kshana-mcp
Provides a JetBrains IDE plugin for integrating the Kshana PNT simulator into JetBrains development environments, allowing simulation and analysis within the IDE.
Provides a Python extension to use the Kshana PNT-resilience simulator from Python code, enabling programmatic scenario execution and analysis.
Enables running the Kshana simulator in the browser as a WebAssembly module, allowing interactive PNT simulations without installation.
Timing and holdover for critical infrastructure come first, because that is the
best-validated domain. The frequency-stability estimators a holdover answer rests on —
Allan deviation (ADEV), modified Allan deviation (MDEV), time deviation (TDEV) and maximum
time interval error (MTIE) — are VALIDATED against Stable32, the independent allantools
library and a real measured caesium clock, and the holdover coast-variance inversion
(how long a free-running clock stays inside a time-error budget) is VALIDATED against SciPy.
The per-clock-class noise floors that dominate a real holdover figure stay MODELLED: supply
measured floors for a number you intend to defend. The telecom-timing scenario kind
applies this to telecom networks — it reports MTIE and TDEV, checks them against the masks of
the International Telecommunication Union Telecommunication Standardization Sector (ITU-T)
for a primary reference time clock (G.8272), an enhanced primary reference time clock
(G.8272.1), a telecom boundary clock (G.8273.2) and the network limits at reference point C
(G.8271.1), and reports how long a holdover stays inside each time-error budget; see
docs/TELECOM-TIMING.md.
What makes it different is not the physics — that is standard — but the evidence
discipline. It is open source, so anyone can rerun and read it; every result is
reproducible bit for bit from scenario + seed + engine version; every sensor parameter is
traceable to a published source, consolidated in one citable table in
docs/PROVENANCE.md; and every capability carries its
VALIDATED / MODELLED / PARTNER provenance tier (PARTNER: owned by a hardware partner),
guarded in CI (continuous integration) so that no capability can be labelled VALIDATED
without an independent external oracle behind it.
Quantum is a neutral trade method, not the headline. Kshana compares quantum and
classical clocks and inertial sensors on the same scenario with the same code, as a
neutral quantum-vs-classical trade method whose results are labelled MODELLED. Most
sensor inputs are published Allan/noise-budget coefficients; a first-principles
cold-atom-interferometer accelerometer layer (Mach–Zehnder phase, quantum projection noise,
contrast decay, vibration coupling) derives its noise coefficient rather than looking it
up. It is not a full quantum-physics simulator — see docs/QUANTUM.md
and docs/QUANTUM-MODELS.md. Lunar / cislunar and deep-space
navigation, orbit propagation and integrity monitoring are maintained capabilities of the
same engine, each carrying its own tier in the matrix.
What it is not. Kshana is not a radio-frequency (RF) signal simulator or a
hardware-in-the-loop test rig, not a GNSS receiver, and not a replacement for
MATLAB/Simulink, STK (Systems Tool Kit) or Orekit. It sits next to them: it reads and
writes their exchange formats, and its force model is cross-checked against Orekit rather
than offered in its place. See What it is / is not and
docs/POSITIONING.md.
Validated against external oracles — every row CI-gated
Each row is checked against an independent external oracle (real dataset, independent reference implementation, or published reference vectors) and re-checked in CI (continuous integration). Full 171-row matrix →
Capability | Result | External oracle | |
✅ | SGP4/SDP4 (Simplified General Perturbations 4 / Simplified Deep-space Perturbations 4, the standard analytic satellite-orbit propagators) propagation | 666/666 vectors, worst 4.12 mm | AIAA 2006-6753 (Vallado; AIAA = American Institute of Aeronautics and Astronautics) + independent |
✅ | Numerical Cowell force model | 0.08 m / 24 h, 275 epochs | Orekit 12.2 |
✅ | Orbit fit vs precise ephemeris | Galileo 0.61 m · Swarm-A 0.10 m | ESA (European Space Agency) / ESOC (European Space Operations Centre) SP3 (Standard Product 3, the precise-orbit format of the IGS — the International GNSS (global navigation satellite system) Service) precise orbits |
✅ | GCRS→ITRS (Geocentric Celestial Reference System → International Terrestrial Reference System) frame chain | bit-for-bit vs SOFA (the International Astronomical Union's Standards of Fundamental Astronomy library); ≤ 0.86 m vs SPICE (Spacecraft, Planet, Instrument, C-matrix, Events — the planetary-geometry toolkit) | ERFA (Essential Routines for Fundamental Astronomy, the open port of SOFA)/SOFA + ANISE (Attitude, Navigation, Instrument, Spacecraft, Ephemeris — a pure-Rust SPICE) |
✅ | Allan deviations | reproduce reference deviations | NIST SP 1065 (National Institute of Standards and Technology Special Publication 1065) + Stable32 on a real Cs (caesium) clock |
✅ | Global navigation satellite system (GNSS) dilution of precision (DOP) · machine-learning (ML) detector metrics | to 1e-6 · to 1e-9 | gnss_lib_py · scikit-learn |
✅ | Fisher information · CRLB (Cramér–Rao lower bound) · observability | eigh / CRLB / DOP to 1e-9 | NumPy 2.4.1 (LAPACK, the Linear Algebra PACKage) + Kay (1993) closed forms |
Free and open source under the GNU AGPL-3.0 (GNU Affero General Public License, version 3)
— with a commercial licence available from Ashforde OÜ (an Estonian private limited
company; OÜ = osaühing) for proprietary/closed integration (see LICENSING.md).
Professionally developed and maintained by Ashforde OÜ; commercial
support, integration, and proprietary extensions available.
Status: v0.27.3 · a validated, reproducible simulation substrate for PNT resilience. A fully reproducible engine spanning the PNT stack — orbit geometry and constellation design, a numerical (Cowell) propagator with a seven-perturbation force model, maneuver and trajectory design, time systems, inertial navigation (incl. map-aided and gravity-map-matching alt-PNT), GNSS / inertial-navigation-system (INS) fusion (loose, tight, unscented Kalman filter — UKF, coupled clock+position, 17-state), orbit determination, ARAIM (advanced receiver autonomous integrity monitoring), clocks, advanced time-and-frequency transfer, the GNSS measurement domain, resilience (jamming + multi-layer spoofing), and an open deep-space / Mars radiometric navigation engine (light-time + Shapiro, CCSDS-TDM — the Consultative Committee for Space Data Systems Tracking Data Message — a reduced-dynamic square-root information filter (SRIF), one-/two-way fusion); plus first-order mission-analysis budgets (launch / re-entry / Earth-observation (EO) coverage / pointing / ground-station passes / link), a space-weather environment model, an AI/ML RF-impairment (artificial-intelligence / machine-learning, radio-frequency) evaluation testbed, and the versioned Kshana Interchange Format (KIF). Honest by design: every figure of merit is labelled validated or modelled, and optical-clock figures are space goals on ground hardware (no strontium optical clock has flown).
Validation ladder (maturity is not uniform across domains — and saying so is the point):
Domain
Tier
Earth PNT (orbit, frames, time, clocks, IMU — inertial measurement unit, integrity)
Real-data validated — ESA SP3 (Galileo 0.13 m / 8 h · 0.61 m / 24 h, Swarm-A 0.10 m), NIST SP1065, SOFA/ERFA, heritage vectors
Deep-space / Mars navigation
Simulation-validated — synthetic closed-loop orbit determination (OD) + analytic self-consistency; Sun-central dynamics cross-checked vs JPL (Jet Propulsion Laboratory) DE440 (Development Ephemeris 440) (137 m @ 1-day arc)
Real-mission deep-space OD
Roadmap — pending real Deep Space Network (DSN) / ESTRACK (European Space Tracking network) tracking-data validation
Deep-space figures (Mars-LMO — low Mars orbit — OD ≈ 0.2 m; relay-PNT orbiter 0.4 m / rover 5.1 m) are simulation / covariance figures of merit, not real-mission results. See Capabilities for what it does, What it is / is not for scope, and
docs/CAPABILITY.md/docs/VALIDATION.mdfor per-capability maturity. The overclaim closure ledgerdocs/CLAIMS-VS-REALITY.mdtracks every historical overclaim, how it was resolved, and a CI guard (tests/no_overclaims.rs) that keeps it resolved.
Try it in your browser: the playground runs the engine client-side as WebAssembly — pick a scenario, edit the parameters, and see the result, with nothing uploaded. Build it locally with
./web/build.sh(seeweb/README.md). The hosted copy at kshana.dev is rebuilt from each release tag by thepagesworkflow.
New to this? In plain terms: GPS-style (Global Positioning System) satellite signals tell things where they are and what time it is. When those signals are lost (jammed, blocked, or out of view in space), a system has to keep going on its own onboard clock and motion sensors — and they slowly drift. A telecom network, a power grid or a trading venue that takes its time from satellites has to ride through that loss on its own clock. Kshana measures, in honest numbers, how long a system can coast before it exceeds its accuracy limits, and how much a better clock or sensor — classical or quantum — buys. New readers should start with the plain-language primer and the glossary.
Contents
Related MCP server: MetroAI — KOLAS Compliance OS
Why
Resilient PNT depends on holding position and time when GNSS is denied or jammed. Critical infrastructure — telecom, power, finance — takes its time from GNSS and has to size holdover: how long a local clock can free-run before its time error breaks the budget. That sizing is usually done with vendor calculators or in-house spreadsheets whose assumptions are hard to inspect. Kshana's aim is to make the same answer open, reproducible and provenance-labelled, so it can be rerun and challenged by an assessor rather than taken on trust. The same machinery gives a neutral trade between classical and quantum clocks and inertial sensors, with those results labelled MODELLED.
The engine knows nothing about "quantum" vs "classical": each sensor is an error model plugged into a common pipeline, so a quantum and a classical device are compared apples-to-apples on the same scenario, with independent noise realizations.
What it is / is not
It is: a deterministic, dependency-light engine spanning the PNT stack — orbit geometry, inertial navigation, GNSS/INS fusion, integrity, clocks, and timing. It runs a scenario (often a GNSS outage), evolves calibrated sensor error models through the appropriate estimator, and scores the result against the operational figures of merit — emitting a reproducible JSON (JavaScript Object Notation) result and an SVG chart, from a Rust library, a command-line interface (CLI), a Python extension, an in-browser WebAssembly module, a Model Context Protocol (MCP) server for AI agents, or a JetBrains IDE (integrated development environment) plugin.
It is not: flight hardware, a quantum-payload design, a full GNSS signal
receiver, a radio-frequency (RF) signal simulator or hardware-in-the-loop rig, or a
certified avionics product — and it does not replace MATLAB/Simulink, STK (Systems Tool
Kit) or Orekit; it sits next to them and exchanges files with them. Quantum-hardware fidelity comes from
published error models, not from this tool. The granular maturity of each
capability is documented in docs/CAPABILITY.md.
It is not (yet): a full atom-interferometry physics engine (most quantum sensors
consume published Allan/noise-budget coefficients; the CAI (cold-atom interferometer) accelerometer has a
first-principles layer — Mach–Zehnder phase, projection noise, contrast decay, and
vibration coupling, plus Coriolis and light-shift systematics — but wavefront systematics and
fringe-ambiguity resolution remain a P2 (roadmap phase 2, the quantum physics layer)
roadmap layer, see ROADMAP.md and docs/QUANTUM-MODELS.md);
a full GNSS signal-acquisition receiver (it now solves a single-point PVT (position, velocity and time) position
fix from real RINEX (Receiver Independent Exchange Format) code observations — validated
on real IGS (International GNSS Service) data — but does not
acquire or track raw signal); or a full mission-design suite (it has Lambert / porkchop /
maneuver / orbit-determination building blocks, but is the performance-simulation layer
above GMAT (General Mission Analysis Tool)/Orekit, not a replacement). Owning this scope is deliberate. If you need first-principles cold-atom
interferometer error budgets (e.g. CARIOQA-PMP-grade — Cold Atom Rubidium Interferometry
in Orbit for Quantum Accelerometry, Pathfinder Mission Preparation — or X-37B-style validation), see
the P2 roadmap and get in touch to collaborate.
Capabilities
One engine spans the whole PNT stack — and its maturity is honest per domain: Timing, Orbits and GNSS geometry are heavily externally validated; Lunar and several quantum/resilience domains are deliberately Modelled until real tracking data exists.
The full domain-by-domain detail follows; for a per-capability maturity ledger see
docs/CAPABILITY.md and docs/VALIDATION.md.
Domain | Capability |
Orbit & geometry | SGP4/SDP4 propagation (validated to 4.12 mm against all 666 AIAA 2006-6753 vectors); real two-line elements (a committed, date-stamped Celestrak |
Numerical propagator | A Cowell numerical propagator ( |
Maneuvers & trajectory design | Impulsive ΔV nodes with 6×6 covariance propagation (ECI — Earth-centred inertial — / LVLH — local vertical, local horizontal — execution-error frames), finite-burn integration checked against the closed-form Tsiolkovsky rocket equation to < 0.01 %, an Izzo-2015 single-revolution Lambert solver, an exact universal-variable Kepler propagator, and a porkchop (launch × arrival) C3 (launch energy) / arrival-V∞ sweep emitted as a JSON contour grid — the performance-simulation layer above GMAT/Orekit, with every Lambert output round-tripped against two-body truth and the porkchop minimum checked against the analytic Hohmann floor. |
Time systems & reference frames | IERS leap-second UTC / TAI / TT / UT1 scales (Coordinated Universal Time, International Atomic Time, Terrestrial Time, and the Earth-rotation time Universal Time 1), a Julian-date API (application programming interface), the IAU-2000 (International Astronomical Union) Earth Rotation Angle (ERA), GMST-based (Greenwich Mean Sidereal Time) TEME ↔ ECEF (true equator, mean equinox ↔ Earth-centred, Earth-fixed) with WGS-84 (World Geodetic System 1984) geodetic frames, IAU 2006 precession (Fukushima–Williams), full IAU 2000A/2000B nutation, IERS polar motion, and the equinox-free CIO-based IAU 2006/2000A GCRS↔ITRS reduction (CIO = Celestial Intermediate Origin) — all validated bit-for-bit against the SOFA/ERFA vectors, and independently cross-checked against ANISE (the pure-Rust NAIF/SPICE reimplementation; NAIF = the Navigation and Ancillary Information Facility of NASA, the US National Aeronautics and Space Administration): kshana's GCRS→ITRS vs ANISE's ITRF93 (International Terrestrial Reference Frame 1993) from JPL's |
Inertial | Three-axis strapdown INS — quaternion attitude, WGS-84 NED (north-east-down) mechanization, coning/sculling compensation, and a deterministic IMU error model (scale-factor, misalignment, g-sensitivity, quantization, drift); a first-principles cold-atom-interferometer accelerometer (Mach–Zehnder phase, quantum projection noise, contrast decay, vibration coupling) that derives the velocity-random-walk coefficient; and a sequential-importance-resampling particle filter for map-aided (terrain-/gravity-referenced) GPS-denied navigation. |
Alt-PNT (GPS-denied) | A cold-atom gravimeter measurement model whose white-noise floor ( |
Fusion | Loosely-coupled 15-state GNSS/INS error-state EKF (extended Kalman filter) with closed-loop feedback (the |
Orbit determination | Recovery of an orbital state |
Observability & estimation theory | A general, reusable Fisher-information / Cramér–Rao layer ( |
Lunar & cislunar | An Earth–Moon circular restricted three-body (CR3BP) propagator in the rotating frame — conserved Jacobi constant and all five Lagrange points ( |
Lunar PNT suite | A modelled lunar/cislunar navigation suite layered on the CR3BP core, each a runnable |
Deep-space & Mars PNT | An open radiometric navigation engine: iterative light-time + Shapiro relativistic delay, two-/one-/three-way Doppler & range (Moyer two-leg), coherent transponder turnaround ratios, regenerative/PN (pseudo-noise) ranging (CCSDS 414, the pseudo-noise ranging standard), and Δ-DOR plane-of-sky (CCSDS 506, the Delta-DOR standard), with solar-plasma/tropo/iono media; CCSDS-TDM (503) tracking-data-message parse + emit; a reduced-dynamic Square-Root Information Filter (RTN — radial, transverse, normal — empirical accelerations + a 3-state onboard clock + Mars atmospheric drag) that does Mars-LMO orbit determination to ≈ 0.2 m in a synthetic closed loop; a joint one-way + two-way fusion estimator; a multi-body dynamics core ( |
Integrity | Snapshot and solution-separation (ARAIM-style) RAIM — receiver autonomous integrity monitoring — with horizontal/vertical protection levels (HPL/VPL), fault detection & exclusion, and Stanford integrity diagrams; an explicit integrity-risk-budget multiple-hypothesis solution separation (MHSS) protection level, including the dual-/multi-constellation constellation-wide fault mode (EU (European Union) ARAIM / DO-316, the RTCA performance standard for GPS airborne equipment with aircraft-based augmentation), exercised on a real GPS + Galileo snapshot ( |
Augmentation (SBAS) | SBAS / WAAS protection levels (WAAS = the Wide Area Augmentation System) in the DO-229E weighted-least-squares form (precision-approach and en-route K-factors) and the L1/L5 dual-frequency ionosphere-free combination (L1 and L5 being two GPS civil signal bands; IS-GPS-705, the GPS interface specification for the L5 signal, γ₁₅ ≈ 1.793) that underpins DO-316 — |
Clock & timing | Two-state Kalman holdover (Joseph-form covariance, NIS/NEES — normalised innovation squared / normalised estimation error squared — consistency health); Allan-family stability (ADEV / MDEV / TDEV / HDEV / MTIE — Allan, modified Allan, time and Hadamard deviation, and maximum time interval error) with noise-type-specific confidence intervals and a full IEEE-1139 five-coefficient power-law fit (IEEE Std 1139, the Institute of Electrical and Electronics Engineers frequency-and-time metrology definitions) — the estimators are validated on real hardware against Stable32: a real 5071A caesium primary standard vs a hydrogen maser (556,990 phase samples, 16 averaging factors, OADEV/OHDEV — overlapping Allan/Hadamard deviation — to 1e-3; |
GNSS measurement domain | Forward pseudorange / Doppler synthesis with Klobuchar (broadcast) and IONEX / TEC-grid (IONosphere map EXchange format / total electron content; measured) ionosphere — including an IONEX file parser, time interpolation between maps, and the thin-shell slant-obliquity mapping — Saastamoinen + Niell troposphere, and snapshot RAIM (HPL/VPL). |
Resilience | Link-budget jamming (J/S → effective C/N₀ → loss of lock — jammer-to-signal ratio, carrier-to-noise-density ratio — with the anti-jam spectral-separation factor |
Passive RF geolocation | TDOA/FDOA emitter geolocation (time-/frequency-difference of arrival; |
Nav-signal & code tracking | The signal level between the link budget and the measurement domain ( |
Interoperability | RINEX-3 multi-GNSS broadcast-ephemeris ingestion (GPS, Galileo, QZSS — Japan's Quasi-Zenith Satellite System —, BeiDou MEO/IGSO — medium Earth orbit / inclined geosynchronous orbit — via IS-GPS-200, the GPS interface specification; GLONASS, Russia's Global Navigation Satellite System, via PZ-90 — the Russian Parametry Zemli 1990 datum — state-vector RK4) usable as a constellation source (RINEX in, PNT geometry out); a RINEX-3 observation parser (pseudorange, carrier phase, Doppler, signal strength; the 4.00 observation layout is expected to parse but is untested, and RINEX 4 navigation files are refused by name rather than mis-decoded) that now feeds a single-point-positioning (SPP) solver ( |
Mission analysis (systems engineering) | First-order mission-design budgets, each a runnable kind: two-body launch & ascent geometry ( |
Decision analysis & trade-off (MCDA) | A full multi-criteria decision-analysis (MCDA) suite ( |
Space environment | A space-weather environment model ( |
AI/ML evaluation & trade | An RF-impairment detection evaluation testbed ( |
Quantum-Enabled PNT demonstrator | Three runnable, MODELLED application areas behind the open engine, each emitting honest |
Frugal engineering & integrity impact | A cost-per-coverage ROI (return on investment) lens ( |
Artifact interchange | The Kshana Interchange Format (KIF) ( |
Each capability is reachable as a Rust API, a runnable scenario kind, or both.
Maturity per capability — validated, runnable, or library — is tracked in
docs/CAPABILITY.md. A machine-checked verification matrix
(src/verification.rs) renders the requirement → module → test → oracle → status
cross-reference, with unit-tested honesty invariants that permit a validated label
only where an independent external oracle backs it — and that record the
hardware/PA (product-assurance) capabilities Kshana deliberately does not provide.
Results
Each scenario compares a quantum sensor against its classical counterpart through a
~1.8 h GNSS outage. Numbers are reproducible (scenario + seed + version).
The advantage is outage- and vibration-dependent, with an explicit break-even where classical wins — shown honestly across the technology-readiness ladder (optical-clock figures are ground-demonstrator targets; no strontium optical clock has flown):
Pack | Scenario | Quantum | Classical |
1 — Clock holdover |
| optical clock holds the full outage | CSAC breaches the spec mid-outage |
2 — Inertial dead-reckoning |
| cold-atom: ~41 m, holds full outage | nav-grade: breaches in ~350 s → tens of km |
3 — Time transfer (optical inter-satellite link) |
| optical: ~0.3 mm ranging | RF (TWSTFT): ~150 mm ranging |
4 — Hybrid fusion (capstone) |
| full position+timing for the whole outage | position-limited at ~350 s |
The capstone shows the fusion thesis: optical inter-satellite time-transfer keeps even a classical clock locked, isolating the inertial sensor as the classical suite's weak link — i.e. quantum inertial + optical timing together.
A further scenario, orbit-gnss-challenged.toml, derives GNSS availability from
orbital geometry rather than hand-authored windows: a spacecraft inside the GNSS
shell is propagated against a GPS-like Walker constellation, and the visible-satellite
count (line-of-sight, Earth-occultation, elevation mask) sets the fix state at each
step. Over a day the user is in fix only ~59% of the time; the quantum clock holds a
5 ns timing solution through every gap (availability 1.0), the chip-scale clock
only ~0.83.
The constellation can also be given as real two-line element sets (TLEs). A full TLE
(line 1 + line 2) is propagated with the full SGP4/SDP4 model — including
atmospheric drag and the deep-space lunar-solar and 12 h / 24 h resonance terms that
matter for ~12 h GNSS orbits — validated against the official AIAA 2006-6753 vectors
to a worst-case ≈ 4 mm. scenarios/orbit-sgp4-gps.toml ships a real Celestrak
gps-ops snapshot of the operational GPS constellation (2021-07-28, 30 satellites)
and requires valid TLE checksums — two-line element sets are open data from the US
Space Force / 18th Space Defense Squadron catalogue, redistributed by Celestrak
(Dr T. S. Kelso, celestrak.org); refresh with
scripts/fetch_tles.sh. A line-2-only block keeps
the analytic two-body propagation (scenarios/orbit-real-tle.toml); the two forms can
be mixed in one constellation. A constellation can equally be built from a block of
RINEX-3 GPS broadcast-ephemeris records — the format a receiver decodes —
propagated by the IS-GPS-200 user algorithm and fed through the same geometry
(scenarios/orbit-rinex.toml).
Install & build
Requires a Rust toolchain (≥ 1.85, the rust-version in Cargo.toml; developed on 1.93).
git clone https://github.com/ashfordeOU/kshana
cd kshana
cargo build --release
cargo test # all tests passUsage
Run any scenario; the CLI dispatches on the scenario's kind field and writes
<scenario>.result.json, <scenario>.chart.svg and <scenario>.report.html next to
it — plus <scenario>.table.csv for the kinds that publish a table:
cargo run -- scenarios/clock-holdover.toml
cargo run -- scenarios/imu-deadreckoning.toml
cargo run -- scenarios/timetransfer.toml
cargo run -- scenarios/hybrid-pnt.toml
cargo run -- scenarios/orbit-gnss-challenged.toml
cargo run -- scenarios/orbit-sgp4-gps.toml
cargo run -- scenarios/orbit-rinex.toml
cargo run -- scenarios/integrity-raim.toml
# Export a propagated constellation to an SP3-c precise-ephemeris file:
cargo run -- scenarios/orbit-sgp4-gps.toml --export-sp3 gps.sp3
# Export the constellation's mean elements to a CCSDS OMM catalogue (one OMM
# message per TLE-defined satellite, with its real NORAD id / COSPAR designator):
cargo run -- scenarios/orbit-sgp4-gps.toml --export-omm gps.omm
# Export the velocity-carrying state to a CCSDS OEM 2.0 ephemeris (GMAT/Orekit/STK):
cargo run -- scenarios/orbit-sgp4-gps.toml --export-oem gps.oemOther CLI modes — lint a scenario, feed real Earth-orientation data, or run a whole suite:
# Lint a scenario without running it (checks the kind + required fields):
cargo run -- --validate scenarios/integrity-raim.toml
# Feed a real IERS Earth-orientation file (finals2000A) for frame precision:
cargo run -- scenarios/orbit-sgp4-gps.toml --eop tests/fixtures/agency/eop/finals2000A_2022001.txt
# Run a SUITE of scenarios into one aggregated, stamped study artifact
# (writes <suite>.study.json + <suite>.study.html next to the manifest):
cargo run -- --study scenarios/quantum-pnt-demonstrator.suite.tomlA suite manifest is a small TOML (Tom's Obvious, Minimal Language) file — a title and a scenarios = [ … ] array of
scenario paths — that the engine runs in turn, folding every result (with its
MODELLED / VALIDATED labels) into one self-describing study artifact. See
scenarios/quantum-pnt-demonstrator.suite.toml.
Interoperability role. Kshana is the performance-simulation layer that sits
alongside the post-processing toolchain, not a replacement for it: feed its RINEX
output into RTKLIB or gLAB for a position solution, and use its SP3 output as a
precise-orbit product for tools like Ginan — Kshana answers what resilience a given
PNT architecture buys before you have real signals, in formats those tools already
ingest (--export-sp3, or export_sp3 = true in an orbit scenario, writes
<scenario>.sp3). The same orbit can be published as standards-track CCSDS OMM
mean elements (--export-omm, or export_omm = true, writes <scenario>.omm) —
one OMM 502.0 KVN (keyword = value notation) message per TLE-defined satellite, carrying each object's real
NORAD (North American Aerospace Defense Command) catalogue number, COSPAR (Committee
on Space Research) international designator, and epoch, for any
OMM-aware consumer instead of a bespoke two-line element set.
Example output (clock holdover — note how the Integrity and Security figures of merit are reported):
scenario 5ba83a232b94 | quantum holdover 6600s p95 1.20e-4ns integrity 1.000 security n/a (no attack) | classical holdover 2610s p95 19.7ns integrity 1.000 security n/a (no attack)
wrote scenarios/clock-holdover.result.json, scenarios/clock-holdover.chart.svg, and scenarios/clock-holdover.report.htmlThe optical clock's 95th-percentile (p95) timing error is 1.20e-4 ns: the summary
prints small values with significant digits rather than rounding them to 0.0.
security reads n/a (no attack) because this scenario configures no attack, so there
is nothing to detect. The JSON result still carries each clock's analytic
spoof-detectability bound in fom.security (0.997 for the optical clock, 0.000 for the
chip-scale atomic clock, whose own noise over the monitoring window exceeds the 20 ns
spec), and its figure_tiers block marks that figure applicable: false. The spoof
scenario kind scores detection against an injected attack. figure_tiers also gives
every reported figure its verification tier — VALIDATED (checked against an external
oracle) or MODELLED — and the verification-matrix row the tier is read from. The orbit
scenario additionally reports a geometry block — fraction of samples with a fix, and
best/median position dilution of precision (PDOP) and position accuracy — alongside the
clock result.
Read these two numbers carefully.
securityis an analytic spoof-detectability bound derived from each clock's stability — it is meaningful only against a configured spoofing scenario and is not a multi-satellite RAIM detector.integrityhere is the filter's self-consistency (fraction of outage samples inside its own k-sigma bound), not an aviation HPL/VPL integrity figure. Seedocs/INTEGRITY.md.For genuine receiver-autonomous integrity, the
integrityscenario kind (scenarios/integrity-raim.toml) runs real snapshot and solution-separation (ARAIM-style) RAIM over the propagated constellation geometry: it computes horizontal/vertical protection levels (HPL/VPL) per epoch and reports the fraction of epochs that meet the configured alert limits, with a Stanford integrity diagram for error-vs-PL (protection level) classification.
Reproducible study artifacts
Four open studies each regenerate a byte-deterministic artifact (fixed seed) from one command — the numbers behind the quantum-vs-classical crossover, RF-impairment optimism-gap, PNT-resilience-scoring, and timing-protection-level studies:
# Quantum-vs-classical resilience crossover map (writes paper/crossover/*.json):
cargo run --release --bin crossover_study -- paper/crossover
# RF-impairment optimism-gap study (13-detector panel, scaling laws, LOO predictor):
cargo run --release --example optimism_study -- paper-artifacts/optimism-study.json
# Framework-aligned PNT-resilience scoring + decision-instability study:
cargo run --release --example resilience_report -- paper-artifacts/resilience-study.json
# Conditional Timing Protection Level, calibrated on a real recorded spoof:
cargo run --release --example tpl_jammertestEach artifact records its engine version, seeds, and a config hash and carries an honest
MODELLED/VALIDATED label. The real-data probes (*_probe) run the same pipeline over
recordings you supply locally; no datasets are shipped in the repo. The RF-impairment
optimism-gap study is written up in the preprint
arXiv:2606.22054, and the conditional timing
protection level (tpl_jammertest above) in the preprint
arXiv:2606.24210 (see Citing).
The published lunar-PNT studies (arXiv:2607.06212
surface-beacon DOP and arXiv:2607.02566 VLBI
observability) have their geometry, dilution-of-precision, real-time frame /
Earth-orientation-parameter (EOP) prediction, distant-retrograde-orbit and RF-ranging
claims independently cross-checked in
tests/validate_p*.rs against separate oracles (scipy.special.j1, an independent NumPy
(HᵀH)⁻¹ DOP solve, a NumPy re-parse of the same IERS finals2000A rows, and the
NASA/JPL Three-Body Periodic Orbit Database). These are additional regression checks over
the modelled lunar suite; they do not change the machine-checked matrix count.
Python
An optional Python extension (PyO3, abi3 — the stable Python binary interface) wraps the same engine. Build and install it with maturin:
pip install maturin
maturin develop --features python # or: maturin build --features pythonimport json, kshana
result = json.loads(kshana.run(open("scenarios/clock-holdover.toml").read()))
print(result["quantum"]["fom"]["integrity"])
# json, svg, and a one-line summary at once:
result_json, chart_svg, summary = kshana.run_full(open("scenarios/orbit-gnss-challenged.toml").read())
print(kshana.version(), summary)Beyond run / run_full / version, the module exposes run_typed (a structured
result object), validate_toml (lint → list of error strings), list_kinds /
scenario_kinds (the dispatchable kinds), and error_kind (the KshanaError tag for
a rejected scenario) — see docs/PYTHON_API.md.
Wheels are built for Linux, macOS, and Windows by the wheels workflow on each
release tag.
WebAssembly
The engine also runs in the browser via wasm-pack:
wasm-pack build --target web -- --features wasmimport init, { run, chart_svg, version } from "./pkg/kshana.js";
await init();
const result = JSON.parse(run(tomlText));
console.log(version(), result.classical.fom.timing_p95_ns);The module also exports summary (the one-line result string), table_csv (the
scenario's CSV (comma-separated values) table, or undefined for kinds that publish none), run_all (all four
from a single engine run, as a JSON object string — each of the others runs the scenario
afresh), list_kinds /
error_kind (introspection), and encode_permalink / decode_permalink — the
shareable-URL (URL: web address) codec the playground uses to round-trip a whole scenario through the
address-bar fragment.
AI agents (MCP)
Kshana ships an MCP server, kshana-mcp,
so AI assistants and agents can run the actual engine instead of guessing the
math — usable from Cursor, JetBrains AI Assistant / Junie, and any MCP-compatible
assistant or agent. It exposes seven tools — run_scenario, list_scenario_kinds,
validate_scenario, export_sp3, export_omm, export_oem and export_table_csv
(each a thin wrapper over kshana::api).
cargo install kshana-mcp # crates.io
docker run --rm -i ghcr.io/ashfordeou/kshana-mcp # or OCI, no Rust toolchainThen register kshana-mcp in your client's mcpServers config. In Claude Code it's one
command — claude mcp add kshana -- kshana-mcp — or install the plugin:
/plugin marketplace add ashfordeOU/kshana then /plugin install kshana@ashforde.
Copy-paste config for Claude Code, Claude Desktop, Codex, Cursor, VS Code, Windsurf and
JetBrains is in docs/integrations.md (per-client snippets also in
mcp/kshana-mcp/README.md). The
server is a standalone, workspace-excluded crate (the rmcp SDK — software development kit — is edition 2024), so it
never affects the lean published kshana crate or its build.
In a JetBrains IDE you can also install the
Kshana — PNT simulator
plugin from the JetBrains Marketplace (or Settings → Plugins → Marketplace → search
"Kshana") to run scenarios from a right-click — see ide/jetbrains/.
Scenario format
Scenarios are declarative TOML. A top-level kind selects the pack — fifty in
all (clock is the default if omitted): inertial, timetransfer, hybrid, hybrid-ukf, fusion,
gnss-ins, orbit, ephemeris, gnss-sim, integrity, lunar-integrity, lunar-time-offset, spoof,
spoof-detect, jamming, sweep, sweep-nd, gravity-map, terrain-nav, terrain-slam,
combined-altpnt, pvt, mars-pnt, impairment-eval (AI/ML RF-impairment detection
evaluation testbed — labelled synthetic corpus + detector-agnostic ROC/AUC harness +
in/out-of-distribution optimism gap), quantum-trade (quantum-vs-classical PNT
trade with measured-ADEV ingestion + GNSS-denied resilience envelope; MODELLED),
space-weather (solar/geomagnetic indices + Jacchia-71 exospheric temperature +
activity-driven thermospheric density over the static atmosphere; MODELLED),
oem-interop (CCSDS OEM import/round-trip bridge for GMAT/Orekit/STK ephemerides;
MODELLED), the mission-analysis trio launch-window (two-body launch azimuth /
plane-change / opportunities), reentry (Allen-Eggers ballistic re-entry corridor),
eo-coverage (EO swath / GSD / access / revisit geometry), space-packet (CCSDS
133.0 TM/TC — telemetry/telecommand — Space Packet framing — exact bit layout, round-trip verified), and
attitude-budget (3-DOF gravity-gradient torque + RSS pointing error budget),
passes (ground-station rise/set pass prediction — AOS/TCA/LOS, max elevation,
access), and link-budget (one-way CCSDS/DSN link equation — FSPL / Eb·N₀ /
margin / closure); telecom-timing (holdover time error, MTIE and TDEV checked
against ITU-T masks); the lunar-PNT suite lunar-vlbi, lunar-joint-od-clock,
lunar-frame-realisation, moonlight-service-volume, lunar-differential-pnt,
lunar-interop-export; the Quantum-Enabled PNT demonstrator
quantum-time-transfer, quantum-gnss-free-nav, quantum-anomaly-detect; and the
signal-security, cislunar & layered-resilience research kinds lunar-attack-surface,
realtime-frame-eop, lunar-time-budget, hybrid-optical-rf, cislunar-observability,
conflict-resilience — the mission-analysis trio and these later kinds all MODELLED
(each with a validated closed-form core; see the matrix).
Common fields: seed, a [time] grid, a [gnss] availability timeline (the outage
driver), and per-sensor blocks with provenance strings citing the source of every
figure. Example (clock):
seed = 42
threshold_ns = 20.0
[time]
step_s = 10.0
duration_s = 7200.0
[gnss]
windows = [
{ t0 = 0.0, t1 = 600.0, state = "nominal" }, # 10 min GNSS sync
{ t0 = 600.0, t1 = 7200.0, state = "denied" }, # ~1.8 h outage
]
[clock_quantum]
id = "optical-sr-lattice"
provenance = "Strontium optical lattice clock, space-oriented goal sigma_y(1s)=1e-15 (arXiv:1503.08457)"
y0 = 5.0e-17
q_wf = 1.0e-30 # white FM: q_wf = sigma_y(1s)^2
q_rw = 0.0 # random-walk FM
drift = 0.0 # linear aging (per second)
[clock_classical]
id = "csac-sa45s"
provenance = "Microchip SA65 / SA.45s CSAC datasheet sigma_y(1s)=3e-10"
y0 = 5.0e-10
q_wf = 9.0e-20
q_rw = 0.0
drift = 0.0Optional fields (off when absent): a clock may add flicker_floor (1/f FM — frequency
modulation — Allan floor); an inertial sensor may add gyro_bias and q_arw (gyro bias and angular
random walk), and bias_instability and q_aa (the Allan bias-instability floor and
acceleration random walk) — together a single-axis (1-DOF) accelerometer error
budget (VRW/ARW — velocity/angular random walk — and bias-instability). This is the error budget the shipped
inertial scenario pack runs. Separately, the library now carries a verified
3-axis strapdown navigator (src/inertial/{attitude,mechanization,imu_errors}.rs):
quaternion attitude with coning/sculling compensation, a full NED mechanization
(Earth-rate and transport-rate terms, WGS-84 Somigliana gravity), and a
deterministic IMU error model in which scale-factor, misalignment,
g-sensitivity, quantization, and rate-ramp are modelled (IEEE Std 952-1997, the IEEE
gyro specification and test-procedure standard, §A.2; Groves 2013 §4.3). That 3-axis path is now wired into a runnable
loosely-coupled GNSS/INS pack (kind = "gnss-ins"): a 15-state error-state EKF
disciplines the strapdown solution against noisy fixes while GNSS is up, then
coasts through the outage, reporting the fused horizontal error against the
open-loop free-INS coast. A tightly-coupled pseudorange update is also
available (it forms the innovation in the range domain, so it keeps correcting
with fewer than four satellites). A
clock-holdover scenario may add runs (> 1) to run a Monte Carlo ensemble — each
figure of merit is then reported as a mean with a 5th–95th-percentile spread and the
chart shades the error confidence band (see scenarios/clock-ensemble.toml).
A fusion scenario (same blocks as hybrid) runs two independent Kalman estimators
— one for the clock state, one for the position state — disciplined by GNSS and aided by
optical time transfer, and reports a combined holdover FoM. The two blocks share no
cross-covariance: this is a stacked pair of error budgets, not a true coupled
clock+position joint filter (cross-block covariance is a roadmap item). See
scenarios/fusion-pnt.toml.
A spoof scenario injects a time-spoof — one of four [attack.shape] kinds
(linear_ramp, step_jump, meaconing, replay; a bare rate_ns_per_s is still
accepted as a linear ramp) — and runs each clock's spoof detector. The detector is a
two-sided χ²₁ energy / Neyman–Pearson test on the clock-aided monitor statistic:
the threshold is set from a target false-alarm budget target_pfa, and the
missed-detection probability P_md is reported both closed-form and by
Monte-Carlo (mc_runs trials per hypothesis — the two agree to a few ×1/√N). The
Security figure of merit is 1 − P_md at the operationally-harmful (spec)
magnitude, so a quiet clock that catches a spec-sized spoof scores ≈ 1 and a noisy
one that often misses it scores lower (see scenarios/spoof-attack.toml,
scenarios/spoof-meaconing.toml).
A gnss-sim scenario is a measurement-domain simulation: for each visible
satellite it synthesises the pseudorange ρ = geometric range + c·δt_rx − c·δt_sv + I + T + noise + multipath and the L1 Doppler, with the Klobuchar single-frequency
ionosphere ([iono], IS-GPS-200 §20.3.3.5.2.5) and the Saastamoinen zenith
troposphere projected by the Niell (1996) mapping function ([tropo]). The
residuals feed snapshot RAIM for per-epoch HPL/VPL, and every satellite's
pseudorange, Doppler, C/N₀, and iono/tropo corrections are emitted in the JSON
gnss_measurements array. It is a forward simulator (it generates measurements from
a known truth), not a receiver/solver — a zero-noise run reproduces geometry plus the
corrections to sub-millimetre (see scenarios/gnss-sim-raim.toml).
A jamming scenario models RF interference as a link budget: a [jammer]
(ECEF position, transmit power_dbw, type) raises the jammer-to-signal ratio at a
[receiver] watching a Walker [constellation]. From the geometry (free-space
path loss and the per-direction receive-antenna gain) it computes each satellite's
J/S, the effective C/N₀ via the standard anti-jam equation (despreading
processing gain × the spectral-separation factor Q; Kaplan & Hegarty §9.4), and
flags loss of lock below a configurable tracking threshold — reporting an
availability_under_jamming figure of merit. A 10 W broadband jammer at 1 km
denies the receiver entirely (J/S ≈ 72 dB); the same jammer at 100 km only
degrades the links (see scenarios/jamming-demo.toml).
A sweep scenario runs a trade study: it varies one parameter (threshold_ns,
duration_s, quantum_q_wf, or classical_q_wf) from start to stop over steps
points on a lin or log scale, records a metric (e.g. holdover_s) for both
clocks, and charts the two curves. The base scenario goes under [base] (see
scenarios/sweep-clock-stability.toml).
A sweep-nd scenario generalises this to any pack and any number of axes: it
varies dotted TOML keys of a [base] scenario (of any kind) over the Cartesian
product of [[axes]], re-runs each grid node, and records metrics given as
dotted JSON paths into the result (e.g. classical.fom.holdover_s). It works for
every pack because it operates at the TOML/result boundary; native runs evaluate
the grid in parallel (no extra dependency, wasm falls back to sequential) and the
output is deterministic and row-major (see scenarios/sweep-nd-inertial.toml).
An orbit scenario derives the [gnss] timeline from geometry instead of authoring
it — give a [user] orbit, a [constellation], an elevation mask_deg, and the two
clock blocks. It also reports position accuracy from the satellite geometry; the
optional sigma_uere_m (1-sigma user-equivalent range error, default 1 m) scales the
position dilution of precision into a position sigma. The user orbit may be made
eccentric with eccentricity and argp_deg, and j2 = true adds Earth-oblateness
secular drift (see scenarios/orbit-molniya.toml). The constellation can instead be a
real one: give [constellation] a tle block of two-line element sets and the
satellites are parsed from it (see scenarios/orbit-real-tle.toml). Add one or more
[[constellations]] blocks for multi-GNSS (e.g. GPS + Galileo; see
scenarios/orbit-multignss.toml):
kind = "orbit"
seed = 7
threshold_ns = 5.0
mask_deg = 10.0
sigma_uere_m = 1.0 # optional; position sigma = position-DOP * this
[time]
step_s = 60.0
duration_s = 86400.0
[user] # spacecraft (altitude in km, angles in deg)
altitude_km = 8000.0
inclination_deg = 0.0
[constellation] # Walker-delta GNSS (GPS-like)
altitude_km = 20180.0
inclination_deg = 55.0
planes = 6
sats_per_plane = 4
phasing_f = 1.0
[clock_quantum] # ... as above
[clock_classical] # ... as aboveThe GPS-denied alt-PNT kinds navigate with no GNSS at all, matching a measured field
sequence against a map through a particle filter. A gravity-map scenario flies a track
through a spherical-harmonic gravity-anomaly field and recovers it from a cold-atom
gravimeter's reading (scenarios/gps-denied-gravity-nav.toml); a terrain-nav scenario
does the same against an SRTM elevation DEM (TERCOM/SITAN, scenarios/terrain-nav.toml);
and a combined-altpnt scenario fuses gravity + IGRF magnetic + terrain in one filter
(scenarios/combined-altpnt.toml).
A lunar-integrity scenario evaluates cislunar PNT: it runs a lunar south-pole
ARAIM protection-level pass against a LunaNet/LNIS relay set and honestly reports the
integrity gap — a ~30 m lunar σ_URE drives the protection level well above a 50 m alert
limit, so the service is unavailable under aviation-style integrity rules
(scenarios/lunanet-araim.toml).
A lunar-time-offset scenario reports the relativistic Earth–Moon clock rate — the
basis of a Lunar Coordinate Time scale (LTC/TCL). A first-principles post-Newtonian
identity sums the self-potential difference (IAU L_G geoid potential minus the Moon's
surface self-potential) and the Moon's kinetic (second-order Doppler) term to a secular
rate of ≈ 57 µs/day, reported with the published 56–59 µs/day band; it also gives the
accumulated LTC−TT offset over a horizon and an inverse-variance ensemble (a lunar
paper-clock). MODELLED — the headline figure is reference-dependent (Earth geoid
vs lunar selenoid, averaging window), which is why a band, not a single certified
number, is reported (scenarios/lunar-time-offset.toml).
See scenarios/ for at least one worked example of every kind (62 kinds, 76 scenario
.toml files + 1 suite manifest — several kinds ship more than one example). Not every
kind has a file named after it: lunar-integrity → scenarios/lunanet-araim.toml and
gravity-map → scenarios/gps-denied-gravity-nav.toml are two of several such.
List the dispatchable kinds at any time with cargo run -- --validate <file>
errors, the Python list_kinds(), or the MCP list_scenario_kinds tool.
Output
The result artifact is versioned, self-describing JSON: per-step time series, the
scored figures of merit, the active model specs (with provenance), the seed, a
scenario hash — so any chart can be reproduced from the file — and, for each clock,
an adev_curve ([{tau_s, adev, n_samples, noise, edf, ci_lo, ci_hi}]): the overlapping
Allan deviation across octave-spaced averaging times — the standard way to read a clock's
stability — now with a noise-type-specific 95% confidence band per point (the record's
power-law type is identified from its modified-Allan slope, and the χ² interval uses the
matching NIST SP 1065 effective degrees of freedom). The browser playground renders it as a
log-log "Clock stability (ADEV)" chart. (MDEV, TDEV, and HDEV are available as library
estimators; the exported result curve is the overlapping ADEV.) Every field, with units and a
source pointer, is documented in docs/SCHEMA.md.
Every chart is self-describing. The browser playground, the CLI's *.chart.svg
export, and the HTML (HyperText Markup Language) scorecard all stamp each chart image with a footer reading
Kshana v<version> · scenario <hash> · kshana.dev. The scenario <hash> is the first
12 hex characters of the run's scenario hash — a SHA-256 (the 256-bit Secure Hash Algorithm) digest over the canonical scenario
definition (seed, thresholds, model parameters, GNSS windows, …); the integrity and lunar
reports, which carry no hash of their own, fall back to a SHA-256 of the scenario source.
It is the same fingerprint shown in the one-line summary and the result JSON, so a
saved or pasted chart always carries its version, the exact scenario that produced it (for
bit-for-bit reproduction), and the source — change any input and the hash changes.
The figures of merit follow the standard operational PNT figures of merit:
Figure of merit | How Kshana computes it |
Timing Performance (clock/orbit packs) | clock-phase error RMS + 95th-percentile over the outage, in nanoseconds ( |
Positioning Performance (inertial/hybrid packs) | 1-DOF position-error RMS + 95th-percentile over the outage, in metres ( |
Autonomy | holdover duration — time in-spec after GNSS loss (grid-quantised: a lower bound) |
Resilience | error-growth slope during the outage |
Availability | fraction of the run with an in-spec solution |
Integrity | filter self-consistency — fraction of outage samples whose error stays inside the Kalman filter's own k-sigma bound. Not an aviation HPL/VPL/RAIM integrity figure (see |
Security | analytic spoof-detectability bound from clock stability — how small/slow a time-spoof a single-clock consistency monitor could flag. Meaningful only with a configured attack; not a multi-satellite RAIM detector |
New to these terms? Each is defined in plain language in the glossary.
Architecture
One engine, many front doors. A single Rust core (kshana) runs every scenario,
reached through a CLI, a Python extension, an in-browser WebAssembly module, an MCP
server for AI agents, and a JetBrains IDE plugin — all converging on one
api::run_toml dispatch. Inside, the sensor packs plug into a common error-model
interface; alongside them sit a reference-frame layer (IAU 2006/2000A
precession–nutation and the CIO-based GCRS↔ITRS reduction), an astrodynamics/numerical
layer (analytic SGP4/SDP4 and a numerical Cowell propagator with its
EGM2008/perturbation force model, maneuver design, and orbit determination), an
integrity/GNSS layer (RAIM/ARAIM, SBAS, the measurement domain, jamming, cislunar),
a fusion / alt-PNT layer (the GNSS/INS estimators and the gravity/terrain/magnetic
map-matchers), a deep-space & lunar layer (radiometric Mars-PNT and the MODELLED
lunar PNT suite — LTC time, VLBI, joint OD+clock, frame realisation, service-volume,
differential PNT, interop), a mission-analysis layer (launch / re-entry / coverage /
pointing / pass / link budgets and the space-weather environment), and the open
resilience & AI/ML study layer (RPCF resilience scoring, the RF-impairment optimism
gap, and the quantum-enabled PNT demonstrator) whose reproducible artifacts ride the
validated kernels.
Two standalone, workspace-excluded crates sit beside the core — mcp/kshana-mcp
(the MCP server, built on the edition-2024 rmcp SDK) and xval/anise-frames (the
ANISE/SPICE frame cross-check, which pulls MPL-2.0 (Mozilla Public License 2.0) deps) — kept out of the published
crate's dependency graph, Cargo.lock, license gate, and MSRV (minimum supported Rust version) build by the root
Cargo.toml exclude list. The JetBrains plugin (ide/jetbrains) is a separate Kotlin
project. See docs/ARCHITECTURE.md for the full set of diagrams.
flowchart LR
SCN["Scenario (.toml)<br/>seed · GNSS timeline · sensor params"] --> ENG
subgraph ENG["Engine (per step)"]
direction TB
M["Error model<br/>step(): evolve noise state"] --> E["Estimator<br/>GNSS-disciplined holdover"]
E --> F["FoM scoring<br/>vs the 7 figures of merit"]
end
ENG --> OUT["result.json + chart.svg<br/>(reproducible: scenario+seed+version)"]flowchart TD
cli["CLI · Python · WebAssembly<br/>MCP server · JetBrains plugin"] --> api["api — run_toml<br/>typed dispatch over 62 kinds"]
subgraph shared["Shared core"]
types["types · scenario<br/>GNSS timeline"]
allan["allan — ADEV/MDEV/TDEV/HDEV"]
end
subgraph frames["Time and reference frames"]
ts["timescales · jd2<br/>UTC/TAI/TT/UT1"]
cio["precession · nutation · cio<br/>GCRS to ITRS, SOFA-anchored"]
end
subgraph packs["Sensor packs"]
p1["clock — models · estimator<br/>kalman · security"]
p2["inertial — strapdown INS<br/>quantum-CAI"]
p3["timetransfer — optical/RF<br/>TWSTFT/PPP"]
p4["hybrid — fused PNT suite"]
end
subgraph astro["Astrodynamics and numerical"]
orbit["orbit · walker · sgp4 · tle<br/>geometry to GNSS and DOP"]
prop["propagator · forces<br/>gravity_sh · integrator"]
odm["orbit_determination · maneuver<br/>precise_od — full-force POD"]
end
subgraph intg["Integrity and GNSS"]
raim["raim · sbas — RAIM/ARAIM<br/>HPL/VPL · DO-229E"]
gsim["gnss_sim · ionex · pvt<br/>measurements + SPP fix"]
jam["jamming · navsignal<br/>J/S to C/N0 · anti-jam Q"]
end
subgraph spf["Spoof detection"]
spoof["spoof — time-spoof attack"]
spm["spoof_monitors — AGC power · SQM"]
det["detection — test-stat theory"]
spd["spoof_detect — runnable scenario"]
end
subgraph fnav["Fusion and alt-PNT"]
fus["fusion — EKF · UKF<br/>17-state · coupled"]
alt["gravimeter · mapmatch<br/>particle_filter · altpnt · igrf"]
end
subgraph deep["Deep-space · Mars · Lunar"]
dsr["radiometric · ccsds_tdm<br/>deepspace_od · mars_pnt"]
lun["lunar suite — cislunar ARAIM<br/>LTC time · VLBI · interop"]
end
subgraph resil["Resilience studies and AI/ML"]
tpl["tpl · resilience<br/>conditional TPL + RPCF"]
opt["impairment_* · eval_stats<br/>sdr · realdata · quantum_*"]
end
VER["verification<br/>machine-checked matrix<br/>SINGLE SOURCE OF TRUTH"]
api --> packs
api --> astro
api --> intg
api --> spf
api --> fnav
api --> deep
api --> resil
packs --> shared
astro --> frames
odm --> prop
spoof --> p1
spm --> det
spd --> spm
fus --> p2
alt --> p2
gsim -. uses .-> raim
VER -. cross-refs .-> packs
VER -. cross-refs .-> intg
VER -. cross-refs .-> spf
VER -. cross-refs .-> astroComponents & distribution. The core crate ships through the Rust, Python, and
JavaScript ecosystems; the MCP server and IDE plugin reach AI agents and JetBrains IDEs.
Each vX.Y.Z tag republishes every channel automatically (see
Versioning & releases).
flowchart LR
subgraph repo["One repository"]
core["kshana core<br/>library and CLI"]
mcp["mcp/kshana-mcp<br/>MCP server (excluded crate)"]
ide["ide/jetbrains<br/>Kotlin IDE plugin"]
subgraph xval["xval cross-checks (excluded)"]
anise["anise-frames · lunar-od<br/>mars-od · service-geometry<br/>Rust ANISE / SPICE DE440"]
orekit["orekit-passes<br/>Java Orekit"]
end
end
core --> crates["crates.io"]
core --> pypi["PyPI — wheels"]
core --> npm["npm — WebAssembly"]
core --> rel["GitHub Releases<br/>binaries · SBOM · SLSA<br/>validation summary"]
core --> pages["kshana.dev<br/>GitHub Pages playground"]
core -. archived .-> zen["Zenodo DOI"]
mcp --> crates
mcp --> ghcr["ghcr.io — OCI image"]
mcp --> reg["official MCP registry"]
ide --> jb["JetBrains Marketplace"]
anise -. validates .-> core
orekit -. validates .-> coreRepository layout
kshana/
├── src/ # the kshana core crate (library + CLI)
│ ├── api.rs · main.rs · lib.rs # typed dispatch (62 kinds) + CLI + crate root
│ ├── python.rs · wasm.rs # optional PyO3 / wasm-bindgen bindings
│ ├── types.rs · scenario.rs · allan.rs # shared core (time grid, GNSS timeline, Allan)
│ │
│ ├── models.rs · estimator.rs · kalman.rs # Pack 1 — clock holdover + integrity
│ ├── security.rs · detection.rs · spoof.rs · spoof_monitors.rs # spoof detection
│ ├── filter_health.rs · fom.rs · fom_label.rs · report.rs · chart.rs · run.rs # health · FoM scoring + labelling · output
│ ├── suite.rs · study.rs # scenario suites + aggregated multi-scenario study artifacts (`--study`)
│ ├── inertial/ # Pack 2 — strapdown INS (attitude · mechanization · imu_errors · quantum_imu)
│ ├── timetransfer.rs · timetransfer_adv.rs · timegeo.rs # Pack 3 — TWSTFT/CV/PPP/optical, Sagnac
│ ├── hybrid.rs · ensemble.rs · sweep.rs # Pack 4 — fused PNT, Monte-Carlo, trade sweeps
│ │
│ ├── timescales.rs · jd2.rs · ephem.rs # time systems, two-part JD, Sun/Moon ephemeris
│ ├── precession.rs · nutation.rs · cio.rs # IAU 2006/2000A precession-nutation + CIO GCRS↔ITRS
│ ├── frames.rs · *_data.rs # TEME↔ECEF + generated nutation/CIO/EGM2008/IGRF tables
│ │
│ ├── orbit.rs · sgp4.rs · tle.rs · walker.rs # geometry, SGP4/SDP4, TLE, Walker design
│ ├── propagator.rs · forces.rs · gravity_sh.rs · integrator.rs # Cowell + perturbations (EGM2008 d/o70, GR) + RK4/DOPRI
│ ├── maneuver.rs · batch_ls.rs · orbit_determination.rs # burns/Lambert/porkchop, Gauss-Newton, OD
│ ├── cr3bp.rs · lunar.rs · lunar_frame.rs · lunar_od.rs # Earth–Moon CR3BP + halo/NRHO STM corrector, cislunar/LunaNet ARAIM, MCI↔MCMF, lunar OD
│ ├── lunar_time.rs · lunar_vlbi.rs · lunar_combination.rs · lunar_frame_realise.rs · lunar_service.rs · lunar_dpnt.rs · lunar_interop.rs # MODELLED lunar PNT suite — LTC time · geodetic VLBI · joint OD+clock · frame realisation · Moonlight service-volume · differential PNT · LunaNet/IOAG interop export
│ ├── body.rs · mars_frame.rs · ephem_provider.rs · radiometric.rs · ccsds_tdm.rs # deep-space: multi-body · Mars frame · ephemeris seam · radiometric obs + CCSDS-TDM
│ ├── deepspace_od.rs · clock_state.rs · mars_atmos.rs · mars_pnt.rs · linkbudget.rs · gse_sim.rs # SRIF OD · onboard clock · Mars drag · relay-PNT · link budget · GSE sim
│ │
│ ├── fusion/ # GNSS/INS — EKF · UKF · tightly_coupled(17) · coupled · closed_loop
│ ├── raim.rs · sbas.rs # RAIM/ARAIM HPL/VPL, SBAS DO-229E PLs + L1/L5 iono-free
│ ├── gnss_sim.rs · ionex.rs · pvt.rs · jamming.rs # measurement domain · ionosphere maps · single-point positioning · jamming
│ ├── navsignal.rs # nav-signal PSD (BPSK-R/BOC) · spectral-separation → anti-jam Q · DLL code-tracking jitter · multipath envelope
│ ├── gravimeter.rs · igrf.rs · mapmatch.rs · particle_filter.rs · altpnt/ # gravity/magnetic/terrain alt-PNT
│ ├── rinex.rs · rinex_obs.rs · glonass.rs · sp3.rs · oem.rs · omm.rs · permalink.rs # interop formats
│ ├── launch.rs · reentry.rs · eo_payload.rs · attitude_budget.rs · passes.rs · space_packet.rs # mission-analysis budgets + CCSDS Space Packet
│ ├── space_weather.rs · holdover.rs · tpl.rs # space-weather environment · GNSS-denied clock-holdover calculator · conditional Timing Protection Level (under spoofing)
│ ├── resilience/ # framework-aligned PNT-resilience scoring + decision-instability study (RPCF · Dirichlet · Kendall-τ · diversity collapse · assurance report)
│ ├── impairment_eval.rs · impairment_study.rs · impairment_ml.rs · eval_stats.rs # AI/ML RF-impairment eval testbed · optimism-gap study · LR/MLP detectors · bootstrap/DeLong/Spearman stats
│ ├── sdr.rs · realdata/ # software-defined-receiver front end (IQ/IF → E/P/L taps → SQM) + real-data ingest adapters (RINEX · UBX · GnssLogger · JammerTest · Yunnan · SatGrid)
│ ├── crossover.rs · quantum_trade.rs · frugal.rs · integrity_impact.rs # quantum-vs-classical crossover map · PNT trade · cost-per-coverage ROI · integrity impact
│ ├── quantum_devices.rs · quantum_faults.rs · quantum_nav_od.rs · qtrade.rs · timetransfer_chain.rs · representativeness.rs # Quantum-Enabled PNT demonstrator — device error models · fault catalogue · GNSS-free quantum OD · unified trade harness · quantum time-transfer chain · representativeness / gaps-to-flight ledger
│ ├── interchange.rs · verification.rs # KIF artifact envelope · machine-checked verification matrix
│ └── bin/crossover_study.rs · bin/validation_report.rs # crossover-study artifact generator · release validation-summary HTML
│
├── mcp/kshana-mcp/ # standalone, workspace-EXCLUDED crate — the MCP server (+ Dockerfile, server.json)
├── ide/jetbrains/ # standalone Kotlin/Gradle IntelliJ-Platform plugin
├── xval/ # standalone, workspace-EXCLUDED external cross-checks: anise-{frames,lunar-od,mars-od,service-geometry} (Rust ANISE/SPICE DE440) + orekit-passes (Java Orekit)
│
├── examples/ # reproducible study generators: tpl_jammertest · resilience_report · optimism_study + real-data probes (jammertest_probe · yunnan_probe · satgrid_probe · texbat_probe · ingest_realdata)
├── paper-artifacts/ # byte-deterministic study artifacts, regenerable from examples/ (optimism-study.json · resilience-study.json); raw datasets stay out
├── scenarios/ # one cited .toml per kind + geometry-driven + GPS-denied
├── scripts/ # reproducibility + repo-hygiene + SBOM guards
├── docs/ # CONCEPTS, ARCHITECTURE, CAPABILITY, VALIDATION, PROVENANCE, GLOSSARY, …
├── web/ # the WebAssembly playground + kshana.dev site
├── tools/ # table generators (EGM2008 · IGRF · nutation · CIO) + fetch_tles.sh
├── .github/workflows/ # ci · release · publish · wheels · pages · mcp-publish · jetbrains-plugin · frame-xval
├── pyproject.toml # Python packaging (maturin)
├── CHANGELOG.md # Keep a Changelog + SemVer
└── CITATION.cff · ROADMAP.md · CONTRIBUTING.md · SECURITY.mdDocumentation
Document | For whom | What's in it |
everyone, start here | what Kshana does and why, from zero to the physics | |
everyone | run the engine in your browser (WebAssembly); build & deploy notes | |
everyone | plain-language definitions of every term | |
developers / reviewers | module map, engine pipeline, dispatch, and diagrams | |
reviewers / citers | what is | |
reviewers / citers | the machine-checked evidence ledger — every capability row with its status, module, test and external oracle, generated from | |
reviewers | why each Modelled row has no external oracle, stated row by row | |
reviewers / citers | every sensor parameter, model, and dataset traced to its published source, in one citable table | |
reviewers / packagers | determinism guarantees, golden-pinning, SBOM (software bill of materials), build provenance | |
packagers | the abi3 Python wheel matrix — which platform tag | |
evaluators | where Kshana sits vs RTKLIB/gLAB (complementary), and the zero-install browser tier | |
reviewers / citers / evaluators | the full extended research paper — architecture, per-domain models, validation, case studies, and limitations — plus the concise JOSS (Journal of Open Source Software) submission | |
reviewers / citers | agreement with the AIAA 2006-6753 reference (666 states, ~4 mm) and a head-to-head against the independent | |
reviewers / citers | the full-force engine ( | |
users | driving scenarios from real Celestrak / Space-Track constellation TLEs (vs the bundled synthetic Walker set) | |
evaluators | what the | |
reviewers / integrators | the open MHSS ARAIM protection-level implementation — the | |
reviewers | the cold-atom-interferometer physics layer, and where coefficients are still looked up | |
evaluators | DO-229E / DO-316 algorithm scope, and what is not a conformance claim | |
integrators | the GNSS / flight-dynamics / agency interchange formats Kshana reads and writes (RINEX, SP3, CCSDS OEM/OMM/TDM/Space-Packet, …) | |
users / integrators | every dispatchable kind with its required and optional TOML fields — generated from | |
integrators | every field of the result JSON, with units and a source pointer | |
Python users | the PyO3 binding surface — calling the engine, the scenario/result types, and examples | |
reviewers | the overclaim-closure ledger + the CI guard ( | |
everyone | the phased roadmap — what has shipped and what is next | |
agents / IDE users | run Kshana from an AI assistant or a JetBrains IDE | |
everyone | released history (Keep a Changelog + SemVer, Semantic Versioning) | |
contributors | build, guards, test/citation discipline, DCO (Developer Certificate of Origin) | |
contributors / community | how Kshana is governed — who decides, how, and the open/closed boundary | |
community | expected conduct (Contributor Covenant) | |
reporters | how to report a vulnerability; dual-use note |
Validation, reproducibility & honesty
Every noise term is calibrated to a published, cited figure and validated against the standard relation (Allan deviation for clocks; Groves' dead-reckoning error growth for inertial; the timing→ranging conversion for time transfer). Status per term is tracked in
docs/VALIDATION.mdasvalidatedornot modeled— nothing is presented as validated that is not.Reproducible by construction:
scenario + seed + engine version → identical bits.scripts/check-reproducible.shenforces it; quantum and classical runs use independent seeds so their noise is uncorrelated.Maturity is stated honestly: optical-clock and optical-link figures are targets / ground-demonstrator results, not flown.
Validation at a glance
Every row is enforced by a named test in CI. This table is a curated highlight;
the full machine-checked matrix is 171 rows — 65 VALIDATED, 102 MODELLED, 4 PARTNER
(src/verification.rs), with the complete evidence (and what is honestly not yet
validated) in docs/VALIDATION.md and the per-release
kshana-validation-summary.html
artifact (generated by cargo run --bin validation_report, SLSA-attested — Supply-chain
Levels for Software Artifacts).
The Status column states the kind of evidence, matching the validation ladder above: VALIDATED = checked against an independent external oracle (real data, an independent library, or published reference vectors); MODELLED = checked against analytic truth or simulation self-consistency (no independent external dataset). VALIDATED describes the method of checking, not a pass/fail — an honest miss against real data (the LRO — Lunar Reconnaissance Orbiter — row) is still VALIDATED. CI rows are process guards, not figures of merit. A few real-data islands (the measured caesium clock, Stable32 PHASE.DAT, and the OPS-SAT/ICGEM checks where the raw inputs carry no redistribution licence) are data-gated: the test prints a skip notice and stays green when the input is absent, and the public reference numbers are committed under tests/fixtures/. Reproduce the raw inputs with the matching scripts/fetch_*.sh.
Status | Capability | Agreement | Reference / oracle |
VALIDATED | SGP4/SDP4 propagation | 666/666 vectors, worst 4.12 mm | AIAA 2006-6753 (Vallado |
VALIDATED | Reference frames — IAU 2000A/B nutation, IAU 2006/2000A CIO chain, ERA | bit-for-bit (X,Y to 1e-14, s to 1e-18, ERA to 1e-12) | ERFA/SOFA |
VALIDATED | GCRS→ITRS vs an independent SPICE engine | max 0.028″ → ≤ 0.86 m ground, ≤ 3.6 m GNSS orbit | ANISE (pure-Rust NAIF/SPICE), same IERS |
MODELLED | EGM2008 geopotential (degree/order 70) | acceleration = ∇V to < 1e-6; zonal collapse to validated J2 | NGA EGM2008 coefficients + analytic ∇V identity |
VALIDATED | Gravity-functional synthesis (gravity-aided / GNSS-free nav map) | GRS80 Somigliana + γ_e/γ_p to 3.5e-12; real EGM2008 disturbance map physical (RMS ≈ 26 mGal, d/o 70) | GRS80 (Moritz 1980, IAG — International Association of Geodesy) Somigliana normal gravity + real ICGEM EGM2008 ( |
VALIDATED | Allan estimators (ADEV/MDEV/TDEV/HDEV) + confidence bands | reproduce reference deviations; χ² bands match | NIST SP 1065 (Riley), 1000-point Table 31/32 |
VALIDATED | Allan estimators on a real measured caesium clock | OADEV/OHDEV to 1e-3 (observed ≤ 3e-5), 16 averaging factors | Stable32 on a real 5071A Cs vs H-maser, 556,990 pts ( |
VALIDATED | Allan estimators on the canonical Stable32 PHASE.DAT | OADEV/MDEV/TDEV to 1e-3 (observed ≤ 5e-5), 139 averaging factors | Stable32 reference deviations for PHASE.DAT ( |
MODELLED | IMU error model — ARW / VRW / bias-instability | recovered to < 5 % (bias-instability < 15 %) | Analog Devices ADIS16465 datasheet; NaveGo reference profile |
VALIDATED | Numerical Cowell propagator + force model (conservative tiers) | worst position error 0.08 m over 24 h, 275 epochs (LEO + GTO) | Orekit 12.2 |
MODELLED | Cowell drag tier + absolute Sun/Moon-ephemeris & density inputs | drag tier characterised ≈ 333 m / 24 h; unperturbed matches universal-variable Kepler sub-m, energy/momentum ~1e-9 | built-in low-precision ephemeris + analytic Kepler |
MODELLED | Lambert · Tsiolkovsky · porkchop | round-trip to two-body truth; ΔV < 0.01 % | Izzo 2015 · rocket equation · analytic Hohmann floor |
MODELLED | Orbit determination (Gauss–Newton batch) | sub-m / mm·s⁻¹ noiseless; ~2 m at a 5 m noise floor | two-body + J2 over an RK4 arc |
VALIDATED | Force-model fit vs Galileo precise ephemeris (full-arc) | 0.61 m 3-D RMS, 24 h, d/o-70, force-only | ESA/ESOC |
VALIDATED | Force-model fit vs Swarm-A precise ephemeris (reduced-dynamic) | 0.10 m 3-D RMS (empirical-tier bound, not a measure) | ESA |
VALIDATED | Force-model fit vs LRO lunar (honest miss) | 6.6 m reduced-dynamic, above the 5 m target | JPL Horizons LRO (NAIF −85) + GRAIL (Gravity Recovery and Interior Laboratory) |
MODELLED | Deep-space Mars OD (reduced-dynamic SRIF) | ≈ 0.2 m Mars-LMO (simulation FoM, not real-mission) | synthetic closed-loop OD — estimator-machinery validation |
VALIDATED | Sun-central Mars dynamics vs JPL DE440 | 137 m @ 1-day arc (grows with arc = unmodelled n-body) | JPL DE440 via ANISE ( |
VALIDATED | Single-point positioning vs a surveyed IGS coordinate (real observations) | 5.7 m 3-D RMS / 1.1 m horizontal, dual-frequency iono-free code SPP | IGS station ABMF survey + GPS broadcast ephemeris, 2018-05-13 ( |
MODELLED | Tightly-coupled GNSS/INS UKF | 0.77 m RMS over a 30-min LEO pass incl. a 120 s outage | force-model coast, hand-derived |
MODELLED | GPS-denied gravity-map navigation | ~70 km INS drift → ~145 m recovered | ESA NAVISP Quantum Wayfarer target |
MODELLED | Terrain-referenced navigation (TERCOM/SITAN) | 70 km drift → < 500 m (grid-resolution floor ~140 m) | SRTM |
MODELLED | IGRF-14 main field (degree/order 13) | pole ~80.7°N, dipole ~29.7 µT, physical 22–67 µT band | IAGA (International Association of Geomagnetism and Aeronomy) |
MODELLED | Nav-signal modulation & code tracking | BPSK self-SSC = 2/(3·R_c); unit-area PSDs; sub-metre C/A DLL jitter @ 45 dB-Hz | Closed-form SSC/PSD anchors + Kaplan & Hegarty DLL thermal-noise formula |
MODELLED | CR3BP halo/NRHO differential corrector | STM = finite differences; orbit closes to machine precision; L2 9:2 NRHO ≈ 6.57 d / perilune ≈ 3,250 km | finite-difference STM check + published L2 southern 9:2 NRHO (≈ 6.56 d / ≈ 3,370 km) — CR3BP, not a real Gateway ephemeris |
VALIDATED | ARAIM dual-constellation integrity | constellation-wide fault mode on real GPS + Galileo | EU ARAIM TR (technical report) / DO-316; Celestrak |
VALIDATED | GNSS geometry / DOP (GDOP/PDOP/HDOP/VDOP/TDOP) | match to 1e-6 relative across 8 geometries (well-conditioned → near-singular) | gnss_lib_py 1.0.4 (Stanford NAV Lab) — independent library ( |
VALIDATED | ML detector-evaluation metrics (AUC/ROC/confusion/Pd-Pmd/precision/F1) | exact counts + < 1e-9 over 5 datasets × 24 thresholds | scikit-learn 1.9.0 (Pedregosa et al., JMLR — Journal of Machine Learning Research — 2011) — independent library ( |
VALIDATED | Anomaly-detection ROC AUC on real ESA OPS-SAT telemetry | AUC reproduces scikit-learn to < 1e-9; peak-count detector AUC ≈ 0.85 on the labelled test split | scikit-learn |
VALIDATED | Quantum-trade numerical kernels (ADEV NNLS fit · χ² consistency bands · van-Loan clock Q) | NNLS + Q exact; χ² < 5e-4 at operating dof ≥ 48 | scipy 1.17.1 — |
VALIDATED | MTIE / MDEV / TDEV telecom wander metrics (ITU-T G.810/G.823/G.8261/G.811 — the International Telecommunication Union's Telecommunication Standardization Sector recommendations) | MTIE (9 averaging factors, bit-exact) and MDEV + TDEV (8 factors, < 1e-9 relative) on the NIST SP 1065 LCG (linear congruential generator) series | allantools 2024.06 |
VALIDATED | MCDA trade-study methods — all four decision families, nine externally-validated aggregators (WSM · WPM · WASPAS · MOORA · COPRAS · TOPSIS · VIKOR · PROMETHEE II · ELECTRE I) plus AHP pairwise-comparison priority weighting | scores / rankings / concordance matrices reproduced to < 1e-9 | pymcdm + pyDecision (independent third-party MCDA libraries) + Saaty RI (Random Index) / SciPy-LAPACK eig ( |
MODELLED | Conditional Timing Protection Level (holdover-limited undetected time error under spoofing) | composition reproduces the multi-step | JammerTest 2024 (Zenodo 15911589) scalars + van-Loan / CUSUM closed forms ( |
MODELLED | PNT-resilience scoring + decision-instability | 35 hand-derived oracle tests; byte-deterministic study artifact (fixed seed) | DHS RPCF v2.0 mapping + Dirichlet / Kendall-τ / Hill-N2 closed forms — synthetic architectures, not a certification |
MODELLED | RF-impairment optimism-gap study (scaling laws + leave-one-out predictor) | permutation-null significance; byte-deterministic artifact (5 seeds) | synthetic parameter-grounded corpus — the eval metrics are VALIDATED vs scikit-learn (above); the study is MODELLED |
CI | Cross-platform reproducibility | bit-identical input + shape goldens on 3 OSes (operating systems) | Linux / macOS / Windows CI matrix, SHA-256 goldens |
CI | Test coverage | ~96 % line on | cargo-tarpaulin (LLVM engine) |
FAQ
Do I need to understand quantum physics to use this? No. If you can run a command line you can run Kshana. Start with the plain-language primer; look terms up in the glossary.
Is this a quantum-hardware design or flight software? No. It is a performance simulator. Quantum-hardware fidelity comes from published error models, not from this tool. See What it is / is not.
Are the quantum results realistic, or marketing? Every parameter is cited to a datasheet or paper, every model is validated against a textbook relation, and maturity is labelled honestly in VALIDATION.md — including that no strontium optical clock has flown. The engine is neutral: quantum and classical are the same code with different published numbers.
Can I trust two runs to agree?
Yes — runs are deterministic: scenario + seed + engine version → bit-identical output,
enforced by scripts/check-reproducible.sh.
Can I use it from Python or in a browser? Yes — see Python and WebAssembly. Both call the same engine.
How do I model my own sensor?
Write a scenario .toml with your sensor's published figures in the provenance
fields. See Scenario format and the examples in scenarios/.
Is it free for commercial use?
Yes — under the AGPL-3.0, including in commercial settings, as long as you honour the
AGPL's copyleft (notably: if you modify Kshana and offer it over a network, you must
offer those users your modified source). If that does not suit you — e.g. you need to
embed Kshana in a proprietary product or run a closed network service — a commercial
licence is available from Ashforde OÜ; see LICENSING.md and
Support.
Troubleshooting
cargo build fails on an old toolchain. Kshana needs Rust ≥ 1.85. Update with
rustup update.
Building the Python extension fails to link on macOS (Undefined symbols … _Py…).
A Python extension resolves its symbols at load time. maturin sets the right linker
flag automatically — use maturin develop --features python rather than a bare
cargo build.
The Python build complains the interpreter is newer than PyO3 knows. Set
PYO3_USE_ABI3_FORWARD_COMPATIBILITY=1 (abi3 wheels are forward-compatible across
CPython versions).
WebAssembly build can't find the target. Install it once with
rustup target add wasm32-unknown-unknown, then wasm-pack build --target web -- --features wasm.
Where did my output go? Each run writes <scenario>.result.json,
<scenario>.chart.svg and <scenario>.report.html next to the input .toml, and
<scenario>.table.csv too for the kinds that publish a table. All of them are
git-ignored by design.
Roadmap
See ROADMAP.md for the phased roadmap, CHANGELOG.md
for released history, and docs/CAPABILITY.md for the
per-capability roadmap. The priority order is: timing and holdover evidence for
critical infrastructure first (telecom masks, longer holdover with ageing and flicker
noise, ingestion of measured clock data); the neutral quantum-vs-classical trade method
second (results labelled MODELLED until a partner's measured data promotes them); and
lunar / cislunar and deep-space navigation maintained, not expanded as the lead. The ITRF-precise frame reduction is now delivered — the
full CIO-based IAU 2006/2000A GCRS↔ITRS chain (polar motion + sub-arcsecond nutation),
validated bit-for-bit against SOFA/ERFA and independently cross-checked against ANISE
(pure-Rust SPICE) to ≤ 3.6 m at GNSS orbit. Near-term items include tightly-coupled carrier-phase fusion and surfacing the
loosely-/tightly-coupled GNSS/INS navigator across more packs; the deep-space / Mars
radiometric-navigation engine landed in v0.17.0 (simulation-validated). The
quantum physics layer is a P2 item: the CAI accelerometer is now simulated from
first principles (Mach–Zehnder phase, projection noise, contrast decay, vibration
coupling), while the clock/time-transfer sensors are still driven by published
Allan/noise-budget coefficients. GMST-based TEME↔ECEF, the IERS
leap-second time systems (UTC/TAI/TT/UT1), SGP4/SDP4 orbit propagation (v0.7.0,
validated against the AIAA 2006-6753 vectors), and the runnable gnss-ins fusion
pack have all shipped, and the inertial velocity is exposed downstream. An active
stochastic time-spoof detector (Neyman–Pearson / χ²₁ energy test with Monte-Carlo
P_fa/P_md and a Security FoM of 1−P_md), a link-budget jamming model (J/S → effective
C/N₀ → loss of lock), multi-constellation availability, a single-axis (1-DOF)
IMU error budget, two independent (clock + position) Kalman estimators reported as a
combined FoM, real constellation geometry from TLEs, an HTML scorecard report,
geometry-derived GNSS availability
and dilution of precision from Keplerian orbits with eccentricity and J2 drift,
Monte Carlo confidence bands, trade-study parameter sweeps, an in-browser WebAssembly
playground, and optional Python (PyO3) and WebAssembly (wasm-bindgen) bindings have
landed on main.
Contributing
See CONTRIBUTING.md. In short: tests pass (cargo test), the
two guard scripts pass, Conventional Commits, and a CHANGELOG.md [Unreleased]
entry for every user-visible change. Participation is governed by our
Code of Conduct. To report a security issue, see the
Security policy — please do not open a public issue for vulnerabilities.
Citing
If you use Kshana in academic or technical work, please cite it. Machine-readable
metadata is in CITATION.cff (GitHub renders a "Cite this repository"
button from it); cite the version you used (e.g. v0.27.3) together with the
scenario and seed for full reproducibility. Every release is archived on Zenodo with
a citable DOI (Digital Object Identifier) — the concept DOI 10.5281/zenodo.20528627
always resolves to the latest version.
Baweja, C. (2026). Kshana — a PNT-resilience simulator with quantum-sensor performance models. Ashforde OÜ. https://doi.org/10.5281/zenodo.20528627
Related publications. Studies built on the open engine are written up separately; their numbers regenerate from a committed scenario + seed or the reproducible study artifacts above.
Baweja, C. (2026). The Cost of Lunar South-Polar Geometry, and Surface Beacons as the Efficient Fix: A Dilution-of-Precision Analysis. arXiv:2607.06212. https://doi.org/10.48550/arXiv.2607.06212
Baweja, C. (2026). Earth-baseline VLBI restores the observability of a lunar surface station in joint orbit-and-clock determination. arXiv:2607.02566. https://doi.org/10.48550/arXiv.2607.02566
Baweja, C. (2026). A Conditional Timing Protection Level: Holdover-Limited Undetected Time Error Under GNSS Spoofing. arXiv:2606.24210. https://doi.org/10.48550/arXiv.2606.24210
Baweja, C. (2026). Anticipating the Optimism Gap: Predicting Distribution-Shift Degradation of RF-Impairment Detectors from In-Distribution Statistics. arXiv:2606.22054. https://doi.org/10.48550/arXiv.2606.22054
Versioning & releases
Kshana follows Semantic Versioning. While pre-1.0 the public
scenario/result schema may still change; breaking changes are called out explicitly in
the CHANGELOG.md. Every result is reproducible from
scenario + seed + engine version.
Every vX.Y.Z tag publishes all channels automatically, in one order — the full
test suite runs on the tagged commit first, nothing is published until it passes, and
afterwards the pipeline checks that each registry really serves the new version
(docs/RELEASING.md). The channels:
Channel | Install / get | Contents |
| Rust library + CLI | |
| the MCP server | |
| abi3 wheels (Linux/macOS/Windows) + sdist (source distribution) | |
| WebAssembly module + JS wrapper | |
| multi-arch OCI (Open Container Initiative) image — no toolchain needed | |
official MCP registry | auto-discovered by MCP clients |
|
IDE → Plugins → search "Kshana" | the Kshana — PNT simulator IDE plugin | |
download | the | |
DOI | a citable archive of every release | |
open in a browser | the WebAssembly playground, rebuilt from each release tag (so the version it shows is the version it runs) |
The MCP server's crate / image / registry version tracks the engine (it bundles the
library); the JetBrains plugin versions independently (it shells out to your installed
kshana binary).
License
Dual-licensed. Use Kshana under either the GNU AGPL-3.0-only (see
LICENSE) or a commercial licence from Ashforde OÜ for
proprietary/closed integration that the AGPL does not suit. Which one applies, and
why it is set up this way, is explained in LICENSING.md.
Contributions are licensed inbound under the AGPL and grant Ashforde OÜ the right
to include them in the commercially-licensed edition (so the dual-licence keeps
working) — see CONTRIBUTING.md. Sign off each commit per the
Developer Certificate of Origin with git commit -s.
Trademark. "Kshana" and its marks are trademarks of Ashforde OÜ. The licence covers the code, not the name — please rename forks and derivative distributions.
Support & professional services
Kshana is free and open source under the AGPL-3.0 and professionally developed and maintained by Ashforde OÜ (Estonia). The open engine is complete and usable on its own. For organisations that need more, Ashforde OÜ offers:
Commercial support & integration — embedding Kshana in your toolchain, custom scenarios, and priority fixes.
Custom sensor models — calibrated to your hardware, including export-sensitive resilience models maintained in a private overlay.
Kshana Pro — proprietary model-based systems-engineering and programme tooling that plugs into the open engine to complete the workflow.
Training & consulting on quantum/classical PNT performance analysis.
This is the open-core model: the engine is, and stays, openly licensed; the sustaining business is expertise, support, and the proprietary extensions — not license fees. Contact contact@ashforde.org · ashforde.org.
Key references
Validation oracles & standards — the external authorities Kshana's checks are anchored to:
Vallado, Crawford, Hujsak & Kelso — Revisiting Spacetrack Report #3 (AIAA 2006-6753; test data): the SGP4/SDP4 verification set Kshana matches to 4.12 mm, and the worked frame examples the TEME→ITRF chain is checked against.
IAU SOFA / ERFA — the reference time and frame routines the IAU 2000A nutation and the CIO GCRS↔ITRS reduction are validated bit-for-bit against.
Petit & Luzum (eds.) — IERS Conventions (2010), IERS TN (Technical Note) 36 (Earth-orientation, polar motion, and frame standards).
Riley — Handbook of Frequency Stability Analysis, NIST SP 1065 (Allan-deviation relations and the NBS14 reference series; NBS = the former US National Bureau of Standards).
Pedregosa et al. — scikit-learn: Machine Learning in Python, JMLR 12 (2011): the reference ROC/AUC, confusion-matrix and precision/recall/F1 implementations the RF-impairment evaluation testbed is matched to exactly (
tests/eval_metrics_reference.rs).Virtanen et al. — SciPy 1.0, Nature Methods 17 (2020):
optimize.nnls,stats.chi2andlinalg.expm— the reference routines the quantum-trade measured-ADEV NNLS fit, the χ² consistency bands, and the van-Loan clock process-noise covariance are validated against (tests/scipy_reference.rs).Knowles, Kanhere, Neamati & Gao — gnss_lib_py, SoftwareX 27 (2024): used both as open prior art (see Comparison & open prior art below) and as the independent DOP oracle the GDOP/PDOP/HDOP/VDOP/TDOP computation is matched to 1e-6 (
tests/dop_reference.rs).Montenbruck & Gill — Satellite Orbits: Models, Methods and Applications (Springer): the force models behind the force-model fit to agency precise ephemerides.
Howell — Three-dimensional, periodic, halo orbits, Celestial Mechanics 32(1) (1984), doi:10.1007/BF01358403; Zimovan-Spreen, Howell & Davis — Near rectilinear halo orbits and nearby higher-period dynamical structures, Astrodynamics 6 (2022), doi:10.1007/s42064-021-0125-x (the halo/NRHO families the CR3BP differential corrector reproduces).
Device & method physics — the cited sources behind the sensor models:
Origlia, Schiller, Bongs et al. — arXiv:1503.08457 (strontium optical lattice clock, space-oriented goal).
Oelker et al., Nature Photonics (2019) — doi:10.1038/s41566-019-0493-4 (laboratory Sr clock, 4.8×10⁻¹⁷).
Templier et al., Science Advances (2022) — arXiv:2209.13209 (hybrid quantum accelerometer triad).
Groves, Principles of GNSS, Inertial, and Multisensor Integrated Navigation — IEEE AESS (Aerospace and Electronic Systems Society) tutorial (University College London Discovery repository) (dead-reckoning error growth).
Giorgetta et al., Nature Photonics 7, 434 (2013) — arXiv:1211.4902; Deschênes et al., Phys. Rev. X 6, 021016 (2016) — APS (American Physical Society) (optical two-way time-frequency transfer; the optical inter-satellite link models its non-reciprocity budget after these).
Betz — Binary Offset Carrier Modulations for Radionavigation, NAVIGATION 48(4) (2001), doi:10.1002/j.2161-4296.2001.tb00247.x (the BOC modulation and spectral-separation theory behind
src/navsignal.rs).Kaplan & Hegarty (eds.) — Understanding GPS/GNSS: Principles and Applications (3rd ed., Artech House, 2017): the anti-jam effective-C/N₀ equation and the early–late DLL code-tracking thermal-noise jitter the nav-signal and jamming models use.
Comparison & open prior art — the tools and surveys Kshana is positioned against:
Humphreys et al. — TEXBAT (the Texas Spoofing Test Battery; ION — Institute of Navigation — GNSS 2012): the spoofing test-battery parameters the multi-layer detector is characterised against.
González et al. — NaveGo (2017): the open, validated inertial-navigation error profiles used as the classical baseline.
Iiyama, Casadesús Vila & Gao — LuPNT (ION GNSS+ 2023, Stanford NavLab): open lunar-PNT simulator.
Knowles, Kanhere, Neamati & Gao — gnss_lib_py, SoftwareX 27 (2024), doi:10.1016/j.softx.2024.101811: open GNSS data analysis.
Li, Zaminpardaz, Kealy & Greentree — Quantum sensors for enhanced positioning and navigation: a comprehensive review, GPS Solutions 30(1):62 (2026), doi:10.1007/s10291-026-02030-y.
Bertone et al. — Earth and Space Science 8(6) (2021), doi:10.1029/2020EA001454: GRAIL reduced-dynamic OD, the empirical-acceleration floor the LRO fit reproduces.
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP server for aerospace calculations: orbital mechanics, ephemeris, DSN operations, ...
TLE MCP — satellite tracking via Two-Line Element sets (tle.ivanstanojevic.me, free, no auth)
Physics-based validation of simulation results: receipts with per-check verdicts, via MCP.
Geospatial AI MCP server — satellite imagery, embeddings, weather, GNS governance
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables control system analysis and testing through PID controller evaluation against second-order plants. Provides regression testing utilities with step response analysis, gust rejection metrics, and settling time calculations for control engineering applications.1MIT
- AlicenseNot gradedqualityAmaintenanceMeasurement uncertainty MCP server for ISO/IEC 17025 and KOLAS-accredited laboratories. GUM/MCM/QMC engine + 9 calibration templates (TEM/SEM-EDS/AFM/OCD nano-metrology) + reverse_uncertainty (novel within prior-art search) + Ed25519 audit signatures + W3C PROV-O provenance. v0.6.0, 36 passing tests on Python 3.10–3.12.MIT
- FlicenseAqualityAmaintenanceMCP server that exposes a deterministic force-on-force simulation of FPV sUAS vs counter-UAS RF direction finding as tools for AI agents to run engagements, sweep seeds, and compare configurations.5-
- AlicenseNot gradedqualityBmaintenanceAn MCP server that equips LLM clients with authoritative astrodynamics tools including TLE/SGP4 propagation, Lambert solving, ground-station access, time-scale and coordinate-frame conversions, and more.84 PyPI2MIT