Cryptographic Protection of TCP Streams (tcpcrypt), May 2019
- File formats:
- A. Bittau
- tcpinc (tsv)
Discuss this RFC: Send questions or comments to the mailing list [email protected]
This document specifies "tcpcrypt", a TCP encryption protocol designed for use in conjunction with the TCP Encryption Negotiation Option (TCP-ENO). Tcpcrypt coexists with middleboxes by tolerating resegmentation, NATs, and other manipulations of the TCP header. The protocol is self-contained and specifically tailored to TCP implementations, which often reside in kernels or other environments in which large external software dependencies can be undesirable. Because the size of TCP options is limited, the protocol requires one additional one-way message latency to perform key exchange before application data can be transmitted. However, the extra latency can be avoided between two hosts that have recently established a previous tcpcrypt connection.
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 8729.