Kshana PNT-resilience simulator

Run the validated Kshana PNT-resilience simulator (orbits, frames, GNSS, fusion) from an AI agent.

AI & MLRustv0.32.0

It quantifies, in hard and reproducible numbers, what quantum clocks, quantum inertial sensors, and optical time-transfer buy a navigation system over classical PNT — scored against the operational figures of merit that matter for resilient navigation. Every result is reproducible from scenario + seed + engine version, and every sensor parameter is traceable to a published source — consolidated in one citable table in docs/PROVENANCE.md.

Validated against external oracles — every row CI-gated

Each row is checked against an independent external oracle (real dataset, independent reference implementation, or published reference vectors) and re-checked in CI. Full 102-row matrix →

CapabilityResultExternal oracle
✅SGP4/SDP4 propagation666/666 vectors, worst 4.12 mmAIAA 2006-6753 (Vallado) + independent sgp4 crate
✅Numerical Cowell force model0.08 m / 24 h, 275 epochsOrekit 12.2 DormandPrince853 (CS GROUP)
✅Orbit fit vs precise ephemerisGalileo 0.61 m · Swarm-A 0.10 mESA/ESOC SP3 precise orbits
✅GCRS→ITRS frame chainbit-for-bit vs SOFA; ≤ 0.86 m vs SPICEERFA/SOFA + ANISE (pure-Rust SPICE)
✅Allan deviationsreproduce reference deviationsNIST SP 1065 + Stable32 on a real Cs clock
✅GNSS DOP · ML detector metricsto 1e-6 · to 1e-9gnss_lib_py · scikit-learn
✅Fisher information · CRLB · observabilityeigh / CRLB / DOP to 1e-9NumPy 2.4.1 (LAPACK) + Kay (1993) closed forms

Free and open source under the GNU AGPL-3.0 — with a commercial licence available from Ashforde OÜ for proprietary/closed integration (see LICENSING.md). Professionally developed and maintained by Ashforde OÜ; commercial support, integration, and proprietary extensions available.

Status: v0.25.0 · a validated, reproducible simulation substrate for PNT resilience. A fully reproducible engine spanning the PNT stack — orbit geometry and constellation design, a numerical (Cowell) propagator with a seven-perturbation force model, maneuver and trajectory design, time systems, inertial navigation (incl. map-aided and gravity-map-matching alt-PNT), GNSS/INS fusion (loose, tight, UKF, coupled clock+position, 17-state), orbit determination, ARAIM integrity, clocks, advanced time-and-frequency transfer, the GNSS measurement domain, resilience (jamming + multi-layer spoofing), and an open deep-space / Mars radiometric navigation engine (light-time + Shapiro, CCSDS-TDM, reduced-dynamic SRIF, one-/two-way fusion); plus first-order mission-analysis budgets (launch / re-entry / EO-coverage / pointing / ground-station passes / link), a space-weather environment model, an AI/ML RF-impairment evaluation testbed, and the versioned Kshana Interchange Format (KIF). Honest by design: every figure of merit is labelled validated or modelled, and optical-clock figures are space goals on ground hardware (no strontium optical clock has flown).

Validation ladder (maturity is not uniform across domains — and saying so is the point):

DomainTier
Earth PNT (orbit, frames, time, clocks, IMU, integrity)Real-data validated — ESA SP3 (Galileo 0.13 m / 8 h · 0.61 m / 24 h, Swarm-A 0.10 m), NIST SP1065, SOFA/ERFA, heritage vectors
Deep-space / Mars navigationSimulation-validated — synthetic closed-loop OD + analytic self-consistency; Sun-central dynamics cross-checked vs JPL DE440 (137 m @ 1-day arc)
Real-mission deep-space ODRoadmap — pending real DSN/ESTRACK tracking-data validation

Deep-space figures (Mars-LMO OD ≈ 0.2 m; relay-PNT orbiter 0.4 m / rover 5.1 m) are simulation / covariance figures of merit, not real-mission results. See Capabilities for what it does, What it is / is not for scope, and docs/CAPABILITY.md / docs/VALIDATION.md for per-capability maturity. The overclaim closure ledger docs/CLAIMS-VS-REALITY.md tracks every historical overclaim, how it was resolved, and a CI guard (tests/no_overclaims.rs) that keeps it resolved.

Try it in your browser: the playground runs the engine client-side as WebAssembly — pick a scenario, edit the parameters, and see the result, with nothing uploaded. Build it locally with ./web/build.sh (see web/README.md), or publish it to GitHub Pages via the pages workflow.

New to this? In plain terms: GPS-style satellite signals tell things where they are and what time it is. When those signals are lost (jammed, blocked, or out of view in space), a system has to keep going on its own onboard clock and motion sensors — and they slowly drift. "Quantum" clocks and sensors drift far more slowly. Kshana measures, in honest numbers, how much longer a quantum-equipped system can coast before it exceeds its accuracy limits. New readers should start with the plain-language primer and the glossary.


Contents

Why

Resilient PNT depends on holding position and time when GNSS is denied or jammed. Quantum sensors promise far slower drift during those outages. There is no good open tool to quantify that advantage honestly and reproducibly — so primes, agencies, and labs each rebuild private one-offs. Kshana aims to be the neutral, citable reference for exactly this question.

The engine knows nothing about "quantum" vs "classical": each sensor is an error model plugged into a common pipeline, so a quantum and a classical device are compared apples-to-apples on the same scenario, with independent noise realizations.

What it is / is not

It is: a deterministic, dependency-light engine spanning the PNT stack — orbit geometry, inertial navigation, GNSS/INS fusion, integrity, clocks, and timing. It runs a scenario (often a GNSS outage), evolves calibrated sensor error models through the appropriate estimator, and scores the result against the operational figures of merit — emitting a reproducible JSON result and an SVG chart, from a Rust library, a CLI, a Python extension, an in-browser WebAssembly module, a Model Context Protocol (MCP) server for AI agents, or a JetBrains IDE plugin.

It is not: flight hardware, a quantum-payload design, a full GNSS signal receiver, or a certified avionics product. Quantum-hardware fidelity comes from published error models, not from this tool. The granular maturity of each capability is documented in docs/CAPABILITY.md.

It is not (yet): a full atom-interferometry physics engine (most quantum sensors consume published Allan/noise-budget coefficients; the CAI accelerometer has a first-principles layer — Mach–Zehnder phase, projection noise, contrast decay, and vibration coupling — but Coriolis and light-shift systematics remain a P2 roadmap layer, see ROADMAP.md and docs/QUANTUM-MODELS.md); a full GNSS signal-acquisition receiver (it now solves a single-point PVT position fix from real RINEX code observations — validated on real IGS data — but does not acquire or track raw signal); or a full mission-design suite (it has Lambert / porkchop / maneuver / orbit-determination building blocks, but is the performance-simulation layer above GMAT/Orekit, not a replacement). Owning this scope is deliberate. If you need first-principles cold-atom interferometer error budgets (e.g. CARIOQA-PMP-grade or X-37B-style validation), see the P2 roadmap and get in touch to collaborate.

Capabilities

One engine spans the whole PNT stack — and its maturity is honest per domain: Timing, Orbits and GNSS geometry are heavily externally validated; Lunar and several quantum/resilience domains are deliberately Modelled until real tracking data exists.

The full domain-by-domain detail follows; for a per-capability maturity ledger see docs/CAPABILITY.md and docs/VALIDATION.md.

DomainCapability
Orbit & geometrySGP4/SDP4 propagation (validated to 4.12 mm against all 666 AIAA 2006-6753 vectors); real two-line elements (a committed, date-stamped Celestrak gps-ops snapshot) or synthetic Walker-delta constellations whose mean elements realise the i:T/P/F formula to under 1 km over a 24 h propagation; multi-constellation visibility, dilution of precision (GDOP/PDOP/HDOP/VDOP/TDOP, validated to 1e-6 against gnss_lib_py 1.0.4, Stanford NAV Lab), and GNSS availability; a gradient-free constellation-design optimiser, streets-of-coverage minimum-satellite sizing, a multi-constellation comparison tool, and a Walker design sweep that tabulates coverage / PDOP / revisit-time over a planes × satellites grid and reports the Pareto-optimal designs.
Numerical propagatorA Cowell numerical propagator (src/propagator.rs) complementing the analytic SGP4/SDP4 path, with a hierarchical seven-perturbation force model (src/forces.rs): two-body + the full J2–J6 zonal field (the exact analytic gradient of its disturbing potential), an optional EGM2008 tesseral spherical-harmonic geopotential to degree/order 70 (src/gravity_sh.rs; real NGA coefficients, Holmes–Featherstone normalized-Legendre recurrence, cross-checked against the closed-form Legendre functions and the analytic ∇V identity), epoch-driven Sun and Moon third-body gravity (a built-in low-precision ephemeris, no DE/SPK kernel), solar-radiation pressure (cannonball model with a conical umbra+penumbra shadow), atmospheric drag (Vallado piecewise-exponential density, co-rotating atmosphere), the post-Newtonian Schwarzschild relativistic correction, and the Lense–Thirring frame-dragging term (IERS 2010 §10, linear in Earth's angular momentum, ~1–2 orders below Schwarzschild) — driven by a choice of two adaptive integrators (RK4 step-doubling or the Dormand–Prince RK5(4) embedded pair). Validated against Orekit 12.2 (CS GROUP, Apache-2.0) NumericalPropagator/DormandPrince853 — 275 epochs across LEO + GTO, the conservative-force tiers agreeing to a worst-case |Δr| 0.08 m over 24 h (tests/numerical_cowell_propagator_reference.rs); the atmospheric-drag tier is characterised separately (≈ 333 m / 24 h) and the absolute Sun/Moon-ephemeris and density inputs stay honestly Modelled. Additional internal evidence (not external validation): the unperturbed orbit is checked against the exact universal-variable Kepler solution to sub-metre over 24 h, energy/angular-momentum conserve to ~1e-9, and each perturbation matches a hand-derived closed-form signature.
Maneuvers & trajectory designImpulsive ΔV nodes with 6×6 covariance propagation (ECI / LVLH execution-error frames), finite-burn integration checked against the closed-form Tsiolkovsky rocket equation to < 0.01 %, an Izzo-2015 single-revolution Lambert solver, an exact universal-variable Kepler propagator, and a porkchop (launch × arrival) C3 / arrival-V∞ sweep emitted as a JSON contour grid — the performance-simulation layer above GMAT/Orekit, with every Lambert output round-tripped against two-body truth and the porkchop minimum checked against the analytic Hohmann floor.
Time systems & reference framesIERS leap-second UTC / TAI / TT / UT1 scales, a Julian-date API, the IAU-2000 Earth Rotation Angle, GMST-based TEME ↔ ECEF with WGS-84 geodetic frames, IAU 2006 precession (Fukushima–Williams), full IAU 2000A/2000B nutation, IERS polar motion, and the equinox-free CIO-based IAU 2006/2000A GCRS↔ITRS reduction — all validated bit-for-bit against the SOFA/ERFA vectors, and independently cross-checked against ANISE (the pure-Rust NAIF/SPICE reimplementation): kshana's GCRS→ITRS vs ANISE's ITRF93 from JPL's earth_latest_high_prec.bpc, the same IERS Earth-orientation parameters fed to both, agree to ≤ 0.86 m on the ground / ≤ 3.6 m at GNSS orbit (max 0.028″) across eight epochs 2020–2023.
InertialThree-axis strapdown INS — quaternion attitude, WGS-84 NED mechanization, coning/sculling compensation, and a deterministic IMU error model (scale-factor, misalignment, g-sensitivity, quantization, drift); a first-principles cold-atom-interferometer accelerometer (Mach–Zehnder phase, quantum projection noise, contrast decay, vibration coupling) that derives the velocity-random-walk coefficient; and a sequential-importance-resampling particle filter for map-aided (terrain-/gravity-referenced) GPS-denied navigation.
Alt-PNT (GPS-denied)A cold-atom gravimeter measurement model whose white-noise floor (σ = ASD/√τ) is derived from the CAI accelerometer physics; a low-degree, fully-normalised spherical-harmonic gravity-anomaly field (checked against the closed-form Legendre functions and a hand-derived single-term anomaly) plus synthetic mascons; the gravity-functional synthesis kernel (gravity_sh::gravity_magnitude / gravity_disturbance_mgal) — the "map reader" a gravity-aided navigator matches against — is validated against the GRS80 normal-gravity standard, reproducing the closed-form Somigliana normal gravity and the published γ_e / γ_p to 3.5e-12 and producing a physically-bounded disturbance map from the real ICGEM EGM2008 field (RMS ≈ 26 mGal, max ≈ 89 mGal at d/o 70; tests/icgem_gravity_reference.rs); and a gravity-map-matching particle filter that recovers a GPS-denied track from the anomaly sequence it flies through. It extends to terrain-referenced navigation (TERCOM/SITAN against an SRTM .hgt DEM, src/altpnt/terrain.rs), an IGRF-14 geomagnetic main field to degree/order 13 (src/igrf.rs, checked against the tilted-dipole closed form and ∇V finite differences), and a combined gravity + magnetic + terrain navigator that fuses all three scalar channels through one particle filter (information is additive — no channel makes the fix worse). A 60-minute GPS-denied benchmark (a ~700 km / one-hour outage where the inertial solution drifts to ~70 km) is recovered to ~145 m (< 500 m) by a hierarchical coarse-to-fine matcher — the ESA NAVISP Quantum Wayfarer target.
FusionLoosely-coupled 15-state GNSS/INS error-state EKF with closed-loop feedback (the gnss-ins pack); a tightly-coupled pseudorange update that keeps correcting with fewer than four satellites; a coupled clock + position filter; a general unscented (sigma-point) Kalman estimator for strongly nonlinear measurements; a tightly-coupled GNSS/INS UKF navigator (pseudorange + Doppler) whose force-model orbital coast is self-consistency-checked to 0.77 m RMS over a 30-minute curving LEO pass that includes a 120-second GNSS outage (a filter-consistency figure, not an external-oracle validation — this navigator stays MODELLED); and a full 17-state tightly-coupled GNSS/INS UKF (position, velocity, attitude error, accelerometer and gyro biases, clock bias and drift) whose quantum-CAI dead-reckoning coasts a 120-second outage on the cold-atom accelerometer's derived velocity-random-walk.
Orbit determinationRecovery of an orbital state [r, v] from ground-station range tracking, composing the two-body + J2 force model and RK4 integrator with a Gauss–Newton batch corrector (determine_orbit_batch, sub-metre / mm·s⁻¹ from noiseless ranges, ~2 m at a 5 m noise floor) and a sequential unscented-filter variant (determine_orbit_sequential).
Observability & estimation theoryA general, reusable Fisher-information / Cramér–Rao layer (src/fim.rs): the information matrix M = HᵀWH, the Cramér–Rao lower bound, observability rank and datum-defect null space (Moore–Penrose pseudo-inverse), and D/A/E/T-optimal experiment-design scalars from a symmetric Jacobi eigensolver. Validated — eigenvalues vs numpy.linalg.eigh, the CRLB covariance vs σ²(XᵀX)⁻¹ via numpy.linalg.inv, and GNSS DOP from the information matrix, all matched to 1e-9 (tests/fim_observability_reference.rs), and additionally cross-checked against the Kay (1993) closed-form bounds with Monte-Carlo CRLB attainment. It underpins the DOP engine, the passive-geolocation CRLB, and the lunar absolute-station observability theorem (below).
Lunar & cislunarAn Earth–Moon circular restricted three-body (CR3BP) propagator in the rotating frame — conserved Jacobi constant and all five Lagrange points (src/cr3bp.rs) — now with a 6×6 state-transition matrix and a single-shooting differential corrector (cr3bp_jacobian, propagate_state_stm, differential_correct_halo) that produces genuinely periodic halo / NRHO orbits: the STM is validated against finite differences, corrected orbits close to machine precision, and seeding the published apolune state reproduces the L2 southern 9:2 NRHO (the Gateway orbit) at period ≈ 6.57 d / perilune ≈ 3,250 km, consistent with the published ≈ 6.56 d / ≈ 3,370 km (a CR3BP — circular, Sun-free — solution, not validated against a real LANS/Gateway ephemeris; the selenocentric MCI/MCMF transform of the corrected orbit is a follow-on); plus LunaNet / LNIS cislunar PNT geometry (MCI↔MCMF reduction, selenographic coordinates) with a lunar south-pole ARAIM pass that honestly surfaces the integrity gap: a ~30 m σ_URE drives the protection level well above a 50 m alert limit (src/lunar.rs, scenarios/lunanet-araim.toml); and a surface-beacon DOP augmentation (src/lunar_beacon.rs) showing how a few surveyed surface ranging beacons supply the low-elevation, wide-azimuth line-of-sight rows an all-overhead orbit-only set lacks — collapsing the ill-conditioned south-polar GDOP and, via a root-sum-square error budget, the realized position accuracy in metres (reusing the gnss_lib_py-validated DOP kernel and the airless-horizon visibility closed form; the dilution-of-precision analysis is written up in arXiv:2607.06212).
Lunar PNT suiteA modelled lunar/cislunar navigation suite layered on the CR3BP core, each a runnable kind: Lunar Coordinate Time (lunar-time-offset, src/lunar_time.rs — the secular LTC/TCL − TT rate from the self-potential difference + kinetic term, reported with the published 56–59 µs/day band); a geodetic lunar VLBI delay observable (lunar-vlbi, src/lunar_vlbi.rs — an Earth-baseline near-field two-range-difference delay + rate, cross-checked against the same-codebase plane-wave Δ-DOR in the far-field limit, partials finite-difference-verified); a joint multi-technique OD + clock batch estimator (lunar-joint-od-clock, src/lunar_combination.rs — a Gauss–Newton fit fusing VLBI + lunar-local ranges + inter-satellite ranges) carrying a Fisher-information observability result: internal ranging alone leaves a six-degree-of-freedom rigid-body datum defect, so a surface station's absolute position is unobservable until an Earth-frame tie is added — an Earth-baseline VLBI delay restores observability for a sparse constellation and sharpens the Cramér–Rao bound for a rich one, the absolute datum closing at three non-collinear Earth stations (the observability result written up in arXiv:2607.02566); reference-frame realisation (lunar-frame-realisation, src/lunar_frame_realise.rs — a 7-parameter Helmert datum fit + IAU 2015 WGCCRE orientation tie); a Moonlight/LCNS-class service-volume analysis (moonlight-service-volume, src/lunar_service.rs — DOP / coverage / availability + a generalised lunar ARAIM HPL/VPL envelope, reusing the gnss_lib_py-validated DOP kernel and the LunaNet σ_URE≈30 m machinery); lunar differential PNT (lunar-differential-pnt, src/lunar_dpnt.rs — a lunar DGNSS/SBAS analogue: exact common-mode clock cancellation + first-order spatial decorrelation vs baseline, reusing the DO-229E SBAS protection level); and a LunaNet/IOAG-aligned interoperability export (lunar-interop-export, src/lunar_interop.rs — CCSDS-OEM + lunar-time-scale round-trip in the IAU 2015 lunar body frame, wrapped in the KIF envelope). All MODELLED against internal consistency / reference implementations from illustrative public-source parameters — not validated against real VLBI/Gateway tracking, not affiliated with or endorsed by any agency, no TRL / heritage claim.
Deep-space & Mars PNTAn open radiometric navigation engine: iterative light-time + Shapiro relativistic delay, two-/one-/three-way Doppler & range (Moyer two-leg), coherent transponder turnaround ratios, regenerative/PN ranging (CCSDS 414), and Δ-DOR plane-of-sky (CCSDS 506), with solar-plasma/tropo/iono media; CCSDS-TDM (503) tracking-data-message parse + emit; a reduced-dynamic Square-Root Information Filter (RTN empirical accelerations + a 3-state onboard clock + Mars atmospheric drag) that does Mars-LMO orbit determination to ≈ 0.2 m in a synthetic closed loop; a joint one-way + two-way fusion estimator; a multi-body dynamics core (Body{μ, re, zonals, gravity, IAU-pole}, Mars GMM-3 gravity, an IAU body-fixed Mars frame, a pluggable EphemerisProvider seam, two-part Julian dates + TT↔TDB); and the mars-pnt relay-PNT scenario (a MARCONI areostationary relay constellation) with an end-to-end GSE performance simulator (geometry → link budget → observables → SRIF → covariance). Simulation-validated (covariance / closed-loop figures of merit); the Sun-central Mars dynamics are cross-checked against JPL DE440 (137 m @ 1-day arc, xval/anise-mars-od). Real DSN/ESTRACK tracking-data validation is on the roadmap.
IntegritySnapshot and solution-separation (ARAIM-style) RAIM with horizontal/vertical protection levels (HPL/VPL), fault detection & exclusion, and Stanford integrity diagrams; an explicit integrity-risk-budget (MHSS) protection level, including the dual-/multi-constellation constellation-wide fault mode (EU ARAIM / DO-316), exercised on a real GPS + Galileo snapshot (scenarios/araim-gps-galileo.toml). The protection level applies the one-sided nominal-bias projection `b_k = Σ_i
Augmentation (SBAS)SBAS / WAAS protection levels in the DO-229E weighted-least-squares form (precision-approach and en-route K-factors) and the L1/L5 dual-frequency ionosphere-free combination (IS-GPS-705, γ₁₅ ≈ 1.793) that underpins DO-316 — src/sbas.rs. The protection-level algorithm is externally validated against the RTKLIB SBAS-PL fork (zsiki/rtklib_ws waasprotlevels(), Siki & Takács 2017, DO-229D App. J) run on real EGNOS data, reproducing its HPL to < 2e-3 m (tests/sbas_reference.rs); gLAB v6.0.0 confirmed the identical convention.
Clock & timingTwo-state Kalman holdover (Joseph-form covariance, NIS/NEES consistency health); Allan-family stability (ADEV / MDEV / TDEV / HDEV / MTIE) with noise-type-specific confidence intervals and a full IEEE-1139 five-coefficient power-law fit — the estimators are validated on real hardware against Stable32: a real 5071A caesium primary standard vs a hydrogen maser (556,990 phase samples, 16 averaging factors, OADEV/OHDEV to 1e-3; tests/cs5071a_reference.rs) and the canonical Stable32 PHASE.DAT regression series (139 averaging factors, OADEV/MDEV/TDEV to 1e-3; tests/phasedat_reference.rs); the ADEV/MDEV/TDEV estimators and the telecom MTIE wander metric are additionally cross-checked against the independent allantools 2024.06 library to < 1e-9 on the NIST SP 1065 series (tests/mtie_reference.rs, tests/mdev_tdev_reference.rs); geometric corrections (Sagnac, GNSS common-view); and the operational transfer methods — TWSTFT with the BIPM Sagnac closed form, GNSS common-view, PPP ionosphere-free time transfer, a free-space optical link with turbulence scintillation, and an inverse-variance clock-ensemble (paper) timescale below the best contributing clock. A GNSS-denied clock-holdover calculator (src/holdover.rs) exposes the closed-form van-Loan coast-error growth as a holdover-to-threshold inversion — how long a clock free-runs before its timing error exceeds budget — across representative classical and quantum-clock classes; modelled (cross-checked against the multi-step clock_state covariance recursion), and honest that for a very stable clock the holdover to a tight threshold is set by the assumed long-tau noise floor, not the cited ADEV. A conditional Timing Protection Level (src/tpl.rs) extends holdover to spoofing: a bound on the undetected time error, given an independent cross-check, that composes a k-sigma monitor floor, the van-Loan coast variance over the detection latency, and a CUSUM time-to-alarm. Calibrated on a real recorded spoof (JammerTest 2024) and reproducible via cargo run --example tpl_jammertest; MODELLED composition (no integrity-risk-per-hour budget), conditional on detection — there is no finite unconditional bound.
GNSS measurement domainForward pseudorange / Doppler synthesis with Klobuchar (broadcast) and IONEX / TEC-grid (measured) ionosphere — including an IONEX file parser, time interpolation between maps, and the thin-shell slant-obliquity mapping — Saastamoinen + Niell troposphere, and snapshot RAIM (HPL/VPL).
ResilienceLink-budget jamming (J/S → effective C/N₀ → loss of lock, with the anti-jam spectral-separation factor Q now derived from the actual signal and jammer power spectra via src/navsignal.rs — Q = 1/(R_c·κ), cross-checked in CI against the previous representative constant); a stochastic time-spoof detector (Neyman–Pearson / χ²₁ energy test with closed-form and Monte-Carlo P_fa/P_md and a Security FoM of 1 − P_md); and a multi-layer spoof detector fusing a RAIM-consistency parity test (with the common-mode blind spot modelled honestly), an RF AGC-power monitor, and a signal-quality (SQM early-minus-late) monitor; and a quantum-inertial dead-reckoning error budget (QuantumNavBudget, src/inertial/quantum_imu.rs) composing the cold-atom-interferometer white-noise velocity-random-walk with residual bias (cross-checked against the independent AccelModel integrator) and scale-factor error into a position-drift-over-holdover figure — the inertial twin of the clock holdover. A framework-aligned resilience-scoring engine (src/resilience/) maps an architecture's simulated behaviour to per-dimension sub-scores across the DHS RPCF categories, then studies the decision-stability of any single composite score or maturity Level under a Dirichlet weighting simplex and a five-threat ensemble — Kendall-τ rank instability, top-1 winner flip rate, and common-mode diversity collapse (Hill-N2), with an integrity-hashed assurance report (35 hand-derived oracle tests). Reproducible via cargo run --example resilience_report; MODELLED synthetic architectures, a self-assessment aligned to RPCF v2.0, not a certification. See docs/RESILIENCE-CROSSWALK.md.
Passive RF geolocationTDOA/FDOA emitter geolocation (src/geolocation.rs) — locate a jammer or spoofer (or an opportunistic source for reverse-PNT) from time-difference-of-arrival hyperboloids across a receiver network, solved by Gauss–Newton least squares; adding frequency-difference-of-arrival with moving receivers jointly recovers the emitter's position and velocity, with the Cramér–Rao bound on the position covariance derived from the network geometry. MODELLED (internal-consistency oracles: forward→inverse round-trips, the J·CRLB = I identity, GDOP monotonicity, and the estimator attaining its own CRLB under Monte-Carlo) — a point-source line-of-sight model, no multipath / NLOS, receiver-clock-bias, or refraction terms.
Nav-signal & code trackingThe signal level between the link budget and the measurement domain (src/navsignal.rs): unit-area power spectral densities for BPSK-R(n) and sine-BOC(m,n); the spectral-separation coefficient κ = ∫ G_s·G_i df, which derives the anti-jam Q the jamming model uses (Q = 1/(R_c·κ)) from the actual signal/jammer spectra instead of a representative constant; the RMS (Gabor) bandwidth (BOC > BPSK — the ranging-information / Cramér–Rao measure); the coherent early–late DLL code-tracking thermal-noise jitter (Kaplan & Hegarty; ~sub-metre for C/A at 45 dB-Hz); and the multipath error envelope (coherent EML — narrow-correlator suppression). Validated against closed-form anchors (BPSK self-SSC = 2/(3·R_c), unit-area PSDs, sub-metre C/A jitter). This is signal-performance analysis, not antenna / RF-payload hardware design (a payload partner's role).
InteroperabilityRINEX-3 multi-GNSS broadcast-ephemeris ingestion (GPS, Galileo, QZSS, BeiDou MEO/IGSO via IS-GPS-200; GLONASS via PZ-90 state-vector RK4) usable as a constellation source (RINEX in, PNT geometry out); a RINEX-3/4 observation parser (pseudorange, carrier phase, Doppler, signal strength) that now feeds a single-point-positioning solver (pvt) — real code observations in, a real receiver position out, validated on IGS data; an SP3-c/d precise-ephemeris reader/writer with 9th-order Lagrange interpolation; and CCSDS OEM 2.0 + OMM (mean-elements) export for flight-dynamics tools (GMAT, Orekit, STK); and CCSDS-TDM (503) tracking-data-message parse + emit for deep-space radiometric tracking.
Mission analysis (systems engineering)First-order mission-design budgets, each a runnable kind: two-body launch & ascent geometry (launch-window — launch azimuth sin Az = cos i/cos lat, minimum inclination, Earth-rotation bonus, dogleg plane-change Δv, daily opportunities; src/launch.rs); an Allen–Eggers ballistic re-entry corridor (reentry — peak deceleration, peak-g velocity/altitude, peak-heating velocity; src/reentry.rs); Earth-observation coverage geometry (eo-coverage — swath / nadir GSD / off-nadir access / revisit via the SMAD space triangle; src/eo_payload.rs); a 3-DOF attitude & pointing error budget (attitude-budget — worst-case gravity-gradient torque + RSS pointing budget; src/attitude_budget.rs); ground-station pass prediction (passes — AOS/TCA/LOS, max elevation, access time; src/passes.rs); and a one-way link budget over the CCSDS 401 / DSN 810-005 link equation (link-budget — FSPL, C/N₀, Eb/N₀, margin, closure; src/linkbudget.rs). MODELLED first-order analytic budgets — the pre-hardware layer below STK/GMAT/Basilisk, not a 6-DoF or radiometric replacement.
Decision analysis & trade-off (MCDA)A full multi-criteria decision-analysis suite (src/mcda/) spanning all four method families — value aggregation (WSM, WPM, WASPAS), distance-to-ideal (TOPSIS), compromise programming (VIKOR), and outranking (PROMETHEE II, ELECTRE I), plus ratio-system MOORA and proportional COPRAS — with AHP pairwise-comparison priority weighting (Consistency Ratio), a Pareto non-dominated front, weight-sensitivity analysis, and multi-attribute utility scoring. The nine aggregators reproduce the independent third-party libraries pymcdm (WSM / WPM / WASPAS / MOORA / TOPSIS / VIKOR / PROMETHEE II) and pyDecision (ELECTRE I, COPRAS) to < 1e-9, and the AHP priority vector + Consistency Ratio match Saaty's Random-Index table and the SciPy/LAPACK principal eigensolver to < 1e-9 (tests/mcda_*_reference.rs). VALIDATED — the decision layer under the trade-study engine.
Space environmentA space-weather environment model (space-weather, src/space_weather.rs): solar (F10.7 / centred-81-day F10.7a) and geomagnetic (Kp, with the definitional Kp↔ap table) activity indices, the Jacchia-1971 exospheric temperature they drive (validated vs published solar min/mean/max), and the activity-corrected vs static thermospheric neutral density at altitude — the solar-cycle density dependence the static USSA76 atmosphere omits. MODELLED: a calibrated first-order scale-height coupling, not a data-validated (NRLMSISE) atmosphere.
AI/ML evaluation & tradeAn RF-impairment detection evaluation testbed (impairment-eval, src/impairment_eval.rs): a labelled, parameter-grounded synthetic corpus (nominal / jamming / spoof-time / spoof-position / multipath), a detector-agnostic ROC/AUC harness scoring any detector (energy | agc | sqm | parity | fused) with per-class Pd at a target Pfa, and the in- vs out-of-distribution optimism gap (distribution-shift mode). Plus a quantum-vs-classical PNT trade (quantum-trade, src/quantum_trade.rs) quantifying a candidate clock's timing/inertial holdover benefit from a measured-ADEV curve vs a classical baseline, with the long-τ floor caveat carried on the artifact and a GNSS-denied resilience-vs-time envelope. The evaluation metrics (AUC / confusion / Pd-Pmd) are validated to an exact match against scikit-learn 1.9.0 — including on real ESA OPS-SAT telemetry (the OPSSAT-AD dataset, Ruszczak et al. 2025, CC BY 4.0), where Kshana's Mann–Whitney ROC AUC reproduces scikit-learn's roc_auc_score to < 1e-9 on the held-out test split and a transparent peak-count detector separates the labelled anomalies at AUC ≈ 0.85 (tests/opssat_ad_reference.rs) — and the trade engine's numerical kernels (ADEV NNLS fit, χ² consistency bands, van-Loan clock Q) against scipy 1.17.1; the device-benefit numbers built on top stay MODELLED operating characteristics — never field/IQ data, no good/bad verdict. Building on the testbed, a deeper optimism-gap study (src/impairment_study.rs, impairment_ml.rs, eval_stats.rs) scores a 13-detector panel (energy/AGC/SQM/parity plus seeded logistic-regression and one-hidden-layer-MLP detectors), fits in- vs out-of-distribution scaling laws with a permutation null, and learns a leave-one-out predictor of out-of-distribution degradation from in-distribution statistics (cargo run --example optimism_study). A software-defined-receiver front end (src/sdr.rs — raw IQ/IF → correlator early/prompt/late taps → SQM) and real-data ingest adapters (src/realdata/ — RINEX, u-blox UBX, GnssLogger, JammerTest, Yunnan, SatGrid) let the same detectors run over recordings supplied locally (no datasets are committed). The quantum-vs-classical resilience crossover map under parameter uncertainty (src/crossover.rs; cargo run --bin crossover_study) regenerates the inertial and clock crossover studies behind the Results figures.
Quantum-Enabled PNT demonstratorThree runnable, MODELLED application areas behind the open engine, each emitting honest TradeEvidence + a representativeness / gaps-to-flight record (src/representativeness.rs): trusted quantum time transfer (quantum-time-transfer, src/timetransfer_chain.rs — an end-to-end optical-lattice-clock + photonic-link vs CSAC + RF two-way budget, with a reused timing protection level, a delay/replay-attack security FoM (1 − P_md), and clock-anomaly detection + CUSUM latency); GNSS-free quantum navigation (quantum-gnss-free-nav, src/quantum_nav_od.rs — a cold-atom-interferometer inertial coast vs a navigation-grade INS over a GNSS outage, honest that with no external fix the accelerometer bias is unobservable so the error still grows); and quantum-system fault/anomaly detection (quantum-anomaly-detect, src/quantum_faults.rs — a labelled fault catalogue with a bootstrap-CI ROC AUC from the externally-validated eval_stats and a minimum-detectable-fault at a fixed false-alarm rate). A shared quantum device error-model library (src/quantum_devices.rs) and a unified quantum-vs-classical trade harness (src/qtrade.rs) underpin them. The validated kernels they ride (eval-metrics vs scikit-learn, trade kernels vs scipy) are reused; the device-benefit numbers built on top stay MODELLED — illustrative public-source device/link parameters, models the class, no TRL / flight heritage / certification, no agency endorsement.
Frugal engineering & integrity impactA cost-per-coverage ROI lens (src/frugal.rs) — cost per unit of delivered coverage for an architecture trade — and a detection-miss → integrity-impact mapping (src/integrity_impact.rs) that turns a monitor's missed-detection rate into its integrity-risk contribution. MODELLED decision-support budgets, additive.
Artifact interchangeThe Kshana Interchange Format (KIF) (src/interchange.rs) — a versioned, self-describing envelope wrapping a scenario result with its kind, schema version, and MODELLED/VALIDATED labels, so a stored artifact stays self-documenting and older envelopes remain forward-compatibly readable.

Each capability is reachable as a Rust API, a runnable scenario kind, or both. Maturity per capability — validated, runnable, or library — is tracked in docs/CAPABILITY.md. A machine-checked verification matrix (src/verification.rs) renders the requirement → module → test → oracle → status cross-reference, with unit-tested honesty invariants that permit a validated label only where an independent external oracle backs it — and that record the hardware/PA capabilities Kshana deliberately does not provide.

Results

Each scenario compares a quantum sensor against its classical counterpart through a ~1.8 h GNSS outage. Numbers are reproducible (scenario + seed + version).

The advantage is outage- and vibration-dependent, with an explicit break-even where classical wins — shown honestly across the technology-readiness ladder (optical-clock figures are ground-demonstrator targets; no strontium optical clock has flown):

PackScenarioQuantumClassical
1 — Clock holdoverclock-holdover.toml (20 ns spec)optical clock holds the full outageCSAC breaches the spec mid-outage
2 — Inertial dead-reckoningimu-deadreckoning.toml (100 m spec)cold-atom: ~41 m, holds full outagenav-grade: breaches in ~350 s → tens of km
3 — Time transfer (optical inter-satellite link)timetransfer.tomloptical: ~0.3 mm rangingRF (TWSTFT): ~150 mm ranging
4 — Hybrid fusion (capstone)hybrid-pnt.tomlfull position+timing for the whole outageposition-limited at ~350 s

The capstone shows the fusion thesis: optical inter-satellite time-transfer keeps even a classical clock locked, isolating the inertial sensor as the classical suite's weak link — i.e. quantum inertial + optical timing together.

A further scenario, orbit-gnss-challenged.toml, derives GNSS availability from orbital geometry rather than hand-authored windows: a spacecraft inside the GNSS shell is propagated against a GPS-like Walker constellation, and the visible-satellite count (line-of-sight, Earth-occultation, elevation mask) sets the fix state at each step. Over a day the user is in fix only ~59% of the time; the quantum clock holds a 5 ns timing solution through every gap (availability 1.0), the chip-scale clock only ~0.83.

Orbit GNSS-challenged: clock timing error over a day for a spacecraft inside the GNSS shell, where the coverage gaps are derived from orbital geometry — the optical clock stays within the 5 ns spec across the gaps while the chip-scale clock breaches it
Timing error over a day with GNSS availability derived from orbital geometry: the visible-satellite coun

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
docker run -i --rm ghcr.io/ashfordeou/kshana-mcp:0.32.0

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-ashfordeou-kshana-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/ashfordeou/kshana-mcp:0.32.0"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

ghcr.io/ashfordeou/kshana-mcp:0.32.0docker

Compatible MCP Clients

Kshana PNT-resilience simulator works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More