5.8. Nonce
The Nonce payload provides freshness guarantees in GDOI exchanges by including random or pseudo-random data.
Usage
- Prevents replay attacks
- Ensures message freshness
- Used in cryptographic operations for key derivation
Technical Notes
- The data portion of the Nonce payload (i.e., Ni_b and Nr_b included in the HASH) MUST be a value between 8 and 128 bytes in length.
- Ni_b: Initiator's nonce, included in the HASH computation
- Nr_b: Responder's nonce, included in the HASH computation