The C2 definition, with one terminology caveat
The
ICAO unmanned-aviation terminology
defines the C2 link by purpose: the data link between a remotely piloted
aircraft and its remote pilot station for managing the flight. The definition
does not prescribe a frequency, protocol, network, or number of radios.
In aviation standards and spectrum work, C2 is often discussed as command and
non-payload communications, or CNPC. The
ITU-R UAS characteristics and spectrum report
describes commands sent toward the aircraft and non-payload telemetry returned
toward the control station. It treats the mission payload as a separate
subsystem while recognizing that information types can share a physical link.
This creates a vocabulary trap. Flight telemetry can be part of a C2 or CNPC
service, but operators also call payload status and other downlink messages
telemetry. Name both the function and the message. C2 aircraft-state
telemetry is more precise than data. Payload health telemetry avoids
implying that every status field manages the flight.
The public summary for
RTCA DO-362A, a
terrestrial CNPC minimum operational performance standard, also distinguishes
mission payload communications from safety-of-flight information. The summary
does not substitute for the standard, and the standard is not applicable to
every drone. It supports the functional boundary: mission content and
flight-management information are not interchangeable merely because they share
transport.
Separate the roles before assigning them to hardware. Actual message sets and
consequences depend on the aircraft, operation, and system design.
Scroll horizontally to compare all columns.
Video is data, but it deserves a separate row because its sustained rate and
compression behavior often dominate a link budget. It also attracts attention on
an operator display. Neither fact makes it C2.
The consequence of video loss depends on its intended function. A payload
preview may degrade while full-quality imagery continues to record onboard. If
an operation relies on video for a defined safety function, that function needs
specific performance, indication, and failure evidence. The label "situational
awareness" does not establish those properties.
C2 is bidirectional even when commands are small
It is tempting to call the uplink C2 because commands travel toward the
aircraft. Usable control normally depends on the return path too. The operator
needs to know the current mode, whether the aircraft accepted a command, and
whether displayed state is fresh enough for the next decision.
Consider a mode-change request. Several distinct events occur:
- The ground application creates a request from an authorized source.
- The transport delivers it to the intended aircraft and component.
- The receiving system checks identity, freshness, permissions, parameters, and
current state.
- The flight system accepts or rejects the command.
- A return message reports receipt, acceptance, rejection, progress, or final
state.
- The display presents that result without implying more certainty than the
message supports.
A button changing color can confirm a local user-interface action without
confirming aircraft receipt. Receipt can occur before the requested state is
reached. Requirements should state what each acknowledgement means, which
component produced it, and how long it remains useful.
This remains true when most flight control is onboard. A waypoint-following
aircraft may receive only occasional route changes, approvals, holds, or landing
requests. Low average command rate does not mean low consequence. The
automation and autonomy decision test
addresses who retains authority over those decisions.
A service is not the bearer that carries it
A service is the functional exchange. A bearer is the transport path.
The bearer might be a direct radio, carrier network, satellite service, mesh, or
a route crossing several networks. One bearer can multiplex C2, payload control,
mission data, video, and maintenance traffic. A service can also move between
bearers.
The
RF, LTE, satellite, and mesh comparison
evaluates transport choices without treating one as universally superior. The
Starlink integration analysis applies the same
distinction to one satellite-terminal class.
The FCC's
2024 UAS spectrum order
created an initial Part 88 framework for UAS communications in the 5030 to 5091
MHz band. The FCC tied that work to reliable two-way flight-control and
telemetry communications, and it separated control-related communications from
payload traffic. The order did not establish that every use of the band meets a
particular operation's C2 requirements.
A shared bearer can reduce hardware and use capacity efficiently. It also
creates coupling. Payload bursts, modem restarts, antenna obstruction, provider
outages, or software faults can affect several services at once. The design must
state how traffic is classified, prioritized, limited, monitored, and degraded
when capacity falls.
The
payload integration interface gate
addresses the same boundary from the payload side. A sensor is not integrated
merely because it powers on and emits data. Its traffic, control authority,
timing, failure behavior, and resource demand need explicit assignments.
Range and peak throughput are easy to quote. Neither is a complete C2
requirement. A
NASA assessment of C2 communications for UAS traffic management
identifies latency, handover, packet error and loss, dropouts, coverage gaps,
received signal, and interference as relevant assessment dimensions. It does not
prescribe universal pass values.
Scroll horizontally to compare all columns.
Relevant values come from consequence and operational context. A small command
that changes flight state may have a short useful life. A large mapping file may
tolerate delayed delivery. A video stream can consume more capacity while having
lower consequence in one mission, then become operationally important in
another. The function, not the packet size, drives the requirement.
NIST's current
UAS communications research portfolio
examines licensed cellular, unlicensed links, mesh behavior, interference,
latency, packet loss, and robustness in public-safety contexts. It is not a
validation of one link type. It shows why evidence needs a named technology,
configuration, environment, traffic load, and measured outcome.
Bandwidth management should follow consequence
When C2 and payload traffic share a constrained path, behavior under congestion
must be designed before flight. Options include reserving capacity, limiting
payload rate, adapting video, storing full-resolution data onboard, or pausing a
nonessential transfer. The mechanism depends on the architecture. The important
point is that consequential traffic should not receive service by accident.
The
drone bandwidth requirements guide
shows how to estimate sustained, peak, and degraded-state demand in each
direction.
A
NASA memorandum on UAS flight-demonstration practices
describes an alternate link that can have greater latency and less capacity than
the primary. It recommends prioritizing C2 over payload data when that alternate
carries both. This is a research-derived practice, not a universal certification
rule. It exposes two requirements for any shared design: what is preserved under
degradation, and what test demonstrates that the priority mechanism works.
Onboard recording can preserve mission data, but it cannot replace C2. It helps
only if the aircraft and storage are recovered, the recording is complete, and
delayed access still meets the mission. A low-rate preview plus onboard
full-resolution capture can reduce transport demand without demonstrating
command integrity or C2 availability.
Redundancy requires independence
Two radios are not necessarily two independent C2 paths. They can share an
antenna location, power rail, flight computer, router, provider gateway, ground
station, credential service, or software process. One obstruction, restart,
configuration error, or account failure can then remove both.
Review independence layer by layer:
- onboard power and isolation;
- antenna position, orientation, and airframe masking;
- radio, modem, and firmware;
- frequency and propagation assumptions;
- terrestrial, satellite, or other provider infrastructure;
- backhaul, routing, identity, and ground-station services;
- software responsible for selection and state indication;
- information sources, including navigation or traffic data; and
- transition, recovery logic, and operator authority.
An alternate path can also add latency, use less capacity, or introduce a new
provider dependency. State which failure it covers, what it shares with the
primary, how transition is detected, and what service remains after transition.
Security is separate from redundancy. A second unauthenticated path can preserve
connectivity while increasing exposure. The
secure BVLOS communications guide
separates confidentiality, identity, integrity, availability, monitoring, and
recovery.
Link state should name the affected function
"Connected" and "disconnected" are too coarse for a system carrying several
services. Useful indications distinguish required C2 status, command round-trip
health, the age and validity of aircraft state, payload-service state, active
bearer, and alternate-path transitions. They should also distinguish a ground
display failure from an air-ground communications failure when the evidence
allows.
A system may move through nominal, degraded, alternate, lost, contingency, and
recovered states. Each label needs observable entry and exit criteria, an owner
for the transition, operator indication, and recorded evidence. Signal bars or
the presence of video do not define those states by themselves.
What the aircraft does after declared C2 loss is a separate, mission-specific
decision. The
UAS lost-link procedures guide owns the
contingency logic. The
C2 interface-control guide owns the
signals, timing, acknowledgements, and system boundaries that support detection
and transition.
For every required flow, document:
- source, destination, and authorized originator;
- message content, units, identifier, and update behavior;
- normal, peak, and worst-case useful rate;
- maximum useful age, latency, and variation;
- acknowledgement meaning and command-state transitions;
- integrity, authentication, confidentiality, and replay requirements;
- availability and coverage assumptions;
- priority when capacity is constrained;
- response to delay, corruption, duplication, reordering, or loss;
- operator indication, authority, and recovery method;
- logging needed to reconstruct an event; and
- the hardware, software, network, and operating configuration covered by the
evidence.
Then map the flows to the installed bearers and their shared components. A
diagram should expose common dependencies, not only show several colored arrows.
A test matrix should cover nominal load, constrained capacity, stale messages,
path loss, transition, and restoration at named observation points.
For US operations under Part 107,
14 CFR 107.49
requires the remote pilot in command to ensure before flight that control links
between the ground control station and small UAS work properly. That preflight
requirement does not turn one green status indicator into evidence of route-wide
coverage, security, independence, or failure recovery.
A defensible link claim therefore has four parts: the named information
function, the configured transport that carries it, the performance and failure
behavior required by the operation, and evidence collected under defined
conditions. With those parts explicit, a design can evaluate radios, data rate,
and video quality without confusing mission data with control of the aircraft.