QPEP: An Actionable Approach to Secure and Performant Broadband From Geostationary Orbit
James Pavur, Martin Strohmeier, Vincent Lenders, Ivan Martinovic
Abstract
—Satellite broadband services are critical infrastructures, bringing connectivity to the most remote regions of the globe. However, due to performance concerns, many geostation-ary satellite broadband services are unencrypted and vulnerable to long-range eavesdropping attacks. This paper delves into the underlying cause of these issues, presenting the case that the widespread use of Performance Enhancing Proxies (PEPs) for TCP optimization has created a security/performance trade-off. A review of previous mitigation proposals finds limited real-world adoption due to a variety of factors ranging from misaligned commercial incentives to the prevalence of unverified “black-box” encryption products. To address these shortcomings, we design and implement a fully open-source and encrypted-by-default PEP/VPN hybrid, called QPEP. Built around the QUIC standard, QPEP enables individuals to encrypt satellite traffic without ISP involvement. Additionally, we present an open and replicable Docker-based testbed for benchmarking QPEP, and other PEP applications, through simulation. These experiments show that QPEP enables satellite customers to encrypt their TCP traffic with up to 72% faster page load times (PLTs) compared to traditional VPN encryption. Even relative to other unencrypted PEPs, QPEP offers up to 54% faster PLTs while also protecting communications in transit. We briefly discuss how QPEP might leverage bespoke modifications to the QUIC protocol for further optimization. Ultimately, our experiments suggest that QPEP’s hybrid architecture represents a promising new technique for bringing both security and performance to satellite broadband while avoiding costly alterations to status-quo networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Wireless Signal Injection Attacks on VSAT Satellite ModemsRobin Bisping, Johannes Willbold, Martin Strohmeier, Vincent LendersUSENIX Security 2024 · 11 citations
- Space Odyssey: An Experimental Software Security Analysis of SatellitesJohannes Willbold, Moritz Schloegel, Manuel Vögele, Maximilian Gerhardt et al.S&P 2023
- SoK: Space Infrastructures Vulnerabilities, Attacks and DefensesJose Luis Castanon Remy, Ekzhin Ear, Caleb Chang, Antonia Feffer et al.S&P 2025
- Web Execution Bundles: Reproducible, Accurate, and Archivable Web MeasurementsFlorian Hantke, Peter Snyder, Hamed Haddadi, Ben StockUSENIX Security 2025
- SatBleed: Security of Commoditized Communication Modules in SatellitesUlysse Planta, Julian Rederlechner, Martin Strohmeier, Mathias Fischer et al.S&P 2026
Builds on1
Related papers
- Internet Connection Splitting: What's Old is New AgainGina Yuan, Thea Rossman, Keith WinsteinUSENIX ATC 2025 · 3 citations
- Dissecting Performance of Production QUICAlexander Yu, Theophilus A. BensonWWW 2021 · 59 citations
- LiteQUIC: Improving QoE of Video Streams by Reducing CPU Overhead of QUICPengqiang Bi, Yifei Zou, Mengbai Xiao, Dongxiao Yu et al.ACM MM 2024 · 3 citations
- QCSD: A QUIC Client-Side Website-Fingerprinting Defence FrameworkJean-Pierre Smith, Luca Dolfi, Prateek Mittal, Adrian PerrigUSENIX Security 2022
- Don't Look Up: There Are Sensitive Internal Links in the Clear on GEO SatellitesWenyi Morty Zhang, Annie Dai, Keegan Ryan, Dave Levin et al.CCS 2025 · 1 citation
