Summary
- RFC 9758 divides an
ipnURI into allocator, node and service numbers, letting one coordinated allocator namespace support many locally managed node registries. - BPv7 resolves that durable name hop by hop; the tuple contains no location, reachability or routing evidence.
- LocalNode and Private Use values remain useful only while borders enforce their scope, and endpoint identity still requires a separate security result.
Picture a bundle waiting through a long disconnection. Its destination may move before the next contact appears. A locator baked into the identifier would age while the data waits. RFC 9758 takes the opposite approach: keep the name stable, and let the network answer the routing question again at every hop.
That decision is the standard's most important feature. The document updates the compact ipn URI used with Bundle Protocol version 7. What was once expanded as “InterPlanetary Network” is now simply the scheme's name; compact integers can help any system constrained by energy, bandwidth or computation. But compactness does not turn the number into geography.
Three numbers, three responsibilities
Every ipn URI is a tuple: Allocator Identifier, Node Number and Service Number. The allocator component identifies the organization responsible for its Node Numbers. The node component is shared by resources hosted on one bundle node. The service component distinguishes functions on that node. Allocator plus node forms the Fully Qualified Node Number, or FQNN.
This hierarchy avoids a single global registry for every node. IANA coordinates Allocator Identifiers. An allocator can then issue Node Numbers under its own policy, needing only to keep its own assignments unique. An organization may receive a consecutive range and use distinct identifiers for sub-organizations. The grouping was inspired by CIDR, yet RFC 9758 states the limit plainly: Allocator Identifiers identify organizations; they are not addresses.
The distinction is more than vocabulary. An IANA row can show that one allocator identifier belongs to one change controller. An allocator's own record can show which node received a number. Neither record shows where that node is today, whether a contact is available, which convergence layer should carry the next copy, or whether the named service is running.
A route is deliberately missing
BPv7 uses late binding. A relay resolves the destination EID to an address or next action as the bundle passes through that relay. RFC 9758 consequently forbids implementations from treating any ipn component as location, reachability, addressing or routing information. Even if an allocator happened to derive a Node Number from a link-layer address, receivers must treat the result as a number, not reverse-engineer it into a forwarding instruction.
The architecture therefore creates a useful chain of separately testable claims. The registry can prove uniqueness within its stated rules. A binding table can show the route a node currently prefers. A forwarding log can show that a contact was attempted. A custody or status report can show a later protocol event. An application receipt can show that the intended result occurred. One cannot be substituted for the next.
RFC 9758 is explicit that an ipn endpoint is not guaranteed reachable. It is equally explicit that Bundle Protocol alone never guarantees the identity of the processing entity operating at that endpoint. A Block Integrity Block protecting the primary block is the relevant BPSec mechanism for verifying the asserted security source, subject to the receiving node's policy and key material. A valid-looking name is not that verification.
Scope is part of meaning
The cleanest test comes from the special numbers. The all-zero tuple is the Null ipn URI: it names nowhere, and a destination using it is unreachable by definition. Service zero names a node's Administrative Endpoint. The reserved LocalNode value names a service only on the current bundle node. It must not leave that node, appear in external discovery or be advertised as a peer identity.
Private Use FQNNs are wider but still bounded. Under the Default Allocator, the current registry reserves Node Numbers 1 through 0x3FFF for that purpose. Their uniqueness is meaningful only inside the administrative domain that coordinates them. A gateway must prevent a bundle using such a source or destination from crossing into another domain. Otherwise two perfectly valid local allocations can become one ambiguous external name.
This is why a scope leak is not merely untidy metadata. It destroys the property on which name-based decisions depend. RFC 9758 warns that leaked LocalNode or Private Use values can be abused to impair a BPv7 network. The border is therefore part of the namespace's correctness.
Equal meaning can have unequal bytes
The update also introduces an explicit three-element CBOR representation while retaining the packed two-element form. EID comparisons operate on decoded allocator, node and service values, so two wire encodings of the same tuple identify the same endpoint. Syntax-based integrity checks can still distinguish their bytes.
Backward compatibility does not make old decoders forward compatible. A legacy BPv7 implementation may reject the newer three-element form as malformed. Mixed fleets need a deliberate encoding policy and evidence from both ends; “supports ipn” is too broad a product claim to settle the question.
The current registry is a ledger, not an oracle
At the research snapshot, IANA listed ipn as a permanent URI scheme and maintained three related registries: allocator identifiers, Default Allocator Node Numbers and BPv7 well-known service numbers. Lower allocator numbers encode more efficiently, so expert review must also protect the scarce compact end of the space. A well-known service assignment aids convention, but the standard notes that configuration may still be required. The row does not start the service.
Heng Lu's minimum-specification principle fits this arrangement unusually well. The common layer keeps only what must be common: enough structure to prevent collision and make responsibility legible. Node assignment, binding, forwarding and security stay closer to the actors that can execute and verify them. The mistake begins when the public ledger is promoted from one reality layer into proof of all the others.
Sources
- IANA Uniform Resource Identifier (URI) Schemes
- RFC 1918: Address Allocation for Private Internets
- RFC 3986: Uniform Resource Identifier Generic Syntax
- RFC 4838: Delay-Tolerant Networking Architecture
- RFC 6260: Compressed Bundle Header Encoding
- RFC 7116: Licklider Transmission Protocol, Compressed Bundle Header Encoding, and Bundle Protocol IANA Registries
- RFC 8126: Guidelines for Writing an IANA Considerations Section
- RFC 9171: Bundle Protocol Version 7
- RFC 9172: Bundle Protocol Security
- RFC 9174: TCP Convergence-Layer Protocol Version 4
- RFC 9758: Updates to the 'ipn' URI Scheme
- Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption
- On Reality Layers, Symbolic Power, and Why Clarity Feels So Hostile
- Running-Code Primacy
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
