<?xml version="1.0" encoding="UTF-8"?>
  <?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
  <!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.3.8) -->


<!DOCTYPE rfc  [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">

<!ENTITY RFC2119 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml">
<!ENTITY RFC8174 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml">
<!ENTITY I-D.ietf-ipsecme-diet-esp SYSTEM "https://bib.ietf.org/public/rfc/bibxml3/reference.I-D.ietf-ipsecme-diet-esp.xml">
<!ENTITY RFC7296 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.7296.xml">
<!ENTITY RFC4301 SYSTEM "https://bib.ietf.org/public/rfc/bibxml/reference.RFC.4301.xml">
]>


<rfc ipr="trust200902" docName="draft-ietf-ipsecme-ikev2-diet-esp-extension-08" category="std" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true">
  <front>
    <title abbrev="EHC extension">Internet Key Exchange version 2 (IKEv2) extension for Header Compression Profile (HCP)</title>

    <author initials="D." surname="Migault" fullname="Daniel Migault">
      <organization>Ericsson</organization>
      <address>
        <email>daniel.migault@ericsson.com</email>
      </address>
    </author>
    <author initials="M." surname="Hatami" fullname="Maryam Hatami">
      <organization>Concordia University</organization>
      <address>
        <email>maryam.hatami@mail.concordia.ca</email>
      </address>
    </author>
    <author initials="S." surname="Céspedes" fullname="Sandra Céspedes">
      <organization>Concordia University</organization>
      <address>
        <email>sandra.cespedes@concordia.ca</email>
      </address>
    </author>
    <author initials="W." surname="Atwood" fullname="J. William Atwood">
      <organization>Concordia University</organization>
      <address>
        <email>william.atwood@concordia.ca</email>
      </address>
    </author>
    <author initials="D." surname="Liu" fullname="Daiying Liu">
      <organization>Ericsson</organization>
      <address>
        <email>harold.liu@ericsson.com</email>
      </address>
    </author>
    <author initials="T." surname="Guggemos" fullname="Tobias Guggemos">
      <organization>LMU</organization>
      <address>
        <email>guggemos@nm.ifi.lmu.de</email>
      </address>
    </author>
    <author initials="D." surname="Schinazi" fullname="David Schinazi">
      <organization>Google LLC</organization>
      <address>
        <email>dschinazi.ietf@gmail.com</email>
      </address>
    </author>
    <author initials="S." surname="Preda" fullname="Stere Preda">
      <organization>Ericsson</organization>
      <address>
        <email>stere.preda@ericsson.com</email>
      </address>
    </author>

    <date year="2026" month="August" day="31"/>

    <area>Security</area>
    <workgroup>IPsecme</workgroup>
    <keyword>Internet-Draft</keyword>

    <abstract>


<?line 61?>

<t>This document describes an IKEv2 extension for Header Compression to agree on Attributes for Rule Derivation. 
This extension defines the necessary registries for the ESP Header Compression Profile (EHCP) Diet-ESP.</t>



    </abstract>



  </front>

  <middle>


<?line 66?>

<section anchor="requirements-notation"><name>Requirements notation</name>

<t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL
NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED",
"MAY", and "OPTIONAL" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.
<?line -6?></t>

</section>
<section anchor="introduction"><name>Introduction</name>

<t>The ESP Header Compression Profile (EHCP) <xref target="I-D.ietf-ipsecme-diet-esp"/> minimizes the overhead associated with ESP by compressing both the ESP header and additional fields within the secured packet. EHCP utilizes Attributes for Rule Derivation (AfRD) that are specified for each Security Association (SA). Certain AfRD have already been established during the SA negotiation process through IKEv2. This extension facilitates the agreement on the remaining AfRD through IKEv2.</t>

</section>
<section anchor="protocol-overview"><name>Protocol Overview</name>

<t>As illustrated in <xref target="fig-overview"/>, an initiator intending to utilize the Header Compression Profile (HCP) informs its peer by sending a HCP_PROPOSAL Notify Payload during the IKE_AUTH and CREATE_CHILD_SA exchanges. The HCP_PROPOSAL includes a list of Proposals, each comprising an EHCP Name along with a set of AfRD <xref target="I-D.ietf-ipsecme-diet-esp"/>. Any AfRD for which the initiator wishes to specify no limitations SHOULD be excluded, i.e., an AfRD is only sent if the sending peer wants the receiving peer to select a subset of the available values. A given AfRD MAY be repeated with different values in order to provide a list of acceptable values. A range of possible AfRD values MAY be indicated as well.</t>

<t>If a Proposal contains an unknown HCP Name, or any AfRD in a Proposal is unknown, then the entire Proposal must be discarded by the responder. If none of the received Proposals are deemed acceptable, the responder MAY choose to discard the HCP_PROPOSAL Notify Payload. Nevertheless, it is anticipated that the responder will provide an explanation for rejecting all HCP Proposals. If the reason pertains to an AfRD with an unacceptable value, the responder SHOULD reply with a NO_PROPOSAL_CHOSEN Notify Payload.</t>

<t>Conversely, if the receiver identifies a suitable Proposal, it will respond with an HCP_PROPOSAL Notify Payload that includes the chosen Proposal. In cases where the AfRD was not explicitly stated, the responder will provide the AfRD unless it defaults to a standard value. Each AfRD MUST NOT be mentioned more than one time. When multiple values are provided for a specific AfRD (either multiple values being provided or via a range of acceptable values), the responder MUST NOT provide more than one value. The Proposal MUST NOT contain any range of AfRD.</t>

<t>Upon receipt of an NO_PROPOSAL_CHOSEN Notify Payload, the initiator has the option to restart the CREATE_CHILD_SA exchange.</t>

<t>When the initiator receives the HCP_PROPOSAL_CHOSEN Notify Payload, it will evaluate the Proposal to ensure that it aligns with the initial proposal and adheres to its policies prior to executing the HCP.</t>

<figure title="The parameters for Diet-ESP have been established through the HCP_PROPOSAL_CHOSEN Notify exchange. In this instance, the responder has opted for the second Proposal, which includes the specified AfRD. Any absent AfRD will default to its predetermined values." anchor="fig-overview"><artwork align="center"><![CDATA[
Initiator                         Responder
-------------------------------------------------------------------
HDR, SA, KEi, Ni -->
                           <-- HDR, SA, KEr, Nr
HDR, SK {IDi, AUTH,
     SA, TSi, TSr,
     N(HCP_PROPOSAL
         Proposal_ID=1, HCP Name="Diet-ESP"
           AfRD_a
           ...
           AfRD_i
         ...
         Proposal_ID=2, HCP Name="Diet-ESP"
           AfRD_a
           ...
           AfRD_j)
                           <-- HDR, SK {IDr, AUTH,
                                    SA, TSi, TSr,
                                    N(HCP_PROPOSAL
                                      Proposal_ID=2, HCP Name="Diet-ESP"
                                        AfRD_a      
                                        ...
                                        AfRD_j, 
                                        AfRD_k, 
                                        ...
                                        AfRD_u)
]]></artwork></figure>

</section>
<section anchor="hcpproposal-notify-payload"><name>HCP_PROPOSAL Notify Payload</name>

<t><xref target="fig-notify"/> describes the HCP_PROPOSAL Notify Payload.</t>

<figure title="Notify Payload" anchor="fig-notify"><artwork align="center"><![CDATA[
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Next Payload  |C|  RESERVED   |         Payload Length        |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|  Protocol ID  |   SPI Size    |      Notify Message Type      |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
]]></artwork></figure>

<t>The fields Next Payload, Critical Bit, RESERVED, and Payload Length are defined in section 3.10 of <xref target="RFC7296"/>.</t>

<dl>
  <dt>Protocol ID (1 octet):</dt>
  <dd>
    <t>set to zero.</t>
  </dd>
  <dt>SPI Size (1 octet):</dt>
  <dd>
    <t>set to zero.</t>
  </dd>
  <dt>Notify Message Type (2 octets):</dt>
  <dd>
    <t>Specifies the type of notification message. It is set to TBA1 for HCP_PROPOSAL_CHOSEN.</t>
  </dd>
</dl>

<t>When sent by the Initiator, the HCP_PROPOSAL Notify Payload contains a list of Proposals described in <xref target="fig-proposal"/>. When sent by the responder the HCP_PROPOSAL Notify Payload contains a single Payload described in <xref target="fig-proposal"/>.</t>

<figure title="Proposal" anchor="fig-proposal"><artwork align="center"><![CDATA[
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|  Proposal ID  |   HCP Name   |      Proposal Length           |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
~                          Proposal Data                        ~
|                                                               |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
]]></artwork></figure>

<dl>
  <dt>Proposal ID (1 octet):</dt>
  <dd>
    <t>The number identifying the Proposal.</t>
  </dd>
  <dt>EHCP Name (1 octet):</dt>
  <dd>
    <t>The identifier of the EHCP Name (see <xref target="tab:hcp-name"/>).</t>
  </dd>
  <dt>Proposal Length (2 octets):</dt>
  <dd>
    <t>The length in octets  of the Proposal Data.</t>
  </dd>
  <dt>Proposal Data:</dt>
  <dd>
    <t>A Proposal contains a set of parameters that are represented via Transform Attribute format <xref section="3.3.5" sectionFormat="comma" target="RFC7296"/> and detailed further as described in <xref target="sec-parameters"/>.</t>
  </dd>
</dl>

</section>
<section anchor="sec-parameters"><name>Attributes for Rule Derivation</name>

<t>Attributes for Rule Derivation (AfRD) follow the same format as the Transform Attribute <xref section="3.3.5" sectionFormat="comma" target="RFC7296"/> copied for convenience in <xref target="fig-attribute"/>.</t>

<figure title="Transform Attribute Payload" anchor="fig-attribute"><artwork align="center"><![CDATA[
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|A|       Attribute Type        |    AF=0  Attribute Length     |
|F|                             |    AF=1  Attribute Value      |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                   AF=0  Attribute Data                        |
|                   AF=1  Not Transmitted                       |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
]]></artwork></figure>

<t>There exist two categories of attributes: 1) generic attributes, which are applicable across all HCPs and serve to enhance the representation of a combination of AfRDs, and 2) AfRDs that are tailored to a particular HCP and possess a distinct value.</t>

<section anchor="generic-attributes"><name>Generic Attributes</name>

<t>This specification defines range_afrd_proposal as a Generic Attribute for Rule Derivation to specify that a given AfRD can be selected within a range of values.</t>

<t><list style="symbols">
  <t>Designation: range_afrd_proposal</t>
  <t>Attribute Format: 0</t>
  <t>Attribute Data: Let AfRD_min and AfRD_max be the minimum and maximum values of the proposed range, expressed following the Transform Attribute Payload format. The corresponding Attribute Data is the concatenation of AfRD_min and AfRD_max.</t>
</list></t>

<t>To avoid ambiguity, it is explicitly required that both AfRD_min and AfRD_max refer to the same type of parameter and that they are processed as attributes with values defining the minimum and maximum of the range. This ensures consistent interpretation during negotiation and compression.</t>

<t>The figure below illustrates a Proposal for a compressed SPI between 6 and 8 bit long. SPI are compressed by sending LSB, so in our case AfRD_min is an esp_spi_lsb AfRD set to 6 and AfRD_max is a esp_spi_lsb set to 8.  The esp_spi_lsb AfRD is detailed in the Diet-ESP EHCP <xref target="sec-diet-esp-ehcp"/> and is a 2 byte length Attribute. The resulting range proposal is expressed via the combination of the range_afrd_proposal and AfRD_min and AfRD_max.</t>

<figure title="Illustration of the use of the range_afrd_proposal defining a range of SPI length" anchor="fig-range_afrg_proposal"><artwork align="center"><![CDATA[
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|0|       range_afrd_proposal    | Attribute Length = 4 octets  |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|1|           esp_spi_lsb        | Attribute Value = 6          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|1|           esp_spi_lsb        | Attribute Value = 8          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

]]></artwork></figure>

</section>
</section>
<section anchor="sec-reg"><name>Registering a Header Compression Profile</name>

<t>An HCP needs to register an HCP Name taken from <xref target="tab:hcp-name"/> in <xref target="sec:hcp-name"/>, the specification that describes the operations of the EHCP, as well as the different AfRD. For each AfRD, the corresponding Attribute Type, the AF value, the Attribute Data or Attribute Value and the Default Value MUST be specified.</t>

</section>
<section anchor="sec-diet-esp-ehcp"><name>AfRD for the Diet-ESP HCP</name>

<t>This section defines the code points that are needed to agree on the AfRD between two IKEv2 peers as described in <xref target="sec-reg"/>.</t>

<t><list style="symbols">
  <t>HCP Name: "Diet-ESP" as specified in <xref target="tab:hcp-name"/>, <xref target="sec:hcp-name"/>.</t>
  <t>Specification : <xref target="I-D.ietf-ipsecme-diet-esp"/></t>
</list></t>

<t>The following Attributes for Rule Derivation are defined:</t>

<t>DSCP Action</t>

<t><list style="symbols">
  <t>Designation: dscp_action</t>
  <t>Attribute Format: 1</t>
  <t>Attribute Value: DSCP Action takes discrete values coded over one byte as described in DSCP Action Value Registry  (<xref target="tab:dscp_action"/> in <xref target="sec:dscp_action"/>)</t>
  <t>Default Value: the default value is set to "not_compressed"</t>
</list></t>

<t>ECN Action</t>

<t><list style="symbols">
  <t>Designation: ecn_action</t>
  <t>Attribute Format: 1</t>
  <t>Attribute Value: ECN ACTION takes discrete values coded over one byte as described in the ECN ACTION Value Registry (<xref target="tab:ecn_action"/> in <xref target="sec:ecn_action"/>)</t>
  <t>Default Value: the default value is set to "not_compressed"</t>
</list></t>

<t>Flow Label Action</t>

<t><list style="symbols">
  <t>Designation: flow_label_action</t>
  <t>Attribute Format: 1</t>
  <t>Attribute Value: Flow Label ACTION takes discrete values coded over one byte as described in the Flow Label ACTION Value Registry (<xref target="tab:fl_action"/> in <xref target="sec:fl_action"/>)</t>
  <t>Default Value: the default value is set to "not_compressed"</t>
</list></t>

<t>ESP Byte Alignment</t>

<t><list style="symbols">
  <t>Designation: alignment</t>
  <t>Attribute Format: 1</t>
  <t>Attribute Value: Byte Alignment takes discrete values coded over one byte as described in the Bit Alignment Value Registry (<xref target="tab:align"/> in <xref target="sec:align"/>)</t>
  <t>Default Value: the default value is set to "64 bit", which corresponds to the standard IPv6 bit alignment. The default value of 64 bit in this specification refers to the bit alignment used for Diet-ESP compression operations and does not override or contradict the alignment requirements of RFC 4303. Instead, the alignment specified here ensures compatibility with the SCHC compression framework, which is designed to operate efficiently in constrained networks.</t>
</list></t>

<t>ESP Trailer</t>

<t><list style="symbols">
  <t>Designation: esp_trailer</t>
  <t>Attribute Format: 1</t>
  <t>Attribute Value: ESP Trailer takes discrete values coded over one byte as described in the Bit Alignment Value Registry (<xref target="tab:esp_trailer"/> in <xref target="sec:esp_trailer"/>)</t>
  <t>Default Value: the default value is set to "Optional", which enables the ESP Trailer to be compressed.</t>
</list></t>

<t>Security Parameter Index (SPI) Least Significant Bits (LSB)</t>

<t><list style="symbols">
  <t>Designation: esp_spi_lsb</t>
  <t>Attribute Format: 1</t>
  <t>Attribute Value: SPI LSB designates the number of bits that are provided to infer the SPI. This number is between 0 and 32.</t>
  <t>Default Value: the default value is 32, which is the size of the standard SPI in the standard ESP.</t>
</list></t>

<t>Sequence Number (SN) Least Significant Bits (LSB)</t>

<t><list style="symbols">
  <t>Designation: esp_sn_lsb</t>
  <t>Attribute Format: 1</t>
  <t>Attribute Value: SN LSB designates the number of bits that are provided to infer the SPI. This number is between 0 and 32.</t>
  <t>Default Value: the default value is 32, which is the size of the standard SN in the standard ESP.</t>
</list></t>

</section>
<section anchor="iana-considerations"><name>IANA Considerations</name>

<section anchor="registration-of-ikev2-notify-message-types"><name>Registration of IKEv2 Notify Message Types</name>

<t>IANA has allocated one value in the "IKEv2 Notify Message Types - Status Types" registry:</t>

<figure><artwork><![CDATA[
  Value    Notify Messages - Status Types
-----------------------------------------
  TBA1    HCP_PROPOSAL
]]></artwork></figure>

<t>This specification requests the IANA to create a  Header Compression Profile registry (see <xref target="sec:hcp-name"/>), as well as the necessary registries for the ESP Header Compression Profile Diet-ESP, that is the Attributes for Rule Derivation (see <xref target="sec:afrg"/>) as well as, when required, the complementary specific AfRD Values associated with each AfRD (see <xref target="sec:afrg-val"/>).</t>

<t>Note that the term "Header Compression Profile" reflects the purpose of the registry, which is to define profiles for ESP header compression using the Diet-ESP methodology. While the registry is managed and utilized exclusively by IKEv2 for negotiating compression parameters, its scope is limited to ESP header compression and does not extend to IKEv2 itself.</t>

<t>All registries are "Specification Required".</t>

</section>
<section anchor="sec:gen-afrg"><name>Registry for Generic Attributes for Rule Derivation</name>

<t>Registry for Generic Attributes for Rule Derivation. When Associated Data is set to YES, the AF bit of the corresponding Transform Attribute Payload is set to 0; otherwise it is set to 1. The AfRD Code Point mentioned here MUST NOT be reused by any Registries associated with any Profile and is shared by all profiles.</t>

<texttable anchor="tab:gen-afrg">
      <ttcol align='left'>AfRD Code Point</ttcol>
      <ttcol align='left'>Full Name</ttcol>
      <ttcol align='left'>Designation</ttcol>
      <ttcol align='left'>Attribute Format</ttcol>
      <ttcol align='left'>Reference</ttcol>
      <c>65535</c>
      <c>RANGE AfRD</c>
      <c>range_afrd_proposal</c>
      <c>0</c>
      <c>ThisRFC</c>
</texttable>

<t>Each entry in the range is represented by two attributes (AfRD_min and AfRD_max), both following the 2-byte Attribute Type format specified in <xref target="RFC7296"/>. This ensures clarity and compatibility in all implementations.</t>

</section>
<section anchor="sec:hcp-name"><name>Registry for IKEv2 Header Compression Profile</name>

<texttable anchor="tab:hcp-name">
      <ttcol align='left'>Value (1 Byte)</ttcol>
      <ttcol align='left'>Designation</ttcol>
      <ttcol align='left'>Reference</ttcol>
      <c>0</c>
      <c>Diet-ESP</c>
      <c>ThisRFC</c>
      <c>1-255</c>
      <c>unallocated</c>
      <c>-</c>
</texttable>

</section>
<section anchor="sec:afrg"><name>Registry for Diet-ESP Attributes for Rule Derivation</name>

<t>Registry for Attributes for Rule Derivation for the ESP Header Compression Profile Diet-ESP. When Associated Data is set to YES, the AF bit of the corresponding Transform Attribute Payload is set to 0; otherwise it is set to 1.</t>

<t>The Diet-ESP Attributes for Rule Derivation registry specifies six AfRD parameters explicitly defined for Diet-ESP that are not part of the standard IKEv2 negotiation process. These attributes are required for implementing the Diet-ESP Header Compression Profile. The remaining attributes referenced in <xref target="RFC7296"/>, <xref target="RFC4301"/>, and related drafts (e.g., DSCP values) are already defined and negotiated during the creation of the CHILD SA.</t>

<texttable anchor="tab:afrg">
      <ttcol align='left'>AfRD Code Point</ttcol>
      <ttcol align='left'>Full Name</ttcol>
      <ttcol align='left'>Designation</ttcol>
      <ttcol align='left'>Attribute Format</ttcol>
      <ttcol align='left'>Reference</ttcol>
      <c>0</c>
      <c>DSCP Action</c>
      <c>dscp_action</c>
      <c>1</c>
      <c>ThisRFC</c>
      <c>1</c>
      <c>ECN Action</c>
      <c>ecn_action</c>
      <c>1</c>
      <c>ThisRFC</c>
      <c>2</c>
      <c>Flow Label Action</c>
      <c>flow_label_action</c>
      <c>1</c>
      <c>ThisRFC</c>
      <c>3</c>
      <c>Alignment</c>
      <c>alignment</c>
      <c>1</c>
      <c>ThisRFC</c>
      <c>4</c>
      <c>SPI LSB</c>
      <c>esp_spi_lsb</c>
      <c>1</c>
      <c>ThisRFC</c>
      <c>5</c>
      <c>SN  LSB</c>
      <c>esp_sn_lsb</c>
      <c>1</c>
      <c>ThisRFC</c>
      <c>6 - 2^16-2</c>
      <c>unallocated</c>
      <c>-</c>
      <c>-</c>
      <c>-</c>
</texttable>

</section>
<section anchor="sec:afrg-val"><name>Registries for the Values of Diet-ESP Attributes for Rule Derivation</name>

<section anchor="sec:dscp_action"><name>DSCP Action Value Registry</name>

<texttable anchor="tab:dscp_action">
      <ttcol align='left'>Value</ttcol>
      <ttcol align='left'>Designation</ttcol>
      <ttcol align='left'>Reference</ttcol>
      <c>0</c>
      <c>not_compressed</c>
      <c>ThisRFC</c>
      <c>1</c>
      <c>lower</c>
      <c>ThisRFC</c>
      <c>2</c>
      <c>sa</c>
      <c>ThisRFC</c>
      <c>3-255</c>
      <c>unallocated</c>
      <c>-</c>
</texttable>

</section>
<section anchor="sec:ecn_action"><name>ECN Action Value Registry</name>

<texttable anchor="tab:ecn_action">
      <ttcol align='left'>Value</ttcol>
      <ttcol align='left'>Designation</ttcol>
      <ttcol align='left'>Reference</ttcol>
      <c>0</c>
      <c>not_compressed</c>
      <c>ThisRFC</c>
      <c>1</c>
      <c>lower</c>
      <c>ThisRFC</c>
      <c>2-255</c>
      <c>unallocated</c>
      <c>-</c>
</texttable>

</section>
<section anchor="sec:fl_action"><name>Flow Label Action Value Registry</name>

<texttable anchor="tab:fl_action">
      <ttcol align='left'>Value</ttcol>
      <ttcol align='left'>Designation</ttcol>
      <ttcol align='left'>Reference</ttcol>
      <c>0</c>
      <c>not_compressed</c>
      <c>ThisRFC</c>
      <c>1</c>
      <c>lower</c>
      <c>ThisRFC</c>
      <c>2</c>
      <c>generated</c>
      <c>ThisRFC</c>
      <c>3</c>
      <c>zero</c>
      <c>ThisRFC</c>
      <c>4-255</c>
      <c>unallocated</c>
      <c>-</c>
</texttable>

</section>
<section anchor="sec:align"><name>ESP Byte Alignment</name>

<texttable anchor="tab:align">
      <ttcol align='left'>Value</ttcol>
      <ttcol align='left'>Designation</ttcol>
      <ttcol align='left'>Reference</ttcol>
      <c>0</c>
      <c>8 bit</c>
      <c>ThisRFC</c>
      <c>1</c>
      <c>16 bit</c>
      <c>ThisRFC</c>
      <c>2</c>
      <c>32 bit</c>
      <c>ThisRFC</c>
      <c>3</c>
      <c>64 bit</c>
      <c>ThisRFC</c>
      <c>4-255</c>
      <c>unallocated</c>
      <c>-</c>
</texttable>

</section>
</section>
<section anchor="sec:esp_trailer"><name>ESP Trailer</name>

<texttable anchor="tab:esp_trailer">
      <ttcol align='left'>Value</ttcol>
      <ttcol align='left'>Designation</ttcol>
      <ttcol align='left'>Reference</ttcol>
      <c>0</c>
      <c>Mandatory</c>
      <c>ThisRFC</c>
      <c>1</c>
      <c>Optional</c>
      <c>ThisRFC</c>
      <c>2-255</c>
      <c>unallocated</c>
      <c>-</c>
</texttable>

</section>
</section>
<section anchor="security-considerations"><name>Security Considerations</name>

<t>The protocol defined in this document does not modify IKEv2.</t>

<t>Proposals may be expressed in various ways and a proposal may be expressed in a specific way so that its treatment overloads the receiver. The receiver needs to consider aborting the exchange when too much resource is required.</t>

</section>
<section anchor="acknowledgements"><name>Acknowledgements</name>

<t>The authors extend their gratitude to Samita Chakrabart, Tero Kivinen, Michael Richardson and Valery Smyslov for their long time support. The authors would like to acknowledge the support from Mitacs through the Mitacs Accelerate program.</t>

</section>


  </middle>

  <back>



    <references title='Normative References' anchor="sec-normative-references">

&RFC2119;
&RFC8174;
&I-D.ietf-ipsecme-diet-esp;
&RFC7296;
&RFC4301;


    </references>





  </back>

<!-- ##markdown-source:
H4sIAAAAAAAAA9U823bbRpLv+Ipe+UWaJXlEyVYc7XgmtCTH2ui2opyceVmd
JtAkOwYBDhqQzFjOt+zr/sbuj21V9RUAL1Ks7EmYc2Kx0V1dXV33KrDb7Ual
LFNxyE6zUhSZKNkPYsFOPsVTnk0EuxOFknnG9tj26Q8nd3s7THwqRUZj47xg
7wVPRMGO8tm8EIqGr4p8LFPBtt8fXe2wiI9Ghbg7ZCfvj/zaKMnjjM9g26Tg
47IrRTnuyrkS8Ux05Udxt9dNYKwr1LzrFnV3X0dyXhyysqhUube7++3uXsQL
wQ/ZUMRVIctFdD+Bk1wRnOjjvT9V9xj3iWJeHjJVJpEqYd0Mnp/cvIuiuTyM
GCvz+JAthII/VV7AhLFy3xcz/zXiVTnNC1zCWJf+z5jM4Olxj53LCa/S0ozq
Mx7zTIq08SgvANWTQsZKAT30mJhxmQJNaH5vpud/J8ykXpzP2nue99h7XvKZ
rG15zosFn9Wf0I5HeRbnRSI5+5BJul2gWm33GS3tTWnpdzgGG5tFvZi3MRj2
2NH//reai4Ro5ZEY8gyut/XwkXgoWt2LhV783XokfuqxQXmf50kNg3/vsZ9k
mkogRe3pI1G412t7nNZuwAAu/0xWjYuXC5lNgvE1tz7lRZ4mvVRWG278pse+
ryYTMcvr5L7JR5Kr5jPa8ez8Q32ziZn0XTbrybHspbOql4j2XniqYTyVGf+l
zmBwtjuZNJ/RZt/n+QTk/+zsqMHWykzuobh/NzGsteSEwFFXhUh4nZtAkkVt
fA0xFU7uzXFynZrw6Xa7jI9AA/C4jKKbqVQM1FE1E1nJgNHiQo6EYjxjpPE2
K7wyZ3xSCMHg70FZwvKqBAA4+7oCQhwDAne8hKk9prfzIBMxlhlMLqeCZQJ4
XYH0sUJMJOAnDRR8eDK8WqtsT0jbHqPShKmwER1zJpMkFXDmF4xdi39WshB4
TMWyvCSM8PyCfQSVfw+crdjW+YfhzVZH/8suLunv65P/+HB6fXKMfw/fD87O
3B+RmTF8f/nh7Nj/5VceXZ6fn1wc68UwympD0db54B/wBESdbV1e3ZxeXgzO
toAJ4MzhtYCWRzKPBDyCm4XjlyJhXEX2vhJc8/bo6n/+q/+Sff78L9fvjvb6
/W+/fDFfXve/eQlf7qci07vlWbowX4G8i4jP54IXCIWnKYv5XJY8VTBXMTXN
7zM2RYaK/vr3FO6LdQ/+/jeiKtiXIk+q2NPycRcFWJ12j3s1u2ctHuA5k5mc
yV8MY+SgnKYAEpBReSw5nv1ellPaa7Rgsd0HVM0oh3HLMFONB56XJ4lEJHnK
xmBc4KoRAhFaMIXmE4DOefxRlD201VesKmVKKKznabY9GF8f7wAcru8J1HUM
KgXA4WzB46kzz2xgDkDrhoMdsByiKDmggUBABd4JoD+Y5mQBly0yJlTJR6lU
UwCXAAw4ISI8HIC0TPLSgJoXOYoOPCryajLVgttjDVkb8xhOBHxvyEpCS+yV
azIUqDwy3IOwqUPD24ZLBCchT9kl3MidFPdRNFAMjESF2qTUXPj581hOurmZ
8eUL8huMS0Q2L4iBs4QOklsa0+4bXSmZAUFnsB/I71zAVLh6ZWBxBlNur64v
ry6HgzN2AaQZL9gVX6Q5r1EODnM7+HDznpji6PpkcHNye/T+9Oz4FmgqjNun
kHaiDlJmcVolqBgZ3AfQbIzozXNFYkLXTHwoiQ3hyMREF6C64UZzGCKO5YAx
rSUKr5cCsOjZQk9ETrqfyliztifmPXKGQkpqrluAYgP0ZlJrN8WMOgLFAWdD
/JMOkz3Ro0sh0MAipAsUMoIcG3nQVCUq33NUmJo/YiHv3APcVaQiLvFU1cgc
jDjrDowQ8C34zzytkJwDNgEXw2wJOg8xKgSoHCfLiRyPQcUAEnoNshKoZL0P
MDhYWxHQnsexmJeNPQry2eEpXIuS+Iz2MwDNthLOFnOtP9m9SFNg7VMA6K4T
7jFDmSQbWGUfM1R/9jI7gBSMm3tBdenXASnNdFKqWqjgRJLstpk0A1lBNBKp
Yg7nS5CNNXXVPM/gwD0G6GR5Jiw5Nd1hpmM4UjQJSm8SUKJTh0MHjqd5rsh4
mA21rK0Wlh67ECC7MCsFKQRuKfFcwAMylnMiG2m6+k7oKPpLArX1aZ7yTCsn
5N1C/Ax8QoIBE5GW7ih0Wg2NK9RlWiESU1se1aKDl9G89uaRDb8Da6F50xJ3
cenOCqJ+OTy5aB45isAXRg9YpIuOFQJDddBYCd7hWJLsq0rq7e0BiEJ0foOF
w3adRiIaOpWC28FFgdg5sECWDMywgqf3aHppjiYGJ/eFaAx3UqLsolJPmrSo
XYpbXmV4r4g0+F4YX2lKI4wsQf4guoINRI2mxdW4Qsi1aC7gUoELZjkhBedE
Ti3lDNb8hEw/A5hy7uSSWNVgoU0ityYy1vC3BRAM8G0uHAlSNXYprLyDWIV7
KW/pgJ2WBFjULRnqWJujoq538umWGC1Awu62RISBXT4AfM0gc62Nss1c1mno
7ik33s28NF50gda+0LK1yjTB5j9Z1eJhGV5VLeFehYrlWYEkAOahhY4GgAv4
DJUmVYmTeSonmfaZgq2JvfQS7WMhpxI/kY3OkT/hOxjFnNS4+ASOUGlNMeAJ
p/n111+jU3eQVZ9re6Xo1n/tJ3p/fN0BH6rDfjiRHXYhWbf7t2jl3oz9FUKJ
YE0BawoD5Af2+fQYgKBP0dEwcNLNUOL/CjN0sR1eit/KUvz29PhNv+OMzJst
G8hshWgh893ycKTX67UmyGj543CvvWfa6+edx5GNqFTUqLThs4SIGz6raLz2
8zSirP1oium/H72oQdTNG/zceTxwWvDxCQuejE21Q/L7+ZC9CJ1+0PklxNMf
u6Q23mzFAqPWLUap1jdbqG/nvAA6w6gOqiy5dQjUCn1sKLJBvTklicaTImhw
JMCuxS0/AZUvKF5jkUwMiMbbm3Xtb9dstA/tyA6Qf85H5DkbPwVUqjGrTgtC
YInnhJBWJNZX3foSUfi8xkWIIh1IZTQKMbFPzWzy4CKtVdku67M9ts9eslfs
gH3DXrNvnzIW/Wv3K/+LHsCZ/FQ6r4c9HD2ALj8Znlz/eHIMTPTg2MlOORPZ
BGyM+Tw8Cw4+bj091nsOr07ZEANPj4Oh4TmmoMDW3yzm4vlwCIVEX+gGEanf
KLILCo3JXIQ07bCjAoxnDCb4rSw7jrg6y9Ogqo4axsSJ4NkoQXkbtt/r76IX
o1NF3+x9ewDBZxSFVNvuszwuRblzGB1SCAvc/YsocpjmaLlmzjLibu/p6Yrm
D41oae4ucUKOURA63rEOJGZ6NQg3hSRmh5u3g77OTLb1gnWWSEJNmOV8jc4m
OQriwHbIz2qZNy2q1hnC0L21r9c9T9gWcwkYa9g8xvo9/0Bi731JK3IuG+Ik
zk2py/zzif1XfR6iX1c/dKgf85KvmvTrM+DwvKrHe+trlY89HagdFoUXWZNw
VEhZNRv5CHlhPXsfxEaRT4P51cwsd5F1YVMdwWwlBPA4+ACH03jexRrIly87
Wi3V2KauRxBsqh9gAokeMAu9dm0hKPyOqwfLkkA2ZRe4LC7ZWwhMViL5EopO
byBSVJim9FljVE4zmO61awcTwkbz7vdegW1HXQ1eApcpeiRVQfEwbykZUNhd
jwUp6Reb0tOfXzRWgXfwuIz2OE/T/F47Pngj5hwmbF120nVHjPO5zYnHmGzJ
pAC/zCsybqHQsf4oimxgRdgf0nsGRpMN3r3ZDScE6uwheni3XglYCP0Qwo/o
JT6fCliGQRPpdYrsYRWEPrlNmhVmskQh+P9RZI5ZNkUaS5i07lMVmBlH4w5g
GKaFJznVHTGp46TkkPV32ERkWEkNhm2MgIqAzzEbR7koHhe5UjbTqUi4FQRG
QudVphiPGJfAKA8tdrgl1hBGMnMDKIlK+3J7O/qbVz6oL3KsW1ECD0Qc/MAq
5eQK0RJMg2Oyj2Pyt4RQprQpL1AcL9j35kReHZhysM3PaTRsjZaSYLd8XCS3
3pAg8BacpVolKFLoE4QlgZhnmF7U9QRTEqDkusu8mcgpiv4CQBVcNkE9XIoV
zPG4vCO1dch2a6Ok8UFUdeR2O6NEX2K+8E+IDF4RFSKrGT2DYfrbpCeNTdGb
AsqESAfTsli+IlWH+tPaxDWsaDSrTkTGeWFcRSrE1QVUmlxxniGr1tmkdQa8
5RvgjLtcJowDW00qWS5sRj9IHxe6Mm6y0lRBXU6UQox1PcbZBOuoO/tCC2yF
YGGTv7GmCHKLNz2UTDTEJB6zpFpGdFsK0eG9rmxSilIhNRSwN9WvbHXccK6u
+4WlUoQZ+xJjzwZWE8x2jgQaPF/PVGF1R6eu7Vo4DQY+I1HeY7LigAC/ZiMg
Llb7evQUTx8sCOqVZ8O3HaZy8lGqghL9nuZUb2HABLdqLm9TNdIyYgKeg/qd
4OTaXDPtdY8RP7XAYF+BdTVM/dtlX8j90n6G7z8D98u4KLTXHpyjdE6WY1DN
vXBSzOLDCbXgzoPamJcM9JQ0H9eUnbvgppJx513C4X8UT2HX2shlJyBD3/IQ
3gAe1kN9FjvfD+10ePHO2Wj6GG+ADM9qpX8TDq+fF4eaq+CuY3L7yPDn1Mp/
wJaVEus41KmvwGChAtBCQtm+F+yauppEYfoVVrc7aJe9EBNYN9Cl50yIROka
kQZiCow6Vir5R9BB4yKftSImFzgEY50wmWmMPKnseooxn4vCtBEE0VnHls1t
IOAL9zop+s52veDXjpHz5TYNXWk9Y/AurOc2rB4AbPKMtjLoX+hkqx6l2t0o
yNP2iPCuhaKm60jVvWirOmadIBPAhC1qcZ6ATsul7ogwbhjejXHCbBucq7Za
+4DepW6nw9YJtSK2wyv/Qi6OvdpD5isR1IvlMtC0qH7XndZN99AVGtYu+nBD
14kxiM532RArBilFCOuj4yEgPjDtYA1PLVHx/JbrZ8sctH5tlG70kAUAic0V
9TFg/5t1HfBOEuoRo5ouGacmeUMomlW0MBYLxrY1GQPsQqmpDe/QkQKOO9QS
YIYIoSA1uZXl5a23/1uYDTm6WEUeEWdPpg6BO8K2wa8gDkm2B9SgjyGPxy6k
Tjj69cR5h97XGQcvbBWNxjDjNsUZTyZVCPw5KNaGt5xw43QJ3YLBZ+ApUGZv
Ec0BmjPs0GjRjbsnj6ZXHeJXEustuMUe1nJCEY4hkczAUwl08BK98C0bnHvb
o1zkYltdTq/uDshld/TRXmwdNhg/DdP15dZNJ0VFDngNHPoNSb3AGQQfoYWl
DGAudGsPErTAdhWdLANfJJGx7gvxoIuwnxlwvH53xF7u7+5j8RM8BNtw4hd4
26HTHi58ms0BiRH2hi58h8fw6P1RDdkxRnjoNrnSKF00QNfGTx8G4I7H2PaR
YWQJBMPoDA5ANadMkN+FUTySAkJicHcK1laF4DaW+uETdGEA8ffn1gDFmkIM
h5/KuZdz3aHseBci/FFqXI/a8agV3GsBjINcj/GVC8VPs0R8YtvgiO5AyMFV
yYZwKGJcONdbrE5vQyC6s5T+xm1/PP3R3wVohidcl7EpEQCDjmToNbm+LqyT
Z2NTFwMgJrq3pQXlfKhdEpL9PXJqHkPX/b2AVUnwsUxpfFmnBBBv2wdux/AV
AiTpPytKUl9oXLaHF7+FkNkT6Xjx5yTjxQoq0msCg4sBvm+kAFWj8SJKQRqx
crGW9pGXlIsVsDhBwc4NDs6pbuF1XXx28601ELpsWPKyUvrrln3NZHFosgg+
715f3lz5+B40gEn1acZqFV/ablmqFXW6UKbdmo4L1wo6DPUqZ+tixsLpJ103
q8cBO62o7WtetrG2rGPaA1U9aFtRVPJ4YTAOOAUodehVFJeItFHjbJ6SfUM0
6z2jP5re0sYLIS7ubG7XvcMS+Q4qSrhb4XuYsTOHba0+LHLJGJPS+pDzqsBs
r+/M1lQPBSQ38RCKJkLQ5AheRwmNaqVs0tM5CKC7p3mSp/lkgW0ESPBwK9xj
xjNgy4QE2bxCkegGfyXvBNjd0cJIEm7t0p+wU7i3rwl2qFNJxWDCETy9QKBV
ygq0a94KvWFCs/WeAEukY5D8ATVFO+5CdbVVD0bNO1nJVo+xmkJYEObtAsXq
EufhRGRd4iyA9BugmJaNgecom3E35vkfJ0OXq0Anz7BAPbexLsvvQe3+G8ux
xHsvgZVk2M3S1w4osfARJhuuMNkQtF2T6xZ2ZBeiMrllbFS+DsjdkA18bCXY
JHPVlBdmrW4VJ35Fnf3AWjg8sHcVzDI9HJTJC41do+DXsnYwdC0oURSL6KGt
KltDS+asexYMIfYHr17tv6ohdD24+P5En0oPrEjU0rPdVgWTzCn42JRYRA/Q
8Rs4s5ycNZLOzCcJkcRhgwB2At3nYQlke2laG7Q1FWHqBaS9LjmsjUK0Kco3
8kJBH1ejVpJychJtGcQ7/ubNP+l0LlnpXlsotZBvSl9640PcpC3rdp/Cyh2g
Zsg5AWfA323meFj5jSrTu42Lcpo0vDZmytj97t6rV8HkKvPOBDzu+jy0vefg
IE1SuJ0epaCWKqcNK59okf8oSkwnER9LHmfalGsCVPKTFtWg6SaoWNomxtol
+IQsGCWshrd8VM26S96cJK0LxwhEU3f3mMIo7uMko2WxV1+MLYrZ9yoD+IVl
+ZbIdsw3COb7+vXJBGandJ30cxGgN0Rv0uvotKZ59UV3IZh3Ry19cKk9bv0N
UnIqgwIHvWjChoPeb9b9v4/KX24FGsq+qa0faglfOxakcoOZ/aamD1Q96ovW
Q5/C9WM+DxrO3AB6r/WwlQCFsVbK8zGg91sPfT7DDPD6wAagDKG+bD21Mb8n
RLPgtxnqq9ZTCCWXQM2CKuJmqAegyvf+s3/Q3bNPQ03PbBNqtw7BfLqNMfru
DIIx+oE1CGOnH113yNOtA0Up2hF+sbZmoZeEtYkoCpvGWFM8GyZ2rYDVDWwg
XQ+snnxumtdAWh4YsK0I3+dqTt3zD1Sj86w2Fd9e2bdGu3WLwf2ENrtOGaRm
ILUNYmpaBpWMPx8pn0qe2mGROm3Fs5RIvmwRsT8dkfwD6uTjvluxOXXfT8X3
F1ayJkx9+VTSByTUfNkq3lh9QNWPBi+u8ZpXkngNeXW/0vKTBaTtH/h5a8i6
v7d6WkBSU0t5CjmXk9JSKDJktNlxI9BBJv73peI5epdljnp5HRVtdn8pFZ9y
7vrJXvhfF2kmWG90e6J+iSd476f+2zIujzPLE0x6mh8P8d3xmG9a6J+QsIII
QO4gkMwrxe75QlevuG/2WjY/eOsblmDvm3m3WDH8LbJS/xDJnSgwzAh/bwJ/
EOEmfB/f9cLE5ryMj/LCueX2JUCdUizznM0qCM8Bk7wqYhOUa7/etIfE+JsN
qUgmupimCad/5Ey57NZUyIJNkLZllVAr75Dj72ywoyn/WPARxBsddoPq4gf8
jQz8YZ1zCZiASr3Gf4tEmcQZ8KIAZhnOFirN76zjANDpZ0LwTXqmqvkcjqQP
bjG5z6s0Yan8SLtzj7UOcvQS3QV0DojF/vdg8LkZGsSxSHWhDq4LzjMDIvwf
+H3CrQdPAAA=

-->

</rfc>

