. Indeed, the positioning error rate or failure rate of one or more GPS satellites does not affect the first sensor, which, augmented by an enhancement system, exceeds the standard related to the risk of integrity. P HMI , the GPS sensor can provide a level of horizontal protection ( HPL (1)< ) and, optionally, a level of vertical protection ( VPL (1)< ) .The second GNSS sensor can be a sensor communicating exclusively with a second satellite constellation, such as GLONASS or Galileo. However, in some cases, the failure rate of these satellites prevents the second sensor from providing adequate protection against the risk of data breach. P HMI . Under these conditions, it is no longer possible for the second sensor to provide real-time horizontal and vertical protection levels that comply with Signal-in-Space standards and the integrity risk. P HMI . Thus, the second position x̂ (2)< may not be intrinsically integral with respect to Signal In Space standards since it suffices to have, in addition to the second position x̂ (2)< , the positioning error of the second position x̂ (2)< represented by the covariance matrix C (2)< .

[0038] Indeed, taking the example of the GPS sensor as the first sensor and the Glonass or Galileo sensor as the second sensor, the probability of a failure or positioning error of at least two satellites in the GPS constellation is on the order of 10⁻⁸, which is far lower than the risk of integrity. P HMI of the order of 10⁻⁷ and proves that an event involving the failure of more than two satellites in the GPS constellation communicating with the first GPS sensor is unlikely. Furthermore, the probability of a failure or positioning error of a single satellite in the GPS constellation is approximately 10⁻⁵. Nevertheless, the augmentation system (ABAS, SBAS, or even GBAS) included in the first GPS sensor allows for the identification of the so-called erroneous satellite and thus enables the data from this so-called erroneous satellite to be excluded from the processing of the first GPS sensor.

[0039] Conversely, the probability of a failure or positioning error of at least two satellites in the second constellation may be greater than the integrity risk. P HMI . This implies that it is highly possible that at least two satellites in the second constellation could be so-called erroneous satellites, without it being possible to identify which ones. Thus, the second position x̂ (2)< can be considered as having low integrity but tolerated by the consolidation process 100 as long as the second position x̂ (2)< is accompanied by the uncertainty related to this data or the positioning error of the second position x̂ (2)< represented by the covariance matrix C (2)< . Thus, the 100% consolidation process of a satellite navigation solution has the advantage of being able to monitor or track an initial calculated solution or position. x̂ (1)< of the aircraft integrates by a second solution or second position x̂ (2)< not necessarily complying with Signal In Space integrity standards.

[0040] The consolidation process 100 of a satellite navigation solution for an aircraft then includes a step 101 of estimating a horizontal deviation, that is to say a deviation in the horizontal plane, of distance between the calculated position x̂ (1)< of the aircraft by the first GNSS sensor and the second position x̂ (2)< of the aircraft calculated by the second GNSS sensor.

[0041] This horizontal deviation allows us to translate, as a three-fold absolute value, a difference in aircraft positioning between the first and second GNSS sensors. Generally, the second GNSS sensor provides constant monitoring of the first sensor or GPS sensor to ensure the integrity of the calculated position. x̂ (1)< .

[0042] Thus, a large horizontal deviation can indicate an error in the aircraft's positioning and therefore alert the avionics components and the personnel interacting with these avionics components to the alteration of the calculated position. x̂ (1)< of the aircraft.

[0043] Conversely, a small horizontal deviation confirms the calculated position x̂ (1)< by its consistency with the second position x̂ (2)< of the aircraft.

[0044] After estimating this horizontal deviation in step 101, the consolidation process 100 of the satellite navigation solution compares (step 102) the estimated horizontal deviation with a predefined detection threshold. The detection threshold is generally defined and calculated from a continuity allocation established according to Signal-in-Space continuity standards and the positioning errors of the calculated position. x̂ (1)< and the second position x̂ (2)< . This continuity allocation can be, for example, the probability that any operation defined by continuity and integrity constraints directly linked to Signal-in-Space standards will be interrupted due to a false alarm resulting from satellite signal monitoring devices. This probability can be evaluated based on the specifications and uncertainties of the sensors used or based on the specific characteristics of the satellite constellations communicating with the first and / or second sensor. For example, the error threshold can be determined as follows: T = K fa × σ inc 1 − 2

[0045] Or T represents the detection threshold, K fa represents the probability that the operation will be interrupted due to a false alarm and σ inc 1 − 2 represents the standard deviation between the two solutions, namely the calculated position x̂ (1)< and the second position x̂ (2)< . Thus, this standard deviation can be calculated as follows: σ inc 1 − 2 = C 1 + C 2

[0046] With C (1)< which is the covariance matrix representing the positioning error of the calculated position x̂ (1)< and C (2)< which is the covariance matrix representing the positioning error of the second position x̂ (2)< .

[0047] If the detection threshold is crossed, that is, if the horizontal gap between the calculated position x̂ (1)< and the second position x̂ (2) < is greater than the detection threshold, the consolidation process 100 of the solution triggers an alert (step 110) to interrupt the operation, thus indicating an anomaly related to the alteration of the calculated position x̂ (1)< . This alert (step 110) then allows the current operation to be stopped directly. More precisely, when the alert (step 110) is triggered following the comparison step (step 102) between the estimated horizontal deviation and the detection threshold, it represents an inconsistency related to the calculated position x̂ (1)< .

[0048] Conversely, if no anomaly is detected, that is, if the detection threshold is not exceeded, the solution consolidation process 100 allows the calculation (step 103) of an additional horizontal protection level to begin. HPL ( MON )< from the second position x̂ (2) and the associated positioning uncertainty. The additional horizontal protection level HPL ( MON )< is, like the horizontal protection level ( HPL (1)< ) , a radius of a circle on the horizontal plane including the calculated position x̂ (1)< according to a certain probability, from the second sensor and the second position x̂ (2)< . More precisely, the additional horizontal protection level HPL ( MON )< , which is not the horizontal protection radius of the second position x̂ (2)< since it is not possible to verify the good integrity of the second position x̂ (2)< in accordance with the integrity risk P HMI Due to the potential failure rates of multiple satellites communicating with the second sensor, it is calculated from the horizontal deviation between the calculated position x̂ (1)< and the second position x̂ (2)< estimated during step 101 and / or the detection threshold for a positioning anomaly in the horizontal plane, and the characterization of the positioning error, in the horizontal plane, of the second position x̂ (2)< , represented by the covariance matrix C(2)< .

[0049] Therefore, the consolidation process 100 of the solution initiates an estimation step (step 104) of a consolidated horizontal protection level HPL ( CON )< of the calculated position x̂ (1)< depending on the additional horizontal protection level HPL ( MON )< of the calculated position x̂ (1)< and the horizontal protection level HPL (1)< of the calculated position x̂ (1)< . More specifically, the consolidation process 100 performs a comparison between the additional horizontal protection level HPL ( MON )< and the horizontal protection level HPL (1)< in order to determine the highest level of protection. This comparison can be made, for example, according to the following formula: max HPL 1 HPL MON

[0050] This estimation step 104 of the consolidated horizontal protection level HPL ( CON )< of the calculated position x̂ (1)< allows guaranteeing protection around the calculated position x̂ (1) by maximizing the uncertainty related to the positioning of the calculated position x̂ (1) < induced by possible unlisted errors. Indeed, this estimation step 104 allows us to define the largest radius of the circle on the horizontal plane including the calculated position x̂ (1)< ensuring the best possible position of the aircraft within this enlarged circle to protect against a design error that would lead, for example, to an underestimation of the horizontal protection level HPL (1)< and to excessive confidence in the guidance solution. In this way, the method makes it possible to provide a protection radius at the desired FDAL level because it is consolidated by the use of two different pieces of information from the first sensor and the second sensor.

[0051] This is followed by a comparison (step 105) of the consolidated horizontal protection level HPL ( CON )< and a predefined horizontal alert limit (HAL) based on Signal-in-Space standards and the operation performed. This comparison step 105 verifies whether the consolidated horizontal protection level HPL ( CON )< is greater or not than the aircraft's horizontal alert limit (HAL).

[0052] The horizontal alert limit (HAL) can be a physical standard or an operational constraint, such as a maximum distance not to be exceeded compared to the radius of the circle of the consolidated horizontal protection level. HPL ( CON )< .The International Civil Aviation Organization (ICAO) has established standards related to the horizontal alert limit (HAL) based on aircraft operations. For example, a typical landing phase (NPA) is standardized by a horizontal alert limit (HAL) of 556 meters. For a Category 1 Precision Approach (PA CAT-I), one of the most demanding approach phases in terms of navigation performance, the ICAO standard is 40 meters. This horizontal alert limit (HAL) can then be assessed directly by a person skilled in the art, provided it does not contradict ICAO recommendations.

[0053] If the level of horizontal protection consolidated HPL ( CON If the horizontal position range (HAL) exceeds the horizontal alert limit, the consolidation process 100 triggers the operation interruption alert (step 110), indicating insufficient horizontal performance. This means the position guarantee range is too large relative to the current operation. The operation must then be interrupted because it could pose an immediate danger to the aircraft by alerting flight crew members who interact directly with avionics components.

[0054] Otherwise, that is, if the level of horizontal protection is consolidated HPL ( CON )< of the calculated position x̂ (1) < is less than the horizontal alert limit HAL, then a horizontal confirmation (step 106) of the first position is performed x̂ (1)< of the aircraft. More specifically, this horizontal confirmation step (step 106) makes it possible to know if the operation is feasible in accordance with the various alert limits.

[0055] As mentioned previously, during an NPA approach phase, only lateral guidance is required to allow the aircraft to land. For this type of operation, the first position x̂ (1)< of the aircraft can then be validated (step 108) by at least one avionics component as consolidated aircraft position.

[0056] However, to ensure the integrity of the aircraft's positioning within its environment, and during phases requiring vertical guidance, typically during APV (Approach and Landing Procedures with Vertical Guidance) or PA (Precision Approach) operations using lateral and vertical guidance, the solution's consolidation process can also perform monitoring to observe the integrity of the calculated position. x̂ (1)< according to verticality standards.

[0057] As stated previously, the first sensor can provide a level of vertical protection ( VPL (1)< ) representing the vertical insurance space in which the calculated position is included x̂ (1)< for a probability of 1 - P HMI using the augmentation system included in the first sensor which complies with the standard related to integrity risk P HMI . The level of vertical protection ( VPL (1)< ) represents the half-segment of the vertical axis passing through the aircraft including the calculated position x̂ (1)< according to the first sensor.

[0058] As mentioned previously, the second sensor is not necessarily capable of associating itself with the estimation of the second position. x̂ (2)< horizontal and vertical protection levels.

[0059] Thus, the consolidation process 100 of the solution may include an additional calculation step 1030 of an additional vertical protection level VPL ( MON )< from a vertical deviation, that is to say a deviation in the vertical plane, between the calculated position x̂ (1)< of the aircraft (10) and the second position x̂ (2) and / or the detection threshold for a vertical positioning anomaly, and the characterization of the second positioning error x̂ (2)< represented by the covariance matrix C (2)<. This step involves calculating the additional vertical protection level VPL ( MON )< can be performed following calculation step 103 of the additional horizontal protection level HPL ( MON )< but can also be executed in parallel with calculation step 103 of the additional horizontal protection level HPL ( MON )< . Calculation step 1030 for the additional vertical protection level VPL ( MON )< can also be executed once the horizontal confirmation (step 106) of the calculated position has been completed. x̂ (1)< is executed.

[0060] Similar to the additional horizontal protection level HPL ( MON )< , the additional vertical protection level VPL ( MON )< is calculated from the vertical gap between the calculated position x̂ (1)< and the second position x̂ (2)< estimated, for example, in parallel with the horizontal deviation during step 101, and / or the detection threshold for a positioning anomaly, and the characterization of the positioning error of the second position x̂ (2)< , represented by the covariance matrix C (2)< .

[0061] Following calculation 1030 of the additional vertical protection level VPL ( MON )< , The consolidation process 100 of the solution may include an additional estimation step 1040 of a consolidated vertical protection level VPL ( CON )< depending on the additional vertical protection level i VPL ( MON )< and the level of vertical protection VPL (1)< . This estimation step 1040 can be performed following the estimation step 104 of the consolidated horizontal protection level HPL ( CON )< or can be performed in parallel with the estimation step 104 of the consolidated horizontal protection level HPL ( CON )< . The estimation step 1040 of the consolidated vertical protection level VPL ( CON )< can also be executed once the horizontal confirmation (step 106) of the calculated position has been completed. x̂ (1)< is executed as long as the estimation step 1040 follows the calculation step 1030 of the additional vertical protection level VPL ( MON )< .

[0062] Thus, the consolidation process 100 performs, during this estimation step 1040, a comparison between the level of additional vertical protection VPL ( MON )< of the calculated position x̂ (1)< and the vertical protection level VPL (1)< of the calculated position x̂ (1)< in order to determine the highest level of protection. This comparison can be made, for example, according to the following formula: max VPL 1 VPL MON

[0063] Similar to the consolidated horizontal protection level HPL ( CON )< , the additional vertical protection level VPL ( MON )< allows for ensuring vertical protection around the calculated position x̂ (1) by maximizing the uncertainty related to the positioning of the calculated position x̂ (1) < induced by possible unlisted errors. Indeed, this estimation step 1040 allows defining the largest half-segment in the vertical axis passing through the aircraft including the calculated position x̂ (1)< ensuring the best possible position of the aircraft. In this way, the method makes it possible to provide a protection radius at the desired FDAL level because it is consolidated by the use of two different pieces of information from the first sensor and the second sensor.

[0064] Following this estimation step 1040 of the consolidated vertical protection level VPL ( CON )< , The consolidation process 100 includes an additional step 1050 of comparison of the consolidated vertical protection level VPL ( CON )< and a previously defined vertical alert limit VAL. This comparison step 1050 can be executed following the comparison step 105 of the consolidated horizontal protection level HPL ( CON )< and the horizontal alert limit HAL or can be executed in parallel with the comparison step 105 of the consolidated horizontal protection level HPL ( CON )< and the horizontal alert limit HAL. The comparison step 1050 can also be executed once the horizontal confirmation 106 of the calculated position has been completed. x̂ (1)< is executed as long as the comparison step 1050 follows the estimation step 1040 of the consolidated vertical protection level VPL ( CON )< .

[0065] As with comparison step 105, this comparison step 1050 allows verification of whether the consolidated vertical protection level VPL ( CON )< is less than the vertical alert limit VAL of the operation.

[0066] As with the horizontal alert limit (HAL), the vertical alert limit (VAL) can be a physical standard or an operational constraint, such as a maximum distance not to be exceeded compared to the consolidated vertical protection level. VPL ( CON )< .The International Civil Aviation Organization (ICAO) has established standards related to the vertical warning limit (VAL) based on aircraft operations. For a non-precision approach (NPA) operation, where vertical guidance is not dependent on GNSS, ICAO has not defined a VAL. However, for a Category 1 Precision Approach (PA-CAT I) operation, corresponding to one of the most demanding approach and landing phases in terms of navigation performance, vertical guidance is necessary. Therefore, ICAO sets the VAL between ten and thirty-five meters. This VAL can then be assessed directly by a person skilled in the art, provided it complies with ICAO standards.

[0067] If the level of vertical protection consolidated VPL ( CON If the value exceeds the vertical alert limit VAL, the consolidation process 100 triggers the alert (step 110) to interrupt the operation, indicating an anomaly related to insufficient vertical performance, meaning that the position guarantee space is too large relative to the current operation. The operation must then be interrupted.

[0068] Otherwise, that is, if the level of consolidated vertical protection VPL ( CON )< of the calculated position x̂ (1) < is less than the vertical alert limit VAL, then a vertical confirmation (step 1060) of the first position is performed x̂ (1)< of the aircraft.

[0069] The vertical confirmation step 1060 can be executed following the horizontal confirmation step 106 or can be executed in parallel with the horizontal confirmation step 106 as long as the vertical confirmation step 1060 follows, directly or indirectly, the comparison step 1050.

[0070] Thus, during operations requiring lateral and vertical guidance (PA or APV operation), when horizontal confirmation (step 106) and vertical confirmation (step 1060) are performed, the first position x̂ (1)< of the aircraft can then be validated (step 108) by at least one avionics component as consolidated aircraft position.

[0071] Furthermore, since aircraft positioning is three-dimensional, the horizontal plane can be considered as a plane with a principal axis in the direction of magnetic north and a secondary axis in the direction forming a right angle with the principal axis in the horizontal plane in a clockwise direction, i.e., the direction of east, the third dimension being the vertical axis. The method may include, as shown in figure 2 , calculation sub-steps 1031 and 1032 of an additional horizontal protection level along the main axis, i.e., as a function of the north direction PL N MON which represents the position error limit within which the calculated position is included x̂ (1) with respect to the main axis pointing towards magnetic north and an additional horizontal protection level along the secondary axis, i.e., in the direction of east PL E MON which represents the position error limit within which the calculated position is included x̂ (1)< relative to the secondary axis which points eastward. These sub-steps of calculation 1031 of the additional horizontal protection level along the main axis PL N MON and calculation 1032 of the additional horizontal protection level along the main axis PL E MON can replace step 103.

[0072] Therefore, the estimation step 104 of the consolidated horizontal protection level HPL ( CON )< of the calculated position x̂ (1) < compare the horizontal protection level HPL (1)< of the calculated position x̂ (1)< , the additional horizontal protection level along the main axis PL N MON and additional horizontal protection level along the secondary axis PL E MON . As an example, estimate 104 of the consolidated horizontal protection level HPL ( CON )< can be done according to the following formula: HPL CON = max HPL 1 PL N MON 2 + PL E MON 2

[0073] To be able to perform the consolidation process 100 of the solution, an aircraft 10 may include a consolidation device 1 of a satellite navigation solution as shown in the figure 3 The consolidation device 1 of the satellite navigation solution is capable of implementing the consolidation process 100. The consolidation device 1 includes a first sensor 2, or GPS sensor, comprising an augmentation system, capable of determining the first position x̂ (1) of aircraft 10, the characterization of the positioning error of the calculated position x̂ (1)< and the horizontal protection level HPL (1)< .As mentioned previously, the first sensor 2 can preferably be a GPS sensor communicating exclusively with 20 satellites of the GPS constellation. The consolidation device 1 also includes a second sensor 3 with a different design from the first sensor 2, which is a GPS sensor. This means that the architecture and operation of the second sensor 2 differ from those of the first sensor 2, and / or the data it captures differs from the data captured by the first sensor 2. For example, the second sensor 3 could be a GLONASS or Galileo sensor communicating only with 30 satellites of the GLONASS or Galileo constellation. The second sensor 3 must also have a design level equivalent to the first sensor 2, meaning it must meet the same FDAL criticality standards. Furthermore, the second sensor 3 is capable of determining a second position. x̂ (2)< of aircraft 10 and a characterization of the second positioning error x̂ ( 2)< , represented by the covariance matrix C (2)< positioning errors.

[0074] Furthermore, a computer program may also include code instructions for performing the steps of the consolidation process 100 of the solution when the program is executed on a computer. But the invention may also be applicable to a processor-readable storage medium on which a program containing instructions for executing the consolidation process 100 is stored when the program is executed by a processor.

[0075] This consolidation of the aircraft 10's position can be implemented in a single piece of equipment that integrates the first sensor 2 and the second sensor 3, as well as a device 4 collecting data from the first sensor 2 and the second sensor 3 to monitor the calculated position x̂ (1)< of aircraft 10 and consolidate the associated protection levels before an outward output of navigation information towards the other avionics components of aircraft 10.

[0076] Consolidation can also be implemented with two separate GNSS devices, i.e., the first sensor 2 and the second sensor 3 are not integrated into a single device, as shown in the diagram. figure 2 providing device 4 with the information required for consolidating the output of the first sensor 2, namely the calculated position x̂ (1)< .

[0077] The consolidation device 1 allows, via the consolidation process 100, during operations requiring only lateral guidance, the execution of the estimation steps 101, comparison 102, calculation 103, estimation 104, comparison 105, horizontal confirmation 106, validation 108 and alert 110. In addition, the consolidation device 1 allows, via the consolidation process 100, during operations requiring lateral and vertical guidance, the execution, in addition to the estimation steps 101, comparison 102, calculation 103, estimation 104, comparison 105, horizontal confirmation 106, validation 108 and alert 110, of the calculation steps 1030, estimation 1040, comparison 1050 and vertical confirmation 1060.

Claims

1. Method (100) for consolidating a satellite navigation solution for an aircraft (10) implementing: - a first sensor (2), comprising an augmentation system, adapted to determine a computed position x̂(1) of the aircraft (10), a characterisation of the positioning error of the computed position x̂(1) and a horizontal protection level HPL(1) of the computed position x̂(1), - a second sensor (3), of design different from the first sensor and of design level equivalent to the first sensor (2), the architecture and the operation of the second sensor being different from the architecture and from the operation of the first sensor (2) and / or data captured by the second sensor being different from the data captured by the first sensor (2), the second sensor (3) being adapted to determine a second position x̂(2) of the aircraft (10) and a characterisation of the positioning error of the second position x̂(2), the consolidation method (100) comprising the following steps: a. Estimation (step 101) of a horizontal deviation between the computed position x̂(1) of the aircraft (10) and the second position x̂(2) of the aircraft (10), b. Comparison (step 102) of the horizontal deviation to a previously defined detection threshold, c. If the horizontal deviation is less than the detection threshold, computation (step 103) of an additional horizontal protection level HPL(MON) of the computed position x̂(1) from the second position x̂(2), d. Estimation (step 104) of a consolidated horizontal protection level HPL(CON) as a function of the additional horizontal protection level HPL(MON) and of the horizontal protection level HPL(1), e. Comparison (step 105) of the consolidated horizontal protection level HPL(CON) and of a previously defined horizontal alert limit HAL, f. If the consolidated horizontal protection level HPL(CON) is less than the horizontal alert limit HAL, horizontal confirmation (step 106) of the computed position x̂(1) of the aircraft (10).

2. Method (100) for consolidating a satellite navigation solution according to claim 1, comprising an additional step following the horizontal confirmation step (step 106) of the first position x̂(1), of validation (step 108) of the computed position x̂(1) of the aircraft as the consolidated position of the aircraft (10).

3. Method (100) for consolidating a satellite navigation solution according to any one of claims 1 or 2, wherein the additional horizontal protection level HPL(MON) is computed from the horizontal deviation between the computed position x̂(1) of the aircraft (10) and the second position x̂(2) of the aircraft (10) and / or of the detection threshold of a positioning anomaly in the horizontal plane, and of the characterisation of the positioning error of the second position x̂(2).

4. Method (100) for consolidating a satellite navigation solution according to any one of claims 1 to 3, wherein the augmentation system of the first sensor (2) is an air augmentation system (ABAS).

5. Method (100) for consolidating a satellite navigation solution according to any one of claims 1 to 3, wherein the augmentation system of the first sensor (2) is a space augmentation system (SBAS) or a ground augmentation system (GBAS).

6. Method (100) for consolidating a satellite navigation system according to any one of claims 1 to 5, wherein the first sensor (2) is adapted to determine a vertical protection level VPL(1).

7. Method (100) for consolidating a satellite navigation solution according to any one of claims 1 to 6, comprising an additional step (step 1030) of computing an additional vertical protection level VPL(MON) from a vertical deviation between the computed position x̂(1) of the aircraft (10) and of the second position x̂(2) of the aircraft (10) and / or of the detection threshold of a vertical positioning anomaly, and of the characterisation of the positioning error of the second position x̂(2) following the step (step 103) of computing the additional horizontal protection level HPL(MON).

8. Method (100) for consolidating a satellite navigation solution according to claim 7, comprising an additional step (step 1040) of estimating a consolidated vertical protection level VPL(CON) as a function of the additional vertical protection level VPL(MON) and of the vertical protection level VPL(1) following the step (step 104) of estimating the consolidated horizontal protection level HPL(CON), the consolidation method (100) comprising an additional step (step 1050) of comparing the consolidated vertical protection level VPL(CON) and a previously defined vertical alert limit VAL following the step (step 105) of comparing the consolidated horizontal protection level HPL(CON) and the previously defined horizontal alert limit HAL.

9. Method (100) for consolidating a satellite navigation solution according to claim 8, comprising an additional step (step 1060) of vertically confirming the first position x̂(1) if the consolidated vertical protection level VPL(CON) is less than the vertical alert limit VAL following the horizontal confirmation step (step 106).

10. Method (100) for consolidating a satellite navigation solution according to any one of the preceding claims, wherein the detection threshold is computed as a function of a continuity allocation.

11. Computer program product, said computer program comprising code instructions making it possible to carry out the steps of the method according to any of claims 1 to 10, when said program is executed on a computer.

12. Recording medium which can be read by a processor, on which a program comprising code instructions for executing the method is recorded, according to any one of claims 1 to 10, when the program is executed by a processor.

13. Device (1) for consolidating a satellite navigation solution adapted to implement the consolidation method (100) according to any one of claims 1 to 10, comprising the first sensor (2) comprising an augmentation system, capable of determining a computed position x̂(1) of the aircraft (10), a characterisation of the positioning error of the computed position x̂(1) and a horizontal protection level HPL(1) and the second sensor (3) of design different from the first sensor (2) and of design level equivalent to the first sensor (2), capable of determining a second position x̂(2) of the aircraft (10) and a characterisation of the positioning error of the second position x̂(2).