QPEP: A QUIC-Based Approach to Encrypted Performance Enhancing Proxies for High-Latency Satellite Broadband
James Pavur, Martin Strohmeier, Vincent Lenders, Ivan Martinovic

TL;DR
QPEP introduces a QUIC-based encrypted PEP for satellite broadband that enhances security without sacrificing TCP performance, significantly reducing page load times and providing over-the-air privacy.
Contribution
This paper presents QPEP, an open-source, QUIC-based encrypted PEP that can be adopted independently by customers, overcoming previous barriers to secure satellite broadband performance.
Findings
QPEP reduces average page load times by over 30% compared to unencrypted PEPs.
QPEP more than halves page load times compared to traditional VPN encryption.
QPEP provides over-the-air privacy without compromising TCP performance.
Abstract
Satellite broadband services are critical infrastructures enabling advanced technologies to function in the most remote regions of the globe. However, status-quo services are often unencrypted by default and vulnerable to eavesdropping attacks. In this paper, we challenge the historical perception that over-the-air security must trade off with TCP performance in high-latency satellite networks due to the deep-packet inspection requirements of Performance Enhancing Proxies (PEPs). After considering why prior work in this area has failed to find wide adoption, we present an open-source encrypted-by-default PEP - QPEP - which seeks to address these issues. QPEP is built around the open QUIC standard and designed so individual customers may adopt it without ISP involvement. QPEP's performance is assessed through simulations in a replicable docker-based testbed. Across many benchmarks and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSatellite Communication Systems · Network Traffic and Congestion Control · Mobile Agent-Based Network Management
