Wouldn't it be better to borrow from HTTP and allow a head request to the original source - with a reply of a current signature?
Isn't this whole exercise really just adapting public key signatures on top of old school caching?
With a http proxy you ask for an url, the proxy fetches or serves on behalf of the owner. This adds some circumvention around the way tls/ssl breaks that type of caching. But it should still be able to do a head-like request for a current signature - with no need to download the content again if it is unchanged?