ietf-corpus

rfc-8064

Recommendation on Stable IPv6 Interface Identifiers

F. Gont, A. Cooper, D. Thaler, W. Liu
date2017-02 streamIETF areaint wg6man statusPROPOSED STANDARD pages9 canonicalhttps://www.rfc-editor.org/rfc/rfc8064 doi10.17487/RFC8064
This document changes the recommended default Interface Identifier (IID) generation scheme for cases where Stateless Address Autoconfiguration (SLAAC) is used to generate a stable IPv6 address. It recommends using the mechanism specified in RFC 7217 in such cases, and recommends against embedding stable link-layer addresses in IPv6 IIDs. It formally updates RFC 2464, RFC 2467, RFC 2470, RFC 2491, RFC 2492, RFC 2497, RFC 2590, RFC 3146, RFC 3572, RFC 4291, RFC 4338, RFC 4391, RFC 5072, and RFC 5121. This document does not change any existing recommendations concerning the use of temporary addresses as specified in RFC 4941.

updates

Extracted elements (11)

design-rationale §1

RFC 7217 is recommended as the default IID generation scheme because it produces semantically opaque identifiers that are stable within a subnet but change across networks, thereby preserving the operational benefits of stable addresses while eliminating the privacy and security harms of MAC-derived IIDs.

ip, privacy, security

design-rationale §1

Some network technologies such as IEEE 802.15.4 (RFC 6282) allow compression of IPv6 datagrams when the IID is based on the underlying link-layer address, which is an acknowledged advantage of the older scheme. This document does not resolve that tension but notes that future revisions of those documents should address the privacy considerations.

ip, privacy

design-rationale §1

The recommendations apply only when implementations would otherwise configure a stable IID containing a link-layer address; they do not change RFC 4941 temporary address recommendations and do not introduce new requirements for when stable addresses must be configured.

ip, privacy

interoperability-note §4

At time of publication, RFC 6282 (6LoWPAN compression), RFC 4944 (IPv6 over IEEE 802.15.4), RFC 6775 (6LoWPAN Neighbor Discovery), and RFC 7428 (IPv6 over G.9959) may require updates to be fully compatible with these recommendations; future revisions should explain any design considerations that lead to use of link-layer-based stable IIDs.

ip, privacy

interoperability-note §1

This document formally updates RFC 2464, RFC 2467, RFC 2470, RFC 2491, RFC 2492, RFC 2497, RFC 2590, RFC 3146, RFC 3572, RFC 4291, RFC 4338, RFC 4391, RFC 5072, and RFC 5121 by replacing the recommended default IID generation algorithm defined in each of those link-layer encapsulation specifications.

ip

normative-requirement §3 SHOULD

A link layer MAY define its own mechanism for stable IPv6 address generation that is more efficient but does not address the security and privacy considerations of RFC 8064. When such a mechanism exists, the choice of whether to enable the security- and privacy-preserving mechanism SHOULD be configurable.

ip, privacy, security

normative-requirement §3 SHOULD NOT

By default, nodes SHOULD NOT employ IPv6 address generation schemes that embed a stable link-layer address in the IID. In particular, the schemes specified in RFC 2464, RFC 2467, RFC 2470, RFC 2491, RFC 2492, RFC 2497, RFC 2590, RFC 3146, RFC 3572, RFC 4338, RFC 4391, RFC 5072, and RFC 5121 are not recommended.

ip, privacy, security

normative-requirement §3 SHOULD

Nodes SHOULD implement and employ RFC 7217 as the default scheme for generating stable IPv6 addresses with SLAAC. This replaces the prior default of embedding a stable link-layer address in the IID.

ip, privacy, security

privacy-consideration §1

Stable link-layer addresses embedded in IPv6 IIDs allow observers to correlate a node's activity across networks and track its location over time. Reusing identifiers with their own semantics across different contexts is detrimental to privacy, as documented in RFC 7721.

ip, privacy

protocol-element §1

The Interface Identifier (IID) is the lower 64 bits of a 128-bit IPv6 address used in SLAAC (RFC 4862). Traditionally formed from a Modified EUI-64 representation of the link-layer address per RFC 4291 Appendix A; this document changes the recommended default generation method to RFC 7217.

ip

security-consideration §5

Embedding a stable link-layer address in an IPv6 IID enables network-activity correlation, location tracking, address scanning, and device-specific vulnerability exploitation. RFC 8064 recommends RFC 7217 as the default stable IID generation scheme to mitigate these risks.

ip, privacy, security