Paper 2025/1689

IPCrypt: Optimal, Practical Encryption of IP Addresses for Privacy and Measurement

Frank Denis, Fastly Inc.
Abstract

This paper introduces efficient, practical methods for encrypting IPv4/IPv6 addresses while preserving utility in logs, telemetry, and third-party data exchange. We focus on three practical goals: (i) format-compatible encryption that keeps outputs in the IPv6 address space and handles IPv4 inputs canonically; (ii) prefix-preserving encryption that retains network structure for analytics while hiding host identity; and (iii) non-deterministic encryption that resists correlation while remaining compact and invertible. We give deterministic, prefix-preserving, and two non-deterministic variants, with security models and arguments under standard assumptions, plus explicit usage bounds and operating limits. We also relate each variant to known efficiency lower bounds (ciphertext expansion and primitive calls) and state our claims within deployable parameter ranges.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
ipcryptipaddressipv4ipv6encryptionobfuscationpseudonymizationkiasuaes
Contact author(s)
fde @ 00f net
History
2025-09-18: approved
2025-09-17: received
See all versions
Short URL
https://ia.cr/2025/1689
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2025/1689,
      author = {Frank Denis},
      title = {{IPCrypt}: Optimal, Practical Encryption of {IP} Addresses for Privacy and Measurement},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1689},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1689}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.