Security of DJI LTE Enhanced transmission (RESERVED)
Category: Vulnerability research
Location: any
Contact:
Daniel Hulliger
DJI’s Enhanced Transmission dynamically combines its proprietary OcuSync link with 4G; if OcuSync becomes unavailable, 4G can carry bidirectional video and command traffic through a relay service. This adds a cellular modem, SIM and mobile operator, Internet connectivity, relay infrastructure, and cross-link state transitions as potential attack surfaces for an adversary.
Objectives
- Map the architecture: Document all components, protocols, data flows, identities, and trust relationships across the drone, cellular dongle, controller/mobile device, network, and relay infrastructure.
- Assess authentication & crypto: Evaluate how pairing, authentication, session establishment, and key management are implemented, and empirically verify their confidentiality, integrity, and freshness guarantees.
- Test link-transition security: Analyze system behavior and security state during transitions between OcuSync-only, hybrid, and 4G-only modes.
- Identify vulnerabilities: Discover exploitable weaknesses or unsafe design assumptions in the end-to-end Enhanced Transmission path.
Requirements
- Hardware security.
- Experience in reverse engineering.
- Mindset to learn the additional skills.