Summary

  • ICE's controlling agent has the bounded job of nominating a valid candidate pair for a component; in a full-agent role conflict, a uniformly chosen 64-bit tie-breaker decides which agent keeps that job.
  • Neither the larger number nor the selected pair proves who owns an endpoint, whether a person consented, whether signaling was honest, whether media is protected, or whether the application worked.

A random number settles a collision

Two endpoints can enter an ICE exchange believing that each is controlling. That is not a constitutional crisis. It is a state-machine collision. Each full ICE agent has already selected a tie-breaker uniformly from zero to 2^64 minus one. The agents compare those values through the ICE-CONTROLLING or ICE-CONTROLLED attributes. One keeps the controlling role; the other changes role, with a 487 Role Conflict response available to repair the mismatch.

The mechanism is deliberately indifferent to institutional status. The larger value does not identify the caller, the offerer, the customer, the person with legal authority, the owner of an address or the more trusted network. An agent that changes role does not even choose a fresh tie-breaker merely because its procedural assignment changed. The number exists so two machines can converge on complementary duties without another election protocol.

That narrowness is a feature. Trouble begins when telemetry labels the result “session owner,” “master endpoint” or “authorized side.” Those names import authority that the RFC never granted.

Controlling means choosing among proved candidates

ICE starts from a different problem: candidate discovery and path testing. Agents gather host, server-reflexive and relayed candidates, exchange them over an assumed signaling connection, form ordered pairs and run STUN connectivity checks. A successful transaction can place a pair on the valid list. It supplies evidence that packets traversed the tested route in both directions at that moment.

The controlling agent then nominates a valid pair for each component according to local policy. Under regular nomination it sends a check carrying USE-CANDIDATE. RFC 8445 retained this model and removed RFC 5245's aggressive nomination procedure. Candidate priority, successful checking, valid-list membership, nomination and final selection are therefore separate receipts.

“Controlling” names the actor allowed to make one selection inside that sequence. It does not certify the inputs. If candidates or credentials crossed a compromised signaling channel, a correctly executed nomination can still act on a false exchange. If the valid pair uses a relay, selection does not prove that the route is direct or cheap. If the NAT binding later changes, the historic nomination does not preserve reachability.

Signaling is an inherited trust boundary

ICE assumes the peers can communicate through signaling; it is not the mechanism that traverses NAT for that signaling connection. The username fragments, passwords and candidates used by connectivity checks arrive through that external channel. STUN short-term credentials can protect checks from tampering, but their meaning depends on how securely those credentials were delivered.

This creates an evidence chain. A role claim is weaker than a resolved role conflict. A resolved role conflict is weaker than an authenticated candidate exchange. An authenticated exchange is weaker than a successful integrity-protected check. A successful check is weaker than nomination and mutual selection.

RFC 8445's security analysis reinforces the point by considering false-invalid, false-valid and false peer-reflexive outcomes. The word “valid” belongs to the ICE state machine. It is not a universal declaration that an address is authentic, owned by the claimant or safe to disclose.

Consent has a different clock

RFC 7675 adds another boundary. Initial ICE success counts as initial application-level consent to send on the selected candidate pair, but the specification explicitly says that no human intervention is involved. It is protocol consent, confined to a particular 5-tuple. Continuing consent requires request-and-response freshness and expires unless renewed.

ICE alone also does not announce when that consent ends. A selected pair can remain in an operational record after its consent evidence has aged out. A product screen that turns “ICE connected” into “the user authorized this session” therefore makes two errors: it converts machine consent into human intent and converts time-bounded evidence into a permanent entitlement.

Keep at least four facts separate: the pair selected, the 5-tuple covered, the last successful consent transaction and the human or business authorization obtained elsewhere. They may correlate. They are not substitutes.

A selected path carries no promise about its cargo

ICE establishes a route for packets. Media confidentiality, integrity and endpoint authentication belong to other protocols. Decoding belongs to the application. Intelligibility belongs to the media path and user environment. Commercial success belongs still farther away.

A dashboard can truthfully report that an integrity-protected check succeeded, the controlling agent nominated the pair and both agents selected it. It cannot infer from those receipts that protected media traversed, that the other side decoded it, that a person heard it, or that a meeting achieved its purpose.

RFC 8828's privacy work makes a related distinction. Candidate disclosure can expose network information, so deployments may prefer mDNS names or other protections. Reachability is not ownership, and knowledge of an address is not permission to publish topology. RFC 5128 likewise explains why direct paths can fail and relays become necessary. Selected does not mean direct, stable or independent.

Preserve the ladder of evidence

The strongest operational record is not one green ICE badge. It is a ladder: role claim; conflict comparison; signaling authentication; check integrity; succeeded pair; nomination; mutual selection; current consent; protected traffic; application acceptance; observed service outcome.

Lu Heng's reality-layer discipline applies cleanly here. Each transition should be allowed to establish exactly what it observed and no more. The random tie-breaker can settle which agent performs nomination. The nomination can settle which checked pair the controlling agent proposes for use. Neither result should inherit identity, governance or outcome authority from a higher layer.

RFC 5245 is now historical. RFC 8445 replaced the common ICE procedures, while RFC 8839 separated the SDP offer/answer usage. That history matters because an audit should test the specification actually governing a deployment. It does not change the lesson: an elegant collision-resolution mechanism stays reliable only when its title is not mistaken for power.

Sources