Method for monitoring anomalies affecting signals of a satellite navigation system; Associated computer program and monitoring system.
A data aggregation and anomaly detection system using multicorrelation and fuzzy logic algorithms addresses the limitations of existing GNSS protection methods, offering real-time monitoring and alerting for jamming and spoofing, enhancing infrastructure and mission reliability.
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- THALES SA
- Filing Date
- 2024-11-14
- Publication Date
- 2026-05-15
AI Technical Summary
Current solutions for protecting GNSS receivers against jamming and spoofing are complex and expensive, lacking real-time monitoring, classification, and alerting capabilities for anomalies affecting satellite navigation systems, which are critical for infrastructure and mission reliability.
A method and system that aggregates data from multiple GNSS receivers and aircraft systems to detect, classify, and map anomalies in real-time using multicorrelation and fuzzy logic algorithms, generating alerts for operators and users.
Provides reliable, real-time monitoring and alerting for GNSS anomalies, enabling effective crisis management and countermeasures across global, national, and local scales without requiring extensive, expensive hardware deployment.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for monitoring anomalies affecting signals of a satellite navigation system; Associated computer program and monitoring system.
[0001] The invention relates to the field of satellite navigation. More particularly, the invention relates to the fields of infrastructure and applications (or missions) which, in their nominal operation, require information provided by one or more satellite navigation systems - or GNSS (“Global Navigation Satellite System”) systems, such as the GPS system or the Galileo system.
[0002] GNSS systems emit positioning and synchronization signals, known as GNSS signals. These signals are used by users equipped with GNSS receivers, who actively exploit them for geolocation (determination of instantaneous position and speed) and absolute timing, and this with a certain degree of accuracy.
[0003] Many critical infrastructures and missions use GNSS systems. Their nominal operation depends on the quality of services offered at any given time by the GNSS systems and the resulting performance. This is the case, for example, in the fields of civil aviation, drones, space launch, and autonomous ground vehicles, primarily for localization needs; or, in the field of energy transport, for timing needs; and in the banking and financial sectors, for transaction synchronization needs.
[0004] However, the services delivered by GNSS systems, particularly public (or OS – “Open Service”) systems, which are the most widely used and whose structure and data are perfectly known, are provided through low-power signals. GNSS signals are therefore vulnerable to potential degradation, which can impact the continuity and security of the infrastructures and / or missions using these GNSS signals.
[0005] In this document, anomaly means any event leading to an abnormal and unpredictable disturbance of the signals and information provided by GNSS systems to end users.
[0006] This refers in particular to the following anomalies:
[0007] - failures or maneuvers of one or more of the satellites of a constellation;
[0008] - ionospheric scintillation, defined as an abnormal variation in total content in electrons of the ionosphere (or TEC - "Total Electron Content"), linked for example to events such as solar flares. This type of anomaly strongly influences the variation in speed and therefore the delays of GNSS signals;
[0009] - multipath, defined as the presence of GNSS interference due to reflection or the refraction of GNSS signals by the local environment of a GNSS receiver. Particularly present in urban environments, they lead to the degradation of the quality of the GNSS signals received, and consequently, of the GNSS receiver's ability to accurately determine its position, speed and / or date;
[0010] - errors or malfunctions affecting the GNSS receivers themselves;
[0011] and, in particular:
[0012] - the jamming of GNSS signals, defined as the Degradation of GNSS signal reception due to the emission of higher-power noise signals on the same frequency band. Jamming, whether intentional or not, induces a denial of service for GNSS receivers in the affected area, rendering GNSS signals unusable or severely degraded. Aside from war zones, where GNSS signal jamming is frequently employed, a resurgence of jamming has been observed in recent years, for example, around airports, disrupting air traffic. In particular, according to current aviation safety standards, when the GNSS signal is insufficient in the geographical area of an airport, air traffic may be disrupted or even interrupted while the source of the jamming is identified and neutralized by the competent authorities; and
[0013] - the spoofing of GNSS signals, defined as The transmission of falsified GNSS signals to disrupt GNSS receivers in the impact zone, altering the results of position, speed, and / or time calculations. These deception methods can be used to divert autonomous vehicles from their trajectory and represent a major danger, particularly for the safety of property and people.
[0014] Although multipath and ionospheric scintillation phenomena represent a challenge to maintaining positioning and timing performance, jamming and spoofing of GNSS signals currently represent a major issue as they directly affect the safety of property and people.
[0015] While known solutions exist to date to protect GNSS receivers against jamming and spoofing, they are essentially based on the implementation of dedicated, complex and very expensive equipment, relying in particular on advanced signal processing algorithms.
[0016] Consequently, their deployment is limited and they are not associated with monitoring devices that allow alerts to be sent back to the operators and / or users of a target infrastructure / application in case of detection of GNSS signal disturbances.
[0017] There is therefore currently no solution which guarantees reliable monitoring, whether at the global, national or local level, of anomalies affecting the services provided by satellite navigation systems - GNSS, and which makes it possible to detect, classify and map in real time the occurrence of anomalies, whatever their nature, and to issue detailed alerts to the operators and / or users of a target infrastructure or mission, whose nominal operation depends on the reliability of GNSS signals and data.
[0018] The invention therefore aims to meet this need by providing a system for monitoring, classifying, mapping and alerting in real time of anomalies that may affect users of GNSS systems.
[0019] To this end, the invention relates to a computer-implemented method for monitoring anomalies affecting signals of a satellite navigation system - GNSS - within visibility of a geographical area of interest, referred to as GNSS signals, characterized in that the method consists of: acquiring data from a plurality of data sources, each data source of the plurality of data sources aggregating data from a plurality of receiving devices, each receiving device integrating a GNSS receiver adapted to process the GNSS signals in order to determine first quantities, the data comprising instantaneous values of the first quantities, calculated by the GNSS receiver of a receiving device, and / or instantaneous values of second quantities,a second quantity being determined by said receiving device from one or more first quantities calculated by the GNSS receiver of said receiving device, the receiving devices of the plurality of receiving devices being geographically distributed to obtain coverage covering at least the geographical area of interest; preprocessing the acquired data to obtain preprocessed data, each preprocessed data item taking the form of a time series; calculating one or more first anomaly indicators, each first anomaly indicator being obtained by applying a multicorrelation algorithm to a group of several preprocessed data items; calculating one or more second anomaly indicators for each preprocessed data item, considered individually, by applying a statistical processing algorithm; merging the first and second anomaly indicators to obtain global anomaly indicators,Each overall anomaly indicator is indicative of the probability of occurrence of a particular type of anomaly; generate an alert for the occurrence of an event belonging to a specific type of anomaly, when a rule for occurrence adapted to said type, anomaly is verified, said occurrence rule being based on the global indicator(s) associated with said type of anomaly.
[0020] According to particular embodiments, the process comprises one or more of the following characteristics, taken individually or in all technically possible combinations:
[0021] - the type of anomaly relates to: a failure of at least one GNSS satellite; a maneuver of at least one GNSS satellite; jamming; spoofing; multipath propagation; ionospheric scintillation; or GNSS receiver failure;
[0022] - the process further comprises a step of associating global indicators characterizing the type of jamming anomaly and / or the type of spoofing, to a geographical position from a position of the receiving devices which enabled the occurrence alert of the corresponding event;
[0023] - the method further includes an estimation of the location of the equipment interference responsible for the event;
[0024] - the method further includes a step of displaying the generated alert on a human-machine interface and / or a notification step of the generated alert to a user system impacted by the event;
[0025] - the first quantities include, for each receiving device and for each GNSS satellite in view of said receiving device a measurement of C / N0, Doppler, pseudo-distance, and phase, as well as information relating to the ephemerides broadcast by each GNSS satellite;
[0026] - the second quantities comprise, for each receiving device of the type flight system of an aircraft, a position, an altitude, a speed, a heading and a trajectory of the aircraft, and one or more pieces of information relating to navigation performance;
[0027] - the merging step implements a fuzzy logic algorithm;
[0028] - the preprocessing step consists of applying a compensation algorithm between several initial magnitudes;
[0029] - the generated alert is transmitted to an end user whose system is impacted by the event associated with the alert, in order to implement an appropriate countermeasure;
[0030] - the first quantities are GNSS data and the second quantities are ADS-B and / or AIS data;
[0031] - the data sources include: data sources managed by data providers, public and / or commercial, with global and / or national coverage; and / or private data sources, associated with opportunistic or specifically deployed GNSS receivers, with local coverage.
[0032] The invention also relates to a computer program product for implementing the previous process.
[0033] The invention also relates to a monitoring system for the implementation of the previous process.
[0034] The invention and its advantages will be better understood upon reading the following detailed description of a particular embodiment, given solely by way of non-limiting example, this description being made with reference to the accompanying drawings in which:
[0035] [Fig-1] Fig. 1 is a schematic representation in the form of modules functional, of a preferred embodiment of a monitoring system for implementing the monitoring method according to the invention; and,
[0036] [Fig.2] Fig.2 is a block representation of a preferred embodiment of the monitoring method according to the invention.
[0037] The monitoring method according to the invention ensures a massive collection of data relating to GNSS signals and from a plurality of data sources of different natures, public and private, their processing by "crowdsourcing" and hybridization methods, in order to detect, classify and map anomalies affecting GNSS signals, in particular jamming and / or spoofing of GNSS signals.
[0038] A target geographical area 1 is considered as the area to be monitored. For example, a critical infrastructure 3 is located within the target area 1. This is, for example, an airport. The proper functioning of the critical infrastructure 3 relies on at least one satellite navigation system, or GNSS system, 2.
[0039] The satellite component of the GNSS 2 system consists of one or more satellite constellations. These are, for example, referenced SI, S2, S3 and S4 in [Fig. 1]. They continuously transmit GNSS signals on different frequency bands. These GNSS signals are, for example, referenced M1, M2, M3 and M4 in [Fig. 1].
[0040] The monitoring system 10 systematically and massively collects data from various data sources, with the aim of leveraging pre-existing data rather than implementing specific high-performance but expensive hardware, including advanced signal processing algorithms.
[0041] Each data source collects data from a plurality of receiving devices, each receiving device being equipped with a GNSS receiver.
[0042] A first type of receiving device consists of ground-based GNSS stations belonging to global or national, public or commercial networks. These ground-based GNSS stations are, for example, referenced as T1, T2, and T3 in [Fig. 1]. They process the GNSS signals transmitted by the satellites, on one or more frequency bands. The data from each GNSS station are instantaneous values of primary GNSS quantities. They are made available, in real time, by Network resources. This provision is achieved through suitable network resources, for example, a data server accessible via a communication network. For example, the NTRIP protocol ("Network and Transport of RTCM via Internet Protocol") allows the transmission of navigation data (ephemerides), GNSS signal measurements, or real-time kinematic corrections of the -RTK ("Real Time Kinematic") type, via the Internet, to GNSS receivers using the services offered by these ground-based GNSS stations.
[0043] A second type of receiving device consists of ground-based GNSS equipment located in the geographical area of interest 1. These are private, pre-existing GNSS receivers (so-called "opportunity" receivers) or receivers deployed specifically to increase the density of the sensor network whose measurements are used by the monitoring system 10. These GNSS devices are, for example, referenced as RI, R2, and R3 in [Fig. 1]. The data from these GNSS devices are also instantaneous values of primary GNSS quantities. They are made available in real time via network means.
[0044] Advantageously, in the preferred embodiment described here, a third type of receiving device consists of the flight systems of aircraft in operation, particularly those transmitting ADS-B messages. This is notably the case for commercial civil aviation aircraft. These aircraft are referenced A1, A2, and A3 in [Fig. 1], and the ADS-B messages they transmit are referenced L1, L2, and L3 in [Fig. 1]. The ADS-B messages contain the instantaneous values of second ADS-B quantities. A second ADS-B quantity is calculated by the flight system from the first GNSS quantities delivered at each instant by the flight system's GNSS receiver. The ADS-B messages transmitted by the aircraft are captured, processed, recorded, and made available by ground-based ADS-B stations operating in real time. These ADS-B stations, equipped with ADS-B receivers, are for example referenced Ul, U2 and U3 on the [Fig.l].These values are made available in real time via network means.
[0045] GNSS quantities include navigation information (satellite ephemerides) and observables (pseudo-range, phase, Doppler, and C / N0 measurements).
[0046] The ADS-B signals transmitted by an aircraft include, for example:
[0047] - the position, altitude and speed indicated in an ADS-B signal, which are estimated from onboard GNSS data and other data delivered by onboard sensors (inertial sensors, magnetometers etc);
[0048] - the navigation accuracy level - NAS (“Navigation Accuracy Category”), on the calculated position for example, which depends on GNSS data;
[0049] - the navigation integrity level - NIC ("Navigation Integrity Category"), which indicates the current integrity level according to indicators defined by the navigation system, which also depends on GNSS data; etc.
[0050] The monitoring system according to the invention, 10, offers a monitoring and alert service.
[0051] Its accuracy depends on the density of the GNSS receiver network whose data are collected, depending on the areas to be monitored, on a global, national, or local scale (the local scale corresponding to the target geographical area 1).
[0052] Through a human-machine interface - HMI 20, the system 10 provides an operator 4 with indicators for monitoring the different types of anomalies that may affect the GNSS system 2 and generates detailed alerts to anticipate crisis management.
[0053] Advantageously, the system 10 has an application programming interface - API (“application programming interface”) 22 allowing the information it produces to be transmitted to any other computer system user of the monitoring service, or user system 5. This makes it possible in particular to integrate the information calculated by the system 10 into other existing operational systems (for example, any computer system which already contributes to monitoring the infrastructure 3, such as computer systems for monitoring the operations of an airport).
[0054] The monitoring system 10 is adapted to detect and classify in real time all of the following types of anomalies:
[0055] anomalies in the spatial segment of the GNSS:
[0056] intentional failures or degradations of the GNSS 2 in its overall operation (this may be, for example, a failure, error or maneuver occurring at the level of the ground segment of the GNSS, and reported to the satellites of the constellation);
[0057] intentional failures or degradations of the performance of individual GNSS satellites (loss of power of a satellite, anomaly of the clock of a satellite, etc.);
[0058] local anomalies, at the level of at least one geographical area of interest, such as area 1 of the critical infrastructure 3 deployment, which can be extended to national or global coverage depending on the density of the available GNSS receiver network:
[0059] degradations, intentional or not, of the jamming type;
[0060] attack of the spoofing type;
[0061] ionospheric scintillation (rapid and irregular variation of the ionosphere, due for example to solar flares);
[0062] local environment close to the receiver degrading signal quality (multipath); and,
[0063] failure of a GNSS receiver of one of the sources whose data are used.
[0064] The monitoring system 10 according to the invention will be presented in more detail in reference to [Fig.1].
[0065] Advantageously, the monitoring system 10 takes the form of a computer service, instantiated in a software form known as cloud (or "cloud").
[0066] The monitoring system 10 systematically and massively collects data from various data sources.
[0067] GNSS data sources are preferably of three kinds:
[0068] - firstly, GNSS data sources associated with the devices Reception of the first type, i.e., ground-based GNSS stations, from public or commercial networks, such as stations T1 to T3. These are networks of several hundred GNSS stations offering national, or even global, coverage. A ground-based GNSS station is defined as a system consisting of an antenna and a GNSS signal receiver, whose position is fixed and known, and whose data (navigation information and observables) are accessible via network means. For example, in [Fig. 1], the data from GNSS stations T1, T2, and T3 are accessible via a data server 12 connected to a communication network 16 (e.g., the Internet). The server 12 makes the GNSS data collected by these ground-based GNSS stations available to users in real time (e.g., using the NTRIP protocol) or in delayed time (making files available, in RINEX format or in a proprietary format, on an FTP / http / https server).
[0069] For example, for public networks, this includes the ground-based GNSS station network of the International GNSS Service - IGS, or those of the National Centre for Space Studies - CNES through the REGINA network.
[0070] For commercial networks, these are networks of ground-based GNSS stations that provide users with a precise positioning service, for example of the RTK type. System 10 can use the data collected by this type of network.
[0071] - secondly, data sources associated with the receiving device The second type consists of ground-based GNSS equipment providing local coverage, i.e., corresponding to the monitored area 1. This essentially involves GNSS receivers, owned and made available by users of system 10, positioned within geographical area 1. These are receivers RI, R2, and R3 in [Fig. 1]. Optionally, additional low-cost GNSS receivers are added within area 1 to achieve denser local coverage.
[0072] The GNSS equipment is connected in some way to a network, such as the internet, so as to allow the system 10 to collect all the data that these receivers produce in real time. For example, in [Fig.1], the GNSS equipment RI, R2 and R3 are connected to a server 14, which is itself connected to the network 16.
[0073] - thirdly, data sources associated with the receiving devices of the third type, namely the flight systems of aircraft in operation. Similarly, this ADS-B data is collected via receiving stations (U1 to U3 in Figure 1) from a public or commercial provider and made available, for example, via a client server 16, which is connected to the public network 16. These are data sources that indirectly provide GNSS data. They correspond to national or even global coverage.
[0074] These various data sources make it possible, on the one hand, to create an extensive monitoring network in order to detect global anomalies affecting GNSS services, thanks to the various measurement points represented by GNSS signal receiving devices such as GNSS stations and aircraft flight systems. This first level of data allows the system 10 to provide monitoring on a global or national scale and, to a lesser extent and depending on their distribution, within the geographical area of interest.
[0075] These different data sources also make it possible to create a more precise surveillance network around the target geographical area 1, in order to detect local anomalies affecting GNSS services thanks to the different measurement points represented by GNSS equipment on the ground and possibly the flight systems of aircraft circulating above or near the area to be monitored.
[0076] The monitoring system 10 is based on taking into account a set of data delivered, at each moment, by the different sources.
[0077] This dataset includes the GNSS data that any GNSS receiver is capable of providing and, in the preferred embodiment, all the ADS-B data that any ADS-B system is capable of providing.
[0078] In other words, the surveillance system 10 is based on the exploitation of the maximum amount of data already available, although heterogeneous, and does not require the large-scale deployment of expensive equipment.
[0079] The set of data collected is composed as follows:
[0080] of GNSS quantities called "observational", namely the measurements of GNSS signals from GNSS satellites carried out by GNSS receivers, in particular measurements of C / N0, Doppler, pseudo-distance (code), and phase;
[0081] of GNSS quantities called "navigation", namely the ephemerides broadcast by GNSS satellites and extracted by GNSS receivers;
[0082] Finally, ADS-B data transmitted by aircraft, in particular: aircraft position, altitude, speed, heading and trajectory, and navigation information, such as as NAC - Navigation Accuracy Category, NIC - Navigation Integrity Category, SIL -Surveillance Integrity Level, and SDA - System Design Assurance.
[0083] The monitoring system 10 is a computer comprising computing means, such as a processor, and storage means, such as memory. The memory stores, in particular, the instructions of computer programs, specifically a program 18 whose execution enables the implementation of the method according to the invention.
[0084] The program 18 of the monitoring system 10 can be subdivided into several functional modules. In the preferred embodiment illustrated in [Fig. 1], it comprises:
[0085] - a data collection module 30, i.e., GNSS values from sources associated with first and second type receiving devices, public, commercial and / or private, and ADS-B quantities from sources associated with third type receiving devices, public and / or commercial;
[0086] - a module 32 for preprocessing instantaneous values of GNSS quantities and ADS-B collected to obtain pre-processed GNSS and ADS-B data;
[0087] - a module 34 for so-called "crowdsourcing" analysis, for anomaly detection starting from pre-processed GNSS and ADS-B data, by implementing a multi-correlation algorithm on the pre-processed data grouped according to the type of anomaly sought, to obtain one or more initial anomaly indicators;
[0088] - a module 36 for statistical analysis of pre-processed GNSS and ADS-B data, for determine one or more secondary anomaly indicators;
[0089] - a module 38 for merging the first and second anomaly indicators in global indicators, by advantageously implementing fuzzy logic algorithms to identify, classify and characterize with a certain level of certainty, the occurrence of an event of a jamming or spoofing type, a satellite maneuver or constellation failure type, or an "other" type including multipath interference, ionospheric scintillation or receiver failures;
[0090] - a module 40 for geo-referencing the identified anomalies;
[0091] - an alert lifting module 42 based on georeferenced anomalies output from the module 40;
[0092] - a visualization module 60, for managing the display on a screen of the HMI 20 allowing the information calculated by the monitoring system 10 to be visually represented; and,
[0093] - a module 70 for disseminating alerts to the user system (of which part critical infrastructure), including user systems impacted by an anomaly, for example by implementing a notification system in order to to allow the managers of these user systems to react quickly in the event of an impactful event.
[0094] The HMI 20 presents, for example, dashboards with global indicators, advantageously associated with each type of anomaly.
[0095] The HMI 20 presents, for example, map views with a color code representing the geographical areas impacted by a detected anomaly, in particular an anomaly of the jamming or spoofing type with, advantageously, an estimate of the location of the interference device causing this anomaly.
[0096] Additional dashboards present an "expertise" view and provide access to all the data produced, including the first and second indicators, as well as the input data, in the form of time series, tables and statistical views.
[0097] The objective of these displays is to enable the operator 4 of the system 10 to trigger the appropriate countermeasures for crisis management in the event of GNSS degradation.
[0098] The program 18 is associated with a database 50 for storing pre-processed data and instantaneous values of all calculated indicators.
[0099] The method according to the invention will now be presented with reference to [Fig.2].
[0100] Method 100 is a method for monitoring anomalies affecting signals GNSS broadcast by a satellite navigation system - GNSS and captured by receiving devices.
[0101] Method 100 aims to detect anomalies that may affect the nominal operation of a critical infrastructure or mission using GNSS signals.
[0102] The process 100 comprises, at each iteration, a succession of steps. Each step corresponds to the execution of a module of the monitoring system 10 of [Fig.1].
[0103] The process 100 begins with a step 130 of acquiring data from a plurality of data sources.
[0104] Each of these sources aggregates data from a plurality of receiving devices. Each receiving device incorporates a GNSS receiver adapted to process GNSS signals.
[0105] The data from a receiving device are either GNSS data calculated directly by the GNSS receiver of the receiving device, or ADS-B data calculated by the receiving device from the GNSS data calculated by the GNSS receiver of that receiving device.
[0106] Step 130 is carried out by module 30 which accesses data servers.
[0107] For receiving devices such as GNSS stations, whether public or commercial, the data are made available by data providers. They can be acquired in real time, for example using the communication protocol NTRIP and the RTCM (“Radio Technical Commission for Maritime Services”) data format.
[0108] For receiving devices such as private GNSS equipment, the data is acquired in a raw format. In this case, specific protocols and decoding procedures can be used as an alternative to the NTRIP protocol and the RTCM format.
[0109] For flight system type receiving devices, data is made available by data providers. It can be acquired using the TCP (“Transmission Control Protocol”) or http / https (“Hyper Text Transfer Protocol / Hyper Text Transfer Protocol Secure”) protocol in binary, JSON (“JavaScript Object Notation”) or CSV (“Comma-separated values”) format.
[0110] The GNSS data retrieved for each GNSS station and each GNSS device includes the instantaneous values of the following initial quantities:
[0111] the GNSS observables determined by the GNSS receiver of the receiving device, namely the measurements of the GNSS satellite signals by the GNSS receivers, in particular measurements of the carrier-to-noise power density ratio (C / N0), Doppler, pseudo-distance (code), and phase; and,
[0112] navigation information determined by the GNSS receiver of the receiving device, namely the ephemerides broadcast by the GNSS satellites.
[0113] The ADS-B data retrieved for each flight system onboard an aircraft includes the instantaneous values of the following second quantities:
[0114] the values of the position, altitude, speed, heading and trajectory of the aircraft, as well as navigation-specific indicators such as "NAC" ("Navigation Accuracy Category"), "NIC" ("Navigation Integrity Category"), "SIL" ("Surveillance Integrity Level"), and "SDA" ("System Design Assurance").
[0115] The next step of process 100 is a preprocessing step 132 of the data acquired in step 130.
[0116] Step 132 is performed by module 32.
[0117] The preprocessing applied is preferably specific to each quantity. More precisely, step 132 applies processing such as normalization, filtering or resampling of the instantaneous values of a quantity over a time interval.
[0118] Advantageously, the preprocessing also includes the processing of the first GNSS quantities to determine third GNSS quantities, such as the orbit and clock of a satellite, the elevation and azimuth of a satellite for each receiving device, the position, velocity and time for each receiving device, the associated errors determined using the reference values, Code-phase coherence, code-Doppler coherence, and / or measured Doppler and expected Doppler difference.
[0119] Advantageously, step 132 allows the application of a known effects compensation ("detrending") algorithm to the first and / or third quantities to obtain fourth quantities. In other words, it involves decorrelating the input GNSS data from each other to increase their significance.
[0120] For example, the C / NO ratio values are strongly correlated with the angular elevation of the satellite in question relative to the GNSS receiver performing the measurement. This prevents the effective detection of malfunctions or maneuvers performed by the satellite that affect the power of the GNSS signals it transmits. It is therefore necessary to decouple the effect of elevation on the C / NO ratio measurement.
[0121] To address this problem, a second-order regression polynomial is applied, for example, to measurements of the C / NO ratio as a function of satellite elevation for a given satellite-GNSS receiver pair. This polynomial is defined over a sliding time period covering the orbital period of the satellites. This polynomial is then subtracted from the measurements of the C / NO ratio for this satellite-GNSS receiver pair to obtain residuals of the C / NO ratio. Such a residual constitutes an example of a fourth quantity.
[0122] At the end of the preprocessing step 132, the preprocessed data are presented in the form of a plurality of time series, each time series corresponding to the temporal evolution of a quantity.
[0123] The process 100 continues with a step 134 of calculating a first set of anomaly indicators by a "crowdsourcing" method.
[0124] Step 134 is performed by executing module 34.
[0125] The "crowdsourcing" method, which can be literally translated as "sourcing by the crowd", refers to the cross-referencing of a large number of measures in order to exploit their common characteristics and thus extract useful information.
[0126] This method is adapted here to detect disturbances affecting the GNSS signals of a set of GNSS receivers and / or a set of satellites.
[0127] This method makes it possible in particular to overcome measurement noise or possible isolated local phenomena in order to clearly identify the occurrence of an abnormal event.
[0128] This involves applying a multicorrelation algorithm to a group of several time series.
[0129] The grouping of several time series is advantageously carried out according to the type of anomaly sought.
[0130] For example, if it is a question of detecting events of the type global anomaly (impacting for example a satellite), the grouping is carried out on all GNSS receivers in view of this impacted satellite.
[0131] For example, if it is a question of detecting events of the type of local anomaly (impacting one or more GNSS receivers on Earth, aircraft, devices or stations), the grouping is carried out on all GNSS transmitters, i.e. the satellites in view of the geographical area where the impacted GNSS receivers are located.
[0132] From the time series output of step 132, module 34 calculates a first indicator, which accounts for common variations of the same quantity identified by a group of satellite / GNSS receiver pairs. In other words, the principle is to identify the occurrence of an abnormal event as a consensus on the same variation in the values of the same quantity determined by different satellite / GNSS receiver pairs during the observation period.
[0133] In the case, for example, of a power anomaly emitted by a satellite, the "crowdsourcing" method makes it possible to strictly isolate the power variations related to the satellite, by combining the measurements of all GNSS receivers within sight of this satellite (since this event is observed by all GNSS receivers on the ground) and to eliminate all local errors affecting a particular GNSS receiver (failures, errors and measurement noise at the level of a GNSS receiver, local multipath effects, or ionospheric errors).
[0134] In the case, for example, of an anomaly related to jamming or spoofing, the effect of which is local, the "crowdsourcing" method makes it possible to strictly isolate the distortions introduced at the level of the jammed or spoofed receiver, by combining the values of the same quantity measured by the GNSS receiver for each of the satellites in visibility of this GNSS receiver in order to identify the common variations.
[0135] The various first indicators calculated in step 134 are thus representative of either local anomalies (jamming and spoofing), or global ones (satellite failures or maneuvers).
[0136] For ADS-B data, it is also a matter of identifying common variations in the information delivered by a set of aircraft, including information associated with GNSS performance.
[0137] The "crowdsourcing" method can be used by hybridizing data of different kinds, including GNSS data and ADS-B data.
[0138] For example, the method makes it possible to calculate a first indicator for a power anomaly emitted by a satellite, using a correlation matrix weighted at time k, denoted and defined as:
[0139]
[0140] with kk, respectively a vector of Nc values of a quantity S on the GNSS signals emitted by the satellite in question, these values being obtained at each sampling step of an interval T= [[ k- Nq kj ) by the GNSS receiver f respectively the GNSS receiver j ; Cov(, )• the covariance operator; (jk, respectively (jk, the variance on the distribution of the values of the vector ,k, respectively 7^ ; i and j being integers between 1 and N, N being the number 'i of observers, i.e. GNSS receivers whose data have been collected and which are within line of sight of the satellite in question.
[0141] The weighting, represented by the variable pk, corresponds to the p value making The statistical relevance of each measure is taken into account. The higher the number of samples Nc, the more strongly the covariance is weighted.
[0142] A scalar indicator Pk representative of the elements of the weighted correlation matrix is then calculated, for example, by performing a statistical reduction. For example, the median (med operator) of the values in the strict upper triangular weighted correlation matrix is used. An additional weighting ...N... where corresponds to the statistically ideal number of observers, allows Nstd to further reduce the weight of the scalar indicator when the consensus .K contains only a few observers:
[0143] pk=med(o)fj)jnax(l, 7^-i, j€ [[1; N]2, j>LN>2
[0144] Thus, the more correlated and statistically representative the data from different GNSS receptors are, the higher the scalar indicator.
[0145] The indicator [3] therefore takes a continuous value, between 0 and 1. The zero value represents nominal behavior, without anomaly, while the unit value accounts for the occurrence of an abnormal event falling within the type of anomaly associated with this indicator.
[0146] In parallel, the process 100 includes a step 136 of statistical analysis of the data delivered at the output of the pre-processing step 132.
[0147] Step 136 is implemented by module 36.
[0148] Step 136 allows a second set of anomaly indicators to be calculated from the time series output from module 32.
[0149] Such a second indicator makes it possible to determine, at the level of each quantity considered in isolation from the others, whether its temporal evolution is nominal.
[0150] For example, a time series is analyzed by applying a machine learning method, preferably unsupervised. This makes it possible, for example, to analyze the dispersion of orbit and clock errors calculated for satellites, or of position, velocity and time errors calculated for GNSS receivers.
[0151] The second anomaly indicators have continuous values between 0 and 1, the zero value representing the nominal case, without anomaly, the unit value reflecting the presence of an abnormal event.
[0152] The process 100 includes a step 138 of merging all the indicators calculated during steps 134 and 136 so as to obtain global indicators.
[0153] This step is implemented by module 38.
[0154] Each global indicator evolves between 0 (anomaly in the data very unlikely) and 1 (anomaly in the data very likely) in a continuous and increasing manner according to the probability of the actual presence of the anomaly to which this global indicator is associated.
[0155] The overall anomaly indicators are representative of the following anomalies:
[0156] presence of a maneuver or satellite or constellation failure (indicator defined for each satellite of the satellite navigation system 2);
[0157] presence of interference, defined for GNSS receivers on the ground and on board aircraft in or over the area of interest;
[0158] presence of spoofing, for GNSS receivers on the ground and on board aircraft in or above the area of interest;
[0159] presence of other non-critical degradations (multipath, ionospheric scintillation or receiver failure);
[0160] The calculation of these global indicators is carried out for example by applying fuzzy logic inference algorithms, which make it possible to obtain non-binary outputs, in order to avoid threshold effects and to obtain values more representative of reality, the interpretation and the associated thresholds being left to the discretion of the operator.
[0161] Hybridization of direct GNSS data and indirect GNSS data can also be done when calculating certain global indicators.
[0162] For example, a fuzzy logic inference algorithm relies on a truth table applied to the combination of a subset of the indicators calculated in steps 134 and 136, previously tuned by statistical analysis.
[0163] A global indicator can be used in the calculation of another global indicator. Typically, a global indicator of satellite failure or maneuver can be used to inhibit the raising of false positives on a global indicator of jamming or spoofing.
[0164] A step 140, performed by module 40, then aggregates all or part of the global anomaly indicators, particularly those associated with jamming and spoofing anomaly, in order to analyze the temporal synchronization of the associated events, their geographical distribution, and their characteristics, in order to:
[0165] to eliminate false positives;
[0166] to determine the geographical areas impacted by an event;
[0167] to estimate the approximate location of jammers and decoys associated with an impacted area.
[0168] For example, the use of grouping methods (“clustering”) makes it possible to define the geographical areas impacted by anomalies raised by a set of receivers at a given time.
[0169] In the event of an event such as jamming or spoofing, this step advantageously implements a search for the location of the equipment causing the interference.
[0170] The location is estimated from a physical interference model and pre-processed measurements from GNSS receivers, preferably private GNSS equipment in the impacted area.
[0171] For example, an iterative method is implemented based on the probable characteristics of the jammer or decoy sought (power and potential positions and parameters of an elliptical area of influence) by varying its range. The most probable characteristics retained for the target material minimize the transmitter power and intercept the minimum number of measurement points where no anomaly is identified.
[0172] The criticality of the degradation in an area of interest is preferably defined. It is a continuous variable in the interval between 0 and 1. It is representative of the overall anomaly indicators calculated for this area of interest. For example, it corresponds to the median of these overall indicators. Optionally, the criticality is weighted by a parameter representing the estimated threat level of the equipment responsible for the degradation.
[0173] In step 142, corresponding to the execution of module 42, the instantaneous values of the georeferenced indicators are analyzed. Alert generation rules, for example of the logical type, which combine one or more indicators (and / or derived quantities) are tested in order to automatically generate an alert when one of them is verified in a geographical area of interest.
[0174] Thus, for example, in the event of a deterioration, that is, if an overall indicator rises above a threshold predetermined by the operator, an alert is issued for the anomaly corresponding to that indicator. Similarly, a configuration allows alerts to be raised only if events occur in specific geographical areas defined by the system operator 10.
[0175] If the use case requires it, step 170 is carried out by executing module 70. Step 170 consists of sending an alert securely to a user system 5 impacted by the degradation, infrastructure terminal or target users, such as aircraft pilots, by disseminating a message in a suitable format, for example the "NOTAM" ("NOTice to AirMen") format.
[0176] This allows target users to react quickly in the event of an impactful occurrence. This reaction could, for example, involve deciding to cease using GNSS during the period of degradation, or switching to another navigation system (interceptor, odometer, LiDAR, etc.), timekeeping system (time server), or another positioning system, for example, by using the base stations of a mobile communication network. Alternatively, the decision-making process could involve avoiding the impacted geographical or temporal area by postponing the mission, and / or requesting the assistance of the relevant authorities to neutralize a jammer or decoy and restore the situation.
[0177] At each time step, the instantaneous data produced at steps 130, 132, 134, 136, 140, and / or 142 are advantageously stored in database 50.
[0178] Periodically, in a display generation step 160, module 60 is executed. It queries database 50 to dynamically generate the visualizations to be displayed on the human-machine interface - HMI 20.
[0179] The HMI 20 presents the final indicators delivered in step 142, preferably in the form of a dashboard containing, for example, map views whose color code is representative of the situation of jamming and spoofing anomalies associated with location estimates of interference equipment and associated impact zones. In addition, indicators associated with each satellite, representative of satellite failure and maneuver anomalies, are presented. The objective of these interfaces is to allow an operator 4 to trigger countermeasures adapted to crisis management in the event of GNSS degradation.
[0180] Additional dashboards present an "expert" view giving access to all the data produced during the different stages of process 100, in the form of time series, tables and statistical views.
[0181] In a first application, monitoring the power emitted by GNSS satellites and any degradation, failures, or maneuvers affecting these signals is among the key elements monitored by space agencies. These events are primarily measured by high-gain antennas, which provide a precise assessment of the power emitted by the satellites. However, these antennas can only track a limited number of satellites at a time and must be programmed in advance according to the orbits to be tracked, without knowing which ones should be monitored as a priority.
[0182] The monitoring system 10 makes it possible to identify, in real time and with global coverage, all satellites exhibiting this type of anomaly, and to obtain an initial estimate of the variation in emitted power. The high-gain antennas can then be controlled to track only the identified satellites and refine the power radiation estimate.
[0183] Other application cases relate to the monitoring of jamming and spoofing, which represent a major challenge that must be addressed in many areas, in particular:
[0184] for air traffic monitoring, involving airports, air traffic management and airlines through pilots, for which GNSS jamming and spoofing can lead to aviation accidents (aircraft collisions, aircraft crashes during automatic approaches) and the use of erroneous navigation data by air traffic control. The use of the system according to the invention makes it possible to identify in real time events affecting the instrumentation on board aircraft, to alert all stakeholders (for example, pilots via NOTAM messages as recommended by the European Air Traffic Control Agency), and to take the necessary measures to restore a nominal situation (for example, locate and neutralize interference equipment), in conjunction with the competent authorities, or to organize maneuvers to avoid the impacted areas;
[0185] Similarly, space launches are becoming increasingly dependent on the launch vehicle, and the presence of jamming or decoys can lead to an erroneous trajectory and cause considerable material and human damage. In this context, the use of the invention makes it possible to take appropriate measures in real time in the event of an identified threat (flight postponement, or neutralization of the launch vehicle);
[0186] Similarly, defense-related systems and missions are heavily dependent on GNSS systems, particularly GPS. The presence of degradation can lead to trajectory errors in certain weapon systems, or errors in tactical tracking solutions for troops and equipment. The system according to the invention thus makes it possible to identify these degradations in order to implement the actions and countermeasures necessary to guarantee the success of a mission;
[0187] Similarly, smart cities, where autonomous air or land transport of goods or people is developing, have a critical dependence on GNSS systems. The aforementioned degradations can jeopardize the safety of property and people by disrupting the navigation system of these vehicles;
[0188] Similarly, critical infrastructures, such as energy transport infrastructures, also rely on GNSS systems for accurate data timing. Disruptions such as jamming and spoofing then have a significant impact on their operation;
[0189] Finally, in the same way, the use of GNSS systems for dating is critical for the timestamping of financial transactions, for which the aforementioned degradations can have a major economic impact.
[0190] The system according to the invention makes it possible, for example, to indicate to onboard navigation systems that satellite positioning is no longer reliable and that it is necessary to switch to another positioning source during the period of degradation.
[0191] It appears that the use of the invention can be broken down into several levels:
[0192] operator type use, for which the information delivered ensures real-time monitoring of the GNSS situation on a global, national and / or a given geographical area scale;
[0193] use for end users of GNSS services, for whom detailed alerts are issued by the system to enable them to implement appropriate countermeasures (for example, use of other sensor sources or geolocation or dating data), or direct actions to avoid the impact of degradation (for example, maneuvering to bypass a jamming or decoy zone).
[0194] The modular structure of the software component of the monitoring system according to the invention facilitates scalability, enabling the acquisition and processing of data from a very large number of sources. However, other ways of developing this software component are conceivable.
[0195] By relying on data available in any type of GNSS receiver, the invention makes it possible to systematically ingest and process new data, regardless of the nature or quality of the information collected. The monitoring system according to the invention thus ensures multi-anomaly detection by a single system aggregating data from heterogeneous receivers.
[0196] The invention relies on means for delivering direct GNSS observables. Alternatively, it relies on means for delivering indirect GNSS observables. The case of flight devices delivering ADS-B observables (for “Automatic Dependent Surveillance-Broadcast”) has been described in more detail above, but other known devices allow the delivery of other indirect GNSS observables, such as AIS devices (for “Automatic Identification System”). In this case, the measuring device is carried on board a vessel. In yet another variant, corresponding to the embodiment described above in detail, the invention relies on means for delivering both direct and indirect GNSS observables.
[0197] ADS-B data can strengthen national / regional coverage, but also, when an aircraft flies over the geographical area of interest, strengthen local coverage.
[0198] While, in the use case of the preferred embodiment described above, the geographical area of interest is associated with a particular critical infrastructure, more generally monitoring can be carried out over a broad geographical area, unrelated to any particular infrastructure. The alerts raised are then transmitted, based on the geolocation of the detected abnormal event, to end users who are subscribed to the monitoring service.
[0199] In the long term, it appears that the use of all available networks will allow for detailed monitoring of the global situation.
[0200] A person skilled in the art will find that the system according to the invention can be deployed at a lower cost, particularly in terms of materials, and without significant modification of existing infrastructure.
Claims
1. Demands A computer-implemented method (100) for monitoring anomalies affecting signals of a GNSS (2) satellite navigation system within a geographical area of interest, referred to as GNSS signals, characterized in that the method consists of: acquiring (130) data from a plurality of data sources, each data source of the plurality of data sources aggregating data from a plurality of receiving devices, each receiving device incorporating a GNSS receiver adapted to process the GNSS signals in order to determine first quantities, the data comprising instantaneous values of the first quantities, calculated by the GNSS receiver of a receiving device, and / or instantaneous values of second quantities, a second quantity being determined by said receiving device from one or more first quantities calculated by the GNSS receiver of said receiving device,the receiving devices of the plurality of receiving devices being geographically distributed to obtain coverage covering at least the geographical area of interest; preprocess (132) the acquired data to obtain preprocessed data, each preprocessed data taking the form of a time series; calculate (134) one or more first anomaly indicators, each first anomaly indicator being obtained by applying a multicorrelation algorithm to a group of several preprocessed data; calculate (136) one or more second anomaly indicators for each preprocessed data, considered individually, by application of a statistical processing algorithm; merge (138) the first and second anomaly indicators to obtain global anomaly indicators, each global anomaly indicator being indicative of a probability of occurrence of a particular type of anomaly; generate (142) an occurrence alert of an event falling within a type of anomaly, when an occurrence rule adapted to said type of anomaly is verified, said occurrence rule being based on the global indicator(s) associated with said type of anomaly.
2. A method according to claim 1, wherein the type of anomaly is due to: a failure or maneuver of at least one GNSS satellite; - jamming; - spoofing; or, - multipath, ionospheric scintillation, and GNSS receiver failure.
3. A method according to claim 2, further comprising a step (140) of associating global indicators characterizing the type of jamming anomaly and / or the type of spoofing, with a geographical position from a position of the receiving devices which enabled the corresponding event occurrence alert to be generated.
4. A method according to claim 3, further comprising an estimation of a location of the interference equipment responsible for said event.
5. A method according to any one of claims 1 to 4, further comprising a step (160) of displaying the generated alert on a human-machine interface (20) and / or a step (170) of notifying the generated alert to a user system (5) impacted by the event.
6. A method according to any one of claims 1 to 5, wherein the first quantities comprise, for each receiving device and for each GNSS satellite in line of sight of said receiving device, a measurement of C / NO, Doppler, a pseudo-range, and a phase, as well as information relating to the ephemerides disseminated by each GNSS satellite.
7. A method according to any one of claims 1 to 6, wherein the second quantities comprise, for each aircraft flight system receiving device, a position, altitude, speed, heading and trajectory of a carrier, and one or more pieces of information relating to navigation performance.
8. A method according to any one of claims 1 to 7, wherein the merging step (138) implements a fuzzy logic algorithm.
9. A method according to any one of claims 1 to 8, wherein the pretreatment step (132) consists of applying a compensation algorithm between several first quantities.
10. A method according to any one of claims 1 to 9, wherein the generated alert is transmitted to an end user whose system is impacted by the event associated with the alert, in order to implement an appropriate countermeasure.
11. A method according to any one of claims 1 to 10, wherein the first quantities are GNSS quantities and the second quantities are ADS-B and / or AIS data.
12. A method according to any one of claims 1 to 11, wherein the data sources include data sources managed by data providers, public and / or commercial, of global and / or national coverage and / or private data sources, associated with opportunistic or specifically deployed GNSS receivers, of local coverage.
13. Computer program comprising program code instructions for carrying out the steps of the process according to any one of claims 1 to 12 when said program is executed on a computer.
14. Monitoring system (10) comprising a computer programmed to perform the steps of the process according to any one of claims 1 to 12.