Summary
- The 1992 CIPSO draft put a 32-bit Domain of Interpretation identifier ahead of security tags because numeric levels and categories had meaning only among systems sharing the same mapping.
- Hosts and ports enforced configured label ranges, while gateways crossing domain boundaries had to translate the option; a structurally valid number was not universal authority.
A compact label with a local dictionary
The Commercial IP Security Option was proposed for commercial multilevel-security systems that did not fit the US-DoD-specific Basic and Extended Security Option spaces. Its IPv4 type was 134. The option was variable in length, copied into fragments and permitted at most once in a datagram.
After the one-octet type and length came an unsigned 32-bit Domain of Interpretation identifier, then one or more tagged structures. DOI zero was reserved. The DOI identified the community whose mapping table translated compact numeric levels and categories into the labels understood by people and policy engines.
That indirection was not decorative metadata. The draft gave a simple example: unrelated groups might encode “Unclassified” as 5 and 1 respectively. Without the DOI, the number could not say which table should be used. A DOI authority defined the mapping and distributed it within its domain; because the mapping could itself be sensitive, publication outside that domain was not mandatory.
CIPSO divided the remaining information into tags. Types 0 through 127 were reserved for standardized formats intended for publication as RFCs. Types above 127 could be defined by a DOI authority, but only for closed networks where outside interoperability was not at issue. The draft defined three Mandatory Access Control sensitivity formats: tag type 1 used a category bitmap, type 2 an ascending category enumeration, and type 5 non-overlapping ascending category ranges. A conforming implementation had to generate ordinary tag type 1 and receive every valid type 1, including its optimized form.
Meaning enforced through configuration
Correct syntax was only the beginning. A multilabel host, gateway or router needed minimum and maximum labels for the system or interface. A host rejected labels it was not authorized to handle; an outgoing packet outside the configured port range was discarded. The DOI for outbound traffic could be selected by port, destination network or destination host.
The error path distinguished malformed meaning from forbidden meaning. An unrecognized CIPSO field caused discard and an ICMP Parameter Problem response. A syntactically valid label outside the configured range caused discard with an administratively prohibited ICMP Destination Unreachable. An administrator could explicitly mark selected unknown tag types as safe to ignore, but that was an extension to the default rejection rule.
Even the absence of an option required policy. A receiving port could assign its own label to unlabeled traffic, supporting a single-level network or a mixed segment whose unlabeled hosts all operated at one label. Where CIPSO was required, a missing option caused discard and an ICMP Parameter Problem indicating the missing type 134 option.
The boundary between DOIs made the institutional dependency visible. A system had to support at least one DOI and was encouraged to support several. A gateway forwarding between networks had to translate CIPSO from one DOI to another. The packet carried the compact label, but the gateway carried responsibility for preserving its meaning across administrative vocabularies.
A specification that did not become an RFC
The CIPSO 2.2 document remained an expired Internet-Draft rather than becoming an RFC. Its approach was later standardized by NIST as FIPS 188, published in 1994 and withdrawn in 2015. RFC 7126 recorded in 2014 that several multilevel-security operating systems implemented CIPSO and that it appeared in some high-security networks. Those are dated observations, not proof of current prevalence.
RFC 7126 also explained why indiscriminate filtering was risky. Removing CIPSO could make a receiver reject a packet as improperly labelled or, worse, associate the data with the wrong sensitivity. Its default advice was therefore not to strip or drop merely because CIPSO was present, while retaining configurable presence-based dropping and per-interface audit counts.
The durable lesson lies in the DOI. Numeric labels save packet space; they do not create shared semantics. The shared semantics live in an authority’s mapping, each system’s configuration and the translation performed at a boundary.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
