HPE and Cisco propose TCP session upgrade to 1,016-octet options
Engineers from HPE, Cisco, and Arista have proposed an experimental TCP session type (SES-U) to the IETF that increases the maximum options field from 40 to 1,016 octets. This change aims to accommodate modern security headers like TCP-AO, potentially enhancing transport layer security for high-bandwidth streaming infrastructure.
Key Takeaways
- The SES-U proposal introduces upgraded segments (SEG-U) that utilize a Data Offset value of 0 to signal extended headers.
- Individual options are recommended to stay under 256 octets to minimize path MTU risks despite the 1,016-octet limit.
- Legacy middleboxes and hardware accelerators may discard these new segments, requiring application-layer 'Happy Eyeballs' approaches for compatibility.
- The draft requires participants to publish experimental results, including hardware upgrade needs and interoperability, within one year.
Why It Matters
This proposal addresses a critical bottleneck in transport layer security for high-bandwidth streaming infrastructure. By expanding the options field, engineers can deploy stronger 36-byte TCP Authentication Options without sacrificing other performance-critical headers. For the streaming ecosystem, this provides a path toward more resilient BGP sessions and control-plane security between CDNs and ISPs. The shift to a 1,016-octet limit allows for modern cryptographic algorithms that were previously too large for standard TCP headers. Watch for the IETF experimental results due by August 2027 to see if middlebox interference prevents wide-scale adoption in production networks.
Additional Context
The IETF's TCP Maintenance (TCPM) working group has been actively addressing header limitations that affect large-scale network operators. In early 2025, Cisco published updated guidance on TCP-AO deployment across its IOS XR routing platforms, documenting how the 36-byte authentication option consumes nearly the entire 40-octet options field when combined with timestamps and MSS negotiation. This operational constraint is precisely what motivated the SES-U proposal from HPE, Cisco, and Arista engineers. The TCP-AO standard (RFC 5925) was designed to replace the older TCP MD5 Signature Option, but its larger key identifiers and cryptographic algorithm fields have created real-world deployment friction on BGP sessions between content delivery networks and internet service providers.
Regulatory and standards-body momentum around transport-layer security has intensified over the past year. NIST finalized its post-quantum cryptography standards in August 2024, establishing FIPS 203, FIPS 204, and FIPS 205 for key encapsulation and digital signatures. These algorithms produce significantly larger signatures and public keys than current elliptic-curve schemes, which means future TCP authentication mechanisms will need even more header space than TCP-AO requires today. The IETF's TCPM working group held an interim session in March 2025 to discuss TCP option space exhaustion, where multiple presenters cited the 40-octet limit as a barrier to deploying newer security primitives alongside performance options like Accurate ECN and TCP Fast Open. This standards-track pressure gives the SES-U proposal a clear runway: if adopted, the 1,016-octet field would provide sufficient headroom for post-quantum authentication headers without displacing existing options.
On the technical side, middlebox compatibility remains the primary risk for any TCP options expansion. A 2024 study by researchers at CAIDA measured TCP option stripping across 14 major cloud and CDN paths, finding that approximately 12% of middleboxes on inter-domain paths silently drop options exceeding 40 bytes. For streaming infrastructure operators, this means SES-U adoption will depend on coordinated deployment across CDN edge nodes and ISP peering points. Arista Networks, a co-author on the draft, announced in June 2025 that its EOS platform would support TCP-AO with extended option fields on its 7800R series, signaling hardware-level readiness for larger option spaces. The convergence of hardware support, standards-body urgency around , and documented middlebox interference rates will determine whether SES-U moves from experimental status to production deployment before the August 2027 deadline.
Read full article at datatracker.ietf.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source