UPSC Darpan

Internal SecurityGS321 September 2026

Army’s AASHVAST Labs Will Scan Drone Firmware for Hidden Chinese Code Before Deployment

Open in the app — quiz, notes, Mistake Vault हिंदी में पढ़ें

The news

NEW DELHI — The Indian Army will soon operate six AASHVAST labs across the country, where all its drones, and eventually CCTV cameras, will undergo mandatory inspection to identify and eliminate firmware-level vulnerabilities, The Indian Express reported (Amrita Nayak Dutta). Firmware is the low-level software built into a device’s chips that controls how its hardware behaves. AASHVAST stands for Assessment and Analysis of Electronic Systems Hardware for Vulnerabilities and Security Threats. One lab has been inaugurated in Delhi, with at least five more planned in the coming months. The Firmware Analysis and Validation Suite was developed by QuickPay Pvt Ltd for the Directorate General of Electronics and Mechanical Engineering (DG EME). The Army published a Request for Proposal in April this year to procure customised licensed software for validating firmware and embedded systems in electronic components, including UAV components; on August 14, its Additional Directorate General of Public Information said on X that the facility, “aligned with the national vision of #AtmanirbharBharat”, would increase cyber resilience. So far, drones procured by the Army had not had firmware vulnerabilities checked. Such flaws can be introduced during manufacture or upgrade: unused code or hidden commands invoked at a certain location could stop a drone from performing its task. The labs can detect about 14 types of vulnerability, including geospatial ones such as a malfunction over a certain location, bugs that stop a drone from reaching its preset destination, hidden code that terminates a flight before the target, and time and location bugs. They will also look for Chinese or other foreign-origin active components, hidden passwords, embedded keys, remote access tools and location-based security controls. Future CCTV cameras will be inspected for Chinese proprietary protocols. “There is no mechanism to determine what is embedded within the silicon. What is visible is merely the invoice,” said a person involved in setting up the lab, adding that the checks would prevent Chinese components being misrepresented as ‘made in India’. The paper noted that the Army is buying drones at scale through the emergency procurement route, many for use along the eastern borders; India has previously prohibited domestic military drone makers from using Chinese parts, and in 2025 the Army Design Bureau submitted a framework to the Ministry of Defence to eliminate Chinese-origin components from UAVs. QuickPay Director Rajib Roy said the aim was to prevent enemy interference in contested areas.

The chain in one line: Drones become central to modern war → Army buys at scale through emergency procurement → components sourced from China enter ‘Indian’ drones through invoices that hide true origin → firmware backdoors could disable drones in contested zones → AASHVAST labs make firmware inspection mandatory

Static syllabus linkage

  1. Supply-chain security is now a formal part of India’s security policy. The National Security Directive on the Telecommunication Sector, approved in December 2020, requires telecom operators to buy equipment only from ‘trusted sources’ certified by the National Cyber Security Coordinator. The logic is the same as AASHVAST’s: the risk lies not only in what a device does but in who built its components. Hardware and firmware backdoors are hard to detect after deployment, so screening must happen before.
  2. India’s drone policy combines liberalisation with import restriction. The Drone Rules, 2021 liberalised civilian drone use by reducing approvals and creating the Digital Sky platform. A Production Linked Incentive scheme for drones and drone components was approved in 2021. In February 2022 the government banned the import of foreign drones, with exemptions for defence, security and R&D, to build domestic manufacturing — but components continued to be imported.
  3. India’s cyber-security institutions have statutory roots in the IT Act. Section 70A of the Information Technology Act, 2000 provides for the National Critical Information Infrastructure Protection Centre (NCIIPC), and Section 70B for CERT-In, the national agency for cyber incident response. The Defence Cyber Agency handles military cyber operations. Firmware testing in the Army is a defence-specific addition to this civil framework.
  4. Emergency procurement trades speed for scrutiny. Under the Defence Acquisition Procedure, 2020, the armed forces can use emergency procurement powers to buy urgently needed equipment quickly, bypassing the longer standard process. This was used after the 2020 Galwan clash and later. The risk is reduced time for quality and security checks, which is why post-purchase testing such as AASHVAST matters.

Why UPSC loves this

  1. GS3 lists cyber security and the role of technology in security. The syllabus names ‘basics of cyber security’ and ‘challenges to internal security through communication networks’. UPSC has asked about cyber threats to critical infrastructure and about indigenisation in defence.
  2. Defence indigenisation is asked with an eye on quality, not only quantity. Questions on Atmanirbhar Bharat in defence increasingly ask about capability and supply chains. This story gives a concrete example of why ‘made in India’ labels need verification.

Prelims nuggets

  • Section 70B of the Information Technology Act, 2000 designates CERT-In as the national agency for incident response.
  • Section 70A of the IT Act provides for the National Critical Information Infrastructure Protection Centre.
  • The Drone Rules, 2021 introduced the Digital Sky platform for drone approvals.
  • The import of foreign drones was banned in February 2022, with exemptions for defence, security and R&D purposes.
  • The Defence Acquisition Procedure, 2020 governs capital procurement by the Ministry of Defence.
  • Firmware is software embedded in a device’s hardware that controls its basic functions.

Analysis

  1. An invoice is not a certificate of origin. The most important sentence in the report is that the invoice shows where a part was bought, not where it was made. Import bans and ‘make in India’ rules that rely on paperwork can be bypassed by routing Chinese components through third countries or local assemblers. Firmware and component analysis verifies the product itself. That shifts enforcement from documents to evidence, which is more reliable.
  2. Firmware is the ideal hiding place for sabotage. Hidden code that activates at a specific location or time would pass every ordinary field test and fail only in a real operation. That is precisely the danger for drones used along the eastern borders, where an adversary knows the likely areas of use. A lab that tests for geospatial and time-based triggers addresses the threat that ordinary acceptance trials miss. This is a genuine capability gap being closed.
  3. The lab is only as good as its scope and independence. Six labs for the whole Army is a start, but drones are being bought in large numbers. The suite itself was developed by a private company; the Army must ensure the testing tools are secure and independently audited. Over time, testing should extend to all electronics, not only drones and CCTV. The same logic applies to the Navy and Air Force.
  4. The counter-view: strict origin rules raise costs and slow supply. India’s drone industry still depends on imported components such as motors, batteries and chips, many from China. Strict exclusion may raise prices and slow deliveries when forces need drones urgently. The practical answer is risk-based: exclude components that can carry hidden code, such as controllers and communication modules, while allowing passive parts from trusted sources until domestic supply grows.

Possible Mains question

“Indigenisation of defence equipment is meaningless without verification of its supply chain.” Discuss in the context of the Indian Army’s initiative to test drones for firmware-level vulnerabilities. (15 marks, 250 words)

Model approach

  1. Introduction. Introduce AASHVAST: six labs, mandatory firmware inspection of drones and later CCTV, one lab already in Delhi.
  2. Body — the threat. Chinese components in drones used on eastern borders; firmware backdoors, geospatial and time-based triggers; invoices that hide true origin.
  3. Body — India’s policy framework. Drone import ban 2022, PLI for drones, Army Design Bureau framework of 2025, telecom trusted-source rules, CERT-In and NCIIPC.
  4. Body — challenges. Scale of procurement, dependence on imported components, cost, need for independent audit of testing tools.
  5. Conclusion. Argue for supply-chain verification as a standing part of defence procurement and a push for domestic chips and controllers.

Administrator's brainstorm

As an officer in the Directorate General of Electronics and Mechanical Engineering, how would you roll out mandatory testing without delaying urgent drone supplies?

I would prioritise testing by risk: drones deployed on the eastern borders and those with the most sensitive functions first. Testing could be built into the acceptance process so that it runs in parallel with other trials. Vendors would be told the requirements in advance, so they can supply clean firmware. Where a drone fails, the vendor must fix it at its own cost within a set time.

A domestic vendor’s drone is found to contain a Chinese controller despite a ‘made in India’ declaration. What action should follow?

The drone should be rejected and the vendor asked to explain. If misrepresentation is established, contractual penalties and possible debarment should follow, and the matter may be referred for investigation. The finding should be shared with other services so they can check their own purchases. Consistent enforcement is what makes the rule credible.

An interview board asks whether India should ban all Chinese electronics in government use.

A blanket ban may not be practical immediately because supply chains are deeply integrated. The better approach is risk-based: strict exclusion in defence, critical infrastructure and surveillance systems, with testing and certification elsewhere. At the same time India should invest in domestic manufacturing of key components. Security and economic capacity must grow together.