Skip to content

Explicit QUIC Proxies for Server-Side Geo-blocking Bypass

Aurélien Buchet , Soyong Kim , Tom Barbette and Cristel Pelsser

arXiv October 2026
Featured image for Explicit QUIC Proxies for Server-Side Geo-blocking Bypass
Download PDF Full Text

This 2026 technical report, by Aurélien Buchet and 3 coauthors, was released as arXiv preprint arXiv:2610.06179. Topics covered include quic, connection migration, geo-blocking, http/3, proxy, and stork.

Full author list: Aurélien Buchet, Soyong Kim, Tom Barbette, and Cristel Pelsser.

Abstract

Geo-restricted content is increasingly common on the Internet, forcing users to rely on circumvention techniques, such as VPNs, to access the web from a seemingly different location. However, these often come with a financial cost and can degrade performance. The rise in popularity of the QUIC protocol, which allows connections to migrate between paths, opens opportunities to circumvent such restrictions. We scan web servers and find that a large portion of geo-blocked content is enforced on the server, at the application layer, rather than on-path. This check is performed once, when the request arrives, and is not repeated as the connection continues. This allows a client to issue its request from a whitelisted IP address and, once the server has accepted it, migrate the connection to an otherwise unauthorized address for the rest of the transfer (post-header migration). It bypasses the block while maximizing direct traffic, thereby reducing eventual circumvention-related costs. Building on this insight, we introduce Stork, an HTTP/2-to-HTTP/3 web proxy that bypasses geo-blocking while introducing negligible additional latency. We demonstrate that our solution is compatible with popular clients and servers. In controlled experiments with 2 MB requests, our proxy migrates 99% of the transferred data onto the unauthorized path. Across real-world targets that support QUIC migration, it migrates at least 75% of the data for more than 52% of them. On real geo-blocked content, post-header migration bypasses the block for 90% of domains, whereas post-handshake migration, as used by prior work, succeeds for only 60%. YouTube, one of the most widely used services on the Internet, is where the approach matters most: a video is not one transfer but a long series of chunk requests, each of which the server re-authorizes on arrival. Migration must therefore be repeated for every chunk, which post-handshake migration cannot do at all, while Stork still delivers more than 90% of the content over the direct path for a set of 37 geo-restricted videos.

Publication Details

Publication Type
Technical Report
Publication Date
October 2026
Available on
arXiv

Suggested citation

Aurélien Buchet, Soyong Kim, Tom Barbette, and Cristel Pelsser. 2026. Explicit QUIC Proxies for Server-Side Geo-blocking Bypass. arXiv preprint arXiv:2610.06179 (Oct. 2026).

BibTeX Citation

@techreport{Buchet2026,
	title        = {Explicit {QUIC} Proxies for Server-Side Geo-blocking Bypass},
	author       = {Aurélien Buchet and Soyong Kim and Tom Barbette and Cristel Pelsser},
	year         = 2026,
	month        = oct,
	day          = 5,
	journal      = {arXiv preprint arXiv:2610.06179},
	institution  = {arXiv},
	numpages     = 14,
	url          = {https://arxiv.org/abs/2610.06179},
	abstract     = {Geo-restricted content is increasingly common on the Internet, forcing users to rely on circumvention techniques, such as VPNs, to access the web from a seemingly different location. However, these often come with a financial cost and can degrade performance. The rise in popularity of the QUIC protocol, which allows connections to migrate between paths, opens opportunities to circumvent such restrictions. We scan web servers and find that a large portion of geo-blocked content is enforced on the server, at the application layer, rather than on-path. This check is performed once, when the request arrives, and is not repeated as the connection continues. This allows a client to issue its request from a whitelisted IP address and, once the server has accepted it, migrate the connection to an otherwise unauthorized address for the rest of the transfer (post-header migration). It bypasses the block while maximizing direct traffic, thereby reducing eventual circumvention-related costs. Building on this insight, we introduce Stork, an HTTP/2-to-HTTP/3 web proxy that bypasses geo-blocking while introducing negligible additional latency. We demonstrate that our solution is compatible with popular clients and servers. In controlled experiments with 2 MB requests, our proxy migrates 99% of the transferred data onto the unauthorized path. Across real-world targets that support QUIC migration, it migrates at least 75% of the data for more than 52% of them. On real geo-blocked content, post-header migration bypasses the block for 90% of domains, whereas post-handshake migration, as used by prior work, succeeds for only 60%. YouTube, one of the most widely used services on the Internet, is where the approach matters most: a video is not one transfer but a long series of chunk requests, each of which the server re-authorizes on arrival. Migration must therefore be repeated for every chunk, which post-handshake migration cannot do at all, while Stork still delivers more than 90% of the content over the direct path for a set of 37 geo-restricted videos.},
	archiveprefix = {arXiv},
	eprint       = {2610.06179},
	primaryclass = {cs.NI},
	groups       = {Technical reports},
	keywords     = {QUIC, Connection migration, Geo-blocking, HTTP/3, Proxy, Stork}
}

Related publications

Type to search · 183 items indexed
↑ ↓ navigate ↵ select