Skip to main content

5.8. Nonce

The Nonce payload provides freshness guarantees in GDOI exchanges by including random or pseudo-random data.

Usage​

  • Prevents replay attacks
  • Ensures message freshness
  • Used in cryptographic operations for key derivation

Technical Notes​

  • The data portion of the Nonce payload (i.e., Ni_b and Nr_b included in the HASH) MUST be a value between 8 and 128 bytes in length.
  • Ni_b: Initiator's nonce, included in the HASH computation
  • Nr_b: Responder's nonce, included in the HASH computation