Summary
The Indian Army is establishing six AASHVAST labs across the country to test drones - and eventually CCTV cameras - for firmware-level vulnerabilities, moving beyond physical inspection and invoice-based origin checks. Developed by QuickPay Pvt Ltd for the Directorate General of Electronics and Mechanical Engineering, the suite can detect roughly 14 types of hidden faults, including geospatial blocks, hidden codes and time-based bugs that could disable a drone during operations.
WHY IN NEWS FOR UPSC & STATE PCS
With the first AASHVAST lab inaugurated in Delhi and five more planned, the Army is responding to concerns that Chinese-origin electronic components could be embedded in drones despite invoices showing other countries of origin, following a 2025 Army Design Bureau framework aimed at eliminating Chinese-origin parts from UAVs.
Standard News
Checking the Invoice Was Never the
Same as Checking the Silicon Here's what's actually happening with AASHVAST: for years, the Army's check on a drone's origin was essentially a paperwork check - the invoice said where a component was purchased from and that was treated as proof of where it came from.
The problem is that an invoice tells you where money changed hands, not what code is actually sitting inside the chip. A component bought through a third country or relabelled along the way, could still carry firmware written somewhere else entirely - and there was no mechanism to check.
The Mechanism That Actually Changed
AASHVAST closes that exact gap by testing the firmware itself rather than the paperwork trail. Firmware is the low-level code baked into a hardware component that controls what it actually does - and vulnerabilities can be planted there during manufacturing or an upgrade, as hidden commands that trigger only under specific conditions.
The labs are built to catch roughly 14 categories of these: geospatial faults that make a drone malfunction over a certain location, hidden or unused code that can terminate a mission early and time-or-location bugs that let a component behave normally until a specific trigger condition is met.
None of this is visible by opening the drone and looking at it - it only shows up when the firmware is actually run through validation.
Why "Made in India" on an Invoice Isn't Enough This is the
sharper point buried in the story: a component can be procured with paperwork showing an Indian or third-country origin while the actual silicon inside was designed or manufactured elsewhere, because the invoice only reflects the point of purchase, not the true supply chain.
That is precisely why the Army has, in the past, banned Chinese-made parts outright rather than trying to vet them - outright bans were the only enforceable check available before a tool like AASHVAST existed. Now, firmware validation gives the Army a way to catch what a ban-by-origin-label approach would miss: components that were never declared as Chinese-origin in the first place.
The limit here is worth being honest about: firmware testing catches what the suite is built to look for - roughly 14 known categories of vulnerability. It is not a guarantee against every conceivable hidden threat and it depends on the testing suite itself being kept current as adversaries adapt.
For the exam, the real shift isn't "India worries about Chinese components"
- that's old news. It's that Indian defence procurement has moved from trusting where something was bought to actively verifying what it does, treating hardware the same way cybersecurity teams have long treated software: as something that must be tested, not assumed trustworthy.
Quick Facts
Key numbers & takeaways — revise these first
-
AASHVAST stands for Assessment and Analysis of Electronic Systems Hardware for Vulnerabilities and Security Threats.
-
Six labs are planned; the first was inaugurated in Delhi in August 2026.
-
The suite was developed by QuickPay Pvt Ltd for the Directorate General of Electronics and Mechanical Engineering.
-
It can detect approximately 14 types of firmware vulnerabilities.
-
The Army Design Bureau submitted a framework to the Ministry of Defence in 2025 to eliminate Chinese-origin components from UAVs.
Connect the dots for your UPSC preparation.
Standard news covers the event. Log in to read our comprehensive analysis and uncover the hidden constitutional, structural, and ethical dimensions of this topic:
The full list logic behind the roughly 14 vulnerability types AASHVAST is built to detect, including how geospatial and time-based bugs actually work.
Why the 2025 Army Design Bureau framework to eliminate Chinese-origin parts couldn't fully solve this problem on its own.
How CCTV camera testing will extend the same firmware-validation logic beyond drones to a much wider category of Army-procured electronics.
The specific limits of firmware testing as a defence and what it would take to keep the suite current against new hidden-threat techniques.
Included in this analysis
Join thousands of aspirants analyzing the news deeply.
Unlock Premium — Rs.699 AnnuallyDon't have an account? Sign up for free