A drone is shown, carrying underneath it a white plastic box. On the side of the box are two patch antennas. A camera extends from one end of the box, and a large GPS antenna from the other end.

Synthetic Aperture Radar Drone Gets Interferometric Imaging

It’s been more than a year since [Henrik Forstén] built the first iteration of his synthetic-aperture radar (SAR) imaging drone, and he’s certainly been productive in the meantime. Not only did he develop a much more powerful autofocus algorithm to clean up the radar images, but he also extended the software to create high-resolution interferometric images.

The main limitation of the original radar system was the GPS, which only had a resolution of about one meter; the autofocus algorithm owed much of its improved clarity to an improved estimation of the drone’s position. A simpler, though more expensive, solution was to add an RTK-capable GPS receiver. RTK (Real-Time Kinematic) receivers use a fixed ground station to constantly transmit a correction signal, letting them reach a couple centimeters of accuracy. Since the drone doesn’t actually need to know its position in real time, it can also use PPK (Post-Processing Kinematic) positioning, which compares recorded GPS signals after the flight to obtain similarly accurate positions.

[Henrik] also implemented a few other hardware improvements, including stabilizing the phase-locked loop used to generate the radar’s frequency sweep. The controller FPGA’s SD card interface had too low a bandwidth to record data in real time, so [Henrik] also implemented a simple, fast compression algorithm to speed that up. Most significantly, he also developed a program for interferometric imaging. The drone flies the same path twice at different altitudes; by comparing phase information from different passes, it’s possible to detect a target’s elevation. Normally, the radar program assumes constant elevation, making tall objects seem to lean toward the radar source; an interferogram, on the other hand, allowed [Henrik] to generate a detailed elevation map.

[Henrik] is no stranger to synthetic aperture radar; we’ve previously covered a bike-mounted iteration and a budget SAR system. If the concepts behind this are still a bit fuzzy, we’ve also covered a guide to making your own SAR setup.

A digital map is shown with a series of red waypoints making a roughly C-shaped curve. A smaller group of green waypoints stays stationary near one of the corners of the map.

Defeating Satellite Spoofing With Galileo’s Encryption

Considering how important it is for everything from navigation to keeping clocks in sync, satellite navigation systems are surprisingly vulnerable to a variety of attacks, ranging from simple jamming to more sophisticated spoofing attacks. This may be changing, though, as Galileo, Europe’s GNSS, recently demonstrated its first cryptographically-secured position fix under spoofing conditions.

Most GNSS systems, including GPS, have no verification measures to keep an adversary from transmitting a false signal at a higher power and hijacking a receiver; since GNSS signals are extremely weak by the time they reach the ground, this presents no great difficulty to a moderately well-equipped attacker.

Galileo’s Signal Authentication System (SAS) aims to fix this. The Galileo ground station pre-selects signal spreading codes, which it then encrypts with a regularly-changing secret key and publishes. A receiver which anticipates needing a verified signal can then download these encrypted codes ahead of time and store them. Galileo satellites then transmit on the E6-C pilot signal, and the receiver records the signal. After transmitting a message block, it then transmits the decryption key on a separate signal, which the receiver uses to recover the spreading codes. The receiver then correlates these spreading codes with the recorded signal to find the satellite’s pseudorange.

It’s a rather complicated system, but it works: earlier this month in Andøya, Norway, the annual Jammertest GNSS testing event took place. For one week, a wide range of organizations tested the resilience of their GNSS systems against various attacks, including jamming, delayed retransmission, and spoofing. Using five Galileo satellites, the European Space Agency was able to obtain a stable lock on their receiver even during spoofing.

In principle, this method could be extended to other GNSS systems. There’s certainly motivation to do so; very large-scale attacks have been demonstrated recently.

A laptop is shown set up on a desk next to a spectrum analyser, an SDR, and two antennas. The antennas are aimed toward assorted electronics, including headphones and a phone handset.

Reviving TEMPEST Attacks With An Injected Signal

TEMPEST attacks are often the most effective way to break air-gapped security: rather than directly accessing a computer, the attacker records the system’s unintended radio emissions and uses them to reconstruct its internal operations. This kind of attack was much more effective in the days of noisy, high-voltage CRT displays, and has gradually become less effective as electronics migrate to quieter, less powerful components. A group of researchers, however, has found that even modern electronics can become effective TEMPEST transmitters when irradiated with an RF signal.

The RF a device emits depends on the unintentional antennas in its internal structure. These are difficult to eliminate, and it’s usually not worth the effort; they’re usually small enough that they only effectively radiate at much higher frequencies than the electronics carry. The researchers’ technique, called InjectEave, radiated these electronics with a radio frequency tuned to their internal antennas, injecting that frequency into the circuit. Nonlinear electronic components, such as amplifiers, then mix the injected frequency with the internal signal, creating RF sidebands. This mixed signal then radiates out of the device and can be picked up and demodulated to recover the device’s internal signal.

Continue reading “Reviving TEMPEST Attacks With An Injected Signal” →

A black robotic hand is shown walking across a granite floor, using its fingers as legs.

Teaching A Robot Hand To Walk

Although it wasn’t apparently designed with this in mind, it seems particularly fortuitous that this walking robotic hand was released in time for Halloween. Designed by researchers from ETH Zurich, the slightly unsettling disembodied hand can use its fingers as legs to traverse terrain, push small objects around, and operate a keyboard.

The researchers started from commercially-available robot hand, equipped it with a battery and Raspberry Pi Zero 2 W, and developed neural net-based software to control it. The hand has twenty joints, four per finger, and the neural net iteratively outputs the next joint state, based on previous movements, the state of the hand, and the hand’s current goal. To train the net, the researchers built a simulated model, then used this for reinforcement learning; this yielded a faster walking speed than an adapted quadrupedal motion model did.

The hand was trained to move in a straight line, turn, recover from a fall, and press the keys of a keyboard (since it doesn’t have a camera, though, it can’t operate a keyboard by itself). The fall recovery is impressive to watch: in 21 out of 25 tests, it was able to right itself within twenty seconds. Due to the hand’s geometry, it drifts to the right while walking, so a constant correction needed to be applied. It did, however, manage to successfully cross fourteen varying surfaces, ranging in roughness from a rubber mat to gravel and grass. It even managed to push light objects toward goals.

The authors envision this kind of autonomous hand enabling greater freedom for a larger robot, such as a robot arm: if it needs to reach something farther away, the hand simply detaches and walks over. Regardless of the use to which they put in, such a project is already within reach of hackers; we’ve seen a few robotic hand projects here over the years.

Continue reading “Teaching A Robot Hand To Walk” →

An angular, 3D-printed base holds two icosahedra with numerals on their faces. Each icosahedron has a zig-zagging path running through it, showing red gears inside.

Keeping Time On Tumbling Icosahedra

Clocks are almost the ideal devices to inspire creativity in hackers — they have a simple, well-defined task, but there’s an almost unlimited number of ways to carry it out. [ekaggrat singh kalsi]’s OVODYO is a particularly intriguing approach, tumbling a pair of icosahedral counters to display the current time.

Each 3D-printed icosahedron has numerals sunk through each of its twelve sides, and is raised above the base of the clock on a brass support shaft. An inner drive shaft runs through the center of the support shaft and drives a set of beveled gears. These spin the outer shells around two axes, periodically cycling through all twelve faces. The pattern in which an icosahedron rotates means that only set of numerals appears upright at a time, making it easier to distinguish the time.

A split path around the icosahedra both lets them rotate around the support shaft and shows off the internal gearing. On the control side, an ATmega8 drives a pair of stepper motors with drv8833 motor drivers, using a hall effect sensor to detect each indicator’s position. Since the minutes dial only gives the time in five-minute intervals, it also drives an LED strip to indicate the exact minute.

[ekaggrat] has a long history of creative clock designs, from this dynamic chain-link sculpture to a hair-tie clock or a mechanical seven-segment display.

Continue reading “Keeping Time On Tumbling Icosahedra” →

On the left side of the image, a mannequin holds a blade of grass in its mouth. A trail of dust follows a blurred green trail past the piece of grass. A man in the background is pointing a wooden device toward the mannequin.

Whip-Cracking Machine Reliably Breaks The Sound Barrier

We tend to think of breaking the sound barrier as a comparatively modern accomplishment, but on a smaller scale, cattle herders have been breaking it for centuries: the cracking sound of the tip of a bullwhip snapping comes from a small-scale sonic boom. Reliably getting a crack out of a whip takes skill and practice, though, which is why [Craig Turner] built a whip-cracking machine.

The first step was to build the whip itself, which was surprisingly complicated. Bullwhips taper down toward the end of the whip. As the whip uncurls during a crack, momentum passes down the whip; since the whip becomes continually narrower and lighter, conservation of momentum means that different stretches of the whip must move progressively faster. To get this effect, [Craig] joined together a series of increasingly thin and light ropes. The heavy end of the whip terminated in an eyelet connected to a length of elastic shock cord. Stretching the whip back on the shock cord and releasing it whipped it around, resulting in a fairly reliable crack.

For greater convenience, [Craig] built this into a launcher mechanism, with the elastic cord wrapped around the end of the launcher, an electrical-conduit guide for the whip, and a spring-loaded trigger mechanism to release it. This worked even better than expected, getting a reliable crack every time. The tip of the whip could slice leaves, tear open aluminium cans, put out candle flames, knock the cap off a bottle without tipping it over, and reliably hit small targets on the first shot.

As [Craig] mentioned, this setup would make it much easier to study the cracking effect with a schlieren imaging setup.

A white background is shown, with a grey metal plate at the base of the image. On the plate are three tiny green Benchy models. Above the Benchies is a glass cylinder. Below one of the Benchy models, text says "250 µm".

Printing Micron-Scale Benchies With Resin And Turmeric

Resin 3D printing has opened up a whole new scale of resolution for hackers, but the technology can go still finer; commercial micro-SLA and two-photon polymerization printers can print items with sub-micron feature sizes, but the machines are well out of reach for hackers. There’s more than one way to get such high resolution, though, as [Diffraction Limited] demonstrated with his micron-scale resin printer.

The printer builds on [Diffraction Limited]’s previous micro-manipulator and fiber-coupled laser. The micro-manipulator holds the end of the optical fiber just in front of the build plate, which is coated with resin. A 405-nm laser shines through the fiber, curing the resin in a narrow cone in front of the fiber’s core, which the micro-manipulator can trace in a pattern to build up objects, much like an FDM printer. Since the fiber’s inner core is only three microns across, the cured resin shears cleanly away from it when the fiber moves. Since the principle is so similar to an FDM printer, a standard slicer could be used to generate the tool paths.

Continue reading “Printing Micron-Scale Benchies With Resin And Turmeric” →