Feedback

Faculté des Sciences appliquées
Faculté des Sciences appliquées
Mémoire

Master thesis : Securing Drone Data in Real-Time: A NATO STANAG-Compliant Data-Centric Security Framework for Integrity Protection

Télécharger
Andries, Alexandre ULiège
Promoteur(s) : Donnet, Benoît ULiège
Date de soutenance : 29-jui-2026/30-jui-2026 • URL permanente : http://hdl.handle.net/2268.2/26098
Détails
Titre : Master thesis : Securing Drone Data in Real-Time: A NATO STANAG-Compliant Data-Centric Security Framework for Integrity Protection
Titre traduit : [fr] Protection de l’intégrité des données de drones en temps réel : un cadre de sécurité centré sur les données conforme aux STANAG de l’OTAN
Auteur : Andries, Alexandre ULiège
Date de soutenance  : 29-jui-2026/30-jui-2026
Promoteur(s) : Donnet, Benoît ULiège
Membre(s) du jury : Ernst, Damien ULiège
Leroy, Pascal ULiège
Rinaldi, Giulia 
Langue : Anglais
Nombre de pages : 98
Mots-clés : [en] data-centric security
[en] confidentiality labelling
[en] metadata binding
[en] integrity protection
[en] NATO STANAG 4774/4778
[en] ECDSA
[en] unmanned aerial vehicles
[en] UAV
[en] UxV
[en] data-centric
[en] NATO
[en] OTAN
[en] integrity
[en] telemetry
[en] STANAG
Discipline(s) : Ingénierie, informatique & technologie > Sciences informatiques
Organisme(s) subsidiant(s) : Thales
Public cible : Chercheurs
Professionnels du domaine
Etudiants
Grand public
Autre
Institution(s) : Université de Liège, Liège, Belgique
Diplôme : Master en sciences informatiques, à finalité spécialisée en "computer systems security"
Faculté : Mémoires de la Faculté des Sciences appliquées

Résumé

[en] A drone in flight produces telemetry, imagery, and command traffic carried over heterogeneous and partly untrusted links. Perimeter and transport controls protect the path these streams travel, but they bind nothing to a data object once it has been stored or forwarded beyond that path. Documented attacks on the navigation signal and the control protocol confirm that drone data is manipulable in transit; channel protection alone therefore cannot assure a recipient about an object it later holds. Existing unmanned aerial vehicle (UAV) defences act in the channel or after the fact, and few travel with a released object. A recipient cannot independently confirm that the object it holds is the one the originator produced.

This thesis designs, implements, and evaluates a Data-Centric Security (DCS) framework that closes this gap at the data-object level. It segments the streams into bounded objects such as a telemetry record, an image frame, or a complete file, and attaches to each a machine-readable confidentiality label. The label is a marking rather than an enforced access control, and the framework does not keep the object secret; instead it binds the label cryptographically to the object, so that stripping, altering, or downgrading the marking becomes detectable. An independent verifier thus detects any later change to the data, the label, or their association. The design aligns with the North Atlantic Treaty Organization (NATO) Standardization Agreements (STANAGs) 4774 and 4778: the label and its binding form a detached sidecar protected by SHA-256 digests under a single elliptic-curve signature (ECDSA, P-256). The Rust prototype requires no central binding service and no public-key infrastructure at verification time; verification instead assumes that an authentic public key is already held. Scope follows from this construction. The guarantee is integrity rather than confidentiality through encryption, and it is tamper-evident rather than replay-resistant. It begins at object formation, so the framework detects alteration of a released object but does not establish the truth of the input that produced it; source-level attacks such as navigation spoofing fall outside its scope.

The evaluation is constructive and exercises the prototype directly on simulator-generated telemetry, on a large still-image corpus used as a per-frame proxy for a video feed, and on a set of heterogeneous files. Tamper detection and format independence are structural: a single signature covers byte-wise digests, and every input is hashed as received rather than parsed by type. Functional testing revealed no defect, detecting and localising every mutation in the tampering catalogue to the altered artefact with no false positives. The remaining results concern cost and timing. Per-object cost is dominated by a fixed component for small objects; only the data-hashing stage scales with payload size. End-to-end medians stay near 0.13 ms for a telemetry record and 0.98 ms for an image frame, and throughput rises with the number of concurrent input streams without saturating across the range tested. Under a fixed cadence, the labelling pipeline holds a one-percent deadline-miss criterion up to 60 frames per second on the reference host, though latency is heavy-tailed and a deployment must budget for the tail rather than the median.

The contribution is a measured demonstration of this workflow on bounded, file-based drone data, where related NATO work in the access-control and release lineage has largely remained at proof of concept and left per-object cost unquantified. The prototype is a research artefact, aligned with and inspired by the referenced standards, not a certified, validated, or operationally endorsed implementation.


Fichier(s)

Document(s)

File
Access s196948_ANDRIES_Alexandre_2026_THESIS.pdf
Description: Master Thesis
Taille: 2.8 MB
Format: Adobe PDF
File
Access s196948_ANDRIES_Alexandre_2026_ABSTRACT.pdf
Description: Abstract
Taille: 106.17 kB
Format: Adobe PDF

Auteur

  • Andries, Alexandre ULiège Université de Liège > Master sc. inform. fin. spéc. comput. syst. secur.

Promoteur(s)

Membre(s) du jury

  • Ernst, Damien ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Smart grids
    ORBi Voir ses publications sur ORBi
  • Leroy, Pascal ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Smart grids
    ORBi Voir ses publications sur ORBi
  • Rinaldi, Giulia








Tous les documents disponibles sur MatheO sont protégés par le droit d'auteur et soumis aux règles habituelles de bon usage.
L'Université de Liège ne garantit pas la qualité scientifique de ces travaux d'étudiants ni l'exactitude de l'ensemble des informations qu'ils contiennent.