[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: AH/ESP & Replay Protection



Phil,

        I think a major reason for the combinatorial complexity you allude
to in your message is because of the way in which ESP and the transforms
are currently separated.  If an integrity check and an IV were both
(optional) parts of the base ESP spec, then the transform specs would be
much cleaner and more easily separable.  The current structuring, in which
ESP is just a shell, tends to create more complexity at the next layer of
specification.

Steve