Master thesis : Securing Drone Data in Real-Time: A NATO STANAG-Compliant Data-Centric Security Framework for Integrity Protection
Andries, Alexandre
Promotor(s) :
Donnet, Benoît
Date of defense : 29-Jun-2026/30-Jun-2026 • Permalink : http://hdl.handle.net/2268.2/26098
Details
| Title : | Master thesis : Securing Drone Data in Real-Time: A NATO STANAG-Compliant Data-Centric Security Framework for Integrity Protection |
| Translated title : | [fr] Protection de l’intégrité des données de drones en temps réel : un cadre de sécurité centré sur les données conforme aux STANAG de l’OTAN |
| Author : | Andries, Alexandre
|
| Date of defense : | 29-Jun-2026/30-Jun-2026 |
| Advisor(s) : | Donnet, Benoît
|
| Committee's member(s) : | Ernst, Damien
Leroy, Pascal
Rinaldi, Giulia |
| Language : | English |
| Number of pages : | 98 |
| Keywords : | [en] data-centric security [en] confidentiality labelling [en] metadata binding [en] integrity protection [en] NATO STANAG 4774/4778 [en] ECDSA [en] unmanned aerial vehicles [en] UAV [en] UxV [en] data-centric [en] NATO [en] OTAN [en] integrity [en] telemetry [en] STANAG |
| Discipline(s) : | Engineering, computing & technology > Computer science |
| Funders : | Thales |
| Target public : | Researchers Professionals of domain Student General public Other |
| Institution(s) : | Université de Liège, Liège, Belgique |
| Degree: | Master en sciences informatiques, à finalité spécialisée en "computer systems security" |
| Faculty: | Master thesis of the Faculté des Sciences appliquées |
Abstract
[en] A drone in flight produces telemetry, imagery, and command traffic carried over heterogeneous and partly untrusted links. Perimeter and transport controls protect the path these streams travel, but they bind nothing to a data object once it has been stored or forwarded beyond that path. Documented attacks on the navigation signal and the control protocol confirm that drone data is manipulable in transit; channel protection alone therefore cannot assure a recipient about an object it later holds. Existing unmanned aerial vehicle (UAV) defences act in the channel or after the fact, and few travel with a released object. A recipient cannot independently confirm that the object it holds is the one the originator produced.
This thesis designs, implements, and evaluates a Data-Centric Security (DCS) framework that closes this gap at the data-object level. It segments the streams into bounded objects such as a telemetry record, an image frame, or a complete file, and attaches to each a machine-readable confidentiality label. The label is a marking rather than an enforced access control, and the framework does not keep the object secret; instead it binds the label cryptographically to the object, so that stripping, altering, or downgrading the marking becomes detectable. An independent verifier thus detects any later change to the data, the label, or their association. The design aligns with the North Atlantic Treaty Organization (NATO) Standardization Agreements (STANAGs) 4774 and 4778: the label and its binding form a detached sidecar protected by SHA-256 digests under a single elliptic-curve signature (ECDSA, P-256). The Rust prototype requires no central binding service and no public-key infrastructure at verification time; verification instead assumes that an authentic public key is already held. Scope follows from this construction. The guarantee is integrity rather than confidentiality through encryption, and it is tamper-evident rather than replay-resistant. It begins at object formation, so the framework detects alteration of a released object but does not establish the truth of the input that produced it; source-level attacks such as navigation spoofing fall outside its scope.
The evaluation is constructive and exercises the prototype directly on simulator-generated telemetry, on a large still-image corpus used as a per-frame proxy for a video feed, and on a set of heterogeneous files. Tamper detection and format independence are structural: a single signature covers byte-wise digests, and every input is hashed as received rather than parsed by type. Functional testing revealed no defect, detecting and localising every mutation in the tampering catalogue to the altered artefact with no false positives. The remaining results concern cost and timing. Per-object cost is dominated by a fixed component for small objects; only the data-hashing stage scales with payload size. End-to-end medians stay near 0.13 ms for a telemetry record and 0.98 ms for an image frame, and throughput rises with the number of concurrent input streams without saturating across the range tested. Under a fixed cadence, the labelling pipeline holds a one-percent deadline-miss criterion up to 60 frames per second on the reference host, though latency is heavy-tailed and a deployment must budget for the tail rather than the median.
The contribution is a measured demonstration of this workflow on bounded, file-based drone data, where related NATO work in the access-control and release lineage has largely remained at proof of concept and left per-object cost unquantified. The prototype is a research artefact, aligned with and inspired by the referenced standards, not a certified, validated, or operationally endorsed implementation.
File(s)
Document(s)
s196948_ANDRIES_Alexandre_2026_THESIS.pdf
Description: Master Thesis
Size: 2.8 MB
Format: Adobe PDF
s196948_ANDRIES_Alexandre_2026_ABSTRACT.pdf
Description: Abstract
Size: 106.17 kB
Format: Adobe PDF
Cite this master thesis
The University of Liège does not guarantee the scientific quality of these students' works or the accuracy of all the information they contain.

Master Thesis Online

