RFC 8750: Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP)
In plain English — editorial summary, not part of the RFC
Encapsulating Security Payload (ESP) sends an initialization vector (IV) in each packet. The size of the IV depends on the applied transform and is usually 8 or 16 octets for the transforms defined at the time this document was written. When used with IPsec, some algorithms, such as AES-GCM, AES-CCM, and ChaCha20-Poly1305, take the IV to generate a nonce that is used as an input parameter for encrypting and decrypting. This IV must be unique but can be predictable. As a result, the value provided in the ESP Sequence Number (SN) can be used instead to generate the nonce. This avoids sending the IV itself and saves 8 octets per packet in the case of AES-GCM, AES-CCM, and ChaCha20-Poly1305. This document describes how to do this.
Document record
- Document ID
- RFC8750
- Published
- March 2020
- Authors
- D. Migault; T. Guggemos; Y. Nir
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 8
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7634ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol (IKE) and IPsecCurrent
August 2015
- RFC 4301Security Architecture for the Internet ProtocolUpdated
December 2005
- RFC 8247Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2)Updated
September 2017
- RFC 8229TCP Encapsulation of IKE and IPsec PacketsObsoleted
August 2017
- RFC 8221Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)Updated
October 2017
- RFC 9329TCP Encapsulation of Internet Key Exchange Protocol (IKE) and IPsec PacketsCurrent
November 2022
- RFC 9395Deprecation of the Internet Key Exchange Version 1 (IKEv1) Protocol and Obsoleted AlgorithmsCurrent
April 2023
- RFC 7427Signature Authentication in the Internet Key Exchange Version 2 (IKEv2)Current
January 2015
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?