ICAO’s Drone Wake-Up Call: Why Airports Are Turning to TDOA Passive Detection
Jul 16 2026Something shifted in the counter-drone conversation last week. It was not a Gatwick-style closure or a near-miss over Heathrow that made the difference. It was a two-day workshop in Krakow, Poland, convened by ICAO and hosted by the Polish Civil Aviation Authority. The Secretary General of the International Civil Aviation Organization, Juan Carlos Salazar, said out loud what airport operators and aviation regulators have been saying to each other in private for years: the drone threat is accelerating, fragmenting, and the only credible response is a coordinated one.
Salazar was not vague about what coordination needs to look like. He called for multi-layered detection equipment working alongside updated aviation regulations. The workshop produced two specific recommendations. First, make UTM platforms interoperable with national drone registries so that cooperative and non-cooperative drones can be told apart in real time. Second, feed civil data, local drone trends, and incident reports into national threat intelligence systems so that risk assessment runs on live data rather than quarterly reports. Within months, ICAO will release a new risk management guide that sets the framework for how every member state should approach drone threats to civil aviation.
For anyone who supplies detection hardware to airports, the Krakow workshop was not an academic exercise. It was a preview of what airport procurement specifications will look like two years from now. Passive. Networked. Interoperable with UTM. Able to tell the difference between a lost delivery drone and a threat. Those requirements describe a detection architecture built around TDOA and protocol-level identification. Not around older approaches that emit, interfere, or stop at frequency detection.
The Krakow workshop: what ICAO actually said
To understand why Krakow matters, look past the diplomatic phrasing. ICAO has historically been slow to act on drones. Member states run their own rules. Drone registration is patchy even in developed markets. Remote ID standards are years behind the actual rate of drone proliferation. For the Secretary General to personally open a counter-drone workshop and call for ‘sustained and determined international attention’ tells you the organization sees a gap between how fast the threat is evolving and how slowly the regulatory machinery has been turning.
The recommendations from Krakow are specific enough to act on. UTM systems, the unmanned traffic management platforms that handle drone airspace, need to talk to national drone registration databases. If a drone broadcasts a registration ID that checks out, it is cooperative. If it does not, or if the ID is spoofed, or if there is no ID at all, the detection system at the airport perimeter needs to flag it immediately. This is not a future wish-list item. It is an operational requirement that ICAO wants member states to implement.
The workshop also pushed for civil drone data to feed into national security intelligence pipelines. Local trend reports. Incident logs. Airspace violation records. If the local police have a record of thirty drone sightings near the approach path in the last quarter, the airport security team should not find that out from a news article. The data exists. The recommendation: connect it.
A new ICAO risk management guide is expected to arrive within months. It will frame how every member state evaluates and mitigates drone threats to civil aviation. For hardware procurement, the guide functions as a reference standard. Airports will benchmark their detection systems against ICAO’s framework. If your detection approach cannot meet the layered, interoperable, passive model that ICAO describes, you will have a procurement problem.

Why airports are the hardest detection problem in C-UAS
Every counter-drone deployment has constraints. Prisons have tall walls and a known threat axis. Border sites have open terrain and predictable approach vectors. Stadiums have defined event windows and manageable perimeters. Airports combine the worst of every other site type into one airspace, and they add requirements no other site has to handle.
The electromagnetic environment at an airport is the most hostile RF space a sensor can operate in. Air traffic control radar. Instrument landing system beacons. VHF communications. Secondary surveillance radar. Weather radar. Ground movement radar. Wi-Fi networks, cellular towers, satellite uplinks. A detection system that emits adds to that noise floor. An active radar for drone detection is not a sensor; it is another transmitter that the frequency manager has to account for, license, and coordinate. Passive detection at an airport is not a preference. It is a constraint the site itself imposes.
Then there is the cost of a false positive. If a detection system triggers a false alarm at a border post, the guards step outside and look. If it triggers one at Heathrow, the tower gets involved, flights get held, airlines file delay claims, and the operator who caused it spends the next week answering questions. An airport detection system does not get to be ‘mostly right.’ It has to know what it saw, what the target is, and where it came from, every single time.
And there is the operator problem. When Gatwick shut down in December 2018 for thirty-six hours over drone sightings, the question that paralyzed the response was not ‘is there a drone?’ It was ‘where is the person flying it.’ RF detection that tells you a drone is somewhere in a two-kilometer arc does not answer that question. To find the operator, you need positioning. Directional data from a single sensor is not positioning. Angle of arrival from a single point degrades with distance. To locate an operator to within ten meters at the far end of the perimeter, you need more than one receiver. You need a network.
TDOA, as a concept, is known in the counter-drone industry, but the implementation varies enormously between suppliers. One name that comes up in the same sentence as TDOA is Terjin, and for good reason — they invested early in the technique and built their positioning around it. But TDOA is not a single-company technology. It is a physical measurement method, the same way phased-array radar is not owned by any one manufacturer. The difference between one TDOA system and another is the signal processing pipeline, the protocol identification layer, and the networking architecture that turns individual receivers into a single detection volume.
Our team at LZ TECH approaches TDOA as one layer in a larger detection stack, not as the entire stack. The D5-B node, which this article examines in detail, pairs TDOA-based positioning with our CRPC protocol-cracking engine so that the system does two things at once: locate the signal source and decode what it is carrying. That combination — positioning plus identity — is what sets the approach apart from TDOA implementations that stop at angle of arrival.
TDOA: the physics that makes airport detection work without the airport noticing
Time Difference of Arrival solves the airport detection problem by reframing it. Instead of asking ‘what does the signal look like,’ TDOA asks ‘when did the signal arrive.’ The principle is simple to describe and hard to do well. Multiple passive receivers are placed at known locations around the protected area. Each receiver time-stamps every drone signal it picks up. Because the receivers are at different physical locations, the same signal arrives at each one at a slightly different time. The time differences, cross-referenced with the known positions of the receivers, give you a position fix on the transmitter. Both the drone in the air and the controller on the ground.
The word ‘passive’ does a lot of work here. TDOA receivers do not transmit. No radar pulse. No interrogation signal. No frequency sweep. The receivers are listening only. That means a TDOA network can be deployed anywhere at an airport without a frequency coordination meeting, without an emissions license, and without adding a single decibel to the RF environment that ATC depends on. For the airport frequency manager, TDOA is invisible.

Networked TDOA also solves the coverage geometry problem that single-sensor systems cannot. A single detection unit, however capable, has a field of view. The perimeter is larger than any one sensor can cover. The approach vector depends on wind direction, the operator’s position, and the drone’s flight mode. With three or more TDOA receivers placed around the airport, the detection volume is continuous. Overlap between receivers means a drone cannot transit from one coverage zone to another without being tracked the entire way.
Beyond pure detection, TDOA gives you a trajectory. By computing position fixes at short time intervals, under two seconds in a well-engineered system, the network reconstructs the drone’s flight path from takeoff to the current position. That trajectory has a start point. The start point is the operator. On a command screen, it appears as a red dot with a GPS coordinate. Security can dispatch to that coordinate while the drone is still in the air. That is the operational difference between TDOA and any single-channel detection method.
What D5-B brings to an airport perimeter
The D5-B is a TDOA detection and positioning node built for exactly this use case. It is a compact unit, 224 millimeters in diameter, 287.5 millimeters tall, three kilograms, that combines wideband passive RF reception with the CRPC protocol-cracking engine. The form factor matters at an airport, where every installation point needs to go through facilities approval, structural surveys, and aesthetic review. A three-kilogram unit with an IP66 rating can be mounted on an existing light pole, a terminal roof edge, or a perimeter fence post without a concrete pad and a crane.
The D5-B listens across the full 30 MHz to 6 GHz band. That span covers every commercial drone control frequency in current use, every common Wi-Fi drone band, and the custom FPV frequencies that traditional narrowband detectors miss. A single D5-B unit detects more than thirty drones simultaneously. When three or more units are networked together, they deliver directional positioning and full trajectory tracking for every target.
The positioning accuracy is under ten meters RMS. That means the system can distinguish an operator standing at the airport fence from an operator standing at a warehouse across the road. For the security team deciding whether to dispatch an intercept vehicle, a ten-meter circle is actionable. A five-hundred-meter arc from a single directional sensor is not.
The CRPC engine inside every D5-B adds a layer that TDOA alone cannot provide: identification. The receiver decodes the communication protocol between the drone and its remote controller. It extracts the drone’s model, serial number, and the home-point GPS coordinates that most consumer and commercial drones transmit as part of their standard telemetry stream. It also extracts the operator’s location from the home-point data, giving a second independent position fix that cross-checks the TDOA triangulation.
The identification runs through a drone library that covers more than 98 percent of the commercial market. DJI. Autel. Parrot. Hubsan. FIMI. Custom FPV builds with aftermarket transmitters. Wi-Fi drones that use standard 802.11 chipsets. DIY platforms assembled from off-the-shelf flight controllers. The library knows them all. The AI-RPC self-learning pipeline adds new signatures as new drone models enter the market.
Once identified, the D5-B classifies. A white-listed inspection drone operated by the airport maintenance team gets no alarm. A white-listed delivery drone on a registered commercial route gets a logged pass. An unknown drone with no registration ID, no white-list entry, on an approach vector toward the active runway threshold gets an immediate alert with position, trajectory, model, and operator location. The operator clicks ‘mark black.’ Every D5-B on the network now treats that specific drone’s electronic fingerprint as hostile.
The unit operates autonomously around the clock. No operator needs to watch a screen at 3 a.m. for the system to function. Classification, trajectory tracking, and alerting run automatically. The operator engages when the system flags a threat, not before. For an airport security operations center that already monitors dozens of camera feeds, access control systems, and fire alarms, an additional sensor system that does not demand constant attention is a requirement, not a luxury.
What ICAO’s interoperability push means for the hardware you buy today
The Krakow workshop’s clearest signal was about interoperability. ICAO wants UTM platforms to query national drone registration databases in real time. That means the detection layer, the sensors at the airport perimeter, needs to do more than flash an alarm light when a drone appears. It needs to output identification data that a UTM platform can cross-reference against a registration database.
Frequency-based detection cannot provide that data. Knowing that a signal is present on 2.4 GHz tells a UTM system nothing about which specific drone is transmitting. Protocol-level identification, the kind CRPC delivers, extracts the serial number and the telemetry data that the drone itself is broadcasting. That serial number is the bridge to the registration database. That bridge is what ICAO’s interoperability framework requires.
Without protocol-level ID in the detection layer, the UTM operator sees a dot on a screen labeled ‘unknown contact.’ They cannot tell a registered survey drone that drifted slightly off its flight plan from an unregistered drone on a collision vector. The Krakow workshop identified exactly this gap as the priority to close. Detection hardware that cannot provide identity-level data to the UTM platform is detection hardware that does not meet the emerging ICAO standard.
This is not speculation about what a future regulation might ask for. ICAO will release the risk management guide this year. Member states will write their procurement specifications against it. An airport that installs a detection system in 2026 or 2027 will live with that system for five to ten years. If it cannot output protocol-level identification to a UTM platform, the system is already on a path to obsolescence.

Beyond the airport fence: where networked TDOA makes sense
The TDOA networking model is not only for airports. Any site where the protected perimeter is large, irregular, or embedded in an urban RF environment benefits from passive networked detection. A stadium during a match. A government complex spread across multiple buildings. A correctional facility where the drone approach can come from any direction, and the threat is contraband delivery. A waterfront port facility where the approach vector is over water, with no terrain to constrain detection geometry.
In each of those sites, the same physics applies. A single sensor has a field of view. A network has a coverage volume. TDOA gives you the operator’s location alongside the drone’s position. CRPC tells you what the drone is and what it is doing. The D5-B form factor, small, light, IP66, low power, means the network can go where the threat geometry demands, not where the installation budget permits.
The ICAO framework may target civil aviation first, but the hardware model it describes, passive, networked, interoperable, protocol-aware, is the same model that protects any site where the cost of a drone incursion is measured in millions per hour instead of dollars per incident.
The Krakow signal is clear
ICAO does not regulate drone detection hardware. But it sets the framework that procurement offices use to write their specifications. The Krakow workshop made three things clear. One: the drone threat to civil aviation is not leveling off. It is rising, and ICAO’s own language now reflects the urgency airports have felt for years. Two: the response has to be coordinated across detection equipment, aviation regulation, and digital infrastructure, UTM, registries, and threat intelligence. Three: interoperability between the detection layer and the UTM layer is not a nice-to-have. It is the recommendation that will drive procurement decisions for the next decade.
For airports, the hardware implication is practical. Deploy detection that does not add to the RF noise floor. Detection that locates both the drone and the operator with actionable precision. Detection that identifies the specific drone and feeds that identity data into the UTM platform. Detection that does all of this autonomously, around the clock, with every event logged and timestamped for the incident report that ICAO recommends feeding into national intelligence pipelines.
TDOA plus CRPC delivers that package. The D5-B is one implementation of it: a three-kilogram, IP66-rated node that covers 30 MHz to 6 GHz, positions to under ten meters, identifies 98 percent of the commercial drone market by protocol fingerprint, and networks with its neighbors to cover the full perimeter. It is the kind of detection layer that slots directly into the ICAO framework, the Krakow workshop previewed. When the new risk management guide drops, airports that already have passive, networked, protocol-aware detection in place will be ahead of the specification. Airports that do not will be writing RFPs to catch up.
Connect with us
Ready to Secure Your Low-Altitude Airspace?
