Summary
- RFC 9985 separates authentication for BFD state-changing packets from authentication for the far more numerous unchanged
Uppackets. - The split creates bounded evidence about one BFD session. Routing, traffic and service decisions still need their own owner, policy and observation.
A cost boundary, not a confidence label
Calling a mechanism “less computationally intensive” can tempt a reader to translate it into “weak.” RFC 9985 explicitly avoids that shortcut. MCI and LCI describe their cost to an implementation, not a universal ranking of cryptographic worth. That distinction matters because BFD is useful only when it can run enough sessions at sufficiently frequent intervals to detect a failure in the bounded path it monitors.
The document is Experimental. It describes a candidate for examination and evaluation, says no implementations were known when it was published, and does not become a deployment fact merely because it has an RFC number. An IANA assignment is likewise a vocabulary entry, not an operations report.
Put expensive proof where the state can move
The division is deliberately asymmetric. Packets in AdminDown, Down, and Init require MCI. So do significant changes: a state transition, a Demand-bit change, a Poll or Final change, and certain parameter changes. In the Up state, a packet using LCI cannot alter content other than its Authentication Section. The design protects the moment at which the BFD state machine can acquire new meaning more intensively than the many packets that merely preserve the existing meaning.
That is a valuable piece of protocol governance. A system should not let a cheap, frequent signal quietly rewrite the state on which other components rely. But the protected state is still BFD state. RFC 5880 binds a BFD session to its encapsulation and to communication with a forwarding-plane next hop. It does not make the result a complete measurement of every application, every selected path, or every customer outcome that may sit beyond that session.
A periodic challenge closes only a session-sized window
LCI is not meant to run indefinitely without a more costly check. RFC 9985 calls for periodic MCI reauthentication through a Poll sequence. If the corresponding MCI-authenticated Final does not arrive within the specified bound, the session must be brought down. The interval is configurable: the operator chooses a cadence in light of capability and risk.
This gives a security team a concrete control surface: record the configured interval, the two authentication modes, the key-management boundary, successful and failed Poll/Final observations, and the exact session and encapsulation to which they relate. RFC 9986 also narrows the comfort available from its current ISAAC pairing: key provisioning is outside its scope, its analysis is limited, and the construction is described as tolerable only for that specified use. Those are reasons to retain provenance, not reasons to infer a broader verdict.
Client notification is an interface, not a service decision
RFC 9985 recommends that an implementation wait to notify a BFD client that the session is Up until the LCI transition works. That is an unusually clear recognition that an internal state change can be technically valid yet premature for a dependent client.
The same discipline should continue beyond the BFD module. A routing client may consume BFD state under its own convergence rules. A traffic controller may need route, capacity, policy and rollback evidence. A service owner may need synthetic transaction or application telemetry before declaring a customer-facing outcome. None should inherit permission merely because an authenticated control packet arrived on time.
What a credible action record looks like
Treat the BFD result as one named input, not the whole decision. An action record should distinguish: authenticated MCI state transition; LCI continuity; periodic MCI reauthentication; BFD-client reaction; forwarding or control-plane change; application observation; approving owner; and rollback condition. RFC 9314’s separation of configuration and operational state is a useful model for the first part of that record. It does not remove the need for the latter parts.
Heng Lu’s coordination principle supplies the final restraint. A common technical artifact can make local verification portable; it does not transfer the responsibility for a later operational choice. Operators may adopt this experiment, reject it, or use another compatible control. The party that turns a BFD observation into action must own that decision and its consequences.
Sources
- RFC 9985 — Optimizing Bidirectional Forwarding Detection Authentication
- RFC Editor information — RFC 9985
- IETF Datatracker — RFC 9985
- RFC 5880 — Bidirectional Forwarding Detection
- RFC 9986 — Meticulous Keyed ISAAC for BFD
- RFC 9314 — BFD YANG Data Model
- IANA BFD Parameters
- RFC 9978 — Bidirectional Forwarding Detection Stability
- Heng Lu — Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
