First identify what was actually lost
The phrase "lost signal" can refer to several different failures. The first
discipline is to name the affected function instead of inferring it from one
screen symptom.
Scroll horizontally to compare all columns.
The companion guide to
C2, telemetry, payload data, and video
explains these functional boundaries in detail. The distinction matters because
a response meant for one failure can be hazardous when another is occurring. For
example, commanding a return based on a navigation problem is a different
decision from allowing a preplanned return after verified C2 loss.
Remote ID, detect and avoid, UTM, navigation, and C2 also serve different
purposes. The
Remote ID, DAA, and UTM comparison
helps keep those services separate. A contingency analysis can identify their
dependencies without treating one as a substitute for another.
Lost link has causes at several layers
A communications path can degrade or fail because of radio propagation,
installed hardware, power, software, network infrastructure, configuration, or
the operator interface. A useful investigation works through the chain rather
than selecting the most visible cause.
Geometry and propagation: terrain, structures, foliage, aircraft attitude,
antenna orientation, airframe masking, and route geometry can change the usable
path. A coverage statement that omits aircraft installation and flight geometry
is incomplete.
Interference and congestion: intentional or unintentional radio-frequency
energy can reduce availability. Shared network capacity can also change with
load. The symptom may be intermittent delay or loss rather than a clean
disconnect.
Hardware and power: an antenna, cable, connector, modem, onboard computer,
ground station, or power source can fail or restart. Two bearers that share one
component may disappear together.
Software and configuration: incompatible versions, expired credentials,
incorrect routing, a process crash, an unintended mode, or a bad parameter can
interrupt the service even when signal strength looks adequate.
Network and infrastructure: carrier handovers, provider outages, satellite
or terrestrial coverage transitions, backhaul, identity services, and other
off-aircraft dependencies can interrupt an end-to-end path.
Human interface: a stale display, frozen application, incorrect vehicle
selection, or ambiguous alert can make a functioning link appear unavailable, or
make a failed link appear healthy.
A NASA technical memorandum on
UAS flight-demonstration best practices
observed that short interruptions can follow temporary antenna blockage or
interference, while an equipment failure can produce a longer loss. It also
recommends examining route, infrastructure, antenna placement, terrain, and
obstructions before flight. These are research-derived practices, not universal
thresholds or proof that one cause applies to a particular event.
Define states, not just a timeout
A robust lost-link concept describes observable states and transitions. The
exact thresholds and timing are aircraft- and operation-specific, so this model
intentionally contains no numbers.
Scroll horizontally to compare all columns.
Detection can use message acknowledgements, age or freshness, delivery quality,
path status, and aircraft-state information. A threshold should be tied to a
hazard and tested configuration. Hysteresis or persistence logic may help
prevent rapid switching near a boundary, but it can also delay a necessary
transition. Neither an instantaneous switch nor a delayed switch is inherently
correct without the operational case.
The state shown to the crew must mean something specific. "Weak," "connected,"
or a set of signal bars is insufficient unless the interface explains which
service is measured, over what interval, and what action the aircraft has taken.
Logs should preserve the underlying events so a later review does not depend on
memory or a screenshot.
Response options have different hazards
The FAA's current
waiver and authorization application instructions
ask applicants to identify the C2 link type, a lost-link latency threshold in
seconds, and a procedure type. The page lists examples including continued
flight, hover, return, holding, landing at a designated waypoint, and immediate
landing. It asks separately about navigation failure or degradation.
Those are examples of information an applicant may need to provide. They are not
a ranked menu or FAA endorsement of one response for every drone.
Scroll horizontally to compare all columns.
The final row is a formal concept found in some authorized operations, not an
instruction to disable an aircraft. Improvised shutdown or deliberate live
link-loss testing can create immediate hazards. Any such function, test, or
procedure belongs under the applicable manual, approval, controlled test plan,
and qualified authority.
Return-to-home deserves particular skepticism because familiarity can make it
feel universal. A return path can climb into an obstacle, cross unsuitable
airspace, consume energy against the wind, rely on a bad home location, or move
the aircraft over people who were not exposed on the outbound route. The right
question is not whether the aircraft has a return button. It is whether the
configured response remains the least hazardous acceptable behavior for the
specific route and conditions.
The operation determines the contingency
NASA's flight-demonstration memorandum notes that when all C2 is lost, onboard
automation and the lost-link procedure must assume functions the pilot had
performed. It also warns that a mitigation can introduce a new hazard. Factors
include traffic or detect-and-avoid dependencies, terrain, weather, air traffic
coordination, and risk to people on the ground.
That does not make a fixed lost-link sequence autonomous. A predetermined
response to a predetermined trigger is automation, even if it is complex. The
automation and authority framework
shows how to identify the actual decision, constraints, authority holder, and
transitions without using hands-off flight as the test.
For each route or operating area, the contingency review should account for:
- expected aircraft state and remaining energy at different points;
- terrain, structures, vegetation, and route containment;
- current and forecast conditions relevant to the response;
- people, property, and suitable landing or diversion areas;
- airspace, traffic, and any crew or air traffic coordination;
- navigation validity and the source of home or alternate coordinates;
- whether DAA, weather, map, or other data remain available after C2 loss;
- primary and alternate communications dependencies;
- aircraft mode logic, limits, and recovery authority;
- changes that invalidate earlier evidence.
The result may vary by mission segment. That does not justify an improvised
procedure. It means the approved logic must cover the relevant states and make
the transitions predictable to the crew and, where applicable, other airspace
participants.
Preflight review should close the full chain
For US small-UAS operations,
14 CFR 107.49
requires the remote pilot in command to brief specified operating and emergency
information and ensure that control links between the ground control station and
aircraft work properly before flight. The regulation does not prescribe one
lost-link mode.
A mission-specific preflight record can verify:
- the exact aircraft, control-station, radio, software, firmware, and parameter
configuration;
- the expected primary and alternate paths, including shared dependencies;
- the configured degraded- and lost-link criteria;
- the response associated with each relevant mission segment;
- current route, home, alternate, altitude, and containment information under
the applicable plan;
- aircraft-state and acknowledgement indications the crew will use;
- crew roles, communication, escalation, and external coordination;
- power, weather, traffic, terrain, and ground-risk assumptions;
- the evidence that the transition and recovery behavior were verified;
- the changes that require re-review before launch.
A green connection icon can support item one only in a limited way. It does not
show route-wide availability, alternate-path independence, threshold validity,
or what the aircraft will do later.
Validate transitions without creating an uncontrolled event
Evidence can come from analysis, simulation, bench or hardware-in-the-loop work,
controlled range testing, and authorized flight testing. Each method has a
boundary. A simulation can exercise states repeatedly but is only as credible as
its models. A bench test can verify messages and mode logic without representing
installed antennas or route geometry. A controlled flight test can represent
more of the integrated system but needs its own hazard controls and
authorization.
The verification record should identify the configuration, test condition,
trigger, observed aircraft state, crew indication, timing, path transition,
recovery behavior, result, discrepancy, and reviewer. It should cover false or
brief indications as well as sustained loss, because bouncing between states can
be as confusing as a clean outage. No reader should intentionally interrupt an
operational aircraft's link based on this article.
Security and resilience questions belong in the same evidence package without
being collapsed into signal strength. The
BVLOS communications security guide
examines authentication, integrity, availability, redundancy, and common-mode
dependencies at a non-sensitive level.
Understand the ATC lost-link context
The FAA's current air traffic control order includes a specific
UAS lost-link section.
It says Code 7400 may be transmitted when the control link is lost, and that the
programmed procedure is associated with the flight plan. Controllers determine
the procedure from the relevant Special Airworthiness Certificate or Certificate
of Waiver or Authorization. The order says each procedure can differ by airframe
and operation.
That material is for the applicable ATC and authorized-operation context. It is
not a general instruction that every Part 107 drone should transmit 7400 or use
the route, orbit, altitude, communication, or termination concepts described in
an ATC order. It reinforces the central lesson: the procedure is known,
operation-specific, and coordinated before the event.
Separately,
14 CFR 107.19
makes the remote pilot in command directly responsible for and the final
authority over a Part 107 operation. It requires the ability to direct the small
unmanned aircraft and requires that the operation pose no undue hazard if
control is lost. It does not select return, hold, divert, or land for the pilot.
After an event, reconstruct before concluding
A post-event review should align aircraft logs, ground-station events, network
records, crew observations, configuration, and the planned state model on one
timeline. Preserve raw evidence before updates or repeated tests change the
configuration. Determine which function failed, when the system declared each
state, what the aircraft executed, what the crew saw, whether an alternate path
worked, and whether recovery matched the approved logic.
Do not convert correlation into cause. A video freeze before a return does not
prove video loss triggered the return. Low displayed signal strength does not
prove interference. A restored application does not prove the aircraft link
failed. Record what is verified, what is attributed to a system log or crew
report, and what remains an engineering inference.
A defensible lost-link procedure joins four things: a clearly defined C2-loss
condition, a mission-specific aircraft response, crew and coordination actions,
and evidence that the transitions behave as intended in the controlled
configuration. If any one is missing, "it comes home" is not yet a complete
contingency case.