Jump to content

Negotiated P2P IPsec

From Calamity Wiki
Revision as of 17:35, 8 May 2026 by Vertex (talk | contribs)

Negotiated P2P IPsec (NPI) is a Layer 3 protocol that secures communications between a client's network(s) and the network(s) belonging to a web host for a particular company. There are multiple types of NPI, which offer variable levels of privacy, including encryption-to-the-ISP (E2S), encryption-to-the-home (E2H), and encryption-to-the-device (E2D). In most cases, NPI is not performed in software, but in a dedicated hardware offload cryptoprocessor (for routers) or a cryptoprocessor attached to the system's network adapter(s) (for E2D devices).

E2S is the oldest solution, attributable to the historical reluctance for governments to divulge access to strong cryptography for consumers and the relatively low computing power of early devices, and is vulnerable to MITM attacks between the consumer and the ISP (or by the ISP itself). It is still used by some legacy websites that use servers which have not been updated. E2H is the current standard, which protects users against ISP eavesdropping but not against devices on the same network. E2D, which is emerging, provides an encrypted channel to each individual device, but is not yet supported by all service providers, and requires hardware support (a dedicated cryptoprocessor) in the network adapter of each device.

Mechanics

The NPI negotiation layer operates similarly to SSL in the real world. It has certificates, which are issued by the ISP of each service provider depending on the IP address or IP address block allocated to them; this also serves as their authority to advertise the block, similar to how RPKI functions in the real world. The NPI Authority Chain is a root certificate store, and usually includes the root certificates of regional internet registries (RIRs). Historically, the Authority Chain was part of a hardware device that would need to physically be swapped out in routers for updates, but with the advent of E2D this became no longer practical, so secure over-the-air update functionality was implemented in all modern NPI cryptoprocessors.