How Tally works

Tally is an open network that collects the radio messages aircraft send, as heard by receivers at people’s homes, and turns them into positions anyone can use. This page explains the whole design with no background assumed.

Three words

  • Feeder: a receiver that sends what it hears. It is a radio receiver at someone’s home and a small program that stamps each message with the exact time it arrived, signs it and sends it on.
  • Relay: the program that collects what feeders send, computes positions and shares them with other relays. Every duty in the network is a relay’s, and anyone may run one.
  • Client: anything that reads Tally data, such as a website, an app or a map. A client never shares. Its access is either the free small tier or the credit of the relay it is linked to: a company that wants the firehose runs a relay, and its clients read on that relay’s credit. A client reads from a relay: its own, if it wants the firehose (often the same company runs both), or a public one for small use.

The pieces

Feeders send their messages to relays. Relays do all the work: they collect, compute positions and pass data on to each other. Clients read from relays. There is no special server and no central operator, because every relay is the same program.

FeedersRelaysClients
Feeders send their messages to relays, relays share with each other, and clients read from relays.

Where the data goes

A feeder sends its data to the two nearest healthy relays, on different networks, so one outage or one dishonest relay cannot silence it. Nearest is measured by how long a message takes to come back, which nobody can fake.

Raw messages stay near home: they travel at most one hop, to the relays that cover the same area, and those relays compute the area’s positions. Only finished positions travel worldwide, which keeps everyone’s bandwidth small.

One areaRawPositionsFeedersRelayRelayThe world
Inside one area, each feeder sends raw messages to two nearby relays. The positions they compute leave the area for the world.

Planes that do not say where they are

Most aircraft broadcast their own GPS position. Some do not, but they still answer radar with short pings. When several feeders hear the same ping, it reaches each one at a slightly different time, because each is a different distance away. Each time gap puts the plane somewhere on a curve, and where the curves cross is the plane. This is multilateration, MLAT for short, and it is a relay’s job.

Same time gapPingFeeder
One ping reaches four feeders at slightly different times. Each time gap between two feeders draws a curve, and the curves cross where the plane is.

That needs feeder clocks that agree to within a millionth of a second, and home receivers do not. So relays correct each clock using planes that do broadcast GPS: their position is known, so the moment their message should arrive is known, and the difference is that clock’s error.

Every answer comes with honest error bars: how far off it could be, including what the clock corrections leave uncertain.

Clocks are corrected together, in fixed groups called tiles. The world is cut into a fixed grid of areas at four sizes, about 50, 100, 200 and 400 km across, and each tile takes up to 48 nearby feeders, chosen only by where the feeders are. Every plane over an area uses its tile’s correction, so the work is done once per area, not once per plane. Every relay computes the same tiles, so the results stay checkable.

TilePlanePlane
Feeders are grouped into fixed tiles that overlap. Both planes over the highlighted tile use its one clock correction.

Every relay computes the same answer, to the last bit, from the same data. So answers from different relays merge without conflict, and anyone can prove a relay wrong if it publishes a bad answer.

Fast and final

Checking a position properly takes time, because a relay waits until every feeder’s messages have arrived. So each MLAT plane gets two answers. First a fast one, about 1 to 2 seconds after the ping, solved with the latest clock correction carried forward and with wider error bars. Then the checked final position, which replaces it. Clients choose whether to receive fast positions.

The quick answer matters in a cockpit: at 150 knots a plane covers half a mile in 12 seconds.

Two products

  • Regional: everything for one area, raw messages included. For researchers, local apps and the relays that cover the area.
  • World: one position per plane per second, everywhere. For flight trackers and companies that want the whole picture.

Sharing, like BitTorrent

Each area’s data first reaches a few relays that want it, and each of them passes it on to a few more. The relays that hold an area’s feeders send a fixed two or three copies however popular the area is, so a busy area never raises their bill.

Source
The source sends three copies, and each relay that receives one passes it on to two more.

Taking an area is a duty: each stream is split into stripes, every relay that takes the area forwards its own slice to a few others, and a relay that does not forward is dropped from the area.

Areas form a tree

The world is divided into a fixed tree of areas that everyone agrees on: small areas sit inside regions, regions inside countries, countries inside continents, and continents inside the world. Nobody hands it out; it is the same fixed grid for everyone.

A relay takes the areas it wants, at whatever level: a regional site takes its region, a national app its country, a global company the world. Whatever level a relay takes, it shares at that level, forwarding that area’s data to others who want it.

The worldContinentContinentCountryCountryCountryRegionRegionRegionRelaysClients
Areas nest inside bigger ones. A relay at each level gathers the level below into a bundle and passes it up, and clients read at the level they need.

A relay that has gathered every area under a bigger one can offer the bigger one as a single bundle. So a world relay connects to a handful of continent or country bundles, not to every small area. Every level has several relays offering it, so one going offline loses nothing.

Bundled data keeps each original relay’s signature, so bundling adds no trust: a bundle is checked exactly as its areas would be.

Fair use

Small use is free: a client can read positions for an area with nothing but a connection. Firehose use, meaning raw data or positions for large regions, is earned by a relay that genuinely contributes, by hosting feeders or uploading fresh data, and the clients linked to that relay read on its credit. A client never shares, so whoever wants the most data runs a relay and adds capacity to the network.

Every relay runs with a required upload speed cap, so its bill can never be more than the cap allows and no operator gets a surprise.

What feeders get back

Every feeder has a public station page showing its uptime, message rates, planes heard, range, the coverage only it provides, how much it helps MLAT, and its place on the leaderboards.

Find a station

All of it is computed from public signed data, so anyone can check it.

Trust

  • Everything is signed. Each feeder has its own key, and a relay cannot alter or invent a feeder’s messages, only fail to pass them on.
  • Answers are reproducible. Anyone with the same raw data can compute a position again and get exactly the same result.
  • Cheating is provable. Two signed answers from the same inputs that disagree are proof of a fault, and anyone can stop using that relay.
  • Feeders earn standing. A feeder whose messages keep agreeing with everyone else’s gains weight over time.