What is Integrity?

In GNSS, integrity is the measure of trust that can be placed in a positioning system’s output — and its ability to provide timely warnings when that output is unreliable or hazardously incorrect. A high-integrity system does not just report a position; it also computes statistical bounds on the position error (a Protection Level) and alerts users when those bounds exceed safe operational thresholds.

 

Why Integrity Matters

Accuracy tells you how close a position is to truth on average. Integrity tells you how much you can trust that claim — and what happens when things go wrong.

Consider an autonomous vehicle on a motorway. A high-accuracy positioning system might report a position within 5 cm of truth 99% of the time. But what about the 1% when it is wrong by 2 metres? Without integrity monitoring, the vehicle has no way to detect those dangerous outliers. Integrity monitoring computes a protection level — a statistical bound containing the true error with very high probability — and alerts the system when that bound becomes too large for safe operation.

This is why integrity is not optional for safety-critical applications. Standards like ISO 26262 (automotive) and DO-178C (aviation) require positioning systems to demonstrate specific integrity performance before use in safety functions.


Key Integrity Concepts

  • Protection Level (PL): A statistical bound on the true position error, computed in real time and guaranteed to contain the error with a specified probability (e.g., 1 − 10⁻⁷).
  • Alert Limit (AL): The maximum allowable position error for a given operation to remain safe — defined by the application or regulatory standard, not the positioning system.
  • Hazardously Misleading Information (HMI): A condition where the true error exceeds the Alert Limit but no warning has been issued. Preventing HMI is the core objective of integrity monitoring.
    Integrity Risk: The probability per unit time of HMI occurring without alert. Expressed as a very small number — e.g., <10⁻⁷ per hour.
  • Time to Alert (TTA): Maximum allowable time between onset of a hazardous condition and issuance of an alert. Aviation standards require 1–10 seconds; automotive may require sub-second alerting.

 

How Integrity Monitoring Works

RAIM (Receiver Autonomous Integrity Monitoring): The receiver uses redundant satellite measurements to detect and exclude faulty satellites. If it cannot bound its error within the Alert Limit, it withholds the position output.

Advanced RAIM (ARAIM): A more sophisticated version accounting for multiple simultaneous faults, constellation health data, and integrity support messages.

Service-level integrity: The correction service computes and transmits error bounds based on network-observed error statistics, giving the rover an additional verification layer beyond satellite-level checks.

 

Integrity in Automotive ADAS

Automotive positioning used in safety functions must comply with ISO 26262 and the ASIL classification system. Key requirements:

  1. Real-time PL output: Horizontal and vertical protection levels, updated at the sensor fusion rate (10–100 Hz).
  2. Alert propagation: When PL > AL, the alert must reach the ADAS system within the required Time to Alert.
  3. ASIL-B/D compliance: Development processes for the correction service and positioning software must meet the relevant ASIL level.

Swift Navigation: Precise Positioning with integrity for automotive

Skylark Cx is the first cloud-based GNSS correction service certified to ISO 26262, delivering real-time Protection Level outputs for ASIL-compliant ADAS and automated driving stacks.

Learn about the Swift Automotive Suite →

Frequently Asked Questions

Accuracy measures how close a position is to truth on average. Integrity measures how reliably the system detects and warns when its position is wrong. A system can be accurate on average but have poor integrity if dangerous outlier errors go undetected. For safety-critical applications, integrity is as important as — often more important than — average accuracy.

A Protection Level (PL) is a computed statistical upper bound on the true position error, updated in real time. If the PL is 0.5 m, the system claims with very high probability (e.g., 1 − 10⁻⁷) that the true error is less than 0.5 m. When PL exceeds the Alert Limit for the current operation, the system issues an alert.

Yes. Functional safety standards for autonomous and semi-autonomous vehicles — including ISO 26262 and UN Regulation 157 — require that safety-critical positioning inputs come from certified, integrity-monitored systems. A raw RTK fix without integrity bounds does not meet these requirements.

PPP-RTK is well suited to automotive applications, particularly when combined with integrity monitoring. ISO 26262-certified PPP-RTK correction services can be integrated into ASIL-compliant ADAS and automated driving positioning stacks.

Related Glossary Terms

Related Content

Automotive

GNSS Basics