💥Mains Ready By December. Smash Mains & Smash PYQ Admissions Open

Six high-tech Army labs to weed out foreign bugs from drones, cameras

Why in the News

The Indian Army will operate six AASHVAST laboratories, at which all its drones will undergo mandatory inspection for firmware level vulnerabilities before use. One laboratory is already running in Delhi, with at least five more planned in the coming months. Drones procured by the Army until now were never checked at the firmware level, and their origin was established from the purchase invoice alone. The tension is that an invoice records where a component was bought, not what is embedded inside the silicon. A component sourced from China can be presented as made in India with no test contradicting the claim.

What is AASHVAST?

  1. The name: AASHVAST stands for Assessment and Analysis of Electronic Systems Hardware for Vulnerabilities and Security Threats.
  2. What it is: It is a firmware analysis and validation suite, built by a private developer for the Directorate General of Electronics and Mechanical Engineering (DG EME).
  3. What it inspects: It examines the software that operates an unmanned aerial vehicle (UAV), rather than physically inspecting the airframe alone.
  4. Procurement route: The Army issued a Request for Proposal in April 2026 for customised licensed software to validate firmware and embedded systems in electronic components, including UAV components.

What vulnerabilities can the laboratories detect?

  1. Scale of the screen: About fourteen types of vulnerability can be detected by the suite.
  2. Geospatial faults: A malfunction triggered when the aircraft flies over a particular location, or a fault that stops it reaching a preset destination.
  3. Hidden and unused code: Code left in the firmware that can make a drone terminate its flight before reaching its target.
  4. Time and location bugs: Instructions that let a drone operate normally except at specific times or in specific places.
  5. Access and identity artefacts: Hidden passwords, embedded keys, remote access tools and location based security controls.
  6. Foreign origin components: Chinese or other foreign origin active components sitting inside the airframe’s electronics.
  7. How a vulnerability enters: It can be introduced during the manufacturing stage of a component or during a later upgrade process.

Why does the invoice not establish origin?

  1. What the invoice shows: A purchase invoice records the point at which a component was bought, not the origin of what is inside it.
  2. No test at the silicon level: No mechanism in the procurement chain determines what is embedded within the silicon itself.
  3. The misrepresentation risk: Active components sourced from China can be presented as made in India or in a third country on the strength of that invoice.
  4. The existing prohibition: Domestic military drone manufacturers have already been barred from using parts made in China.
  5. The framework in progress: The Army Design Bureau submitted a detailed framework to the Ministry of Defence in 2025 aimed at eliminating Chinese origin components from UAVs.

Why does the screen matter now?

  1. Procurement volume: The Army is acquiring drones at scale through the emergency procurement route, which compresses the time available for technical scrutiny.
  2. Where the drones fly: Many of these drones are used in operations along the eastern borders, where the supplier concern and the adversary are the same state.
  3. The gap being closed: Firmware level checks were absent from Army drone procurement until now, so the suite covers a stage that no other test reached.
  4. Operational purpose: The stated aim is to neutralise enemy interference that would stop a drone performing its designated task in a contested area.
  5. Cameras next: CCTV cameras procured by the Army in future will also be inspected, for Chinese proprietary protocols or their equivalent.
  6. The declared frame: The Army has placed the facility under the Atmanirbhar Bharat vision, presenting it as raising cyber resilience and growing the domestic defence electronics ecosystem.

Challenges to firmware screening of military drones

  1. Screening capacity against procurement volume: Six laboratories testing every drone and later every camera create a throughput bottleneck at the point of induction. Eg. Emergency procurement contracts run on delivery timelines measured in months rather than years.
    The Fix: Set a risk tier so that only new firmware builds and new component sources take full analysis, with repeat builds cleared on a cryptographic hash comparison.
  2. Firmware changes after clearance: A drone cleared at induction can be altered through a later update pushed by the supplier. Eg. Commercial drone platforms routinely push updates that change flight envelope and geofencing behaviour.
    The Fix: Require signed firmware with a key held by the Army, and revalidate any build before it is loaded onto a fielded aircraft.
  3. Hardware implants escape a software test: A malicious function fabricated into the chip itself is not visible to firmware analysis. Eg. Counterfeit and re-marked integrated circuits are a recurring finding in defence supply chain audits worldwide.
    The Fix: Pair the firmware suite with hardware level testing, such as X ray and die level inspection, on a sampled share of every batch.
  4. Supply chain depth beyond the first tier: A vendor can certify an Indian assembly while its own sub suppliers buy from the restricted origin. Eg. Restrictions on direct imports have historically shifted sourcing to intermediaries in third countries rather than changing the component.
    The Fix: Require a component level bill of materials with origin declarations down to the sub tier, verified against the laboratory’s own findings.
  5. Substitutes must exist before a ban works: Removing a restricted component only helps where a qualified domestic or allied alternative exists at the same performance and price. Eg. Motors, flight controllers and imaging sensors for small drones are concentrated in a few overseas suppliers.
    The Fix: Fund qualification of domestic alternatives for the specific component classes the laboratories flag most often, rather than relying on a blanket origin ban.

Conclusion

Procurement has until now verified where a component was bought. The laboratories move verification to what the component actually does, which is the only level at which a concealed function can be found. The gap that remains sits between a one time clearance at induction and a fleet that keeps receiving software through its service life. The marker to watch is whether the screen is applied to the drone and camera stock already in service, or only to what is bought next.

Back2Basics: Directorate General of Electronics and Mechanical Engineering (DG EME)

  1. What it heads: DG EME heads the Corps of Electronics and Mechanical Engineers, the Indian Army’s technical corps, from Army Headquarters.
  2. Mandate: The Corps maintains, repairs and upgrades the Army’s equipment, covering vehicles, weapon systems, electronics and instrumentation.
  3. Origin: The Corps was raised in 1943 and took its present form after Independence.
  4. Indigenisation role: DG EME sponsors development and validation projects with Indian industry for equipment support, testing and life extension.

Matching Previous Year Question

“Keeping in view India’s internal security, analyse the impact of cross-border cyber attacks. Also, discuss defensive measures against these sophisticated attacks.”


Join the Community

Free Daily News, Daily Prelims and Mains questions.