@techreport{denis-ipcrypt-13, number = {draft-denis-ipcrypt-13}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-denis-ipcrypt/13/}, author = {Frank Denis}, title = {{Methods for IP Address Encryption and Obfuscation}}, pagetotal = 44, year = 2026, month = mar, day = 15, abstract = {This document specifies secure, efficient methods for encrypting IP addresses for privacy-preserving storage, logging, and analytics. Unlike truncation, which destroys data irreversibly, these methods are reversible with the encryption key while providing strong privacy guarantees. Four modes are defined: ipcrypt-deterministic (format-preserving, IP- address output), ipcrypt-pfx (prefix-preserving, native address size), ipcrypt-nd and ipcrypt-ndx (non-deterministic with random tweaks). All support high-performance processing at network speeds and produce interoperable results across implementations.}, }