Starshields for iOS: Navigating the Security Cosmos in Satellite Communication
Jiska Classen, Alexander Heinrich, Fabian Portner, Felix Rohrbach, Matthias Hollick
Abstract
—Apple has integrated satellite communication into their latest iPhones, enabling emergency communication, road-side assistance, location sharing with friends, iMessage, and SMS. This technology allows communication when other wireless services are unavailable. However, the use of satellites poses restrictions on bandwidth and delay, making it difficult to use modern communication protocols with their security and privacy guarantees. To overcome these challenges, Apple designed and implemented a proprietary satellite communication protocol. We are the first to successfully reverse-engineer this protocol and analyze its security and privacy properties. In addition, we develop a simulation-based testbed for testing emergency services without causing emergency calls. Our tests reveal protocol and infrastructure design issues. For example, compact protocol messages come at the cost of missing integrity protection and require an internet-based setup phase. We further demonstrate various restriction bypasses, such as misusing location sharing to send arbitrary text messages on old iOS versions and sending iMessages over satellite from region-locked countries. These bypasses allow us to overcome censorship and operator control of text messaging services.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e1c93d30-08aa-46e4-a3fa-9cfcc1aa724bBuilds on5
- ICARUS: Attacking low Earth orbit satellite networksGiacomo Giuliari, Tommaso Ciussani, Adrian Perrig, Ankit SinglaUSENIX ATC 2021 · 99 citations
- A Tale of Sea and Sky On the Security of Maritime VSAT CommunicationsJames Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders et al.S&P 2020 · 72 citations
- RECORD: A RECeption-Only Region Determination Attack on LEO Satellite UsersEric Jedermann, Martin Strohmeier, Vincent Lenders, Jens B. SchmittUSENIX Security 2024 · 18 citations
- A Comprehensive Analysis of Security Vulnerabilities and Attacks in Satellite ModemsLingjing Yu, Jingli Hao, Jun Ma, Yong Sun et al.CCS 2024 · 8 citations
- Space Odyssey: An Experimental Software Security Analysis of SatellitesJohannes Willbold, Moritz Schloegel, Manuel Vögele, Maximilian Gerhardt et al.S&P 2023
Related papers
- Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessageChristina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers et al.USENIX Security 2016 · 62 citations
- Blue Bubbles, Red Flags: Investigating Privacy Leakage in Apple iMessageViktor E. Garske, Swantje Lange, Gabriel K. Gegenhuber), David Schmidt et al.CCS 2026
- Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical RisksRishav Chourasia, Ergute Bao, Uzair Javaid, Xiaokui XiaoS&P 2026 · 2 citations
- Disrupting Continuity of Apple's Wireless Ecosystem Security: New Tracking, DoS, and MitM Attacks on iOS and macOS Through Bluetooth Low Energy, AWDL, and Wi-FiMilan Stute, Alexander Heinrich, Jannik Lorenz, Matthias HollickUSENIX Security 2021 · 31 citations
- The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-ConstellationsWei Liu, Yuanjie Li, Hewu Li, Yimei Chen et al.S&P 2024 · 21 citations
