Identify which function was lost
"Lost signal" can describe several different failures. Name the affected
function before selecting a response:
- C2 uplink loss: the aircraft is not receiving valid commands.
- C2 downlink or required telemetry loss: the crew cannot confirm the state
needed to manage the flight.
- Video loss: the payload or pilot view is unavailable, although other
control and state paths may remain.
- Payload-data loss: the mission product is not reaching the ground, while
flight management may still work.
- Ground-application failure: the aircraft path may work while the operator
display or software does not.
- Navigation degradation: the aircraft may communicate normally but lack a
trustworthy position or guidance input.
The UAS data-link roles guide separates C2,
telemetry, payload control, payload data, and video. The distinction matters
because an aircraft response intended for communications loss can be hazardous
when the underlying problem is invalid navigation.
Remote ID, detect and avoid, UTM, and navigation are also not C2 substitutes.
The
Remote ID, DAA, and UTM comparison
helps keep their functions and dependencies separate.
Trace failures through the full path
A communications service can degrade at several layers:
- Geometry and propagation: terrain, structures, foliage, aircraft attitude,
antenna orientation, airframe masking, and route geometry change the path.
- Interference or congestion: radio energy or shared network loading can
cause delay and intermittent loss rather than a clean disconnect.
- Hardware and power: antennas, cables, connectors, modems, routers, onboard
computers, ground stations, and power sources can fail or restart.
- Software and configuration: incompatible versions, expired credentials,
routing errors, process faults, and incorrect parameters can interrupt
service.
- External infrastructure: carrier handoffs, provider outages, satellite or
terrestrial coverage transitions, gateways, and backhaul can fail.
- Human interface: stale data, a frozen application, an incorrect vehicle
selection, or an ambiguous alert can conceal the actual aircraft state.
NASA's memorandum on
UAS flight-demonstration best practices
describes short interruptions associated with temporary blockage or interference
and longer loss associated with equipment failure. It also emphasizes route,
infrastructure, antenna placement, terrain, and obstruction review. Those are
research observations from specific demonstrations, not universal timeout
values.
Define a state machine, not one timer
A useful lost-link concept defines observable states and permitted transitions.
The thresholds remain aircraft- and operation-specific.
Scroll horizontally to compare all columns.
Detection can use command acknowledgements, message age, delivery quality, path
state, and aircraft-state data. Signal bars alone are rarely enough. The display
should identify which service is measured, the interval behind the indication,
the current aircraft mode, and whether an alternate path is active.
Persistence or hysteresis can prevent rapid switching near a threshold, but it
can also delay a necessary transition. The evidence has to show that both brief
and sustained conditions produce the intended result. Recovery needs equal care:
a returned carrier signal is not proof that endpoint identity, message
freshness, and aircraft state are valid.
Choose the response by its hazards
The FAA's current
Form 7711-2 application instructions
ask applicable applicants to identify the C2 link type, a lost-link latency
threshold in seconds, and the procedure type. Examples include continued flight,
hover, return, holding, landing at a designated waypoint, and immediate landing.
The list is not a ranking or an endorsement of one response for every drone.
Scroll horizontally to compare all columns.
Return deserves particular scrutiny because familiarity can make it look
universal. A return path can climb into an obstacle, cross unsuitable airspace,
consume energy against the wind, depend on a wrong home point, or expose people
who were not beneath the outbound route. The useful question is whether the
configured path remains an accepted response for the aircraft state and current
mission segment.
Build the contingency by mission segment
NASA's flight-demonstration memorandum notes that, after complete C2 loss,
onboard automation and the lost-link procedure must take over functions the
remote pilot had performed. It also warns that a mitigation can create a new
hazard. That makes route context part of the design.
For each segment or operating area, record:
- expected aircraft mode, altitude, groundspeed, and remaining energy;
- terrain, structures, vegetation, and containment boundaries;
- wind and other conditions material to the response;
- people, property, and suitable landing or diversion areas;
- airspace, traffic, detect-and-avoid, and coordination dependencies;
- navigation validity and the source of home or alternate coordinates;
- weather, map, or network data that may disappear with the C2 path;
- primary and alternate communications paths and shared components;
- aircraft mode logic, limits, and recovery authority; and
- configuration or environmental changes that invalidate prior evidence.
The response may legitimately vary by segment. That does not imply an improvised
decision after the link is gone. It means the controlled configuration includes
the relevant states, boundaries, and transitions.
A fixed trigger and programmed sequence are automation, even when the sequence
is complex. The
automation and authority framework
explains why hands-off behavior alone does not establish autonomy.
Align aircraft behavior with crew actions
For every transition, the crew procedure should state:
- the indication that starts the action;
- which service or function that indication represents;
- the expected aircraft state and next transition;
- the operator action, if any, and who has authority;
- communication with other crew or external parties;
- the limit after which the procedure escalates;
- the criteria for accepting a restored link; and
- the event record to preserve.
Avoid using one icon to represent aircraft link, provider connection, payload
video, and ground application health. If the aircraft changes mode, the display
and log should show which rule caused the change and whether a command was
acknowledged.
The
secure BVLOS communications guide
connects authentication, availability, alternate-path independence, and recovery
to this state model. A link can return physically while remaining unusable
because its credential, routing, or endpoint state is wrong.
Close the preflight chain
For U.S. Part 107 operations,
14 CFR 107.49
requires the remote pilot in command to brief specified operating and emergency
information and ensure before flight that control links between the ground
control station and aircraft work properly. It does not prescribe one lost-link
mode.
A mission-specific record can verify:
- aircraft, control-station, radio, software, firmware, and parameter versions;
- expected primary and alternate paths, including shared dependencies;
- degraded- and lost-link criteria and their displayed meaning;
- response logic for each relevant route segment;
- home, alternate, route, altitude, and containment data;
- aircraft-state and command-acknowledgement indications;
- crew roles, communication, escalation, and external coordination;
- energy, weather, traffic, terrain, and ground-risk assumptions;
- evidence that transitions and recovery were verified; and
- changes that require review before launch.
A green connection icon can confirm only a small portion of that list. It does
not establish route-wide availability, alternate-path independence, threshold
validity, or later aircraft behavior. The
C2 interface contract should define
the messages, timing, states, acknowledgements, and recovery boundaries behind
the indication.
Validate transitions in stages
Use a progression appropriate to the consequence and approval context:
- analysis checks route, energy, timing, state, and dependency assumptions;
- simulation exercises many state sequences and boundary conditions;
- software- or hardware-in-the-loop work verifies messages and mode logic;
- bench testing checks the integrated aircraft and ground configuration; and
- controlled, authorized flight testing represents installation and operating
conditions that lower-level methods cannot.
Each method has a boundary. Simulation is only as credible as its models. Bench
tests do not reproduce route geometry. Flight tests add realism and their own
hazards. Deliberately interrupting an operational aircraft's link is not a
substitute for a controlled test plan.
Record the configuration, condition, trigger, observed aircraft state, crew
indication, timing, path transition, recovery behavior, result, discrepancy, and
reviewer. Include brief or bouncing conditions as well as clean sustained loss.
Rapid alternation between nominal and lost states can be harder to manage than a
single outage.
Keep the ATC procedure in context
The current
FAA air traffic control order
has a UAS lost-link section for the applicable ATC and authorized-operation
context. It says Code 7400 may be transmitted after control-link loss and
directs controllers to the programmed procedure associated with the flight plan
and the relevant Special Airworthiness Certificate or Certificate of Waiver or
Authorization. The order also states that procedures differ by airframe and
operation.
That material is not a general instruction for every Part 107 drone to transmit
7400 or adopt the route, orbit, altitude, communication, or termination concepts
used in an ATC order. Its broader lesson is that affected parties know the
operation-specific behavior before the event.
Separately,
14 CFR 107.19
makes the remote pilot in command directly responsible for and the final
authority over a Part 107 operation, and addresses the hazard if control is
lost. It does not select hold, return, divert, or land for a specific aircraft
and site.
Reconstruct an event before assigning cause
After an event, align aircraft logs, ground-station events, network records,
crew observations, configuration, and the planned state model on one timeline.
Preserve raw records before an update or repeat test changes the configuration.
Determine which function failed, when each component declared a state, what the
aircraft executed, what the crew saw, whether an alternate path worked, and
whether recovery followed the defined rules.
A video freeze before a return does not prove video loss caused the return. Low
displayed signal strength does not prove interference. A restarted application
does not prove the aircraft link failed. Separate verified events, system logs,
crew reports, and engineering inference.
A complete lost-link procedure joins four records: a defined C2-loss condition,
a mission-specific aircraft response, coordinated crew actions, and evidence
that the controlled configuration performs those transitions as intended. "It
comes home" covers only one possible behavior, not the contingency case.