Summary

  • RFC 1455 assigned IPv4 TOS value 15 to request the route least exposed to surreptitious observation, but called it a preference rather than a guaranteed security level.
  • Participating routers translated that request through locally chosen relative costs for lines and router sites. A packet mark therefore proved intent, not common policy, actual path, encryption or confidentiality.
  • The proposal’s most durable lesson is an evidence boundary: a declared service class has no more authority than the nodes that recognize it, the policy that maps it and the observations that confirm its effect.

Four amber blocks at the router

Imagine an IPv4 datagram arriving at a 1993 gateway. Its payload may be encrypted or plain. Its source and destination remain visible because routers need them. In the Type of Service field, the four-bit value is 1111.

Nothing cryptographic has happened. No clearance decision has been made. The mark asks for a routing preference: minimize the chance that agents outside the network can observe the packet’s contents or traffic pattern. RFC 1455 called this “maximum physical link security,” yet it also denied that the facility could deliver any particular guaranteed level.

That apparent contradiction is the design. “Maximum” described the ordering objective among the options available, not an absolute floor. A restaurant can offer the quietest table it has without offering silence. A router could prefer the route its operator rated least observable without knowing whether the resulting path was confidential enough for the sender’s purpose.

The threat remained visible in the header

RFC 1455 began with traffic analysis. Even when every byte after the IP header was protected by end-to-end encryption, addresses still had to be exposed to forwarding equipment. An observer who could watch the stream might infer which hosts were active, when they communicated and how traffic volume changed.

The proposed service addressed an outsider trying to observe physical lines. It did not solve an adversary with inside access to the network. It did not hide endpoints from routers. It did not authenticate the sender or receiver. It did not decide whether a receiving process was authorized to read the data.

More secure physical carriage could add friction. Fibre was considered harder to tap than metallic cable; point-to-point media harder to observe than shared Ethernet or FDDI; guarded or alarmed conduit harder than an exposed land line; spread spectrum less accessible than ordinary broadcast; link encryption more useful after interception than an unencrypted bearer. But each comparison described a property, not a completed outcome.

Why the value was all ones

The memo assigned decimal 15, hexadecimal F, to the four-bit TOS field. The choice placed the new value at the maximum Hamming distance from the other defined TOS values. It was an engineering attempt to make mistaken interpretation less likely, not a security strength score.

RFC 1349 had already changed the way those four bits were read. TOS values were integers, not independent flags to combine with a logical OR. 1111 therefore did not mean “delay plus throughput plus reliability plus cost.” It meant the one new service request attached to that exact value.

That grammar boundary matters. A field can be syntactically intact and semantically lost when a node reads it under the wrong table. Conversely, recognizing the code says only which request was made. It does not show what the router did with it.

Local policy turned the request into a route

RFC 1455 proposed implementation through TOS-aware routing, including the facilities then available in OSPF. Operators would assign costs to links for this particular objective. Establishing those costs was explicitly a local policy function.

The illustrative table gave strong link encryption with secure key distribution a cost of 1, a physically secure point-to-point line 2, ordinary point-to-point 6, local shared media 8, metropolitan shared media 12, local radio 24 and satellite 32. The numbers did not report measurements. They encoded one hypothetical operator’s belief about relative interception likelihood.

That distinction prevents false precision. A satellite cost of 32 did not mean a 32 per cent interception probability. It did not prove a satellite was always 32 times worse. It said that, under the example policy, the routing calculation should treat it as 32 times as exposed as the reference encrypted link.

Another network could value the same facilities differently. Its site security, key distribution, geography, radio footprint and adversary model might differ. The packet carried no version number for the policy table that interpreted it.

Fifty hops could beat two

The memo offered a deliberately counterintuitive consequence. More than 50 highly secure links could be preferable to two insecure links, such as an unencrypted satellite hop followed by radio. The shortest path and the least observable path need not be the same.

But increasing hop count enlarged another surface. Every router had a site, operators, software, configuration and physical access boundary. A cost system based only on the cable could route a packet through many poorly protected routers while congratulating itself on secure lines. RFC 1455 therefore required router security to enter the judgment as well.

The example did not prove that a 50-hop route was secure. It exposed which facts the optimization needed. Link medium without router state was incomplete; route computation without actual forwarding was incomplete; forwarding without a contemporaneous facility record was incomplete.

The metric added what the model wanted to multiply

Routing algorithms commonly added link costs. For this security objective, the RFC observed that a product of secure-transmission probabilities would be more appropriate. It accepted summation as an adequate approximation for most uses, as RFC 1349 had done for high reliability.

This is a rare and useful admission. The route selector was not measuring the desired outcome directly. It was ordering paths through a simplified model. That model depended on relative estimates that might be stale, incomparable or attached to the wrong object.

An additive metric could still be operationally valuable. Yet its output had to be named honestly: preferred under this configured approximation. It was not a probability statement, a cryptographic proof or a warranty.

Better service when available, not refusal when absent

RFC 1349 described TOS words such as “minimize” and “maximize” as attempts using the network’s often imperfect information. It chose weak TOS routing. When a route matching a non-default request was unavailable, a default-TOS route could be used rather than punishing the sender by discarding the packet.

That availability decision made practical deployment easier. It also widened the evidentiary gap. Successful delivery of a marked packet did not show that the requested treatment was available. Silence did not distinguish a router that honored the mark from one that ignored it or fell back to default.

RFC 1455 itself expected no realistic chance that the whole Internet would implement the new value soon. End-to-end claims therefore required a hop-by-hop or domain-by-domain record, not faith in the header.

A security label was a different proposition

RFC 1108 shows what RFC 1455 did not carry. Its Basic Security Option included a classification level and protection-authority flags. Systems could validate whether a datagram was appropriate for a source, destination and protected route. Routing protocols needed security-label information to support that control.

The two mechanisms could be related without being interchangeable. A label said at what level the data had to be protected and whose rules applied. RFC 1455’s value asked for the hardest-to-observe available physical path. One did not infer the other.

Nor did either field encrypt content by itself. A trusted label, recognized route and physically guarded line still left key state, endpoint controls and actual exposure as separate observations.

The octet acquired a new grammar

RFC 2474 later obsoleted the old TOS definitions and defined the Differentiated Services field. A DSCP selected a per-hop behavior; classifiers and traffic conditioners at domain boundaries, plus administrative policy, constructed the service.

That successor did not retrospectively make RFC 1455 deploy. It demonstrates a lifecycle boundary. The same header octet can outlive one interpretation while the control architecture around it changes. Reading a packet capture requires the semantics, date, domain and policy that gave the bits meaning.

From request to observed secrecy

The evidence chain is longer than the field:

sender preference → recognized code → current local cost policy → computed route → actual forwarding path → physical and router protection → cryptographic state → endpoint authorization → observed security outcome

Each arrow changes the custodian and the proposition. The sender can show what it requested. The router can show which policy it loaded. Forwarding telemetry can show where the packet went. Facility and key records can show protection states. Only a bounded observation can say what a named adversary obtained.

RFC 1455’s strength was not that it solved confidentiality. It marked where an operational preference entered the packet, then stated with unusual clarity how far that mark could not reach.

Sources and limits

The publication status and obsolescence come from the RFC Editor record for RFC 1455. The request, threat model, cost example, route-length argument and approximation are in RFC 1455. The enumerated-request grammar, weak fallback and non-guarantee semantics come from RFC 1349. The distinct classification and protection-authority mechanism is documented in RFC 1108. The later field replacement is established by the RFC Editor record for RFC 2474.

These sources establish designs and stated limits. They do not establish deployment of RFC 1455, actual cost tables, measured interception rates, a protected real-world path, current legal restrictions, successful confidentiality or present operational guidance.