The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Kshana PNT Resilience simulator listing page.
क्षण — Sanskrit for the precise instant, the smallest measure of time.
Open, reproducible PNT (positioning, navigation, and timing) resilience simulation with published quantum-sensor performance models.
Kshana (क्षण, Sanskrit: "the precise instant") is an open, reproducible PNT-resilience simulator with quantum-sensor performance models — positioning, navigation, and timing. It compares quantum and classical sensors mostly from published Allan/noise-budget coefficients, with a first-principles cold-atom- interferometer accelerometer layer (Mach–Zehnder phase, quantum projection noise, contrast decay, and vibration coupling) that derives the noise coefficient rather than looking it up; it is not yet a full quantum-physics simulator (Coriolis and light-shift systematics remain coefficient-level — see docs/QUANTUM.md and docs/QUANTUM-MODELS.md).
It quantifies, in hard and reproducible numbers, what quantum clocks, quantum
inertial sensors, and optical time-transfer buy a navigation system over classical
PNT — scored against the operational figures of merit that matter for resilient
navigation. Every result is reproducible from scenario + seed + engine version,
and every sensor parameter is traceable to a published source — consolidated in one
citable table in docs/PROVENANCE.md.
Validated, not asserted. 666/666 AIAA SGP4 vectors to 4.12 mm · Cowell force model 0.08 m vs Orekit 12.2 · Galileo 0.61 m / Swarm-A 0.10 m vs real ESA precise ephemerides · GCRS→ITRS bit-for-bit vs SOFA/ERFA · ML metrics exact vs scikit-learn · 64 of 168 capabilities validated against independent external oracles; 100 honestly labelled Modelled.
One engine, five front doors · SVG
Each row is checked against an independent external oracle (real dataset, independent reference implementation, or published reference vectors) and re-checked in CI (continuous integration). Full 168-row matrix →
| Capability | Result | External oracle | |
|---|---|---|---|
| ✅ | SGP4/SDP4 (Simplified General Perturbations 4 / Simplified Deep-space Perturbations 4, the standard analytic satellite-orbit propagators) propagation | 666/666 vectors, worst 4.12 mm | AIAA 2006-6753 (Vallado; AIAA = American Institute of Aeronautics and Astronautics) + independent sgp4 crate |
| ✅ | Numerical Cowell force model | 0.08 m / 24 h, 275 epochs | Orekit 12.2 DormandPrince853 (CS GROUP) |
| ✅ | Orbit fit vs precise ephemeris | Galileo 0.61 m · Swarm-A 0.10 m | ESA (European Space Agency) / ESOC (European Space Operations Centre) SP3 (Standard Product 3, the precise-orbit format of the IGS — the International GNSS (global navigation satellite system) Service) precise orbits |
| ✅ | GCRS→ITRS (Geocentric Celestial Reference System → International Terrestrial Reference System) frame chain | bit-for-bit vs SOFA (the International Astronomical Union's Standards of Fundamental Astronomy library); ≤ 0.86 m vs SPICE (Spacecraft, Planet, Instrument, C-matrix, Events — the planetary-geometry toolkit) | ERFA (Essential Routines for Fundamental Astronomy, the open port of SOFA)/SOFA + ANISE (Attitude, Navigation, Instrument, Spacecraft, Ephemeris — a pure-Rust SPICE) |
| ✅ | Allan deviations | reproduce reference deviations | NIST SP 1065 (National Institute of Standards and Technology Special Publication 1065) + Stable32 on a real Cs (caesium) clock |
| ✅ | Global navigation satellite system (GNSS) dilution of precision (DOP) · machine-learning (ML) detector metrics | to 1e-6 · to 1e-9 | gnss_lib_py · scikit-learn |
| ✅ | Fisher information · CRLB (Cramér–Rao lower bound) · observability | eigh / CRLB / DOP to 1e-9 | NumPy 2.4.1 (LAPACK, the Linear Algebra PACKage) + Kay (1993) closed forms |
64 Validated · 100 Modelled · 4 Partner — SVG
Free and open source under the GNU AGPL-3.0 (GNU Affero General Public License, version 3)
— with a commercial licence available from Ashforde OÜ (an Estonian private limited
company; OÜ = osaühing) for proprietary/closed integration (see LICENSING.md).
Professionally developed and maintained by Ashforde OÜ; commercial
support, integration, and proprietary extensions available.
Status: v0.27.2 · a validated, reproducible simulation substrate for PNT resilience. A fully reproducible engine spanning the PNT stack — orbit geometry and constellation design, a numerical (Cowell) propagator with a seven-perturbation force model, maneuver and trajectory design, time systems, inertial navigation (incl. map-aided and gravity-map-matching alt-PNT), GNSS / inertial-navigation-system (INS) fusion (loose, tight, unscented Kalman filter — UKF, coupled clock+position, 17-state), orbit determination, ARAIM (advanced receiver autonomous integrity monitoring), clocks, advanced time-and-frequency transfer, the GNSS measurement domain, resilience (jamming + multi-layer spoofing), and an open deep-space / Mars radiometric navigation engine (light-time + Shapiro, CCSDS-TDM — the Consultative Committee for Space Data Systems Tracking Data Message — a reduced-dynamic square-root information filter (SRIF), one-/two-way fusion); plus first-order mission-analysis budgets (launch / re-entry / Earth-observation (EO) coverage / pointing / ground-station passes / link), a space-weather environment model, an AI/ML RF-impairment (artificial-intelligence / machine-learning, radio-frequency) evaluation testbed, and the versioned Kshana Interchange Format (KIF). Honest by design: every figure of merit is labelled validated or modelled, and optical-clock figures are space goals on ground hardware (no strontium optical clock has flown).
Validation ladder (maturity is not uniform across domains — and saying so is the point):
Domain Tier Earth PNT (orbit, frames, time, clocks, IMU — inertial measurement unit, integrity) Real-data validated — ESA SP3 (Galileo 0.13 m / 8 h · 0.61 m / 24 h, Swarm-A 0.10 m), NIST SP1065, SOFA/ERFA, heritage vectors Deep-space / Mars navigation Simulation-validated — synthetic closed-loop orbit determination (OD) + analytic self-consistency; Sun-central dynamics cross-checked vs JPL (Jet Propulsion Laboratory) DE440 (Development Ephemeris 440) (137 m @ 1-day arc) Real-mission deep-space OD Roadmap — pending real Deep Space Network (DSN) / ESTRACK (European Space Tracking network) tracking-data validation Deep-space figures (Mars-LMO — low Mars orbit — OD ≈ 0.2 m; relay-PNT orbiter 0.4 m / rover 5.1 m) are simulation / covariance figures of merit, not real-mission results. See Capabilities for what it does, What it is / is not for scope, and
docs/CAPABILITY.md/docs/VALIDATION.mdfor per-capability maturity. The overclaim closure ledgerdocs/CLAIMS-VS-REALITY.mdtracks every historical overclaim, how it was resolved, and a CI guard (tests/no_overclaims.rs) that keeps it resolved.
Try it in your browser: the playground runs the engine client-side as WebAssembly — pick a scenario, edit the parameters, and see the result, with nothing uploaded. Build it locally with
./web/build.sh(seeweb/README.md), or publish it to GitHub Pages via thepagesworkflow.
New to this? In plain terms: GPS-style (Global Positioning System) satellite signals tell things where they are and what time it is. When those signals are lost (jammed, blocked, or out of view in space), a system has to keep going on its own onboard clock and motion sensors — and they slowly drift. "Quantum" clocks and sensors drift far more slowly. Kshana measures, in honest numbers, how much longer a quantum-equipped system can coast before it exceeds its accuracy limits. New readers should start with the plain-language primer and the glossary.
Resilient PNT depends on holding position and time when GNSS is denied or jammed. Quantum sensors promise far slower drift during those outages. There is no good open tool to quantify that advantage honestly and reproducibly — so primes, agencies, and labs each rebuild private one-offs. Kshana aims to be the neutral, citable reference for exactly this question.
The engine knows nothing about "quantum" vs "classical": each sensor is an error model plugged into a common pipeline, so a quantum and a classical device are compared apples-to-apples on the same scenario, with independent noise realizations.
It is: a deterministic, dependency-light engine spanning the PNT stack — orbit geometry, inertial navigation, GNSS/INS fusion, integrity, clocks, and timing. It runs a scenario (often a GNSS outage), evolves calibrated sensor error models through the appropriate estimator, and scores the result against the operational figures of merit — emitting a reproducible JSON result and an SVG chart, from a Rust library, a command-line interface (CLI), a Python extension, an in-browser WebAssembly module, a Model Context Protocol (MCP) server for AI agents, or a JetBrains IDE (integrated development environment) plugin.
It is not: flight hardware, a quantum-payload design, a full GNSS signal
receiver, or a certified avionics product. Quantum-hardware fidelity comes from
published error models, not from this tool. The granular maturity of each
capability is documented in docs/CAPABILITY.md.
It is not (yet): a full atom-interferometry physics engine (most quantum sensors
consume published Allan/noise-budget coefficients; the CAI (cold-atom interferometer) accelerometer has a
first-principles layer — Mach–Zehnder phase, projection noise, contrast decay, and
vibration coupling — but Coriolis and light-shift systematics remain a P2 (roadmap
phase 2, the quantum physics layer) roadmap layer, see ROADMAP.md and docs/QUANTUM-MODELS.md);
a full GNSS signal-acquisition receiver (it now solves a single-point PVT (position, velocity and time) position
fix from real RINEX (Receiver Independent Exchange Format) code observations — validated
on real IGS (International GNSS Service) data — but does not
acquire or track raw signal); or a full mission-design suite (it has Lambert / porkchop /
maneuver / orbit-determination building blocks, but is the performance-simulation layer
above GMAT (General Mission Analysis Tool)/Orekit, not a replacement). Owning this scope is deliberate. If you need first-principles cold-atom
interferometer error budgets (e.g. CARIOQA-PMP-grade — Cold Atom Rubidium Interferometry
in Orbit for Quantum Accelerometry, Pathfinder Mission Preparation — or X-37B-style validation), see
the P2 roadmap and get in touch to collaborate.
One engine spans the whole PNT stack — and its maturity is honest per domain: Timing, Orbits and GNSS geometry are heavily externally validated; Lunar and several quantum/resilience domains are deliberately Modelled until real tracking data exists.
Breadth across the PNT stack, and honest maturity per domain · SVG
The full domain-by-domain detail follows; for a per-capability maturity ledger see
docs/CAPABILITY.md and docs/VALIDATION.md.
| Domain | Capability |
|---|---|
| Orbit & geometry | SGP4/SDP4 propagation (validated to 4.12 mm against all 666 AIAA 2006-6753 vectors); real two-line elements (a committed, date-stamped Celestrak gps-ops snapshot) or synthetic Walker-delta constellations whose mean elements realise the i:T/P/F formula to under 1 km over a 24 h propagation; multi-constellation visibility, dilution of precision — geometric, position, horizontal, vertical and time (GDOP/PDOP/HDOP/VDOP/TDOP), validated to 1e-6 against gnss_lib_py 1.0.4, Stanford NAV Lab (Navigation and Autonomous Vehicles Laboratory), and GNSS availability; a gradient-free constellation-design optimiser, streets-of-coverage minimum-satellite sizing, a multi-constellation comparison tool, and a Walker design sweep that tabulates coverage / PDOP / revisit-time over a planes × satellites grid and reports the Pareto-optimal designs. |
| Numerical propagator | A Cowell numerical propagator (src/propagator.rs) complementing the analytic SGP4/SDP4 path, with a hierarchical seven-perturbation force model (src/forces.rs): two-body + the full J2–J6 zonal field (the Earth-oblateness zonal harmonic coefficients J2 to J6; the exact analytic gradient of its disturbing potential), an optional EGM2008 tesseral spherical-harmonic geopotential to degree/order 70 (Earth Gravitational Model 2008; src/gravity_sh.rs; real NGA — US National Geospatial-Intelligence Agency — coefficients, Holmes–Featherstone normalized-Legendre recurrence, cross-checked against the closed-form Legendre functions and the analytic ∇V identity), epoch-driven Sun and Moon third-body gravity (a built-in low-precision ephemeris, no DE/SPK — Development Ephemeris / SPICE Spacecraft and Planet Kernel — kernel), solar-radiation pressure (cannonball model with a conical umbra+penumbra shadow), atmospheric drag (Vallado piecewise-exponential density, co-rotating atmosphere), the post-Newtonian Schwarzschild relativistic correction, and the Lense–Thirring frame-dragging term (IERS — International Earth Rotation and Reference Systems Service — Conventions 2010 §10, linear in Earth's angular momentum, ~1–2 orders below Schwarzschild) — driven by a choice of two adaptive integrators (RK4 — fourth-order Runge–Kutta — step-doubling or the Dormand–Prince RK5(4) embedded pair). Validated against Orekit 12.2 (CS GROUP, Apache-2.0) NumericalPropagator/DormandPrince853 — 275 epochs across LEO (low Earth orbit) + GTO (geostationary transfer orbit), the conservative-force tiers agreeing to a worst-case |Δr| 0.08 m over 24 h (tests/numerical_cowell_propagator_reference.rs); the atmospheric-drag tier is characterised separately (≈ 333 m / 24 h) and the absolute Sun/Moon-ephemeris and density inputs stay honestly Modelled. Additional internal evidence (not external validation): the unperturbed orbit is checked against the exact universal-variable Kepler solution to sub-metre over 24 h, energy/angular-momentum conserve to ~1e-9, and each perturbation matches a hand-derived closed-form signature. |
| Maneuvers & trajectory design | Impulsive ΔV nodes with 6×6 covariance propagation (ECI — Earth-centred inertial — / LVLH — local vertical, local horizontal — execution-error frames), finite-burn integration checked against the closed-form Tsiolkovsky rocket equation to < 0.01 %, an Izzo-2015 single-revolution Lambert solver, an exact universal-variable Kepler propagator, and a porkchop (launch × arrival) C3 (launch energy) / arrival-V∞ sweep emitted as a JSON contour grid — the performance-simulation layer above GMAT/Orekit, with every Lambert output round-tripped against two-body truth and the porkchop minimum checked against the analytic Hohmann floor. |
| Time systems & reference frames | IERS leap-second UTC / TAI / TT / UT1 scales (Coordinated Universal Time, International Atomic Time, Terrestrial Time, and the Earth-rotation time Universal Time 1), a Julian-date API, the IAU-2000 (International Astronomical Union) Earth Rotation Angle (ERA), GMST-based (Greenwich Mean Sidereal Time) TEME ↔ ECEF (true equator, mean equinox ↔ Earth-centred, Earth-fixed) with WGS-84 (World Geodetic System 1984) geodetic frames, IAU 2006 precession (Fukushima–Williams), full IAU 2000A/2000B nutation, IERS polar motion, and the equinox-free CIO-based IAU 2006/2000A GCRS↔ITRS reduction (CIO = Celestial Intermediate Origin) — all validated bit-for-bit against the SOFA/ERFA vectors, and independently cross-checked against ANISE (the pure-Rust NAIF/SPICE reimplementation; NAIF = the Navigation and Ancillary Information Facility of NASA, the US National Aeronautics and Space Administration): kshana's GCRS→ITRS vs ANISE's ITRF93 (International Terrestrial Reference Frame 1993) from JPL's earth_latest_high_prec.bpc, the same IERS Earth-orientation parameters fed to both, agree to ≤ 0.86 m on the ground / ≤ 3.6 m at GNSS orbit (max 0.028″) across eight epochs 2020–2023. |
| Inertial | Three-axis strapdown INS — quaternion attitude, WGS-84 NED (north-east-down) mechanization, coning/sculling compensation, and a deterministic IMU error model (scale-factor, misalignment, g-sensitivity, quantization, drift); a first-principles cold-atom-interferometer accelerometer (Mach–Zehnder phase, quantum projection noise, contrast decay, vibration coupling) that derives the velocity-random-walk coefficient; and a sequential-importance-resampling particle filter for map-aided (terrain-/gravity-referenced) GPS-denied navigation. |
| Alt-PNT (GPS-denied) | A cold-atom gravimeter measurement model whose white-noise floor (σ = ASD/√τ, ASD = amplitude spectral density) is derived from the CAI accelerometer physics; a low-degree, fully-normalised spherical-harmonic gravity-anomaly field (checked against the closed-form Legendre functions and a hand-derived single-term anomaly) plus synthetic mascons; the gravity-functional synthesis kernel (gravity_sh::gravity_magnitude / gravity_disturbance_mgal) — the "map reader" a gravity-aided navigator matches against — is validated against the GRS80 normal-gravity standard (Geodetic Reference System 1980), reproducing the closed-form Somigliana normal gravity and the published γ_e / γ_p to 3.5e-12 and producing a physically-bounded disturbance map from the real ICGEM (International Centre for Global Earth Models) EGM2008 field (RMS — root mean square — ≈ 26 mGal, max ≈ 89 mGal at d/o 70; tests/icgem_gravity_reference.rs); and a gravity-map-matching particle filter that recovers a GPS-denied track from the anomaly sequence it flies through. It extends to terrain-referenced navigation (TERCOM/SITAN — terrain contour matching / Sandia Inertial Terrain-Aided Navigation — against an SRTM (Shuttle Radar Topography Mission) .hgt DEM (digital elevation model), src/altpnt/terrain.rs), an IGRF-14 geomagnetic main field (14th-generation International Geomagnetic Reference Field) to degree/order 13 (src/igrf.rs, checked against the tilted-dipole closed form and ∇V finite differences), and a combined gravity + magnetic + terrain navigator that fuses all three scalar channels through one particle filter (information is additive — no channel makes the fix worse). A 60-minute GPS-denied benchmark (a ~700 km / one-hour outage where the inertial solution drifts to ~70 km) is recovered to ~145 m (< 500 m) by a hierarchical coarse-to-fine matcher — the ESA NAVISP (Navigation Innovation and Support Programme) Quantum Wayfarer target. |
| Fusion | Loosely-coupled 15-state GNSS/INS error-state EKF (extended Kalman filter) with closed-loop feedback (the gnss-ins pack); a tightly-coupled pseudorange update that keeps correcting with fewer than four satellites; a coupled clock + position filter; a general unscented (sigma-point) Kalman estimator for strongly nonlinear measurements; a tightly-coupled GNSS/INS UKF navigator (pseudorange + Doppler) whose force-model orbital coast is self-consistency-checked to 0.77 m RMS over a 30-minute curving LEO pass that includes a 120-second GNSS outage (a filter-consistency figure, not an external-oracle validation — this navigator stays MODELLED); and a full 17-state tightly-coupled GNSS/INS UKF (position, velocity, attitude error, accelerometer and gyro biases, clock bias and drift) whose quantum-CAI dead-reckoning coasts a 120-second outage on the cold-atom accelerometer's derived velocity-random-walk. |
| Orbit determination | Recovery of an orbital state [r, v] from ground-station range tracking, composing the two-body + J2 force model and RK4 integrator with a Gauss–Newton batch corrector (determine_orbit_batch, sub-metre / mm·s⁻¹ from noiseless ranges, ~2 m at a 5 m noise floor) and a sequential unscented-filter variant (determine_orbit_sequential). |
| Observability & estimation theory | A general, reusable Fisher-information / Cramér–Rao layer (src/fim.rs): the information matrix M = HᵀWH, the Cramér–Rao lower bound, observability rank and datum-defect null space (Moore–Penrose pseudo-inverse), and D/A/E/T-optimal experiment-design scalars from a symmetric Jacobi eigensolver. Validated — eigenvalues vs numpy.linalg.eigh, the CRLB covariance vs σ²(XᵀX)⁻¹ via numpy.linalg.inv, and GNSS DOP from the information matrix, all matched to 1e-9 (tests/fim_observability_reference.rs), and additionally cross-checked against the Kay (1993) closed-form bounds with Monte-Carlo CRLB attainment. It underpins the DOP engine, the passive-geolocation CRLB, and the lunar absolute-station observability theorem (below). |
| Lunar & cislunar | An Earth–Moon circular restricted three-body (CR3BP) propagator in the rotating frame — conserved Jacobi constant and all five Lagrange points (src/cr3bp.rs) — now with a 6×6 state-transition matrix (STM) and a single-shooting differential corrector (cr3bp_jacobian, propagate_state_stm, differential_correct_halo) that produces genuinely periodic halo / NRHO (near-rectilinear halo orbit) orbits: the STM is validated against finite differences, corrected orbits close to machine precision, and seeding the published apolune state reproduces the L2 southern 9:2 NRHO (L2 = the second Earth–Moon Lagrange point; the Gateway orbit) at period ≈ 6.57 d / perilune ≈ 3,250 km, consistent with the published ≈ 6.56 d / ≈ 3,370 km (a CR3BP — circular, Sun-free — solution, not validated against a real LANS (Lunar Augmented Navigation Service)/Gateway ephemeris; the selenocentric MCI/MCMF (Moon-centred inertial / Moon-centred, Moon-fixed) transform of the corrected orbit is a follow-on); plus LunaNet / LNIS (LunaNet Interoperability Specification) cislunar PNT geometry (MCI↔MCMF reduction, selenographic coordinates) with a lunar south-pole ARAIM pass that honestly surfaces the integrity gap: a ~30 m σ_URE (user range error) drives the protection level well above a 50 m alert limit (src/lunar.rs, scenarios/lunanet-araim.toml); and a surface-beacon DOP augmentation (src/lunar_beacon.rs) showing how a few surveyed surface ranging beacons supply the low-elevation, wide-azimuth line-of-sight rows an all-overhead orbit-only set lacks — collapsing the ill-conditioned south-polar GDOP and, via a root-sum-square error budget, the realized position accuracy in metres (reusing the gnss_lib_py-validated DOP kernel and the airless-horizon visibility closed form; the dilution-of-precision analysis is written up in arXiv:2607.06212). |
| Lunar PNT suite | A modelled lunar/cislunar navigation suite layered on the CR3BP core, each a runnable kind: Lunar Coordinate Time (lunar-time-offset, src/lunar_time.rs — the secular LTC/TCL − TT rate (LTC = Lunar Coordinate Time; TCL = its French form, Temps-Coordonnée Lunaire) from the self-potential difference + kinetic term, reported with the published 56–59 µs/day band); a geodetic lunar VLBI (very-long-baseline interferometry) delay observable (lunar-vlbi, src/lunar_vlbi.rs — an Earth-baseline near-field two-range-difference delay + rate, cross-checked against the same-codebase plane-wave Δ-DOR (delta differential one-way ranging) in the far-field limit, partials finite-difference-verified); a joint multi-technique OD + clock batch estimator (lunar-joint-od-clock, src/lunar_combination.rs — a Gauss–Newton fit fusing VLBI + lunar-local ranges + inter-satellite ranges) carrying a Fisher-information observability result: internal ranging alone leaves a six-degree-of-freedom rigid-body datum defect, so a surface station's absolute position is unobservable until an Earth-frame tie is added — an Earth-baseline VLBI delay restores observability for a sparse constellation and sharpens the Cramér–Rao bound for a rich one, the absolute datum closing at three non-collinear Earth stations (the observability result written up in arXiv:2607.02566); reference-frame realisation (lunar-frame-realisation, src/lunar_frame_realise.rs — a 7-parameter Helmert datum fit + IAU 2015 WGCCRE orientation tie — WGCCRE = the IAU Working Group on Cartographic Coordinates and Rotational Elements); a Moonlight/LCNS-class service-volume analysis (LCNS = Lunar Communications and Navigation Services; moonlight-service-volume, src/lunar_service.rs — DOP / coverage / availability + a generalised lunar ARAIM HPL/VPL (horizontal/vertical protection level) envelope, reusing the gnss_lib_py-validated DOP kernel and the LunaNet σ_URE≈30 m machinery); lunar differential PNT (lunar-differential-pnt, src/lunar_dpnt.rs — a lunar differential-GNSS / satellite-based-augmentation-system (SBAS) analogue: exact common-mode clock cancellation + first-order spatial decorrelation vs baseline, reusing the DO-229E SBAS protection level — DO-229E being the RTCA (formerly the Radio Technical Commission for Aeronautics) minimum operational performance standard for SBAS receivers); and a LunaNet/IOAG-aligned interoperability export (IOAG = Interagency Operations Advisory Group; lunar-interop-export, src/lunar_interop.rs — CCSDS-OEM (Orbit Ephemeris Message) + lunar-time-scale round-trip in the IAU 2015 lunar body frame, wrapped in the KIF envelope). All MODELLED against internal consistency / reference implementations from illustrative public-source parameters — not validated against real VLBI/Gateway tracking, not affiliated with or endorsed by any agency, no TRL (technology readiness level) / heritage claim. |
| Deep-space & Mars PNT | An open radiometric navigation engine: iterative light-time + Shapiro relativistic delay, two-/one-/three-way Doppler & range (Moyer two-leg), coherent transponder turnaround ratios, regenerative/PN (pseudo-noise) ranging (CCSDS 414, the pseudo-noise ranging standard), and Δ-DOR plane-of-sky (CCSDS 506, the Delta-DOR standard), with solar-plasma/tropo/iono media; CCSDS-TDM (503) tracking-data-message parse + emit; a reduced-dynamic Square-Root Information Filter (RTN — radial, transverse, normal — empirical accelerations + a 3-state onboard clock + Mars atmospheric drag) that does Mars-LMO orbit determination to ≈ 0.2 m in a synthetic closed loop; a joint one-way + two-way fusion estimator; a multi-body dynamics core (Body{μ, re, zonals, gravity, IAU-pole}, Mars GMM-3 (Goddard Mars Model 3) gravity, an IAU body-fixed Mars frame, a pluggable EphemerisProvider seam, two-part Julian dates + TT↔TDB (Barycentric Dynamical Time)); and the mars-pnt relay-PNT scenario (a MARCONI areostationary relay constellation) with an end-to-end GSE performance simulator (GSE = ground-support equipment) (geometry → link budget → observables → SRIF → covariance). Simulation-validated (covariance / closed-loop figures of merit); the Sun-central Mars dynamics are cross-checked against JPL DE440 (137 m @ 1-day arc, xval/anise-mars-od). Real DSN/ESTRACK tracking-data validation is on the roadmap. |
| Integrity | Snapshot and solution-separation (ARAIM-style) RAIM — receiver autonomous integrity monitoring — with horizontal/vertical protection levels (HPL/VPL), fault detection & exclusion, and Stanford integrity diagrams; an explicit integrity-risk-budget multiple-hypothesis solution separation (MHSS) protection level, including the dual-/multi-constellation constellation-wide fault mode (EU ARAIM / DO-316, the RTCA performance standard for GPS airborne equipment with aircraft-based augmentation), exercised on a real GPS + Galileo snapshot (scenarios/araim-gps-galileo.toml). The protection level applies the one-sided nominal-bias projection `b_k = Σ_i |
| Augmentation (SBAS) | SBAS / WAAS protection levels (WAAS = the Wide Area Augmentation System) in the DO-229E weighted-least-squares form (precision-approach and en-route K-factors) and the L1/L5 dual-frequency ionosphere-free combination (L1 and L5 being two GPS civil signal bands; IS-GPS-705, the GPS interface specification for the L5 signal, γ₁₅ ≈ 1.793) that underpins DO-316 — src/sbas.rs. The protection-level algorithm is externally validated against the RTKLIB SBAS-PL fork (RTKLIB = the open real-time-kinematic positioning library; PL = protection level) (zsiki/rtklib_ws waasprotlevels(), Siki & Takács 2017, DO-229D — the previous revision of DO-229 — App. J) run on real EGNOS data (European Geostationary Navigation Overlay Service), reproducing its HPL to < 2e-3 m (tests/sbas_reference.rs); gLAB (the GNSS Laboratory tool suite) v6.0.0 confirmed the identical convention. |
| Clock & timing | Two-state Kalman holdover (Joseph-form covariance, NIS/NEES — normalised innovation squared / normalised estimation error squared — consistency health); Allan-family stability (ADEV / MDEV / TDEV / HDEV / MTIE — Allan, modified Allan, time and Hadamard deviation, and maximum time interval error) with noise-type-specific confidence intervals and a full IEEE-1139 five-coefficient power-law fit (IEEE Std 1139, the Institute of Electrical and Electronics Engineers frequency-and-time metrology definitions) — the estimators are validated on real hardware against Stable32: a real 5071A caesium primary standard vs a hydrogen maser (556,990 phase samples, 16 averaging factors, OADEV/OHDEV — overlapping Allan/Hadamard deviation — to 1e-3; tests/cs5071a_reference.rs) and the canonical Stable32 PHASE.DAT regression series (139 averaging factors, OADEV/MDEV/TDEV to 1e-3; tests/phasedat_reference.rs); the ADEV/MDEV/TDEV estimators and the telecom MTIE wander metric are additionally cross-checked against the independent allantools 2024.06 library to < 1e-9 on the NIST SP 1065 series (tests/mtie_reference.rs, tests/mdev_tdev_reference.rs); geometric corrections (Sagnac, GNSS common-view); and the operational transfer methods — TWSTFT (two-way satellite time and frequency transfer) with the BIPM (International Bureau of Weights and Measures) Sagnac closed form, GNSS common-view, PPP (precise point positioning) ionosphere-free time transfer, a free-space optical link with turbulence scintillation, and an inverse-variance clock-ensemble (paper) timescale below the best contributing clock. A GNSS-denied clock-holdover calculator (src/holdover.rs) exposes the closed-form van-Loan coast-error growth as a holdover-to-threshold inversion — how long a clock free-runs before its timing error exceeds budget — across representative classical and quantum-clock classes; modelled (cross-checked against the multi-step clock_state covariance recursion), and honest that for a very stable clock the holdover to a tight threshold is set by the assumed long-tau noise floor, not the cited ADEV. A conditional Timing Protection Level (src/tpl.rs) extends holdover to spoofing: a bound on the undetected time error, given an independent cross-check, that composes a k-sigma monitor floor, the van-Loan coast variance over the detection latency, and a CUSUM (cumulative-sum) time-to-alarm. Calibrated on a real recorded spoof (JammerTest 2024) and reproducible via cargo run --example tpl_jammertest; MODELLED composition (no integrity-risk-per-hour budget), conditional on detection — there is no finite unconditional bound. |
| GNSS measurement domain | Forward pseudorange / Doppler synthesis with Klobuchar (broadcast) and IONEX / TEC-grid (IONosphere map EXchange format / total electron content; measured) ionosphere — including an IONEX file parser, time interpolation between maps, and the thin-shell slant-obliquity mapping — Saastamoinen + Niell troposphere, and snapshot RAIM (HPL/VPL). |
| Resilience | Link-budget jamming (J/S → effective C/N₀ → loss of lock — jammer-to-signal ratio, carrier-to-noise-density ratio — with the anti-jam spectral-separation factor Q now derived from the actual signal and jammer power spectra via src/navsignal.rs — Q = 1/(R_c·κ), cross-checked in CI against the previous representative constant); a stochastic time-spoof detector (Neyman–Pearson / χ²₁ energy test with closed-form and Monte-Carlo P_fa/P_md and a Security figure of merit (FoM) of 1 − P_md); and a multi-layer spoof detector fusing a RAIM-consistency parity test (with the common-mode blind spot modelled honestly), an RF AGC-power (automatic gain control) monitor, and a signal-quality (SQM — signal-quality monitoring, early-minus-late) monitor; and a quantum-inertial dead-reckoning error budget (QuantumNavBudget, src/inertial/quantum_imu.rs) composing the cold-atom-interferometer white-noise velocity-random-walk with residual bias (cross-checked against the independent AccelModel integrator) and scale-factor error into a position-drift-over-holdover figure — the inertial twin of the clock holdover. A framework-aligned resilience-scoring engine (src/resilience/) maps an architecture's simulated behaviour to per-dimension sub-scores across the DHS RPCF categories (the US Department of Homeland Security Resilient PNT Conformance Framework), then studies the decision-stability of any single composite score or maturity Level under a Dirichlet weighting simplex and a five-threat ensemble — Kendall-τ rank instability, top-1 winner flip rate, and common-mode diversity collapse (Hill-N2), with an integrity-hashed assurance report (35 hand-derived oracle tests). Reproducible via cargo run --example resilience_report; MODELLED synthetic architectures, a self-assessment aligned to RPCF v2.0, not a certification. See docs/RESILIENCE-CROSSWALK.md. |
| Passive RF geolocation | TDOA/FDOA emitter geolocation (time-/frequency-difference of arrival; src/geolocation.rs) — locate a jammer or spoofer (or an opportunistic source for reverse-PNT) from time-difference-of-arrival hyperboloids across a receiver network, solved by Gauss–Newton least squares; adding frequency-difference-of-arrival with moving receivers jointly recovers the emitter's position and velocity, with the Cramér–Rao bound on the position covariance derived from the network geometry. MODELLED (internal-consistency oracles: forward→inverse round-trips, the J·CRLB = I identity, GDOP monotonicity, and the estimator attaining its own CRLB under Monte-Carlo) — a point-source line-of-sight model, no multipath / NLOS (non-line-of-sight), receiver-clock-bias, or refraction terms. |
| Nav-signal & code tracking | The signal level between the link budget and the measurement domain (src/navsignal.rs): unit-area power spectral densities (PSDs) for BPSK-R(n) (binary phase-shift keying with rectangular chips) and sine-BOC(m,n) (binary offset carrier); the spectral-separation coefficient (SSC) κ = ∫ G_s·G_i df, which derives the anti-jam Q the jamming model uses (Q = 1/(R_c·κ)) from the actual signal/jammer spectra instead of a representative constant; the RMS (Gabor) bandwidth (BOC > BPSK — the ranging-information / Cramér–Rao measure); the coherent early–late DLL code-tracking thermal-noise jitter (DLL = delay-lock loop; Kaplan & Hegarty; ~sub-metre for C/A — the GPS coarse/acquisition code — at 45 dB-Hz); and the multipath error envelope (coherent EML, early-minus-late — narrow-correlator suppression). Validated against closed-form anchors (BPSK self-SSC = 2/(3·R_c), unit-area PSDs, sub-metre C/A jitter). This is signal-performance analysis, not antenna / RF-payload hardware design (a payload partner's role). |
| Interoperability | RINEX-3 multi-GNSS broadcast-ephemeris ingestion (GPS, Galileo, QZSS — Japan's Quasi-Zenith Satellite System —, BeiDou MEO/IGSO — medium Earth orbit / inclined geosynchronous orbit — via IS-GPS-200, the GPS interface specification; GLONASS, Russia's Global Navigation Satellite System, via PZ-90 — the Russian Parametry Zemli 1990 datum — state-vector RK4) usable as a constellation source (RINEX in, PNT geometry out); a RINEX-3 observation parser (pseudorange, carrier phase, Doppler, signal strength; the 4.00 observation layout is expected to parse but is untested, and RINEX 4 navigation files are refused by name rather than mis-decoded) that now feeds a single-point-positioning (SPP) solver (pvt) — real code observations in, a real receiver position out, validated on IGS data; an SP3-c/d precise-ephemeris reader/writer with 9th-order Lagrange interpolation; and CCSDS OEM 2.0 + OMM (Orbit Mean-elements Message) export for flight-dynamics tools (GMAT, Orekit, STK — Systems Tool Kit); and CCSDS-TDM (503) tracking-data-message parse + emit for deep-space radiometric tracking. |
| Mission analysis (systems engineering) | First-order mission-design budgets, each a runnable kind: two-body launch & ascent geometry (launch-window — launch azimuth sin Az = cos i/cos lat, minimum inclination, Earth-rotation bonus, dogleg plane-change Δv, daily opportunities; src/launch.rs); an Allen–Eggers ballistic re-entry corridor (reentry — peak deceleration, peak-g velocity/altitude, peak-heating velocity; src/reentry.rs); Earth-observation coverage geometry (eo-coverage — swath / nadir GSD (ground sample distance) / off-nadir access / revisit via the SMAD (Space Mission Analysis and Design) space triangle; src/eo_payload.rs); a 3-DOF attitude & pointing error budget (three-degree-of-freedom; attitude-budget — worst-case gravity-gradient torque + RSS (root-sum-square) pointing budget; src/attitude_budget.rs); ground-station pass prediction (passes — AOS/TCA/LOS, acquisition of signal / time of closest approach / loss of signal, max elevation, access time; src/passes.rs); and a one-way link budget over the CCSDS 401 / DSN 810-005 link equation (the CCSDS radio-frequency and modulation standard / the Deep Space Network link design handbook; link-budget — FSPL (free-space path loss), C/N₀, Eb/N₀ (energy-per-bit to noise-density ratio), margin, closure; src/linkbudget.rs). MODELLED first-order analytic budgets — the pre-hardware layer below STK/GMAT/Basilisk, not a 6-DoF or radiometric replacement. |
| Decision analysis & trade-off (MCDA) | A full multi-criteria decision-analysis (MCDA) suite (src/mcda/) spanning all four method families — value aggregation (WSM, WPM, WASPAS — weighted sum model, weighted product model, weighted aggregated sum product assessment), distance-to-ideal (TOPSIS, Technique for Order of Preference by Similarity to Ideal Solution), compromise programming (VIKOR, from the Serbian for multi-criteria optimisation and compromise solution), and outranking (PROMETHEE II, Preference Ranking Organization Method for Enrichment of Evaluations; ELECTRE I, from the French for elimination and choice expressing reality), plus ratio-system MOORA (Multi-Objective Optimization on the basis of Ratio Analysis) and proportional COPRAS (Complex Proportional Assessment) — with AHP (Analytic Hierarchy Process) pairwise-comparison priority weighting (Consistency Ratio), a Pareto non-dominated front, weight-sensitivity analysis, and multi-attribute utility scoring. The nine aggregators reproduce the independent third-party libraries pymcdm (WSM / WPM / WASPAS / MOORA / TOPSIS / VIKOR / PROMETHEE II) and pyDecision (ELECTRE I, COPRAS) to < 1e-9, and the AHP priority vector + Consistency Ratio match Saaty's Random-Index table and the SciPy/LAPACK principal eigensolver to < 1e-9 (tests/mcda_*_reference.rs). VALIDATED — the decision layer under the trade-study engine. |
| Space environment | A space-weather environment model (space-weather, src/space_weather.rs): solar (F10.7 / centred-81-day F10.7a — the 10.7 cm solar radio flux) and geomagnetic (Kp, the planetary K-index, with the definitional Kp↔ap table — ap being its linear planetary amplitude) activity indices, the Jacchia-1971 exospheric temperature they drive (validated vs published solar min/mean/max), and the activity-corrected vs static thermospheric neutral density at altitude — the solar-cycle density dependence the static USSA76 (US Standard Atmosphere 1976) atmosphere omits. MODELLED: a calibrated first-order scale-height coupling, not a data-validated (NRLMSISE — the US Naval Research Laboratory Mass Spectrometer and Incoherent Scatter Radar Exosphere model) atmosphere. |
| AI/ML evaluation & trade | An RF-impairment detection evaluation testbed (impairment-eval, src/impairment_eval.rs): a labelled, parameter-grounded synthetic corpus (nominal / jamming / spoof-time / spoof-position / multipath), a detector-agnostic ROC/AUC (receiver operating characteristic / area under the curve) harness scoring any detector (energy | agc | sqm | parity | fused) with per-class Pd (probability of detection) at a target Pfa (probability of false alarm), and the in- vs out-of-distribution optimism gap (distribution-shift mode). Plus a quantum-vs-classical PNT trade (quantum-trade, src/quantum_trade.rs) quantifying a candidate clock's timing/inertial holdover benefit from a measured-ADEV curve vs a classical baseline, with the long-τ floor caveat carried on the artifact and a GNSS-denied resilience-vs-time envelope. The evaluation metrics (AUC / confusion / Pd-Pmd, Pmd being the probability of missed detection) are validated to an exact match against scikit-learn 1.9.0 — including on real ESA OPS-SAT telemetry (the OPSSAT-AD anomaly-detection dataset, Ruszczak et al. 2025, CC BY 4.0 — Creative Commons Attribution 4.0), where Kshana's Mann–Whitney ROC AUC reproduces scikit-learn's roc_auc_score to < 1e-9 on the held-out test split and a transparent peak-count detector separates the labelled anomalies at AUC ≈ 0.85 (tests/opssat_ad_reference.rs) — and the trade engine's numerical kernels (ADEV NNLS — non-negative least squares — fit, χ² consistency bands, van-Loan clock Q) against scipy 1.17.1; the device-benefit numbers built on top stay MODELLED operating characteristics — never field/IQ (in-phase/quadrature sample) data, no good/bad verdict. Building on the testbed, a deeper optimism-gap study (src/impairment_study.rs, impairment_ml.rs, eval_stats.rs) scores a 13-detector panel (energy/AGC/SQM/parity plus seeded logistic-regression and one-hidden-layer-MLP — multi-layer perceptron — detectors), fits in- vs out-of-distribution scaling laws with a permutation null, and learns a leave-one-out predictor of out-of-distribution degradation from in-distribution statistics (cargo run --example optimism_study). A software-defined-receiver front end (src/sdr.rs — raw IQ/IF (intermediate-frequency) → correlator early/prompt/late taps → SQM) and real-data ingest adapters (src/realdata/ — RINEX, u-blox UBX (the u-blox binary protocol), GnssLogger, JammerTest, Yunnan, SatGrid) let the same detectors run over recordings supplied locally (no datasets are committed). The quantum-vs-classical resilience crossover map under parameter uncertainty (src/crossover.rs; cargo run --bin crossover_study) regenerates the inertial and clock crossover studies behind the Results figures. |
| Quantum-Enabled PNT demonstrator | Three runnable, MODELLED application areas behind the open engine, each emitting honest TradeEvidence + a representativeness / gaps-to-flight record (src/representativeness.rs): trusted quantum time transfer (quantum-time-transfer, src/timetransfer_chain.rs — an end-to-end optical-lattice-clock + photonic-link vs CSAC (chip-scale atomic clock) + RF two-way budget, with a reused timing protection level, a delay/replay-attack security FoM (1 − P_md), and clock-anomaly detection + CUSUM latency); GNSS-free quantum navigation (quantum-gnss-free-nav, src/quantum_nav_od.rs — a cold-atom-interferometer inertial coast vs a navigation-grade INS over a GNSS outage, honest that with no external fix the accelerometer bias is unobservable so the error still grows); and quantum-system fault/anomaly detection (quantum-anomaly-detect, src/quantum_faults.rs — a labelled fault catalogue with a bootstrap-CI (confidence-interval) ROC AUC from the externally-validated eval_stats and a minimum-detectable-fault at a fixed false-alarm rate). A shared quantum device error-model library (src/quantum_devices.rs) and a unified quantum-vs-classical trade harness (src/qtrade.rs) underpin them. The validated kernels they ride (eval-metrics vs scikit-learn, trade kernels vs scipy) are reused; the device-benefit numbers built on top stay MODELLED — illustrative public-source device/link parameters, models the class, no TRL / flight heritage / certification, no agency endorsement. |
| Frugal engineering & integrity impact | A cost-per-coverage ROI (return on investment) lens (src/frugal.rs) — cost per unit of delivered coverage for an architecture trade — and a detection-miss → integrity-impact mapping (src/integrity_impact.rs) that turns a monitor's missed-detection rate into its integrity-risk contribution. MODELLED decision-support budgets, additive. |
| Artifact interchange | The Kshana Interchange Format (KIF) (src/interchange.rs) — a versioned, self-describing envelope wrapping a scenario result with its kind, schema version, and MODELLED/VALIDATED labels, so a stored artifact stays self-documenting and older envelopes remain forward-compatibly readable. |
Each capability is reachable as a Rust API, a runnable scenario kind, or both.
Maturity per capability — validated, runnable, or library — is tracked in
docs/CAPABILITY.md. A machine-checked verification matrix
(src/verification.rs) renders the requirement → module → test → oracle → status
cross-reference, with unit-tested honesty invariants that permit a validated label
only where an independent external oracle backs it — and that record the
hardware/PA (product-assurance) capabilities Kshana deliberately does not provide.
Each scenario compares a quantum sensor against its classical counterpart through a
~1.8 h GNSS outage. Numbers are reproducible (scenario + seed + version).
What quantum sensors buy when GNSS is gone — clock-holdover · seed 42 · drawn at engine 0.22.0, and every figure above re-checked against the current engine on each build by tests/published_figures_still_reproduce.rs · SVG
The advantage is outage- and vibration-dependent, with an explicit break-even where classical wins — shown honestly across the technology-readiness ladder (optical-clock figures are ground-demonstrator targets; no strontium optical clock has flown):
Quantum-vs-classical resilience crossover — clock holdover TRL ladder (top) · inertial advantage map with break-even contour (bottom). Regenerable via cargo run --release --bin crossover_study.
Dead-reckoning position error during a GNSS outage: the quantum sensor (blue)
stays flat near the spec; the classical sensor (red) diverges to tens of kilometres.
Generated by Kshana from scenarios/imu-deadreckoning.toml.
| Pack | Scenario | Quantum | Classical |
|---|---|---|---|
| 1 — Clock holdover | clock-holdover.toml (20 ns spec) | optical clock holds the full outage | CSAC breaches the spec mid-outage |
| 2 — Inertial dead-reckoning | imu-deadreckoning.toml (100 m spec) | cold-atom: ~41 m, holds full outage | nav-grade: breaches in ~350 s → tens of km |
| 3 — Time transfer (optical inter-satellite link) | timetransfer.toml | optical: ~0.3 mm ranging | RF (TWSTFT): ~150 mm ranging |
| 4 — Hybrid fusion (capstone) | hybrid-pnt.toml | full position+timing for the whole outage | position-limited at ~350 s |
The capstone shows the fusion thesis: optical inter-satellite time-transfer keeps even a classical clock locked, isolating the inertial sensor as the classical suite's weak link — i.e. quantum inertial + optical timing together.
Clock holdover through a GNSS outage: the optical clock (blue) stays inside the
20 ns spec for the full coast; the chip-scale clock (red) breaches it part-way.
Generated by Kshana from scenarios/clock-holdover.toml.
A further scenario, orbit-gnss-challenged.toml, derives GNSS availability from
orbital geometry rather than hand-authored windows: a spacecraft inside the GNSS
shell is propagated against a GPS-like Walker constellation, and the visible-satellite
count (line-of-sight, Earth-occultation, elevation mask) sets the fix state at each
step. Over a day the user is in fix only ~59% of the time; the quantum clock holds a
5 ns timing solution through every gap (availability 1.0), the chip-scale clock
only ~0.83.
Timing error over a day with GNSS availability derived from orbital geometry: the
visible-satellite count (line-of-sight, Earth-occultation, elevation mask) sets the fix
state at each step, so the clock must coast every gap — the optical clock holds the 5 ns
spec while the chip-scale clock breaches it. Generated by Kshana from
scenarios/orbit-gnss-challenged.toml.
The constellation can also be given as real two-line element sets (TLEs). A full TLE
(line 1 + line 2) is propagated with the full SGP4/SDP4 model — including
atmospheric drag and the deep-space lunar-solar and 12 h / 24 h resonance terms that
matter for ~12 h GNSS orbits — validated against the official AIAA 2006-6753 vectors
to a worst-case ≈ 4 mm. scenarios/orbit-sgp4-gps.toml ships a real Celestrak
gps-ops snapshot of the operational GPS constellation (2021-07-28, 30 satellites)
and requires valid TLE checksums — two-line element sets are open data from the US
Space Force / 18th Space Defense Squadron catalogue, redistributed by Celestrak
(Dr T. S. Kelso, celestrak.org); refresh with
scripts/fetch_tles.sh. A line-2-only block keeps
the analytic two-body propagation (scenarios/orbit-real-tle.toml); the two forms can
be mixed in one constellation. A constellation can equally be built from a block of
RINEX-3 GPS broadcast-ephemeris records — the format a receiver decodes —
propagated by the IS-GPS-200 user algorithm and fed through the same geometry
(scenarios/orbit-rinex.toml).
Requires a Rust toolchain (≥ 1.85, the rust-version in Cargo.toml; developed on 1.93).
Run any scenario; the CLI dispatches on the scenario's kind field and writes
<scenario>.result.json, <scenario>.chart.svg and <scenario>.report.html next to
it — plus <scenario>.table.csv for the kinds that publish a table:
Other CLI modes — lint a scenario, feed real Earth-orientation data, or run a whole suite:
A suite manifest is a small TOML (Tom's Obvious, Minimal Language) file — a title and a scenarios = [ … ] array of
scenario paths — that the engine runs in turn, folding every result (with its
MODELLED / VALIDATED labels) into one self-describing study artifact. See
scenarios/quantum-pnt-demonstrator.suite.toml.
Interoperability role. Kshana is the performance-simulation layer that sits
alongside the post-processing toolchain, not a replacement for it: feed its RINEX
output into RTKLIB or gLAB for a position solution, and use its SP3 output as a
precise-orbit product for tools like Ginan — Kshana answers what resilience a given
PNT architecture buys before you have real signals, in formats those tools already
ingest (--export-sp3, or export_sp3 = true in an orbit scenario, writes
<scenario>.sp3). The same orbit can be published as standards-track CCSDS OMM
mean elements (--export-omm, or export_omm = true, writes <scenario>.omm) —
one OMM 502.0 KVN (keyword = value notation) message per TLE-defined satellite, carrying each object's real
NORAD (North American Aerospace Defense Command) catalogue number, COSPAR (Committee
on Space Research) international designator, and epoch, for any
OMM-aware consumer instead of a bespoke two-line element set.
Example output (clock holdover — note the Integrity and Security figures of merit):
The optical clock's tight detection floor keeps security 0.997; the chip-scale
clock's own noise over the monitoring window exceeds the 20 ns spec, so it has no
spoof-detection margin (security 0.000). The orbit scenario additionally reports a
geometry block — fraction of samples with a fix, and best/median PDOP and position
accuracy — alongside the clock result.
Read these two numbers carefully.
securityis an analytic spoof-detectability bound derived from each clock's stability — it is meaningful only against a configured spoofing scenario and is not a multi-satellite RAIM detector.integrityhere is the filter's self-consistency (fraction of outage samples inside its own k-sigma bound), not an aviation HPL/VPL integrity figure. Seedocs/INTEGRITY.md.For genuine receiver-autonomous integrity, the
integrityscenario kind (scenarios/integrity-raim.toml) runs real snapshot and solution-separation (ARAIM-style) RAIM over the propagated constellation geometry: it computes horizontal/vertical protection levels (HPL/VPL) per epoch and reports the fraction of epochs that meet the configured alert limits, with a Stanford integrity diagram for error-vs-PL (protection level) classification.
Four open studies each regenerate a byte-deterministic artifact (fixed seed) from one command — the numbers behind the quantum-vs-classical crossover, RF-impairment optimism-gap, PNT-resilience-scoring, and timing-protection-level studies:
Each artifact records its engine version, seeds, and a config hash and carries an honest
MODELLED/VALIDATED label. The real-data probes (*_probe) run the same pipeline over
recordings you supply locally; no datasets are shipped in the repo. The RF-impairment
optimism-gap study is written up in the preprint
arXiv:2606.22054, and the conditional timing
protection level (tpl_jammertest above) in the preprint
arXiv:2606.24210 (see Citing).
The published lunar-PNT studies (arXiv:2607.06212
surface-beacon DOP and arXiv:2607.02566 VLBI
observability) have their geometry, dilution-of-precision, real-time frame /
Earth-orientation-parameter (EOP) prediction, distant-retrograde-orbit and RF-ranging
claims independently cross-checked in
tests/validate_p*.rs against separate oracles (scipy.special.j1, an independent NumPy
(HᵀH)⁻¹ DOP solve, a NumPy re-parse of the same IERS finals2000A rows, and the
NASA/JPL Three-Body Periodic Orbit Database). These are additional regression checks over
the modelled lunar suite; they do not change the machine-checked matrix count.
An optional Python extension (PyO3, abi3 — the stable Python binary interface) wraps the same engine. Build and install it with maturin:
Beyond run / run_full / version, the module exposes run_typed (a structured
result object), validate_toml (lint → list of error strings), list_kinds /
scenario_kinds (the dispatchable kinds), and error_kind (the KshanaError tag for
a rejected scenario) — see docs/PYTHON_API.md.
Wheels are built for Linux, macOS, and Windows by the wheels workflow on each
release tag.
The engine also runs in the browser via wasm-pack:
The module also exports summary (the one-line result string), table_csv (the
scenario's CSV table, or undefined for kinds that publish none), run_all (all four
from a single engine run, as a JSON object string — each of the others runs the scenario
afresh), list_kinds /
error_kind (introspection), and encode_permalink / decode_permalink — the
shareable-URL codec the playground uses to round-trip a whole scenario through the
address-bar fragment.
Kshana ships an MCP server, kshana-mcp,
so AI assistants and agents can run the actual engine instead of guessing the
math — usable from Cursor, JetBrains AI Assistant / Junie, and any MCP-compatible
assistant or agent. It exposes seven tools — run_scenario, list_scenario_kinds,
validate_scenario, export_sp3, export_omm, export_oem and export_table_csv
(each a thin wrapper over kshana::api).
Then register kshana-mcp in your client's mcpServers config. In Claude Code it's one
command — claude mcp add kshana -- kshana-mcp — or install the plugin:
/plugin marketplace add ashfordeOU/kshana then /plugin install kshana@ashforde.
Copy-paste config for Claude Code, Claude Desktop, Codex, Cursor, VS Code, Windsurf and
JetBrains is in docs/integrations.md (per-client snippets also in
mcp/kshana-mcp/README.md). The
server is a standalone, workspace-excluded crate (the rmcp SDK — software development kit — is edition 2024), so it
never affects the lean published kshana crate or its build.
In a JetBrains IDE you can also install the
Kshana — PNT simulator
plugin from the JetBrains Marketplace (or Settings → Plugins → Marketplace → search
"Kshana") to run scenarios from a right-click — see ide/jetbrains/.
Scenarios are declarative TOML. A top-level kind selects the pack — fifty in
all (clock is the default if omitted): inertial, timetransfer, hybrid, hybrid-ukf, fusion,
gnss-ins, orbit, ephemeris, gnss-sim, integrity, lunar-integrity, lunar-time-offset, spoof,
spoof-detect, jamming, sweep, sweep-nd, gravity-map, terrain-nav, terrain-slam,
combined-altpnt, pvt, mars-pnt, impairment-eval (AI/ML RF-impairment detection
evaluation testbed — labelled synthetic corpus + detector-agnostic ROC/AUC harness +
in/out-of-distribution optimism gap), quantum-trade (quantum-vs-classical PNT
trade with measured-ADEV ingestion + GNSS-denied resilience envelope; MODELLED),
space-weather (solar/geomagnetic indices + Jacchia-71 exospheric temperature +
activity-driven thermospheric density over the static atmosphere; MODELLED),
oem-interop (CCSDS OEM import/round-trip bridge for GMAT/Orekit/STK ephemerides;
MODELLED), the mission-analysis trio launch-window (two-body launch azimuth /
plane-change / opportunities), reentry (Allen-Eggers ballistic re-entry corridor),
eo-coverage (EO swath / GSD / access / revisit geometry), space-packet (CCSDS
133.0 TM/TC — telemetry/telecommand — Space Packet framing — exact bit layout, round-trip verified), and
attitude-budget (3-DOF gravity-gradient torque + RSS pointing error budget),
passes (ground-station rise/set pass prediction — AOS/TCA/LOS, max elevation,
access), and link-budget (one-way CCSDS/DSN link equation — FSPL / Eb·N₀ /
margin / closure); the lunar-PNT suite lunar-vlbi, lunar-joint-od-clock,
lunar-frame-realisation, moonlight-service-volume, lunar-differential-pnt,
lunar-interop-export; the Quantum-Enabled PNT demonstrator
quantum-time-transfer, quantum-gnss-free-nav, quantum-anomaly-detect; and the
signal-security, cislunar & layered-resilience research kinds lunar-attack-surface,
realtime-frame-eop, lunar-time-budget, hybrid-optical-rf, cislunar-observability,
conflict-resilience — the mission-analysis trio and these later kinds all MODELLED
(each with a validated closed-form core; see the matrix).
Common fields: seed, a [time] grid, a [gnss] availability timeline (the outage
driver), and per-sensor blocks with provenance strings citing the source of every
figure. Example (clock):
Optional fields (off when absent): a clock may add flicker_floor (1/f FM — frequency
modulation — Allan floor); an inertial sensor may add gyro_bias and q_arw (gyro bias and angular
random walk), and bias_instability and q_aa (the Allan bias-instability floor and
acceleration random walk) — together a single-axis (1-DOF) accelerometer error
budget (VRW/ARW — velocity/angular random walk — and bias-instability). This is the error budget the shipped
inertial scenario pack runs. Separately, the library now carries a verified
3-axis strapdown navigator (src/inertial/{attitude,mechanization,imu_errors}.rs):
quaternion attitude with coning/sculling compensation, a full NED mechanization
(Earth-rate and transport-rate terms, WGS-84 Somigliana gravity), and a
deterministic IMU error model in which scale-factor, misalignment,
g-sensitivity, quantization, and rate-ramp are modelled (IEEE Std 952-1997, the IEEE
gyro specification and test-procedure standard, §A.2; Groves 2013 §4.3). That 3-axis path is now wired into a runnable
loosely-coupled GNSS/INS pack (kind = "gnss-ins"): a 15-state error-state EKF
disciplines the strapdown solution against noisy fixes while GNSS is up, then
coasts through the outage, reporting the fused horizontal error against the
open-loop free-INS coast. A tightly-coupled pseudorange update is also
available (it forms the innovation in the range domain, so it keeps correcting
with fewer than four satellites). A
clock-holdover scenario may add runs (> 1) to run a Monte Carlo ensemble — each
figure of merit is then reported as a mean with a 5th–95th-percentile spread and the
chart shades the error confidence band (see scenarios/clock-ensemble.toml).
A fusion scenario (same blocks as hybrid) runs two independent Kalman estimators
— one for the clock state, one for the position state — disciplined by GNSS and aided by
optical time transfer, and reports a combined holdover FoM. The two blocks share no
cross-covariance: this is a stacked pair of error budgets, not a true coupled
clock+position joint filter (cross-block covariance is a roadmap item). See
scenarios/fusion-pnt.toml.
A spoof scenario injects a time-spoof — one of four [attack.shape] kinds
(linear_ramp, step_jump, meaconing, replay; a bare rate_ns_per_s is still
accepted as a linear ramp) — and runs each clock's spoof detector. The detector is a
two-sided χ²₁ energy / Neyman–Pearson test on the clock-aided monitor statistic:
the threshold is set from a target false-alarm budget target_pfa, and the
missed-detection probability P_md is reported both closed-form and by
Monte-Carlo (mc_runs trials per hypothesis — the two agree to a few ×1/√N). The
Security figure of merit is 1 − P_md at the operationally-harmful (spec)
magnitude, so a quiet clock that catches a spec-sized spoof scores ≈ 1 and a noisy
one that often misses it scores lower (see scenarios/spoof-attack.toml,
scenarios/spoof-meaconing.toml).
A gnss-sim scenario is a measurement-domain simulation: for each visible
satellite it synthesises the pseudorange ρ = geometric range + c·δt_rx − c·δt_sv + I + T + noise + multipath and the L1 Doppler, with the Klobuchar single-frequency
ionosphere ([iono], IS-GPS-200 §20.3.3.5.2.5) and the Saastamoinen zenith
troposphere projected by the Niell (1996) mapping function ([tropo]). The
residuals feed snapshot RAIM for per-epoch HPL/VPL, and every satellite's
pseudorange, Doppler, C/N₀, and iono/tropo corrections are emitted in the JSON
gnss_measurements array. It is a forward simulator (it generates measurements from
a known truth), not a receiver/solver — a zero-noise run reproduces geometry plus the
corrections to sub-millimetre (see scenarios/gnss-sim-raim.toml).
A jamming scenario models RF interference as a link budget: a [jammer]
(ECEF position, transmit power_dbw, type) raises the jammer-to-signal ratio at a
[receiver] watching a Walker [constellation]. From the geometry (free-space
path loss and the per-direction receive-antenna gain) it computes each satellite's
J/S, the effective C/N₀ via the standard anti-jam equation (despreading
processing gain × the spectral-separation factor Q; Kaplan & Hegarty §9.4), and
flags loss of lock below a configurable tracking threshold — reporting an
availability_under_jamming figure of merit. A 10 W broadband jammer at 1 km
denies the receiver entirely (J/S ≈ 72 dB); the same jammer at 100 km only
degrades the links (see scenarios/jamming-demo.toml).
A sweep scenario runs a trade study: it varies one parameter (threshold_ns,
duration_s, quantum_q_wf, or classical_q_wf) from start to stop over steps
points on a lin or log scale, records a metric (e.g. holdover_s) for both
clocks, and charts the two curves. The base scenario goes under [base] (see
scenarios/sweep-clock-stability.toml).
A sweep-nd scenario generalises this to any pack and any number of axes: it
varies dotted TOML keys of a [base] scenario (of any kind) over the Cartesian
product of [[axes]], re-runs each grid node, and records metrics given as
dotted JSON paths into the result (e.g. classical.fom.holdover_s). It works for
every pack because it operates at the TOML/result boundary; native runs evaluate
the grid in parallel (no extra dependency, wasm falls back to sequential) and the
output is deterministic and row-major (see scenarios/sweep-nd-inertial.toml).
An orbit scenario derives the [gnss] timeline from geometry instead of authoring
it — give a [user] orbit, a [constellation], an elevation mask_deg, and the two
clock blocks. It also reports position accuracy from the satellite geometry; the
optional sigma_uere_m (1-sigma user-equivalent range error, default 1 m) scales the
position dilution of precision into a position sigma. The user orbit may be made
eccentric with eccentricity and argp_deg, and j2 = true adds Earth-oblateness
secular drift (see scenarios/orbit-molniya.toml). The constellation can instead be a
real one: give [constellation] a tle block of two-line element sets and the
satellites are parsed from it (see scenarios/orbit-real-tle.toml). Add one or more
[[constellations]] blocks for multi-GNSS (e.g. GPS + Galileo; see
scenarios/orbit-multignss.toml):
The GPS-denied alt-PNT kinds navigate with no GNSS at all, matching a measured field
sequence against a map through a particle filter. A gravity-map scenario flies a track
through a spherical-harmonic gravity-anomaly field and recovers it from a cold-atom
gravimeter's reading (scenarios/gps-denied-gravity-nav.toml); a terrain-nav scenario
does the same against an SRTM elevation DEM (TERCOM/SITAN, scenarios/terrain-nav.toml);
and a combined-altpnt scenario fuses gravity + IGRF magnetic + terrain in one filter
(scenarios/combined-altpnt.toml).
A lunar-integrity scenario evaluates cislunar PNT: it runs a lunar south-pole
ARAIM protection-level pass against a LunaNet/LNIS relay set and honestly reports the
integrity gap — a ~30 m lunar σ_URE drives the protection level well above a 50 m alert
limit, so the service is unavailable under aviation-style integrity rules
(scenarios/lunanet-araim.toml).
A lunar-time-offset scenario reports the relativistic Earth–Moon clock rate — the
basis of a Lunar Coordinate Time scale (LTC/TCL). A first-principles post-Newtonian
identity sums the self-potential difference (IAU L_G geoid potential minus the Moon's
surface self-potential) and the Moon's kinetic (second-order Doppler) term to a secular
rate of ≈ 57 µs/day, reported with the published 56–59 µs/day band; it also gives the
accumulated LTC−TT offset over a horizon and an inverse-variance ensemble (a lunar
paper-clock). MODELLED — the headline figure is reference-dependent (Earth geoid
vs lunar selenoid, averaging window), which is why a band, not a single certified
number, is reported (scenarios/lunar-time-offset.toml).
See scenarios/ for at least one worked example of every kind (61 kinds, 73 scenario
.toml files + 1 suite manifest — several kinds ship more than one example). Not every
kind has a file named after it: lunar-integrity → scenarios/lunanet-araim.toml and
gravity-map → scenarios/gps-denied-gravity-nav.toml are two of several such.
List the dispatchable kinds at any time with cargo run -- --validate <file>
errors, the Python list_kinds(), or the MCP list_scenario_kinds tool.
The result artifact is versioned, self-describing JSON: per-step time series, the
scored figures of merit, the active model specs (with provenance), the seed, a
scenario hash — so any chart can be reproduced from the file — and, for each clock,
an adev_curve ([{tau_s, adev, n_samples, noise, edf, ci_lo, ci_hi}]): the overlapping
Allan deviation across octave-spaced averaging times — the standard way to read a clock's
stability — now with a noise-type-specific 95% confidence band per point (the record's
power-law type is identified from its modified-Allan slope, and the χ² interval uses the
matching NIST SP 1065 effective degrees of freedom). The browser playground renders it as a
log-log "Clock stability (ADEV)" chart. (MDEV, TDEV, and HDEV are available as library
estimators; the exported result curve is the overlapping ADEV.) Every field, with units and a
source pointer, is documented in docs/SCHEMA.md.
Every chart is self-describing. The browser playground, the CLI's *.chart.svg
export, and the HTML scorecard all stamp each chart image with a footer reading
Kshana v<version> · scenario <hash> · kshana.dev. The scenario <hash> is the first
12 hex characters of the run's scenario hash — a SHA-256 (the 256-bit Secure Hash Algorithm) digest over the canonical scenario
definition (seed, thresholds, model parameters, GNSS windows, …); the integrity and lunar
reports, which carry no hash of their own, fall back to a SHA-256 of the scenario source.
It is the same fingerprint shown in the one-line summary and the result JSON, so a
saved or pasted chart always carries its version, the exact scenario that produced it (for
bit-for-bit reproduction), and the source — change any input and the hash changes.
The figures of merit follow the standard operational PNT figures of merit:
| Figure of merit | How Kshana computes it |
|---|---|
| Timing Performance (clock/orbit packs) | clock-phase error RMS + 95th-percentile over the outage, in nanoseconds (timing_rms_ns) — a timing metric, not position |
| Positioning Performance (inertial/hybrid packs) | 1-DOF position-error RMS + 95th-percentile over the outage, in metres (pos_rms_m); single-axis. A single run is flagged monte_carlo: false; set runs = N for a Monte Carlo ensemble that reports each metric's mean, spread, and bootstrap 95% CI (confidence interval). Still not a 2-D CEP/2DRMS (circular error probable / twice the distance root mean square) or DOP-weighted accuracy (those need the 3-axis model — roadmap) |
| Autonomy | holdover duration — time in-spec after GNSS loss (grid-quantised: a lower bound) |
| Resilience | error-growth slope during the outage |
| Availability | fraction of the run with an in-spec solution |
| Integrity | filter self-consistency — fraction of outage samples whose error stays inside the Kalman filter's own k-sigma bound. Not an aviation HPL/VPL/RAIM integrity figure (see docs/INTEGRITY.md) |
| Security | analytic spoof-detectability bound from clock stability — how small/slow a time-spoof a single-clock consistency monitor could flag. Meaningful only with a configured attack; not a multi-satellite RAIM detector |
New to these terms? Each is defined in plain language in the glossary.
One engine, many front doors. A single Rust core (kshana) runs every scenario,
reached through a CLI, a Python extension, an in-browser WebAssembly module, an MCP
server for AI agents, and a JetBrains IDE plugin — all converging on one
api::run_toml dispatch. Inside, the sensor packs plug into a common error-model
interface; alongside them sit a reference-frame layer (IAU 2006/2000A
precession–nutation and the CIO-based GCRS↔ITRS reduction), an astrodynamics/numerical
layer (analytic SGP4/SDP4 and a numerical Cowell propagator with its
EGM2008/perturbation force model, maneuver design, and orbit determination), an
integrity/GNSS layer (RAIM/ARAIM, SBAS, the measurement domain, jamming, cislunar),
a fusion / alt-PNT layer (the GNSS/INS estimators and the gravity/terrain/magnetic
map-matchers), a deep-space & lunar layer (radiometric Mars-PNT and the MODELLED
lunar PNT suite — LTC time, VLBI, joint OD+clock, frame realisation, service-volume,
differential PNT, interop), a mission-analysis layer (launch / re-entry / coverage /
pointing / pass / link budgets and the space-weather environment), and the open
resilience & AI/ML study layer (RPCF resilience scoring, the RF-impairment optimism
gap, and the quantum-enabled PNT demonstrator) whose reproducible artifacts ride the
validated kernels.
Two standalone, workspace-excluded crates sit beside the core — mcp/kshana-mcp
(the MCP server, built on the edition-2024 rmcp SDK) and xval/anise-frames (the
ANISE/SPICE frame cross-check, which pulls MPL-2.0 (Mozilla Public License 2.0) deps) — kept out of the published
crate's dependency graph, Cargo.lock, license gate, and MSRV (minimum supported Rust version) build by the root
Cargo.toml exclude list. The JetBrains plugin (ide/jetbrains) is a separate Kotlin
project. See docs/ARCHITECTURE.md for the full set of diagrams.
Per-step engine flow · SVG
Full crate / module map · SVG (zoomable)
Components & distribution. The core crate ships through the Rust, Python, and
JavaScript ecosystems; the MCP server and IDE plugin reach AI agents and JetBrains IDEs.
Each vX.Y.Z tag republishes every channel automatically (see
Versioning & releases).
One repository → every distribution channel · SVG (zoomable)
| Document | For whom | What's in it |
|---|---|---|
| Concepts primer | everyone, start here | what Kshana does and why, from zero to the physics |
| Playground | everyone | run the engine in your browser (WebAssembly); build & deploy notes |
| Glossary | everyone | plain-language definitions of every term |
| Architecture | developers / reviewers | module map, engine pipeline, dispatch, and diagrams |
| Validation status | reviewers / citers | what is validated vs not modeled, with evidence |
| Verification matrix | reviewers / citers | the machine-checked evidence ledger — every capability row with its status, module, test and external oracle, generated from src/verification.rs |
| Modelled rationale | reviewers | why each Modelled row has no external oracle, stated row by row |
| Provenance | reviewers / citers | every sensor parameter, model, and dataset traced to its published source, in one citable table |
| Reproducibility & provenance | reviewers / packagers | determinism guarantees, golden-pinning, SBOM (software bill of materials), build provenance |
| Wheel platform tags | packagers | the abi3 Python wheel matrix — which platform tag pip install kshana resolves |
| Positioning | evaluators | where Kshana sits vs RTKLIB/gLAB (complementary), and the zero-install browser tier |
| Technical report · JOSS paper | reviewers / citers / evaluators | the full extended research paper — architecture, per-domain models, validation, case studies, and limitations — plus the concise JOSS (Journal of Open Source Software) submission |
| SGP4 validation | reviewers / citers | agreement with the AIAA 2006-6753 reference (666 states, ~4 mm) and a head-to-head against the independent sgp4 crate (agree to sub-micron / 4.12 mm) |
| Force-model validation | reviewers / citers | the full-force engine (src/precise_od.rs) fit to agency ephemerides — methodology and validated residuals |
| Real TLE guide | users | driving scenarios from real Celestrak / Space-Track constellation TLEs (vs the bundled synthetic Walker set) |
| Integrity FoM | evaluators | what the integrity / security figures mean — and what they are not vs aviation HPL/VPL |
| ARAIM reference | reviewers / integrators | the open MHSS ARAIM protection-level implementation — the b_k nominal-bias projection, σ_URA vs σ_URE, and the fault-mode priors |
| Quantum models · details | reviewers | the cold-atom-interferometer physics layer, and where coefficients are still looked up |
| Compliance | evaluators | DO-229E / DO-316 algorithm scope, and what is not a conformance claim |
| Standards & interoperability | integrators | the GNSS / flight-dynamics / agency interchange formats Kshana reads and writes (RINEX, SP3, CCSDS OEM/OMM/TDM/Space-Packet, …) |
| Scenario catalogue | users / integrators | every dispatchable kind with its required and optional TOML fields — generated from api::list_scenario_kinds() |
| Result schema | integrators | every field of the result JSON, with units and a source pointer |
| Python API | Python users | the PyO3 binding surface — calling the engine, the scenario/result types, and examples |
| Claims vs reality | reviewers | the overclaim-closure ledger + the CI guard (tests/no_overclaims.rs) that keeps it resolved |
| Roadmap | everyone | the phased roadmap — what has shipped and what is next |
| MCP server · JetBrains plugin | agents / IDE users | run Kshana from an AI assistant or a JetBrains IDE |
| Changelog | everyone | released history (Keep a Changelog + SemVer, Semantic Versioning) |
| Contributing | contributors | build, guards, test/citation discipline, DCO (Developer Certificate of Origin) |
| Governance | contributors / community | how Kshana is governed — who decides, how, and the open/closed boundary |
| Code of Conduct | community | expected conduct (Contributor Covenant) |
| Security policy | reporters | how to report a vulnerability; dual-use note |
docs/VALIDATION.md as validated or
not modeled — nothing is presented as validated that is not.scenario + seed + engine version → identical bits. scripts/check-reproducible.sh enforces it; quantum and classical runs use
independent seeds so their noise is uncorrelated.
How a capability earns its label — the CI-enforced invariant: no external oracle ⇒ cannot be Validated · SVG
Top: every Validated row is backed by an external dataset, by construction. Bottom: SGP4 matches the official reference in every regime (worst 4.12 mm). SVG · SVG
Every row is enforced by a named test in CI. This table is a curated highlight;
the full machine-checked matrix is 168 rows — 64 VALIDATED, 100 MODELLED, 4 PARTNER
(src/verification.rs), with the complete evidence (and what is honestly not yet
validated) in docs/VALIDATION.md and the per-release
kshana-validation-summary.html
artifact (generated by cargo run --bin validation_report, SLSA-attested — Supply-chain
Levels for Software Artifacts).
The Status column states the kind of evidence, matching the validation ladder above: VALIDATED = checked against an independent external oracle (real data, an independent library, or published reference vectors); MODELLED = checked against analytic truth or simulation self-consistency (no independent external dataset). VALIDATED describes the method of checking, not a pass/fail — an honest miss against real data (the LRO — Lunar Reconnaissance Orbiter — row) is still VALIDATED. CI rows are process guards, not figures of merit. A few real-data islands (the measured caesium clock, Stable32 PHASE.DAT, and the OPS-SAT/ICGEM checks where the raw inputs carry no redistribution licence) are data-gated: the test prints a skip notice and stays green when the input is absent, and the public reference numbers are committed under tests/fixtures/. Reproduce the raw inputs with the matching scripts/fetch_*.sh.
| Status | Capability | Agreement | Reference / oracle |
|---|---|---|---|
| VALIDATED | SGP4/SDP4 propagation | 666/666 vectors, worst 4.12 mm | AIAA 2006-6753 (Vallado tcppver.out) + head-to-head vs the independent sgp4 crate |
| VALIDATED | Reference frames — IAU 2000A/B nutation, IAU 2006/2000A CIO chain, ERA | bit-for-bit (X,Y to 1e-14, s to 1e-18, ERA to 1e-12) | ERFA/SOFA eraXys06a · eraC2ixys · eraEra00 · eraNut00a/b |
| VALIDATED | GCRS→ITRS vs an independent SPICE engine | max 0.028″ → ≤ 0.86 m ground, ≤ 3.6 m GNSS orbit | ANISE (pure-Rust NAIF/SPICE), same IERS finals2000A EOP, 8 epochs 2020–2023 |
| MODELLED | EGM2008 geopotential (degree/order 70) | acceleration = ∇V to < 1e-6; zonal collapse to validated J2 | NGA EGM2008 coefficients + analytic ∇V identity |
| VALIDATED | Gravity-functional synthesis (gravity-aided / GNSS-free nav map) | GRS80 Somigliana + γ_e/γ_p to 3.5e-12; real EGM2008 disturbance map physical (RMS ≈ 26 mGal, d/o 70) | GRS80 (Moritz 1980, IAG — International Association of Geodesy) Somigliana normal gravity + real ICGEM EGM2008 (tests/icgem_gravity_reference.rs) |
| VALIDATED | Allan estimators (ADEV/MDEV/TDEV/HDEV) + confidence bands | reproduce reference deviations; χ² bands match | NIST SP 1065 (Riley), 1000-point Table 31/32 |
| VALIDATED | Allan estimators on a real measured caesium clock | OADEV/OHDEV to 1e-3 (observed ≤ 3e-5), 16 averaging factors | Stable32 on a real 5071A Cs vs H-maser, 556,990 pts (tests/cs5071a_reference.rs, data-gated) |
| VALIDATED | Allan estimators on the canonical Stable32 PHASE.DAT | OADEV/MDEV/TDEV to 1e-3 (observed ≤ 5e-5), 139 averaging factors | Stable32 reference deviations for PHASE.DAT (tests/phasedat_reference.rs, data-gated) |
| MODELLED | IMU error model — ARW / VRW / bias-instability | recovered to < 5 % (bias-instability < 15 %) | Analog Devices ADIS16465 datasheet; NaveGo reference profile |
| VALIDATED | Numerical Cowell propagator + force model (conservative tiers) | worst position error 0.08 m over 24 h, 275 epochs (LEO + GTO) | Orekit 12.2 NumericalPropagator/DormandPrince853 (CS GROUP), tests/numerical_cowell_propagator_reference.rs |
| MODELLED | Cowell drag tier + absolute Sun/Moon-ephemeris & density inputs | drag tier characterised ≈ 333 m / 24 h; unperturbed matches universal-variable Kepler sub-m, energy/momentum ~1e-9 | built-in low-precision ephemeris + analytic Kepler |
| MODELLED | Lambert · Tsiolkovsky · porkchop | round-trip to two-body truth; ΔV < 0.01 % | Izzo 2015 · rocket equation · analytic Hohmann floor |
| MODELLED | Orbit determination (Gauss–Newton batch) | sub-m / mm·s⁻¹ noiseless; ~2 m at a 5 m noise floor | two-body + J2 over an RK4 arc |
| VALIDATED | Force-model fit vs Galileo precise ephemeris (full-arc) | 0.61 m 3-D RMS, 24 h, d/o-70, force-only | ESA/ESOC ESA0MGNFIN final orbit (E11), real finals2000A EOP |
| VALIDATED | Force-model fit vs Swarm-A precise ephemeris (reduced-dynamic) | 0.10 m 3-D RMS (empirical-tier bound, not a measure) | ESA SW_OPER_SP3ACOM_2_ precise orbit |
| VALIDATED | Force-model fit vs LRO lunar (honest miss) | 6.6 m reduced-dynamic, above the 5 m target | JPL Horizons LRO (NAIF −85) + GRAIL (Gravity Recovery and Interior Laboratory) GRGM660PRIM |
| MODELLED | Deep-space Mars OD (reduced-dynamic SRIF) | ≈ 0.2 m Mars-LMO (simulation FoM, not real-mission) | synthetic closed-loop OD — estimator-machinery validation |
| VALIDATED | Sun-central Mars dynamics vs JPL DE440 | 137 m @ 1-day arc (grows with arc = unmodelled n-body) | JPL DE440 via ANISE (xval/anise-mars-od, kernel-gated) |
| VALIDATED | Single-point positioning vs a surveyed IGS coordinate (real observations) | 5.7 m 3-D RMS / 1.1 m horizontal, dual-frequency iono-free code SPP | IGS station ABMF survey + GPS broadcast ephemeris, 2018-05-13 (tests/pvt_abmf.rs) |
| MODELLED | Tightly-coupled GNSS/INS UKF | 0.77 m RMS over a 30-min LEO pass incl. a 120 s outage | force-model coast, hand-derived |
| MODELLED | GPS-denied gravity-map navigation | ~70 km INS drift → ~145 m recovered | ESA NAVISP Quantum Wayfarer target |
| MODELLED | Terrain-referenced navigation (TERCOM/SITAN) | 70 km drift → < 500 m (grid-resolution floor ~140 m) | SRTM .hgt DEM; hand-injected drift (non-circular check) |
| MODELLED | IGRF-14 main field (degree/order 13) | pole ~80.7°N, dipole ~29.7 µT, physical 22–67 µT band | IAGA (International Association of Geomagnetism and Aeronomy) igrf14coeffs.txt (Schmidt semi-normalised) |
| MODELLED | Nav-signal modulation & code tracking | BPSK self-SSC = 2/(3·R_c); unit-area PSDs; sub-metre C/A DLL jitter @ 45 dB-Hz | Closed-form SSC/PSD anchors + Kaplan & Hegarty DLL thermal-noise formula |
| MODELLED | CR3BP halo/NRHO differential corrector | STM = finite differences; orbit closes to machine precision; L2 9:2 NRHO ≈ 6.57 d / perilune ≈ 3,250 km | finite-difference STM check + published L2 southern 9:2 NRHO (≈ 6.56 d / ≈ 3,370 km) — CR3BP, not a real Gateway ephemeris |
| VALIDATED | ARAIM dual-constellation integrity | constellation-wide fault mode on real GPS + Galileo | EU ARAIM TR (technical report) / DO-316; Celestrak gps-ops 2021-07-28 |
| VALIDATED | GNSS geometry / DOP (GDOP/PDOP/HDOP/VDOP/TDOP) | match to 1e-6 relative across 8 geometries (well-conditioned → near-singular) | gnss_lib_py 1.0.4 (Stanford NAV Lab) — independent library (tests/dop_reference.rs) |
| VALIDATED | ML detector-evaluation metrics (AUC/ROC/confusion/Pd-Pmd/precision/F1) | exact counts + < 1e-9 over 5 datasets × 24 thresholds | scikit-learn 1.9.0 (Pedregosa et al., JMLR — Journal of Machine Learning Research — 2011) — independent library (tests/eval_metrics_reference.rs) |
| VALIDATED | Anomaly-detection ROC AUC on real ESA OPS-SAT telemetry | AUC reproduces scikit-learn to < 1e-9; peak-count detector AUC ≈ 0.85 on the labelled test split | scikit-learn roc_auc_score on the OPSSAT-AD test split (Ruszczak et al. 2025, CC BY 4.0) — real OPS-SAT telemetry (tests/opssat_ad_reference.rs) |
| VALIDATED | Quantum-trade numerical kernels (ADEV NNLS fit · χ² consistency bands · van-Loan clock Q) | NNLS + Q exact; χ² < 5e-4 at operating dof ≥ 48 | scipy 1.17.1 — optimize.nnls / stats.chi2.ppf / linalg.expm (tests/scipy_reference.rs) |
| VALIDATED | MTIE / MDEV / TDEV telecom wander metrics (ITU-T G.810/G.823/G.8261/G.811 — the International Telecommunication Union's Telecommunication Standardization Sector recommendations) | MTIE (9 averaging factors, bit-exact) and MDEV + TDEV (8 factors, < 1e-9 relative) on the NIST SP 1065 LCG (linear congruential generator) series | allantools 2024.06 mtie / mdev / tdev — independent library (tests/mtie_reference.rs, tests/mdev_tdev_reference.rs) |
| VALIDATED | MCDA trade-study methods — all four decision families, nine externally-validated aggregators (WSM · WPM · WASPAS · MOORA · COPRAS · TOPSIS · VIKOR · PROMETHEE II · ELECTRE I) plus AHP pairwise-comparison priority weighting | scores / rankings / concordance matrices reproduced to < 1e-9 | pymcdm + pyDecision (independent third-party MCDA libraries) + Saaty RI (Random Index) / SciPy-LAPACK eig (tests/mcda_*_reference.rs) |
| MODELLED | Conditional Timing Protection Level (holdover-limited undetected time error under spoofing) | composition reproduces the multi-step clock_state covariance recursion; calibrated on a real recorded spoof | JammerTest 2024 (Zenodo 15911589) scalars + van-Loan / CUSUM closed forms (examples/tpl_jammertest) |
| MODELLED | PNT-resilience scoring + decision-instability | 35 hand-derived oracle tests; byte-deterministic study artifact (fixed seed) | DHS RPCF v2.0 mapping + Dirichlet / Kendall-τ / Hill-N2 closed forms — synthetic architectures, not a certification |
| MODELLED | RF-impairment optimism-gap study (scaling laws + leave-one-out predictor) | permutation-null significance; byte-deterministic artifact (5 seeds) | synthetic parameter-grounded corpus — the eval metrics are VALIDATED vs scikit-learn (above); the study is MODELLED |
| CI | Cross-platform reproducibility | bit-identical input + shape goldens on 3 OSes | Linux / macOS / Windows CI matrix, SHA-256 goldens |
| CI | Test coverage | ~96 % line on src/ excluding src/*_data.rs and src/main.rs, gated ≥ 85 % | cargo-tarpaulin (LLVM engine) |
Do I need to understand quantum physics to use this? No. If you can run a command line you can run Kshana. Start with the plain-language primer; look terms up in the glossary.
Is this a quantum-hardware design or flight software? No. It is a performance simulator. Quantum-hardware fidelity comes from published error models, not from this tool. See What it is / is not.
Are the quantum results realistic, or marketing? Every parameter is cited to a datasheet or paper, every model is validated against a textbook relation, and maturity is labelled honestly in VALIDATION.md — including that no strontium optical clock has flown. The engine is neutral: quantum and classical are the same code with different published numbers.
Can I trust two runs to agree?
Yes — runs are deterministic: scenario + seed + engine version → bit-identical output,
enforced by scripts/check-reproducible.sh.
Can I use it from Python or in a browser? Yes — see Python and WebAssembly. Both call the same engine.
How do I model my own sensor?
Write a scenario .toml with your sensor's published figures in the provenance
fields. See Scenario format and the examples in scenarios/.
Is it free for commercial use?
Yes — under the AGPL-3.0, including in commercial settings, as long as you honour the
AGPL's copyleft (notably: if you modify Kshana and offer it over a network, you must
offer those users your modified source). If that does not suit you — e.g. you need to
embed Kshana in a proprietary product or run a closed network service — a commercial
licence is available from Ashforde OÜ; see LICENSING.md and
Support.
cargo build fails on an old toolchain. Kshana needs Rust ≥ 1.85. Update with
rustup update.
Building the Python extension fails to link on macOS (Undefined symbols … _Py…).
A Python extension resolves its symbols at load time. maturin sets the right linker
flag automatically — use maturin develop --features python rather than a bare
cargo build.
The Python build complains the interpreter is newer than PyO3 knows. Set
PYO3_USE_ABI3_FORWARD_COMPATIBILITY=1 (abi3 wheels are forward-compatible across
CPython versions).
WebAssembly build can't find the target. Install it once with
rustup target add wasm32-unknown-unknown, then wasm-pack build --target web -- --features wasm.
Where did my output go? Each run writes <scenario>.result.json,
<scenario>.chart.svg and <scenario>.report.html next to the input .toml, and
<scenario>.table.csv too for the kinds that publish a table. All of them are
git-ignored by design.
See ROADMAP.md for the phased roadmap, CHANGELOG.md
for released history, and docs/CAPABILITY.md for the
per-capability roadmap. The ITRF-precise frame reduction is now delivered — the
full CIO-based IAU 2006/2000A GCRS↔ITRS chain (polar motion + sub-arcsecond nutation),
validated bit-for-bit against SOFA/ERFA and independently cross-checked against ANISE
(pure-Rust SPICE) to ≤ 3.6 m at GNSS orbit. Near-term items include tightly-coupled carrier-phase fusion and surfacing the
loosely-/tightly-coupled GNSS/INS navigator across more packs; the deep-space / Mars
radiometric-navigation engine landed in v0.17.0 (simulation-validated). The
quantum physics layer is a P2 item: the CAI accelerometer is now simulated from
first principles (Mach–Zehnder phase, projection noise, contrast decay, vibration
coupling), while the clock/time-transfer sensors are still driven by published
Allan/noise-budget coefficients. GMST-based TEME↔ECEF, the IERS
leap-second time systems (UTC/TAI/TT/UT1), SGP4/SDP4 orbit propagation (v0.7.0,
validated against the AIAA 2006-6753 vectors), and the runnable gnss-ins fusion
pack have all shipped, and the inertial velocity is exposed downstream. An active
stochastic time-spoof detector (Neyman–Pearson / χ²₁ energy test with Monte-Carlo
P_fa/P_md and a Security FoM of 1−P_md), a link-budget jamming model (J/S → effective
C/N₀ → loss of lock), multi-constellation availability, a single-axis (1-DOF)
IMU error budget, two independent (clock + position) Kalman estimators reported as a
combined FoM, real constellation geometry from TLEs, an HTML scorecard report,
geometry-derived GNSS availability
and dilution of precision from Keplerian orbits with eccentricity and J2 drift,
Monte Carlo confidence bands, trade-study parameter sweeps, an in-browser WebAssembly
playground, and optional Python (PyO3) and WebAssembly (wasm-bindgen) bindings have
landed on main.
See CONTRIBUTING.md. In short: tests pass (cargo test), the
two guard scripts pass, Conventional Commits, and a CHANGELOG.md [Unreleased]
entry for every user-visible change. Participation is governed by our
Code of Conduct. To report a security issue, see the
Security policy — please do not open a public issue for vulnerabilities.
If you use Kshana in academic or technical work, please cite it. Machine-readable
metadata is in CITATION.cff (GitHub renders a "Cite this repository"
button from it); cite the version you used (e.g. v0.27.2) together with the
scenario and seed for full reproducibility. Every release is archived on Zenodo with
a citable DOI (Digital Object Identifier) — the concept DOI 10.5281/zenodo.20528627
always resolves to the latest version.
Baweja, C. (2026). Kshana — a PNT-resilience simulator with quantum-sensor performance models. Ashforde OÜ. https://doi.org/10.5281/zenodo.20528627
Related publications. Studies built on the open engine are written up separately; their numbers regenerate from a committed scenario + seed or the reproducible study artifacts above.
Baweja, C. (2026). The Cost of Lunar South-Polar Geometry, and Surface Beacons as the Efficient Fix: A Dilution-of-Precision Analysis. arXiv:2607.06212. https://doi.org/10.48550/arXiv.2607.06212
Baweja, C. (2026). Earth-baseline VLBI restores the observability of a lunar surface station in joint orbit-and-clock determination. arXiv:2607.02566. https://doi.org/10.48550/arXiv.2607.02566
Baweja, C. (2026). A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing. arXiv:2606.24210. https://doi.org/10.48550/arXiv.2606.24210
Baweja, C. (2026). Anticipating the Optimism Gap: Predicting Distribution-Shift Degradation of RF-Impairment Detectors from In-Distribution Statistics. arXiv:2606.22054. https://doi.org/10.48550/arXiv.2606.22054
Kshana follows Semantic Versioning. While pre-1.0 the public
scenario/result schema may still change; breaking changes are called out explicitly in
the CHANGELOG.md. Every result is reproducible from
scenario + seed + engine version.
Every vX.Y.Z tag publishes all channels automatically — one CI pipeline fans out to:
| Channel | Install / get | Contents |
|---|---|---|
| crates.io | cargo install kshana · kshana = "0.27" | Rust library + CLI |
| crates.io | cargo install kshana-mcp | the MCP server |
| PyPI | pip install kshana | abi3 wheels (Linux/macOS/Windows) + sdist (source distribution) |
| npm | npm install kshana | WebAssembly module + JS wrapper |
| ghcr.io | docker run -i ghcr.io/ashfordeou/kshana-mcp | multi-arch OCI (Open Container Initiative) image — no toolchain needed |
| official MCP registry | auto-discovered by MCP clients | io.github.ashfordeOU/kshana-mcp |
| JetBrains Marketplace | IDE → Plugins → search "Kshana" | the Kshana — PNT simulator IDE plugin |
| GitHub Releases | download | kshana + kshana-mcp binaries, a CycloneDX SBOM, SLSA build provenance, and an HTML validation summary |
| Zenodo | DOI | a citable archive of every release |
| kshana.dev | open in a browser | the WebAssembly playground (redeployed from main) |
The MCP server's crate / image / registry version tracks the engine (it bundles the
library); the JetBrains plugin versions independently (it shells out to your installed
kshana binary).
Dual-licensed. Use Kshana under either the GNU AGPL-3.0-only (see
LICENSE) or a commercial licence from Ashforde OÜ for
proprietary/closed integration that the AGPL does not suit. Which one applies, and
why it is set up this way, is explained in LICENSING.md.
Contributions are licensed inbound under the AGPL and grant Ashforde OÜ the right
to include them in the commercially-licensed edition (so the dual-licence keeps
working) — see CONTRIBUTING.md. Sign off each commit per the
Developer Certificate of Origin with git commit -s.
Trademark. "Kshana" and its marks are trademarks of Ashforde OÜ. The licence covers the code, not the name — please rename forks and derivative distributions.
Kshana is free and open source under the AGPL-3.0 and professionally developed and maintained by Ashforde OÜ (Estonia). The open engine is complete and usable on its own. For organisations that need more, Ashforde OÜ offers:
This is the open-core model: the engine is, and stays, openly licensed; the sustaining business is expertise, support, and the proprietary extensions — not license fees. Contact contact@ashforde.org · ashforde.org.
Validation oracles & standards — the external authorities Kshana's checks are anchored to:
tests/eval_metrics_reference.rs).optimize.nnls, stats.chi2 and linalg.expm — the reference routines the quantum-trade measured-ADEV NNLS fit, the χ² consistency bands, and the van-Loan clock process-noise covariance are validated against (tests/scipy_reference.rs).tests/dop_reference.rs).Device & method physics — the cited sources behind the sensor models:
src/navsignal.rs).Comparison & open prior art — the tools and surveys Kshana is positioned against: