Grand Theft Drone: Reaching Breaking Point in Drone Proprietary RF Link Security

No ratings

Presented at BlackHat Europe 2022 by

The drone industry is under enormous change, and the technology in the remote control for drones has vastly improved. Nevertheless, many remote control vendors reveal a lack of security features, and they use proprietary protocols instead of standard ones. (Many remote control vendors use proprietary protocols, which lack security instead of standard protocols.) The absence of the standards violates the "Principle of Open Design". It makes manufacturers hide hopping patterns and RF signal specifications of their products' communication mechanisms to ensure lifespan by "security through obscurity".To overcome counterfeiting, eavesdropping, and skyjacking from hackers, the vendors have shifted from the design, which connects separated CPU and RF chip via a serial interface, to an SoC (System on Chip); such ICs are custom-made for a specific purpose on the vendor's demand. The firmware is usually encrypted, and their datasheets and other such information are usually private and not publicly available. Despite their effort, one of the most popular vendors still reveals a lack of security features in terms of RF reverse engineering. We present SDR based live packet sniffer and cloning transmitter for a proprietary drone protocol, FrSky next generation "ACCESS", which the vendor claims enhanced security. We found out that the newest protocol doesn't cloak critical information thrown in the air. They also have the security issue on frequency hopping table and sequence generation, which can easily lead to a takeover of drones by malicious attackers. We will demonstrate skyjacking, which takes full control of the drone. We will also examine the feasible and suitable mitigation strategies for RF reverse-engineering attacks.