Summary
- RFC 5285, now replaced by RFC 8285, calls the number inside an RTP extension element a local identifier; an SDP
extmapbinds that number to the URI that defines format and meaning. - A recorder that keeps packets but discards negotiation history has transport evidence without a trustworthy semantic receipt. Decoding, operational action and observed outcome require separate proof.
The incident archive looked complete. It held the media packets, arrival times, SSRCs and an extension element marked ID 3. The analyst knew that several systems commonly put an audio level at 3, so the graph was labelled “speaker activity”. It was neat, plausible and wrong. In this session, the offer had bound 3 to a transmission-time offset.
No byte had been corrupted. The recorder had preserved the packet and discarded its vocabulary.
That is the compact bargain at the centre of RFC 5285. RTP's base extension mechanism offered one profile-defined area. The 2008 specification made it possible to place several small elements there. Instead of assigning a universal meaning to every four-bit or eight-bit number, it gave each element a local ID and used an absolute URI to name the extension. SDP then carried the binding: a=extmap:<value> <URI>. RFC 8285 replaced RFC 5285 in 2017, but retained that architectural split.
The split is not a flaw. A four-bit ID can be sent frequently without repeating a long URI in every media packet. A session can choose only the extensions it needs. Private experiments need not consume a central number. Yet the efficiency has an accounting cost: the packet alone does not contain the complete claim.
The number is an index, not a name
RFC 8285 is explicit. Each element has a local identifier and a length. There are no static allocations of those local identifiers. The identifiers present in a stream must have been negotiated or defined out of band, and each distinct extension in the relevant scope needs a unique ID.
The durable name is the URI. The IANA RTP Compact Header Extensions registry lists URIs for transmission-time offsets, synchronisation timestamps, audio levels, SDES-derived identifiers, frame marking and other functions. It does not decree that audio level is always 3 or MID is always 1. Those short numbers are chosen in session context.
This gives ID 3 two legitimate lives. In conference A it can point to one URI; in conference B it can point to another. Even within a description, scope matters. extmap declarations may sit at session level or media level, but the two styles cannot be mixed. A decoder that caches “3 means X” globally converts a local optimisation into a cross-session collision.
The appropriate evidence tuple is therefore wider than (SSRC, sequence, ID, bytes). It includes the applicable media description or BUNDLE group, the offer/answer epoch, direction, URI, extension attributes and packet framing. Without those fields, ID 3 remains an accurately observed number whose semantic status is unresolved.
Two compact formats create a capability boundary
The one-byte form spends four bits on the ID and supports IDs 1 through 14. It is efficient when a session uses a small set of short elements. The two-byte form uses an eight-bit element ID and supports a larger value and length space. Each packet announces which form it carries through the RTP extension profile field.
RFC 5285 required a stream to use one form or the other. RFC 8285 removed that stream-wide limitation, but not by pretending every endpoint could suddenly parse both in arbitrary succession. It introduced extmap-allow-mixed. Mixed use must be negotiated through offer/answer, or otherwise known to every recipient. A packet still uses one indicated form; the permission concerns the stream over time.
That distinction catches a familiar observability mistake. Recognising the 0xBEDE one-byte profile or the two-byte profile establishes a format receipt. It does not establish a mapping receipt. A parser may locate ID 3 perfectly and still lack the extmap that explains it. Conversely, a stored SDP description may contain the binding while the recorder cannot parse the packet form used after a capability change. Both pieces are necessary, and neither should impersonate the other.
Offer and answer freeze a working dictionary
Within the applicable scope, valid IDs cannot be assigned twice. RFC 8285 also keeps an accepted valid mapping stable: a session update may add or remove extensions and may change direction, but it must not remap an active valid ID to a different meaning. That rule protects running code from a dictionary changing underneath in-flight media.
The negotiation still has flexibility. Values 4096–4351 can advertise mutually exclusive alternatives or excess candidates. An answerer can choose one and map it into a free on-wire range. Those high negotiation values are not packet IDs. Treating an offered candidate as though it had already become usable is another way to manufacture a semantic receipt.
Direction is part of the contract too. sendonly, recvonly, sendrecv and inactive qualify the extension relative to the configured endpoint. A declaration that proves permission to receive an extension does not by itself prove that a peer actually sent one. A packet proves presence; the negotiation proves which interpretation was authorized for that direction and epoch.
BUNDLE expands the blast radius of a bad map
BUNDLE lets several SDP media descriptions share one transport. That saves ports and simplifies connectivity, but it makes demultiplexing state more important. MID can identify the media description to which a packet belongs, and RFC 9143 requires the MID header extension in bundled RTP descriptions.
RFC 8285 treats all media descriptions in a BUNDLE group as one local-ID space. When the same extension URI and configuration appears across members, it must use the same ID. Different extension sets can still appear on different descriptions. A recorder that stores only a single flattened map may therefore be wrong in two directions: it can miss group-wide consistency or erase a media-specific absence.
RtpStreamId adds another scoped label. RFC 8852 says it is scoped by source and media session, and under BUNDLE also by MID. The architecture is nested on purpose. The outer packet identifies a source; a compact extension number finds a URI through extmap; MID and RID values then select media and stream contexts. Flattening the stack into one global identifier column destroys the boundaries that make reuse safe.
Visibility is not stable either
Header extensions can carry sensitive metadata. RFC 6904 defined selective encryption of extension values. RFC 9335 later observed that even visible extension IDs and lengths can fingerprint an endpoint or application, and defined Cryptex to protect more of the header-extension structure.
An observer may therefore move between three different states: seeing an ID and clear value, seeing only an encrypted extension area, or seeing decrypted content at an authorized endpoint. These are not equivalent monitoring failures or successes. A network sensor that no longer sees an audio-level element after encryption has not proved that the sender stopped producing it. An endpoint that decrypts bytes has not proved its extmap epoch is correct.
The safe model records a chain of receipts. First, a packet arrived. Second, its extension framing parsed. Third, a named negotiation snapshot mapped the local ID to a URI and attributes. Fourth, the URI-specific decoder accepted the payload. Fifth, an authorized component used the result. Sixth, an independent signal showed what happened next. “Processed” is too small a word for six different claims.
Preserve the dictionary with the evidence
A useful RTP archive retains raw packets, but it also retains the exact offers and answers, their ordering, the time at which each became effective, the BUNDLE group, media-section identity, direction qualifiers and extension attributes. It keeps the original evidence immutable and creates derived interpretations that point back to the mapping version used.
When context is missing, the right result is not a best-effort guess from popular defaults. It is an explicit unresolved state. The packet can still support timing, loss and transport analysis. Its extension bytes remain evidence. The system simply refuses to inflate a local integer into a universal fact.
That restraint is the larger achievement of RFC 5285. The standard made rich per-packet metadata cheap by refusing to make the short number sovereign. The packet carries an index. The negotiated session carries the language. Reliable operations must keep both.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
