Mandatory cryptographic attestation for all aircraft in U.S. airspace — civil, commercial, law enforcement, and federal. Anything that cannot prove itself is mapped, netted, towed home intact, and forfeited as evidence. Nothing gets shot down.
Since September 2023, most drones in U.S. airspace must broadcast identification and location in flight under 14 CFR Part 89. Every FAA-registered aircraft, every Part 107 operation, every recreational drone over 0.55 lbs (FAA Remote ID).
Those broadcasts are plain text with no authentication. Researchers describe Remote ID as "critically incomplete from a security perspective," open to spoofing, relay, and replay attacks (arXiv). It has the same fundamental weakness as ADS-B: clear-text messages, no mandatory encryption or authentication (peer-reviewed survey, Linköping University). Working spoofers are published on GitHub and run on a Raspberry Pi (Cyber-Defence Campus).
So today, "it is broadcasting an ID" proves nothing. A hostile operator invents an identity and becomes indistinguishable from a delivery drone. Or floods the picture with a thousand fake aircraft and destroys the operator's ability to trust any of it.
The cryptographic layer is already a published standard. The IETF's DRIP working group exists to make Remote ID trustworthy (charter) and has shipped it: RFC 9374 defines the DRIP Entity Tag, an identifier that is a public-key commitment. RFC 9575 — Standards Track, June 2024 — proves the aircraft holds the private key by signing unpredictable data, defeating replay, and chains the identity to registered endorsers. RFC 9153 sets requirements; RFC 9886 the registries.
RFC 9575 states the problem outright: existing Remote ID regulations and standards "do not address trust." The token, the person-and-organization hierarchy, the endorsement chain, the anti-replay proof — all written, standardized, and mandated nowhere.
The gap is not invention. It is adoption.
This is simultaneously aviation infrastructure and national security infrastructure — which is exactly why it has never been built. Layers 1–3 belong to the FAA. Layers 4–6 belong to DHS, DOJ, and DoD. The handoff is where the program lives or dies.
Issue cryptographic identities to aircraft, operators, and organizations. Maintain endorsement chains and revocation.
The aircraft continuously proves possession of its private key over the air, with unpredictable signed data.
Collect, correlate, and distribute the airspace picture to authorized parties across service suppliers.
Fuse radar, RF, EO/IR, and acoustic tracks. Match what sensors see against what the sky claims. Flag every mismatch.
Intercept, net, tow, and seize the airframe intact. Preserve chain of custody for prosecution.
Encrypted, air-gapped interceptors that collect forensic evidence in flight, coordinate over a closed mesh, and drive pattern-of-targeting analysis.
The statute already authorizes exactly this sequence — and stopping short of force is what makes the program legally clean, operationally superior, and politically survivable.
§124n(b)(1)(A)Detect, identify, monitor, and track, without prior consentMap§124n(b)(1)(B)Warn the operator — including through the Remote ID broadcast channelWarn§124n(b)(1)(C)Disrupt control of the aircraftSkip§124n(b)(1)(D)Seize or exercise control of the aircraftCapture§124n(b)(1)(E)Seize or otherwise confiscate the aircraftForfeit§124n(b)(1)(F)Use reasonable force to disable, damage, or destroyNeverCounter-drone authority lives in 6 U.S.C. §124n, which shields agencies from statutes that would otherwise make interception illegal — the Wiretap Act, the Computer Fraud and Abuse Act, the Aircraft Sabotage and Aircraft Piracy Acts. The SAFER SKIES Act, enacted December 2025 in the FY2026 NDAA, extended that authority to September 30, 2031 and for the first time gave state, local, Tribal, and territorial law enforcement mitigation power (Congressional Research Service). A DOJ/DHS Interim Final Rule became legally effective July 1, 2026 (Crowell, Homeland Security Today), with Tier 1 detection certified online and Tier 2 mitigation requiring in-person training at the FBI's National Counter-UAS Training Center.
The Fortem DroneHunter F700 does not jam and does not spoof. It pursues, fires an expanding tethered net, and tows the capture to a forensics recovery point — or lowers it under a parachute. Guidance comes from an onboard AESA radar with no ground-based cue required, and it has captured platforms larger than itself, including the Orlan-10 and the Shahed-136 (UAS Feed). Net interception is a maturing category, not one vendor: ParaZero DefendAir is shipping for critical infrastructure and ARGUS A1-Falke is adding lidar for terminal precision.
Jamming is already obsolete against the threat that matters. A drone flying a GPS-waypoint mission carries its profile onboard and transmits nothing — no datalink to sever, no uplink to overpower, no signal to intercept. Both sides in Ukraine adapted commercial drones to fly RF-silent for exactly this reason. Net capture is spectrum-independent: a propeller catches the mesh, motors stall under load, lift is lost — effective against autonomous, fiber-tethered, and swarming systems (technical guide).
And capture is the only effect that preserves evidence. A netted airframe arrives intact with SD cards, flight logs, and payload available. Shooting a drone down ends one incident. Capturing it starts an investigation — operator, launch point, route, target, payload, and if it is part of a coordinated effort, the rest of the network. Do that a hundred times and you are no longer defending airspace incident by incident; you are mapping an adversary's entire program.
Destruction also destroys deterrence. A drone that disappears in a fireball is deniable. A drone sitting in an evidence locker with its flight log intact is not.
Our interceptors are not nets on rotors. Each one is an encrypted, air-gapped flying forensic node that carries its own attested identity, talks only to its own fleet over a closed mesh, and begins documenting the target the moment it launches. By the time the net fires, we already have the profile. The capture just confirms it.
| Collection | What it yields |
|---|---|
| RF fingerprint (raw I/Q) | Hardware-level identity of the transmitter, independent of any claimed ID |
| Control-link characterization | Protocol, hopping pattern, whether the aircraft is RF-silent and autonomous |
| EO/IR imagery | Airframe type, payload, modifications, markings |
| Acoustic signature | Motor and propeller class — useful when RF is absent entirely |
| Kinematic track | Launch bearing, route, loiter points, target dwell time |
| Attestation transcript | Exactly how and when identity verification failed — the legal predicate |
The RF fingerprint is the load-bearing one, and it is real science. Fingerprinting extracts nuanced but sufficiently detailed characteristics from a received signal (arXiv). Ensemble models like DrIfTeR detect and classify drones purely from RF fingerprints; wavelet analytics have been benchmarked for the same task; CrossRF attacks the generalization problem directly. There is even prior art for the inverse — AirID injects a deliberate RF signature into transmitted I/Q samples to mark authorized aircraft.
Why this is a genuine advance: a cryptographic token can be absent, but an RF fingerprint cannot be. A drone that refuses to identify itself still radiates a hardware signature. Pair attestation — what it claims — with fingerprinting — what its transmitter is — and you can recognize the same physical airframe across separate incidents weeks apart, even if it never broadcasts a valid token once. That is what turns individual captures into a case file.
Fully air-gapped end to end. Onboard encrypted vault, mesh-only coordination, recovery to an on-premise forensic lab. No cloud dependency of any kind. The configuration for contested environments.
After recovery, evidence crosses a data diode into an Azure confidential-computing enclave. The hardware is physically incapable of bidirectional transmission — no return pathway, no reverse communication (Nexor, NATO).
Real-time streaming during flight. Faster analysis and remote human review, at the cost of a jammable, detectable, attackable dependency. Fine for a stadium perimeter. Never the default — falls back to Tier A the instant the link degrades.
The destination side exists at government classification levels today. Azure Confidential Computing reached general availability on AMD SEV-SNP virtual machines across all U.S. government data classification levels (Microsoft Azure Government), hardening the environment against the host, the hypervisor, the host administrator, and even your own VM administrator (Microsoft Learn). Microsoft Sovereign Cloud adds data-residency and operational-sovereignty controls. The Azure forensics layer belongs on the far side of a diode — not on the airframe.
This is the most operationally valuable capability in the program, because it addresses a harm that is already happening and already prosecutable.
Drone harassment and stalking are crimes under existing law, and local stalking, trespass, and harassment statutes have already secured convictions without waiting on the FAA (DRONERESPONDERS). In Rockingham County, Virginia, a man was charged with two counts of spying using an electronic device, four counts of entering a property to harass using a drone, and two counts of stalking with fear of death or assault (Police1). Practitioners note there is no single drone law for this — ordinary trespass, voyeurism, harassment, and stalking statutes get applied to drone facts, and the civil/criminal line generally turns on intent and repetition (Watkins).
Read that last clause again. Intent and repetition. Repetition is exactly what the Sovereign Fleet produces. A single overflight is ambiguous. Nine overflights of the same residence at the same hour across three weeks, tied to one RF fingerprint, is a stalking case with the element of repetition already proven. Today victims cannot establish that pattern because nobody is recording it.
The analysis profiles drone behavior, not residents. It must never become a standing database of who lives near what. A targeting analysis for a private individual is opened on that individual's complaint or consent, or under a protective order — never as ambient monitoring of a neighborhood. Aggregate pattern analysis runs against protected facilities and critical infrastructure, which have institutional standing to consent.
Build it the other way and you have created the surveillance system this project family exists to argue against — and it will be attacked on exactly those grounds. Victim-initiated, consent-scoped, and audit-logged is both the ethical design and the survivable one.
Millions of aircraft already fly with unsigned Remote ID. Signing needs key storage and compute, and Bluetooth message budgets are tight — which is why RFC 9575 needed a specialized wire format. A hard cutover orphans a large legacy fleet.
The hardest politics. DoD will not publish keys that let anyone geolocate sensitive operations. The workable answer is a separate hierarchy: valid token, restricted attribution, resolvable only by cleared authorities.
RF fingerprinting degrades across channel conditions and hardware batches. Treat matches as investigative leads with confidence scores — never courtroom-grade identity on their own.
A small interceptor cannot carry a full forensic lab. Lightweight onboard capture, heavy analysis in the ground enclave. Do not promise onboard deep learning at scale.
Secure elements, provisioning, rotation, revocation across an intermittently connected mesh, recovery when an interceptor is lost. This is where sovereign systems usually fail.
A national attestation registry is a large, sensitive identity database. The existing Remote ID Session ID precedent is the answer: public observers see a rotating pseudonym, authorities resolve identity only through the registry.
The standards are public and the crypto is implementable. Steps 1–4 run on your own hardware with no special permissions — and step 4 alone is the artifact that convinces a policy audience.
A local-first registry that mints RFC 9374 DRIP Entity Tags for simulated operators, organizations, and aircraft, with an endorsement chain and revocation list.
Emit ASTM F3411-style Remote ID messages plus RFC 9575 Authentication Messages with real signatures, over Bluetooth or Wi-Fi beacons.
Receive broadcasts, validate signature chains, and classify each contact as attested, unattested, expired, revoked, or spoof-suspected.
Run the public spoofer against your own verifier. Side by side: today's unsigned rule collapses, DRIP holds. This is the demo.
Feed in a synthetic sensor track and detect a drone whose signed position claim disagrees with observed position — the non-cryptographic validation RFC 9575 requires.
A clean-sky dashboard where attested traffic renders normally and everything else escalates, with an immutable evidence log.
The layer-2-to-layer-6 bus that exists nowhere. Classify contacts, apply the escalation ladder, and assign interceptors against multiple simultaneous unattested tracks.
Per capture: attestation failure proof, fused sensor track, intercept log, recovery point, hash chain. Cryptographic custody pointed at an airframe instead of a ballot.