Starshields for iOS: Navigating the Security Cosmos in Satellite Communication

Jiska Classen

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Wireless, Cellular & Satellite Security · Wireless, Cellular & Satellite Security

Overview

As modern smartphones integrate advanced capabilities, Apple's introduction of satellite communication features in iOS devices marked a significant leap, promising connectivity in off-grid scenarios where traditional cellular and Wi-Fi networks are unavailable. This talk, presented by Alexander, delves into the intricate security architecture of Apple's Starshields for iOS system, offering a comprehensive analysis of how these features operate, the cryptographic mechanisms employed, and potential avenues for bypassing intended restrictions. The research, led by Jiska Classen and her colleague, provides an unprecedented look into a largely opaque system, shedding light on the robust security measures Apple has implemented to protect user data in highly resource-constrained environments.

Watch on YouTube · Slides

Key moments

  1. 0:00 Overview of iPhone satellite features
  2. 1:20 Apple's satellite infrastructure: Globalstar, Stewie, ground stations
  3. 2:45 Research questions and Globalstar's 9kbps data limit
  4. 3:15 Satellite session key generation and secure enclave authentication
  5. 5:55 Emergency communication encryption: master session key and compression
  6. 7:00 End-to-end encryption for Find My Friends location sharing

Starshields for iOS: Navigating the Security Cosmos in Satellite Communication

Speakers: Jiska Classen

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=BJryLUsa0zU

Overview

As modern smartphones integrate advanced capabilities, Apple's introduction of satellite communication features in iOS devices marked a significant leap, promising connectivity in off-grid scenarios where traditional cellular and Wi-Fi networks are unavailable. This talk, presented by Alexander, delves into the intricate security architecture of Apple's Starshields for iOS system, offering a comprehensive analysis of how these features operate, the cryptographic mechanisms employed, and potential avenues for bypassing intended restrictions. The research, led by Jiska Classen and her colleague, provides an unprecedented look into a largely opaque system, shedding light on the robust security measures Apple has implemented to protect user data in highly resource-constrained environments.

The motivation behind this investigation stems from the critical nature of satellite communication for emergency services and personal safety, alongside a natural curiosity about how such complex technology is secured. Apple's satellite features, including Emergency SOS, Find My, Roadside Assistance, and iMessage/SMS, leverage existing Globalstar infrastructure, presenting unique challenges for data transfer speed and system reliability. This article unpacks the detailed findings presented, from the multi-layered encryption schemes to the practical demonstrations of bypassing geographical and feature limitations, offering valuable insights for security professionals, developers, and users alike.

The findings reveal a system designed with strong cryptographic foundations, yet also expose fascinating insights into the interplay between technical security and service-level restrictions. The researchers’ ability to reverse engineer and interact with this proprietary system provides a rare glimpse into Apple's approach to secure communication in novel contexts, highlighting both the strengths of its design and the ingenuity of security researchers in exploring its boundaries.

Background

▶ Watch: Overview of iPhone satellite features (0:00)

Apple's foray into satellite communication began with essential safety features, designed to provide a lifeline when users are beyond the reach of conventional networks. Initially rolled out with Emergency SOS via Satellite, the iPhone allowed users to send emergency messages and share their location with first responders, even in remote areas. This capability was later expanded to include Find My location sharing, Roadside Assistance, and more recently, the ability to send standard text messages (SMS) and iMessages over satellite, though the latter is currently limited to the US. These features represent a paradigm shift in mobile connectivity, extending the utility of the iPhone into previously inaccessible domains.

The underlying infrastructure for Apple's satellite services relies not on proprietary satellites, but on the existing Globalstar constellation. This network comprises 48 low-Earth orbit (LEO) satellites that act as passive relays, or "mirrors," in space. An iPhone sends a signal upwards to a Globalstar satellite (internally termed a "target"), which then reflects the signal down to a designated Globalstar ground station (an "anchor"). At these ground stations, Apple maintains servers that process and route the satellite-transmitted data to its internal services. This entire system, internally code-named Stewie, allows Apple to leverage established satellite infrastructure rather than building its own.

A critical aspect of this system is the highly resource-constrained environment of satellite communication. The Globalstar network, while offering broad coverage, permits a mere 9 kilobits per second data transfer rate. This limitation heavily influences the design of the communication protocols, necessitating efficient data compression and streamlined security mechanisms. Despite Globalstar's global reach, Apple has strategically rolled out its satellite features to specific regions, including North America (US, Canada), various European countries, Australia, and New Zealand.

The researchers embarked on this project with two primary questions: First, how are security and privacy features implemented and maintained within such a resource-constrained environment? Second, can they bypass any of the restrictions Apple has imposed, such as limiting usage to iPhones or specific functionalities? Understanding these facets is crucial for assessing the overall resilience and integrity of this vital communication channel.

Key Findings

▶ Watch: Research questions and Globalstar's 9kbps data limit (2:45)

The research into Apple's satellite communication system uncovered several significant findings regarding its security architecture, cryptographic implementations, and the potential for bypassing service restrictions.

Firstly, the system demonstrates robust security mechanisms with multiple layers of encryption designed to protect sensitive user data. At the core, all emergency messages and location data are end-to-end encrypted, ensuring that even Apple's servers do not have direct access to the plaintext content. This commitment to privacy is a cornerstone of the system's design.

Key generation is handled by the iPhone's Secure Enclave Processor, a dedicated hardware security module that ensures cryptographic keys are generated and stored securely, preventing their export from the device. Specifically, 30 LLC keys are generated on the iPhone, and their public counterparts are pre-synchronized with Apple's servers. In return, Apple pre-generates and sends back a corresponding set of server public keys to the iPhone. These 30 key pairs allow for 30 distinct satellite communication sessions.

When a satellite session is initiated, a session key is established using an Elliptic Curve Diffie-Hellman (ECDH) key exchange. The iPhone uses one of its Secure Enclave-protected private keys, combined with a pre-received Apple public key, to derive a shared secret. This shared secret is fundamental for establishing an authenticated and encrypted connection to the ground station. The actual physical layer communication and connection setup are managed by the iOS baseband chip, which is typically a Qualcomm chip (though newer iPhones, like the 16e, are transitioning to Apple's own baseband).

For emergency communication, once the shared secret is established, the ground station sends a Master Session Key (a 256-bit key) back to the iPhone's baseband, which is then exported to the operating system. This master key is subsequently used with a hash-based key derivation function (HKDF) to derive two further keys: message_key_in and message_key_out. Messages are encrypted using message_key_out with AES-CTR mode, employing the conversation_ID (valid for two hours) and an incrementing message_ID as the initialization vector (IV). Data is also highly compressed using custom, language-specific models, achieving up to a 2.5 times reduction in size.

Find My location encryption functions similarly to its internet-connected counterpart, leveraging a friends key shared with designated recipients and employing the Elliptic Curve Integrated Encryption Scheme (ECIES) for end-to-end encryption. This design ensures that location data remains private between the sender and their chosen contacts, inaccessible to Apple.

A notable finding related to transport encryption clarified an initial concern. While AES-CTR for message encryption typically lacks inherent integrity protection, Apple confirmed upon responsible disclosure that the shared secret derived during session setup is used for an additional, underlying layer of transport encryption that does include integrity protection. This multi-layered approach significantly strengthens the overall security posture.

Beyond the core security mechanisms, the researchers successfully demonstrated two key bypasses on jailbroken iPhones:

  1. Region Restriction Bypass: By modifying a configuration file on a jailbroken device, they could enable satellite communication features in regions not officially supported by Apple (e.g., using satellite services from Poland, despite being designed for Germany).
  2. Feature Restriction Bypass: By replacing the encrypted location data stream (from the Find My feature) with arbitrary text messages, they could send text over satellite. Initially, this allowed sending up to 160 bytes of custom text. Following responsible disclosure, Apple implemented server-side limitations, reducing this capacity to 82 bytes. Apple classified these bypasses as "monetization issues" rather than security vulnerabilities, as they did not compromise user data or system integrity.

These findings collectively paint a picture of a well-secured system, albeit one with discoverable service-level flexibility when device-level controls are circumvented.

Technical Deep Dive

▶ Watch: Satellite session key generation and secure enclave authentication (3:15)

The technical architecture of Apple's Starshields for iOS system is a sophisticated blend of hardware security, cryptographic protocols, and efficient data handling, all optimized for the constraints of satellite communication. The system, internally known as Stewie, orchestrates communication between the iPhone, the Globalstar satellite constellation, and Apple's ground infrastructure.

At the lowest level, the iPhone's baseband chip is crucial. This is the same chip responsible for cellular communication, typically a Qualcomm modem, though Apple is transitioning to its own silicon in newer models like the iPhone 16e. This chip is not merely a transceiver; it runs custom software developed by Apple to manage the complexities of satellite communication, including antenna pointing, signal acquisition, and the initial handshake with the Globalstar network.

The foundation of secure communication lies in key management. Each iPhone generates 30 unique LLC keys within its Secure Enclave Processor. This hardware security module is designed to isolate cryptographic operations and prevent private keys from ever leaving the device. The public keys corresponding to these 30 LLC keys are then securely synchronized with Apple's servers. In a reciprocal process, Apple's servers pre-generate and send back 30 server public keys, which are stored on the iPhone. Each of these 30 key pairs is designated for a single satellite communication session, providing a pool of pre-authenticated session credentials.

When an iPhone initiates a satellite session, it performs an Elliptic Curve Diffie-Hellman (ECDH) key exchange. The iPhone uses one of its Secure Enclave-protected private LLC keys and a corresponding server public key (received from Apple) to compute a shared secret. This shared secret is vital; it authenticates the iPhone to Apple's ground station and serves as the basis for deriving further cryptographic keys.

The communication path is as follows: iPhone transmits to a Globalstar satellite (the "target"), which acts as a "mirror" to reflect the signal to a Globalstar ground station (the "anchor"). At the ground station, Apple's servers process the data. The shared secret ensures that only authenticated iPhones can establish a connection and that the initial communication channel is protected.

For emergency messaging, once the connection is established and the shared secret derived, the ground station sends a 256-bit Master Session Key back to the iPhone's baseband. This key is then securely exported to the iOS operating system. The Master Session Key is not directly used for message encryption; instead, it feeds into a hash-based key derivation function (HKDF). This HKDF generates two distinct keys: message_key_in (for incoming messages) and message_key_out (for outgoing messages).

Outgoing emergency messages are encrypted using message_key_out with the Advanced Encryption Standard (AES) in Counter (CTR) mode. The Initialization Vector (IV) for each message is constructed from two components: a conversation_ID, which remains constant for a two-hour satellite session, and a message_ID, which increments with every message sent within that conversation. Before encryption, plaintext messages undergo significant compression using custom, language-specific models, achieving up to a 2.5x reduction in data size. This compression is critical given the 9 kilobits per second bandwidth limitation of the Globalstar network. The end-to-end encryption for emergency messages ensures that only the intended first responder (after decryption at their end, which the researchers could not observe) can access the plaintext.

Find My location sharing over satellite employs a similar end-to-end encryption philosophy. A friends key is shared among the user and their trusted contacts. The actual location data is then encrypted using the Elliptic Curve Integrated Encryption Scheme (ECIES), ensuring that only the designated friends can decrypt and view the location. Apple itself does not have access to the unencrypted location data.

A crucial clarification arose regarding transport encryption. Initially, the researchers noted that AES-CTR, while providing confidentiality, does not inherently offer integrity protection. Through responsible disclosure, Apple confirmed that an additional layer of transport encryption exists, utilizing the initial shared secret derived from the ECDH key exchange. This layer provides both confidentiality and integrity protection for the data transmitted between the iPhone and the ground station, addressing potential manipulation concerns. The difficulty in observing this layer was attributed to the proprietary nature and complexity of reverse engineering Qualcomm baseband chips. The researchers expressed intent to investigate this further with Apple's new, potentially more accessible, baseband chip.

In summary, the technical design of Starshields for iOS is characterized by:

  • Hardware-backed key generation via Secure Enclave.
  • Authenticated session establishment using ECDH and a shared secret.
  • Multi-layered encryption: End-to-end encryption for payload data (AES-CTR for emergency, ECIES for Find My) and transport encryption with integrity protection for the communication channel.
  • Extreme efficiency through custom data compression algorithms.
  • Reliance on the iOS baseband chip for low-level communication.

This detailed examination highlights Apple's commitment to securing critical communications even under severe technical constraints, while also pointing to the challenges and opportunities for security research in such complex, proprietary systems.

Demo / Proof of Concept

▶ Watch: Emergency communication encryption: master session key and compression (5:55)

The research included compelling demonstrations of how the system's intended restrictions could be bypassed on a modified device, primarily focusing on geographical and feature limitations rather than breaking core encryption. These proofs of concept were carried out on jailbroken iPhones, which provided the necessary access to the device's file system and internal configurations.

One key demonstration involved bypassing region restrictions. Apple's satellite services are geographically limited, even though the underlying Globalstar network offers broader coverage. The researchers identified a configuration file on the iPhone that explicitly lists the services available via satellite and the countries in which they are supported. By obtaining a jailbroken iPhone and modifying this config file—specifically, changing the country code from "Germany" (DOI) to "Poland"—they successfully enabled satellite communication functionality in Poland, a country where Apple does not officially support the service. This was practically demonstrated by Alexander's colleague, Jiska Classen, who drove from Germany to Poland to perform the test. The iPhone, after the modification, successfully communicated its location via satellite from an unsupported region, proving that these geographical restrictions are enforced at the software configuration level on the device, rather than solely by the satellite network itself.

The second, and perhaps more impactful, demonstration involved bypassing feature restrictions to send arbitrary text messages instead of location data. The Find My feature, when used over satellite, is designed to send encrypted location information. The researchers realized that since this location data is end-to-end encrypted with ECIES, Apple's servers would not inherently know if the encrypted payload contained location coordinates or something else. Leveraging this, they developed a custom application for a jailbroken iPhone that could intercept the outgoing location data stream and replace it with arbitrary text.

Initially, this allowed them to send up to 160 bytes of custom text messages over the satellite link, effectively transforming the location-sharing feature into a rudimentary satellite text messenger. This proof of concept highlighted that while the encryption was robust, the system's interpretation of the content type could be manipulated at the device level. The researchers mentioned that this application is available on GitHub, though it requires a jailbroken phone to function. Following their responsible disclosure to Apple, the company implemented server-side limitations, reducing the maximum payload size that could be sent this way to 82 bytes. While the bypass still functions within this new limit, it demonstrates Apple's ability to mitigate such "misuse" of services through server-side controls without redesigning the core cryptographic protocols.

These demonstrations underscore that while Apple's cryptographic implementations are strong and protect user data integrity, the proprietary nature of the system and reliance on device-side configuration for service restrictions can be an avenue for exploration by determined researchers or malicious actors with access to a modified device. The "monetization issue" classification by Apple indicates their focus on preventing free usage of paid services rather than a perceived security vulnerability leading to data compromise.

Defensive Implications

▶ Watch: End-to-end encryption for Find My Friends location sharing (7:00)

The detailed analysis of Apple's satellite communication system provides several crucial insights for defenders, ranging from general security awareness to specific operational considerations.

Firstly, the research confirms that Apple has implemented robust, multi-layered encryption for its satellite communication features. Emergency SOS messages and Find My location data are protected by end-to-end encryption, meaning that sensitive user information remains confidential from the iPhone to its intended recipient (first responders or designated friends), inaccessible even to Apple. This strong cryptographic foundation should reassure users about the privacy of their critical communications in off-grid scenarios. Defenders should emphasize this strength when discussing the security posture of these features.

However, the demonstrations of bypassing region and feature restrictions highlight the inherent risks associated with jailbroken devices. The ability to modify configuration files or inject custom payloads into encrypted streams underscores that compromising the device's root of trust can lead to unauthorized use of services. While Apple classified these bypasses as "monetization issues" because they didn't leak user data, they still represent a deviation from intended service usage. Organizations or individuals providing iPhones to personnel in sensitive roles or environments should reinforce policies against jailbreaking and maintain device integrity.

The discovery that Apple's server-side controls can limit the effectiveness of such bypasses (e.g., reducing the custom message length from 160 to 82 bytes) is an important defensive mechanism. This indicates that while device-side modifications can open doors, Apple maintains server-side checks and balances to prevent widespread abuse or excessive resource consumption. Defenders should recognize that a multi-tiered approach, combining strong client-side security with robust server-side validation, is essential for maintaining control over complex service offerings.

Furthermore, the extensive reverse engineering work involved in this research provides valuable transparency into a previously undocumented and proprietary system. This knowledge empowers the broader security community to understand potential attack surfaces and contribute to future hardening efforts. While Apple's proprietary baseband chips remain challenging to analyze, the insights gained can inform more targeted research and defensive strategies.

Finally, the discussion around the transport encryption layer, specifically the confirmation by Apple that the shared secret provides integrity protection for the communication channel, is a critical piece of information. This addresses a potential concern about the manipulability of AES-CTR encrypted messages. Defenders can now confidently state that data transmitted over Apple's satellite link is protected against tampering, not just eavesdropping, due to this additional layer.

In summary, defenders should leverage the confirmed strength of Apple's encryption for user data, educate users about the risks of jailbreaking, appreciate the role of server-side controls in mitigating service misuse, and encourage continued research to ensure the long-term security and integrity of these vital communication capabilities.

Key Takeaways

  • Apple's Starshields for iOS system leverages the Globalstar satellite constellation (code-named Stewie) to provide emergency, location, and messaging services in off-grid areas, operating within a highly resource-constrained environment of ~9 kilobits per second bandwidth.
  • The system employs robust, multi-layered security, including Secure Enclave Processor for LLC key generation, Elliptic Curve Diffie-Hellman (ECDH) for shared secret establishment, and end-to-end encryption (using AES-CTR for emergency messages and ECIES for Find My location data) to protect user privacy.
  • Apple confirmed that an additional layer of transport encryption, utilizing the shared secret, provides integrity protection for the communication channel, addressing initial concerns about potential message manipulation.
  • Researchers successfully demonstrated bypasses on jailbroken iPhones to circumvent both geographical restrictions (by modifying a config file) and feature limitations (by sending arbitrary text instead of location data, initially 160 bytes, later limited to 82 bytes by Apple).
  • Apple classified these bypasses as "monetization issues" rather than security vulnerabilities, as they did not compromise user data or system integrity, and implemented server-side mitigations to limit their impact.
  • The research involved significant reverse engineering of the iOS baseband and provides critical transparency into the previously opaque security architecture of Apple's satellite communication system.

About the Speaker(s)

The research presented in this talk, "Starshields for iOS: Navigating the Security Cosmos in Satellite Communication," was led by Jiska Classen, with the presentation delivered by her colleague, Alexander. While specific titles and affiliations for Jiska Classen and Alexander were not provided in the talk's metadata or transcript, their work demonstrates a deep expertise in reverse engineering, mobile security, and cryptographic analysis. Jiska Classen is known in the security research community for her contributions to mobile and wireless security. The collaborative nature of their work, including Alexander's presentation and Jiska's practical involvement (e.g., driving to Poland for testing), highlights their hands-on approach to uncovering the intricate details of complex, proprietary systems like Apple's satellite communication features.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Jiska Classen and collaborator do the hard thing: they crack open an opaque, hardware-rooted, baseband-adjacent proprietary system that nobody else has documented and come out with a credible cryptographic analysis, working bypasses, and a responsible disclosure loop that actually produced a server-side mitigation. This is exactly the kind of unglamorous, deep reverse-engineering work NDSS was built for.

Heather Calloway (CISO) — WEAK

Technically credible reverse engineering of Apple's satellite communication stack, but the talk never escapes the lab. The defensive implications section reads like a wrapper written to justify an academic paper, not a genuine attempt to tell operators what to do with what was found.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025