Aggregation and Fragmentation Mode for Encapsulating Security Payload and Its Use for IP Traffic Flow Security
RFC 9347, “Aggregation and Fragmentation Mode for Encapsulating Security Payload and Its Use for IP Traffic Flow Security”, is a Proposed Standard document published in January 2023 by C. Hopps. The canonical text is published by the RFC Editor.
Abstract
This document describes a mechanism for aggregation and fragmentation of IP packets when they are being encapsulated in Encapsulating Security Payload (ESP). This new payload type can be used for various purposes, such as decreasing encapsulation overhead for small IP packets; however, the focus in this document is to enhance IP Traffic Flow Security (IP-TFS) by adding Traffic Flow Confidentiality (TFC) to encrypted IP-encapsulated traffic. TFC is provided by obscuring the size and frequency of IP traffic using a fixed-size, constant-send-rate IPsec tunnel. The solution allows for congestion control, as well as nonconstant send-rate usage.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9347 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9346 IS-IS Extensions in Support of Inter-Autonomous System MPLS and GMPLS Traffic Engineering
- RFC 9348 A YANG Data Model for IP Traffic Flow Security
- RFC 9345 Delegated Credentials for TLS and DTLS
- RFC 9349 Definitions of Managed Objects for IP Traffic Flow Security
- RFC 9344 CCNinfo: Discovering Content and Network Information in Content- Centric Networks
- RFC 9350 IGP Flexible Algorithm
- RFC 9351 Border Gateway Protocol - Link State Extensions for Flexible Algorithm Advertisement
- RFC 9352 IS-IS Extensions to Support Segment Routing over the IPv6 Data Plane