MoQ End-to-End Encryption Profile rev 00 lands on the IETF Datatracker
This document specifies moq-e2ee-00, a versioned profile for end-to- end encryption of MoQ application payloads. Authorized publishers and subscribers share a 32-byte broadcast secret out of band. Each publisher instance mints an epoch and publishes under an opaque broadcast path ending in it. HKDF-SHA-256 derives opaque physical track names and per-track AES-128-GCM keys from the secret and the epoch; grouped frames and datagrams use separate key domains. Media frames and datagrams carry only ciphertext plus a 16-byte tag. The profile binds object identity through derivation and the nonce, not an on-wire header.
Draft Snapshot
- Draft:
draft-lcurley-moq-e2ee - Revision: 00
- Last updated: 2026-09-24
- Source: IETF Datatracker
Summary
This document specifies moq-e2ee-00, a versioned profile for end-to- end encryption of MoQ application payloads. Authorized publishers and subscribers share a 32-byte broadcast secret out of band. Each publisher instance mints an epoch and publishes under an opaque broadcast path ending in it. HKDF-SHA-256 derives opaque physical track names and per-track AES-128-GCM keys from the secret and the epoch; grouped frames and datagrams use separate key domains. Media frames and datagrams carry only ciphertext plus a 16-byte tag. The profile binds object identity through derivation and the nonce, not an on-wire header.
Analysis
This draft is directly relevant to the MOQ ecosystem and worth tracking because it reflects current protocol work or adjacent implementation guidance from the IETF process.
Abstract
This document specifies moq-e2ee-00, a versioned profile for end-to- end encryption of MoQ application payloads. Authorized publishers and subscribers share a 32-byte broadcast secret out of band. Each publisher instance mints an epoch and publishes under an opaque broadcast path ending in it. HKDF-SHA-256 derives opaque physical track names and per-track AES-128-GCM keys from the secret and the epoch; grouped frames and datagrams use separate key domains. Media frames and datagrams carry only ciphertext plus a 16-byte tag. The profile binds object identity through derivation and the nonce, not an on-wire header.