quinta-feira, 8 de setembro de 2022

INDUCED SPOOFING FROM APPROACH TO LANDING - During Taxi and Takeoff as well

 


ABRIDGED RESEARCH ON FLIGHT INDUCED SPOOFING


IET Radar, Sonar & Navigation

University of Texas at Austin

Flight Induced spoofing

Accepted: 29 August 2021

Revised: 22 July 2021

Received: 3 June 2021


Sources:

Wang, W., Wang, J.: GNSS induced spoofing simulation based on path planning.

IET Radar Sonar Navig. 16(1), 103–112 (2022).

https://doi.org/10.1049/rsn2.12167

 

DW INTERNATIOONAL - A NAVTECH COMPANY

John Wilde

Radio Navigation System Engineer at Qascom, Italy

Samuele Fantinato

Signal Processing Engineer at Qascom, Italy

Stefano Montagner

Signal Processing Engineer at Qascom, Italy

Stefano Ciccotosto

Founder and Technical director of Qascom, Italy

Oscar Pozzobon

 

REFERENCES

1. JafarniaJahromi, A., et al.: GPS vulnerability to spoofing threats and a review of antispoofing techniques. Int. J. Navig. Obs. 2012, 127072 (2012). https://doi.org/10.1155/2012/127072

2. Carroll, J.V.: Vulnerability assessment of the transportation infrastructure relying on global positioning system. J. Navig. 56(2), 185–193 (2003)

3. Humphreys, T.E., et al.: The Texas spoofing test battery: Toward a standard for evaluating GPS signal authentication techniques. In: Proceedings of the ION GNSS+ meeting, pp. 3569–3583. Nashville. September 2012

4. Kerns, A.J., et al.: Unmanned aircraft capture and control via GPS spoofing. J. Field Robot. 31(4), 617–636 (2014)

5. Morales, F.R., et al.: A survey on coping with intentional interference in satellite navigation for manned and unmanned aircraft. IEEE Commun. Surv. Tut. 22(1), 249–291 (2020)

6. Ioannides, R.T., Pany, T., Gibbons, G.: Known vulnerabilities of global navigation satellite systems, status, and potential mitigation techniques. Proc. of IEEE. 104(6), 1174–1194 (2016)

7. Humphreys, T.E., et al.: Assessing the spoofing threat: Development of a portable GPS civilian spoofer. In: Proceedings of the ION GNSS meeting, pp. 16–19. Savannah. September 2008

8. Gao, Y., Lv, Z., Zhang, L.: Asynchronous liftoff spoofing on satellite navigation receivers in the signal tracking stage. IEEE Sens. J. 20(15), 8604–8613 (2020)


Global Navigation Satellite Systems (GNSS) are highly susceptible to various interferences.

By 2030 it is expected that GNSS will be the main navigation system for most of the flight phases. GNSS is nowadays also as an essential component for other aviation systems, such as the Enhanced Ground Proximity Warning System (EGPWS) and Ground Based Augmentation System (GBAS).

It is expected that GNSS based air routes will be able to accommodate up to three times the current traffic volume.




Intentional Spoofing during Approach

An instrument approach may be divided into four approach segments: initial, intermediate, final, and missed approach.

Depending on speed of the aircraft, availability of weather information, and the complexity of the approach procedure or special terrain avoidance procedures for the airport of intended landing, the in-flight planning phase of an instrument approach can begin as far as 100-200 nautical miles (NM) – from the destination,

The ILS system

The major risk for aircraft navigation (most likely during bad visibility conditions) is at the beginning of the approach phase.

The spoofing detection algorithms configurations as:

• Spoofing Doppler could have an offset of several KHz from the authentic.

• Spoofing delay might have an offset up hundreds of chips from the authentic

• Spoofing power offset depends on the relative distance between the aircraft under attack and the sensor

Non Intentional Spoofing during Taxi-in or Take Off

Certain non-aeronautical systems transmit radio signals intended to supplement GNSS coverage in areas where GNSS signals cannot be readily received (e.g. inside buildings). These systems include GNSS repeaters and pseudolites. GNSS repeaters (also known as “reradiators”) are systems that amplify existing GNSS signals and re-radiate them in real-time.


The interference caused alerts of the Enhanced Ground Proximity Warning System providing the messages ”pull-up” and ”FMS/GPS Position disagree” during Taxi-in and departure of the airplanes.


In these interferences, induced spoofing is very difficult to be detected because it can gradually drag off the tracking points without unlocking the tracking loops of the attacked receiver and cause the victim to obtain a wrong position and/or time information.

The importance of GNSS makes it an increasingly attractive target for hackers and criminals.

The openness of the civil GNSS signal structure and the weak transmitting and receiving power make GNSS vulnerable to variable natural and malicious interferences.

The spoofing, as a kind of malicious interference, can possibly make GNSS victims produce wrong positioning and/or time information.

The spoofing attack mainly includes meaconing and generative spoofing attack [5, 6]. For meaconing, spoofers first receive the authentic satellite signals and then amplify and retransmit the signals to the target receivers. However, for generative spoofing, spoofers usually use GNSS simulation software to generate forged signals, which have the same structure as authentic signals but have false navigation data information.

Generative spoofing can be classified as:

Simplistic spoofing - the spoofing and authentic signals received by victims have asynchronous parameters including code phase, carrier phase and other parameters. Simplistic spoofing usually adopts the ‘jammingspoofing’ mode, which first unlocks the target receiver by high power jamming and then enables the victim recapture and lock on spoofing signals.

Intermediate spoofing - is also called induced spoofing or liftoff spoofing. The spoofer first controls the spoofing to synchronise with the authentic signals in the code phase and Doppler frequency so as to disguise as the authentic signals and then gradually controls the tracking loop of the target receiver. Induced spoofing does not destroy the tracking state of the target receiver and smoothly induces the victim to a false position/time, which is more threatening and difficult to be detected.

Sophisticated spoofing - based on induced spoofing, uses multiple transmit antennas and controls the directions of transmitting antennas so that the spoofing signals have the same arrival directions as the authentic ones [10]. It can defend against angleofarrival detection but needs a huge increase in cost and complexity.

Data generation algorithm based on path planning

Induced spoofing and antispoofing




Signal model

Induced spoofing has the same structure as that of the authentic satellite signal but different parameters.

Take GPS L1 C/A as an example; they can be denoted as


When there is an induced spoofing, the victim will simultaneously receive the authentic signal and spoofing as follows:

For induced spoofing, the key feature is that it can gradually drag off the tracking points without unlocking the code loop and carrier loop of the victim. In order to achieve this goal, the spoofer has to first estimate the parameters of the authentic signals received by the target receiver and then adjust the parameters of the spoofing signals to synchronize the code and carrier phases with the authentic signal. After that, the spoofing can drag off the tracking loop of the victim by increasing the power.

However, it is difficult for the spoofer to produce the spoofing signals whose carrier phase is exactly the same as that of authentic signals.

When the spoofer shifts the code phase of the spoofing signals, there are two modes of carrier phase alignment between the spoofing and authentic signals. The first one is the nonfrequency lock mode, where the change rate of the carrier phase is proportional to that of the code phase as follows:


where fc is the carrier frequency in Hz, ϕ and τ represent the change rates of the code phase and carrier phase in seconds per second and cycles per second, respectively.

 

The second one is the frequency lock mode in which the spoofing and authentic signals have a certain initial carrier phase offset, and the fixed offset is maintained in the process of changing the code phase. Thus, the spoofing signal and the authentic signal have the same carrier Doppler frequency.

 

 

It should also be noted that, in the nonfrequency lock mode, the carrier phase difference between the spoofing and authentic signals cannot be kept fixed, which leads to the rapid amplitude variation of the blended signal. The frequency lock mode can avoid the above situation, that is amplitude fluctuation.

Thus, spoofing detection methods based on amplitude fluctuation cannot detect the spoofing.

 

However, the method, based on code rate and Doppler frequency consistency, can be used to detect the frequency lock mode. On the contrary, due to the continuous movement of the satellites, the Doppler frequency of the authentic signals constantly changes even if the victim is stationary. The movement of the victim will intensify this change. In other words, it is difficult for the spoofer to estimate the accurate Doppler frequency of the authentic signals. Therefore, the frequency lock mode is not easy to implement.

The induction process of induced spoofing can be demonstrated by the autocorrelation function (ACF) model of the authentic and spoofing signals. Depending on the methods of code phase alignment, induced spoofings can be classified as synchronous and asynchronous. Figure 1 shows the induction processes of the two methods.

The green dot marks indicate the code phase discrimination result, that is, the tracking point of the receiver. As the correlation peak of the spoofing signal moves, the tracking point of the receiver will shift gradually and finally completely transfer to the spoofing signal. Then, the tracking loop is controlled by the induced spoofing.

As shown in Figure 1a, synchronous induced spoofing mainly has two phases:

(1) T0 T1: alignment phase and

(2) T2: dragoff phase.

 In the alignment phase T0, the power of the spoofing is initially lower than that of the authentic signal when the spoofing is injected, but the code phase and carrier frequency are synchronised with those of the authentic signal.

Then, in T1, the power of the spoofing signal increases gradually until it exceeds the power of the authentic signal. With the power advantage, the tracking loop will be controlled by the spoofing signal. Subsequently, in T2, the spoofing increases its code rate, which causes the spoofing correlation peak to move away from the authentic correlation peak during the dragoff phase. Thus, the tracking point shifts gradually until it is completely transferred to the spoofing correlation peak as T3.

Synchronous induced spoofing signals can effectively forge the authentic signals, but it is necessary to know the precise geographical location and velocity of the target receiver to accurately estimate the code phase and carrier Doppler frequency of the authentic signal. However, it is very difficult to implement in a real spoofing scenario. Therefore, at the beginning, the spoofing generated by the spoofer usually has a certain code phase and Doppler frequency difference with the authentic signal. In this case, the generated spoofing is an asynchronous induced spoofing.

As shown in Figure 1b, the strategy of asynchronous induced spoofing is similar to that of synchronous induced spoofing, and the whole induction process includes three phases: 

In T0', the spoofing initially has some code phase difference from the authentic signal. Then, the spoofing signal will continuously adjust its code phase so that its correlation peak gradually approaches that of the authentic signal until they are aligned. And the subsequent process is similar to synchronous induced spoofing. In this induction process, the spoofer does not know the accurate code phase and Doppler frequency of the authentic signals, which makes it impossible to know when it is synchronised with the authentic signal. Therefore, the spoofing correlation peak must always be higher than the authentic correlation peak to ensure that the spoofing signal can successfully lift off the tracking point after alignment.

In short, by adjusting the change rate of the code phase of spoofing based on a given strategy, the induced spoofing can gradually change the relative code phase difference between the authentic signal and spoofing.

Then, the induced spoofing can control the tracking loop of the victim, which will eventually lead to a wrong position and/or time information output. Therefore, the key step of induced spoofing is to gradually change the relative code phase difference between authentic signal and spoofing.

On the other hand, it is well known that the code phase received by the receiver is related to the transmission time of the satellite signal and the distance between the satellite and receiver based on the principle of satellite navigation. Thus, signals received by receivers in different locations have different code phases even for signals coming from the same satellite and the same transmission time.

Path planning

Suppose there are two receivers; one is called target receiver whose received satellite signals simulate the authentic signals received by the victim receiver. The other is called spoofing receiver whose received satellite signals simulate the spoofing generated by the spoofer.

When the target and spoofing receivers are located at the same threedimensional geographical positions at the same time, the distances from them to each satellite are equal, that is. Similarly, when the target and spoofing receivers are in different threedimensional geographic locations (in a small area), ∆=τi will change and approximately satisfy 

where dr is the distance between the target receiver and the spoofing receiver as

Example of asynchronous induced spoofing to illustrate the algorithm of path planning. The path planning consists of three phases:

(1) As shown in Figure 2a, the target and the spoofing receivers separately move along the solid line and the dotted line at different speeds from time t0 and meet at M1 at time t1, which corresponds to the T0  of Figure 1(b).

Then, Δτi  will change from Δτi  > 0 to Δτi  ¼ = 0.

(2) As shown in Figure 2b, from time t1 to time t2, two receivers move at the same speed along the same path. This process corresponds to the T0 of Figure 1b.

(3) After time t2, as shown in Figure 2c, two receivers begin to move along different paths and the distance between them continuously increases. Thus, the Δτi  changes from Δτi  ¼ = 0 to Δτi  >0. This process corresponds to the T2  of Figure 1b.

The power control of spoofing

The power of spoofing signals is another crucial factor affecting the success of the inducing process. It is worth noting that it is not that the higher the power of the spoofing signal, the better. For the victim, the intrusion of the spoofing will increase the noise floor and affect the carrier-to noise ratio. Excessive power will cause the victim to issue an abnormal alarm. Nevertheless, if the power of spoofing is too low and not synchronized with the authentic signal in the carrier phase, the stability of the tracking loop will be affected. Consequently, the power of the spoofing should be higher than the authentic signal, but not too high.






FIGURE 2 An example of path planning for the target and spoofing receivers to produce an asynchronous induced spoofing (a) Path from time t0 to time t1 (b) Path from time t0 to time t2 (c) Path from start t0 to the end of time.





FIGURE 6 Positioning solutions of authentic, spoofing and mixed signals. (a) Latitude (b) Longitude (c) Height


Non Intentional Spoofing: Repeaters

Intentional Spoofing, Landing Case (Simulated)


Spoofing detection techniques

 The spoofing detection engine has been designed according to the following requirements:

• Capability to Monitor Spoofing with:

– Power Offset: between -3 dB and +15 dB. Lower bound is related to receiver acquisition sensitivity, upper bound is a limit over which the spoofing signal can be considered as an interferer.

– Frequency Offset: related to the maximum relative velocity between the sensor and a plane during the approach phase.

– Delay Offset linked to common distance from the airport of the approach phase beginning.

• Spoofing Detection probability 95% and False Alarm lower than 10-4

• Time to Alarm lower than 5 seconds.





quinta-feira, 28 de julho de 2022

LATERAL ERROR DURING LANDING

 


Conventional head-down display X Head-up display (HUD)

Source:

Örjan Goteman

Scandinavian Airlines Stockholm, Sweden

 

Kip Smith and Sidney Dekker

Department of Industrial Ergonomics Linköping Institute of Technology

References

Refer to FAA Advisory Circular 90-106A, issued 3/2/17

Nichol, Ryan J., “Airline Head-up Display Systems: Human Factors Considerations”. International Journal of Economics and Management Sciences, 4:248, May 3, 2015. https://www.omicsonline.org/open-access/airline-headup-display-systems-human-factors-considerations-2162-6359-1000248.php?aid=54170

 

AC No: 90-106A 2017

AC No: 20-167A 2016

AC No: 25-118 2014

AC No: 90-106A 2017





Third-generation aviation HUDs use optical waveguides that produce images directly in the combiner, without the need for a projection system. Some of the latest HUD systems use a scanning laser, which can display images and video on a clear transparent medium, such as a windshield.

It is possible that, during approach and landing, the HUD might affect the pilot’s ability to assimilate outside cues at the decision height, thereby reducing the success ratio for landings using an HUD.

HUD use reduced the width of the touchdown footprint in all tested visibility and lighting conditions, including visibility below the minimum allowed.

HUD use had no effect on the length of the touchdown footprint.

How ambient RVR affects approach and landing operations.

HUD USE IN COMMERCIAL FLIGHT OPERATIONS

A computer-generated aircraft flight-path and energy symbols presented onto a transparent screen in the pilot’s primary view.

HUDs replicate the information on the pilot’s conventional flight instruments, showing aircraft attitude, speed, altitude, and heading, and containing a flight-path symbol showing the aircraft velocity.

Conformal HUDs

A conformal HUD with a flight-path symbol can explicitly show the pilot where the aircraft is going relative to the surrounding world.

A pilot flying with conventional flight instruments must infer the aircraft’s flight path from a synthesis of the H-angle (Lintern & Liu, 1991), optical flow (Gibson, 1986), and possibly also the relative perspective gradient (Lintern, 2000).

Comparisons between HUDs and head-down displays in manual flight have found that conformal HUDs use improved track, speed, and altitude maintenance (Lauber, Bray, Harrison, Hemingway, & Scott, 1982; Martin-Emerson & Wickens, 1997).

The civil aviation community assumed that these HUD performance advantages over conventional head-down instrumentation could reduce the number of approach and landing incidents and accidents (Flight Safety Foundation, 1991).

Two well-documented problems associated with approach and landing: visual approaches to runways without radio navigation aids or with unreliable navigation aids, and the transition from instrument to external visual cues for landing in low visibility (e.g., Newman, 1995).

Pilot performance during landing in low-RVR conditions where transitioning from instrument to external cues for maneuvering is an issue.

The presumed sources for the advantage in flight-tracking performance for the HUD are that it eliminates the need for the pilot to move his or her gaze from head-down instruments to the outside world to look for maneuvering cues (Stuart, McAnally, & Meehan, 2003) and it minimizes scanning requirements (Mar[1]tin-Emerson & Wickens, 1997). The transition from head down to the outside world requires a change in visual accommodation (e.g., the visual depth of field changes from less than 1 m to infinity). Because conformal HUD symbology is focused at infinity, HUD use eliminates the need for and time demand of visual accommodation, simplifying the pilot’s task.

Cognitive tunneling

One possible negative effect of HUD in the landing situation is that inserting a glass plate with symbols in front of a pilot may affect his or her ability to visually acquire the approach lights, which is necessary to continue the approach below the decision height.

The light transmission through the HUD is not 100%. A commercial HUD will let about 85% to 90% of the incoming light pass through the glass plate. A detrimental effect of HUD use during the landing would then show up as a lower success ratio for HUD than for a conventional flight deck without HUD.

The segment of flight immediately before touch[1]down performed in U.S. and European civil air transport operation are conducted as Category I instrument landing system (ILS) approaches.

The two critical factors when making the decision of whether to land are the decision height and the RVR. Decision height refers to the aircraft’s vertical distance above the runway threshold where the pilot must make the decision to land or make a go-around.

The pilot must be able to see at least some of the approach or runway lights at the decision height.

The RVR is a measure of horizontal visibility defined by the length of visible approach and runway lights in the ambient atmospheric conditions. If the RVR is too low the pilot will not be able to see any of the approach lights at the decision height and must make a go-around.

Missed approach

It  is part of normal operations (and formal procedures), it adds an undesired additional risk(International Civil Aviation Organization [ICAO], 1993).

The approach light lengths differ from runway to runway. Geographical constraints sometimes make the standard full length of 720 m (Full Facilities) impossible to achieve. Fewer approach lights means less guidance and later contact with the approach lights during the approach.

For example, to commence a Category I ILS approach to a runway equipped with a 720 m length of approach lights, the RVR measured at the runway must not be less than 550 m (Federal Aviation Administration [FAA], 2002; Joint Aviation Authorities [JAA], 2004b). This RVR is expected to allow the pilot to see a visual segment of the ground that contains enough of the runway approach lights to judge the aircraft’s lateral position, cross-track velocity, and position in roll when the aircraft is at decision height.

Apart from the obvious effect that the approach lights will come in view later with lower RVR, other effects of shorter approach lights lengths could also come into play. If runway length has been shown to influence the perceived descent path (Lintern & Walker, 1991) it is also possible that a reduced length of approach lights can have similar effects, adding a source of uncertainty to the vertical control of the aircraft.

During landing the pilots have to concurrently process both outside cues and HUD cues to get any benefit from the HUD. The operational benefit from a reduction in touchdown variability could be that regulations would allow approach operations using HUD in lower than standard RVR conditions. The current operating minima were not set bearing HUD operations in mind and may be too restrictive for operations using HUD, a fact that the existing legislative text acknowledges (JAA, 2004b).

Setting RVR for approach too low will ultimately reduce approach success rate. In low RVR with very few external cues available at decision height, there is a risk that the pilots will focus their attention on the HUD symbology to the extent that they might not perceive the few visible approach lights at decision height. Pilots who do not pick up the out[1]side cues may thereby initiate a go-around when the approach actually could have been continued, an outcome that is not desirable from an operational stand[1]point.

The effect of HUD on touchdown performance for two different approach lights conditions as defined in the European regulations:

F     Full Approach Light facilities (≥ 720 m) and

b     Intermediate Approach Light facilities (420 to 719 m; JAA, 2004b).


EXPERIMENT 1

Experience on the B–737–700 varied from 50 hr to more than 1,000 hr.

It was used a CAE B–737–700 training simulator with aircraft aerodynamics and visual angles valid for B–737–700 to collect data. This six-axis full-motion simulator is approved for low-visibility operations down to an RVR of 200 m. The simulator’s visual system had a field of vision of 180°/40° with a focal distance greater than 10 m.

The HUD installed in the simulator was a Rockwell-Collins Flight Dynamics HGS–4000® (Head-up Guidance System), certified for low-visibility operations down to and including an RVR of 200 m. The HUD symbology and functionality used in the experiment met the production-line standard specification for the instrument meteorological conditions (IMC) mode used when conducting Cate[1]gory I ILS and non-precision approaches.


Forty-eight pilots from a major European airline volunteered to participate. All were qualified to fly the B–737–700 aircraft and had completed their HUD training for the operator. The HUD training sessions consisted of 1 day of theory and two simulator sessions of 4 hr duration each.

The HUD provided conformal display of flight path (velocity) and flight-path guidance. The flight path was displayed as a circle with slanted wings. Flight-path guidance was displayed in the form of a ring inside the flight-path symbol.

Flight-path guidance was not available in the conventional head-down instrumentation.

Each pilot manually flew two approaches using standard operating procedures of the airline. The scenarios started as a 6 nm final to the runway in lower than standard or standard RVR in a simulated 10 kt left crosswind. In the with-HUD condition, the pilots kept the aircraft on lateral and vertical by following the flight-path guidance ring with the flight-path symbol on the HUD. At 50 ft above the runway threshold, the guidance cue was automatically removed and the pilots performed the landing flare using external visual cues in conjunction with the HUD flight-path symbol. The HGS–4000® IMC mode incorporating automatic removal[1]of the guidance cue was deliberately chosen to ensure that the pilots could not attend solely to the HUD symbology in the with-HUD conditions.

In the no-HUD condition the pilots kept the aircraft on lateral and vertical track by following the flight director bar guidance. At decision height they continued the approach and landing using the external cues only.

Touchdown performance

11 of the 48 pilots con[1]ducted one or two go-arounds. The simulator failed to capture the location of the landing footprint for another 7 pilots. As a result the data set for comparing the touchdown footprints across the HUD and no-HUD conditions consists of 30 pairs of approaches. Of these 30, 15 were flown using the HUD in the first approach and 15 using the conventional head-down instruments (no-HUD) in the first approach;

15 were flown in standard RVR (550 m) conditions and 15 in lower than standard RVR conditions (450 m).

Lateral touchdown performance was measured as the absolute lateral deviation from the runway centerline at touchdown.





EXPERIMENT 2

Approaches in Experiment 2 were flown to simulations of a runway with 420 m of approach lights. This length falls within the intermediate facilities category of approach lights as defined by European aviation regulations (JAA, 2004b).

Each participant flew one approach with HUD and one approach without HUD to a runway with a system of approach lights of 420 m length. The between-subject variable was RVR at two levels, a standard minimum RVR (700 m) for intermediate facilities and a lower than standard minimum RVR (550 m to 600 m).

Forty-five [45] pilots from the same major European airline volunteered to participate. None of the volunteers had participated in Experiment 1. All were qualified to fly the B–737–700 aircraft and had completed their HUD training for the operator. Experience on the B–737–700 varied from more than 50 hr to more than 1,000 hr.

Each of the 45 pilots attempted two approaches.

Thirty-two made two successful landings, one with HUD and one without. Four pi[1]lots made go-arounds in both conditions. Three pilots landed with the HUD and made go-arounds without the HUD; six pilots landed without the HUD and made go-arounds with the HUD.

Touchdown performance

As a result, the data set for comparing the touchdown footprints across the HUD and no-HUD conditions consists of 28 pairs of approaches. Of these 28 pairs of approaches, 9 were flown using the HUD in the first approach and 19 using the conventional head-down instruments (no-HUD) in the first approach; 14 were flown in standard RVR (700 m) conditions and 14 in lower than standard RVR conditions.

As in Experiment 1, the effect for HUD use on the lateral component of the touch[1]down footprint is strong, F(1, 26) = 14.9, p < .001, η2 = .10, indicating a power greater than .70. Once again, landings were closer to the centerline when pilots used the HUD.

Three findings:

111. HUD use per se did not influence the pilots’ decision to land or go-around at the decision height.

The lack of an effect of HUD suggests that the additional information in the HUD did not distract the pilots’ attention or interfere with their decision making during the most critical portion of the approach and landing sequence.

2.2.HUD use significantly reduced the size of the lateral component of the touchdown footprint for all RVR conditions.

The difference between the HUD and the no-HUD conditions lay in the presence of a conformal flight-path vector in the pilots’ primary field of view during the landing.

3.3.In contrast to its effect on the lateral component of the touchdown footprint, it appears that the HUD did not influence the size of the longitudinal footprint.

The ubiquitous and ever-varying direction and velocity of wind is likely to preclude the development of true automaticity at touch[1]down. Crosswinds introduce an element of uncertainty regarding drift (the shift in lateral location of the aircraft relative to the runway’s centerline). For the pilot to detect drift the visual ground segment needs to be long enough to determine the aircraft’s movement over the ground. That means that to detect drift at all, a notice able lateral displacement must take place and not all of this displacement can be corrected before touchdown.

The HUD largely eliminates uncertainty about drift.

The addition of a conformal flight-path vector projected over the runway provides instantaneous feedback about aircraft drift and actual flight path. The additional information enables precise control of the flight path during approach and landing and reduces the variance in lateral displacement practically to nil.

Control of the longitudinal component of the touchdown footprint is largely an effect of how pilots handle the aircraft’s energy (operationally manifested as sink rate) in the final seconds before landing. The pilot uses information provided by the optic flow from the looming runway to control the aircraft’s energy (Lee, 1974). It is important to note that pilots of large commercial air transport aircraft are also aided by radio altimeter callouts that count down from 50 ft to 0 ft (runway contact) in 10-ft decrements.

The initiation of the landing flare has been shown to be a function of time to contact (Mulder, Pleijsant, van der Vaart, & van Wieringen, 2000). A small change in the timing of a landing flare at the nominal glide slope of 3° results in large longitudinal differences. The HUD mode used in the experiments provided no flare guidance and no additional information that could be used to guide the pilots when to initiate the landing flare.