Summary
- RFC 1108 defined IPv4 option 130 so classification level and protection-authority flags could travel with a datagram and influence validation and routing.
- The option was not encryption or a universal Internet policy: it depended on shared label meanings and remained relevant mainly inside bounded high-security environments.
Policy inside the header
The option began with a type octet whose value was 130. Its copy bit meant that fragmentation copied the label into every fragment. It could appear only once, and its variable length started at three octets: type, length and one classification byte. Protection-authority flags could follow, but they could also be absent.
That small shape carried a large institutional assumption. RFC 1108 described standard security labels that a system could use to validate transmission, validate delivery and ensure that the selected route offered protection acceptable to every authority indicated in the packet. The label therefore belonged to forwarding policy as well as endpoint processing.
The classification byte was deliberately not a simple ordinal scale. Values were sparse encodings, with reserved and unlisted patterns treated as errors. An implementation could not safely decide that one label outranked another by ordinary arithmetic comparison. It had to know the defined vocabulary. The following authority field was a bitmap: several programmes could claim handling relevance at once, and the final octet could be padded. Those authorities stated whose rules applied; they were not themselves accreditation authorities.
The design reached beyond one host. If routers were to choose paths according to labels, routing protocols had to distribute security-label information. The packet could announce what protection it required, but the network still needed a shared map of which routes could satisfy that requirement. Classification syntax without aligned route knowledge was only half a control system.
This also marks the boundary of the mechanism. The option did not encrypt the payload. It did not prove the sender's identity, publish a current list of authorities or establish that every intermediate system enforced the same policy. It carried metadata on which a configured security domain could act.
A narrow survival
By 2014, RFC 7126 treated many IPv4 options as operational liabilities. Yet it did not place option 130 in the same category as experiments with no remaining deployment case. It recorded use in particular high-security environments and noted implementations in operating systems and routers known at the time. A blanket edge rule dropping every packet with the option could therefore break legitimate, bounded deployments.
That is not evidence of broad public-Internet adoption. The cited RFCs provide no current market share, no universal firewall default and no active authority roster. Their narrower claim is more instructive: a mechanism can be awkward for general transit while still serving a specialised domain whose participants share labels, routing information and enforcement rules.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
