PasskeyBridge —

NTN · 2026-10-01

Timing Side Channels at 550 km: What Orbital Latency Jitter Reveals and Hides

By J. W. Bouckaert

Timing Side Channels at 550 km: What Orbital Latency Jitter Reveals and Hides

Starlink's first-generation shells sit between 540 and 570 km, where the FCC moved them in 2021 from an earlier plan of 1,100 to 1,300 km. Light takes about 1.8 ms to cover 550 km straight up, and a terminal will track a satellite down to an elevation of 25 degrees, which stretches the slant range and the leg to roughly 3.6 ms. SpaceX's own latency note gives exactly that range, 1.8 to 3.6 ms per leg, and puts the round trip through the satellite at "usually under 10ms". Geoff Huston's measurement put the floor at 3.7 ms for a 550 km pass.

The rest of what a user sees is terrestrial. SpaceX reported cutting US peak-hour median latency from 48.5 ms to 33 ms and the p99 from over 150 ms to under 65 ms, with the causes it names being scheduling on the radio link, buffer sizing and the location of ground points of presence; its stated goal is a stable 20 ms median. Ookla's 2026 reports put the best US states at 37 ms median in late 2025 and the network at 39 ms nationally in the first quarter of 2026, against 674 ms for Hughesnet and 750 ms for Viasat on geostationary orbits. The satellite hop, then, is a small fraction of the total, and the total is now close to a wired connection. Where a link stands out is in how it varies.

The fifteen-second rhythm

Every measurement campaign since 2022 has found the same signature. Mohan and colleagues, in the paper presented at WWW 2024, wrote that "Starlink performs network reconfigurations every 15 s, leading to noticeable latency and throughput degradations at sub-second granularity", that the reconfigurations are "globally synchronized and likely independent of satellite handovers", and that the interval is the time-step at which satellite paths are reallocated to users. Huston found that "the minimum latency changes regularly every 15 seconds", measured the average jitter between successive round-trip intervals at 6.7 ms, and recorded a worst case of a 30 ms to 80 ms shift when a terminal was moved to a different spacecraft. A 2026 vehicular study pinned the boundaries to the 12th, 27th, 42nd and 57th second of every minute. A 2026 one-way measurement at 500 Hz found latency spikes of about 140 ms at the start of each cycle and about 75 ms at its end, with a stable regime in between.

That is a fingerprint. A server that timestamps a client's requests, or a long-lived connection's keepalives, at sub-second resolution can see a latency floor that steps every fifteen seconds on a global clock and infer the link type with no help from an IP database. It is a coarse inference, but it is a true one, and it is the first thing a satellite link reveals about itself.

The distance rule breaks

The oldest trick in network geolocation is that a round trip bounds a distance. Constraint-based geolocation, published in 2004, rests on the observation that light in fibre travels at about two thirds of c, so that "1 ms RTT per 100 km of cable" is a hard lower bound on how far away a host can be. Fraud tooling inherited the idea: measure the round trip, compare it with the distance the claimed IP location implies, and flag the mismatch as a proxy or a relay. A US patent granted in 2021 claims exactly this, anomaly detection on round-trip times to pre-selected location servers.

A satellite link breaks the rule in two directions. It adds up to a few milliseconds in the sky, which the bound absorbs. It then delivers the traffic to a ground point of presence that can be in another country, which the bound cannot see. Measurement studies found Starlink users associated with neighbouring PoPs for redundancy and load balancing, address blocks labelled for Seattle that routed to Frankfurt, and, after the Philippines got a local PoP in May 2023, in-country latency falling by 90 percent because traffic had until then been going through Japan. Ookla measured Kenya at 289 ms before the Nairobi PoP opened in January 2025 and 53 ms afterwards. The geofeed the operator publishes is itself unreliable: a 2025 IETF study found a dish inside the Arctic Circle listed as Vancouver, more than 2,400 km away, and a Delft thesis found a French subnet labelled with the Doha PoP.

So the honest reading of a satellite user's round trip is that it says something about the distance from the PoP, and the PoP is a choice the operator makes for its own reasons. Fingerprint's engineering blog says of VPN detection by latency that it "is indirect and inaccurate"; SEON's documentation still suggests that a connection "slower than expected" points to a proxy. Both were written for terrestrial links. On a satellite link the second heuristic produces a false positive on every user, and the more careful first one is the right one. This is the second thing the link does: it hides distance behind the ground segment.

There is a stranger property, and it comes from the 3GPP design rather than from any operator's implementation. On a terrestrial cell the base station tells a phone how much to advance its transmit timing, and the phone obeys. On a non-terrestrial cell the delay is too large and changes too fast for that loop, so Release 17 moved the computation to the device. TS 38.300 states that in this release the NTN-capable UE is GNSS-capable, that it "shall have valid GNSS position as well as ephemeris and Common TA before connecting to an NTN cell", that it computes the round trip to the reference point from its own position and the satellite ephemeris broadcast in SIB19 and pre-compensates both its timing advance and its Doppler shift, and that "if the UE does not have a valid GNSS position and/or valid ephemeris and Common TA, it shall not transmit until both are regained". The reference scenario in TR 38.821 gives the scale: a maximum round trip of 25.77 ms for a 600 km transparent payload, and a maximum differential delay of 3.12 ms between two devices in the same cell.

Read as an identity engineer, that says the physical layer of a direct-to-device satellite link has the device's position as an input. The network does not learn the coordinates, since what it sees is a transmission that arrived on time, but a device that lies about where it is cannot stay on the air. This is the property our Doppler validation leans on from the other side: the expected frequency and range rate for a claimed position and a public ephemeris can be computed on the server, and a claim that does not match the physics fails. Timing on an orbital link is evidence in a way that timing on a wired link never was, because the link cannot function unless the timing is right.

Timing attacks in a jittery channel

The reveal-and-hide pattern applies to the classic timing side channel as well. Brumley and Boneh showed in 2003 that a remote attacker could extract an RSA private key from an OpenSSL server, on a campus network, in about two hours and a million queries. The obvious hope is that a link with 6.7 ms of average jitter and 140 ms handover spikes would bury a microsecond-scale leak. Crosby, Wallach and Riedi took that hope apart in 2009: they measured events "with 15-100 us accuracy across the Internet", reliably distinguished processing-time differences "as low as 20 us" after filtering, and characterised Internet jitter as a "highly skewed distribution" in which "up to 75 percent or more of Internet measurements may be unacceptably noisy". Skewed noise is filterable noise: the fast tail of the distribution is the true path, and enough samples find it. A satellite link changes the number of samples an attacker needs, and changes nothing about whether the attack works.

The defensive conclusion is unchanged, then. Constant-time comparison of secrets and signatures, and a decision path that does not vary in duration with the outcome, are required whatever the link, because jitter is a cost to the attacker rather than a protection for the defender. The one timing property a verifier can influence is the one it emits. Our post on attestation fatigue describes the oracle in the other direction: a verifier that answers in 22 ms from a live check and in under a millisecond from a cache tells an observer which one happened. On our ingest path the measured figure, decision_ms, is stamped on the server and excludes every network hop, which is what lets it be read as a number rather than asserted; it is also why it is not a channel that carries the link's jitter, which is the property that makes it useful for monitoring and useless to an attacker sitting on the link.

Our own coefficient takes a number on trust

Candour section. The combined trust coefficient in the A2A handshake subtracts a jitter penalty: nothing up to 150 ms, then a linear penalty reaching 0.20 at 1,000 ms. The number it penalises is network_jitter_ms, and in the negotiate handler that value is read from the request body, with a default of 50 when it is absent, and stored in the negotiation's metadata. It is reported by the agent, not measured by the platform. An honest agent on a satellite link reports its 15 s spikes and takes the penalty; a dishonest agent reports 40 and takes none. The penalty is therefore a statement about what a well-behaved agent will admit to, and a cooperative agent pays it for being on a worse link. That is a design choice we made for a protocol with no negotiation volume behind it yet, and it is the right thing to change before there is: the value should be the platform's own observation of the handshake's request timing, which the replay-protection layer already has, since every mutating action carries a client timestamp checked against a five-minute drift tolerance and a nonce that expires after five minutes.

The provenance guard's carrier channel makes the opposite mistake on purpose. Its carrier_jitter_entropy field is bounded, with zero read as synthetic and anything above 1.0 read as noise, because a jitter series that is too clean is the signature of a replayed capture rather than of a good link. That is the correct way to use jitter: as a check on the plausibility of a claimed channel, never as a measure of the claimant's honesty.

Using orbital timing without fooling yourself

Four rules fall out of the above, for anyone feeding link timing into an identity or fraud decision.

SignalSound inferenceUnsound inference
Latency floor steps every 15 s on a global clockThe session is on a LEO satellite linkThe user is in any particular place
Round-trip time against the IP's claimed locationDistance from the operator's PoP, if the PoP is knownDistance from the user, or proxy use
Jitter distribution of a claimed carrier channelWhether the series is plausible for a live link (too clean means replayed)How trustworthy the party on the channel is
A device's timing advance and Doppler on an NTN cellThe device's claimed position is consistent with the physicsAnything, if the value is self-reported rather than observed

First, latency and jitter classify a link; they do not locate a person, and on a satellite link the round trip is a fact about the ground segment. Second, a self-reported timing value is a claim, and a claim from the party being scored is worth what any other unverified claim is worth. Third, the one place timing is physical evidence, the NTN air interface, is also the place where the evidence lives in the carrier's core and reaches a verifier only as a carrier signal, which is why the carrier-signal path is the one to build on rather than anything measured at the application layer. Fourth, a verifier's own response timing is a side channel it emits, and the only defensible policy is that the decision path takes the same time whatever it decides.

Left open

The one-way delay of a satellite link, up versus down, is the measurement that would separate the sky from the ground segment cleanly, and it needs synchronised clocks at both ends: GPS to tens of microseconds, per RFC 7679, or NTP to a few milliseconds, which is too coarse for the 1.8 ms leg. The 500 Hz bidirectional campaign published in January 2026 is the first we know of at that resolution, and its results are for one terminal in one place. Whether the fifteen-second signature survives the operator's stated move towards a 20 ms median, and whether the shells planned at 340 to 360 km change the floor enough to matter, are questions for the next measurement rather than for this post. The technical whitepaper places the orbital work within the three-pillar architecture, and the Doppler post has the error budget for the part of it that is in production.

Start free · Test the API