How Can I Check Your Certificate Status in Dead Zones? A Secure Solution for Satellite Networks
Yali Wang, Yuan Zhang, Jingwen Lu, Dairu Han, Ruijin Sun, Zhisheng Yin, Nan Cheng · 2025
Certificate revocation checking (CRC) is a fundamental component for securing certificates which has been widely deployed in satellite networks to support security-related services. However, directly utilizing existing CRC mechanisms in satellite networks would cause critical issues in terms of security, privacy, and practicality. Typically, the trustworthiness of checking results cannot be guaranteed in the presence of active adversaries; the certificate to be checked contains the satellite’s identity, which is sensitive in some applications but could be exposed during CRC; CRC cannot be trivially launched when the satellite is being under constrained networks (e.g., it enters dead zones where direct communication with base stations fails). In this paper, we propose a privacy-preserving and lightweight CRC scheme, dubbed SNCRC, for satellite networks, where a neighboring-assisted forwarding paradigm is utilized to support CRC in constrained networks. SNCRC is secure against adversaries who invalidate checking results or violate related sensitive information about the satellite, which is achieved by utilizing authenticated encryption with associated data (AEAD). Furthermore, SNCRC utilizes a 2-layer revocation checking protocol to perform lightweight CRC, where the certificate authority (CA) and base stations handle CRC tasks from satellites in a cooperative way, which frees CA from heavy costs and reduces CRC delay significantly. We analyze the security of SNCRC, implement an SNCRC prototype, and conduct a comprehensive performance evaluation, which demonstrates its security, efficiency, and practicality.