Uppsats
Exploration of Remote ID Vulnerabilities : spoofing & replay attacks on Remote ID messages
Kandidat-uppsats
Linköpings universitet/Institutionen för datavetenskap
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
Remote ID is requirement for most drones in the EU and USA. It functions both as a way to identify drones and their pilots, as well as to monitor drone flights. The need for better monitoring of drones have arisen from the rapid growth of drone traffic. The goal of Remote ID is to enable law enforcement and other authorities to ensure safer skies. Remote ID lacks basic security mechanisms. Similar to ADS-B used in air traffic management, no authentication or encryption is mandatory. This means that Remote ID is susceptible to a number of attacks. As seen in ADS-B, the lack of security can have large consequences. In this thesis a spoofing attack is performed on Remote ID messages. A "fake drone" is created by using a Raspberry Pi and broadcasting Remote ID messages like a real drone would. This highlights how the lack of security means that an malicious actor easily can use the weaknesses to negatively impact the drone environment. The ability to create fake drones and similar attacks limits the trust, availability and integrity of Remote ID. These weaknesses needs to be addressed if Remote ID wants to avoid the same issues as ADS-B has faced.Additionally, a replay attack is also performed to further highlight how the lack of security mechanisms makes Remote ID vulnerable to attacks. The replay attack is performed by intercepting a Remote ID message from a DroneTag using the Raspberry Pi. Then the intercepted message is repackaged within a Remote ID message and broadcast by the Raspberry Pi. The results of the spoofing attack proved that a Raspberry Pi is able to be used to create and broadcast fake Remote ID messages that appears as if from a real drone. The captured traces of the experiment shows a difference between the behavior of broadcast and transmission frequency. Where the transmission frequency from captured traces is unequal and lower than the authentic transmissions in the implementation. The replay attack results show how a Raspberry Pi can be utilized to intercept and retransmit a real drones Remote ID messages. Traces of the Raspberry Pi's transmission shows the intercepted DroneTag message within a Remote ID message from the Raspberry Pi. Both the attacks show how the lack of security mechanisms in Remote ID leaves systems vulnerable to attacks that affect the integrity of the messages and availability of the systems.
Information
- Författare
- Jonsson, Ella, Slopi, Teresia
- Lärosäte / institution
- Linköpings universitet/Institutionen för datavetenskap
- Publiceringsdatum
- 2026
- Uppsatstyp
- Kandidat-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Master-uppsats, Lunds universitet/Institutionen för naturgeografi och ekosystemvetenskap
Kananen, Didrick
Publicerad: 2025
Yrkesexamen på grundnivå
Lindström, Rasmus, Nyrén, Wilma
Publicerad: 2025
Kandidat-uppsats, Högskolan i Skövde/Institutionen för informationsteknologi
Dargren, Calle
Publicerad: 2026
Kandidat-uppsats, Högskolan i Halmstad/Akademin för informationsteknologi
Johansson, Nathalie, Jonsson, Liam
Publicerad: 2026
Kandidat-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Löfgren, Nils
Publicerad: 2026
Kandidat-uppsats, Uppsala universitet/Institutionen för informatik och media
Kappler, Elena, Bakhtiyarova, Zamira
Publicerad: 2026