Dear chairs,

We would like to request a slot in the IPSECME agenda at IETF 126 to present 
and discuss our updated draft on Stateless Encryption Profile for Enhanced 
Encapsulating Security Payload (EESP).

Topic/Title: Stateless Encryption Profile for Enhanced Encapsulating Security 
Payload (EESP)

Name of Presenter(s): Chao Shang

Length of time requested: 10 minutes

Name of draft(s) discussed: draft-xia-ipsecme-eesp-stateless-encryption-03


FYI: In the -03 draft,
1.we shift the document from describing a standalone “scheme” to a concrete 
stateless profile that cleanly builds on top of EESP and its IKEv2 negotiation.
2.We define more clearly how the stateless metadata is carried as EESP 
extensions, instead of looking like a separate security header, so implementers 
know exactly where things go.
3.We also tighten up the stateless keying model based on root keys and a 
canonical context, together with adding more implementation details, so both 
ends can derive per‑packet data keys on the fly without keeping per‑flow state.
4.On top of that, we add more practical guidance on KDF inputs, IV construction 
and uniqueness, and we expand the negotiation, security, and operational 
consideration text (key rotation, epoch handling, etc.) with large cloud, HPC, 
NIC/DPU pool, and AI scenarios in mind.


B.R.
Frank
_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to