INTEGRATED PRECISION TIME BROADCASTING SYSTEM
Patent Information
- Application Number
- DE602023005864
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-10-27
- Filing Date
- 2023-10-19
- Publication Date
- 2025-08-20
- Estimated Expiration
- 2043-10-19
AI Technical Summary
Existing methods fail to provide a precise and integrity-guaranteed time service using terrestrial beacons, especially in the presence of accidental failures or malicious acts, and lack integrity control adapted to time transfer systems.
A method for broadcasting time and measuring integrity using a network of synchronized terrestrial beacons, involving pseudo-distance measurements, a maximum likelihood criterion, and a resolution algorithm to detect clock or position biases, with a protection zone defined for time offset integrity.
Ensures precise time synchronization and integrity monitoring, detecting and rejecting biased beacons, guaranteeing a safety interval for time information transmission.
Description
Technical field :
[0001] The invention relates to the field of broadcasting time information by radio frequency from terrestrial beacons, so that a mobile or semi-mobile receiver can have a time service, i.e. a time synchronized with the time of the beacon network. The invention relates in particular to a method for guaranteeing the accuracy of the time service broadcast by the beacon network in the presence of accidental failure (such as a clock failure of a beacon, a synchronization failure of a beacon or a positioning error of a beacon) or malicious acts (such as the movement of a beacon carried out in such a way as to disrupt the measurement), as well as to the raising of an alert as soon as the integrity of the time service no longer meets established standards. Previous technique:
[0002] Sharing a common, high-precision time reference between multiple devices can be essential. This is generally the case when it is necessary to synchronize equipment, such as for time-division multiplexed radio transmissions (TDMA, English acronym for Time Division Multiple Access, or time division multiple access) or code spread (CDMA, English acronym for Code Division Multiple Access, or code division multiple access), or using frequency hopping spreading (FHSS, English acronym for Frequency Hopping Spread Spectrum ). The desired accuracy depends on the intended application, but a standard order of magnitude for desired accuracy is microseconds or less.
[0003] Typically, equipment seeking to determine precise time uses GNSS (Global Navigation System) positioning. Global Navigation Satellite Systems,or global navigation satellite system), which allows a position and time to be precisely determined by measuring a pseudo-distance with at least four satellites, the positions of the satellites being known. However, in some cases, broadcasting a time by a satellite network is not possible. This is the case, for example, when the visibility conditions of the satellites are poor or disturbed, when there are no means of receiving signals from the satellites, or when one does not wish to rely on a GNSS network.
[0004] It is also possible to broadcast precise time information via wired channels, but this solution is not applicable when the equipment is mobile or semi-mobile (i.e. fixed but movable).
[0005] Another solution is to transmit a time marker by three or more terrestrial time transfer beacons over a radio channel. As long as the beacons are precisely synchronized (by wired channels or high-precision clocks) and their positions are transmitted or known to the equipment seeking to determine the network time, it is possible to calculate a distance to each beacon and deduce the position of the equipment. This determination is made in a manner comparable to GNSS positioning, by estimating pseudo-distances to each of the beacons, obtained by measuring the propagation time, then by multilateration from the pseudo-distances.Document FR3114164 discloses a method comprising the determination of an estimated state vector from a measurement vector comprising position measurements of the landmarks, direction measurements of the landmarks and distance measurements and the determination of a test variable, a decentralization value of the distribution law of said variable, a minimum bias detectable from the decentralization value of the test variable and a characteristic vector associated with this type of failure.
[0006] One of the technical problems that is the subject of the invention consists of providing a precise time service, and guaranteeing its integrity by detecting accidental failures of the beacons (such as the failure of the clock of a beacon or its synchronization problems with other beacons or location) or malicious acts (such as the movement of a time transfer beacon).
[0007] Integrity control is a very widespread function in the field of positioning in air navigation, with algorithms of the RAIM type (English acronym for Receiver Autonomous Integrity Monitoring, or autonomous monitoring of the integrity of the receiver). These algorithms are applied to guarantee the position service for navigation based on GNSS (English acronym for Global Navigation Satellite System, or global navigation satellite system) in the face of potential failures of satellite clocks. Their objective is to provide, within a set timeframe, malfunction alerts when the positioning system no longer meets navigation accuracy requirements, for a given probability of non-detection and a given probability of false alarm. They make it possible to determine a protection zone 102 (also called integrity zone) around the aircraft, shown in the figure 1 , defined by HPL protection ( Horizontal Protection Level) along the horizontal axis and VPL protection ( Vertical Protection Level)along the vertical axis. Within the protection zone, the position of the carrier 101 is guaranteed with a given probability of non-detection of error and false alarm. As long as the alert threshold is not crossed and the protection zone 102 is less than an alert zone (or confidence zone) 103, defined by a horizontal alert zone HAL ( Horizontal Alert Limit) along the horizontal axis and a vertical alert zone VAL ( Vertical Alert Limit) along the vertical axis, the integrity of the positioning solution is guaranteed. When the alert threshold is crossed or when the protection zone exceeds the alert zone, the integrity of the positioning measurement is no longer guaranteed under the specified conditions. RAIM GNSS relies on an analysis of pseudo-distances calculated from at least 5 satellites for error detection, and from at least 6 satellites to be able to determine and reject the defective satellite.
[0008] State-of-the-art integrity control methods, adapted for satellite positioning systems, apply to the positioning service but not to the time service, nor to failures based on position biases of the time transfer beacons (for example the malicious movement of a beacon) in addition to failures based on clock biases of the time transfer beacons (following for example a malfunction or deception).
[0009] An aim of the invention is therefore to describe a method for broadcasting time and measuring the integrity of the broadcast time, specifically adapted to the integral transfer of a time by a network of beacons, and for which a protection zone (in the form of an interval on the estimated time offset of the receiver clock) is defined with respect to a possible position or clock bias of one or more time transfer beacons. Summary of the invention:
[0010] To this end, the present invention describes a method for broadcasting time and measuring the integrity of the broadcast time for a receiver in radio frequency connection with at least four synchronized terrestrial time transfer beacons each broadcasting a time message comprising a time marker and a transmission time. The method described comprises: a first step of calculating an arrival time of the time messages transmitted by said terrestrial time transfer beacons, the positions of the terrestrial time transfer beacons being known by the receiver or transmitted to the receiver, and of determining a pseudo-distance measurement associated with each terrestrial time transfer beacon, a second step of implementing a resolution algorithm optimizing a maximum likelihood criterion using the pseudo-distances calculated in the first step and jointly solving the positions of the terrestrial time transfer beacons, the position of the receiver and the time offset of the receiver, a third step of calculating a test variable T equal to the sum of the square of the residuals of the positions of the receiver and the terrestrial time transfer beacons, weighted by variances of the positions of the receiver and the terrestrial time transfer beacons,a fourth step of determining an alert threshold on the test variable T as a function of a given false alarm probability Pfa, and when the test variable T is greater than or equal to the alert threshold, of raising an integrity loss alert, and otherwise a fifth step of determining a non-centrality parameter λ of the test variable T for the false alarm probability Pfa and for a given detection probability Pd, a sixth step of determining a minimum detectable clock bias for each terrestrial time transfer beacon, from the test variable T and the non-centrality parameter λ, a seventh step of determining a minimum detectable position bias for each terrestrial time transfer beacon, from the test variable T and the non-centrality parameter λ,an eighth step of determining a protection zone for the receiver time shift information calculated during the second step, from the minimum detectable biases calculated during the sixth step and the seventh step of the method, and of raising a loss of integrity alert when said protection zone is greater than or equal to an alert zone.
[0011] According to different embodiments, the algorithm using a maximum likelihood criterion implemented during the second step may be a Gauss-Newton algorithm or a Levenberg-Marquardt algorithm.
[0012] According to one embodiment, the second step of the method of broadcasting time and measuring the integrity of the broadcast time of the invention comprises: the construction of a state vector X comprising an estimated position of the receiver, an estimated time offset of the receiver, and estimated positions of the terrestrial time transfer beacons, the construction of an observation vector y comprising the known or transmitted positions of the terrestrial time transfer beacons and the pseudo-distances calculated during the first step, the construction of a linearized observation vector Y comprising a difference between the known or transmitted positions of said at least three terrestrial time transfer beacons and their estimated positions, and a difference between the pseudo-distances calculated during the first step and the pseudo-distances constructed from the values of the state vector X, the construction of a Jacobian matrix H from the state vector X and the observation vector y such as H = ∂ y ∂ X ,and the iterative resolution of the system, by calculating X̂ = H*Y Or H* is the left pseudo-inverse of the Jacobian matrix H.
[0013] According to one embodiment, the test variable T calculated during the third step of the method according to the invention follows a mathematical law of x 2< .
[0014] According to an embodiment of the method for broadcasting time and measuring the integrity of the broadcast time according to the invention, the eighth step of determining a protection zone for the time offset information comprises calculating a maximum estimation error that cannot be detected with a probability greater than or equal to the probability of detection Pd of a clock or position bias of one or more of the terrestrial time transfer beacons.
[0015] According to an embodiment of the method according to the invention in which the receiver is in radiofrequency link with N synchronized terrestrial time transfer beacons each broadcasting a time message comprising a time marker and a transmission time, with N greater than or equal to 5, when a loss of integrity alert is raised during the fourth step or during the eighth step, the method according to the invention is re-implemented successively on each subset of terrestrial time transfer beacons of size N - M, with 1 ≤ M ≤ N - 4, so as to determine a subset of terrestrial time transfer beacons not raising an integrity alert in order to identify the time transfer station(s) affected by a clock bias or a position bias.
[0016] The invention also relates to radiocommunications equipment in radiofrequency connection with at least four synchronized terrestrial time transfer beacons each broadcasting a time message comprising a time marker and a transmission time. This radiocommunications equipment comprises a radio chain configured to receive and interpret the time message transmitted by the beacons. It further comprises calculation means configured to implement a method for broadcasting time and measuring the integrity of the broadcast time according to one embodiment of the invention.
[0017] The invention also relates to a computer program comprising program code instructions for performing the steps of the method of broadcasting time and measuring an integrity of the broadcast time according to an embodiment of the invention when said program is executed on a computer.
[0018] Finally, the invention relates to a computer-readable recording medium on which this computer program is recorded. Brief description of the figures:
[0019] The invention will be better understood and other characteristics, details and advantages will appear more clearly on reading the following description, given without limitation, and thanks to the appended figures, given by way of example. [ Fig. 1 ] There figure 1 illustrates the definition of a time shift information protection zone, and an alert zone around an aircraft. Fig. 2 ] There figure 2 represents an operational configuration in which the method of broadcasting time and measuring the integrity of the broadcast time according to the invention can be implemented. Fig. 3 ] There figure 3schematically represents the steps of a method for broadcasting time and measuring the integrity of the broadcast time according to an embodiment of the invention. Fig. 4 ] There figure 4 gives an example of a false alarm curve and a non-detection curve for a test variable such as that defined in the method of broadcasting time and measuring the integrity of broadcast time according to the invention. Detailed description:
[0020] The invention applies to the case of a network of terrestrial time transfer beacons whose position is known, possibly imperfectly. This application case is frequent when it is a question of deploying a network temporarily on a site in the absence of GNSS service, or in the case of so-called "ad-hoc" networks (decentralized wireless network not based on a fixed architecture of access points). In these networks, each node can act as a time transfer beacon, and thus contributes to the synchronization of the other nodes of the network. Since the nodes may be mobile or movable, their position is not necessarily known very precisely. The accuracy of the broadcast time may then not reach the desired levels of requirement, in particular when the nodes are distant, even when the time transfer beacons are perfectly synchronized.
[0021] There figure 2represents an equipment configuration in which a method for broadcasting time and measuring the integrity of the broadcast time according to the invention can be implemented. It comprises radio communications equipment 201 seeking to synchronize itself temporally with at least four terrestrial time transfer beacons 202 to 205 with which it is in radio link. The terrestrial time transfer beacons can be mobile or fixed, and their positions known precisely or imperfectly.
[0022] In theory, the beacons must be synchronized very precisely, for example by embedding high-precision clocks such as atomic clocks or by being connected to a wired network or a dedicated radio network implementing a precise synchronization mechanism. However, the method according to the invention takes into account possible inaccuracies in the positions of the beacons. It also makes it possible to detect a possible clock or position bias of the time transfer beacons and, provided that the number of beacons is sufficient, to reject this or these beacons.
[0023] Subsequently, the network will be considered to be planar, and the unknowns will only relate to orthogonal positions x and y in a horizontal plane, which is an approximation generally valid in the case of time transfer by terrestrial beacons. Only three time transfer beacons are then necessary to allow radio equipment to retrieve precise time information. However, the invention also applies in three dimensions, by adding the dimension z orthogonal to x and y, in which case a minimum of four stations is required. The addition of additional time transfer stations also makes it possible to improve the quality of the time determination, by smoothing out the measurement noise.
[0024] In order to enable the detection of the presence of a beacon whose position or clock is biased, the method for broadcasting time and measuring the integrity of the broadcast time according to the invention requires at least one additional time transfer beacon, i.e. at least 4 beacons. An additional beacon, i.e. 5 time transfer beacons, makes it possible to identify the biased time transfer beacon.
[0025] The method for broadcasting time and measuring the integrity of broadcast time according to the invention consists in a first step of explicitly taking into account the positions of the time transfer beacons in a least squares estimator in order to jointly estimate the positions of the beacons, the position of the receiver and its temporal bias with respect to the beacon network. Then, the results of the estimator are used with the pseudo-distance measurements to calculate a test variable and compare it with an alert threshold defined from a specified false alarm rate. When the threshold is not exceeded, it then makes it possible to calculate a protection radius associated with the false alarm rate and a detection probability specifically targeting the transfer of time information, then to compare this protection radius with an alert radius.The protection radius is determined by quantifying the minimum detectable biases on the position or clock of one or more of the time transfer beacons. It therefore allows: . to detect a possible inconsistency of the pseudo-distance measurements, for a given probability of false alarm, and with a given probability of detection of a failure; to reject erroneous beacons (subject to sufficient redundancy of the measurements), to guarantee a safety interval, or confidence zone, TAL (English acronym for Time Alert Level, or time alert level) of time information, within which the absence of failure detection is guaranteed to within the detection probability.
[0026] To this end, the method according to the invention identifies failures likely to affect the time transfer service, constructs the corresponding failure models, then implements a specific integrity control algorithm adapted to the broadcasting of time information and to the identified failure models.
[0027] It assumes the existence of a radio waveform suitable for the need for time transfer by broadcasting, i.e. the transmission by the beacons of a time message and a periodic clock pulse, which the radio receiver to be synchronized knows how to receive and measure precisely. The time message contains the time of transmission of the clock pulse, defined according to the reference time of the beacon network. The position of each beacon (potentially imprecise) can be transmitted in the time message, stored in the receiver, or transmitted to the receiver by a data link.
[0028] There figure 3schematically represents the steps of a method for broadcasting time and measuring the integrity of the broadcast time according to an embodiment of the invention. It comprises the following steps: a step 301 of pseudo-distance measurements with at least four terrestrial time transfer beacons, the positions of the terrestrial time transfer beacons being known by the receiver or transmitted to the receiver, and of determining a pseudo-distance measurement PD i associated with each terrestrial time transfer beacon, a step 302 of implementing a resolution algorithm optimizing a maximum likelihood criterion using the pseudo-distances PD i calculated in step 301 and jointly solving the position of the terrestrial time transfer beacons, the position of the receiver and the time offset of the receiver relative to the terrestrial time transfer beacons, a step 303 of calculating a test variable T equal to the sum of the square of the residuals (vector of differences between the observed measurements and the predicted measurements) of the positions of the receiver and the terrestrial time transfer beacons,weighted by variances of the positions of the receiver and the terrestrial time transfer beacons, a step 304 of determining an alert threshold on the variable T, as a function of a given false alarm probability. When the variable T is greater than or equal to the alert threshold, a loss of integrity alert is raised, meaning that one of the beacons is very probably (relative to the false alarm probability) affected by a clock or position bias, and the method can be stopped at this step (for the cycle considered), a step 305 of determining a non-centrality parameter, l of the law of x 2< followed by the test variable T for the given false alarm probability and for a given detection probability, a step 306 of determining a minimum detectable clock bias for each terrestrial time transfer beacon, from the test variable T and the non-centrality parameter l, a step 307 of determining a minimum detectable position bias for each terrestrial time transfer beacon, from the test variable T and the non-centrality parameter λ, a step 308 of determining a protection zone for the receiver time shift information calculated during the second step 302, from the minimum detectable biases calculated in steps 306 and 307, and of comparing the protection zone with an alert zone to determine whether the receiver time shift measurement is intact.
[0029] Step 301 is a usual step for those skilled in the art, which consists of detecting the synchronization pulses in the signals transmitted by the N terrestrial time transfer beacons to determine an arrival time of the signal, and comparing them with their transmission times, transmitted in the time message contained in the signal, in order to calculate a time difference, and consequently a pseudo-distance between the receiver and the terrestrial time transfer beacons with which it is in radio contact.
[0030] The measurements of the arrival times of the time markers follow a normal distribution (0 , σ t ), with s t the standard deviation on the measurements of signal arrival times.
[0031] The pseudo-distance PD i measured between the time transfer beacon i and the receiver is PD i = c(TOA i + Δt - Te i + ε i ) = di + c. Δt + c.ε i , with: TOA i the arrival time of the synchronization pulse in the signal from beacon i, measured by the receiver from its local clock, Te i the time of transmission by the beacon of the synchronization pulse, time measured according to the time reference of the beacon system and transmitted in the time message, Δt the receiver clock bias, i.e. the difference between the beacon system time and the time of the receiver's local clock, ε i a white Gaussian noise affecting measurement i, c the speed of light (speed of propagation of the radio signal), and di the distance between beacon i and the receiver.
[0032] Step 302 consists of simultaneously estimating the position of the carrier, its clock bias Δt and the position of each terrestrial time transfer beacon by an algorithm optimizing a maximum likelihood criterion. This step can be implemented for example by a Gauss-Newton algorithm, well known to those skilled in the art, or by an equivalent least squares resolution algorithm, such as for example a Levenberg-Marquardt algorithm.
[0033] For resolution by a Gauss-Newton algorithm, step 302 includes the construction of a state vector X including the estimated position P̂ r of the receiver, the estimated clock bias Δ t ^ and estimated positions P̂ i terrestrial time transfer beacons, with for example the estimated X̂ of the vector X constructed as follows: X ^ = P ^ r c . Δ t ^ P ^ = P ^ xr P ^ yr c . Δ t ^ P ^ x 1 P ^ y 1 ⋮ P ^ xN P ^ yN ,
[0034] The vector P̂ includes all of P̂ iThe indices x and y are the decomposition of the positions respectively according to the x axis or the y axis of the orthonormal plane in which the measurements are made.
[0035] Subsequently, we will note A i the positions of the terrestrial time transfer beacons known or transmitted to the receiver, P i their exact positions, and A the vector comprising all of the A i , with A i = P i + µ i , µ i being the initial positioning error of the terrestrial time transfer beacon, and PD the vector comprising all pseudodistances PD i.
[0036] Step 302 also includes constructing an observation vector y including positions A i terrestrial time transfer beacons and pseudodistances, or y = A PD , and its linearized counterpart Y including the gap between the positions A iterrestrial time transfer beacons and positions P̂ i estimated at the previous iteration, and the difference between the pseudo-distances PD i and the pseudo-distances constructed from the estimated positions P̂ of the receiver and P̂ i terrestrial time transfer beacons, and estimated time shift Δ t ^ between the receiver and the beacons, or Y = A − P ^ PD − d ^ − c . Δ t ^ = A x 1 − P ^ x 1 A y 1 − P ^ y 1 ⋮ A xN − P ^ xN A yN − P ^ yN PD 1 − d 1 ^ − c . Δ t ^ ⋮ PD N − d N ^ − c . Δ t ^ with d̂ i the distance between the estimated position P̂ of the receiver and the estimated position P̂ i of the earth beacon of index time transfer i , And d̂ the vector constructed from the d̂ i . In the first iteration, the estimated positions P̂ time transfer terrestrial beacons are equal to their known or transmitted positions to the receiver A, and the estimated time shift Δ t ^ is zero.
[0037] The solution to the problem is obtained by solving the equation: Y = HX + ε , Or H is a Jacobian resolution matrix, and ε is centered random noise when terrestrial time transfer beacons are not tainted by clock or position bias. The Jacobian matrix H is worth: H = ∂ y ∂ X = ∂ A ∂ X ∂ PD ∂ X .
[0038] By construction, ∂ A xi ∂ P xi = 1 And ∂ A yi ∂ P yi = 1 . Therefore : ∂ A xi ∂ X = 0 0 … 0 1 0 ⋯ , ∂ A yi ∂ X = 0 0 ⋯ 0 0 1 ⋯ .
[0039] By construction always: ∂ PD i ∂ X = − P ^ yi − P ^ y d ^ i − P ^ xi − P ^ x d ^ i 1 0 0 P ^ yi − P ^ y d ^ i P ^ xi − P ^ x d ^ i 0 0 , so that: H = 0 0 0 1 0 0 0 0 0 ⋮ ⋮ ⋮ ⋮ ⋱ 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 ⋱ 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 − P ^ y 1 − P ^ y d ^ 1 − P ^ x 1 − P ^ x d ^ 1 1 P ^ y 1 − P ^ y d ^ 1 P ^ x 1 − P ^ x d ^ 1 0 0 0 0 ⋮ ⋮ ⋮ ⋮ ⋮ ⋱ ⋱ ⋮ ⋮ − P ^ yN − P ^ y d ^ N − P ^ xN − P ^ x d ^ N 1 0 0 0 0 P ^ yN − P ^ y d ^ N P ^ xN − P ^ x d ^ N
[0040] In the first iteration of the resolution algorithm by optimizing a maximum likelihood criterion, the matrix H is calculated by taking as position P̂from the receiver an initial position estimate obtained by any method, such as for example multilateration on the measured pseudo-distances PD i, or more advantageously by a pseudo-linear estimation method based on a clause form implemented on the measured pseudo-distances, that is to say a form directly giving the desired solution in the absence of noise. The initial positions of the terrestrial time transfer beacons used are the positions A i , known to the receiver or transmitted to it. During the following iterations, the values of the matrix Y and the matrix H are recalculated from the values contained in the state vector X̂ calculated during the previous iteration of the algorithm.
[0041] The observation covariance matrix Γ e is worth: Γ e = Γ μ 0 0 Γ ε , Or : Γ µ is the error covariance matrix on the knowledge of the positions of the beacons, with Γ μ = σ p 2 I 2 N , Or p p is the standard deviation on the measurements of the position coordinates and I 2 N the identity matrix of size 2N, Γ e is the covariance matrix of the pseudo-distance measurements PD i , with Γ ε = E PD ∗ PD t = c 2 σ t 2 I N .
[0042] An efficient estimator is the maximum likelihood estimator. Since the noise is generally assumed to be a centered Gaussian random vector, the maximum likelihood estimator then coincides with the weighted least squares estimator, and has the expression: X ^ = H t Γ ε − 1 H − 1 . H t Γ ε − 1 Y = H * Y .
[0043] The Matrix H* is worth H * = H t Γ ε − 1 H − 1 H t Γ ε − 1 .
[0044] The covariance matrix of the estimator Γ X̂ is worth: Γ X ^ = H t Γ ε − 1 H − 1 .
[0045] The equations given above are formed from matrices arranged in a given organization for illustration purposes only. The same results can be achieved by arranging the matrices in a different way, for example by permuting their rows, without affecting the accuracy of the calculations and the results obtained.
[0046] Step 302 of the method according to the invention performs the joint optimization of the position of the receiver, its clock bias and the positions of the terrestrial time transfer beacons. This joint optimization makes it possible to take into account a possible inaccuracy in the position of the time transfer beacons when calculating the clock bias of the receiver, so as to calculate a time offset. Δ t ^ of the optimal receiver, even when the position of the beacons is imprecise. However, this result is biased when one of the terrestrial time transfer beacons suffers from a position bias or a time bias, since the estimator is built on a centered white Gaussian noise assumption and cannot correct measurements whose noise is outside the assumption, such as non-centered position measurements. In addition, the time transfer stations are considered to be perfectly synchronized. This is why the method according to the invention aims, in the following steps, to determine a protection zone for the time offset information taking into account a possible position or clock bias of the terrestrial time transfer beacons.
[0047] For this purpose, it comprises a third step 303, during which a test variable T is calculated, subsequently used to determine a protection zone for the time shift information around the receiver.
[0048] This variable T is constructed as equal to the sum of the square of the residuals weighted by the variances, that is to say the square of the Mahalanobis distance between the measurement vector Y and theoretical measurements HX̂ associated with the estimated state X̂, either T = Δ Y t . Γ ε − 1 . Δ Y with Δ Y the sum of the square of the residuals, and C e the covariance matrix of the pseudodistance measurements.
[0049] The sum of the square of the (linearized) residuals Δ Y is worth Δ Y = Y - HX̂ = Y - HH*Y = (I - HH*)Y.
[0050] So, by posing G = I − HH ∗ t Γ ε − 1 I − HH ∗ , we a T = Y t< GY.
[0051] When the system is just determined, that is, there are only three time transfer tags, the test variable T is necessarily equal to 0. It is therefore not possible to identify the presence of a bias on one of the tags.
[0052] When the system is overdetermined, i.e. there are more than three time transfer tags, the test variable T follows a distribution of x 2< (chi-2) to K = N - 3 degrees of freedom. We say that T ~ x 2< ( K ) .
[0053] When the measurements are unbiased, Δ Y is centered and the law of x 2< is centered.
[0054] When the position or clock of one of the Earth's time transfer beacons is biased, the law of x 2< is off-center. T then follows a law of x 2< of order K not centered.
[0055] Step 304 of the method according to the invention consists of determining an alert threshold on the variable T, as a function of a given false alarm probability, and raising a loss of integrity alert in the event of this alert threshold being exceeded.
[0056] The calculation of the alert threshold is done by observing the distribution function of the test variable T. The decision threshold T d for the test variable T is positioned relative to a probability of false alarm P fa of the given integrity function, and is worth s 2< , with s the value of the alert threshold on the Mahalanobis distance. A value of T greater than or equal to T d triggers a loss of integrity alert, and generally means, i.e. according to the specified false alarm rate, that one of the terrestrial time transfer beacons is affected by a bias, and that the time service is not intact.
[0057] We have F x 2 ( s2< , K) = 1 - P fa , with F x 2 ( s 2< , K ) the value at the point s 2< of the distribution function of the law of x 2< of order K centered. Therefore: s = F χ 2 − 1 1 − P fa , K .
[0058] The threshold s can therefore be easily determined for the given false alarm probability, thanks to the distribution function of the law of x 2< centered of order K. Since it is a value that does not depend on pseudo-distance measurements, it can also be calculated upstream and stored in memory.
[0059] When the variable T is greater than or equal to the threshold s, an alert is raised and the process can be stopped at this stage (for the cycle considered) since at least one of the measurements made at the terrestrial time transfer beacons is probably biased and the time service is not intact.
[0060] Otherwise, the method comprises a fifth step 305 of determining a non-centrality parameter λ of the test variable T for this same probability of false alarm, and for a given probability of detection. This step comprises the determination of the non-centrality parameter l of the law of x 2< followed by the test variable T for a detection probability Pd specified and for the false alarm probability Pfa. To do this, we use the relationship: F χ 2 s 2 K λ = 1 − P d with F x 2 ( s 2< , K, l ) the distribution function of the law of x 2< of order K off-centered by a parameter l to the point s 2< (determined in the previous step) and Pd the probability of detecting a specified failure (bias in the position or clock measurements of one of the terrestrial time transfer beacons).
[0061] Therefore, the noncentrality parameter l for a given false alarm probability and a given detection probability is: λ = F χ 2 − 1 s 2 , K , 1 − Pd .
[0062] There figure 4 gives an example of threshold positioning s 2< 401 with respect to a given false alarm probability 402, and represents the detection probability 403 of the test variable.
[0063] Subsequently, the impact on the test variable T of two types of bias on the time transfer tags are considered and referenced by an index j: a clock bias ( j = 0) and a position bias ( j = 1).
[0064] The sixth step 306 of the method according to the invention consists in determining the minimum detectable clock bias for each time transfer beacon, from the test variable T and the non-centrality parameter λ, i.e. for the given false alarm probability and detection probability. This step consists in characterizing the minimum detectable bias B min,i,j in the case of a “scalar” bias corresponding to a clock bias ( j = 0) on one of the time transfer tags.
[0065] The bias B i,j clock on the earth beacon of index time transfer i (with i varying between 0 and N) and for a scalar bias model ( j = 0) results on the test variable T by a decentering of the law of x 2< non-centrality parameter λ i,j .
[0066] We have: T B i , 0 = B i , 0 t I − HH ∗ t Γ ε − 1 I − HH ∗ B i , 0 = B i , 0 t GB i , 0 .
[0067] The non-centrality parameter being defined by l and increasing as a function of the bias, we can in particular determine the minimum detectable bias for the failure and the measurement(s) considered, by seeking the solution to the equation: T B min , i , j = λ .
[0068] Failures being characterized by biases in the form B i ,0 = bW i where b is a real scalar and W i is a zero binary vector except at the position of the pseudo-distance measurement relative to the time transfer beacon i considered, we have: B min , i , 0 = λ W i t GW i .
[0069] A bias B i ,0 results in an estimation error Δ X i of the state vector X̂ . When a failure occurs with a bias less than B min,i, 0, the maximum error in the estimation of the state vector is expressed as Δ X max,i, 0 = H*B min,i, 0.
[0070] The seventh step 307 of the method according to the invention consists in determining the minimum detectable position bias for each terrestrial time transfer beacon, from the test variable T and the non-centrality parameter λ, i.e. for the given false alarm probability and detection probability. This step consists in characterizing the minimum detectable bias B min,i,j in the case of a 2D position bias ( j = 1) on a terrestrial time transfer beacon.
[0071] The bias B i ,1 is the sum of a bias on the abscissa and on the ordinate of the position of the transfer beacon, so that: B i , 1 = b x , i . W x , i + b y , i . W y , i Or W x,i (respectively W y,i ) is a zero binary vector except at the x (respectively y) coordinate of the position of the time transfer beacon i considered.
[0072] Position bias B i,1 is translated on the test variable T by a decentering of the law of x 2< , non-centrality parameter l i,1 . A failure of the position measurement of the time transfer beacon i with the smallest detectable bias (i.e. detection probability Pd) verifies: T B min , i , 1 = λ with T B i , 1 = B i , 1 t I − HH * t Γ ε − 1 I − HH * B i , 1 = B i , 1 t GB i , 1 .
[0073] We deduce two possible values of by depending on bx when T ( B ) = l : b y = − G x i y i b x ± G x i y i 2 b x 2 − G y i y i b x 2 G x i x i − λ G y i y i with xi And yes the coordinates of the time transfer earth beacon i.
[0074] The error Δ X associated with bias B i ,1 affecting the state vector X̂ is worth: Δ X i , 1 = H * B i , 1 = b xi , 1 H * W xi , 1 + b yi , 1 H * W yi , 1
[0075] The minimum detectable bias B min,i ,1 = ( B minx,i ,1 , B miny,i ,1) for measurement iin the case of a 2D position bias on a time transfer beacon ( j = 1) corresponding to the estimation bias r i the largest can therefore be determined by finding the maximum of the function r i ( bx ) For bx varying between 0 and B MAXx,i, 1, considering the two possible solutions for by , with B MAXx , i , 1 = λ W xi , 1 t GW xi , 1 W xi , 1 . There is no need to examine the negative solutions of bx because the maximums are identical for the opposite solutions.
[0076] We then have: B min , x , i , 1 = argmax r i b x For 0 ≤ b x ≤ λ W xi , 1 t GW xi , 1 W xi , 1 with r i b = b x H * W xi t + b y H * W yi t the notation V[t] designating the time component of a state vector V, and B miny , i , 1 = − G x i y i B minx , i , 1 ± G x i y i 2 V minx , i , 1 2 − G y i y i B minx , i , 1 2 G x i x i − λ G y i y i .
[0077] The eighth step 308 of the method according to the invention consists of determining an information protection zone Δ̂ treceiver time shift calculated during the second step 302, from the minimum detectable biases calculated in steps 306 and 307, and comparing it with an alert zone (or confidence zone).
[0078] This protection zone associated with the time broadcasting service corresponds to a TPL circle (for Time Protection Level, or temporal protection level) whose radius is equal to the maximum undetectable bias on the estimation of the state vector, associated with the i th< measurement and the j th< type of failure, that is to say: TPL ≈ max i , j H * B min , i , j t with : in the case of a clock bias on a time transfer beacon ( j = 0) B min , i , 0 = λ W i t GW i W i , pour i = 1 , … , N in the case of a position bias on a time transfer beacon ( j = 1) B min , i , 1 = max B min , x , i , 1 H * W xi + b 1 yi H * W yi , b xi H * W xi + b 2 yi H * W yi For i = 1, ... , N, with b 1 y , i = − G xi yi B minx , i , 1 − G xi yi 2 B minx , i , 1 2 − G yi yi B minx , i , 1 2 G xi xi − λ G yi yi b 2 y , i = − G xi yi B minx , i , 1 + G xi yi 2 B minx , i , 1 2 − G yi yi B minx , i , 1 2 G xi xi − λ G yi yi
[0079] In the absence of an alert at the fourth step 304 of the process, the TPL protection zone on the time service is then guaranteed with a probability Pd data (i.e. an integrity risk 1 - Pd ) and a probability of false alarm P fa given as long as the time protection radius is less than the alert boundary, i.e. as long as the protection zone of the time shift information is included in the trust zone (TPL < TAL).
[0080] On the other hand, the time service is no longer guaranteed under the defined integrity conditions when: an alert is triggered, i.e. when T > Td (fifth step of the process), and / or TPL ≥ TAL.
[0081] The method of broadcasting time and measuring the integrity of broadcast time described above makes it possible to detect the presence of a position or synchronization bias on one of the terrestrial time transfer beacons. When the number of beacons is greater than or equal to 5, it also makes it possible to determine and reject the biased beacon.
[0082] For this, when the test variable T exceeds the alert threshold Td (fourth step 304 of the method according to the invention) or when the protection zone (or integrity zone) TPL defined in the eighth step 308 of the method according to the invention is greater than or equal to the alert zone (or confidence zone) TAL, the method is repeated N times, each time considering the signals coming from a group of N- 1 different beacons. Only one of these tests will result in both an absence of alert on the test variable and the definition of a protection zone smaller than the alert zone, which makes it possible to directly identify the biased time transfer beacon. This beacon can then be excluded from the implementation of the time transfer method according to the invention, which makes it possible to ensure the time service with greater precision.
[0083] The same principle can be extended to the determination of sets of M terrestrial time transfer beacons affected by a position or time bias, by implementing the method on groups of beacons so as to successively exclude each possible set of M beacons, provided that N - M is greater than or equal to 4.
[0084] The invention therefore relates to a method for broadcasting time and measuring the integrity of the broadcast time for a terminal receiving radiofrequency signals with at least four synchronized terrestrial time transfer beacons each broadcasting a time message comprising a time marker and a transmission time, but also on the terminal itself.
[0085] Such a terminal must have a radio channel enabling it to receive and interpret the time message broadcast by the beacons to determine the arrival time of time markers, and calculation means enabling it to implement the process, such as for example a microprocessor, a DSP (English acronym for Digital Signal Processor, or digital signal processor), an FPGA (English acronym for Field Programmable Gate Array, or programmable gate array), an ASIC (English acronym for Application-Specific Integrated Circuit,or application-specific integrated circuit), any combination of these means, or any hardware component capable of performing the aforementioned functions.
[0086] Finally, it relates to a computer program comprising program code instructions for executing the steps of the method for broadcasting time and measuring the integrity of the broadcast time according to the invention when said program is executed on a computer, as well as to a recording medium readable by a computer on which such a computer program is recorded.
Claims
1. A method for broadcasting time and for measuring the integrity of the broadcast time for a receiver (101) communicating over radiofrequencies with at least four synchronised terrestrial time transfer beacons (102, 103, 104) each broadcasting a time message comprising a time marker and a transmission time, the method for broadcasting time and for measuring the integrity of the broadcast time being characterised in that it comprises: - a first step (301) of computing a time of arrival of the time messages transmitted by said terrestrial time transfer beacons, with the positions of said terrestrial time transfer beacons being known by the receiver or being transmitted to the receiver, and of determining a pseudo-distance measurement associated with each time transfer terrestrial beacon; - a second step (302) of implementing a resolution algorithm optimising a maximum likelihood criterion using the pseudo-distances computed in the first step (301) and jointly resolving the positions of the terrestrial time transfer beacons, the position of the receiver and the time shift of the receiver; - a third step (303) of computing a test variable T equal to the sum of the square of the remainders of the positions of the receiver and of the terrestrial time transfer beacons, weighted by variances in the positions of the receiver and of the terrestrial time transfer beacons; - a fourth step (304) of determining an alert threshold on the test variable T according to a given false alarm probability Pfa, and, when the test variable T is greater than or equal to said alert threshold, issuing a loss of integrity warning; and otherwise - a fifth step (305) of determining a non-centrality parameter λ of the test variable T for said false alarm probability Pfa and for a given detection probability Pd; - a sixth step (306) of determining a minimum detectable clock bias for each time transfer terrestrial beacon based on the test variable T and the non-centrality parameter λ; - a seventh step (307) of determining a minimum detectable position bias for each time transfer terrestrial beacon based on the test variable T and the non-centrality parameter λ; - an eighth step (308) of determining a protection area for the time shift information of the receiver computed during the second step (302) based on the detectable minimum biases computed during the sixth step (306) and the seventh step (307) of the method, and of issuing a loss of integrity warning when said protection area is greater than or equal to a warning area.
2. The method for broadcasting time and for measuring the integrity of the broadcast time according to claim 1, wherein the algorithm using a maximum likelihood criterion implemented during the second step (302) is a Gauss-Newton algorithm or a Levenberg-Marquardt algorithm.
3. The method for broadcasting time and for measuring the integrity of the broadcast time according to any of the preceding claims, wherein the second step (302) comprises: - constructing a state vector X comprising an estimated position of the receiver, an estimated time shift of the receiver, and estimated positions of said terrestrial time transfer beacons; - constructing an observation vector y comprising the known or transmitted positions of said terrestrial time transfer beacons and the pseudo-distances computed during the first step (301), constructing a linearised observation vector Y comprising a deviation between the known or transmitted positions of said at least three terrestrial time transfer beacons and their estimated positions, and a deviation between the pseudo-distances computed during the first step (301) and the pseudo-distances constructed from the values of the state vector X; - constructing a Jacobian matrix H based on the state vector X and on the observation vector y, such that H = ∂ y ∂ X , and iteratively resolving the system by computing X̂ = H*Y.
4. The method for broadcasting time and for measuring the integrity of the broadcast time according to any of the preceding claims, wherein the test variable T computed during the third step (303) follows a mathematical law of χ2.
5. The method for broadcasting time and for measuring the integrity of the broadcast time according to any of the preceding claims, wherein the eighth step (308) of determining a protection area for the time shift information comprises computing an undetectable maximum estimation error with a probability that is greater than or equal to the probability Pd of detecting a clock or a position bias of one or more of the terrestrial time transfer beacons.
6. The method for broadcasting time and for measuring the integrity of the broadcast time according to any of the preceding claims, wherein the receiver (101) communicates over radiofrequencies with N synchronised terrestrial time transfer beacons each broadcasting a time message comprising a time marker and a transmission time, with N being greater than or equal to 5, and wherein, when a loss of integrity warning is issued during the fourth step (304) or during the eighth step (308), the method is successively reimplemented on each subset of terrestrial time transfer beacons of size N-M, with 1 ≤ M ≤ N-4, so as to determine a subset of terrestrial time transfer beacons not issuing a loss of integrity warning in order to identify the one or more time transfer stations affected by a clock bias or a position bias.
7. Radiocommunication equipment (101) communicating over radiofrequencies with at least four synchronised terrestrial time transfer beacons (102, 103, 104) each broadcasting a time message comprising a time marker and a transmission time, the radio communication equipment comprising a radio chain configured to receive and interpret the time message transmitted by the terrestrial time transfer beacons, the radio communication equipment being characterised in that it further comprises computation means configured to implement a method for broadcasting time and for measuring the integrity of the broadcast time according to any of the preceding claims.
8. A computer program comprising program code instructions for executing the steps of the method for broadcasting time and for measuring the integrity of the broadcast time according to any of claims 1 to 6 when said program is executed on a computer.
9. A computer-readable storage medium storing a computer program according to claim 8.