Implicit Initialization Vector for Counter-Based Ciphers in Encapsulating Security Payload
RFC 8750, “Implicit Initialization Vector for Counter-Based Ciphers in Encapsulating Security Payload”, is a Proposed Standard document published in March 2020 by D. Migault, T. Guggemos, Y. Nir. The canonical text is published by the RFC Editor.
Abstract
Encapsulating Security Payload (ESP) sends an initialization vector (IV) in each packet. The size of the IV depends on the applied transform and is usually 8 or 16 octets for the transforms defined at the time this document was written. When used with IPsec, some algorithms, such as AES-GCM, AES-CCM, and ChaCha20-Poly1305, take the IV to generate a nonce that is used as an input parameter for encrypting and decrypting. This IV must be unique but can be predictable. As a result, the value provided in the ESP Sequence Number (SN) can be used instead to generate the nonce. This avoids sending the IV itself and saves 8 octets per packet in the case of AES-GCM, AES-CCM, and ChaCha20-Poly1305. This document describes how to do this.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8750 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8749 Moving DNSSEC Lookaside Validation to Historic Status
- RFC 8751 Hierarchical Stateful Path Computation Element
- RFC 8748 Registry Fee Extension for the Extensible Provisioning Protocol
- RFC 8752 Report from the IAB Workshop on Exploring Synergy between Content Aggregation and the Publisher Ecosystem
- RFC 8747 Proof-of-Possession Key Semantics for CBOR Web Tokens
- RFC 8753 Internationalized Domain Names for Applications Review for New Unicode Versions
- RFC 8746 Concise Binary Object Representation Tags for Typed Arrays
- RFC 8754 IPv6 Segment Routing Header