Summary

  • draft-ietf-scone-protocol-09 adds a minimum test for taking network throughput advice into account: the accompanying QUIC packet must authenticate as valid, and advice accompanying packets discarded or ignored—including likely duplicates—must be ignored.
  • The same revision says senders must not create a QUIC transmission merely to carry SCONE. Advice can expire while a connection is otherwise idle. These are draft rules, not evidence of an approved RFC or of changed deployments.

Consider a receiver that sees a perfectly formed rate hint before a QUIC packet it decides is a duplicate. A monitoring system might record “advice received”; an implementation following the September draft must not turn that observation into an operative rate. The distinction sits in the space between arrival and acceptance. It is small on the wire and large in an audit.

SCONE is a proposed way for an on-path element to write its view of sustainable throughput into a packet sent alongside ordinary QUIC traffic. The receiver can pass that hint to the application or peer, which may adapt a longer-term send rate. Earlier revisions already required the SCONE packet to be coalesced with a QUIC packet and required another packet in the datagram to be successfully processed before its advice counted. Revision 09 did not invent that coupling. It specifies what success must minimally mean: authentication of the accompanying QUIC packet as valid.

If the later QUIC packets are discarded or ignored, including as possible duplicates, the rate hint is ignored too.

This is not a general claim that all packets in one UDP envelope share a fate. QUIC packets retain separate processing semantics. Rather, SCONE makes acceptance of its unauthenticated hint depend on successful processing of companion QUIC traffic. The condition matters against a naive replay: a second copy of valid encrypted traffic should not become a fresh opportunity to alter the receiver's rate view after it is treated as duplicate. Yet it does not make SCONE advice cryptographically authenticated. The draft's security section still says it is not. It even describes an observer able to race an altered copy ahead of the original. A valid carrier is a narrower admission test, not proof of who set the number or whether an operator's policy authorized it.

Revision 09 draws a second boundary at the sender. Prior text discussed sending SCONE regularly, including at least twice per 67-second monitoring period for endpoints seeking advice. The new sentence is categorical about why a datagram exists: a sender must not send SCONE unless some QUIC packet needs to be sent for another reason. A quiet flow may therefore let its previous advice lapse instead of generating activity solely to solicit an update. The network element waits for the next suitable SCONE packet. A QUIC keepalive needed for an independent application reason is a different decision; this draft does not declare every keepalive unlawful. Equally, expiration of a SCONE-derived constraint does not prove a separately configured network limit has vanished or that the QUIC connection has closed.

That combination changes how an operator should read telemetry. “Saw a SCONE field,” “accepted the accompanying QUIC packet,” “reported the lowest advice to an application,” and “advice remains current” are different states. Revision 09 also clarifies that, where advice is reported to applications, the endpoint reports the lowest value received in the previous monitoring period. These distinctions cannot be reconstructed from a single last-seen timestamp or an attractive rate graph.

They call for implementation evidence: whether the companion packet authenticated and was processed, whether duplicate detection rejected it, which monitoring window supplied the reported value, and whether any subsequent traffic existed independently of SCONE.

The Datatracker still lists this work as an active Internet-Draft in IESG Evaluation with AD follow-up and a DISCUSS position; IANA review says the version changed and needs review. Those process facts neither negate the value of the revision nor turn it into an adopted standard. There is no deployment census here. The useful conclusion is narrower: the draft now names the admission and activity boundaries that a future implementation can test. Counting raw hints as accepted advice—or manufacturing traffic to keep a hint fresh—would erase precisely the distinction the new text is trying to preserve.

Sources