Space Fabric: A Satellite-Enhanced Trusted Execution Architecture
Filip Rezabek, Dahlia Malkhi, and Amir Yahalom

TL;DR
Space Fabric introduces a satellite-based trusted execution architecture that enhances security and trust in orbital computing by leveraging physical inaccessibility, distributed secure elements, and a Byzantine-tolerant endorsement protocol.
Contribution
It relocates the trusted computing stack to satellites, enabling post-launch secure attestation without pre-provisioned secrets or vendor dependence, and implements a novel endorsement protocol.
Findings
Successfully implemented on USB Armory Mk II with ARM TrustZone
End-to-end attestation verified using Veraison
Security analysis confirms robustness against strong adversaries
Abstract
The emergence of decentralized satellite networks creates a pressing need for trust architectures that operate without physical access to hardware, without pre-provisioned vendor secrets, and without dependence on a single manufacturer's attestation service. Terrestrial TEEs are insufficient: hardware-based designs are susceptible to physical attacks, and most platforms root their attestation chains in secrets provisioned during manufacturing, creating a pre-launch trust window and single-vendor dependency that cannot be independently audited. We present Space Fabric, an architecture that provides the missing trust foundation for orbital computing by relocating the trusted computing stack to satellite infrastructure, exploiting post-launch physical inaccessibility as a tamper barrier unattainable by terrestrial deployments. Our Satellite Execution Assurance Protocol binds workload…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSecurity and Verification in Computing · Distributed systems and fault tolerance · Cryptography and Data Security
