Skip to main content

Secret IV and its use with ESP

Document Type Expired Internet-Draft (individual)
Expired & archived
Author Jerome Etienne
Last updated 2001-05-24
RFC stream (None)
Intended RFC status (None)
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


This memo presents a system of secret IV for ESP, based on the encryption of the sequence number. It doesn't add any space overhead in the packet and its generation can be parallelized and precomputed. Compared to the common explicit random IV (current MUST for ESP RFC2405.3 [5], or AES-CBC.3 [7]), it is more secure, saves bandwidth (e.g. 8 bytes with DES/3DES and 16 bytes with AES) but requires slightly more computation.


Jerome Etienne

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)