In the recent years, concerns over Chinese-origin components finding their way into military drones have prompted the Indian Army to strengthen the scrutiny of UAVs and other critical defence electronics. As part of these efforts, the Army has set up a specialised laboratory designed to uncover possible vulnerabilities that may not be detected through conventional inspections.
The Army has established AASHVAST (Assessment and Analysis of Electronic Systems Hardware for Vulnerabilities and Security Threats) in Delhi to ensure that military drones do not contain Chinese components and to identify hidden security risks in defence electronics and other critical digital systems.
The laboratory, inaugurated by Army Chief General Dhiraj Seth in August, is aimed at improving the integrity, reliability and security of military electronic systems.
Concerns surrounding Chinese components in military UAVs are not new. Their presence in drones deployed along India's sensitive northern and eastern borders has long been a cause of concern within the defence establishment.
A few years ago, India barred domestic manufacturers of military drones from using Chinese-made components because of concerns over potential security vulnerabilities. In 2025, the Army Design Bureau also submitted a comprehensive framework to the defence ministry for phasing out Chinese-origin components from UAVs.
How AASHVAST addresses the problem
Built for the Directorate General of Electronics and Mechanical Engineering (DG EME) by QuickPay Tech, AASHVAST is designed to go beyond physical inspection of a drone and examine the software operating inside it.
While an airframe can be inspected, weighed and physically tested, the firmware controlling a drone is more difficult to examine. This software determines how the aircraft flies, which commands it accepts and where it can operate.
“The system addresses a gap that has, until now, gone unexamined in routine practice,” Rajib Roy, director of QuickPay Tech, which established the laboratory, has been quoted as saying.
AASHVAST can scan systems for hidden passwords, embedded keys and remote-access tools. It can also check whether a drone accepts only manufacturer-approved software updates.
The system further examines location-based security controls and assesses how a drone would respond to GPS spoofing or jamming by an adversary.
AASHVAST operates completely offline inside an air-gapped facility. It functions as a read-only system and therefore does not alter the drone being examined.
Software can be extracted directly from a connected flight controller or camera payload. Stored software images can also be uploaded for analysis.
Once the examination is complete, vulnerabilities are classified according to their severity and presented in simple language. The findings are then combined into a single security assessment that can be exported as a structured record, according to a report by The Tribune.