Summary

  • RFC 9566 carries DetNet sequencing in a control word over MPLS-over-UDP/IP, letting service-layer nodes replicate a packet, eliminate duplicate arrivals and order the survivor stream.
  • A clean outgoing sequence proves what one configured PREOF chain released. It does not by itself prove that member paths were independent, why a sequence was absent, whether a late copy still existed, or whether the application met its deadline.
  • Operational evidence must preserve configuration, per-copy paths and timestamps, elimination-window decisions, ordering timers and the receiver's observed result as separate receipts.

A packet enters a protected DetNet service and becomes three. One copy crosses the fast path, one the slow path, and one a route that looks separate on the diagram but shares a conduit, power domain or queue with the first. At the merge point, the earliest copy survives. Later copies disappear as duplicates. A downstream ordering function waits for a missing sequence until its timer expires, then releases the buffered packets in a neat line.

That line is useful. It is not the history of everything that happened.

RFC 9566 brings Packet Replication, Elimination and Ordering Functions—PREOF—to the DetNet IP data plane by reusing the MPLS service sub-layer over UDP/IP. The DetNet Control Word carries sequencing information; an S-Label carries a receiver-side Service-ID; the UDP/IP tunnel provides the forwarding surface. Zero F-Labels mean the design can use MPLS header fields without requiring an MPLS forwarding plane.

The separation matters. The Service-ID says which local context a receiving node should apply. It is driven by the receiver, may change at relay nodes and may differ among member flows created by replication. It is not a globally authoritative name for the application packet. The UDP source port, addresses, prefixes, Flow Label, DSCP and other configured selectors help identify a flow, but matching them proves only that a packet entered a configured processing context.

Replication creates candidates, not independence

The architecture describes copies sent over multiple maximally disjoint paths. “Maximally” carries the operational burden. Two tunnels can traverse different visible hops and still share fibre, a queue, a failure domain, a clock, a controller mistake or an aggregation tunnel. RFC 9566 also notes that several DetNet flows aggregated in one UDP tunnel follow the same path.

A replication receipt therefore needs more than a counter saying three copies were made. It needs the configuration epoch, member-flow identifiers, actual paths, shared-risk information and per-copy departure and arrival times. Without those joins, three packet copies may be three expressions of one hidden dependency.

Elimination turns arrivals into a local verdict

Elimination uses sequencing to recognize replicas. A history window decides whether an arrival is new, duplicate, late or outside retained state. That decision is local to a flow context and an epoch. A sequence gap can mean network loss, delayed arrival, selector mismatch, state reset, window expiry, filtering or a copy that never entered the expected member flow.

The copy that survives was acceptable to the configured elimination function at that moment. It was not necessarily the copy with the lowest latency budget, the healthiest provenance or the only copy still in the network. Discarding a later replica prevents duplicate delivery; it does not make the first arrival an authoritative account of every path.

Ordering exchanges waiting time for a cleaner stream

RFC 9550 is explicit: the Packet Ordering Function supplies order within the DetNet flow's latency bound and adds no reliability. Its basic algorithm buffers a packet when a predecessor is missing and releases it when the predecessor arrives or POFMaxDelay expires. The timer is an engineered decision boundary. It is not proof that the missing packet never existed or cannot arrive later.

POF assumes duplicates have already been eliminated and that the delay difference among replicated paths is bounded and known. Violating either assumption can create duplicate out-of-order delivery or additional delay. Reset and initialization introduce their own epoch boundary. Conditional buffering can also increase burstiness, leaving regulation or de-jittering to a separate function.

The evidence chain is therefore longer than the sequence visible at egress: configured selector and Service-ID; source sequencing; each replicated member flow; path and queue observations; elimination-window state; chosen survivor and discarded copies; ordering buffer and timer; egress timestamps; application completeness and deadline result.

The disciplined conclusion follows Heng Lu's separation of symbolic authority from operating reality. A standard defines interoperable mechanics. Configuration authorizes local treatment. Running code produces events. Only joined observations can show that the promised service emerged.