<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version  (Ruby 3.2.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-ietf-schc-8824-update-03" category="std" consensus="true" submissionType="IETF" obsoletes="8824" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.21.0 -->
  <front>
    <title abbrev="SCHC for CoAP">Static Context Header Compression (SCHC) for the Constrained Application Protocol (CoAP)</title>
    <seriesInfo name="Internet-Draft" value="draft-ietf-schc-8824-update-03"/>
    <author initials="M." surname="Tiloca" fullname="Marco Tiloca">
      <organization>RISE AB</organization>
      <address>
        <postal>
          <street>Isafjordsgatan 22</street>
          <city>Kista</city>
          <code>16440</code>
          <country>Sweden</country>
        </postal>
        <email>marco.tiloca@ri.se</email>
      </address>
    </author>
    <author initials="L." surname="Toutain" fullname="Laurent Toutain">
      <organization>IMT Atlantique</organization>
      <address>
        <postal>
          <street>CS 17607, 2 rue de la Chataigneraie</street>
          <city>Cesson-Sevigne Cedex</city>
          <code>35576</code>
          <country>France</country>
        </postal>
        <email>Laurent.Toutain@imt-atlantique.fr</email>
      </address>
    </author>
    <author initials="I." surname="Martinez" fullname="Ivan Martinez">
      <organization>Nokia Bell Labs</organization>
      <address>
        <postal>
          <street>12 Rue Jean Bart</street>
          <city>Massy</city>
          <code>91300</code>
          <country>France</country>
        </postal>
        <email>ivan.martinez_bolivar@nokia-bell-labs.com</email>
      </address>
    </author>
    <author initials="A." surname="Minaburo" fullname="Ana Minaburo">
      <organization>Consultant</organization>
      <address>
        <postal>
          <street>Rue de Rennes</street>
          <city>Cesson-Sevigne</city>
          <code>35510</code>
          <country>France</country>
        </postal>
        <email>anaminaburo@gmail.com</email>
      </address>
    </author>
    <date year="2024" month="October" day="21"/>
    <area>Internet</area>
    <workgroup>SCHC Working Group</workgroup>
    <keyword>Internet-Draft</keyword>
    <abstract>
      <t>This document defines how to compress Constrained Application Protocol (CoAP) headers using the Static Context Header Compression and fragmentation (SCHC) framework. SCHC defines a header compression mechanism adapted for constrained devices. SCHC uses a static description of the header to reduce the header's redundancy and size. While RFC 8724 describes the SCHC compression and fragmentation framework, and its application for IPv6/UDP headers, this document applies SCHC to CoAP headers. The CoAP header structure differs from IPv6 and UDP, since CoAP uses a flexible header with a variable number of options, themselves of variable length. The CoAP message format is asymmetric: the request messages have a header format different from the format in the response messages. This specification gives guidance on applying SCHC to flexible headers and how to leverage the asymmetry for more efficient compression Rules. This document replaces and obsoletes RFC 8824.</t>
    </abstract>
    <note removeInRFC="true">
      <name>Discussion Venues</name>
      <t>Discussion of this document takes place on the
    Static Context Header Compression Working Group mailing list (schc@ietf.org),
    which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/schc/"/>.</t>
      <t>Source for this draft and an issue tracker can be found at
    <eref target="https://github.com/marco-tiloca-sics/draft-ietf-schc-8824-update"/>.</t>
    </note>
  </front>
  <middle>
    <section anchor="intro">
      <name>Introduction</name>
      <t>The Constrained Application Protocol (CoAP) <xref target="RFC7252"/> is a command/response protocol designed for microcontrollers with small RAM and ROM, and optimized for services based on REST (Representational State Transfer). Although the constrained devices are a leading factor in the design of CoAP, a CoAP header's size is still too large for LPWANs (Low-Power Wide-Area Networks). Static Context Header Compression and fragmentation (SCHC) over CoAP headers is required to increase performance or to use CoAP over LPWAN technologies.</t>
      <t><xref target="RFC8724"/> defines the SCHC framework, which includes a header compression mechanism for LPWANs that is based on a static context. <xref section="5" sectionFormat="of" target="RFC8724"/> explains where compression and decompression occur in the architecture. The SCHC compression scheme assumes as a prerequisite that both endpoints know the static context before transmission. The way the context is configured, provisioned, or exchanged is out of this document's scope.</t>
      <t>CoAP is an application protocol, so CoAP compression requires installing common Rules between the two SCHC instances. SCHC compression may apply at two different levels: at the IP and UDP level in the LPWAN, as well as at the application level for CoAP. These two compression techniques may be independent. Both follow the same principle as that described in <xref target="RFC8724"/>. As different entities manage the CoAP compression process at different levels, the SCHC Rules driving the compression/decompression are also different. <xref target="RFC8724"/> describes how to use SCHC for IP and UDP headers. This document specifies how to apply SCHC compression to CoAP headers.</t>
      <t>SCHC compresses and decompresses headers based on common contexts between Devices. The SCHC context includes multiple Rules. Each Rule can match the header fields to specific values or ranges of values. If a Rule matches, the matched header fields are replaced by the RuleID and the Compression Residue that contains the residual bits of the compression. Thus, different Rules may correspond to different protocol headers in the packet that a Device expects to send or receive.</t>
      <t>A Rule describes the packets' entire header with an ordered list of Field Descriptors (see <xref section="7" sectionFormat="of" target="RFC8724"/>). In turn, each Field Descriptor contains the Field ID (FID), Field Length (FL), and Field Position (FP), as well as a Direction Indicator (DI) (upstream, downstream, or bidirectional) and some associated Target Values (TVs). The DI allows the compression to be based on the best TV for the Field Descriptor, when the TV to consider is different for the different transmission directions. Therefore, a field may be described several times in the same Rule.</t>
      <t>Furthermore, a Matching Operator (MO) is associated with each header Field Descriptor. The Rule is selected if all the MOs fit the TVs for all the fields of the header. A Rule cannot be selected if the message contains a field that is unknown to the SCHC compressor.</t>
      <t>In that case, a Compression/Decompression Action (CDA) associated with each field specifies the method to compress and decompress that field. Compression mainly results in one of four actions:</t>
      <ul spacing="normal">
        <li>
          <t>send the field value (value-sent),</t>
        </li>
        <li>
          <t>send nothing (not-sent),</t>
        </li>
        <li>
          <t>send some Least Significant Bits (LSBs) of the field, or</t>
        </li>
        <li>
          <t>send an index (mapping-sent).</t>
        </li>
      </ul>
      <t>After applying the compression, there may be some bits to be sent. These values are called "Compression Residue".</t>
      <t>SCHC is a general mechanism applied to different protocols, with the exact Rules to be used depending on the protocol and the application. <xref section="10" sectionFormat="of" target="RFC8724"/> describes the compression scheme for IPv6 and UDP headers. This document targets CoAP header compression using SCHC.</t>
      <t>The use of SCHC compression applied to CoAP headers was originally defined in <xref target="RFC8824"/>. While this document does not alter the core approach, design choices, and features specified therein, this document clarifies, updates, and extends the SCHC compression of CoAP headers defined in <xref target="RFC8824"/>.</t>
      <t>In particular, this documents replaces and obsoletes <xref target="RFC8824"/> as follows.</t>
      <ul spacing="normal">
        <li>
          <t>It provides clarifications and amendments to the original specification text, based on collected feedback and reported errata.</t>
        </li>
        <li>
          <t>It clarifies how the SCHC compression handles CoAP options in general (see <xref target="sec-coap-options"/>).</t>
        </li>
        <li>
          <t>It clarifies the SCHC compression for the CoAP options: Size1, Size2, Proxy-Uri, and Proxy-Scheme (see <xref target="ssec-size1-size2-proxy-uri-proxy-scheme-option"/>); ETag and If-Match (see <xref target="ssec-etag-if-match-option"/>); and If-None-Match (see <xref target="ssec-if-none-match"/>).</t>
        </li>
        <li>
          <t>It defines the SCHC compression for the recently defined CoAP options Proxy-Cri and Proxy-Scheme-Number (see <xref target="ssec-proxy-cri-proxy-scheme-number-option"/>).</t>
        </li>
        <li>
          <t>It defines the SCHC compression for the CoAP option Hop-Limit (see <xref target="coap-options-hop-limit"/>).</t>
        </li>
        <li>
          <t>It defines the SCHC compression for the recently defined CoAP options Echo (see <xref target="coap-options-echo"/>), Request-Tag (see <xref target="coap-options-request-tag"/>), EDHOC (see <xref target="coap-options-edhoc"/>), as well as Q-Block1 and Q-Block2 (see <xref target="ssec-coap-extensions-block"/>).</t>
        </li>
        <li>
          <t>It updates the SCHC compression processing for the CoAP option OSCORE (see <xref target="ssec-coap-extensions-oscore"/>), in the light of recent developments related to the security protocol OSCORE as defined in <xref target="I-D.ietf-core-oscore-key-update"/> and <xref target="I-D.ietf-core-oscore-groupcomm"/>.</t>
        </li>
        <li>
          <t>It clarifies how the SCHC compression handles the CoAP payload marker (see <xref target="payload-marker"/>).</t>
        </li>
        <li>
          <t>It defines the SCHC compression of CoAP headers in the presence of CoAP proxies (see <xref target="compression-with-proxies"/>), for which examples are provided (see <xref target="examples"/>).</t>
        </li>
      </ul>
      <section anchor="terminology">
        <name>Terminology</name>
        <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
        <t>Readers are expected to be familiar with the terms and concepts related to the SCHC framework <xref target="RFC8724"/>, the web-transfer protocol CoAP <xref target="RFC7252"/>, and the security protocols OSCORE <xref target="RFC8613"/> and Group OSCORE <xref target="I-D.ietf-core-oscore-groupcomm"/>.</t>
      </section>
    </section>
    <section anchor="sec-applicability-to-coap">
      <name>SCHC Applicability to CoAP</name>
      <t>SCHC compression for CoAP headers <bcp14>MAY</bcp14> be done in conjunction with the lower layers (IPv6/UDP) or independently. The SCHC adaptation layers, described in <xref section="5" sectionFormat="of" target="RFC8724"/>, may be used as shown in <xref target="fig-applicability-to-coap-1"/>, <xref target="fig-applicability-to-coap-2"/>, and <xref target="fig-applicability-to-coap-3"/>.</t>
      <t>In the first example depicted in <xref target="fig-applicability-to-coap-1"/>, a Rule compresses the complete header stack from IPv6 to CoAP. In this case, the Device and the Network Gateway (NGW) perform SCHC C/D (SCHC Compression/Decompression, see <xref target="RFC8724"/>). The application communicating with the Device does not implement SCHC C/D.</t>
      <figure anchor="fig-applicability-to-coap-1">
        <name>Compression/Decompression at the LPWAN Boundary</name>
        <artset>
          <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="256" width="512" viewBox="0 0 512 256" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
              <path d="M 8,64 L 8,224" fill="none" stroke="black"/>
              <path d="M 80,64 L 80,232" fill="none" stroke="black"/>
              <path d="M 128,128 L 128,232" fill="none" stroke="black"/>
              <path d="M 200,160 L 200,224" fill="none" stroke="black"/>
              <path d="M 264,128 L 264,224" fill="none" stroke="black"/>
              <path d="M 432,64 L 432,224" fill="none" stroke="black"/>
              <path d="M 504,64 L 504,224" fill="none" stroke="black"/>
              <path d="M 8,64 L 80,64" fill="none" stroke="black"/>
              <path d="M 432,64 L 504,64" fill="none" stroke="black"/>
              <path d="M 8,96 L 80,96" fill="none" stroke="black"/>
              <path d="M 432,96 L 504,96" fill="none" stroke="black"/>
              <path d="M 8,128 L 80,128" fill="none" stroke="black"/>
              <path d="M 128,128 L 264,128" fill="none" stroke="black"/>
              <path d="M 432,128 L 504,128" fill="none" stroke="black"/>
              <path d="M 8,160 L 80,160" fill="none" stroke="black"/>
              <path d="M 128,160 L 264,160" fill="none" stroke="black"/>
              <path d="M 432,160 L 504,160" fill="none" stroke="black"/>
              <path d="M 8,192 L 80,192" fill="none" stroke="black"/>
              <path d="M 128,192 L 200,192" fill="none" stroke="black"/>
              <path d="M 8,224 L 80,224" fill="none" stroke="black"/>
              <path d="M 128,224 L 264,224" fill="none" stroke="black"/>
              <path d="M 432,224 L 504,224" fill="none" stroke="black"/>
              <path d="M 56,240 L 80,240" fill="none" stroke="black"/>
              <path d="M 128,240 L 152,240" fill="none" stroke="black"/>
              <path d="M 248,240 L 288,240" fill="none" stroke="black"/>
              <path d="M 400,240 L 448,240" fill="none" stroke="black"/>
              <g class="text">
                <text x="44" y="36">(Device)</text>
                <text x="200" y="36">(NGW)</text>
                <text x="464" y="36">(App)</text>
                <text x="44" y="84">CoAP</text>
                <text x="468" y="84">CoAP</text>
                <text x="40" y="116">UDP</text>
                <text x="464" y="116">UDP</text>
                <text x="44" y="148">IPv6</text>
                <text x="196" y="148">IPv6</text>
                <text x="468" y="148">IPv6</text>
                <text x="44" y="180">SCHC</text>
                <text x="164" y="180">SCHC</text>
                <text x="48" y="212">LPWAN</text>
                <text x="160" y="212">LPWAN</text>
                <text x="104" y="244">LPWAN</text>
                <text x="348" y="244">Internet</text>
              </g>
            </svg>
          </artwork>
          <artwork type="ascii-art" align="center"><![CDATA[
 (Device)             (NGW)                            (App)

+--------+                                           +--------+
|  CoAP  |                                           |  CoAP  |
+--------+                                           +--------+
|  UDP   |                                           |  UDP   |
+--------+     +----------------+                    +--------+
|  IPv6  |     |      IPv6      |                    |  IPv6  |
+--------+     +--------+-------+                    +--------+
|  SCHC  |     |  SCHC  |       |                    |        |
+--------+     +--------+       +                    +        +
|  LPWAN |     | LPWAN  |       |                    |        |
+--------+     +--------+-------+                    +--------+
      ((((LPWAN))))           ------   Internet  -------
]]></artwork>
        </artset>
      </figure>
      <t><xref target="fig-applicability-to-coap-1"/> shows the use of SCHC header compression above Layer 2 in the Device and the NGW. The SCHC layer receives non-encrypted packets and can apply compression Rules to all the headers in the stack. On the other end, the NGW receives the SCHC packet and reconstructs the headers using the Rule and the Compression Residue. After the decompression, the NGW forwards the IPv6 packet toward the destination. The same process applies in the other direction when a non-encrypted packet arrives at the NGW. Thanks to the IP forwarding based on the IPv6 prefix, the NGW identifies the Device and compresses headers using the Device's Rules.</t>
      <t>In the second example depicted in <xref target="fig-applicability-to-coap-2"/>, SCHC compression is applied in the CoAP layer, compressing the CoAP header independently of the other layers. The RuleID, Compression Residue, and CoAP payload are encrypted using a mechanism such as DTLS <xref target="RFC9147"/>. Only the other end (App) can decipher the information. If needed, layers below use SCHC to compress the header as defined in <xref target="RFC8724"/> (represented by dotted lines in the figure).</t>
      <t>This use case needs an end-to-end context initialization between the Device and the application. The context initialization is out of scope for this document.</t>
      <figure anchor="fig-applicability-to-coap-2">
        <name>Standalone CoAP End-to-End Compression/Decompression</name>
        <artset>
          <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="320" width="512" viewBox="0 0 512 320" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
              <path d="M 8,64 L 8,160" fill="none" stroke="black"/>
              <path d="M 80,64 L 80,160" fill="none" stroke="black"/>
              <path d="M 432,64 L 432,160" fill="none" stroke="black"/>
              <path d="M 504,64 L 504,160" fill="none" stroke="black"/>
              <path d="M 8,64 L 80,64" fill="none" stroke="black"/>
              <path d="M 432,64 L 504,64" fill="none" stroke="black"/>
              <path d="M 8,96 L 80,96" fill="none" stroke="black"/>
              <path d="M 432,96 L 504,96" fill="none" stroke="black"/>
              <path d="M 8,128 L 80,128" fill="none" stroke="black"/>
              <path d="M 432,128 L 504,128" fill="none" stroke="black"/>
              <path d="M 8,160 L 80,160" fill="none" stroke="black"/>
              <path d="M 432,160 L 504,160" fill="none" stroke="black"/>
              <path d="M 56,304 L 80,304" fill="none" stroke="black"/>
              <path d="M 128,304 L 152,304" fill="none" stroke="black"/>
              <path d="M 248,304 L 288,304" fill="none" stroke="black"/>
              <path d="M 400,304 L 448,304" fill="none" stroke="black"/>
              <g class="text">
                <text x="44" y="36">(Device)</text>
                <text x="200" y="36">(NGW)</text>
                <text x="464" y="36">(App)</text>
                <text x="44" y="84">CoAP</text>
                <text x="468" y="84">CoAP</text>
                <text x="44" y="116">SCHC</text>
                <text x="468" y="116">SCHC</text>
                <text x="44" y="148">DTLS</text>
                <text x="468" y="148">DTLS</text>
                <text x="8" y="180">.</text>
                <text x="40" y="180">udp</text>
                <text x="80" y="180">.</text>
                <text x="432" y="180">.</text>
                <text x="464" y="180">udp</text>
                <text x="504" y="180">.</text>
                <text x="44" y="196">..........</text>
                <text x="196" y="196">..................</text>
                <text x="468" y="196">..........</text>
                <text x="8" y="212">.</text>
                <text x="44" y="212">ipv6</text>
                <text x="80" y="212">.</text>
                <text x="128" y="212">.</text>
                <text x="196" y="212">ipv6</text>
                <text x="264" y="212">.</text>
                <text x="432" y="212">.</text>
                <text x="468" y="212">ipv6</text>
                <text x="504" y="212">.</text>
                <text x="44" y="228">..........</text>
                <text x="196" y="228">..................</text>
                <text x="468" y="228">..........</text>
                <text x="8" y="244">.</text>
                <text x="44" y="244">schc</text>
                <text x="80" y="244">.</text>
                <text x="128" y="244">.</text>
                <text x="164" y="244">schc</text>
                <text x="200" y="244">.</text>
                <text x="264" y="244">.</text>
                <text x="432" y="244">.</text>
                <text x="504" y="244">.</text>
                <text x="44" y="260">..........</text>
                <text x="164" y="260">..........</text>
                <text x="264" y="260">.</text>
                <text x="432" y="260">.</text>
                <text x="504" y="260">.</text>
                <text x="8" y="276">.</text>
                <text x="48" y="276">lpwan</text>
                <text x="80" y="276">.</text>
                <text x="128" y="276">.</text>
                <text x="160" y="276">lpwan</text>
                <text x="200" y="276">.</text>
                <text x="264" y="276">.</text>
                <text x="432" y="276">.</text>
                <text x="504" y="276">.</text>
                <text x="44" y="292">..........</text>
                <text x="196" y="292">..................</text>
                <text x="468" y="292">..........</text>
                <text x="104" y="308">LPWAN</text>
                <text x="348" y="308">Internet</text>
              </g>
            </svg>
          </artwork>
          <artwork type="ascii-art" align="center"><![CDATA[
 (Device)             (NGW)                            (App)

+--------+                                           +--------+
|  CoAP  |                                           |  CoAP  |
+--------+                                           +--------+
|  SCHC  |                                           |  SCHC  |
+--------+                                           +--------+
|  DTLS  |                                           |  DTLS  |
+--------+                                           +--------+
.  udp   .                                           .  udp   .
..........     ..................                    ..........
.  ipv6  .     .      ipv6      .                    .  ipv6  .
..........     ..................                    ..........
.  schc  .     .  schc  .       .                    .        .
..........     ..........       .                    .        .
.  lpwan .     . lpwan  .       .                    .        .
..........     ..................                    ..........
      ((((LPWAN))))           ------   Internet  -------
]]></artwork>
        </artset>
      </figure>
      <t>The third example depicted in <xref target="fig-applicability-to-coap-3"/> shows the use of Object Security for Constrained RESTful Environments (OSCORE) <xref target="RFC8613"/>. In this case, SCHC needs two Rules to compress the CoAP header. A first Rule focuses on the Inner header. The result of this first compression is encrypted using the OSCORE mechanism. Then, a second Rule compresses the Outer header, including the CoAP Option OSCORE.</t>
      <figure anchor="fig-applicability-to-coap-3">
        <name>OSCORE Compression/Decompression</name>
        <artset>
          <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="416" width="512" viewBox="0 0 512 416" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
              <path d="M 8,64 L 8,256" fill="none" stroke="black"/>
              <path d="M 80,64 L 80,256" fill="none" stroke="black"/>
              <path d="M 432,64 L 432,256" fill="none" stroke="black"/>
              <path d="M 504,64 L 504,256" fill="none" stroke="black"/>
              <path d="M 8,64 L 80,64" fill="none" stroke="black"/>
              <path d="M 432,64 L 504,64" fill="none" stroke="black"/>
              <path d="M 8,112 L 80,112" fill="none" stroke="black"/>
              <path d="M 432,112 L 504,112" fill="none" stroke="black"/>
              <path d="M 8,160 L 80,160" fill="none" stroke="black"/>
              <path d="M 432,160 L 504,160" fill="none" stroke="black"/>
              <path d="M 8,208 L 80,208" fill="none" stroke="black"/>
              <path d="M 432,208 L 504,208" fill="none" stroke="black"/>
              <path d="M 8,256 L 80,256" fill="none" stroke="black"/>
              <path d="M 432,256 L 504,256" fill="none" stroke="black"/>
              <path d="M 56,400 L 80,400" fill="none" stroke="black"/>
              <path d="M 128,400 L 152,400" fill="none" stroke="black"/>
              <path d="M 248,400 L 288,400" fill="none" stroke="black"/>
              <path d="M 400,400 L 448,400" fill="none" stroke="black"/>
              <g class="text">
                <text x="44" y="36">(Device)</text>
                <text x="200" y="36">(NGW)</text>
                <text x="464" y="36">(App)</text>
                <text x="44" y="84">CoAP</text>
                <text x="468" y="84">CoAP</text>
                <text x="48" y="100">Inner</text>
                <text x="472" y="100">Inner</text>
                <text x="44" y="132">SCHC</text>
                <text x="468" y="132">SCHC</text>
                <text x="48" y="148">Inner</text>
                <text x="472" y="148">Inner</text>
                <text x="44" y="180">CoAP</text>
                <text x="468" y="180">CoAP</text>
                <text x="48" y="196">Outer</text>
                <text x="472" y="196">Outer</text>
                <text x="44" y="228">SCHC</text>
                <text x="468" y="228">SCHC</text>
                <text x="48" y="244">Outer</text>
                <text x="472" y="244">Outer</text>
                <text x="8" y="276">.</text>
                <text x="40" y="276">udp</text>
                <text x="80" y="276">.</text>
                <text x="432" y="276">.</text>
                <text x="464" y="276">udp</text>
                <text x="504" y="276">.</text>
                <text x="44" y="292">..........</text>
                <text x="196" y="292">..................</text>
                <text x="468" y="292">..........</text>
                <text x="8" y="308">.</text>
                <text x="44" y="308">ipv6</text>
                <text x="80" y="308">.</text>
                <text x="128" y="308">.</text>
                <text x="196" y="308">ipv6</text>
                <text x="264" y="308">.</text>
                <text x="432" y="308">.</text>
                <text x="468" y="308">ipv6</text>
                <text x="504" y="308">.</text>
                <text x="44" y="324">..........</text>
                <text x="196" y="324">..................</text>
                <text x="468" y="324">..........</text>
                <text x="8" y="340">.</text>
                <text x="44" y="340">schc</text>
                <text x="80" y="340">.</text>
                <text x="128" y="340">.</text>
                <text x="164" y="340">schc</text>
                <text x="200" y="340">.</text>
                <text x="264" y="340">.</text>
                <text x="432" y="340">.</text>
                <text x="504" y="340">.</text>
                <text x="44" y="356">..........</text>
                <text x="164" y="356">..........</text>
                <text x="264" y="356">.</text>
                <text x="432" y="356">.</text>
                <text x="504" y="356">.</text>
                <text x="8" y="372">.</text>
                <text x="48" y="372">lpwan</text>
                <text x="80" y="372">.</text>
                <text x="128" y="372">.</text>
                <text x="160" y="372">lpwan</text>
                <text x="200" y="372">.</text>
                <text x="264" y="372">.</text>
                <text x="432" y="372">.</text>
                <text x="504" y="372">.</text>
                <text x="44" y="388">..........</text>
                <text x="196" y="388">..................</text>
                <text x="468" y="388">..........</text>
                <text x="104" y="404">LPWAN</text>
                <text x="348" y="404">Internet</text>
              </g>
            </svg>
          </artwork>
          <artwork type="ascii-art" align="center"><![CDATA[
 (Device)             (NGW)                            (App)

+--------+                                           +--------+
|  CoAP  |                                           |  CoAP  |
|  Inner |                                           |  Inner |
+--------+                                           +--------+
|  SCHC  |                                           |  SCHC  |
|  Inner |                                           |  Inner |
+--------+                                           +--------+
|  CoAP  |                                           |  CoAP  |
|  Outer |                                           |  Outer |
+--------+                                           +--------+
|  SCHC  |                                           |  SCHC  |
|  Outer |                                           |  Outer |
+--------+                                           +--------+
.  udp   .                                           .  udp   .
..........     ..................                    ..........
.  ipv6  .     .      ipv6      .                    .  ipv6  .
..........     ..................                    ..........
.  schc  .     .  schc  .       .                    .        .
..........     ..........       .                    .        .
.  lpwan .     . lpwan  .       .                    .        .
..........     ..................                    ..........
      ((((LPWAN))))           ------   Internet  -------
]]></artwork>
        </artset>
      </figure>
      <t>In the case of several SCHC instances, as shown in <xref target="fig-applicability-to-coap-2"/> and <xref target="fig-applicability-to-coap-3"/>, the Rules may come from different provisioning domains.</t>
      <t>This document focuses on CoAP compression, as represented by the dashed boxes in the previous figures.</t>
    </section>
    <section anchor="sec-coap-header-compression">
      <name>CoAP Headers Compressed with SCHC</name>
      <t>The use of SCHC over the CoAP header applies the same description and compression/decompression techniques as the technique used for IP and UDP, as explained in <xref target="RFC8724"/>. For CoAP, the SCHC Rules description uses the direction information to optimize the compression by reducing the number of Rules needed to compress headers. The Field Descriptor <bcp14>MAY</bcp14> define both request/response headers and TVs in the same Rule, using the DI to indicate the header type.</t>
      <t>As for other header compression protocols, when the compressor does not find a correct Rule to compress the header, the packet <bcp14>MUST</bcp14> be sent uncompressed using the RuleID dedicated to this purpose, and where the Compression Residue is the complete header of the packet (see <xref section="6" sectionFormat="of" target="RFC8724"/>).</t>
      <section anchor="ssec-differences-with-udp-ip">
        <name>Differences between CoAP and UDP/IP Compression</name>
        <t>CoAP compression differs from IPv6 and UDP compression in the following aspects:</t>
        <ul spacing="normal">
          <li>
            <t>The CoAP message format is asymmetric, i.e., the headers are different for a request and a response.  </t>
            <t>
For example, the Uri-Path Option can be used in a request, while it is not used in a response. A request might contain an Accept Option, while both a request and a response might include a Content-Format Option. In comparison, the IPv6 and UDP returning path swaps the value of some fields in the header. However, all the directions have the same fields (e.g., source and destination address fields).  </t>
            <t><xref target="RFC8724"/> defines the use of a DI in the Field Descriptor, which allows a single Rule to process a message header differently, depending on the direction.</t>
          </li>
          <li>
            <t>Even when a field is "symmetric" (i.e., found in both directions), the values carried in each direction are different. The compression may use a "match-mapping" MO to limit the range of expected values in a particular direction and reduce the Compression Residue's size. Through the DI, a Field Descriptor in the Rules splits the possible field value into two parts, one for each direction.  </t>
            <t>
For instance, if a client sends only Confirmable (CON) requests <xref target="RFC7252"/>, the Type can be elided by compression, and the reply from the server may use one single bit to carry either the Acknowledgement (ACK) or Reset (RST) type. The field Code has the same behavior: the 0.0X code format value in a request and the Y.ZZ code format in a response.</t>
          </li>
          <li>
            <t>In SCHC, the Rule defines the different header fields' length, so SCHC does not need to send it. In IPv6 and UDP headers, the fields have a fixed size, known by definition.  </t>
            <t>
On the other hand, some CoAP header fields have variable lengths, and the Rule description specifies it. For example, the size of the Token field may vary from 0 to 8 bytes, and the CoAP options rely on the Type-Length-Value encoding format to specify the size of the actual option value in bytes.  </t>
            <t>
When doing SCHC compression of a variable-length field, <xref section="7.4.2" sectionFormat="of" target="RFC8724"/> makes it possible to define a function for the Field Length in the Field Descriptor, in order to determine the length before compression. If the Field Length is unknown, the Rule will set it as a variable, and SCHC will send the compressed field's length in the Compression Residue.</t>
          </li>
          <li>
            <t>A field can appear several times in the CoAP headers. This is typically the case for elements of a URI (i.e., path segments or query arguments). The SCHC specification <xref target="RFC8724"/> allows a FID to appear several times in the Rule and uses the Field Position (FP) to identify the correct instance, thereby removing the MO's ambiguity.</t>
          </li>
          <li>
            <t>Field Lengths defined in CoAP can be too large when it comes to LPWAN traffic constraints. For instance, this is particularly true for the Message ID field and the Token field. SCHC uses different MOs to perform the compression (see <xref section="7.4" sectionFormat="of" target="RFC8724"/>). In this case, SCHC can apply the Most Significant Bits (MSBs) MO to reduce the information carried on LPWANs.</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="sec-coap-fields-compression">
      <name>Compression of CoAP Header Fields</name>
      <t>This section discusses the SCHC compression of the CoAP header fields (see <xref section="3" sectionFormat="of" target="RFC7252"/>), building on what is specified in <xref section="7.1" sectionFormat="of" target="RFC8724"/>.</t>
      <section anchor="ssec-coap-version-field">
        <name>CoAP Version Field</name>
        <t>The Version field is described as bidirectional in a SCHC Rule, and it <bcp14>MUST</bcp14> be elided during SCHC compression, since it always contains the same value. In the future, or if a new version of CoAP is defined, new Rules will be needed to avoid ambiguities between versions.</t>
      </section>
      <section anchor="ssec-coap-type-field">
        <name>CoAP Type Field</name>
        <t>The Type field specifies one of the four types of CoAP messages, encoded as specified in <xref section="3" sectionFormat="of" target="RFC7252"/>: Confirmable (CON), Non-confirmable (NON), Acknowledgement (ACK), and Reset (RST).</t>
        <t>The SCHC compression scheme <bcp14>SHOULD</bcp14> elide this field if, for instance, a client is sending only NON messages or only CON messages. For RST messages, SCHC may use a dedicated Rule. For other usages, SCHC can use a "match-mapping" MO.</t>
      </section>
      <section anchor="ssec-coap-tkl-field">
        <name>CoAP Token Length (TKL) Field</name>
        <t>The Token Length (TKL) field specifies the size in bytes of the later Token field (see <xref target="ssec-coap-token-field"/>), and is described as bidirectional in a SCHC Rule.</t>
        <t>If the field value does not change over time, the SCHC Rule describes the TV set to that value, the MO set to "equal", and the CDA set to "not-sent", thereby eliding the field.</t>
        <t>Otherwise, if the field value changes over time, the SCHC Rule does not set the TV, while setting the MO to "ignore" and the CDA to "value-sent". The Rule may also use a "match-mapping" MO to compress the value.</t>
      </section>
      <section anchor="ssec-coap-code-field">
        <name>CoAP Code Field</name>
        <t>The Code field takes value from the "Code" column of the "CoAP Codes" IANA registry, encoded as specified in <xref section="3" sectionFormat="of" target="RFC7252"/>. This field indicates the Method Code of a CoAP request or the Response Code of a CoAP Response, while the value 0.00 indicates an Empty message. The compression of the CoAP Code field follows the same principle as that of the CoAP Type field.</t>
        <t>If the Device plays a specific role, SCHC may split the code values into two Field Descriptors: (1) the Method Codes with the 0 class and (2) the Response Codes. SCHC will use the DI to identify the correct value in the packet. If the Device only implements a CoAP client, SCHC compression may focus only on the Method Codes that the client uses in its outgoing requests.</t>
        <t>For known values, SCHC can use a "match-mapping" MO. If SCHC cannot compress the Code field, it will send the values in the Compression Residue.</t>
      </section>
      <section anchor="ssec-coap-message-id-field">
        <name>CoAP Message ID Field</name>
        <t>SCHC can compress the Message ID field with the MSB MO and the LSB CDA (see <xref section="7.4" sectionFormat="of" target="RFC8724"/>).</t>
      </section>
      <section anchor="ssec-coap-token-field">
        <name>CoAP Token Field</name>
        <t>A CoAP message fully specifies the Token by using two CoAP fields: the Token Length (TKL) field in the mandatory header (see <xref target="ssec-coap-tkl-field"/>) and the variable-length Token field that directly follows the mandatory CoAP header and specifies the Token value.</t>
        <t>For the Token field, SCHC <bcp14>MUST NOT</bcp14> send it as variable-size data in the Compression Residue, to avoid ambiguity with the Token Length field. Therefore, SCHC <bcp14>MUST</bcp14> use the value of the Token Length field to define the size of the Token field in the Compression Residue.</t>
        <t>To this end, SCHC designates a specific function, "tkl", that the Rule <bcp14>MUST</bcp14> use to complete the Field Descriptor. During the decompression, this function returns the value contained in the Token Length field, hence the length of the Token field.</t>
      </section>
    </section>
    <section anchor="sec-coap-options">
      <name>Compression of CoAP Options</name>
      <t>CoAP defines options placed after the mandatory header and the Token field, ordered by option number (see <xref section="3" sectionFormat="of" target="RFC7252"/>). As per <xref section="3.1" sectionFormat="of" target="RFC7252"/>, each option instance in a message uses the format Option Delta (D), Option Length (L), Option Value (V).</t>
      <t>In particular, the Option Delta is used to express the option number of a CoAP option within a CoAP message, as the difference between the Option Number of that option and the Option Number of the previous option in that message (or zero for the first option). Also, the Option Length specifies the length of the Option Value, in bytes.</t>
      <t>In a SCHC Rule, the Field Descriptor related to a CoAP option is as follows:</t>
      <ul spacing="normal">
        <li>
          <t>the FID is set to an unambiguous identifier of the CoAP option associated with the corresponding option number;</t>
        </li>
        <li>
          <t>the FL is set to the Option Length L of the CoAP option, encoded as per <xref section="7.1" sectionFormat="of" target="RFC8724"/>; and</t>
        </li>
        <li>
          <t>the TV is set to the Option Value V of the CoAP option.</t>
        </li>
      </ul>
      <t>Note that the MO and the CDA specified in the Field Descriptor operates only on the Option Value V. That is, SCHC compression produces a residue from the Option Value V, while ignoring the option number, the Option Delta, and the Option Length. Therefore, the residue of a SCHC packet conveying a compressed CoAP header does not include the option number, the Option Delta, and the Option Length, which the recipient will be able to reconstruct by performing SCHC Decompression.</t>
      <t>When the Option Length has a well-known value, the Rule may specify the Option Length value in the FL of the Field Descriptor (see above). In such a case, SCHC compression treats the Option Value as a fixed-length field (see <xref section="7.4.1" sectionFormat="of" target="RFC8724"/>).</t>
      <t>Otherwise, the Rule specifies the FL of the Field Descriptor as indicating a variable length, and SCHC compression treats the Option Value as a variable-length field (see <xref section="7.4.2" sectionFormat="of" target="RFC8724"/>). In such a case, when the CDA specified in the Field Descriptor is "value-sent" or LSB, then SCHC compression additionally carries the length of the Compression Residue, as prepended to the Compression Residue value. Note that the length coding differs between CoAP options and the Compression Residue of SCHC variable-length fields.</t>
      <t>CoAP requests and responses do not include the same options. Compression Rules may reflect this asymmetry by using the DI.</t>
      <t>The following sections present how SCHC compresses some specific CoAP options. Unless otherwise indicated, the referred CoAP options are specified in <xref target="RFC7252"/>.</t>
      <t>If the use of an additional CoAP option is later introduced, the SCHC Rules <bcp14>MAY</bcp14> be updated, in which case a new FID description <bcp14>MUST</bcp14> be assigned to perform the compression of the CoAP option. Otherwise, if no Rule describes that CoAP option, SCHC compression is not achieved, and SCHC sends the CoAP header without compression.</t>
      <section anchor="ssec-content-format-accept-option">
        <name>CoAP Option Content-Format and Accept Fields</name>
        <t>If the client expects a single specific value, SCHC can elide these fields, by specifying the value in the TV of a Rule description with an "equal" MO and a "not-sent" CDA.</t>
        <t>Otherwise, if the client expects several possible values, a "match-mapping" MO <bcp14>SHOULD</bcp14> be used to limit the Compression Residue's size. If not, SCHC has to send the option value in the Compression Residue (with fixed or variable length).</t>
      </section>
      <section anchor="ssec-max-age-uri-host-uri-port-option">
        <name>CoAP Option Max-Age, Uri-Host, and Uri-Port Fields</name>
        <t>SCHC compresses these three fields in the same way. When the values of these options are known, SCHC can elide these fields. If the option uses well-known values, SCHC can use a "match-mapping" MO.</t>
        <t>Otherwise, these options' values will be sent in the Compression Residue, i.e., the SCHC Rule description does not set the TV, while setting the MO to "ignore" and the CDA to "value-sent".</t>
      </section>
      <section anchor="ssec-uri-path-uri-query-option">
        <name>CoAP Option Uri-Path and Uri-Query Fields</name>
        <t>The Uri-Path and Uri-Query fields are repeatable options, i.e., the CoAP header may include them several times and with different values. The SCHC Rule description uses the FP to distinguish the different instances of such options.</t>
        <t>To compress these repeatable field values, SCHC can use a "match-mapping" MO to reduce the size of variable paths or queries. When doing so, several elements can be regrouped into a single entry in order to optimize the compression. The numbering of elements does not change, and the first matching element sets the MO comparison.</t>
        <t>For example, as per the Rule descriptions shown in <xref target="_table-complex-path"/>, SCHC can use a single bit in the Compression Residue to code the path segments "/a/b" or the path segments "/c/d". If regrouping were not allowed, then 2 bits in the Compression Residue would be needed. At the same time, SCHC sends the third path element following "/a/b" or "/c/d" as a variable-size field in the Compression Residue.</t>
        <table align="center" anchor="_table-complex-path">
          <name>Complex Path Example</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">Uri-Path</td>
              <td align="left"> </td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">["/a/b", <br/> "/c/d"]</td>
              <td align="left">match-mapping</td>
              <td align="left">mapping-sent</td>
            </tr>
            <tr>
              <td align="left">Uri-Path</td>
              <td align="left">var <br/> (B)</td>
              <td align="left">3</td>
              <td align="left">Up</td>
              <td align="left"> </td>
              <td align="left">ignore</td>
              <td align="left">value-sent</td>
            </tr>
          </tbody>
        </table>
        <t>The length of the Uri-Path and Uri-Query Options may be known when the Rule is defined. In any other case, SCHC <bcp14>MUST</bcp14> set the Field Length (FL) to a variable value. The unit of the variable length is bytes, hence the Compression Residue size is expressed in bytes, encoded as defined in <xref section="7.4.2" sectionFormat="of" target="RFC8724"/>.</t>
        <t>SCHC compression can use the MSB MO for a Uri-Path or Uri-Query element. In such a case, care must be taken when specifying the MSB parameter value in bits, which <bcp14>MUST</bcp14> be a multiple of 8. The length sent at the beginning of the variable-size field Compression Residue indicates the LSB's size in bytes, consistent with the unit of the variable length in the Rule description.</t>
        <t>For instance, for a CORECONF path /c/X6?k=eth0, the Rule description can be as shown in <xref target="_table-CoMicompress"/>. That is, SCHC compresses the first part of the Uri-Path with a "not-sent" CDA. Also, SCHC will send the second element of the Uri-Path preceded with the length (i.e., 0b0010 "X6"), which is followed by the query option preceded with the length (i.e., 0b0100 "eth0").</t>
        <table align="center" anchor="_table-CoMicompress">
          <name>CORECONF URI compression</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">Uri-Path</td>
              <td align="left"> </td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"c"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
            </tr>
            <tr>
              <td align="left">Uri-Path</td>
              <td align="left">var <br/> (B)</td>
              <td align="left">2</td>
              <td align="left">Up</td>
              <td align="left"> </td>
              <td align="left">ignore</td>
              <td align="left">value-sent</td>
            </tr>
            <tr>
              <td align="left">Uri-Query</td>
              <td align="left">var <br/> (B)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"k="</td>
              <td align="left">MSB(16)</td>
              <td align="left">LSB</td>
            </tr>
          </tbody>
        </table>
        <section anchor="variable-number-of-path-or-query-elements">
          <name>Variable Number of Path or Query Elements</name>
          <t>SCHC fixes the number of Uri-Path or Uri-Query elements in a Rule at Rule creation time. If the number of such elements varies, SCHC <bcp14>SHOULD</bcp14> either:</t>
          <ul spacing="normal">
            <li>
              <t>create several Rules to cover all possibilities; or</t>
            </li>
            <li>
              <t>create a Rule that defines several entries for Uri-Path to cover the longest path, and send a Compression Residue with a length of 0 to indicate that a Uri-Path entry is empty.  </t>
              <t>
However, this adds 4 bits to the variable Compression Residue size (see <xref section="7.4.2" sectionFormat="of" target="RFC8724"/>).</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="ssec-size1-size2-proxy-uri-proxy-scheme-option">
        <name>CoAP Option Size1, Size2, Proxy-Uri, and Proxy-Scheme Fields</name>
        <t>The Size2 field is an option defined in <xref target="RFC7959"/>.</t>
        <t>The SCHC Rule description <bcp14>MAY</bcp14> define sending some field values by not setting the TV, while setting the MO to "ignore" and the CDA to "value-sent". A Rule <bcp14>MAY</bcp14> also use a "match-mapping" MO when there are different alternatives for the same FID. Otherwise, the Rule sets the TV to a specific value, the MO to "equal", and the CDA to "not-sent".</t>
      </section>
      <section anchor="ssec-proxy-cri-proxy-scheme-number-option">
        <name>CoAP Option Proxy-Cri and Proxy-Scheme-Number Fields</name>
        <t>The Proxy-Cri field is an option defined in <xref target="I-D.ietf-core-href"/>. The option carries an encoded CBOR data item <xref target="RFC8949"/> that represents an absolute CRI reference (see <xref section="5" sectionFormat="of" target="I-D.ietf-core-href"/>). The option is used analogously to the Proxy-Uri option as defined in <xref section="5.10.2" sectionFormat="of" target="RFC7252"/>.</t>
        <t>The Proxy-Scheme-Number field is an option defined in <xref target="I-D.ietf-core-href"/>. The option carries a CRI Scheme Number represented as a CoAP unsigned integer (see Sections <xref target="I-D.ietf-core-href" section="5.1.1" sectionFormat="bare"/> and <xref target="I-D.ietf-core-href" section="8.1" sectionFormat="bare"/> of <xref target="I-D.ietf-core-href"/>). The option is used analogously to the Proxy-Scheme option as defined in <xref section="5.10.2" sectionFormat="of" target="RFC7252"/>.</t>
        <t>The SCHC Rule description <bcp14>MAY</bcp14> define sending some field values by not setting the TV, while setting the MO to "ignore" and the CDA to "value-sent". A Rule <bcp14>MAY</bcp14> also use a "match-mapping" MO when there are different alternatives for the same FID. Otherwise, the Rule sets the TV to a specific value, the MO to "equal", and the CDA to "not-sent".</t>
      </section>
      <section anchor="ssec-location-path-location-query-option">
        <name>CoAP Location-Path and Location-Query Fields</name>
        <t>A Rule entry cannot store these fields' values. Therefore, SCHC compression <bcp14>MUST</bcp14> always send these values in the Compression Residue. That is, in the SCHC Rule, the TV is not set, while the MO is set to "ignore" and the CDA is set to "value-sent".</t>
      </section>
      <section anchor="ssec-etag-if-match-option">
        <name>CoAP Option ETag and If-Match Fields</name>
        <t>When a CoAP message uses the ETag Option or the If-Match Option, SCHC compression <bcp14>MAY</bcp14> send its content in the Compression Residue. That is, in the SCHC Rule, the TV is not set, while the MO is set to "ignore" and the CDA is set to "value-sent". Alternatively, if a pre-defined set of values determined by the server is known and is used by the client as ETag values or If-Match values, then a Rule <bcp14>MAY</bcp14> use a "match-mapping" MO when there are different alternatives for the same FID.</t>
      </section>
      <section anchor="ssec-if-none-match">
        <name>CoAP Option If-None-Match</name>
        <t>The If-None-Match Option occurs at most once and is always empty. The SCHC Rule <bcp14>MUST</bcp14> describe an empty TV, with the MO set to "equal" and the CDA set to "not-sent".</t>
      </section>
      <section anchor="coap-options-hop-limit">
        <name>CoAP Option Hop-Limit Field</name>
        <t>The Hop-Limit field is an option defined in <xref target="RFC8768"/> that can be used to detect forwarding loops through a chain of CoAP proxies. The first proxy in the chain that understands the option includes it in a received request with a proper value set, before forwarding the request. Any following proxy that understands the option decrements the option value and forwards the request if the new value is different than zero, or returns a 5.08 (Hop Limit Reached) error response otherwise.</t>
        <t>When a CoAP message uses the Hop-Limit Option, SCHC compression <bcp14>SHOULD</bcp14> send its content in the Compression Residue. That is, in the SCHC Rule, the TV is not set, while the MO is set to "ignore" and the CDA is set to "value-sent". As an exception, and consistently with the default value 16 defined for the Hop-Limit Option in <xref section="3" sectionFormat="of" target="RFC8768"/>, a Rule <bcp14>MAY</bcp14> describe a TV with value 16, with the MO set to "equal" and the CDA set to "not-sent".</t>
      </section>
      <section anchor="coap-options-echo">
        <name>CoAP Option Echo Field</name>
        <t>The Echo field is an option defined in <xref target="RFC9175"/> that a server can include in a CoAP response as a challenge to the client, and that the client echoes back to the server in one or more CoAP requests. This enables the server to verify the freshness of a request and to cryptographically verify the aliveness of the client. Also, it forces the client to demonstrate reachability at its claimed network address.</t>
        <t>When a CoAP message uses the Echo Option, SCHC compression <bcp14>SHOULD</bcp14> send its content in the Compression Residue. That is, in the SCHC Rule, the TV is not set, while the MO is set to "ignore" and the CDA is set to "value-sent". An exception applies in case the server generates the values to use for the Echo Option by means of a persistent counter (see <xref section="A" sectionFormat="of" target="RFC9175"/>). In such a case, a Rule <bcp14>MAY</bcp14> use the MSB MO and the LSB CDA. This would be effectively applicable until the persistent counter at the server becomes greater than the maximum threshold value that produces an MSB-matching.</t>
      </section>
      <section anchor="coap-options-request-tag">
        <name>CoAP Option Request-Tag Field</name>
        <t>The Request-Tag field is an option defined in <xref target="RFC9175"/> that the client can set in CoAP requests throughout block-wise operations, with value an ephemeral short-lived identifier of the specific block-wise operation in question. This allows the server to match message fragments belonging to the same request operation and, if the server supports it, to reliably process simultaneous block-wise request operations on a single resource. If requests are integrity protected, this also protects against interchange of fragments between different block-wise request operations.</t>
        <t>When a CoAP message uses the Request-Tag Option, SCHC compression <bcp14>MAY</bcp14> send its content in the Compression Residue. That is, in the SCHC Rule, the TV is not set, while the MO is set to "ignore" and the CDA is set to "value-sent". Alternatively, if a pre-defined set of Request-Tag values used by the client is known, a Rule <bcp14>MAY</bcp14> use a "match-mapping" MO when there are different alternatives for the same FID.</t>
      </section>
      <section anchor="coap-options-edhoc">
        <name>CoAP Option EDHOC Field</name>
        <t>The EDHOC field is an option defined in <xref target="I-D.ietf-core-oscore-edhoc"/> that a client can include in a CoAP request, in order to perform an optimized, shortened execution of the authenticated key exchange protocol EDHOC <xref target="RFC9528"/>. Such a request conveys both the final EDHOC message and actual application data, where the latter is protected with OSCORE <xref target="RFC8613"/> using a Security Context derived from the result of the current EDHOC execution.</t>
        <t>The EDHOC Option occurs at most once and is always empty. The SCHC Rule <bcp14>MUST</bcp14> describe an empty TV, with the MO set to "equal" and the CDA set to "not-sent".</t>
      </section>
    </section>
    <section anchor="sec-coap-extensions">
      <name>Compression of CoAP Extensions</name>
      <section anchor="ssec-coap-extensions-block">
        <name>Block-Wise Transfers</name>
        <t>When a CoAP message uses a Block1 or Block2 Option <xref target="RFC7959"/> or a Q-Block1 or Q-Block2 Option <xref target="RFC9177"/>, SCHC compression <bcp14>MUST</bcp14> send its content in the Compression Residue. In the SCHC Rule, the TV is not set, while the MO is set to "ignore" and the CDA is set to "value-sent".</t>
        <t>The Block1, Block2, Q-Block1, and Q-Block2 options allow fragmentation at the CoAP level that is compatible with SCHC fragmentation. Both fragmentation mechanisms are complementary, and the node may use them for the same packet as needed.</t>
      </section>
      <section anchor="ssec-coap-extensions-observe">
        <name>Observe</name>
        <t><xref target="RFC7641"/> defines the Observe Option. The SCHC Rule description does not set the TV, while setting the MO to "ignore" and the CDA to "value-sent". SCHC does not limit the maximum size for this option (3 bytes). To reduce the transmission size, either the Device implementation <bcp14>MAY</bcp14> limit the delta between two consecutive values or a proxy can modify the increment.</t>
        <t>Since the client <bcp14>MAY</bcp14> use a RST message to inform a server that the Observe response is not required, a specific SCHC Rule <bcp14>SHOULD</bcp14> exist to allow the compression of a RST message.</t>
      </section>
      <section anchor="ssec-coap-extensions-no-response">
        <name>No-Response</name>
        <t><xref target="RFC7967"/> defines a No-Response Option limiting the CoAP responses made by a server to a CoAP request. Different behaviors exist while using this option to limit the responses made by a server to a request. If both ends know the specific value, then the SCHC Rule describes the TV set to that value, the MO set to "equal", and the CDA set to "not-sent".</t>
        <t>Otherwise, if the value changes over time, the SCHC Rule does not set the TV, while setting the MO to "ignore" and the CDA to "value-sent". The Rule may also use a "match-mapping" MO to compress the value.</t>
      </section>
      <section anchor="ssec-coap-extensions-oscore">
        <name>OSCORE</name>
        <t>The security protocol OSCORE <xref target="RFC8613"/> provides end-to-end protection for CoAP messages. Group OSCORE <xref target="I-D.ietf-core-oscore-groupcomm"/> builds on OSCORE and defines end-to-end protection of CoAP messages in group communication <xref target="I-D.ietf-core-groupcomm-bis"/>. This section describes how SCHC Rules can be applied to compress messages protected with OSCORE or Group OSCORE.</t>
        <t><xref target="fig-oscore-option"/> shows the OSCORE Option value encoding, as it was originally defined in <xref section="6.1" sectionFormat="of" target="RFC8613"/>. As explained later in this section, this has been extended in <xref target="I-D.ietf-core-oscore-key-update"/> and <xref target="I-D.ietf-core-oscore-groupcomm"/>. The first byte of the OSCORE Option value specifies information to parse the rest of the value by using flags, as described below.</t>
        <ul spacing="normal">
          <li>
            <t>As defined in <xref section="4.1" sectionFormat="of" target="I-D.ietf-core-oscore-key-update"/>, the eight least significant bit, when set, indicates that the OSCORE Option includes a second byte of flags. The seventh least significant bit is currently unassigned.</t>
          </li>
          <li>
            <t>As defined in <xref section="5" sectionFormat="of" target="I-D.ietf-core-oscore-groupcomm"/>, the sixth least significant bit, when set, indicates that the message including the OSCORE option is protected with the group mode of Group OSCORE (see <xref section="8" sectionFormat="of" target="I-D.ietf-core-oscore-groupcomm"/>). When not set, the bit indicates that the message is protected either with OSCORE, or with the pairwise mode of Group OSCORE (see <xref section="9" sectionFormat="of" target="I-D.ietf-core-oscore-groupcomm"/>), while the specific OSCORE Security Context used to protect the message determines which of the two cases applies.</t>
          </li>
          <li>
            <t>As defined in <xref section="6.1" sectionFormat="of" target="RFC8613"/>, bit h, when set, indicates the presence of the kid context field in the option. Also, bit k, when set, indicates the presence of the kid field. Finally, the three least significant bits form the n field, which indicates the length of the piv (Partial Initialization Vector) field in bytes. When n = 0, no piv is present.</t>
          </li>
        </ul>
        <t>Assuming the presence of a single flag byte, this is followed by the piv field. After that, if the h bit is set, the kid context field is present, preceded by one byte "s" indicating its length in bytes. After that, if the k bit is set, the kid field is present, and it ends where the OSCORE Option value ends.</t>
        <figure anchor="fig-oscore-option">
          <name>OSCORE Option</name>
          <artwork align="center"><![CDATA[
 0 1 2 3 4 5 6 7 <--------- n bytes ------------->
+-+-+-+-+-+-+-+-+---------------------------------+
|0 0 0|h|k|  n  |        Partial IV (if any)      |
+-+-+-+-+-+-+-+-+---------------------------------+
|               |                                 |
|<--   CoAP  -->|<------- CoAP OSCORE_piv ------> |
   OSCORE_flags

 <-- 1 byte --> <------ s bytes ----->
+--------------+----------------------+-----------------------+
|  s (if any)  | kid context (if any) | kid (if any)      ... |
+--------------+----------------------+-----------------------+
|                                     |                       |
|<-------- CoAP OSCORE_kidctx ------->|<-- CoAP OSCORE_kid -->|
]]></artwork>
        </figure>
        <t><xref target="fig-oscore-option-kudos"/> shows the extended OSCORE Option value encoding, with the second byte of flags also present. As defined in <xref section="4.1" sectionFormat="of" target="I-D.ietf-core-oscore-key-update"/>, the least significant bit d of this byte, when set, indicates that two additional fields are included in the option, following the kid context field (if any).</t>
        <t>These two fields, namely x and nonce, are used when running the key update protocol KUDOS defined in <xref target="I-D.ietf-core-oscore-key-update"/>, with x specifying the length of the nonce field in bytes as well as the specific behavior to adopt during the KUDOS execution.</t>
        <t>If the seventh least significant bit z of the x field is set, it indicates that two additional fields are included in the option, following the x and nonce fields. These two fields, namely y and old_nonce, are also used when running the key update protocol KUDOS, with y specifying the length of the old_nonce field in bytes.</t>
        <t><xref target="fig-oscore-option-kudos"/> provides the breakdown of the x field, where its four least significant bits form the sub-field m, which specifies the size of nonce in bytes, minus 1. Also, the figure provides the breakdown of the y field, where its four least significant bits form the sub-field w, which specifies the size of old_nonce in bytes, minus 1.</t>
        <figure anchor="fig-oscore-option-kudos">
          <name>OSCORE Option extended to support a KUDOS execution</name>
          <artwork align="center"><![CDATA[
 0 1 2 3 4 5 6 7  8   9   10  11  12  13  14  15 <----- n bytes ----->
+-+-+-+-+-+-+-+-+---+---+---+---+---+---+---+---+---------------------+
|1|0|0|h|k|  n  | 0 | 0 | 0 | 0 | 0 | 0 | 0 | d | Partial IV (if any) |
+-+-+-+-+-+-+-+-+---+---+---+---+---+---+---+---+---------------------+
|                                               |                     |
|<------------------- CoAP -------------------->|<- CoAP OSCORE_piv ->|
                   OSCORE_flags

 <- 1 byte -> <----------- s bytes ------------>
+------------+----------------------------------+
| s (if any) |       kid context (if any)       |
+------------+----------------------------------+
|                                               |
|<------------- CoAP OSCORE_kidctx ------------>|


 <------ 1 byte -----> <----- m + 1 bytes ----->
+---------------------+-------------------------+
|     x (if any)      |      nonce (if any)     |
+---------------------+-------------------------+
|<-- CoAP OSCORE_x -->|<-- CoAP OSCORE_nonce -->|
|                     |
|   0 1 2 3 4 5 6 7   |
|  +-+-+-+-+-+-+-+-+  |
|  |0|z|b|p|   m   |  |
|  +-+-+-+-+-+-+-+-+  |


 <------ 1 byte ----->  <------ w + 1 bytes ------>
+---------------------+----------------------------+
|     y (if any)      |     old_nonce (if any)     |
+---------------------+----------------------------+
|<-- CoAP OSCORE_y -->|<-- CoAP OSCORE_oldnonce -->|
|                     |
|   0 1 2 3 4 5 6 7   |
|  +-+-+-+-+-+-+-+-+  |
|  |0|0|0|0|   w   |  |
|  +-+-+-+-+-+-+-+-+  |


+-----------------------+
|    kid (if any) ...   |
+-----------------------+
|                       |
|<-- CoAP OSCORE_kid -->|
]]></artwork>
        </figure>
        <t>To better perform OSCORE SCHC compression, the Rule description needs to identify the OSCORE Option and the fields it contains.</t>
        <t>Conceptually, it discerns up to eight distinct pieces of information within the OSCORE Option: the flag bits, the piv, the kid context prepended by its size, the x byte, the nonce, the y byte, the old_nonce, and the kid. The SCHC Rule splits the OSCORE Option into eight corresponding Field Descriptors in order to compress those pieces of information:</t>
        <ul spacing="normal">
          <li>
            <t>CoAP OSCORE_flags</t>
          </li>
          <li>
            <t>CoAP OSCORE_piv</t>
          </li>
          <li>
            <t>CoAP OSCORE_kidctx</t>
          </li>
          <li>
            <t>CoAP OSCORE_x</t>
          </li>
          <li>
            <t>CoAP OSCORE_nonce</t>
          </li>
          <li>
            <t>CoAP OSCORE_y</t>
          </li>
          <li>
            <t>CoAP OSCORE_oldnonce</t>
          </li>
          <li>
            <t>CoAP OSCORE_kid</t>
          </li>
        </ul>
        <t><xref target="fig-oscore-option"/> shows the original format of the OSCORE Option with the four fields OSCORE_flags, OSCORE_piv, OSCORE_kidctx, and OSCORE_kid superimposed on it. Also, <xref target="fig-oscore-option-kudos"/> shows the extended format of the OSCORE option with all the eight fields superimposed on it.</t>
        <t>If a field is not present, then the corresponding Field Descriptor in the SCHC Rule describes the TV set to b'', with the MO set to "equal" and the CDA set to "not-sent". Note that, if the field kid context is present, it directly includes the size octet, s.</t>
        <t>In addition, the following applies.</t>
        <ul spacing="normal">
          <li>
            <t>For the x field, if both endpoints know the value, then the corresponding Field Descriptor in the SCHC Rule describes the TV set to that value, with the MO set to "equal" and the CDA set to "not-sent". This models: the case where the x field is not present, and thus TV is set to b''; and the case where the two endpoints run KUDOS with a pre-agreed size of the nonce field as per the m sub-field of the x field, as well as with a pre-agreed combination of its modes of operation, as per the bits b and p of the x field.  </t>
            <t>
Otherwise, if the value changes over time, then the corresponding Field Descriptor in the SCHC Rule does not set the TV, while it sets the MO to "ignore" and the CDA to "value-sent". The Rule may also use a "match-mapping" MO to compress this field, in case the two endpoints pre-agree on a set of alternative ways to run KUDOS, with respect to the size of the nonce field and the combination of the KUDOS modes of operation to use.</t>
          </li>
          <li>
            <t>For the y field, if both endpoints know the value, then the corresponding Field Descriptor in the SCHC Rule describes the TV set to that value, with the MO set to "equal" and the CDA set to "not-sent". This models: the case where the y field is not present, and thus TV is set to b''; and the case where the two endpoints run KUDOS with a pre-agreed size of the old_nonce field as per the w sub-field of the y field.  </t>
            <t>
Otherwise, if the value changes over time, then the corresponding Field Descriptor in the SCHC Rule does not set the TV, while it sets the MO to "ignore" and the CDA to "value-sent". The Rule may also use a "match-mapping" MO to compress this field, in case the two endpoints pre-agree on a set of sizes of the old_nonce field.</t>
          </li>
          <li>
            <t>For the nonce field, if it is not present (i.e., the x field is not present in the first place), then the corresponding Field Descriptor in the SCHC Rule describes the TV set to b'', with the MO set to "equal" and the CDA set to "not-sent".  </t>
            <t>
Otherwise, if the nonce field is present, then the corresponding Field Descriptor in the SCHC Rule has the TV not set, while the MO is set to "ignore" and the CDA is set to "value-sent". In such a case, for the value of the nonce field, SCHC <bcp14>MUST NOT</bcp14> send it as variable-length data in the Compression Residue, to avoid ambiguity with the length of the nonce field encoded in the x field. Therefore, SCHC <bcp14>MUST</bcp14> use the m sub-field of the x field to define the size of the Compression Residue. SCHC designates a specific function, "osc.x.m", that the Rule <bcp14>MUST</bcp14> use to complete the Field Descriptor. During the decompression, this function returns the length of the nonce field in bytes, as the value of the m sub-field of the x field, plus 1.</t>
          </li>
          <li>
            <t>For the old_nonce field, if it is not present (i.e., the y field is not present in the first place), then the corresponding Field Descriptor in the SCHC Rule describes the TV set to b'', with the MO set to "equal" and the CDA set to "not-sent".  </t>
            <t>
Otherwise, if the old_nonce field is present, then the corresponding Field Descriptor in the SCHC Rule has the TV not set, while the MO is set to "ignore" and the CDA is set to "value-sent". In such a case, for the value of the old_nonce field, SCHC <bcp14>MUST NOT</bcp14> send it as variable-length data in the Compression Residue, to avoid ambiguity with the length of the old_nonce field encoded in the y field. Therefore, SCHC <bcp14>MUST</bcp14> use the w sub-field of the y field to define the size of the Compression Residue. SCHC designates a specific function, "osc.y.w", that the Rule <bcp14>MUST</bcp14> use to complete the Field Descriptor. During the decompression, this function returns the length of the old_nonce field in bytes, as the value of the w sub-field of the y field, plus 1.</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="payload-marker">
      <name>Compression of the CoAP Payload Marker</name>
      <t>The following applies with respect to the 0xFF payload marker. A SCHC compression Rule for CoAP includes all the expected CoAP options, therefore the payload marker does not have to be specified in a SCHC Rule description.</t>
      <t>If the CoAP message to compress with SCHC is not going to be protected with OSCORE <xref target="RFC8613"/> and includes a payload, then the 0xFF payload marker <bcp14>MUST NOT</bcp14> be included in the compressed message, which is composed of the Compression RuleID, the Compression Residue (if any), and the CoAP payload.</t>
      <t>After having decompressed an incoming message, the recipient endpoint <bcp14>MUST</bcp14> prepend the 0xFF payload marker to the CoAP payload, if any was present after the consumed Compression Residue.</t>
      <t>If the CoAP message to compress with SCHC is going to be protected with OSCORE, the 0xFF payload marker is compressed as specified later in <xref target="ssec-examples-oscore"/>.</t>
    </section>
    <section anchor="sec-examples">
      <name>Examples of CoAP Header Compression</name>
      <section anchor="ssec-examples-con-message">
        <name>Mandatory Header with CON Message</name>
        <t>In this first scenario, the SCHC compressor on the NGW side receives a POST message from an Internet client, which is immediately acknowledged by the Device. <xref target="_table-CoAP-header-1"/> describes the SCHC Rule descriptions for this scenario.</t>
        <artwork><![CDATA[
+----------+
| RuleID 1 |
+----------+
]]></artwork>
        <table align="center" anchor="_table-CoAP-header-1">
          <name>CoAP Context to compress header without Token</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP <br/> Version</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">CON</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">[ACK, <br/> RST]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">T</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> TKL</td>
              <td align="left">4</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">[0.00, <br/> ... <br/> 5.05]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">CC CCC</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> MID</td>
              <td align="left">16</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0000</td>
              <td align="left">MSB(7)</td>
              <td align="left">LSB</td>
              <td align="left">MID</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Path</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">"status"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t>In this example, SCHC compression elides the version and Token Length fields. The 25 Method and Response Codes defined in <xref target="RFC7252"/> have been shrunk to 5 bits using a "match-mapping" MO. The Uri-Path contains a single element with the TV set to "status" and the CDA set to "not-sent", thereby eliding the single occurrence of the Uri-Path Option with value "status".</t>
        <t>SCHC compression reduces the header, sending only a mapped Type (and only for uplink messages), a mapped code, and the least significant bits of the Message ID (9 bits in the example above).</t>
        <t>Note that, if a client is located in an Application Server and sends a request to a server located in the Device, then the request may not be compressed through this Rule, since the MID might not start with 7 bits equal to 0. A CoAP proxy placed before SCHC C/D can rewrite the Message ID to fit the value and match the Rule.</t>
      </section>
      <section anchor="ssec-examples-oscore">
        <name>OSCORE Compression</name>
        <t>OSCORE aims to solve the problem of end-to-end protection for CoAP messages. Therefore, the goal is to hide as much as possible of the CoAP message, while still enabling proxy operations.</t>
        <t>Conceptually, this is achieved by splitting the CoAP message into an Inner Plaintext and an Outer OSCORE message. The Inner Plaintext contains (sensitive) information that is not necessary for performing proxy operations. Therefore, that information can be encrypted end-to-end, until it reaches the other origin endpoint as its final destination. The Outer Message acts as a shell matching the regular CoAP message format, and includes all the CoAP options and information needed for performing proxy operations and caching. This is summarized in <xref target="fig-inner-outer"/>.</t>
        <t>In particular, the CoAP options are arranged into three classes, each of which is granted a specific type of protection by the OSCORE protocol:</t>
        <ul spacing="normal">
          <li>
            <t>Class E: Encrypted options moved to the Inner Plaintext.</t>
          </li>
          <li>
            <t>Class I: Integrity-protected options, included in the Additional Authenticated Data (AAD) when protecting the Plaintext, but otherwise left untouched in the Outer Message.</t>
          </li>
          <li>
            <t>Class U: Unprotected options, left untouched in the Outer Message.</t>
          </li>
        </ul>
        <t>As per these classes, the Outer options comprise the OSCORE Option, which indicates that the message is protected with OSCORE and carries the information necessary for the recipient endpoint to retrieve the Security Context for decrypting the message.</t>
        <figure anchor="fig-inner-outer">
          <name>CoAP Message Split into OSCORE Outer Header and Plaintext</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="560" width="528" viewBox="0 0 528 560" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
                <path d="M 8,368 L 8,456" fill="none" stroke="black"/>
                <path d="M 8,480 L 8,528" fill="none" stroke="black"/>
                <path d="M 24,368 L 24,400" fill="none" stroke="black"/>
                <path d="M 40,368 L 40,400" fill="none" stroke="black"/>
                <path d="M 64,496 L 64,528" fill="none" stroke="black"/>
                <path d="M 72,368 L 72,400" fill="none" stroke="black"/>
                <path d="M 144,48 L 144,136" fill="none" stroke="black"/>
                <path d="M 144,160 L 144,272" fill="none" stroke="black"/>
                <path d="M 144,368 L 144,400" fill="none" stroke="black"/>
                <path d="M 160,48 L 160,80" fill="none" stroke="black"/>
                <path d="M 176,48 L 176,80" fill="none" stroke="black"/>
                <path d="M 200,176 L 200,208" fill="none" stroke="black"/>
                <path d="M 208,48 L 208,80" fill="none" stroke="black"/>
                <path d="M 224,480 L 224,496" fill="none" stroke="black"/>
                <path d="M 272,48 L 272,80" fill="none" stroke="black"/>
                <path d="M 272,368 L 272,400" fill="none" stroke="black"/>
                <path d="M 312,400 L 312,432" fill="none" stroke="black"/>
                <path d="M 360,160 L 360,176" fill="none" stroke="black"/>
                <path d="M 360,368 L 360,528" fill="none" stroke="black"/>
                <path d="M 400,48 L 400,80" fill="none" stroke="black"/>
                <path d="M 400,208 L 400,272" fill="none" stroke="black"/>
                <path d="M 424,368 L 424,400" fill="none" stroke="black"/>
                <path d="M 424,432 L 424,464" fill="none" stroke="black"/>
                <path d="M 440,80 L 440,112" fill="none" stroke="black"/>
                <path d="M 520,400 L 520,432" fill="none" stroke="black"/>
                <path d="M 520,464 L 520,528" fill="none" stroke="black"/>
                <path d="M 144,48 L 400,48" fill="none" stroke="black"/>
                <path d="M 144,80 L 408,80" fill="none" stroke="black"/>
                <path d="M 144,112 L 400,112" fill="none" stroke="black"/>
                <path d="M 144,176 L 360,176" fill="none" stroke="black"/>
                <path d="M 144,208 L 400,208" fill="none" stroke="black"/>
                <path d="M 144,272 L 400,272" fill="none" stroke="black"/>
                <path d="M 8,368 L 272,368" fill="none" stroke="black"/>
                <path d="M 360,368 L 424,368" fill="none" stroke="black"/>
                <path d="M 8,400 L 280,400" fill="none" stroke="black"/>
                <path d="M 360,400 L 472,400" fill="none" stroke="black"/>
                <path d="M 8,432 L 272,432" fill="none" stroke="black"/>
                <path d="M 360,432 L 480,432" fill="none" stroke="black"/>
                <path d="M 360,464 L 520,464" fill="none" stroke="black"/>
                <path d="M 8,496 L 224,496" fill="none" stroke="black"/>
                <path d="M 8,528 L 64,528" fill="none" stroke="black"/>
                <path d="M 360,528 L 520,528" fill="none" stroke="black"/>
                <path d="M 332,280 L 372,360" fill="none" stroke="black"/>
                <path d="M 164,360 L 204,280" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="380,360 368,354.4 368,365.6" fill="black" transform="rotate(63.43494882292201,372,360)"/>
                <polygon class="arrowhead" points="172,360 160,354.4 160,365.6" fill="black" transform="rotate(116.56505117707799,164,360)"/>
                <g class="text">
                  <text x="196" y="36">Original</text>
                  <text x="252" y="36">CoAP</text>
                  <text x="304" y="36">Message</text>
                  <text x="152" y="68">v</text>
                  <text x="168" y="68">t</text>
                  <text x="192" y="68">TKL</text>
                  <text x="236" y="68">code</text>
                  <text x="312" y="68">Message</text>
                  <text x="356" y="68">ID</text>
                  <text x="424" y="84">...</text>
                  <text x="176" y="100">Token</text>
                  <text x="420" y="116">....</text>
                  <text x="184" y="132">Options</text>
                  <text x="240" y="132">(IEU)</text>
                  <text x="360" y="132">|</text>
                  <text x="144" y="148">.</text>
                  <text x="360" y="148">.</text>
                  <text x="172" y="196">0xFF</text>
                  <text x="216" y="244">Payload</text>
                  <text x="48" y="356">Outer</text>
                  <text x="100" y="356">Header</text>
                  <text x="424" y="356">Plaintext</text>
                  <text x="16" y="388">v</text>
                  <text x="32" y="388">t</text>
                  <text x="56" y="388">TKL</text>
                  <text x="88" y="388">new</text>
                  <text x="124" y="388">code</text>
                  <text x="184" y="388">Message</text>
                  <text x="228" y="388">ID</text>
                  <text x="388" y="388">code</text>
                  <text x="296" y="404">...</text>
                  <text x="496" y="404">.....</text>
                  <text x="40" y="420">Token</text>
                  <text x="400" y="420">Options</text>
                  <text x="448" y="420">(E)</text>
                  <text x="292" y="436">....</text>
                  <text x="500" y="436">....</text>
                  <text x="48" y="452">Options</text>
                  <text x="100" y="452">(IU)</text>
                  <text x="224" y="452">|</text>
                  <text x="388" y="452">0xFF</text>
                  <text x="8" y="468">.</text>
                  <text x="224" y="468">.</text>
                  <text x="44" y="484">OSCORE</text>
                  <text x="100" y="484">Option</text>
                  <text x="400" y="500">Payload</text>
                  <text x="36" y="516">0xFF</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
                    Original CoAP Message
                 +-+-+---+-------+---------------+
                 |v|t|TKL| code  | Message ID    |
                 +-+-+---+-------+---------------+....+
                 | Token                              |
                 +-------------------------------.....+
                 | Options (IEU)            |
                 .                          .
                 .                          .
                 +------+-------------------+
                 | 0xFF |
                 +------+------------------------+
                 |                               |
                 |     Payload                   |
                 |                               |
                 +-------------------------------+
                        /                \
                       /                  \
                      /                    \
                     /                      \
   Outer Header     v                        v  Plaintext
+-+-+---+--------+---------------+          +-------+
|v|t|TKL|new code| Message ID    |          | code  |
+-+-+---+--------+---------------+....+     +-------+-----......+
| Token                               |     | Options (E)       |
+--------------------------------.....+     +-------+------.....+
| Options (IU)             |                | 0xFF  |
.                          .                +-------+-----------+
. OSCORE Option            .                |                   |
+------+-------------------+                | Payload           |
| 0xFF |                                    |                   |
+------+                                    +-------------------+

]]></artwork>
          </artset>
        </figure>
        <t><xref target="fig-inner-outer"/> shows the packet format for the OSCORE Outer header and Plaintext.</t>
        <t>In the Outer header, the original header code is hidden and replaced by a well-known value. As specified in Sections <xref target="RFC8613" section="4.1.3.5" sectionFormat="bare"/> and <xref target="RFC8613" section="4.2" sectionFormat="bare"/> of <xref target="RFC8613"/>, the original header code is replaced with POST for requests and Changed for responses, when the message does not include the Observe Option. Otherwise, the original header code is replaced with FETCH for requests and Content for responses.</t>
        <t>The first byte of the Plaintext contains the original header code, the class E options, and, if present, the original message payload preceded by the payload marker.</t>
        <t>After that, an Authenticated Encryption with Associated Data (AEAD) algorithm encrypts the Plaintext. This also integrity-protects the Security Context parameters and, if present, any class I options from the Outer header. The resulting ciphertext becomes the new payload of the OSCORE message, as illustrated in <xref target="fig-full-oscore"/>.</t>
        <t>As defined in <xref target="RFC5116"/>, this ciphertext is the encrypted Plaintext's concatenation with the Authentication Tag. Note that Inner Compression only affects the Plaintext before encryption. The Authentication Tag, fixed in length and uncompressed, is considered part of the cost of protection.</t>
        <figure anchor="fig-full-oscore">
          <name>OSCORE Message</name>
          <artwork align="center"><![CDATA[
   Outer Header
+-+-+---+--------+---------------+
|v|t|TKL|new code| Message ID    |
+-+-+---+--------+---------------+....+
| Token                               |
+--------------------------------.....+
| Options (IU)             |
.                          .
. OSCORE Option            .
+------+-------------------+
| 0xFF |
+------+---------------------------+
|                                  |
| Ciphertext: Encrypted Inner      |
|             Header and Payload   |
|             + Authentication Tag |
|                                  |
+----------------------------------+
]]></artwork>
        </figure>
        <t>The SCHC compression scheme consists of compressing both the Plaintext before encryption and the resulting OSCORE message after encryption, as shown in <xref target="fig-OSCORE-Compression"/>. Note that, since the recipient endpoint can only decrypt the Inner part of the message, that endpoint will also have to implement Inner SCHC Compression/Decompression.</t>
        <figure anchor="fig-OSCORE-Compression">
          <name>OSCORE Compression Diagram</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="592" width="576" viewBox="0 0 576 592" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
                <path d="M 8,48 L 8,136" fill="none" stroke="black"/>
                <path d="M 8,160 L 8,272" fill="none" stroke="black"/>
                <path d="M 24,48 L 24,80" fill="none" stroke="black"/>
                <path d="M 24,336 L 24,384" fill="none" stroke="black"/>
                <path d="M 24,448 L 24,576" fill="none" stroke="black"/>
                <path d="M 40,48 L 40,80" fill="none" stroke="black"/>
                <path d="M 64,176 L 64,208" fill="none" stroke="black"/>
                <path d="M 72,48 L 72,80" fill="none" stroke="black"/>
                <path d="M 72,280 L 72,328" fill="none" stroke="black"/>
                <path d="M 72,392 L 72,440" fill="none" stroke="black"/>
                <path d="M 104,448 L 104,480" fill="none" stroke="black"/>
                <path d="M 144,48 L 144,80" fill="none" stroke="black"/>
                <path d="M 168,208 L 168,272" fill="none" stroke="black"/>
                <path d="M 168,336 L 168,384" fill="none" stroke="black"/>
                <path d="M 208,480 L 208,576" fill="none" stroke="black"/>
                <path d="M 224,160 L 224,176" fill="none" stroke="black"/>
                <path d="M 232,448 L 232,480" fill="none" stroke="black"/>
                <path d="M 256,240 L 256,440" fill="none" stroke="black"/>
                <path d="M 272,48 L 272,80" fill="none" stroke="black"/>
                <path d="M 312,80 L 312,112" fill="none" stroke="black"/>
                <path d="M 336,448 L 336,480" fill="none" stroke="black"/>
                <path d="M 376,48 L 376,208" fill="none" stroke="black"/>
                <path d="M 376,272 L 376,320" fill="none" stroke="black"/>
                <path d="M 392,384 L 392,512" fill="none" stroke="black"/>
                <path d="M 440,48 L 440,80" fill="none" stroke="black"/>
                <path d="M 440,112 L 440,144" fill="none" stroke="black"/>
                <path d="M 440,216 L 440,264" fill="none" stroke="black"/>
                <path d="M 440,328 L 440,376" fill="none" stroke="black"/>
                <path d="M 480,384 L 480,416" fill="none" stroke="black"/>
                <path d="M 520,272 L 520,320" fill="none" stroke="black"/>
                <path d="M 552,80 L 552,112" fill="none" stroke="black"/>
                <path d="M 552,144 L 552,208" fill="none" stroke="black"/>
                <path d="M 568,416 L 568,512" fill="none" stroke="black"/>
                <path d="M 8,48 L 272,48" fill="none" stroke="black"/>
                <path d="M 376,48 L 440,48" fill="none" stroke="black"/>
                <path d="M 8,80 L 280,80" fill="none" stroke="black"/>
                <path d="M 376,80 L 504,80" fill="none" stroke="black"/>
                <path d="M 8,112 L 272,112" fill="none" stroke="black"/>
                <path d="M 376,112 L 512,112" fill="none" stroke="black"/>
                <path d="M 376,144 L 552,144" fill="none" stroke="black"/>
                <path d="M 8,176 L 224,176" fill="none" stroke="black"/>
                <path d="M 8,208 L 168,208" fill="none" stroke="black"/>
                <path d="M 376,208 L 552,208" fill="none" stroke="black"/>
                <path d="M 176,240 L 256,240" fill="none" stroke="black"/>
                <path d="M 8,272 L 168,272" fill="none" stroke="black"/>
                <path d="M 376,272 L 520,272" fill="none" stroke="black"/>
                <path d="M 376,320 L 520,320" fill="none" stroke="black"/>
                <path d="M 24,336 L 168,336" fill="none" stroke="black"/>
                <path d="M 24,384 L 168,384" fill="none" stroke="black"/>
                <path d="M 392,384 L 480,384" fill="none" stroke="black"/>
                <path d="M 392,416 L 568,416" fill="none" stroke="black"/>
                <path d="M 24,448 L 104,448" fill="none" stroke="black"/>
                <path d="M 232,448 L 336,448" fill="none" stroke="black"/>
                <path d="M 392,448 L 568,448" fill="none" stroke="black"/>
                <path d="M 344,464 L 384,464" fill="none" stroke="black"/>
                <path d="M 24,480 L 208,480" fill="none" stroke="black"/>
                <path d="M 232,480 L 336,480" fill="none" stroke="black"/>
                <path d="M 24,512 L 208,512" fill="none" stroke="black"/>
                <path d="M 392,512 L 568,512" fill="none" stroke="black"/>
                <path d="M 24,576 L 208,576" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="448,376 436,370.4 436,381.6" fill="black" transform="rotate(90,440,376)"/>
                <polygon class="arrowhead" points="448,264 436,258.4 436,269.6" fill="black" transform="rotate(90,440,264)"/>
                <polygon class="arrowhead" points="352,464 340,458.4 340,469.6" fill="black" transform="rotate(180,344,464)"/>
                <polygon class="arrowhead" points="184,240 172,234.4 172,245.6" fill="black" transform="rotate(180,176,240)"/>
                <polygon class="arrowhead" points="80,440 68,434.4 68,445.6" fill="black" transform="rotate(90,72,440)"/>
                <polygon class="arrowhead" points="80,328 68,322.4 68,333.6" fill="black" transform="rotate(90,72,328)"/>
                <g class="text">
                  <text x="48" y="36">Outer</text>
                  <text x="104" y="36">Message</text>
                  <text x="404" y="36">OSCORE</text>
                  <text x="472" y="36">Plaintext</text>
                  <text x="16" y="68">v</text>
                  <text x="32" y="68">t</text>
                  <text x="56" y="68">TKL</text>
                  <text x="88" y="68">new</text>
                  <text x="124" y="68">code</text>
                  <text x="184" y="68">Message</text>
                  <text x="228" y="68">ID</text>
                  <text x="404" y="68">code</text>
                  <text x="296" y="84">...</text>
                  <text x="528" y="84">.....</text>
                  <text x="40" y="100">Token</text>
                  <text x="416" y="100">Options</text>
                  <text x="464" y="100">(E)</text>
                  <text x="292" y="116">....</text>
                  <text x="532" y="116">....</text>
                  <text x="48" y="132">Options</text>
                  <text x="100" y="132">(IU)</text>
                  <text x="224" y="132">|</text>
                  <text x="404" y="132">OxFF</text>
                  <text x="8" y="148">.</text>
                  <text x="224" y="148">.</text>
                  <text x="44" y="164">OSCORE</text>
                  <text x="100" y="164">Option</text>
                  <text x="416" y="180">Payload</text>
                  <text x="36" y="196">0xFF</text>
                  <text x="60" y="244">Ciphertext</text>
                  <text x="424" y="292">Inner</text>
                  <text x="468" y="292">SCHC</text>
                  <text x="448" y="308">Compression</text>
                  <text x="72" y="356">Outer</text>
                  <text x="116" y="356">SCHC</text>
                  <text x="96" y="372">Compression</text>
                  <text x="428" y="404">RuleID</text>
                  <text x="448" y="436">Compression</text>
                  <text x="528" y="436">Residue</text>
                  <text x="64" y="468">RuleID'</text>
                  <text x="284" y="468">Encryption</text>
                  <text x="432" y="484">Payload</text>
                  <text x="80" y="500">Compression</text>
                  <text x="164" y="500">Residue'</text>
                  <text x="76" y="548">Ciphertext</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
   Outer Message                               OSCORE Plaintext
+-+-+---+--------+---------------+            +-------+
|v|t|TKL|new code| Message ID    |            | code  |
+-+-+---+--------+---------------+....+       +-------+-------......+
| Token                               |       | Options (E)         |
+--------------------------------.....+       +-------+--------.....+
| Options (IU)             |                  | OxFF  |
.                          .                  +-------+-------------+
. OSCORE Option            .                  |                     |
+------+-------------------+                  | Payload             |
| 0xFF |                                      |                     |
+------+------------+                         +---------------------+
|                   |                                 |
| Ciphertext        |<---------+                      |
|                   |          |                      v
+-------------------+          |              +-----------------+
        |                      |              |   Inner SCHC    |
        |                      |              |   Compression   |
        v                      |              +-----------------+
  +-----------------+          |                      |
  |   Outer SCHC    |          |                      |
  |   Compression   |          |                      v
  +-----------------+          |                +----------+
        |                      |                | RuleID   |
        |                      |                +----------+----------+
        v                      |                | Compression Residue |
  +---------+               +------------+      +---------------------+
  | RuleID' |               | Encryption |<-----|                     |
  +---------+------------+  +------------+      | Payload             |
  | Compression Residue' |                      |                     |
  +----------------------+                      +---------------------+
  |                      |
  | Ciphertext           |
  |                      |
  +----------------------+
]]></artwork>
          </artset>
        </figure>
        <t>The OSCORE message translates into a segmented process where SCHC compression is applied independently in two stages, each with its corresponding set of Rules, i.e., the Inner SCHC Rules and the Outer SCHC Rules. By doing so, compression is applied to all the fields of the original CoAP message.</t>
        <t>As to the compression of the 0xFF payload marker, the same rationale described in <xref target="payload-marker"/> applies to both the Inner SCHC Compression and the Outer SCHC Compression. That is:</t>
        <ul spacing="normal">
          <li>
            <t>After the Inner SCHC Compression of a CoAP message including a payload, the payload marker <bcp14>MUST NOT</bcp14> be included in the input to the AEAD Encryption, which is composed of the Inner Compression RuleID, the Inner Compression Residue (if any), and the CoAP payload.</t>
          </li>
          <li>
            <t>The Outer SCHC Compression takes as input the OSCORE-protected message, which always includes a payload (i.e., the OSCORE Ciphertext) preceded by the payload marker.</t>
          </li>
          <li>
            <t>After the Outer SCHC Compression, the payload marker <bcp14>MUST NOT</bcp14> be included in the final compressed message, which is composed of the Outer Compression RuleID, the Outer Compression Residue (if any), and the OSCORE Ciphertext.</t>
          </li>
        </ul>
        <t>After having completed the Outer SCHC Decompression of an incoming message, the recipient endpoint <bcp14>MUST</bcp14> prepend the 0xFF payload marker to the OSCORE Ciphertext.</t>
        <t>After having completed the Inner SCHC Decompression of an incoming message, the recipient endpoint <bcp14>MUST</bcp14> prepend the 0xFF payload marker to the CoAP payload, if any was present after the consumed Compression Residue.</t>
      </section>
      <section anchor="example-oscore-compression">
        <name>Example OSCORE Compression</name>
        <t>This section provides an example with a GET request and a corresponding Content response, exchanged between a Device-based CoAP client and a cloud-based CoAP server. The example also describes a possible set of Rules for Inner SCHC Compression and Outer SCHC Compression. A dump of the results and a contrast between SCHC + OSCORE performance and SCHC + CoAP performance are also listed. This example shows an estimate of the cost of security with SCHC-OSCORE.</t>
        <t>Our first CoAP message is the GET request in <xref target="fig-GET-temp"/>.</t>
        <figure anchor="fig-GET-temp">
          <name>CoAP GET Request</name>
          <artwork><![CDATA[
Original message:
=================
0x4101000182bb74656d7065726174757265

Header:
0x4101
01   Ver
  00   CON
    0001   TKL
        00000001   Request Code 1 "GET"

0x0001 = mid
0x82 = token

Options:

0xbb74656d7065726174757265
Option 11: Uri-Path
Value = temperature

Original message length: 17 bytes
]]></artwork>
        </figure>
        <t>Its corresponding response is the Content response in <xref target="fig-CONTENT-temp"/>.</t>
        <figure anchor="fig-CONTENT-temp">
          <name>CoAP Content Response</name>
          <artwork><![CDATA[
Original message:
=================
0x6145000182ff32332043

Header:
0x6145
01   Ver
  10   ACK
    0001   TKL
        01000101 Successful Response Code 69 "2.05 Content"

0x0001 = mid
0x82 = token

0xFF  Payload marker

Payload:
0x32332043

Original message length: 10 bytes
]]></artwork>
        </figure>
        <t>The SCHC Rules for the Inner Compression include all the fields present in a regular CoAP message. The methods described in <xref target="sec-coap-fields-compression"/> apply to these fields. Table 4 provides an example.</t>
        <artwork><![CDATA[
 +----------+
 | RuleID 0 |
 +----------+
]]></artwork>
        <table align="center" anchor="_table-Inner-Rules">
          <name>Inner SCHC Rule</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[69, 132]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">C</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Path</td>
              <td align="left"> </td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"temperature"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t><xref target="fig-Inner-Compression-GET"/> shows the Plaintext obtained for the example GET request. The packet follows the process of Inner Compression and encryption until the payload. The Outer OSCORE message adds the result of the Inner process.</t>
        <figure anchor="fig-Inner-Compression-GET">
          <name>Plaintext Compression and Encryption for GET Request</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="656" width="432" viewBox="0 0 432 656" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
                <path d="M 8,32 L 8,208" fill="none" stroke="black"/>
                <path d="M 48,528 L 48,640" fill="none" stroke="black"/>
                <path d="M 120,288 L 120,432" fill="none" stroke="black"/>
                <path d="M 232,216 L 232,280" fill="none" stroke="black"/>
                <path d="M 232,440 L 232,520" fill="none" stroke="black"/>
                <path d="M 336,288 L 336,432" fill="none" stroke="black"/>
                <path d="M 424,32 L 424,208" fill="none" stroke="black"/>
                <path d="M 424,528 L 424,640" fill="none" stroke="black"/>
                <path d="M 8,32 L 424,32" fill="none" stroke="black"/>
                <path d="M 8,208 L 424,208" fill="none" stroke="black"/>
                <path d="M 120,288 L 336,288" fill="none" stroke="black"/>
                <path d="M 120,432 L 336,432" fill="none" stroke="black"/>
                <path d="M 48,528 L 424,528" fill="none" stroke="black"/>
                <path d="M 48,640 L 424,640" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="240,520 228,514.4 228,525.6" fill="black" transform="rotate(90,232,520)"/>
                <polygon class="arrowhead" points="240,280 228,274.4 228,285.6" fill="black" transform="rotate(90,232,280)"/>
                <g class="text">
                  <text x="44" y="68">OSCORE</text>
                  <text x="112" y="68">Plaintext</text>
                  <text x="132" y="100">0x01bb74656d7065726174757265</text>
                  <text x="272" y="100">(13</text>
                  <text x="316" y="100">bytes)</text>
                  <text x="36" y="132">0x01</text>
                  <text x="88" y="132">Request</text>
                  <text x="140" y="132">Code</text>
                  <text x="176" y="132">GET</text>
                  <text x="156" y="164">bb74656d7065726174757265</text>
                  <text x="284" y="164">Option</text>
                  <text x="328" y="164">11:</text>
                  <text x="380" y="164">Uri-Path</text>
                  <text x="280" y="180">Value</text>
                  <text x="312" y="180">=</text>
                  <text x="368" y="180">temperature</text>
                  <text x="264" y="244">Inner</text>
                  <text x="308" y="244">SCHC</text>
                  <text x="376" y="244">Compression</text>
                  <text x="172" y="324">Compressed</text>
                  <text x="256" y="324">Plaintext</text>
                  <text x="148" y="356">0x00</text>
                  <text x="156" y="388">RuleID</text>
                  <text x="192" y="388">=</text>
                  <text x="220" y="388">0x00</text>
                  <text x="252" y="388">(1</text>
                  <text x="288" y="388">byte)</text>
                  <text x="144" y="404">(No</text>
                  <text x="208" y="404">Compression</text>
                  <text x="292" y="404">Residue)</text>
                  <text x="260" y="468">AEAD</text>
                  <text x="324" y="468">Encryption</text>
                  <text x="268" y="484">(piv</text>
                  <text x="296" y="484">=</text>
                  <text x="328" y="484">0x04)</text>
                  <text x="144" y="564">encrypted_plaintext</text>
                  <text x="232" y="564">=</text>
                  <text x="260" y="564">0xa2</text>
                  <text x="292" y="564">(1</text>
                  <text x="328" y="564">byte)</text>
                  <text x="80" y="580">tag</text>
                  <text x="104" y="580">=</text>
                  <text x="188" y="580">0xc54fe1b434297b62</text>
                  <text x="276" y="580">(8</text>
                  <text x="316" y="580">bytes)</text>
                  <text x="108" y="612">ciphertext</text>
                  <text x="160" y="612">=</text>
                  <text x="252" y="612">0xa2c54fe1b434297b62</text>
                  <text x="348" y="612">(9</text>
                  <text x="388" y="612">bytes)</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
+---------------------------------------------------+
|                                                   |
| OSCORE Plaintext                                  |
|                                                   |
| 0x01bb74656d7065726174757265  (13 bytes)          |
|                                                   |
| 0x01 Request Code GET                             |
|                                                   |
|      bb74656d7065726174757265 Option 11: Uri-Path |
|                               Value = temperature |
|                                                   |
+---------------------------------------------------+
                            |
                            | Inner SCHC Compression
                            |
                            v
              +--------------------------+
              |                          |
              | Compressed Plaintext     |
              |                          |
              | 0x00                     |
              |                          |
              | RuleID = 0x00 (1 byte)   |
              | (No Compression Residue) |
              |                          |
              +--------------------------+
                            |
                            | AEAD Encryption
                            |  (piv = 0x04)
                            |
                            v
     +----------------------------------------------+
     |                                              |
     |  encrypted_plaintext = 0xa2 (1 byte)         |
     |  tag = 0xc54fe1b434297b62 (8 bytes)          |
     |                                              |
     |  ciphertext = 0xa2c54fe1b434297b62 (9 bytes) |
     |                                              |
     +----------------------------------------------+
]]></artwork>
          </artset>
        </figure>
        <t>In this case, the original message has no payload, and its resulting Plaintext is compressed up to only 1 byte (the size of the RuleID). The AEAD algorithm preserves this length in its first output and yields a fixed-size tag. SCHC cannot compress the tag, and the OSCORE message must include it without compression. The use of integrity protection translates into an overhead on the total message length, thus limiting the amount of compression that can be achieved and contributing to the cost of adding security to the exchange.</t>
        <t><xref target="fig-Inner-Compression-CONTENT"/> shows the process for the example Content response. The Compression Residue is 1 bit long. Note that since SCHC adds padding after the payload, this misalignment causes the hexadecimal code from the payload to differ from the original, even if SCHC cannot compress the tag. The overhead for the tag bytes limits SCHC's performance but adds security to the exchange.</t>
        <figure anchor="fig-Inner-Compression-CONTENT">
          <name>Plaintext Compression and Encryption for Content Response</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="720" width="488" viewBox="0 0 488 720" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
                <path d="M 8,32 L 8,224" fill="none" stroke="black"/>
                <path d="M 16,304 L 16,496" fill="none" stroke="black"/>
                <path d="M 16,592 L 16,704" fill="none" stroke="black"/>
                <path d="M 232,232 L 232,296" fill="none" stroke="black"/>
                <path d="M 232,504 L 232,584" fill="none" stroke="black"/>
                <path d="M 408,32 L 408,224" fill="none" stroke="black"/>
                <path d="M 408,304 L 408,496" fill="none" stroke="black"/>
                <path d="M 480,592 L 480,704" fill="none" stroke="black"/>
                <path d="M 8,32 L 408,32" fill="none" stroke="black"/>
                <path d="M 8,224 L 408,224" fill="none" stroke="black"/>
                <path d="M 16,304 L 408,304" fill="none" stroke="black"/>
                <path d="M 16,496 L 408,496" fill="none" stroke="black"/>
                <path d="M 16,592 L 480,592" fill="none" stroke="black"/>
                <path d="M 16,704 L 480,704" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="240,584 228,578.4 228,589.6" fill="black" transform="rotate(90,232,584)"/>
                <polygon class="arrowhead" points="240,296 228,290.4 228,301.6" fill="black" transform="rotate(90,232,296)"/>
                <g class="text">
                  <text x="44" y="68">OSCORE</text>
                  <text x="112" y="68">Plaintext</text>
                  <text x="76" y="100">0x45ff32332043</text>
                  <text x="156" y="100">(6</text>
                  <text x="196" y="100">bytes)</text>
                  <text x="36" y="132">0x45</text>
                  <text x="100" y="132">Successful</text>
                  <text x="180" y="132">Response</text>
                  <text x="236" y="132">Code</text>
                  <text x="268" y="132">69</text>
                  <text x="304" y="132">"2.05</text>
                  <text x="364" y="132">Content"</text>
                  <text x="60" y="164">ff</text>
                  <text x="104" y="164">Payload</text>
                  <text x="164" y="164">marker</text>
                  <text x="100" y="196">32332043</text>
                  <text x="168" y="196">Payload</text>
                  <text x="264" y="260">Inner</text>
                  <text x="308" y="260">SCHC</text>
                  <text x="376" y="260">Compression</text>
                  <text x="68" y="340">Compressed</text>
                  <text x="152" y="340">Plaintext</text>
                  <text x="84" y="372">0x001919902180</text>
                  <text x="156" y="372">(6</text>
                  <text x="196" y="372">bytes)</text>
                  <text x="52" y="404">00</text>
                  <text x="92" y="404">RuleID</text>
                  <text x="48" y="436">0b0</text>
                  <text x="76" y="436">(1</text>
                  <text x="104" y="436">bit</text>
                  <text x="176" y="436">match-mapping</text>
                  <text x="280" y="436">Compression</text>
                  <text x="364" y="436">Residue)</text>
                  <text x="116" y="452">0x32332043</text>
                  <text x="172" y="452">&gt;&gt;</text>
                  <text x="192" y="452">1</text>
                  <text x="236" y="452">(shifted</text>
                  <text x="308" y="452">payload)</text>
                  <text x="248" y="468">0b0000000</text>
                  <text x="320" y="468">Padding</text>
                  <text x="260" y="532">AEAD</text>
                  <text x="324" y="532">Encryption</text>
                  <text x="268" y="548">(piv</text>
                  <text x="296" y="548">=</text>
                  <text x="328" y="548">0x04)</text>
                  <text x="112" y="628">encrypted_plaintext</text>
                  <text x="200" y="628">=</text>
                  <text x="268" y="628">0x10c6d7c26cc1</text>
                  <text x="340" y="628">(6</text>
                  <text x="380" y="628">bytes)</text>
                  <text x="48" y="644">tag</text>
                  <text x="72" y="644">=</text>
                  <text x="156" y="644">0xe9aef3f2461e0c29</text>
                  <text x="244" y="644">(8</text>
                  <text x="284" y="644">bytes)</text>
                  <text x="76" y="676">ciphertext</text>
                  <text x="128" y="676">=</text>
                  <text x="260" y="676">0x10c6d7c26cc1e9aef3f2461e0c29</text>
                  <text x="400" y="676">(14</text>
                  <text x="444" y="676">bytes)</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
+-------------------------------------------------+
|                                                 |
| OSCORE Plaintext                                |
|                                                 |
| 0x45ff32332043  (6 bytes)                       |
|                                                 |
| 0x45 Successful Response Code 69 "2.05 Content" |
|                                                 |
|     ff Payload marker                           |
|                                                 |
|       32332043 Payload                          |
|                                                 |
+-------------------------------------------------+
                            |
                            | Inner SCHC Compression
                            |
                            v
 +------------------------------------------------+
 |                                                |
 | Compressed Plaintext                           |
 |                                                |
 | 0x001919902180 (6 bytes)                       |
 |                                                |
 |   00 RuleID                                    |
 |                                                |
 |  0b0 (1 bit match-mapping Compression Residue) |
 |       0x32332043 >> 1 (shifted payload)        |
 |                        0b0000000 Padding       |
 |                                                |
 +------------------------------------------------+
                            |
                            | AEAD Encryption
                            |  (piv = 0x04)
                            |
                            v
 +---------------------------------------------------------+
 |                                                         |
 |  encrypted_plaintext = 0x10c6d7c26cc1 (6 bytes)         |
 |  tag = 0xe9aef3f2461e0c29 (8 bytes)                     |
 |                                                         |
 |  ciphertext = 0x10c6d7c26cc1e9aef3f2461e0c29 (14 bytes) |
 |                                                         |
 +---------------------------------------------------------+
]]></artwork>
          </artset>
        </figure>
        <t>The Outer SCHC Rule shown in <xref target="_table-Outer-Rules"/> is used, also to process the OSCORE Option fields. <xref target="fig-Protected-Compressed-GET"/> and <xref target="fig-Protected-Compressed-CONTENT"/> show a dump of the OSCORE messages generated from the example messages, also including the Inner Compressed ciphertext in the payload. These are the messages that have to be compressed via the Outer SCHC Compression scheme.</t>
        <t><xref target="_table-Outer-Rules"/> shows a possible set of Outer Rule items to compress the Outer header.</t>
        <artwork><![CDATA[
+----------+
| RuleID 1 |
+----------+
]]></artwork>
        <table align="center" anchor="_table-Outer-Rules">
          <name>Outer SCHC Rule</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP <br/> Version</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">2</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> TKL</td>
              <td align="left">4</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">2</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">68</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> MID</td>
              <td align="left">16</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0000</td>
              <td align="left">MSB(12)</td>
              <td align="left">LSB</td>
              <td align="left">MMMM</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Token</td>
              <td align="left">tkl</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x80</td>
              <td align="left">MSB(5)</td>
              <td align="left">LSB</td>
              <td align="left">TTT</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_flags</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x09</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_piv</td>
              <td align="left">var <br/> (b)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x00</td>
              <td align="left">MSB(4)</td>
              <td align="left">LSB</td>
              <td align="left">PPPP</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kid</td>
              <td align="left">var <br/> (b)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x636c69 <br/> 656e70</td>
              <td align="left">MSB(44)</td>
              <td align="left">LSB</td>
              <td align="left">KKKK</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kidctx</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_x</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_nonce</td>
              <td align="left">osc.x.m</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_y</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_oldnonce</td>
              <td align="left">osc.y.w</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_flags</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_piv</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kid</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not- <br/> sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <figure anchor="fig-Protected-Compressed-GET">
          <name>Protected and Inner SCHC Compressed GET Request</name>
          <artwork align="center"><![CDATA[
Protected message:
==================
0x4102000182980904636c69656e74ffa2c54fe1b434297b62
(24 bytes)

Header:
0x4102
01   Ver
  00   CON
    0001   TKL
        00000010   Request Code 2 "POST"

0x0001 = mid
0x82 = token

Options:

0x98 0904636c69656e74 (9 bytes)
Option 9: OSCORE
Value = 0x0904636c69656e74
          09 = 000 0 1 001 flag byte
                   h k  n
            04 piv
              636c69656e74 kid

0xFF  Payload marker

Payload:
0xa2c54fe1b434297b62 (9 bytes)
]]></artwork>
        </figure>
        <figure anchor="fig-Protected-Compressed-CONTENT">
          <name>Protected and Inner SCHC Compressed Content Response</name>
          <artwork align="center"><![CDATA[
Protected message:
==================
0x614400018290ff10c6d7c26cc1e9aef3f2461e0c29
(21 bytes)

Header:
0x6144
01   Ver
  10   ACK
    0001   TKL
        01000100   Successful Response Code 68 "2.04 Changed"

0x0001 = mid
0x82 = token

Options:

0x90 (1 byte)
Option 9: OSCORE
Value = b''

0xFF  Payload marker

Payload:
0x10c6d7c26cc1e9aef3f2461e0c29 (14 bytes)
]]></artwork>
        </figure>
        <t>For the flag bits, some SCHC compression methods are useful, depending on the application. The most straightforward alternative is to provide a fixed value for the flags, combining an "equal" MO and a "not-sent" CDA. This SCHC description saves most bits but could prevent flexibility. Otherwise, SCHC could use a "match-mapping" MO to choose from several configurations for the exchange. If not, the SCHC description may use an MSB MO to mask off the three hard-coded most significant bits.</t>
        <t>Note that fixing a flag bit will limit the possible OSCORE options that can be used in the exchange, since the value of the flag bits plays a role in determining a specific OSCORE option.</t>
        <t>The piv field lends itself to having some bits masked off with an MSB MO and an LSB CDA. This SCHC description could be useful in applications where the message transmission frequency is low, such as with LPWAN technologies. Note that compressing the piv field may reduce the maximum number of sequence numbers that can be used in an exchange. Once the sequence number exceeds the maximum value, the OSCORE keys need to be re-established.</t>
        <t>The size, s, that is included in the OSCORE_kidctx field <bcp14>MAY</bcp14> be masked off with an LSB CDA. The rest of the OSCORE_kidctx field could have additional bits masked off, or the whole field could be fixed in accordance with an "equal" MO and a "not-sent" CDA. The same holds for the OSCORE_kid field.</t>
        <t>The Outer Rule of <xref target="_table-Outer-Rules"/> is applied to the example GET request and Content response. <xref target="fig-Compressed-GET"/> and <xref target="fig-Compressed-CONTENT"/> show the resulting messages.</t>
        <figure anchor="fig-Compressed-GET">
          <name>SCHC-OSCORE Compressed GET Request</name>
          <artwork><![CDATA[
Compressed message:
==================
0x01148889458a9fc3686852f6c4 (13 bytes)
0x01 RuleID
    148889 compression residue
          458a9fc3686852f6c4 padded payload

Compression Residue:
0b 0001 010
    mid tkn

   0100 0100
         piv (residue size and residue)

   0100 0100
         kid (residue size and residue)

   (23 bits -> 3 bytes with padding)

Payload
0xa2c54fe1b434297b62 (9 bytes)

Compressed message length: 13 bytes
]]></artwork>
        </figure>
        <figure anchor="fig-Compressed-CONTENT">
          <name>SCHC-OSCORE Compressed Content Response</name>
          <artwork><![CDATA[
Compressed message:
==================
0x0114218daf84d983d35de7e48c3c1852 (16 bytes)
0x01 RuleID
    14 Compression Residue
      218daf84d983d35de7e48c3c1852 Padded payload

Compression Residue:
0b0001 010 (7 bits -> 1 byte with padding)
   mid tkn

Payload
0x10c6d7c26cc1e9aef3f2461e0c29 (14 bytes)
]]></artwork>
        </figure>
        <t>In contrast, the following compares these results with what would be obtained by SCHC compressing the original CoAP messages without protecting them with OSCORE, according to the SCHC Rule in <xref target="_table-NoOsc-Rules"/>.</t>
        <artwork><![CDATA[
+----------+
| RuleID 2 |
+----------+
]]></artwork>
        <table align="center" anchor="_table-NoOsc-Rules">
          <name>SCHC-CoAP Rule (No OSCORE)</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP <br/> Version</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">2</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> TKL</td>
              <td align="left">4</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">2</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[69, 132]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">C</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> MID</td>
              <td align="left">16</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0000</td>
              <td align="left">MSB(12)</td>
              <td align="left">LSB</td>
              <td align="left">MMMM</td>
            </tr>
            <tr>
              <td align="left">CoAP Token</td>
              <td align="left">tkl</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x80</td>
              <td align="left">MSB(5)</td>
              <td align="left">LSB</td>
              <td align="left">TTT</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Path</td>
              <td align="left"> </td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"temperature"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t>The Rule in <xref target="_table-NoOsc-Rules"/> yields the SCHC compression results shown in <xref target="fig-GET-temp-no-oscore"/> for the request and in <xref target="fig-CONTENT-temp-no-oscore"/> for the response.</t>
        <figure anchor="fig-GET-temp-no-oscore">
          <name>CoAP GET Compressed without OSCORE</name>
          <artwork><![CDATA[
Compressed message:
==================
0x0214
0x02 = RuleID

Compression Residue:
0b00010100 (1 byte)

Compressed message length: 2 bytes
]]></artwork>
        </figure>
        <figure anchor="fig-CONTENT-temp-no-oscore">
          <name>CoAP Content Compressed without OSCORE</name>
          <artwork><![CDATA[
Compressed message:
==================
0x020a32332043
0x02 = RuleID

Compression Residue:
0b00001010 (1 byte)

Payload
0x32332043

Compressed message length: 6 bytes
]]></artwork>
        </figure>
        <t>As can be seen, the difference between applying SCHC + OSCORE as compared to regular SCHC + CoAP is about 10 bytes.</t>
      </section>
    </section>
    <section anchor="compression-with-proxies">
      <name>CoAP Header Compression with Proxies</name>
      <t>This section defines how SCHC Compression/Decompression is performed when CoAP proxies are deployed. The following refers to the origin client and origin server as application endpoints.</t>
      <t>Note that SCHC Compression/Decompression of CoAP headers is not necessarily used between each pair of hops in the communication chain. For example, if a proxy is deployed between an origin client and an origin server, SCHC might be used on the communication leg between the origin client and the proxy, but not on the communication leg between the proxy and the origin server.</t>
      <section anchor="compression-with-proxies-without-oscore">
        <name>Without End-to-End Security</name>
        <t>In case OSCORE is not used end-to-end between client and server, the SCHC processing occurs hop-by-hop, by relying on SCHC Rules that are consistently shared between two adjacent hops.</t>
        <t>In particular, SCHC is used as defined below.</t>
        <ul spacing="normal">
          <li>
            <t>The sender application endpoint compresses the CoAP message, by using the SCHC Rules that it shares with the next hop towards the recipient application endpoint. The resulting, compressed message is sent to the next hop towards the recipient application endpoint.</t>
          </li>
          <li>
            <t>Each proxy decompresses the incoming compressed message, by using the SCHC Rules that it shares with the (previous hop towards the) sender application endpoint.  </t>
            <t>
Then, the proxy compresses the CoAP message to be forwarded, by using the SCHC Rules that it shares with the (next hop towards the) recipient application endpoint.  </t>
            <t>
The resulting, compressed message is sent to the (next hop towards the) recipient application endpoint.</t>
          </li>
          <li>
            <t>The recipient application endpoint decompresses the incoming compressed message, by using the SCHC Rules that it shares with the previous hop towards the sender application endpoint.</t>
          </li>
        </ul>
      </section>
      <section anchor="compression-with-proxies-with-oscore">
        <name>With End-to-End Security</name>
        <t>In case OSCORE is used end-to-end between client and server (see <xref target="ssec-examples-oscore"/>), the following applies.</t>
        <t>The SCHC processing occurs end-to-end as to the Inner SCHC Compression/Decompression, by relying on Inner SCHC Rules that are consistently shared between the two application endpoints acting as OSCORE endpoints and sharing the used OSCORE Security Context.</t>
        <t>Instead, the SCHC processing occurs hop-by-hop as to the Outer SCHC Compression/Decompression, by relying on Outer SCHC Rules that are consistently shared between two adjacent hops.</t>
        <t>In particular, SCHC is used as defined below.</t>
        <ul spacing="normal">
          <li>
            <t>The sender application endpoint performs the Inner SCHC Compression on the original CoAP message, by using the Inner SCHC Rules that it shares with the recipient application endpoint.  </t>
            <t>
Following the AEAD Encryption of the compressed input obtained from the previous step, the sender application endpoint performs the Outer SCHC Compression on the resulting OSCORE-protected message, by using the Outer SCHC Rules that it shares with the next hop towards the recipient application endpoint.  </t>
            <t>
The resulting, compressed message is sent to the next hop towards the recipient application endpoint.</t>
          </li>
          <li>
            <t>Each proxy performs the Outer SCHC Decompression on the incoming compressed message, by using the SCHC Rules that it shares with the (previous hop towards the) sender application endpoint.  </t>
            <t>
Then, the proxy performs the Outer SCHC Compression of the OSCORE-protected message to be forwarded, by using the SCHC Rules that it shares with the (next hop towards the) recipient application endpoint.  </t>
            <t>
The resulting, compressed message is sent to the (next hop towards the) recipient application endpoint.</t>
          </li>
          <li>
            <t>The recipient application endpoint performs the Outer SCHC Decompression on the incoming compressed message, by using the Outer SCHC Rules that it shares with the previous hop towards the sender application endpoint.  </t>
            <t>
Then, the recipient application endpoint performs the AEAD Decryption of the OSCORE-protected message obtained from the previous step.  </t>
            <t>
Finally, the recipient application endpoint performs the Inner SCHC Decompression on the compressed input obtained from the previous step, by using the Inner SCHC Rules that it shares with the sender application endpoint. The result is the original CoAP message produced by the sender application endpoint.</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="examples">
      <name>Examples of CoAP Header Compression with Proxies</name>
      <t>This section provides examples of SCHC Compression/Decompression in the presence of a CoAP proxy.</t>
      <t>The presented examples refer to the same deployment considered in <xref target="sec-applicability-to-coap"/>, including a Device communicating over LPWAN with a Network Gateway (NGW), which in turn communicates with an Application Server over the Internet. The Application Server and the Device exchange CoAP messages through the NGW.</t>
      <t>The following also applies in the presented examples.</t>
      <ul spacing="normal">
        <li>
          <t>CoAP request messages are sent only by the Device as targeting the Application Server (uplink traffic), which replies to the Device with corresponding CoAP response messages (downlink traffic). That is, the Device acts as CoAP client, while the Application Server acts as CoAP server.</t>
        </li>
        <li>
          <t>A CoAP proxy is co-located on the Network Gateway (NGW) deployed between the Application Server and the Device.</t>
        </li>
        <li>
          <t>SCHC is used also on the communication leg between the Application Server and the proxy.</t>
        </li>
      </ul>
      <t>Like in <xref target="sec-applicability-to-coap"/>, the presented examples focus on SCHC Compression/Decompression of CoAP headers, i.e., irrespective of possible SCHC Compression/Decompression applied to further protocol headers.</t>
      <t>The example in <xref target="examples-without-oscore"/> considers an exchange of two unprotected messages, while the example in <xref target="examples-with-oscore"/> considers an exchange of two messages protected end-to-end with OSCORE. In the examples, the character | denotes bit concatenation.</t>
      <t><xref target="fig-example-req"/> and <xref target="fig-example-resp"/> show the two CoAP messages exchanged between the Device and the Application Server, via the proxy. The figures show the two messages as originally generated by the application at the two origin endpoints, i.e., before they are possibly protected end-to-end with OSCORE as considered by the example in <xref target="examples-with-oscore"/>.</t>
      <t>In particular, note that:</t>
      <ul spacing="normal">
        <li>
          <t>On the communication leg between the Device and the proxy, the CoAP Message ID has value 0x0001 and the CoAP Token has value 0x82.</t>
        </li>
        <li>
          <t>On the communication leg between the proxy and the Application Server, the CoAP Message ID has value 0x0004 and the CoAP Token has value 0x75.</t>
        </li>
      </ul>
      <figure anchor="fig-example-req">
        <name>CoAP GET Request</name>
        <artwork align="left"><![CDATA[
Original message:
=================
0x41010001823b6578616d706c652e636f6d
  8b74656d7065726174757265d40f636f6170

Header:
0x4101
01   Ver
  00   CON
    0001   TKL
        00000001   Request Code 1 "GET"

0x0001 = mid
0x82 = token

Options:

0x3b6578616d706c652e636f6d
Option 3: Uri-Host
Value = example.com

0x8b74656d7065726174757265
Option 11: Uri-Path
Value = temperature

0xd40f636f6170
Option 39: Proxy-Scheme
Value = coap

Original message length: 35 bytes

]]></artwork>
      </figure>
      <figure anchor="fig-example-resp">
        <name>CoAP Content Response</name>
        <artwork align="left"><![CDATA[
Original message:
=================
0x6145000475ff32332043

Header:
0x6145
01   Ver
  10   ACK
    0001   TKL
        01000101 Successful Response Code 69 "2.05 Content"

0x0004 = mid
0x75 = token


0xFF Payload marker

Payload:
0x32332043

Original message length: 10 bytes

]]></artwork>
      </figure>
      <section anchor="examples-without-oscore">
        <name>Without End-to-End Security</name>
        <t>In case OSCORE is not used end-to-end between the Device and the Application Server, the following SCHC Rules are shared between the different entities. Based on those Rules, the SCHC Compression/Decompression is performed as per <xref target="compression-with-proxies-without-oscore"/>.</t>
        <t>The Device and the proxy share the SCHC Rule shown in <xref target="fig-rules-device-proxy"/>, with RuleID 0.</t>
        <artwork><![CDATA[
+----------+
| RuleID 0 |
+----------+
]]></artwork>
        <table align="center" anchor="fig-rules-device-proxy">
          <name>SCHC Rule between the Device and the Proxy</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP <br/> Version</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[0, 2]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">T</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> TKL</td>
              <td align="left">4</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">[1, 2, <br/> 3, 4]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">CC</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[65, 68, <br/> 69, 132]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">CC</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> MID</td>
              <td align="left">16</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x00</td>
              <td align="left">MSB(12)</td>
              <td align="left">LSB</td>
              <td align="left">MMMM</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Token</td>
              <td align="left">tkl</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x80</td>
              <td align="left">MSB(5)</td>
              <td align="left">LSB</td>
              <td align="left">TTT</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Host</td>
              <td align="left">var <br/> (B)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left"> </td>
              <td align="left">ignore</td>
              <td align="left">value- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Path</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"temperature"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Proxy-Scheme</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"coap"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t>Instead, the proxy and the Application Server share the SCHC Rule shown in <xref target="fig-rules-proxy-server"/>, with RuleID 1.</t>
        <artwork><![CDATA[
+----------+
| RuleID 1 |
+----------+
]]></artwork>
        <table align="center" anchor="fig-rules-proxy-server">
          <name>SCHC Rule between the Proxy and the Application Server</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP <br/> Version</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[0, 2]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">T</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> TKL</td>
              <td align="left">4</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">[1, 2, <br/> 3, 4]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">CC</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[65, 68, <br/> 69, 132]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">CC</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> MID</td>
              <td align="left">16</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x00</td>
              <td align="left">MSB(12)</td>
              <td align="left">LSB</td>
              <td align="left">MMMM</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Token</td>
              <td align="left">tkl</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x70</td>
              <td align="left">MSB(5)</td>
              <td align="left">LSB</td>
              <td align="left">TTT</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Host</td>
              <td align="left">var <br/> (B)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left"> </td>
              <td align="left">ignore</td>
              <td align="left">value- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Path</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"temperature"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t>First, the Device applies the Rule in <xref target="fig-rules-device-proxy"/> shared with the proxy to the CoAP request in <xref target="fig-example-req"/>. The result is the compressed CoAP request in <xref target="fig-example-req-to-proxy"/>, which the Device sends to the proxy.</t>
        <figure anchor="fig-example-req-to-proxy">
          <name>CoAP GET Request Compressed for the Proxy</name>
          <artwork align="left"><![CDATA[
Compressed message:
=================
0x00055b2bc30b6b836329731b7b68 (14 bytes)
0x00 RuleID
    055b2bc30b6b836329731b7b68 compression residue
                                and padded payload

Compression Residue (101 bits -> 13 bytes with padding)
0b   00 0001 010      1011  |  0x6578616d706c652e636f6d
   code  mid tkn  Uri-Host (residue size and residue)

Compressed message length: 14 bytes

]]></artwork>
        </figure>
        <t>Upon receiving the message in <xref target="fig-example-req-to-proxy"/>, the proxy decompresses it with the Rule in <xref target="fig-rules-device-proxy"/> shared with the Device, and obtains the same CoAP request in <xref target="fig-example-req"/>.</t>
        <t>After that, the proxy removes the Proxy-Scheme Option from the decompressed CoAP request. Also, the proxy replaces the values of the CoAP Message ID and of the CoAP Token to 0x0004 and 0x75, respectively. The result is the CoAP request shown in <xref target="fig-example-req-from-proxy"/>.</t>
        <figure anchor="fig-example-req-from-proxy">
          <name>CoAP GET Request to be Compressed by the Proxy</name>
          <artwork align="left"><![CDATA[
Message to forward:
=================
0x41010004753b6578616d706c652e636f6d
  8b74656d7065726174757265

Header:
0x4101
01   Ver
  00   CON
    0001   TKL
        00000001   Request Code 1 "GET"

0x0004 = mid
0x75 = token

Options:

0x3b6578616d706c652e636f6d
Option 3: Uri-Host
Value = example.com

0x8b74656d7065726174757265
Option 11: Uri-Path
Value = temperature

Original message length: 29 bytes

]]></artwork>
        </figure>
        <t>Then, the proxy applies the Rule in <xref target="fig-rules-proxy-server"/> shared with the Application Server to the CoAP request in <xref target="fig-example-req-from-proxy"/>.</t>
        <t>The result is the compressed CoAP request in <xref target="fig-example-req-from-proxy-compressed"/>, which the proxy forwards to the Application Server.</t>
        <figure anchor="fig-example-req-from-proxy-compressed">
          <name>CoAP GET Request Forwarded by the Proxy</name>
          <artwork align="left"><![CDATA[
Compressed message to forward:
=================
0x0112db2bc30b6b836329731b7b68 (14 bytes)
0x01 RuleID
    12db2bc30b6b836329731b7b68 compression residue
                                and padded payload


Compression Residue (101 bits -> 13 bytes with padding)
0b   00 0100 101      1011  |  0x6578616d706c652e636f6d
   code  mid tkn  Uri-Host (residue size and residue)

Compressed message length: 14 bytes

]]></artwork>
        </figure>
        <t>Upon receiving the message in <xref target="fig-example-req-from-proxy-compressed"/>, the Application Server decompresses it using the Rule in <xref target="fig-rules-proxy-server"/> shared with the proxy. The result is the same CoAP request in <xref target="fig-example-req-from-proxy"/>, which the Application Server delivers to the application.</t>
        <t>After that, the Application Server produces the CoAP response in <xref target="fig-example-resp"/>, and compresses it using the Rule in <xref target="fig-rules-proxy-server"/> shared with the proxy. The result is the compressed CoAP response shown in <xref target="fig-example-resp-to-proxy"/>, which the Application Server sends to the proxy.</t>
        <figure anchor="fig-example-resp-to-proxy">
          <name>CoAP Content Response Compressed for the Proxy</name>
          <artwork align="left"><![CDATA[
Compressed message:
=================
0x01c94c8cc810c0 (7 bytes)
0x01 RuleID
    c94c8cc810c0 compression residue
                 and padded payload


Compression Residue (10 bits -> 2 bytes with padding)
0b    1   10 0100 101
   type code  mid tkn

Payload
0x32332043 (4 bytes)

Compressed message length: 7 bytes

]]></artwork>
        </figure>
        <t>Upon receiving the message in <xref target="fig-example-resp-to-proxy"/>, the proxy decompresses it using the Rule in <xref target="fig-rules-proxy-server"/> shared with the Application Server. The result is the same CoAP response in <xref target="fig-example-resp"/>.</t>
        <t>Then, the proxy replaces the values of the CoAP Message ID and of the CoAP Token to 0x0001 and 0x82, respectively. The result is the CoAP response shown in <xref target="fig-example-resp-from-proxy"/>.</t>
        <figure anchor="fig-example-resp-from-proxy">
          <name>CoAP Content Response to be Compressed by the Proxy</name>
          <artwork align="left"><![CDATA[
Message to forward:
=================
0x6145000182ff32332043

Header:
0x6145
01   Ver
  10   ACK
    0001   TKL
        01000101 Successful Response Code 69 "2.05 Content"

0x0001 = mid
0x82 = token


0xFF Payload marker

Payload:
0x32332043

Original message length: 10 bytes

]]></artwork>
        </figure>
        <t>Then, the proxy compresses the CoAP response in <xref target="fig-example-resp-from-proxy"/> with the Rule in <xref target="fig-rules-device-proxy"/> shared with the Device. The result is the compressed CoAP response shown in <xref target="fig-example-resp-from-proxy-compressed"/>, which the proxy forwards to the Device.</t>
        <figure anchor="fig-example-resp-from-proxy-compressed">
          <name>CoAP Content Response Forwarded by the Proxy</name>
          <artwork align="left"><![CDATA[
Compressed message:
=================
0x00c28c8cc810c0 (7 bytes)
0x00 RuleID
    c28c8cc810c0 compression residue
                 and padded payload


Compression Residue (10 bits -> 2 bytes with padding)
0b    1   10 0001 010
   type code  mid tkn

Payload
0x32332043 (4 bytes)

Compressed message length: 7 bytes

]]></artwork>
        </figure>
        <t>Upon receiving the message in <xref target="fig-example-resp-from-proxy-compressed"/>, the Device decompresses it using the Rule in <xref target="fig-rules-device-proxy"/> shared with the proxy. The result is the same CoAP request in <xref target="fig-example-resp-from-proxy"/>, which the Device delivers to the application.</t>
      </section>
      <section anchor="examples-with-oscore">
        <name>With End-to-End Security</name>
        <t>In case OSCORE is used end-to-end between the Device and the Application Server, the following SCHC Rules are shared between the different entities. Based on those Rules, the SCHC Compression/Decompression is performed as per <xref target="compression-with-proxies-with-oscore"/>.</t>
        <t>The Device and the Application Server share the SCHC Rule shown in <xref target="fig-rules-oscore-device-server"/>, with RuleID 2. The Device and the Application Server use this Rule to perform the Inner SCHC Compression/Decompression end-to-end.</t>
        <artwork><![CDATA[
+----------+
| RuleID 2 |
+----------+
]]></artwork>
        <table align="center" anchor="fig-rules-oscore-device-server">
          <name>Inner SCHC Rule between the Device and the Application Server</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">[1, 2, <br/> 3, 4]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">CC</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[65, 68, <br/> 69, 132]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">CC</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Path</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"temperature"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t>The Device and the proxy share the SCHC Rule shown in <xref target="fig-rules-oscore-device-proxy"/>, with RuleID 3. The Device and the proxy use this Rule to perform the Outer SCHC Compression/Decompression hop-by-hop on their communication leg.</t>
        <artwork><![CDATA[
+----------+
| RuleID 3 |
+----------+
]]></artwork>
        <table align="center" anchor="fig-rules-oscore-device-proxy">
          <name>Outer SCHC Rule between the Device and the Proxy</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP <br/> Version</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[0, 2]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">T</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> TKL</td>
              <td align="left">4</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">2</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">68</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> MID</td>
              <td align="left">16</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x00</td>
              <td align="left">MSB(12)</td>
              <td align="left">LSB</td>
              <td align="left">MMMM</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Token</td>
              <td align="left">tkl</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x80</td>
              <td align="left">MSB(5)</td>
              <td align="left">LSB</td>
              <td align="left">TTT</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Host</td>
              <td align="left">var <br/> (B)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left"> </td>
              <td align="left">ignore</td>
              <td align="left">value- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_flags</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x09</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_piv</td>
              <td align="left">var <br/> (b)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x00</td>
              <td align="left">MSB(4)</td>
              <td align="left">LSB</td>
              <td align="left">PPPP</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kid</td>
              <td align="left">var <br/> (b)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x0000</td>
              <td align="left">MSB(12)</td>
              <td align="left">LSB</td>
              <td align="left">KKKK</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kidctx</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_x</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_nonce</td>
              <td align="left">osc.x.m</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_y</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_oldnonce</td>
              <td align="left">osc.y.w</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_flags</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_piv</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kid</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Proxy-Scheme</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">"coap"</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t>The proxy and the Application Server share the SCHC Rule shown in <xref target="fig-rules-oscore-proxy-server"/>, with RuleID 4. The proxy and the Application Server use this Rule to perform the Outer SCHC Compression/Decompression hop-by-hop on their communication leg.</t>
        <artwork><![CDATA[
 +----------+
 | RuleID 4 |
 +----------+
]]></artwork>
        <table align="center" anchor="fig-rules-oscore-proxy-server">
          <name>Outer SCHC Rule between the Proxy and the Application Server</name>
          <thead>
            <tr>
              <th align="left">Field</th>
              <th align="left">FL</th>
              <th align="left">FP</th>
              <th align="left">DI</th>
              <th align="left">TV</th>
              <th align="left">MO</th>
              <th align="left">CDA</th>
              <th align="left">Sent  [bits]</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">CoAP <br/> Version</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Type</td>
              <td align="left">2</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">[0, 2]</td>
              <td align="left">match- <br/> mapping</td>
              <td align="left">mapping- <br/> sent</td>
              <td align="left">T</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> TKL</td>
              <td align="left">4</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">1</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">2</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Code</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">68</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> MID</td>
              <td align="left">16</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x00</td>
              <td align="left">MSB(12)</td>
              <td align="left">LSB</td>
              <td align="left">MMMM</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Token</td>
              <td align="left">tkl</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">0x70</td>
              <td align="left">MSB(5)</td>
              <td align="left">LSB</td>
              <td align="left">TTT</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> Uri-Host</td>
              <td align="left">var <br/> (B)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left"> </td>
              <td align="left">ignore</td>
              <td align="left">value- <br/> sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_flags</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x09</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_piv</td>
              <td align="left">var <br/> (b)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x00</td>
              <td align="left">MSB(4)</td>
              <td align="left">LSB</td>
              <td align="left">PPPP</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kid</td>
              <td align="left">var <br/> (b)</td>
              <td align="left">1</td>
              <td align="left">Up</td>
              <td align="left">0x0000</td>
              <td align="left">MSB(12)</td>
              <td align="left">LSB</td>
              <td align="left">KKKK</td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kidctx</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_x</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_nonce</td>
              <td align="left">osc.x.m</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_y</td>
              <td align="left">8</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_oldnonce</td>
              <td align="left">osc.y.w</td>
              <td align="left">1</td>
              <td align="left">Bi</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_flags</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_piv</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">CoAP <br/> OSCORE_kid</td>
              <td align="left">var</td>
              <td align="left">1</td>
              <td align="left">Dw</td>
              <td align="left">b''</td>
              <td align="left">equal</td>
              <td align="left">not-sent</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t>When the Device applies the Rule in <xref target="fig-rules-oscore-device-server"/> shared with the Application Server to the CoAP request in <xref target="fig-example-req"/>, this results in the Compressed Plaintext shown in <xref target="fig-plaintext-req"/>.</t>
        <t>As per <xref target="ssec-examples-oscore"/>, the message follows the process of SCHC Inner Compression and encryption until the payload (if any). The ciphertext resulting from the overall Inner process is used as payload of the Outer OSCORE message.</t>
        <figure anchor="fig-plaintext-req">
          <name>Plaintext Compression and Encryption for the GET Request</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="784" width="448" viewBox="0 0 448 784" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
                <path d="M 8,32 L 8,208" fill="none" stroke="black"/>
                <path d="M 8,288 L 8,544" fill="none" stroke="black"/>
                <path d="M 8,640 L 8,752" fill="none" stroke="black"/>
                <path d="M 200,216 L 200,280" fill="none" stroke="black"/>
                <path d="M 200,552 L 200,632" fill="none" stroke="black"/>
                <path d="M 400,640 L 400,752" fill="none" stroke="black"/>
                <path d="M 408,288 L 408,544" fill="none" stroke="black"/>
                <path d="M 440,32 L 440,208" fill="none" stroke="black"/>
                <path d="M 8,32 L 440,32" fill="none" stroke="black"/>
                <path d="M 8,208 L 440,208" fill="none" stroke="black"/>
                <path d="M 8,288 L 408,288" fill="none" stroke="black"/>
                <path d="M 8,544 L 408,544" fill="none" stroke="black"/>
                <path d="M 8,640 L 400,640" fill="none" stroke="black"/>
                <path d="M 8,752 L 400,752" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="208,632 196,626.4 196,637.6" fill="black" transform="rotate(90,200,632)"/>
                <polygon class="arrowhead" points="208,280 196,274.4 196,285.6" fill="black" transform="rotate(90,200,280)"/>
                <g class="text">
                  <text x="44" y="68">OSCORE</text>
                  <text x="112" y="68">Plaintext</text>
                  <text x="132" y="100">0x01bb74656d7065726174757265</text>
                  <text x="272" y="100">(13</text>
                  <text x="316" y="100">bytes)</text>
                  <text x="36" y="132">0x01</text>
                  <text x="88" y="132">Request</text>
                  <text x="140" y="132">Code</text>
                  <text x="176" y="132">GET</text>
                  <text x="164" y="164">0xbb74656d7065726174757265</text>
                  <text x="300" y="164">Option</text>
                  <text x="344" y="164">11:</text>
                  <text x="396" y="164">Uri-Path</text>
                  <text x="296" y="180">Value</text>
                  <text x="328" y="180">=</text>
                  <text x="384" y="180">temperature</text>
                  <text x="232" y="244">Inner</text>
                  <text x="276" y="244">SCHC</text>
                  <text x="344" y="244">Compression</text>
                  <text x="60" y="324">Compressed</text>
                  <text x="144" y="324">Plaintext</text>
                  <text x="44" y="356">0x0200</text>
                  <text x="84" y="356">(2</text>
                  <text x="124" y="356">bytes)</text>
                  <text x="44" y="404">RuleID</text>
                  <text x="80" y="404">=</text>
                  <text x="108" y="404">0x02</text>
                  <text x="140" y="404">(1</text>
                  <text x="176" y="404">byte)</text>
                  <text x="64" y="452">Compression</text>
                  <text x="144" y="452">residue</text>
                  <text x="32" y="468">and</text>
                  <text x="76" y="468">padded</text>
                  <text x="136" y="468">payload</text>
                  <text x="176" y="468">=</text>
                  <text x="204" y="468">0x00</text>
                  <text x="236" y="468">(1</text>
                  <text x="272" y="468">byte)</text>
                  <text x="36" y="500">0b00</text>
                  <text x="68" y="500">(2</text>
                  <text x="100" y="500">bits</text>
                  <text x="176" y="500">match-mapping</text>
                  <text x="280" y="500">Compression</text>
                  <text x="364" y="500">Residue)</text>
                  <text x="52" y="516">0b000000</text>
                  <text x="100" y="516">(6</text>
                  <text x="128" y="516">bit</text>
                  <text x="180" y="516">padding)</text>
                  <text x="228" y="580">AEAD</text>
                  <text x="292" y="580">Encryption</text>
                  <text x="236" y="596">(piv</text>
                  <text x="264" y="596">=</text>
                  <text x="296" y="596">0x04)</text>
                  <text x="96" y="676">encrypted_plaintext</text>
                  <text x="184" y="676">=</text>
                  <text x="220" y="676">0xa2cf</text>
                  <text x="260" y="676">(2</text>
                  <text x="300" y="676">bytes)</text>
                  <text x="32" y="692">tag</text>
                  <text x="56" y="692">=</text>
                  <text x="140" y="692">0xc54fe1b434297b62</text>
                  <text x="228" y="692">(8</text>
                  <text x="268" y="692">bytes)</text>
                  <text x="60" y="724">ciphertext</text>
                  <text x="112" y="724">=</text>
                  <text x="212" y="724">0xa2cfc54fe1b434297b62</text>
                  <text x="320" y="724">(10</text>
                  <text x="364" y="724">bytes)</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
+-----------------------------------------------------+
|                                                     |
| OSCORE Plaintext                                    |
|                                                     |
| 0x01bb74656d7065726174757265  (13 bytes)            |
|                                                     |
| 0x01 Request Code GET                               |
|                                                     |
|      0xbb74656d7065726174757265 Option 11: Uri-Path |
|                                 Value = temperature |
|                                                     |
+-----------------------------------------------------+
                        |
                        | Inner SCHC Compression
                        |
                        v
+-------------------------------------------------+
|                                                 |
| Compressed Plaintext                            |
|                                                 |
| 0x0200 (2 bytes)                                |
|                                                 |
|                                                 |
| RuleID = 0x02 (1 byte)                          |
|                                                 |
|                                                 |
| Compression residue                             |
| and padded payload = 0x00 (1 byte)              |
|                                                 |
| 0b00 (2 bits match-mapping Compression Residue) |
| 0b000000 (6 bit padding)                        |
|                                                 |
+-------------------------------------------------+
                        |
                        | AEAD Encryption
                        |  (piv = 0x04)
                        |
                        v
+------------------------------------------------+
|                                                |
| encrypted_plaintext = 0xa2cf (2 bytes)         |
| tag = 0xc54fe1b434297b62 (8 bytes)             |
|                                                |
| ciphertext = 0xa2cfc54fe1b434297b62 (10 bytes) |
|                                                |
+------------------------------------------------+

]]></artwork>
          </artset>
        </figure>
        <t>When the Application Server applies the Rule in <xref target="fig-rules-oscore-device-server"/> shared with the Device to the CoAP response in <xref target="fig-example-resp"/>, this results in the Compressed Plaintext shown in <xref target="fig-plaintext-resp"/>.</t>
        <t>As per <xref target="ssec-examples-oscore"/>, the message follows the process of SCHC Inner Compression and encryption until the payload (if any). The ciphertext resulting from the overall Inner process is used as payload of the Outer OSCORE message.</t>
        <figure anchor="fig-plaintext-resp">
          <name>Plaintext Compression and Encryption for the Content Response</name>
          <artset>
            <artwork type="svg" align="center"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="816" width="480" viewBox="0 0 480 816" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px">
                <path d="M 8,32 L 8,224" fill="none" stroke="black"/>
                <path d="M 8,304 L 8,576" fill="none" stroke="black"/>
                <path d="M 8,672 L 8,784" fill="none" stroke="black"/>
                <path d="M 168,232 L 168,296" fill="none" stroke="black"/>
                <path d="M 168,584 L 168,664" fill="none" stroke="black"/>
                <path d="M 408,32 L 408,224" fill="none" stroke="black"/>
                <path d="M 408,304 L 408,576" fill="none" stroke="black"/>
                <path d="M 472,672 L 472,784" fill="none" stroke="black"/>
                <path d="M 8,32 L 408,32" fill="none" stroke="black"/>
                <path d="M 8,224 L 408,224" fill="none" stroke="black"/>
                <path d="M 8,304 L 408,304" fill="none" stroke="black"/>
                <path d="M 8,576 L 408,576" fill="none" stroke="black"/>
                <path d="M 8,672 L 472,672" fill="none" stroke="black"/>
                <path d="M 8,784 L 472,784" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="176,664 164,658.4 164,669.6" fill="black" transform="rotate(90,168,664)"/>
                <polygon class="arrowhead" points="176,296 164,290.4 164,301.6" fill="black" transform="rotate(90,168,296)"/>
                <g class="text">
                  <text x="44" y="68">OSCORE</text>
                  <text x="112" y="68">Plaintext</text>
                  <text x="76" y="100">0x45ff32332043</text>
                  <text x="156" y="100">(6</text>
                  <text x="196" y="100">bytes)</text>
                  <text x="36" y="132">0x45</text>
                  <text x="100" y="132">Successful</text>
                  <text x="180" y="132">Response</text>
                  <text x="236" y="132">Code</text>
                  <text x="268" y="132">69</text>
                  <text x="304" y="132">"2.05</text>
                  <text x="364" y="132">Content"</text>
                  <text x="68" y="164">0xff</text>
                  <text x="120" y="164">Payload</text>
                  <text x="180" y="164">marker</text>
                  <text x="124" y="196">0x32332043</text>
                  <text x="200" y="196">Payload</text>
                  <text x="200" y="260">Inner</text>
                  <text x="244" y="260">SCHC</text>
                  <text x="312" y="260">Compression</text>
                  <text x="60" y="340">Compressed</text>
                  <text x="144" y="340">Plaintext</text>
                  <text x="76" y="372">0x028c8cc810c0</text>
                  <text x="148" y="372">(6</text>
                  <text x="188" y="372">bytes)</text>
                  <text x="44" y="420">RuleID</text>
                  <text x="80" y="420">=</text>
                  <text x="108" y="420">0x02</text>
                  <text x="64" y="468">Compression</text>
                  <text x="144" y="468">residue</text>
                  <text x="32" y="484">and</text>
                  <text x="76" y="484">padded</text>
                  <text x="136" y="484">payload</text>
                  <text x="176" y="484">=</text>
                  <text x="236" y="484">0x8c8cc810c0</text>
                  <text x="300" y="484">(5</text>
                  <text x="340" y="484">bytes)</text>
                  <text x="36" y="516">0b10</text>
                  <text x="68" y="516">(2</text>
                  <text x="100" y="516">bits</text>
                  <text x="176" y="516">match-mapping</text>
                  <text x="280" y="516">Compression</text>
                  <text x="364" y="516">Residue)</text>
                  <text x="108" y="532">0x32332043</text>
                  <text x="164" y="532">&gt;&gt;</text>
                  <text x="184" y="532">2</text>
                  <text x="228" y="532">(shifted</text>
                  <text x="300" y="532">payload)</text>
                  <text x="236" y="548">0b000000</text>
                  <text x="304" y="548">Padding</text>
                  <text x="196" y="612">AEAD</text>
                  <text x="260" y="612">Encryption</text>
                  <text x="204" y="628">(piv</text>
                  <text x="232" y="628">=</text>
                  <text x="264" y="628">0x04)</text>
                  <text x="104" y="708">encrypted_plaintext</text>
                  <text x="192" y="708">=</text>
                  <text x="260" y="708">0x10c6d7c26cc1</text>
                  <text x="332" y="708">(6</text>
                  <text x="372" y="708">bytes)</text>
                  <text x="40" y="724">tag</text>
                  <text x="64" y="724">=</text>
                  <text x="148" y="724">0xe9aef3f2461e0c29</text>
                  <text x="236" y="724">(8</text>
                  <text x="276" y="724">bytes)</text>
                  <text x="68" y="756">ciphertext</text>
                  <text x="120" y="756">=</text>
                  <text x="252" y="756">0x10c6d7c26cc1e9aef3f2461e0c29</text>
                  <text x="392" y="756">(14</text>
                  <text x="436" y="756">bytes)</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="center"><![CDATA[
+-------------------------------------------------+
|                                                 |
| OSCORE Plaintext                                |
|                                                 |
| 0x45ff32332043  (6 bytes)                       |
|                                                 |
| 0x45 Successful Response Code 69 "2.05 Content" |
|                                                 |
|     0xff Payload marker                         |
|                                                 |
|         0x32332043 Payload                      |
|                                                 |
+-------------------------------------------------+
                    |
                    | Inner SCHC Compression
                    |
                    v
+-------------------------------------------------+
|                                                 |
| Compressed Plaintext                            |
|                                                 |
| 0x028c8cc810c0 (6 bytes)                        |
|                                                 |
|                                                 |
| RuleID = 0x02                                   |
|                                                 |
|                                                 |
| Compression residue                             |
| and padded payload = 0x8c8cc810c0 (5 bytes)     |
|                                                 |
| 0b10 (2 bits match-mapping Compression Residue) |
|       0x32332043 >> 2 (shifted payload)         |
|                        0b000000 Padding         |
|                                                 |
+-------------------------------------------------+
                    |
                    | AEAD Encryption
                    |  (piv = 0x04)
                    |
                    v
+---------------------------------------------------------+
|                                                         |
|  encrypted_plaintext = 0x10c6d7c26cc1 (6 bytes)         |
|  tag = 0xe9aef3f2461e0c29 (8 bytes)                     |
|                                                         |
|  ciphertext = 0x10c6d7c26cc1e9aef3f2461e0c29 (14 bytes) |
|                                                         |
+---------------------------------------------------------+

]]></artwork>
          </artset>
        </figure>
        <t>After having performed the SCHC Inner Compression of the CoAP request in <xref target="fig-example-req"/>, the Device protects it with OSCORE by considering the Compressed Plaintext in <xref target="fig-plaintext-req"/>. The result is the OSCORE-protected CoAP request shown in <xref target="fig-example-oscore-req"/>.</t>
        <figure anchor="fig-example-oscore-req">
          <name>Protected and Inner SCHC Compressed CoAP GET Request</name>
          <artwork align="left"><![CDATA[
Protected message:
==================
0x41020001823b6578616d706c652e636f6d
  6409040005d411636f6170ffa2cfc54fe1b434297b62
(39 bytes)

Header:
0x4102
01   Ver
  00   CON
    0001   TKL
        00000010   Request Code 2 "POST"

0x0001 = mid
0x82 = token

Options:

0x3b6578616d706c652e636f6d
Option 3: Uri-Host
Value = example.com

0x6409040005
Option 9: OSCORE
Value = 0x09040005
          09 = 000 0 1 001 flag byte
                   h k  n
            04 piv
              0005 kid

0xd411636f6170
Option 39: Proxy-Scheme
Value = coap


0xFF Payload marker

Payload:
0xa2cfc54fe1b434297b62 (10 bytes)

]]></artwork>
        </figure>
        <t>Then, the Device applies the Rule in <xref target="fig-rules-oscore-device-proxy"/> shared with the proxy to the OSCORE-protected CoAP request in <xref target="fig-example-oscore-req"/>, thus performing the SCHC Outer Compression of such request. The result is the OSCORE-protected and Outer Compressed CoAP request shown in <xref target="fig-example-oscore-req-to-proxy"/>, which the Device sends to the proxy.</t>
        <figure anchor="fig-example-oscore-req-to-proxy">
          <name>SCHC-OSCORE CoAP GET Request Compressed for the Proxy</name>
          <artwork align="left"><![CDATA[
Compressed message:
=================
0x03156caf0c2dae0d8ca5cc6deda888b459f8a9fc3686852f6c40 (26 bytes)
0x03 RuleID
    156caf0c2dae0d8ca5cc6deda888b459f8a9fc3686852f6c40 compression
                                                       residue and
                                                       padded payload


Compression Residue
0b 0001 010      1011  |  0x6578616d706c652e636f6d  |
    mid tkn  Uri-Host (residue size and residue)

0b 0100 0100
         piv (residue size and residue)

   0100 0101
         kid (residue size and residue)

   (115 bits -> 15 bytes with padding)

Payload
0xa2cfc54fe1b434297b62 (10 bytes)

Compressed message length: 26 bytes

]]></artwork>
        </figure>
        <t>Upon receiving the message in <xref target="fig-example-oscore-req-to-proxy"/>, the proxy decompresses it with the Rule in <xref target="fig-rules-oscore-device-proxy"/> shared with the Device, thus performing the SCHC Outer Decompression. The result is the same OSCORE-protected CoAP request in <xref target="fig-example-oscore-req"/>.</t>
        <t>After that, the proxy removes the Proxy-Scheme Option from the decompressed OSCORE-protected CoAP request. Also, the proxy replaces the values of the CoAP Message ID and of the CoAP Token to 0x0004 and 0x75, respectively. The result is the OSCORE-protected CoAP request shown in <xref target="fig-example-oscore-req-from-proxy"/>.</t>
        <figure anchor="fig-example-oscore-req-from-proxy">
          <name>SCHC-OSCORE CoAP GET Request to be Compressed by the Proxy</name>
          <artwork align="left"><![CDATA[
Protected message:
==================
0x41020004753b6578616d706c652e636f6d
  6409040005ffa2cfc54fe1b434297b62
(33 bytes)

Header:
0x4102
01   Ver
  00   CON
    0001   TKL
        00000010   Request Code 2 "POST"

0x0004 = mid
0x75 = token

Options:

0x3b6578616d706c652e636f6d
Option 3: Uri-Host
Value = example.com

0x6409040005
Option 9: OSCORE
Value = 0x09040005
          09 = 000 0 1 001 flag byte
                   h k  n
            04 piv
              0005 kid


0xFF Payload marker

Payload:
0xa2cfc54fe1b434297b62 (10 bytes)

]]></artwork>
        </figure>
        <t>Then, the proxy applies the Rule in <xref target="fig-rules-oscore-proxy-server"/> shared with the Application Server to the OSCORE-protected CoAP request in <xref target="fig-example-oscore-req-from-proxy"/>, thus performing the SCHC Outer Compression of such request. The result is the OSCORE-protected and Outer Compressed CoAP request shown in <xref target="fig-example-oscore-req-from-proxy-compressed"/>, which the proxy forwards to the Application Server.</t>
        <figure anchor="fig-example-oscore-req-from-proxy-compressed">
          <name>SCHC-OSCORE CoAP GET Request Forwarded by the Proxy</name>
          <artwork align="left"><![CDATA[
Compressed message:
=================
0x044b6caf0c2dae0d8ca5cc6deda888b459f8a9fc3686852f6c40 (26 bytes)
0x04 RuleID
    4b6caf0c2dae0d8ca5cc6deda888b459f8a9fc3686852f6c40 compression
                                                       residue and
                                                       padded payload


Compression Residue
0b 0100 101      1011  |  0x6578616d706c652e636f6d
    mid tkn  Uri-Host (residue size and residue)

0b 0100 0100
         piv (residue size and residue)

0b 0100 0101
         kid (residue size and residue)

   (115 bits -> 15 bytes with padding)


Payload
0xa2cfc54fe1b434297b62 (10 bytes)

Compressed message length: 26 bytes

]]></artwork>
        </figure>
        <t>Upon receiving the message in <xref target="fig-example-oscore-req-from-proxy-compressed"/>, the Application Server decompresses it using the Rule in <xref target="fig-rules-oscore-proxy-server"/> shared with the proxy, thus performing the SCHC Outer Decompression. The result is the same OSCORE-protected CoAP request in <xref target="fig-example-oscore-req-from-proxy"/>.</t>
        <t>The Application Server decrypts and verifies such a request, which results in the same Compressed Plaintext in <xref target="fig-plaintext-req"/>. Then, the Application Server applies the Rule in <xref target="fig-rules-oscore-device-server"/> shared with the Device to such a Compressed Plaintext, thus performing the SCHC Inner Decompression. The result is used to rebuild the same CoAP request in <xref target="fig-example-req"/>, which the Application Server delivers to the application.</t>
        <t>After having performed the SCHC Inner Compression of the CoAP response in <xref target="fig-example-resp"/>, the Application Server protects it with OSCORE by considering the Compressed Plaintext in <xref target="fig-plaintext-resp"/>. The result is the OSCORE-protected CoAP response shown in <xref target="fig-example-oscore-resp"/>.</t>
        <figure anchor="fig-example-oscore-resp">
          <name>Protected and Inner SCHC Compressed CoAP Content Response</name>
          <artwork align="left"><![CDATA[
Protected message:
==================
0x614400047590ff10c6d7c26cc1e9aef3f2461e0c29
(21 bytes)

Header:
0x6144
01   Ver
  10   ACK
    0001   TKL
        01000100   Successful Response Code 68 "2.04 Changed"

0x0004 = mid
0x75 = token

Options:

0x90
Option 9: OSCORE
Value = b''


0xFF Payload marker

Payload:
0x10c6d7c26cc1e9aef3f2461e0c29 (14 bytes)

]]></artwork>
        </figure>
        <t>Then, the Application Server applies the Rule in <xref target="fig-rules-oscore-proxy-server"/> shared with the proxy to the OSCORE-protected CoAP response in <xref target="fig-example-oscore-resp"/>, thus performing the SCHC Outer Compression of such response. The result is the OSCORE-protected and Outer Compressed CoAP response shown in <xref target="fig-example-oscore-resp-to-proxy"/>, which the Application Server sends to the proxy.</t>
        <figure anchor="fig-example-oscore-resp-to-proxy">
          <name>SCHC-OSCORE CoAP Content Response Compressed for the Proxy</name>
          <artwork align="left"><![CDATA[
Compressed message:
=================
0x04a510c6d7c26cc1e9aef3f2461e0c29  (16 bytes)
0x04 RuleID
    a510c6d7c26cc1e9aef3f2461e0c29 compression residue
                                   and padded payload


Compression Residue (8 bits -> 1 byte with padding)
0b    1 0100 101
   type  mid tkn

Payload
0x10c6d7c26cc1e9aef3f2461e0c29 (14 bytes)

Compressed message length: 16 bytes

]]></artwork>
        </figure>
        <t>Upon receiving the message in <xref target="fig-example-oscore-resp-to-proxy"/>, the proxy decompresses it with the Rule in <xref target="fig-rules-oscore-proxy-server"/> shared with the Application Server, thus performing the SCHC Outer Decompression. The result is the same OSCORE-protected CoAP response in <xref target="fig-example-oscore-resp"/>.</t>
        <t>After that, the proxy replaces the values of the CoAP Message ID and of the CoAP Token to 0x0001 and 0x82, respectively. The result is the OSCORE-protected CoAP response shown in <xref target="fig-example-oscore-resp-from-proxy"/>.</t>
        <figure anchor="fig-example-oscore-resp-from-proxy">
          <name>SCHC-OSCORE CoAP Content Response to be Compressed by the Proxy</name>
          <artwork align="left"><![CDATA[
Protected message:
==================
0x614400018290ff10c6d7c26cc1e9aef3f2461e0c29
(21 bytes)

Header:
0x6144
01   Ver
  10   ACK
    0001   TKL
        01000100   Successful Response Code 68 "2.04 Changed"

0x0001 = mid
0x82 = token

Options:

0x90
Option 9: OSCORE
Value = b''


0xFF Payload marker

Payload:
0x10c6d7c26cc1e9aef3f2461e0c29 (14 bytes)

]]></artwork>
        </figure>
        <t>Then, the proxy applies the Rule in <xref target="fig-rules-oscore-device-proxy"/> shared with the Device to the OSCORE-protected CoAP response in <xref target="fig-example-oscore-resp-from-proxy"/>, thus performing the SCHC Outer Compression of such response. The result is the OSCORE-protected and Outer Compressed CoAP response shown in <xref target="fig-example-oscore-resp-from-proxy-compressed"/>, which the proxy forwards to the Device.</t>
        <figure anchor="fig-example-oscore-resp-from-proxy-compressed">
          <name>SCHC-OSCORE CoAP Content Response Forwarded by the Proxy</name>
          <artwork align="left"><![CDATA[
Compressed message:
=================
0x038a10c6d7c26cc1e9aef3f2461e0c29 (16 bytes)
0x03 RuleID
    8a10c6d7c26cc1e9aef3f2461e0c29 compression residue
                                   and padded payload


Compression Residue (8 bits -> 1 byte with padding)
0b    1 0001 010
   type  mid tkn

Payload
0x10c6d7c26cc1e9aef3f2461e0c29 (14 bytes)

Compressed message length: 16 bytes

]]></artwork>
        </figure>
        <t>Upon receiving the message in <xref target="fig-example-oscore-resp-from-proxy-compressed"/>, the Device decompresses it using the Rule in <xref target="fig-rules-oscore-device-proxy"/> shared with the proxy, thus performing the SCHC Outer Decompression. The result is the same OSCORE-protected CoAP response in <xref target="fig-example-oscore-resp-from-proxy"/>.</t>
        <t>The Device decrypts and verifies such a response, which results in the same Compressed Plaintext in <xref target="fig-plaintext-resp"/>. Then, the Device applies the Rule in <xref target="fig-rules-oscore-device-server"/> shared with the Application Server to such a Compressed Plaintext, thus performing the SCHC Inner Decompression. The result is used to rebuild the same CoAP response in <xref target="fig-example-resp"/>, which the Device delivers to the application.</t>
      </section>
    </section>
    <section anchor="sec-coap-fields">
      <name>CoAP Fields</name>
      <t><xref target="_table-coap-fields"/> lists the CoAP fields and subfields for which SCHC Compression has been defined or revised in this document.</t>
      <table align="center" anchor="_table-coap-fields">
        <name>CoAP Fields</name>
        <thead>
          <tr>
            <th align="left">Field</th>
            <th align="left">Description</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">CoAP Version</td>
            <td align="left">CoAP header field Version <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Type</td>
            <td align="left">CoAP header field Type <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Token Length (TKL)</td>
            <td align="left">CoAP header field Token Length (TKL) <xref target="RFC7252"/><xref target="RFC8974"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Code</td>
            <td align="left">CoAP header field Code <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Code Class</td>
            <td align="left">CoAP header field Code (subfield Class) <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Code Detail</td>
            <td align="left">CoAP header field Code (subfield Detail) <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP MID</td>
            <td align="left">CoAP header field Message ID <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Token</td>
            <td align="left">CoAP field Token <xref target="RFC7252"/><xref target="RFC8974"/></td>
          </tr>
          <tr>
            <td align="left">CoAP If-Match</td>
            <td align="left">CoAP option If-Match <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Uri-Host</td>
            <td align="left">CoAP option Uri-Host <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP ETag</td>
            <td align="left">CoAP option ETag <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP If-None-Match</td>
            <td align="left">CoAP option If-None-Match <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Observe</td>
            <td align="left">CoAP option Observe <xref target="RFC7641"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Uri-Port</td>
            <td align="left">CoAP option Uri-Port <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Location-Path</td>
            <td align="left">CoAP option Location-Path <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE</td>
            <td align="left">CoAP option OSCORE <xref target="RFC8613"/><xref target="I-D.ietf-core-oscore-key-update"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE Flags</td>
            <td align="left">CoAP option OSCORE (subfield Flags) <xref target="RFC8613"/><xref target="I-D.ietf-core-oscore-key-update"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE PIV</td>
            <td align="left">CoAP option OSCORE (subfield PIV) <xref target="RFC8613"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE kid</td>
            <td align="left">CoAP option OSCORE (subfield kid) <xref target="RFC8613"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE kidctx</td>
            <td align="left">CoAP option OSCORE (subfield kid context) <xref target="RFC8613"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE x</td>
            <td align="left">CoAP option OSCORE (subfield x) <xref target="I-D.ietf-core-oscore-key-update"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE nonce</td>
            <td align="left">CoAP option OSCORE (subfield nonce) <xref target="I-D.ietf-core-oscore-key-update"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE y</td>
            <td align="left">CoAP option OSCORE (subfield y) <xref target="I-D.ietf-core-oscore-key-update"/></td>
          </tr>
          <tr>
            <td align="left">CoAP OSCORE old_nonce</td>
            <td align="left">CoAP option OSCORE (subfield old_nonce) <xref target="I-D.ietf-core-oscore-key-update"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Uri-Path</td>
            <td align="left">CoAP option Uri-Path <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Content-Format</td>
            <td align="left">CoAP option Content-Format <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Max-Age</td>
            <td align="left">CoAP option Max-Age <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Uri-Query</td>
            <td align="left">CoAP option Uri-Query <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Accept</td>
            <td align="left">CoAP option Accept <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Location-Query</td>
            <td align="left">CoAP option Location-Query <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Block2</td>
            <td align="left">CoAP option Block2 <xref target="RFC7959"/><xref target="RFC8323"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Block1</td>
            <td align="left">CoAP option Block1 <xref target="RFC7959"/><xref target="RFC8323"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Size2</td>
            <td align="left">CoAP option Size2 <xref target="RFC7959"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Proxy-Uri</td>
            <td align="left">CoAP option Proxy-Uri <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Proxy-Scheme</td>
            <td align="left">CoAP option Proxy-Scheme <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Size1</td>
            <td align="left">CoAP option Size1 <xref target="RFC7252"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Proxy-Cri</td>
            <td align="left">CoAP option Proxy-Cri <xref target="I-D.ietf-core-href"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Proxy-Scheme-Number</td>
            <td align="left">CoAP option Proxy-Scheme-Number <xref target="I-D.ietf-core-href"/></td>
          </tr>
          <tr>
            <td align="left">CoAP No-Response</td>
            <td align="left">CoAP option No-Response <xref target="RFC7967"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Hop-Limit</td>
            <td align="left">CoAP option Hop-Limit <xref target="RFC8768"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Echo</td>
            <td align="left">CoAP option Echo <xref target="RFC9175"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Request-Tag</td>
            <td align="left">CoAP option Request-Tag <xref target="RFC9175"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Q-Block1</td>
            <td align="left">CoAP option Q-Block1 <xref target="RFC9177"/></td>
          </tr>
          <tr>
            <td align="left">CoAP Q-Block2</td>
            <td align="left">CoAP option Q-Block2 <xref target="RFC9177"/></td>
          </tr>
          <tr>
            <td align="left">CoAP EDHOC</td>
            <td align="left">CoAP option EDHOC <xref target="I-D.ietf-core-oscore-edhoc"/></td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The use of SCHC header compression for CoAP header fields only affects the representation of the header information. SCHC header compression itself does not increase or decrease the overall level of security of the communication. When the connection does not use a security protocol (OSCORE, DTLS, etc.), it is necessary to use a Layer 2 security mechanism to protect the SCHC messages.</t>
      <t>If an LPWAN is the Layer 2 technology being used, the SCHC security considerations discussed in <xref target="RFC8724"/> continue to apply. When using another Layer 2 protocol, the use of a cryptographic integrity-protection mechanism to protect the SCHC headers is <bcp14>REQUIRED</bcp14>. Such cryptographic integrity protection is necessary in order to continue to provide the properties that <xref target="RFC8724"/> relies upon.</t>
      <t>When SCHC is used with OSCORE, the security considerations discussed in <xref target="RFC8613"/> continue to apply. When SCHC is used with Group OSCORE, the security considerations discussed in <xref target="I-D.ietf-core-oscore-groupcomm"/> apply. When SCHC is used in the presence of CoAP proxies, the security considerations discussed in <xref section="11.2" sectionFormat="of" target="RFC7252"/> continue to apply.</t>
      <t>When SCHC is used with the OSCORE Outer headers, the Initialization Vector (IV) size in the Compression Residue must be carefully selected. There is a trade-off between compression efficiency (with a longer MSB MO prefix) and the frequency at which the Device must renew its key material (in order to prevent the IV from expanding to an incompressible value). The key-renewal operation itself may require several message exchanges and result in energy-intensive computation, but the optimal trade-off will depend on the specifics of the Device and expected usage patterns. In order to renew its key material with another OSCORE endpoint, the Device can rely on the lightweight key update protocol KUDOS defined in <xref target="I-D.ietf-core-oscore-key-update"/>.</t>
      <t>If an attacker can introduce a corrupted SCHC-compressed packet onto a link, DoS attacks can be mounted by causing excessive resource consumption at the decompressor. However, an attacker able to inject packets at the link layer is also capable of other, potentially more damaging, attacks.</t>
      <t>SCHC compression emits variable-length Compression Residues for some CoAP fields. In the representation of the compressed header, the length field that is sent is not the length of the original header field but rather the length of the Compression Residue that is being transmitted. If a corrupted packet arrives at the decompressor with a longer or shorter length than that of the original compressed representation, the SCHC decompression procedures will detect an error and drop the packet.</t>
      <t>SCHC header compression Rules <bcp14>MUST</bcp14> remain tightly coupled between the compressor and the decompressor. If the compression Rules get out of sync, a Compression Residue might be decompressed differently at the receiver, thus yielding a result different than the initial message submitted to compression procedures. Accordingly, any time the context Rules are updated on an OSCORE endpoint, that endpoint <bcp14>MUST</bcp14> trigger OSCORE key re-establishment, e.g., by running the lightweight key update protocol KUDOS <xref target="I-D.ietf-core-oscore-key-update"/>. Similar procedures may be appropriate to signal Rule updates when other message-protection mechanisms are in use.</t>
      <section anchor="sec-security-considerations-yang-module">
        <name>YANG Module</name>
        <t>The YANG data model defined in Appendix A extends the ietf-schc module defined in <xref target="RFC9363"/>.</t>
        <t>Therefore, all the security considerations compiled in <xref section="8" sectionFormat="of" target="RFC9363"/> apply to the resulting, extended YANG data model as well.</t>
      </section>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has the following actions for IANA.</t>
      <t>Note to RFC Editor: Please replace all occurrences of "[RFC-XXXX]" with the RFC number of this specification and delete this paragraph.</t>
      <section anchor="ietf-xml">
        <name>IETF XML</name>
        <t>IANA is asked to register the following entry in the "IETF XML" registry <xref target="RFC3688"/>.</t>
        <ul spacing="normal">
          <li>
            <t>URI: urn:ietf:params:xml:ns:yang:ietf-schc-coap</t>
          </li>
          <li>
            <t>Registrant Contact: The IESG.</t>
          </li>
          <li>
            <t>XML: N/A; the requested URI is an XML namespace.</t>
          </li>
        </ul>
      </section>
      <section anchor="yang-module-names">
        <name>YANG Module Names</name>
        <t>IANA is asked to register the following entry in the "YANG Module Names" registry <xref target="RFC6020"/><xref target="RFC8407"/> within the "YANG Parameters" registry group.</t>
        <ul spacing="normal">
          <li>
            <t>Name: ietf-schc-coap</t>
          </li>
          <li>
            <t>Namespace: urn:ietf:params:xml:ns:yang:ietf-schc-coap</t>
          </li>
          <li>
            <t>Prefix: schc-coap</t>
          </li>
          <li>
            <t>Reference: [RFC-XXXX]</t>
          </li>
        </ul>
      </section>
      <section anchor="sec-iana-coap-fields">
        <name>SCHC Compression of CoAP Fields</name>
        <t>IANA is asked to establish the "SCHC Compression of CoAP Fields" IANA registry.</t>
        <t>As registration policy, the registry uses "Specification Required" per <xref section="4.6" sectionFormat="of" target="RFC8126"/>. Expert Review guidelines are provided in <xref target="sec-iana-expert-review"/>.</t>
        <section anchor="intended-use">
          <name>Intended Use</name>
          <t>The objective of this registry is to collect a list of CoAP fields and subfields, for which it has been defined how to perform SCHC compression.</t>
          <t>Such a definition does not necessarily have to be in the same documentation that defines the CoAP fields and subfields in question. While that can be the case, it is also possible to provide that definition in a separate specification.</t>
          <t>Each entry of the registry is intended to include references to the documentation that defines the associated CoAP field or subfield, as well as references to the specifications that define the SCHC compression of that CoAP field or subfield.</t>
          <t>When a specification defines how to perform SCHC compression of a CoAP field, the following applies.</t>
          <ul spacing="normal">
            <li>
              <t>If a registry entry for the CoAP field does not already exist, it is strongly encouraged to register an associated new entry.</t>
            </li>
            <li>
              <t>If a registry entry for the CoAP field already exists, it is strongly encouraged to update its list of references. The update is intended to add references to the specification that provides the new or updated SCHC compression of the CoAP field, as well as to any documentation that updates the definition of the CoAP field itself.</t>
            </li>
          </ul>
          <t>If the defined SCHC compression considers the CoAP field as composed of subfields, it is strongly encouraged that the same as above is also performed for each subfield and the associated registry entry.</t>
        </section>
        <section anchor="structure-of-entries">
          <name>Structure of Entries</name>
          <t>The columns of this registry are:</t>
          <ul spacing="normal">
            <li>
              <t>Field: a unique identifier of the CoAP field or subfield associated with this entry. This identifier can be used as value of the "Field" column in a SCHC compression Rule. This identifier must have a corresponding item or set of items in the YANG data model for the CoAP field or subfield associated with this entry, as specified in <xref section="6" sectionFormat="of" target="RFC9363"/> or in <xref target="sec-yang-module"/> of [RFC-XXXX].</t>
            </li>
            <li>
              <t>Description: a short description of the CoAP field or subfield associated with this entry, together with public references to the resources that define it.</t>
            </li>
            <li>
              <t>Reference: public references to the resources that define how a SCHC compression Rule works for the CoAP field or subfield associated with this entry.</t>
            </li>
          </ul>
          <t>This registry has been initially populated with the values in <xref target="_table-coap-fields"/>. The "Reference" column for all of these entries refers to this document.</t>
        </section>
      </section>
      <section anchor="sec-iana-expert-review">
        <name>Expert Review Instructions</name>
        <t>The IANA registry established in this document is defined as "Specification Required". This section gives some general guidelines for what the experts should be looking for, but they are being designated as experts for a reason so they should be given substantial latitude.</t>
        <t>Expert reviewers should take into consideration the following points:</t>
        <ul spacing="normal">
          <li>
            <t>Point squatting should be discouraged. Reviewers are encouraged to get sufficient information for registration requests to ensure that the usage is not going to duplicate one that is already registered and that the point is likely to be used in deployments.  </t>
            <t>
Specifically, for every CoAP field, only one corresponding registry entry is allowed. Also, for every CoAP subfield, only one corresponding registry entry is allowed.</t>
          </li>
          <li>
            <t>Consistent with the "Specification Required" registration policy, specifications should exist, but early assignment before a specification is available is considered to be permissible. When specifications are not provided, the description provided needs to have sufficient information to identify what the point is being used for.</t>
          </li>
        </ul>
        <t>If the expert becomes aware of a definition for SCHC compression of CoAP fields and subfields that is deployed and in use, the expert may also initiate a registration or update an existing one on their own, if they deem important that the definition in question gains visibility through the registry entry.</t>
      </section>
    </section>
  </middle>
  <back>
    <references>
      <name>References</name>
      <references>
        <name>Normative References</name>
        <reference anchor="RFC3688">
          <front>
            <title>The IETF XML Registry</title>
            <author fullname="M. Mealling" initials="M." surname="Mealling"/>
            <date month="January" year="2004"/>
            <abstract>
              <t>This document describes an IANA maintained registry for IETF standards which use Extensible Markup Language (XML) related items such as Namespaces, Document Type Declarations (DTDs), Schemas, and Resource Description Framework (RDF) Schemas.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="81"/>
          <seriesInfo name="RFC" value="3688"/>
          <seriesInfo name="DOI" value="10.17487/RFC3688"/>
        </reference>
        <reference anchor="RFC5116">
          <front>
            <title>An Interface and Algorithms for Authenticated Encryption</title>
            <author fullname="D. McGrew" initials="D." surname="McGrew"/>
            <date month="January" year="2008"/>
            <abstract>
              <t>This document defines algorithms for Authenticated Encryption with Associated Data (AEAD), and defines a uniform interface and a registry for such algorithms. The interface and registry can be used as an application-independent set of cryptoalgorithm suites. This approach provides advantages in efficiency and security, and promotes the reuse of crypto implementations. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="5116"/>
          <seriesInfo name="DOI" value="10.17487/RFC5116"/>
        </reference>
        <reference anchor="RFC6020">
          <front>
            <title>YANG - A Data Modeling Language for the Network Configuration Protocol (NETCONF)</title>
            <author fullname="M. Bjorklund" initials="M." role="editor" surname="Bjorklund"/>
            <date month="October" year="2010"/>
            <abstract>
              <t>YANG is a data modeling language used to model configuration and state data manipulated by the Network Configuration Protocol (NETCONF), NETCONF remote procedure calls, and NETCONF notifications. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6020"/>
          <seriesInfo name="DOI" value="10.17487/RFC6020"/>
        </reference>
        <reference anchor="RFC7252">
          <front>
            <title>The Constrained Application Protocol (CoAP)</title>
            <author fullname="Z. Shelby" initials="Z." surname="Shelby"/>
            <author fullname="K. Hartke" initials="K." surname="Hartke"/>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <date month="June" year="2014"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP) is a specialized web transfer protocol for use with constrained nodes and constrained (e.g., low-power, lossy) networks. The nodes often have 8-bit microcontrollers with small amounts of ROM and RAM, while constrained networks such as IPv6 over Low-Power Wireless Personal Area Networks (6LoWPANs) often have high packet error rates and a typical throughput of 10s of kbit/s. The protocol is designed for machine- to-machine (M2M) applications such as smart energy and building automation.</t>
              <t>CoAP provides a request/response interaction model between application endpoints, supports built-in discovery of services and resources, and includes key concepts of the Web such as URIs and Internet media types. CoAP is designed to easily interface with HTTP for integration with the Web while meeting specialized requirements such as multicast support, very low overhead, and simplicity for constrained environments.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7252"/>
          <seriesInfo name="DOI" value="10.17487/RFC7252"/>
        </reference>
        <reference anchor="RFC7641">
          <front>
            <title>Observing Resources in the Constrained Application Protocol (CoAP)</title>
            <author fullname="K. Hartke" initials="K." surname="Hartke"/>
            <date month="September" year="2015"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP) is a RESTful application protocol for constrained nodes and networks. The state of a resource on a CoAP server can change over time. This document specifies a simple protocol extension for CoAP that enables CoAP clients to "observe" resources, i.e., to retrieve a representation of a resource and keep this representation updated by the server over a period of time. The protocol follows a best-effort approach for sending new representations to clients and provides eventual consistency between the state observed by each client and the actual resource state at the server.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7641"/>
          <seriesInfo name="DOI" value="10.17487/RFC7641"/>
        </reference>
        <reference anchor="RFC7959">
          <front>
            <title>Block-Wise Transfers in the Constrained Application Protocol (CoAP)</title>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <author fullname="Z. Shelby" initials="Z." role="editor" surname="Shelby"/>
            <date month="August" year="2016"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP) is a RESTful transfer protocol for constrained nodes and networks. Basic CoAP messages work well for small payloads from sensors and actuators; however, applications will need to transfer larger payloads occasionally -- for instance, for firmware updates. In contrast to HTTP, where TCP does the grunt work of segmenting and resequencing, CoAP is based on datagram transports such as UDP or Datagram Transport Layer Security (DTLS). These transports only offer fragmentation, which is even more problematic in constrained nodes and networks, limiting the maximum size of resource representations that can practically be transferred.</t>
              <t>Instead of relying on IP fragmentation, this specification extends basic CoAP with a pair of "Block" options for transferring multiple blocks of information from a resource representation in multiple request-response pairs. In many important cases, the Block options enable a server to be truly stateless: the server can handle each block transfer separately, with no need for a connection setup or other server-side memory of previous block transfers. Essentially, the Block options provide a minimal way to transfer larger representations in a block-wise fashion.</t>
              <t>A CoAP implementation that does not support these options generally is limited in the size of the representations that can be exchanged, so there is an expectation that the Block options will be widely used in CoAP implementations. Therefore, this specification updates RFC 7252.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7959"/>
          <seriesInfo name="DOI" value="10.17487/RFC7959"/>
        </reference>
        <reference anchor="RFC7967">
          <front>
            <title>Constrained Application Protocol (CoAP) Option for No Server Response</title>
            <author fullname="A. Bhattacharyya" initials="A." surname="Bhattacharyya"/>
            <author fullname="S. Bandyopadhyay" initials="S." surname="Bandyopadhyay"/>
            <author fullname="A. Pal" initials="A." surname="Pal"/>
            <author fullname="T. Bose" initials="T." surname="Bose"/>
            <date month="August" year="2016"/>
            <abstract>
              <t>There can be machine-to-machine (M2M) scenarios where server responses to client requests are redundant. This kind of open-loop exchange (with no response path from the server to the client) may be desired to minimize resource consumption in constrained systems while updating many resources simultaneously or performing high-frequency updates. CoAP already provides Non-confirmable (NON) messages that are not acknowledged by the recipient. However, the request/response semantics still require the server to respond with a status code indicating "the result of the attempt to understand and satisfy the request", per RFC 7252.</t>
              <t>This specification introduces a CoAP option called 'No-Response'. Using this option, the client can explicitly express to the server its disinterest in all responses against the particular request. This option also provides granular control to enable expression of disinterest to a particular response class or a combination of response classes. The server MAY decide to suppress the response by not transmitting it back to the client according to the value of the No-Response option in the request. This option may be effective for both unicast and multicast requests. This document also discusses a few examples of applications that benefit from this option.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7967"/>
          <seriesInfo name="DOI" value="10.17487/RFC7967"/>
        </reference>
        <reference anchor="RFC8126">
          <front>
            <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
            <author fullname="M. Cotton" initials="M." surname="Cotton"/>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <author fullname="T. Narten" initials="T." surname="Narten"/>
            <date month="June" year="2017"/>
            <abstract>
              <t>Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA).</t>
              <t>To make assignments in a given registry prudently, guidance describing the conditions under which new values should be assigned, as well as when and how modifications to existing values can be made, is needed. This document defines a framework for the documentation of these guidelines by specification authors, in order to assure that the provided guidance for the IANA Considerations is clear and addresses the various issues that are likely in the operation of a registry.</t>
              <t>This is the third edition of this document; it obsoletes RFC 5226.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="26"/>
          <seriesInfo name="RFC" value="8126"/>
          <seriesInfo name="DOI" value="10.17487/RFC8126"/>
        </reference>
        <reference anchor="RFC8323">
          <front>
            <title>CoAP (Constrained Application Protocol) over TCP, TLS, and WebSockets</title>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <author fullname="S. Lemay" initials="S." surname="Lemay"/>
            <author fullname="H. Tschofenig" initials="H." surname="Tschofenig"/>
            <author fullname="K. Hartke" initials="K." surname="Hartke"/>
            <author fullname="B. Silverajan" initials="B." surname="Silverajan"/>
            <author fullname="B. Raymor" initials="B." role="editor" surname="Raymor"/>
            <date month="February" year="2018"/>
            <abstract>
              <t>The Constrained Application Protocol (CoAP), although inspired by HTTP, was designed to use UDP instead of TCP. The message layer of CoAP over UDP includes support for reliable delivery, simple congestion control, and flow control.</t>
              <t>Some environments benefit from the availability of CoAP carried over reliable transports such as TCP or Transport Layer Security (TLS). This document outlines the changes required to use CoAP over TCP, TLS, and WebSockets transports. It also formally updates RFC 7641 for use with these transports and RFC 7959 to enable the use of larger messages over a reliable transport.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8323"/>
          <seriesInfo name="DOI" value="10.17487/RFC8323"/>
        </reference>
        <reference anchor="RFC8407">
          <front>
            <title>Guidelines for Authors and Reviewers of Documents Containing YANG Data Models</title>
            <author fullname="A. Bierman" initials="A." surname="Bierman"/>
            <date month="October" year="2018"/>
            <abstract>
              <t>This memo provides guidelines for authors and reviewers of specifications containing YANG modules. Recommendations and procedures are defined, which are intended to increase interoperability and usability of Network Configuration Protocol (NETCONF) and RESTCONF protocol implementations that utilize YANG modules. This document obsoletes RFC 6087.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="216"/>
          <seriesInfo name="RFC" value="8407"/>
          <seriesInfo name="DOI" value="10.17487/RFC8407"/>
        </reference>
        <reference anchor="RFC8613">
          <front>
            <title>Object Security for Constrained RESTful Environments (OSCORE)</title>
            <author fullname="G. Selander" initials="G." surname="Selander"/>
            <author fullname="J. Mattsson" initials="J." surname="Mattsson"/>
            <author fullname="F. Palombini" initials="F." surname="Palombini"/>
            <author fullname="L. Seitz" initials="L." surname="Seitz"/>
            <date month="July" year="2019"/>
            <abstract>
              <t>This document defines Object Security for Constrained RESTful Environments (OSCORE), a method for application-layer protection of the Constrained Application Protocol (CoAP), using CBOR Object Signing and Encryption (COSE). OSCORE provides end-to-end protection between endpoints communicating using CoAP or CoAP-mappable HTTP. OSCORE is designed for constrained nodes and networks supporting a range of proxy operations, including translation between different transport protocols.</t>
              <t>Although an optional functionality of CoAP, OSCORE alters CoAP options processing and IANA registration. Therefore, this document updates RFC 7252.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8613"/>
          <seriesInfo name="DOI" value="10.17487/RFC8613"/>
        </reference>
        <reference anchor="RFC8724">
          <front>
            <title>SCHC: Generic Framework for Static Context Header Compression and Fragmentation</title>
            <author fullname="A. Minaburo" initials="A." surname="Minaburo"/>
            <author fullname="L. Toutain" initials="L." surname="Toutain"/>
            <author fullname="C. Gomez" initials="C." surname="Gomez"/>
            <author fullname="D. Barthel" initials="D." surname="Barthel"/>
            <author fullname="JC. Zuniga" initials="JC." surname="Zuniga"/>
            <date month="April" year="2020"/>
            <abstract>
              <t>This document defines the Static Context Header Compression and fragmentation (SCHC) framework, which provides both a header compression mechanism and an optional fragmentation mechanism. SCHC has been designed with Low-Power Wide Area Networks (LPWANs) in mind.</t>
              <t>SCHC compression is based on a common static context stored both in the LPWAN device and in the network infrastructure side. This document defines a generic header compression mechanism and its application to compress IPv6/UDP headers.</t>
              <t>This document also specifies an optional fragmentation and reassembly mechanism. It can be used to support the IPv6 MTU requirement over the LPWAN technologies. Fragmentation is needed for IPv6 datagrams that, after SCHC compression or when such compression was not possible, still exceed the Layer 2 maximum payload size.</t>
              <t>The SCHC header compression and fragmentation mechanisms are independent of the specific LPWAN technology over which they are used. This document defines generic functionalities and offers flexibility with regard to parameter settings and mechanism choices. This document standardizes the exchange over the LPWAN between two SCHC entities. Settings and choices specific to a technology or a product are expected to be grouped into profiles, which are specified in other documents. Data models for the context and profiles are out of scope.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8724"/>
          <seriesInfo name="DOI" value="10.17487/RFC8724"/>
        </reference>
        <reference anchor="RFC8768">
          <front>
            <title>Constrained Application Protocol (CoAP) Hop-Limit Option</title>
            <author fullname="M. Boucadair" initials="M." surname="Boucadair"/>
            <author fullname="T. Reddy.K" initials="T." surname="Reddy.K"/>
            <author fullname="J. Shallow" initials="J." surname="Shallow"/>
            <date month="March" year="2020"/>
            <abstract>
              <t>The presence of Constrained Application Protocol (CoAP) proxies may lead to infinite forwarding loops, which is undesirable. To prevent and detect such loops, this document specifies the Hop-Limit CoAP option.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8768"/>
          <seriesInfo name="DOI" value="10.17487/RFC8768"/>
        </reference>
        <reference anchor="RFC8949">
          <front>
            <title>Concise Binary Object Representation (CBOR)</title>
            <author fullname="C. Bormann" initials="C." surname="Bormann"/>
            <author fullname="P. Hoffman" initials="P." surname="Hoffman"/>
            <date month="December" year="2020"/>
            <abstract>
              <t>The Concise Binary Object Representation (CBOR) is a data format whose design goals include the possibility of extremely small code size, fairly small message size, and extensibility without the need for version negotiation. These design goals make it different from earlier binary serializations such as ASN.1 and MessagePack.</t>
              <t>This document obsoletes RFC 7049, providing editorial improvements, new details, and errata fixes while keeping full compatibility with the interchange format of RFC 7049. It does not create a new version of the format.</t>
            </abstract>
          </front>
          <seriesInfo name="STD" value="94"/>
          <seriesInfo name="RFC" value="8949"/>
          <seriesInfo name="DOI" value="10.17487/RFC8949"/>
        </reference>
        <reference anchor="RFC8974">
          <front>
            <title>Extended Tokens and Stateless Clients in the Constrained Application Protocol (CoAP)</title>
            <author fullname="K. Hartke" initials="K." surname="Hartke"/>
            <author fullname="M. Richardson" initials="M." surname="Richardson"/>
            <date month="January" year="2021"/>
            <abstract>
              <t>This document provides considerations for alleviating Constrained Application Protocol (CoAP) clients and intermediaries of keeping per-request state. To facilitate this, this document additionally introduces a new, optional CoAP protocol extension for extended token lengths.</t>
              <t>This document updates RFCs 7252 and 8323 with an extended definition of the "TKL" field in the CoAP message header.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8974"/>
          <seriesInfo name="DOI" value="10.17487/RFC8974"/>
        </reference>
        <reference anchor="RFC9175">
          <front>
            <title>Constrained Application Protocol (CoAP): Echo, Request-Tag, and Token Processing</title>
            <author fullname="C. Amsüss" initials="C." surname="Amsüss"/>
            <author fullname="J. Preuß Mattsson" initials="J." surname="Preuß Mattsson"/>
            <author fullname="G. Selander" initials="G." surname="Selander"/>
            <date month="February" year="2022"/>
            <abstract>
              <t>This document specifies enhancements to the Constrained Application Protocol (CoAP) that mitigate security issues in particular use cases. The Echo option enables a CoAP server to verify the freshness of a request or to force a client to demonstrate reachability at its claimed network address. The Request-Tag option allows the CoAP server to match block-wise message fragments belonging to the same request. This document updates RFC 7252 with respect to the following: processing requirements for client Tokens, forbidding non-secure reuse of Tokens to ensure response-to-request binding when CoAP is used with a security protocol, and amplification mitigation (where the use of the Echo option is now recommended).</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9175"/>
          <seriesInfo name="DOI" value="10.17487/RFC9175"/>
        </reference>
        <reference anchor="RFC9177">
          <front>
            <title>Constrained Application Protocol (CoAP) Block-Wise Transfer Options Supporting Robust Transmission</title>
            <author fullname="M. Boucadair" initials="M." surname="Boucadair"/>
            <author fullname="J. Shallow" initials="J." surname="Shallow"/>
            <date month="March" year="2022"/>
            <abstract>
              <t>This document specifies alternative Constrained Application Protocol (CoAP) block-wise transfer options: Q-Block1 and Q-Block2.</t>
              <t>These options are similar to, but distinct from, the CoAP Block1 and Block2 options defined in RFC 7959. The Q-Block1 and Q-Block2 options are not intended to replace the Block1 and Block2 options but rather have the goal of supporting Non-confirmable (NON) messages for large amounts of data with fewer packet interchanges. Also, the Q-Block1 and Q-Block2 options support faster recovery should any of the blocks get lost in transmission.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9177"/>
          <seriesInfo name="DOI" value="10.17487/RFC9177"/>
        </reference>
        <reference anchor="RFC9363">
          <front>
            <title>A YANG Data Model for Static Context Header Compression (SCHC)</title>
            <author fullname="A. Minaburo" initials="A." surname="Minaburo"/>
            <author fullname="L. Toutain" initials="L." surname="Toutain"/>
            <date month="March" year="2023"/>
            <abstract>
              <t>This document describes a YANG data model for the Static Context Header Compression (SCHC) compression and fragmentation Rules.</t>
              <t>This document formalizes the description of the Rules for better interoperability between SCHC instances either to exchange a set of Rules or to modify the parameters of some Rules.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9363"/>
          <seriesInfo name="DOI" value="10.17487/RFC9363"/>
        </reference>
        <reference anchor="I-D.ietf-core-oscore-edhoc">
          <front>
            <title>Using Ephemeral Diffie-Hellman Over COSE (EDHOC) with the Constrained Application Protocol (CoAP) and Object Security for Constrained RESTful Environments (OSCORE)</title>
            <author fullname="Francesca Palombini" initials="F." surname="Palombini">
              <organization>Ericsson</organization>
            </author>
            <author fullname="Marco Tiloca" initials="M." surname="Tiloca">
              <organization>RISE AB</organization>
            </author>
            <author fullname="Rikard Höglund" initials="R." surname="Höglund">
              <organization>RISE AB</organization>
            </author>
            <author fullname="Stefan Hristozov" initials="S." surname="Hristozov">
              <organization>Fraunhofer AISEC</organization>
            </author>
            <author fullname="Göran Selander" initials="G." surname="Selander">
              <organization>Ericsson</organization>
            </author>
            <date day="9" month="April" year="2024"/>
            <abstract>
              <t>   The lightweight authenticated key exchange protocol Ephemeral Diffie-
   Hellman Over COSE (EDHOC) can be run over the Constrained Application
   Protocol (CoAP) and used by two peers to establish a Security Context
   for the security protocol Object Security for Constrained RESTful
   Environments (OSCORE).  This document details this use of the EDHOC
   protocol, by specifying a number of additional and optional
   mechanisms.  These especially include an optimization approach for
   combining the execution of EDHOC with the first OSCORE transaction.
   This combination reduces the number of round trips required to set up
   an OSCORE Security Context and to complete an OSCORE transaction
   using that Security Context.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-core-oscore-edhoc-11"/>
        </reference>
        <reference anchor="I-D.ietf-core-oscore-groupcomm">
          <front>
            <title>Group Object Security for Constrained RESTful Environments (Group OSCORE)</title>
            <author fullname="Marco Tiloca" initials="M." surname="Tiloca">
              <organization>RISE AB</organization>
            </author>
            <author fullname="Göran Selander" initials="G." surname="Selander">
              <organization>Ericsson AB</organization>
            </author>
            <author fullname="Francesca Palombini" initials="F." surname="Palombini">
              <organization>Ericsson AB</organization>
            </author>
            <author fullname="John Preuß Mattsson" initials="J. P." surname="Mattsson">
              <organization>Ericsson AB</organization>
            </author>
            <author fullname="Rikard Höglund" initials="R." surname="Höglund">
              <organization>RISE AB</organization>
            </author>
            <date day="26" month="September" year="2024"/>
            <abstract>
              <t>   This document defines the security protocol Group Object Security for
   Constrained RESTful Environments (Group OSCORE), providing end-to-end
   security of CoAP messages exchanged between members of a group, e.g.,
   sent over IP multicast.  In particular, the described protocol
   defines how OSCORE is used in a group communication setting to
   provide source authentication for CoAP group requests, sent by a
   client to multiple servers, and for protection of the corresponding
   CoAP responses.  Group OSCORE also defines a pairwise mode where each
   member of the group can efficiently derive a symmetric pairwise key
   with any other member of the group for pairwise OSCORE communication.
   Group OSCORE can be used between endpoints communicating with CoAP or
   CoAP-mappable HTTP.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-core-oscore-groupcomm-23"/>
        </reference>
        <reference anchor="I-D.ietf-core-oscore-key-update">
          <front>
            <title>Key Update for OSCORE (KUDOS)</title>
            <author fullname="Rikard Höglund" initials="R." surname="Höglund">
              <organization>RISE AB</organization>
            </author>
            <author fullname="Marco Tiloca" initials="M." surname="Tiloca">
              <organization>RISE AB</organization>
            </author>
            <date day="8" month="July" year="2024"/>
            <abstract>
              <t>   This document defines Key Update for OSCORE (KUDOS), a lightweight
   procedure that two CoAP endpoints can use to update their keying
   material by establishing a new OSCORE Security Context.  Accordingly,
   it updates the use of the OSCORE flag bits in the CoAP OSCORE Option
   as well as the protection of CoAP response messages with OSCORE, and
   it deprecates the key update procedure specified in Appendix B.2 of
   RFC 8613.  Thus, this document updates RFC 8613.  Also, this document
   defines a procedure that two endpoints can use to update their OSCORE
   identifiers, run either stand-alone or during a KUDOS execution.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-core-oscore-key-update-08"/>
        </reference>
        <reference anchor="I-D.ietf-core-href">
          <front>
            <title>Constrained Resource Identifiers</title>
            <author fullname="Carsten Bormann" initials="C." surname="Bormann">
              <organization>Universität Bremen TZI</organization>
            </author>
            <author fullname="Henk Birkholz" initials="H." surname="Birkholz">
              <organization>Fraunhofer SIT</organization>
            </author>
            <date day="24" month="July" year="2024"/>
            <abstract>
              <t>   The Constrained Resource Identifier (CRI) is a complement to the
   Uniform Resource Identifier (URI) that represents the URI components
   in Concise Binary Object Representation (CBOR) instead of in a
   sequence of characters.  This simplifies parsing, comparison, and
   reference resolution in environments with severe limitations on
   processing power, code size, and memory size.

   This RFC updates RFC 7595 to add a note on how the URI Schemes
   registry RFC 7595 describes cooperates with the CRI Scheme Numbers
   registry created by the present RFC.


   // (This "cref" paragraph will be removed by the RFC editor:) The
   // present revision –16 of this draft continues -15 by picking up
   // more comments; it was made specifically for IETF 120.  This
   // revision still contains open issues and is intended to serve as a
   // snapshot.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-core-href-16"/>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references>
        <name>Informative References</name>
        <reference anchor="RFC8824">
          <front>
            <title>Static Context Header Compression (SCHC) for the Constrained Application Protocol (CoAP)</title>
            <author fullname="A. Minaburo" initials="A." surname="Minaburo"/>
            <author fullname="L. Toutain" initials="L." surname="Toutain"/>
            <author fullname="R. Andreasen" initials="R." surname="Andreasen"/>
            <date month="June" year="2021"/>
            <abstract>
              <t>This document defines how to compress Constrained Application Protocol (CoAP) headers using the Static Context Header Compression and fragmentation (SCHC) framework. SCHC defines a header compression mechanism adapted for Constrained Devices. SCHC uses a static description of the header to reduce the header's redundancy and size. While RFC 8724 describes the SCHC compression and fragmentation framework, and its application for IPv6/UDP headers, this document applies SCHC to CoAP headers. The CoAP header structure differs from IPv6 and UDP, since CoAP uses a flexible header with a variable number of options, themselves of variable length. The CoAP message format is asymmetric: the request messages have a header format different from the format in the response messages. This specification gives guidance on applying SCHC to flexible headers and how to leverage the asymmetry for more efficient compression Rules.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8824"/>
          <seriesInfo name="DOI" value="10.17487/RFC8824"/>
        </reference>
        <reference anchor="RFC9147">
          <front>
            <title>The Datagram Transport Layer Security (DTLS) Protocol Version 1.3</title>
            <author fullname="E. Rescorla" initials="E." surname="Rescorla"/>
            <author fullname="H. Tschofenig" initials="H." surname="Tschofenig"/>
            <author fullname="N. Modadugu" initials="N." surname="Modadugu"/>
            <date month="April" year="2022"/>
            <abstract>
              <t>This document specifies version 1.3 of the Datagram Transport Layer Security (DTLS) protocol. DTLS 1.3 allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.</t>
              <t>The DTLS 1.3 protocol is based on the Transport Layer Security (TLS) 1.3 protocol and provides equivalent security guarantees with the exception of order protection / non-replayability. Datagram semantics of the underlying transport are preserved by the DTLS protocol.</t>
              <t>This document obsoletes RFC 6347.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9147"/>
          <seriesInfo name="DOI" value="10.17487/RFC9147"/>
        </reference>
        <reference anchor="RFC9528">
          <front>
            <title>Ephemeral Diffie-Hellman Over COSE (EDHOC)</title>
            <author fullname="G. Selander" initials="G." surname="Selander"/>
            <author fullname="J. Preuß Mattsson" initials="J." surname="Preuß Mattsson"/>
            <author fullname="F. Palombini" initials="F." surname="Palombini"/>
            <date month="March" year="2024"/>
            <abstract>
              <t>This document specifies Ephemeral Diffie-Hellman Over COSE (EDHOC), a very compact and lightweight authenticated Diffie-Hellman key exchange with ephemeral keys. EDHOC provides mutual authentication, forward secrecy, and identity protection. EDHOC is intended for usage in constrained scenarios, and a main use case is to establish an Object Security for Constrained RESTful Environments (OSCORE) security context. By reusing CBOR Object Signing and Encryption (COSE) for cryptography, Concise Binary Object Representation (CBOR) for encoding, and Constrained Application Protocol (CoAP) for transport, the additional code size can be kept very low.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9528"/>
          <seriesInfo name="DOI" value="10.17487/RFC9528"/>
        </reference>
        <reference anchor="I-D.ietf-core-groupcomm-bis">
          <front>
            <title>Group Communication for the Constrained Application Protocol (CoAP)</title>
            <author fullname="Esko Dijk" initials="E." surname="Dijk">
              <organization>IoTconsultancy.nl</organization>
            </author>
            <author fullname="Chonggang Wang" initials="C." surname="Wang">
              <organization>InterDigital</organization>
            </author>
            <author fullname="Marco Tiloca" initials="M." surname="Tiloca">
              <organization>RISE AB</organization>
            </author>
            <date day="24" month="April" year="2024"/>
            <abstract>
              <t>   This document specifies the use of the Constrained Application
   Protocol (CoAP) for group communication, including the use of UDP/IP
   multicast as the default underlying data transport.  Both unsecured
   and secured CoAP group communication are specified.  Security is
   achieved by use of the Group Object Security for Constrained RESTful
   Environments (Group OSCORE) protocol.  The target application area of
   this specification is any group communication use cases that involve
   resource-constrained devices or networks that support CoAP.  This
   document replaces and obsoletes RFC 7390, while it updates RFC 7252
   and RFC 7641.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-core-groupcomm-bis-11"/>
        </reference>
      </references>
    </references>
    <section anchor="sec-yang-module">
      <name>YANG Data Model</name>
      <t>This appendix defines the ietf-schc-coap module, which extends the ietf-schc module defined in <xref target="RFC9363"/> to include the new CoAP options as defined in the present document.</t>
      <figure anchor="fig-yang-data-model">
        <name>SCHC CoAP Extension YANG Data Model</name>
        <sourcecode markers="true" name="ietf-schc-coap@2024-10-21.yang"><![CDATA[

module ietf-schc-coap {
  yang-version 1.1;
  namespace "urn:ietf:params:xml:ns:yang:ietf-schc-coap";
  prefix schc-coap;

  import ietf-schc {
      prefix schc;
  }

  organization
    "IETF Static Context Header Compression (schc) Working Group";
  contact
    "WG Web:   <https://datatracker.ietf.org/wg/schc/about/>
     WG List:  <mailto:schc@ietf.org>
     Editor:   Marco Tiloca
       <mailto:marco.tiloca@ri.se>";
  description
    "Copyright (c) 2021 IETF Trust and the persons identified as
     authors of the code.  All rights reserved.
     Redistribution and use in source and binary forms, with or
     without modification, is permitted pursuant to, and subject to
     the license terms contained in, the Simplified BSD License set
     forth in Section 4.c of the IETF Trust's Legal Provisions
     Relating to IETF Documents
     (https://trustee.ietf.org/license-info).
     This version of this YANG module is part of RFC XXXX
     (https://www.rfc-editor.org/info/rfcXXXX); see the RFC itself
     for full legal notices.
     The key words 'MUST', 'MUST NOT', 'REQUIRED', 'SHALL', 'SHALL
     NOT', 'SHOULD', 'SHOULD NOT', 'RECOMMENDED', 'NOT RECOMMENDED',
     'MAY', and 'OPTIONAL' in this document are to be interpreted as
     described in BCP 14 (RFC 2119) (RFC 8174) when, and only when,
     they appear in all capitals, as shown here.
     ****************************************************************

     This module extends the ietf-schc module defined in RFC 9363 to
     include the new CoAP options as defined in RFC YYYY.";

  revision 2024-10-21 {
    description
      "New CoAP extensions and extended OSCORE fields.";
    reference
      "RFC YYYY Static Context Header Compression (SCHC) for the
                Constrained Application Protocol (CoAP) (see
                Sections 5 and 6)";
  }

  // Field ID

  identity fid-coap-option-proxy-cri {
    base "schc:fid-coap-option";
    description
      "Proxy-Cri option.";
    reference
      "RFC XXXX Constrained Resource Identifiers";
  }

  identity fid-coap-option-proxy-scheme-number {
    base "schc:fid-coap-option";
    description
      "Proxy-Scheme-Number option.";
    reference
      "RFC XXXX Constrained Resource Identifiers";
  }

  identity fid-coap-option-hop-limit {
    base "schc:fid-coap-option";
    description
      "Hop Limit option to avoid infinite forwarding loops.";
    reference
      "RFC 8768 Constrained Application Protocol (CoAP)
                Hop-Limit Option";
  }

  identity fid-coap-option-echo {
    base "schc:fid-coap-option";
    description
      "Echo option.";
    reference
      "RFC 9175 Constrained Application Protocol (CoAP):
                Echo, Request-Tag, and Token Processing";
  }

  identity fid-coap-option-request-tag {
    base "schc:fid-coap-option";
    description
      "Request-Tag option.";
    reference
      "RFC 9175 Constrained Application Protocol (CoAP):
                Echo, Request-Tag, and Token Processing";
  }

  identity fid-coap-option-q-block1 {
    base "schc:fid-coap-option";
    description
      "Q-Block1 option.";
    reference
      "RFC 9177 Constrained Application Protocol (CoAP)
                Block-Wise Transfer Options Supporting
                Robust Transmission";
  }

  identity fid-coap-option-q-block2 {
    base "schc:fid-coap-option";
    description
      "Q-Block2 option.";
    reference
      "RFC 9177 Constrained Application Protocol (CoAP)
                Block-Wise Transfer Options Supporting
                Robust Transmission";
  }

  identity fid-coap-option-edhoc {
    base "schc:fid-coap-option";
    description
      "EDHOC option.";
    reference
      "RFC XXXX Using Ephemeral Diffie-Hellman Over COSE (EDHOC)
                with the Constrained Application Protocol (CoAP)
                and Object Security for Constrained RESTful
                Environments (OSCORE)";
  }

  identity fid-coap-option-oscore-x {
       base "schc:fid-coap-option";
       description
         "CoAP option OSCORE x field.";
       reference
         "RFC YYYY Static Context Header Compression (SCHC) for the
                   Constrained Application Protocol (CoAP) (see
                   Section 6.4)
          RFC XXXX Key Update for OSCORE (KUDOS)";
  }

  identity fid-coap-option-oscore-nonce {
       base "schc:fid-coap-option";
       description
         "CoAP option OSCORE nonce field.";
       reference
         "RFC YYYY Static Context Header Compression (SCHC) for the
                   Constrained Application Protocol (CoAP) (see
                   Section 6.4)
          RFC XXXX Key Update for OSCORE (KUDOS)";
  }

  identity fid-coap-option-oscore-y {
       base "schc:fid-coap-option";
       description
         "CoAP option OSCORE y field.";
       reference
         "RFC YYYY Static Context Header Compression (SCHC) for the
                   Constrained Application Protocol (CoAP) (see
                   Section 6.4)
          RFC XXXX Key Update for OSCORE (KUDOS)";
  }

  identity fid-coap-option-oscore-oldnonce {
       base "schc:fid-coap-option";
       description
         "CoAP option OSCORE old_nonce field.";
       reference
         "RFC YYYY Static Context Header Compression (SCHC) for the
                   Constrained Application Protocol (CoAP) (see
                   Section 6.4)
          RFC XXXX Key Update for OSCORE (KUDOS)";
  }

  // Function Length

  identity fl-oscore-oscore-nonce-length {
       base "schc:fl-base-type";
       description
         "Size in bytes of the OSCORE nonce corresponding to m+1.";
       reference
         "RFC YYYY Static Context Header Compression (SCHC) for the
                   Constrained Application Protocol (CoAP) (see
                   Section 6.4)
          RFC XXXX Key Update for OSCORE (KUDOS)";
  }

  identity fl-oscore-oscore-oldnonce-length {
       base "schc:fl-base-type";
       description
         "Size in bytes of the OSCORE old_nonce corresponding to w+1.
         ";
       reference
         "RFC YYYY Static Context Header Compression (SCHC) for the
                   Constrained Application Protocol (CoAP) (see
                   Section 6.4)
          RFC XXXX Key Update for OSCORE (KUDOS)";
  }
}

]]></sourcecode>
      </figure>
    </section>
    <section anchor="sec-document-updates" removeInRFC="true">
      <name>Document Updates</name>
      <section anchor="sec-02-03">
        <name>Version -02 to -03</name>
        <ul spacing="normal">
          <li>
            <t>Consistent representation of "CoAP Version" 1 in example Rules.</t>
          </li>
          <li>
            <t>Split the compression of Token Length and Token into two sections.</t>
          </li>
          <li>
            <t>Disambiguated example of Rule on eliding a Uri-Path option.</t>
          </li>
          <li>
            <t>Fixed compression examples with OSCORE.</t>
          </li>
          <li>
            <t>Inherited security considerations on the YANG module from RFC 9363.</t>
          </li>
          <li>
            <t>Fixes and editorial improvements.</t>
          </li>
        </ul>
      </section>
      <section anchor="sec-01-02">
        <name>Version -01 to -02</name>
        <ul spacing="normal">
          <li>
            <t>Added compression for the CoAP options Proxy-Cri and Proxy-Scheme-Number.</t>
          </li>
          <li>
            <t>Defined new IANA registry "SCHC Compression of CoAP Fields".</t>
          </li>
          <li>
            <t>Updated the YANG data model.</t>
          </li>
          <li>
            <t>Fixes and editorial improvements.</t>
          </li>
        </ul>
      </section>
      <section anchor="sec-00-01">
        <name>Version -00 to -01</name>
        <ul spacing="normal">
          <li>
            <t>Fixed an example, as per the erratum with Errata ID 7623.</t>
          </li>
          <li>
            <t>Clarified building of Field Descriptor for CoAP options.</t>
          </li>
          <li>
            <t>Clarified what SCHC compression considers for CoAP options.</t>
          </li>
          <li>
            <t>Revised SCHC Compression of the ETag and If-Match CoAP option.</t>
          </li>
          <li>
            <t>Revised SCHC Compression of the If-None-Match CoAP option.</t>
          </li>
          <li>
            <t>Added YANG data model for the YANG module.</t>
          </li>
          <li>
            <t>Added IANA considerations.</t>
          </li>
          <li>
            <t>Fixes and editorial improvements.</t>
          </li>
        </ul>
      </section>
    </section>
    <section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>The authors sincerely thank <contact fullname="Christian Amsüss"/>, <contact fullname="Quentin Lampin"/>, <contact fullname="John Preuß Mattsson"/>, <contact fullname="Carles Gomez Montenegro"/>, <contact fullname="Göran Selander"/>, <contact fullname="Pascal Thubert"/>, and <contact fullname="Éric Vyncke"/> for their comments and feedback.</t>
      <t>This work was supported by the Sweden's Innovation Agency VINNOVA within the EUREKA CELTIC-NEXT project CYPRESS; and by the H2020 projects SIFIS-Home (Grant agreement 952652) and ARCADIAN-IoT (Grant agreement 101020259).</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+y923Yjx5Uo+M6vyKHWGpEWAAHgnbY1pkiWxKOqYrnIkuxj
9+qVABJkuoBMdGaCJKyq8z5fMfMV8zRP0z82+xa3zEjcSFaVu8Vuq0ggM2LH
jh079n03m82Nu+NgZ2OjiItRdBxcFWER94PTNCmihyL4MQoHUQZ/jidZlOdx
mgRbV6c/nm4HwzQLitsIn8yLLIyTaBCcTCajuA8DwGNvsrRI++ko2DpNT95s
b4S9XhbBVPg2vYwfbwzSfhKOYd5BFg6LZhwVw2bev+03Dw+7u83pZBAWUXME
/8mLjY14kh0HRTbNi267fdTuboRZFB4HFwBqlkTFxv2NDP9Lmr2Pk5vghyyd
Tjbe35tnmmc4zwbAeBzkxWAjn/bGMa2rmE0AjIvz6xcbaS9PRxHMeRwgGBsb
/XQAwx0HU4DucGMjnBa3aXa8EdBPU/4NgjiBN161gut4lPZD/TEv8FWY9dPy
V2kGo769uDoPTr7XHwI6owjgu8jD4T/SbJDfhEWYBN2ufqIfF7Pj4Kc4L8xQ
ACNu33mzs7+727Y+niZFBk9f3UeDKNGfR+MwHh0HY4SqVRBUf8riVh75V/US
VpVOC9jm0rJehtMsSorKt7Syi1fXwUkxCpMi/o9pVFng6VXQOdhvHzSCbpBN
o2AQBaMwOL2F5cY3SQREFZWWfAo0mCbNq+gOH4A/B9FDCQM7e3sH+9Xlv8jC
pB+Vly/QtwT6P8XjohlqgFvDzI+NixZuZwE0/88SOi7uYKcq3xEyXqfv4zD4
PhqNYNpeXsFGpxu8BST8jwhG+B5GKC39VZjns9Jajzo7bc9W+9caA2itsYD2
7710BB9kf0oQqmYPoIJj1stb/XTsX/MJrDlOwt40S0trPknC6le0ZOQN0xEQ
b1FZ7Vve77dRkkT53F2u7m9n6TWHAKFA9qcb/IjWt5Gk2Ri41F2EZ/jti9Od
/cND+XWv09mXX/fb3bb8etDd66pf93c76tejvSP96/6B/HrY6aoRDne6O+rX
3bZ+YL+jPz3o7upf9xUMh0e7R/rXA/XAUedgz/yqBjva2afBLppnLeKe/TSL
mmlO/0SD27Rf++0NckfAx7j2iffRTHhw9ZHbLBoeA09OhiVkIsvUcO5qOPe6
h9VBNAjNXpzDaHAWkQLguavzly+Og82/wavNv8DPv21ubDSbzQBoFG6bPtwG
17dxHsD9MR0j/xlEQ6DrPLhN74MiBbrgC2vZ6ym4pYsuD6Y5Xhx4sS2+CcNk
EAyz8AYB4FHV3ZjBwbiHS6jF95ECLpRpNHj4zjjq34ZJnI+DcBBOCoATb8e+
BfcADkI/ymWwaU4j5QzeIMr7WTyh2dMhAS5zABayaDDtR9aHX+f0WTKAwzIj
+PP4n1Er+OU2HkW4TQFSpAzag3kIEThrf+669YIb9GVcAIQWsnFBF2/u9r99
d/ZGYboBY9sbSM/DjDQbwI7bop6Fy4ckDf0JspFpvwDmHQzi4RA3bpilY5qE
IICJGrA2YAn8miBtOIoe4t5I4+g+Lm7hY2CEcYgfJ9NxDz4GRKaEUoIyGufR
6A7eh4/1k6MouSluLcDGgJzwJgr4OASwtDCfjcdRkcX9Y8JjFsGdkhfqSaDV
8C4yNCEv8noQI7QifFENmcgw+QQgi/Q4CARMl0+ifjxUKL+JEeKbaYxbHQW4
a4DgGRK3wnAJGTkhTs7PKLqD+/eGaUctZEYbOYaDG0RDmClGKG3CeDsdaXD0
xmbRZBT2Ix5ei1ZMbMAqWnyux/FgMIo2Nr5CUS1LgW5pGV8Fv34V4wcf8cAv
LW0Gv/4qXPvjR9oKBHMMAHyrsTdRbwCx4zXDx24c9zP4FGccjRAnRCH5OIRb
++3JK1rD28tXTOZII2M4P/xqHmV0TINemMNHiI7zq+tg622E+FFHJRwRY4mC
a7iwctjp7VZwMgJ5cnpzS8j2HPwA5FxYwgi2CfdvCOwP5hNyYPCRNnHlAJh9
TuC84wFHFOQg5I1ga2Fvw4zpNHj55peT13mw9TK9b75J74EIf4kHUfMExOrg
dVTggc4BvkdwwvQuypyjjKDgQYiBDyGhwRGF2XA/oozonKiVuBecWX6VBiFY
gwKYZZKO0htgFUA5tM3IsmCbFZPVLMtiSve3cf8W5xpNB4v5sIWa4pbPst5T
zXj7jI0WkNpVxMS6h7tgAIoegPBBdoLZ4UBXOOggsj9J+/2p3lMQym9jWCoy
OGYxFR4MSlI0xqOZwylDXgOQwZeE2hzeZch7KVBvlAwmKRyiPHif4OmG4dw1
BL1oiIe6QJIUdYinvQ9niijpQcAE/DqMbwCwQQPP0F2MT+MfgLToAVF4A5iC
B0Gk5hvJYgZIj/10EsHW0c7i0Uycq0IdS+DecgfYqxbKyVEkLeBM4nHAk614
D6ykuI8ixiLQL+ONHk7MDersOqyQOGMA6MI3DP9FHjgCyRe/gOEu3qibhb9R
m0WU0sAduEfZHneCX7CXxW8otZeQmzOENjBE3ah55ARXDw5uMogmsIGopATf
424OgTGpXQT6BoQBWceTEdICb7q6vQcIoXVCgNHk1vJI1oppqkRx+grCYTv6
KEY5FxMjpmFOGuN+kMV3SniyxvjWJXTiZaPcQnQrcI+xkj3kKkI2oI0G1iZY
soF93cg1aN7n3a1sfFnE2NhwHpH7ysCOAwoL08xASE9Oh6G+MyWwWUdXDpBi
QWPQi2jX5M48D4FB4e9BP0SqLPq3tjAHCxoNcgRaXfMgioyQUAApGZ45EU/w
s1ZwMQR2QKPRSJFsFv8xKA2KOyKX9CDo8YHHdy/OCAVMF9YlDxfOYCoMBtdF
PE4kE/gGbrgeCoAijVo4R3xMARRDSUw4SOugDvDVTLeCeUJf0/r+4FM3Cfvv
o4KBCAXhyHGBaTKaIrygATdRPwJRCLb3hBHiyrY8TP41nYasJBcCV87gL8DK
KM6Jmb1AjMFsLHOnAM5WHkXWFXDgXAFwd14AuNMsaQQRbnD5fRd//C2gfevF
xdl2Q/5+SZImfPZym8UO/vhNCmyebtoXb7Zd9hOcwVIYnotkgCwIZto6u9gO
tqYTVMDDMWxCep+o3+HrXjxQL4WjbVYNUr5g0n4colpyjXJDEfzMdLd1/TPK
BkjhZxdwooEp5eUNx40AJqbPC37dQxH4+mdtPyyjBC9rYeDwFKlyCZAVbEps
cy/1uvnEvr0CvRg+hBldcCgcEc0r7mo4ZU7yLshH8TjSNEb8FYkGqOfFNIOP
srEM8wpPEjK7S5BbGL+vLrdZ6tcIIyqifReyKq+V0UdkiRJaNAKYkW0PEZ8E
wqtL0GziQtCR07LVd3J8Ha0PeLzmIkmKN7szLDEBUVQ06SmkKFlnmqCcQJtX
Uf8A5o0NpGk6/LCvLHAaZn/mMPsTpsKt07OTbT9meGrDtBlCkIcHjhrv8mKe
nl5tObxpDAsCZg9/AnulfQTZBDE0TEG6Cpkijjc2fsf8QWORGWewRf80UVjf
buinAI+01VvwS/k7OiMvQYAtgisQw0n/Alr8Hhng1sur7/NttT80Dx41/S7w
F7zeH4KtMdxRMAMPjqxqWAC1aIWtdKqIl2eRImICgTgun7acrlQWMOSOQA7f
B7IBzG96WPmmuvxIU7qJEjoKll2CVPMaxgz8nHYTgYweAMXC1BmYaU5qDIow
uBLhAZqpq/vFEpVsgbrTdiVql3d7xGFlaFgkJBTEynLHpGAPx1YgxEmL9U4U
QgCUqinEoMbRcu5DvJnjmxi4KRAk6yaWQHbIAhnbXVxDyCCF9eHZDUdIBbzS
jHCUpXBkGkrl69+mKGXwpTCMQtQWtBkgGjCVxEnZ0NIH/Y/OWiNg256MAOIJ
7FKNyUfUS72+mgURb5igjbk/hWlKU+d1tgBrCLzAWMRFkex3wUXBWgbKTAI5
0wmPARw6GfDYwq4U1kv2EJS+GrbkNhKuOIyiQQ+kABoO4Esz/DTKgKuHCgKN
MpYpfQiCozJAsmeFlY1HiB11mkROyKN+s5+Gk6Y8gjJCZRLvBMbfZiY4Bqbz
z6jToH+6DbSCPMya77KYd5T/vOKjoQBACNAm0KH/dpsTemiaxfIbnySBD8D7
fXB+Hd7QeBfDJt17zlhREd4042GTZEv7NXnjNXBgz2vwRoLf0GsWFipavA8H
KNQlhXWuHKzzsk+zuIKE5mu279mA8Kr75fWzJdCsZyX4LHCCH9NJ82U8hjtc
ZrW3v3kL347w26dFwTnwBu98wNNTmKoBrJ+MkU3cW9+DYqxswu7S8+dnP16e
+odEJwM9Y8mgf25+P0r77zu0BfJH18E7jUE8J6dheviIhQXhTX4siFpK1jAP
zi+vTi/fns+djj0cBLZIe6P45paEfEYtGt+iUTpRjGtEgoswGRgRTkwxMzeZ
TBmWWOMCtwryO0BQzXPaO0KcdVVOpJEyCWejNEShN3tviF8+bfKny5Jf+R5Q
2hhZOPuR/h7PEkKpCUYP0URpoSnfE/5xB9lAB/LDeDISgUXY/kCNob5kUL/6
KrgGcTwmY+As+AoNxYX5QMzFgOngHl3oweard1fXmw3+N3h9Sb+/Pf/zu4u3
52f4+9WPJy9f6l825ImrHy/fvTwzv5k3Ty9fvTp/fcYvw6eB89HG5quTv24y
G968fHN9cfn65OUmo8vxeqDZLWVLD4APSEIqC/MNx4jz/emb/+//7uwCEv43
uCi7nc4REA7/cdg5wFsTdSYxSqMAzH/Czsw2QGyIQrIsot7QDydxEaLQBpSa
36KYj1IC7v3fEDP/dhz8odefdHa/kw9wwc6HCmfOh4Sz6ieVlxmJno8802hs
Op+XMO3Ce/JX52+Fd+vDjY23ytmRKXsBH2vYgmE4jkdxmBmBFimKBQ3QlvrR
pMoJXEuzbclik8t91GsWYuo33ILOiOWjaGhJuMJZcsVaeOj9zo4wDQpuMV8u
wUG+YmjFb9KDtcI8SnLFA4SMMrS/bRYpcc6PJeuYuokcXgDoJ6UaVa6YrGL/
mCYsyGuEjsjLMApn+MKW8gluB+TP0KbO0cwynZFXVKyo9F6jbOH0298bSkEi
HUSTO70xjG/8C2128MV5D+jdmvfQjpKFWfPLQD0U9oXKUMzq+BKAiBHPskEq
xQcFZ+MMRfnVOEBlS9n4hOyGFXV8VQxlitrEyRP8ACSNtv6t1z/8sq1cMYz+
02/P2JlTr+Y3AubQtt3rumQARyKcJvQXXNqaHgQerfPEuDLijGpywOP/Mj9B
GOZ3NxvBFr+4Hdg/DP2cny0g/e2NjW+a8vPNvIdLP+aljQ8BE37wYYX3zUtP
MT/qtivPLy+V59d/zgXLnZ/oTOYXKPgj64PK/PJS7fzfLD8/UYeZ3/6zfn75
pX5+NZV3fv0Lzs/eSDU///X4+ZdcP3+wBT808Tb8WA/yU/CLinlUHzXtg7Tx
63Hw1RzuE1A86B8362174uXitX+fYlBJNtuEe5VYSjMEeTr54yaK0lG2+RF9
tXOZHbFn5m+2scVjnAl76R3Mi3dB0FUSaJmx/fCLdYXQvaFcAchokiZIq9mM
om3EBcC3vHgjZ9WwBnIlieW1JP0S/20Fl/xXinYXdLo2FCRmZi0xiPuCbQ7s
8p+S58Ia3YQi0SUwxxfTCthiyPEAZVMhgQAM/T7MxLxDB1F5UFL8XIUSAHcW
K9y1cTCKC1ACdGJ7mdrOzlb70ItboImMli8kI5sTJu+11ebijYIQ1+w4DBjY
DLSSB7OcGMUEYy2xdt/jrzOI5Oe+zsXrpq/oHPdgsPIdTbJARTCKc20WFFwR
4ycibJgnBSTbBOmIQMpwzIhm0cc4DC7OGj5KYNHEUftI0NU7wrgILetuPgXN
C8Sjs+uXV3yJY9geWicvUZVwSJpvUDomQGfx5FaITkcBIuVcDIMkigYYEyCC
Xi9Cl7V25NqGfcvHWdadjd13K1MxNOyhHKRFQV65xNAjByVstyQwECdDsYdA
oSgDAB83LmJhXryxcREDo/onyyh28ECJnzgG6ms7IsIdwsQ9UJyDWCcsje83
ccY3v3t/Lzm/vPQU8xPtrzq/vPTo+VtBMB1M4LPWCu+blzZa+oe/qfx439c/
OH88QcmspUbGH/7I+qAyv7z0FPNjyoc1v/1n/fzyS/38y74fBKPJPXAINT//
9fj5l1w/f/Cs4lxXiXNXBXC0cIQqOh3fc2aK53Rp1Eh6c2Q65ITA3rLVr84d
n8R32fsHSBPBlbKBsInBxENiQOVwOgKo7+IsTdg0u8UmkG3bQFJWfYlV8E2A
MVdaoHOuIesmRjc6q+0keg2BeaNAoSSSJIHrSj15zZEv05EJd+NXSzJB+Q7G
kcR6oy9jGg0NeUoi8an/l9NCT9+QiCJHmri0reD/BS8cVCVpC1Z8X1767BfW
FwD/Y/HPNLji+/LSl4D/zwr/bxf+bxf+M1/4O+rClxtmnctddGPSolChkRA5
N6S6sbRlvaudnXOlgoa2eKjAUIzrQdu2E3vEced47Q1SjPrKW+WMMOvSLoc1
E9AlnZIMIGGO4bG99CGyXZt3cTrNRcHMyY9CA/4o5gWFWxXXRghS7hRaFt/V
TQuCj9WwIspyKFsElNFFhyPa+V62uaMaaG0Fk4e5eLPkE3aJuPHUhBNJWfCE
jr8Qb0816tsCaKpEFGMWsiwDKHCplJlKAFdvxtlqSpAxmVg8DVsUHJnNSQ6r
RNaiN4rNCZwFIQENJgHIznrC0Mpy0GfDthtdcK4KBdPaCXUBpo1jxB6HZrKh
xGOztKPlVHiriak0/g+Ad0DZShkikMU/v7mkYYdBk6dWYv+CadI3FOkaES/O
ACe8CPFgwomZTLNJmovpiHNVauyMKMb6HFBiqRJgSiHR+6WQaPLdn8lZ7ls5
G0T3Qo3fAmHaAPB5wgM1MG9yKAHcis0YPZSV5IXa1EBXNBf7EQWdkXEspyhy
ChO9vl0ivQ+E8FbUajjG2zCLStHKoU4ApMA1nccHCAnoeIkKxeO8y+LmmxDo
VoR5NLkpXyb68tVglNuE8cMEE5KQ/YjMANqMTj6kKBeJ/UWz2Ekf/doyjRqN
TkwdwDKGpDJQ/C8w0aRovmDc8FCkgiGewyzOlSXa2YQswsh4xPgEF5rfhxMm
Lw7GxSuHeD+HOcs2Ka3rx/Qe76OGtsmbiG/Oq9RnWd7filo3LcwqmmZi17PM
3UE4GND54oe3aU/qksuEaYfIFQQqXxA7BrRIWHyIqag3kuyB507b1DVdyUnS
JDOaNapxs3qNFKtzfhdpsztHMQMFbGqq3Ay2mCyH6JtBSGlXDZ62GwbbqChn
mZisKTDbsHCHlJX1082gQpSEwSbHAEo082bw6pJSSSn4jWLWME8FUafjLmRu
olYTNmrPTQ4SncXs4UmS4ohwZTqJ8uwCdejKnSC7xTdKDjereFyA/eWUCWsH
g8cJMsj7lAADvo02EzzHLnb06VUSUYPC94P+iLJjcwqppZicU0ycgwOC82yd
Xr7eVscrdyNBEKBruFXUkY9GFAXVm5UkGLFMY0jtzOQKYxYq0JHaFARaaK+H
u5DSPs+CKC6U7f6kj+H+o2hww473rZPTnyggAxCM3Pzt1fU2X3O09Yyi0xRO
/m1oCSa9CI5dnGac69xutf9CBRsUw1Q4LXEVfPavrf/5P51nXeZFYWkJiRxG
NnQOpOGzTmLT15KkTamEnIevrlmUJnSWUFwQr/LFjTfEtUAcRNK1h/FDxHnz
jYATJXoShRlrgnBcgRiQ12BeZot29qiltPLcbK+Vs8QXgUmVQLgr9wal+8p9
fJ2+B+ZgMl5gFqGUNi7+EADX0d9a8FQhpFmELqhEk2OT85CalP6Dxqx0IOGX
uGU6MW1WgSLsF5gTJqGZmg5obkLWL8jCBqlOTS/FG5r0/CZjR6VSWFlXrd1W
100VGIfvCUXmbGP2AsuDsIcqMMnNQpJUq1qmHktGGI/F4YbMmAQySaR1ct4u
hp4ZdJaNRdL3mKCNRw6gpjQutW7eIcKNPCMbZsl5hBPghSNnCT5fMZ6nE6EK
8XdjgKA3A6pchCGm/G1gBnGf8hq0fkiMkSN3ct60d28v1AXE13t0I99mAZx/
oMQwu+G0gG3LVe9G7dtXsL5LX4AUy3mdtXBrh7nWSDxJcyTSsx9ZZTmz1G1Y
OZ7fiFSTcapzW19dAp7DcQ/0QdBdCZ/25jpeTJZJmZGb3Hu6tGOyELMdWpLb
sxDLKpgSAEXeKt0thWyBuSxxF7B4kqLkVyJQAJJ4j9XptriBXUnEME/MNUPZ
RKK/yhpaOdOxtevLdSzZ3E1ABcGWevOkXlGeFEsL1mVvq45KOoFfOTNf1PBq
ZPKPVqpd7qrhzHErajil3vGiBnHen2pDu48blRV0JV26yNkR1PCdDoJWbxqP
lCR3L3l2JlPHiWI8aHUcxLLCRHP+DMcQH2Fy0yoRLe6Ov+NFinlBPa+lQxM4
CQzGSfnkS1fr9aqOi9YsRQoZTDMfn1a1VpBzje7DWe4mtpKAQJxfiATIdYrp
SpR6SvJSEt0HsgS9lbE+Sg36nuU2YoG9yLIIhHdpPNAnMrZUShkxt3BIopUP
gSjiONijJ8v5iZJPyBrjlPX/XEOsSrI0+IKUuFP/Prs0clyVDxvBa9jPvv3x
a/rYK7Hxjlkym2Su1VWOkLhr2lfltSIqGXJEvuE5Wpilg6IUEjjSAI0pZoPW
DxJzrQ+ZewEwFmIIHqMzGHMEJdrSCyw2Te0XkI/UKRn25hKPUxnT1z+93PZv
9fuRu9PV13x5qVxKRUQXRQUYDZ45olYl7aTAL2XCj7JRqxxGjFOykkhFhtLC
LNfcEPsh3IIlE10pa/L6Z5IxyPij5PKG3Gvqm02Q0MPRpiUZnp3o71QW7Ka5
HpGI1O3IF8zGxiV+eR/nrBCVgWeY8zlAq9XRtAS3Mk7AJ4W5iwkmuFJA7tp0
4MXPTT7vppVrTTU/sATFPLXVMbkx7zJ0RuqPj7Lw0DukRU9KfjWJpLx+ra9t
4gObmI84HesLZlNPkm8GFyev0XxzE4NMMFudsYjYJodbLJi5iAqUZ00gksxG
0yr1TOSJt8rqU3pMfa52xRhuQPdrWzPByT0fT4qZ4gFVC4J9rVr4kjRQc4NU
S53Ybxp2bc6LRHFNRnglhaZ2RpaOIosVkSlABJ5BZKwSYgCoVH04DrY622UU
5iaqvY15WpK1vtXdruJRVaKhuwyp0DIy+yRSrTUZM6tWLGSNxHx1+HyutolZ
tydKEddNLhJ+UzQ9Zz2EYgKD+T/Ji3FC5d3SaXFDKpsyYmCNBCAZ1ogZg8vw
blyFeoqYmRuRMdCJ87BBrvJjbEf1mo46r5ZQ7Du1QpnNeKDProbcAagiXOst
BxkWGYdiQC/hT2RCC4Xm8t3lva6s+wPrmLgG6SkqYu5FxUP1Zsr6fy85Piys
HlvPeO48QShWS8PCFjMl6VavNX2LftzWCy/r6vbFyNWJ6JpDk5V1vM1kjvMr
Kd/APJrixi+ERVlzCMmpzDVl4EGGoSGjaxymC+fQTqMqV87MZju4E43q2lQZ
MSCoo60t2v63LdvEPBvOXFK/Fm8OBZ5L1UksE8A82LA+ZfpoBJuwgXSJyymn
u9GAnRo3j88a0grOWBcgC1w56BxvHGVjYTu/bdoX5cAESFdR0gAiSPqOcaWK
kVol8FKMWI76p1LuxVOkLIjK4CUFkEIdSV85AR5NuqFLBMFpExNX4iSZ16iE
VIwLVG37Ca34KVMwmZplVCWPs2yoTr+2bwxt3wts0wjIewuLCMkn6qC/NB+x
JW/r521f2YbIHYojqolQowfDD90VG+FAPscDQ+DaHKuh3NHGk+dEXsu8r/WY
fNMbl3fNQ5arXqOM31XI2gJ+8c8oS7WthOP0+Gmqw5inztoFaS4PcqnRxmXD
tmtelPRp3xmyk0ldzJF/UbFI8kTS+3DvkBJGkjheqwlzJ1y0TonIHLFIIa5U
fEdLF1Rzi1Q6ey9/r6d8ac1YRc1Lz1yOjOqSeNm2QVUi1FSgmXinYjr92TMT
oPl1qmodijrgqCy2gOzdgJTKN0WuEOTOS6kqqPx6hKgJVSolBpuJi1xL9u4o
2k+Lmopimw7Kq6euUSb3l6borLpr8Fs1NZ0/O70I+OxdNOOED8tWbN+xJvNS
3Lnrw6WcngwSCOokNCpzTSg2eCvdCXmmWBu1UckJToL9/eXWZQtCd7dkIMdq
E01L4rSM6SzWG4+E+7ojT7/QRFwhD+LhlG/G5k3OlXEMnHbETRaF4lF0Nj/M
ldvI8WB4hMPS8dh29Wi9OJchzYE/zJUixkRQ8jNZjoWl1+F1xviW0i0tpYI/
HQiz3FFF57alz6N+ClI2YSXxFGYaDGI2pmAyH1mPfezbn0KV41VCiVg6z98X
DSMWTZcFyfjiHlMhKE6Mi5I45lVXVFFhXnTnqn6q9iCzn5w1TIyBqxxpUqBl
Yrdmmgm1A56CRZFYfDNFn40eQUqq2BVNvEyu4i4kno5Kk5SLaZL7UwuhNhpa
wbtkhAJFqihdGw8Gir8BDrNyjRsMSyhZQIzRQ1sAVLCGTRHlm5ZNeLHUnVaz
WjFuUtmAa7YM6JpnVke+LzZev6DYKuOnVYZzuHi5vPQc14rnZgtc+1mSVm15
QHDOretLRKQ6Yv3bOLpDuPVpz3WlL/suQMEAs9dcDqz0U2EFpWAfHFJCiGyX
Cwvd/CSLps2QnlIVlfQGiW1Ble7UoTJunVPLlKAs1ljfjk9DA0lUmL2iU4fD
X//Md2PFma7qfIrBU8kPoWXlRO7kNWeWAFd+SO1vVjYQr4FRrO8qossJk5kX
5IK5laky51D8RWosImUXex1v2aJlcxwDcNHSpbBd3fNX4UPzBCV3jEr7McWo
MwqUwBi1NKvu/BieR3sKVhW7hce5vBg8aXa/zB94P4vbLCpHfBHnug9nrUDL
Aqr07VBes1mCeNXnkIu2nKVW1GpZlFjS8eDezgaUrxWMSvwhxjjP3mBCCMuW
e4by6Q3ilW3WMYdqc/9Mfvry7tJmhhh5Cb+QK99sK94MNcO41YZBwiCa030W
zPptloTXknWNjUvufopYjSmqTXmxVQnk61pMmpiAN1zSEsMAb6ZxfuuopSYO
gCiNRBd1ZZG5xbYM5s6iLE/HMnRU8nsr848+l4hsHTeBhe/tkBlUWRVSdASG
RBxkERUAouuRVEzhrRH2zHGiWerishmPrAiQkjg0k5QcUEYrYLV6rErkygtI
prmiURMYKnY8HcQkOqOWda2dcxINCNNNNlE9ED2aZHyNayv0bQ4/JFOXyElu
rMrmt+G3vU3lCil/1/92sEnMRPBMlW0wfJqrd2Kto4HIp12u0DoHiPt0CjSj
/dqt4KQw7I89ZKWrmxMvCSiFYiOUGcgZzpLwTjS2hFXxg8jhASZAgaJhfj7g
8fmATosPeL/W/HzAzXb+Rk5k/tz40NQ/1q/6zw+eL6pP1f+NyV6aH30ow9bB
/7ybwH/+/jdGWCP4Qy/7TnD293+jp5zzSn+bar1BaQJAMI+w9f02/LmjJ6j/
+cA2gcj8bZg0oQgzfarUbhdogc8CAuCcTxHsti9T11V9ati0Mp1K8Sy+ErWq
pmpVS1wGKXVhMhOXvaUXk/irrqpKIXM2eGkGJ4oUwjhNYu3WKwkm1IeDIxaN
bdh3lFTLE7FUsnYgb1qmKafYRL3mWu4MEEs0vrLti+eHQ/w1UuEvg1M5nlUV
uI+34XiaU6Fu9A8LqkvCLE4B7BI4ASoqJoQyLnJldNHqhuksAIs4ZKQK/oii
RE3tRTdxkghLt5FtswZvCojjQgYNXPeY0Timiu15wdYfsTXO3dfEy+7lZjCB
KIxizGc7vXz9gjkfHNS/7P8f7/8YFbfthncYdRmGnuvjNH0Vq31lV7nP0qdM
7HStoZm8coSkj1RJaxCDsidwU9WbEbZdHm6CBYMGtqlWMCUBle1eu91pB5t/
2d/c1s1tlLnYpLNxmKVIuUuM2WnDmIjITdQBbN6/kPkbPu9weIe/L2TwH/xP
Oix2HhPf7G/i76TL0VdqOxgSZ5ASo+66jNrwZIcbq0H4VFcGsSB5/8dNxMnV
91udffwK/cEaJ4ah2/SnGbqib4ygdTM1y0z9KxDgf1aHyfhCFANiMM9FXhM2
hmof07Px2szlWpKewSG1kpKGPZs4pQ8EE61PmQGJyen38bxrQVjFnVECAnk2
aLBIC7FWcQYMDsL8HtapMVUUxvm91NCX1wQy6XzDLj0tD4Oci3a/oayL1qhH
pjOQYhhSQbyEBVguze8X0fiUm2u0XcoKpF4keiKRsuEewvAXCnU3aUtsYxuA
KLeri/c7vLH2YlvC1FrR7JYvE15W9pYvFS7hhvikCTjFHiqiv5ZKO2HzTLpc
6xU1K4VTxR2ajDClYAOvE61Y68CPDxWTJhoIwPxAMSUYYX1+J+OPivcn1Bcz
1/5GkuVfXJw51j1j1Vf6Efc9CSsmMGsVvgA9JzivSgOLy6KX936p0ui8gWbw
RVtf7SLKF682xyhjPZXsYmHt9PvLtxKxUURjyQo42sUqyHTodCo3txPDvgJT
OJCnwEDJdkzSYuncULFYHzDbDjTK8R0m4Si9Saf5aKaOqj5Gxsfqlyn3Wp22
PqPaQG3Q5u7C0yGQECDnWga3k95DHSQ2TcRGjUWobyqxCzmuoMW13A/ZRfUE
iBPA1sbdbzzjGXnGy5QzcIyGqD/xGwVH6muyDOq/SuZBwRHfjBLxlxdp5hpo
v7aNeE5Qla2DkcYj2QZKsM6XCQs0Ur48VIrS4DgEIRA7vBXwaAIUvERhfT3X
0lptqVHGp7ethrjD3XgaY8+kUWUGoR49vsrvrqIR6FWi5DhrY76h+jNgD/uj
qnOBadGULwJwNRXDwJd08zuTmKf1IMmJjXOxZkj8PbEneUScOcCFCImmt55G
oLLmFrwD+qw/9TGv0IrbQ0UTiNtAhVmi+6iiBOwsSrVXx5h+hXXsFQbk9LB8
WrKY0/FS7ka6jCmIm/ikDnotZwzMTxiors00R5G4V1xeTYMUXqJ5YwkZE3uq
KxnBLqAg6Zv9wi46O0pTqj/AWeQhWrVjE1EoDStUDjRZAvAaU6eAn6aZpgmm
S2KhPSdITrd+jHWGM1UFHuiIe9EvYNyJNvPQIZK0UgvY4lb3k4bzkcwsyy+D
NQ+SQQS6kzRNKrsNqZeUXStYASdeT8rTYgOUnTsI0yUUW9fgposc8RnC9d0+
DLZg0wLetLcY0hgNtrHBEj0oQfHa999awOPM/tdyNNEwv3SmxhLuAzrFY5XQ
byxnIyvcGMg6xPKCjPfOvqZzxTzKSPHng/BpaNjMy5xvXCJNqCZ5ymNO7Yjq
Tji1JOLDTc8tca6POgd76lyHir33Q33GAhN0qimMpF04pSNU3yMliqr0CF6Q
m+6AgKGwiM0VdN8fvkmkr6A0Q3dCcSTfJkpQi8/tt2AM+EcFpA0BstuE4l6G
5aIIaUClItObLJzcSqq19Wo4ArahXjUAK3tjTGytr5pF8GKI5Y05sbjAUw3n
ULUAQdIvqL1aPAYsJ9IUQmqiLDqRtGn/6ofROol2oXOK77G2kLu5KeO3SAnS
o1gdRgsfKF2MozCRPZ5gNirbxfvpFI14ZaX0RI4qE7gnZq4keFj+h1LmiZCh
9ipGwKn7LEGpYtZoZQIoYq6f4wFOjoOsvRdxuvoN2d0yZvn4/Th8iMdTjGpC
kk51jh+dJxMhmyCkTeUVrjIJuyNZHa+wu5Ixy7DfWpFzWKcDeQdVXkjcw6zE
AYyKogZlTYpP46hhjluwmCby8wkqtWh7BExkRXNEF3w1NFurab5REQyaXxzw
JKmZVDjNTbhLtE4EykLxTGO59eSGxITUCJc6r09PQ3VJ5F6XUfPpBON0UEhp
cFjCCM2RM12xKI/RvxQmEYacW8BXRqfCe9oDD5RBhZfEXa6iFjPue3WjOx5R
WSBlHUUtWj6Ev24wnbyg5zOV8jp0Vs0hlkYomQveIrZmE9Z/A+XJXq7wNY9+
pFSoCiN6Vg2Iew/Wyg/Uf1AECHpyNQuatMqSNoZKqLAYg0+okNprdgiNCu6U
STGaBsv+IBuIcOroIepPCyvcM5yiLllI+ju2qoM7iAlbNwrjBTHr2useoqXv
iu8DRdEc459zcS92U2KIK7+oqJqCGrkOj92UCU2qDavk3ygsClaU9Vlk/uZp
QaYaSehi3afSEQHQQUxPJ0JkVnFsoKRpRjTAAGqktOwN/CI1V2+i2bnuKOnm
mplOk+SmC6gBZvMXZEXX0g0uL2V5VnphzmFQYSDtNeHsSG9NwZnlWwnIXa47
caJDsOl5GK7EA28fEwnhWIG7XXwyexruOK+rIQho6JU23KajOjgUr1B9X8gN
qCJusT8L9vsMVBN0ClArKJDXFHV1Xm4F3+ORcwfUldyl6XaqErJDzN1XS0sw
2kzVwCgwrNFhgqprjqp6yhzxskd3dD3VpPwAtVpCItjf7ZQqF6ohVIXGejP6
M5RfcCuwmXBnJT5y3InqlyJ8e2uHg0rQt+AESVJPxXEsJU2oGJtV005y4nU6
fKh9A2beASU26szD+5S0b2JHd5FlAQzFooJXwTgdKCUMbgU2omB8UKzCkeTa
MNeiVfyEncV8R2gpTgmiamu0vipHBtl8nFHwvhEazZ4pb/oDiO7SoUr6wlaq
qFmQMEG9Tpu6KEEtUSVpU4GkCeto/8AirNAZSDgLodlpSmCyU8YhUD/IFaEl
yroXa0vXhy10XcFcFslEqBJSDKW4lSYXTKbnAWmULk4KqkTRxpXOjROlxNme
raiKN9XgX71miogP9ZyLmzEzW6/trWxLH7onvNXVSWQWJAbdm9RUIlqxXSpX
7CIlRrV2ppKxTPP+WctVoPCupCHt7pdpVQLV0zZ7ca4rtuiaZJrSdF4Vh8io
uDbpNWbjX0Pgl+MAOzY6Wqo5n6BBNT23GrTIi5e2qVjVgKSYbSzPESK/jG9i
TrrzunP3TYajNGo5sauOq0wsPtmCAVEHMdulh6yaCGfw5B22Lcs+Xjk6wduz
cqsGp1vefBJmYpXJSNu0j69OoxuOwhuum28qQFGHNC7NWOMI3/U53j3LZaYQ
UYnmURQCFLlVcK8XF5J4SbKYHcypLiJnvdppoTvSKNzQKqRNIEhOCVCXdzoS
pljmB6KYJiofbu5iPcEZ1R1TBU8f6qZesFJ1LbsddNQR0VEMpSOEz/ChHktB
JIezlAx6h8ssZFsSOrSIjHNwzkI90DZgIvlYR5zcMBreSRhzYuUyIB8tBbIt
x+vrUgasqITK6SYQOwvR7tpcAlnl0JBAFpKyw/bYuQRT5isNwt9tHQW4Hevx
7/exaQvo5EWofEy2reOo71cbVerDvGC2yJvLeW5eoiWDCCvOusaIRPg6U7nB
/JP4Lth6gxU8QMW/cHsS/gw4SjOrvA+XqBCaC/4YtBuYX4pDxDqJl3oa5NOx
Ohb2yrRVD3kAjWYKk5ZjkHFUwYDqURoWWrC5VRxCk71nHzRMDRPEjNVWsLMD
MqPNfNPOckcUmsByWatn7vfeuatzSiFMkhCNqcR/IVJmtt2lJWgHnaAb7AS7
wNP2g4PgDzqsOVCFBJ2g6O82vmmW/2/RzzcbH9owUfvD7Yf3HwIY1wRJa5L4
OdhC018y21ZRyGvNU8ldWfTzYePDH6ibDTePggV+UCgQGx8h8t+RTgQD8A48
L5/TNbOxgXgDTNJ+4yMyRpDbOPxuo7SGmiXVrZTWl1uI+uCQo/6cP3bxiV1/
PjzF/Ev81D3FuPYgF8DtFw+K0GgHyt/TzngbDDlCYamtEJP/wqbPzhDN99NB
mjvSpZbo5ouZ+j7ziSLKXcDc64nEKL9EM9CN/pj31UsZcIdZZQesDFiRq0q3
TMMK4/AzQ0V0bALL+ZpUWfBJOEb33gOxrCTl4q2ZxLwQkNmUc35o8GgmFQ2M
pvXTu7PLqyWM5S6maF8eyklL7gVF4JSuIBSBMe9aFYQyTjHR+UlZHwBuVN1h
fIphtA3HF8qFNU8M/aeC5MHweN6zqpz1yG2zNkCnnNfu1oweTkeDf7d2TGna
q2yb7EOlEoK7D3qisjgw/6xqfZtE0ywK3w8wks5FqXIlsBAzzRYKOPm015T2
BErI8VTcTYeCS5NhBmLJNA86dskubs+1ANDZowG9nw+oQW8V2AWSAegKAQjf
QdBpw/868L8u/G8H/rcL/9uTK8+VGvzSwqL/eW+ezof2B0eCaM/53wD+5xMt
/FLFWvAsdRMuuhPtG9H64cvPNzHejVW55LsPG57BKxKKFlC+C+xZXSFFTeTK
CouFL8JJbgsh/OOVUNTq15ljRbyXMTxH8BAMb7A4Rw9rka5ppLpgHHwjX9QJ
dgtXpBbyUBZ7+R8+os5XFeFtmTnKgtRD4BOveDZaei2Zwn8rDIE/r5wo+RxO
6z8/9D5M8NUxL63++VqU64/vy0hfA+sW4mdexBv2+Ejc+9E/86IfJn22HeD/
gwfvF+/AArHf0Sm4iWgdXuYd1A9VtCwv3vN97xXyjZCOJYc4TCgIy9LYvF7h
KTrbUA1XkRLKXFRpJlHcetK4pX13qUK2C6OpQMIVhHSnO66YlmCI35TNMCjH
x3k/wjjl6YQKm5LNlMvB9ItgEkdS+sU28kpJ08rUXFSZDSKUli/Gj6pVw5SW
681IAmHvJctRypgSKfmdpRbzsS0oymJh8LIr1+ptVrbn6oW61T8rNc6d2BbL
sZPmkR81lMtrkx1fjL8rX6elT/iKKH1Y/ptWXPpsVvpbHfPq+IvdG8ptocro
em3/Wv0kkVFIzF5rw1plw10f75Z1HuEERVk8xsab1NUm1uG7K6rMXoit+ru6
QSLvuoDtmZ70KKuTIFqjtRFMe0DnU00lrK3WT9r7+utHhOOYmoul7hL2QbON
eLFVeFz7NIzg3i9QE1Rle0X1E73C9AW17NCq9LjWfGLjSJ6k2LnJeJPLTuSn
QqHtal4fk+RrRL/ASArDU8yzMXQ+1FAEDwuKjVO2F7b193rG0kio/Br0gE4r
l4dOe4ma4U0WSXM9n+HAqg01tnSyshZqmRWqYwMr66mun8jACl49cTMdHeqU
oSJVsEermpTm4qT+1Rz2axJBvW8/dktrPb9vX7UTaTgh8u72aoxLGDBHmVqB
nwEF8GGIsSIEoWJECzmJUkezrtCC6YFn76exEFV3VSL1nQM8+y9/gGef+QCX
LU7WybqvHuLZbwdrnYOFCM9rMO7Qu/U5IdX0jVbVe7dMJUY/71c4lCxIbJuw
/cVJCDX045g+8yeQb1QPXID7ScP2y4k/KkDU6STibObixidiCX5U65N6q74q
1iEjqxtyfmOU+mt8Tk8Ub+zxci1PQKxuPbTGn7rtyWJfiO6K4WzwPClnMhKr
sjncpYO/+ID774Z/5QNe8W/8yx/yyqZ+joNeRmvpsM+WOuz11/3zHfZZ6/7z
HvY6h5v/wNejyDrwlVQUxtPJm+BNOBul4SB4FWbvsfHKVxP+AGQO/OBjuXS/
SnX1Cd7thxdYY5EH5PexyE0lTYRQqgNuTcCgMjtQffRS8X5pHTmUyi+laYxM
Rs3RkVWUSv2H/rQF4wt2UmZsIcskcwjP4y52PMfirCcKBjIxkQK3xVo8WDNn
tVf1IFttWXR/JF3QEb9kC43nLMDaL84adWdEm5JL7d0FNAzvopAodLRjn4rI
AoRz3lKK/dJA4Qimq4uSR3ltYtKsRYDuoWEA4EzEZEZRw+reMb23MBVjOo68
JUhX3eWFO9yoBVz2QOHFbrmpQ5WlJZ4UsNbB7NS3WRXkNR2CpT21vSyVOKZG
4IyxV7r72I+mOwN111VNCE2tIDU1YE31MvxIpixRKfAaz/tRAvdDaiUNqKVR
6176+PUPvwDzHUSqNgnS+JtLK4WFkvqAPi7Qqp9giyEpoKBpNh7DtmGjKUw0
N42KdUAgp+a0rBKsJ2+aXO29yflKtrTgPea5SRNSqxLnuu0vQRcJH5Kg43pS
vuFnnQKnxn9ClU6Xq24dVAtcq0+dMtfqwyskcioY+ve/oVXp7/9WqpCqfz6Y
/y4sgV379ZyRyx8CLog8CTjVNpzroqrCpt/H/Ns8XKjSq+6nVhlW86HvfQUF
tXK1nrWgOLtH5MIp+KxQSM3wk9OfpGD426trqhZuPc7KPn9dLR7On3NV2eB6
DhT03PVPL9Wwu4G7I+16TDwhLqgTq/XsYQmKv/8Nu/4KMtB5Sb/stdp7SOOr
4OL0FP7/dA4uXsGBFig6+yVcwM8cXGA53oPt8qdWaV7rUTVJHRSlmu82dW7m
RVhM880aKB67I3b1YIt1mnrwtF3sArHvxFKTH2pi6akprG4N3ZChIvBRRxWR
XYVToIhR7eEp6SHdPdVWWDrUW32Qq2VhqcQjC36U7ZPfZtOECvDssSVeJZ77
mgnjdHpnlOvX6nsh9bZNI1etjOpNW6PluYxO6eqZHf6vQbE9iCzvq/l81eU5
zZUxzLvW0MUsqU9hSEcHsEYsaosCCBNqqZsFU5DoAV8qAwzlP/U0qmxGHKyJ
eRPQrU7HW0dO8wohDNUWz2rBKNUlTK0IKgMpEnsSnFiVB644GVMVXM6tggZc
xpK/twYwsoMlbat30NCKwnzPEahVLTeiZ85Hz3WmLp7wMblEuQgllnWn/Tng
1fIxBWDaqPXoGnAz1SdWarLR5p1+e0bZeFl0n8WiS1oILDDos7CUPVw2F29R
OqmTJ1kRDn3y5caGykuMx9wGKh3diTaVpcAextSsZdn0SEtxxyFuUlh8TOPe
ojwIou+YLBW5aXCVVoVwnW5aYLl7qoFlStI5tVfcYAyVPaJalXFDr1FcuDnE
JmOrSFkKTYBI3mDyILE7KnORBJdTFM0FPU7X+fILmkVs5ZiLin6pbTenT8oB
II0kGPSQhxmfM6txZWV5LjZxBGtISdsEPoE1vjB7S+9RQ+oxxQUX6BIewM01
OEbBaF6UdJlLuY8BVgtKQpPWzzhQRBhSBR3ihLfoGdW9efgQ3WDX31JbcYK3
UVJ4RaevdDG018c1CxbhiMvdhVwLin1YKM5Px6B5YeUUvhAwEiLGPWumuB5u
7FdtVVzpCxhmGXqIpO8RZ1v1RyG2clBdlYdGZbmBh6kgsrEiFchY4Rnr0PSc
gCMVe81RLzh0cH4cnOtNVdCM0zvTRLJEfi3z7sUxqVRUCKlplFTTHatkNjgx
4eknThmZM7T5bZ2cnG1z6LhagOy1nrsR9EAIMC0XR9EQ60UW6RTrM6ppHCqy
wH13HLxLPGAuN8qJ9gDm1raYJxXuiJXHuSfhypcSNy9B0jbnMOGZhqAu7dpH
vMbkQWWxsLGAsNtKuiO+izU2gRIU3k3hBSsGLwjD/O7GF1ocXKqAJCJtQV31
STvCutmsBkx+U33lw92H4gPoEx+45xXKuuamIgFz9VlA4G/5phKZcO6Pd775
P63a+VTzoq2L83eOoO+ZpVUPU+uxT3/jR1TdlrDtqR4TtQjxDjb/xzMLv6Js
xyu8stIsi3bVsxb5+bb8wd/rHq08Wf+s59Hah73PytPMssRGhz93NbDhF5r9
bpTPVPVQmRf1udvQhxfL8OL5rZxe85Y+4EvMRQfKnYv+25KjttRJlsmtU3he
k4ng+2nVwdDUMJjT7R7uKjXKiYJ5553b8gc+/vYNjOCGgc4bwXcs9Nq93KA6
QvUcouWBOUT9YpaFYZkR/GzLGz1uCWeOAUJR5RUK8SyFKSza54U6kagzsTCN
1JEErVhYqZclkbDq5nbmu/XM1xJjR+Q8I2HW6v6VF+koYRGSeDCIEmm3rTTB
macVPWWgltpT63Yau61Oa6e1R8NY3XukcsG8+fWkJNGQaX5IdbStPuCntyz7
Dq0C27nVbl1XXlBeNrtPeLlEWKnpxHJwvTi/Pv3RA5iUkHMAU+3EK4VXPFpa
HQQMW5+lcCONqvqmdgCAeV+hQbl87NoCVZ+kdpixoQPNGY7cLZK/tvKc5Hna
j22R/Bxl8nB0AwAUt2Ol/+XuWnW51zw1lVGbugiqV9zUnQHz6orRw8Z4udBi
tS7MaJM9a41cqhGFVpB6YeNpfFX4F1/Be0chxg051xYA1EtHoykXmrb0uOEU
TojlHCtnaMMJ2Ot09vkEoOPNQBBLzLvWrjS+vqbChLgFicnPYA3JbA9+fh3e
WFHjook5bnQyrFGV5NKeKFNPpLeYkVWdoSFNtWE9EgSAZD9NjE2qwS7FBJ1s
2NHe7ibYT7lkkNE5lVcrcMWMJS70JSSFZcWCZS//Za/4uRf53Pt67lU895bV
F+i8p+ynF/6QN0BTqK35M2nph+wf+9bTt3z5oW88hFV5qAampVI8nQvcOpWl
tC8hl3kZXWVHMtVi5LZO0smA7Mn6a+ArukztnOOlTdSGHblMRgIFzBuNUndP
XBm/0rTOOBb5sozVxhbsUfLRSkcsQRR5y35jn1krPCK03qZun8TEVQSLLkUp
g7Dd2MD27ZkdXlRnJ3CtevN/BGXrqRzrKh3rqh1V4Xsd1cOvfKyqfngUgTVU
EIJlDSXEr4asqojUJ8Svooz41ZFVFZLVYKnXUFYpFbBUYSKLgetP/7AIED8n
/uD91f6589LgN7XvVZ82BpKaKSqtcQOb2QS2VWb5EWwZyR6hxsyx1Co8n9aO
oD/e4K+YBeoVLf1eaR0L37tbGU4nwmgRVNUPJFZp9V1yZ/YBsdxeUdiSJ5Lw
g4OJ8rHwHd66k2qW+XVl8g+2CiXHsI5vOPCU5vfBU8fFalZcBa4OYR546sil
Fmcl/NRO4WNXgaHvFQHzWnOqIlNJJrS/OYvDG1A8F8iHJcGNynaPyGPDTtwg
j6h8ejTQLUY44awiWMa5LnUbJwPOoU84n5dSpPICPdni3iM1kMvW26H+qtkF
1s8FVUznQVhskmvrKgnU4jb0RSv4HkTClNuKNurg40LcNIDkW6tgcMetY5xC
J7r/c6lsd01gqpQ+pbYuIfsBI6uaLMnApdDvjzrYGyNhlRTuF0Z9y7e+1m1M
yPl5ooN2awajipEl/72quOqGUK8SOB0nk6mOVUfjisU/5oRQVxV/O5Da8+2y
4dS/s9zuFRQU4XsudyZQ64Nh+XpL4d/S4aIabG7n76hjqRnD9mIzlr1jfnBX
3guOQVgplJ1nrtsHz7e1+1DBQTm2XaV4VEjaUbmITJ8p8H1FEK1z9MlAfLrY
/K901LsnngkvBau2ua7WRq0Q+SXJJv7h/NppiheWWLkyJitDckN3zxnopg6h
RIw1e2GuMlBUp1cecpROB/a3HHfG9j0d6IZ6vAlLD00ElH2dkFV7DjutY6Un
wWA61nUF2OKR6xUncGGiXVwWRK9/o2NQOLwmVH1x5FveSvs7VVFwhA3eBqpD
oSyP/Si4AXkRj0NjgFf2SF2QX2dVNHXd+EuqhIKme5fBswnV3kNtl4EPm0U0
npAR2JZCLkuW+eONP5Z/NtoPu512p91udw67vd7B7v7e/uCgvb930N3vHOwe
4L97GxtsZzuWpzfaGLX+c5SBOETxwaeXr0k0xmHgn+ufXmpJuc0/+LF0xOLQ
506wCXBvbsCQ9PUfg3E8gD8Ou/BrgQYKwAXbBo7xoVrYRHfvdI51dOjGzxQU
COMAVjA+appFGxVsiEX5OOgccAKZV4JTyHWccbgNshqK8K2IRXbTEWYG7tky
mweouz5//agN3O/s7vEGDoc73Z2dbnt3x94y/N7eMiyHGJyc/lS7ZUQO8PHV
tI/y43A6coOMg/2jYLPbau+pdc3fRvYcv3G45MaG/I0AGqDr96g9Z49sHFaj
tpNCQ+/YWA2T8QsqyolXEjytlN7QG+nHvG5MAdp5WYbUzTp4tKZ1GYlAOZML
JLdKnVJnyV0fc9cODVdN1cpvG3WWlTJ16hN1njMzpz4x58kycTwZF3bySae0
gOfL87BTG/7+t/2jRtDZ6VKyy2p5HXNmLWdUBO5aNy3GuPmkGRR0jJp8tOQk
llRBT4YEc0J+1TqByHudsATj4Uh7Reg0bFZ3r3VB8jnUoQym36dSi7FqdeXU
47VvOU6sdq6imFhaSdmHMtAdvu3+fOLj4Em9foglnEyVn9ULiyoCKbsxlntr
vbngVujU3dxBsNVRzcieai5XxkBiWPTWenPRT+3CPCLJEnN5hJa1IVyPouaP
OffbGkH9EUPelb6ds6Qy5HNwVp7TmCvtIIiaR1cYFcWhJR9dYVS51P/Iw29x
ddlt76Nbr1OfOrn9GABW2IL5A5UhKFmbFjwdbGENaULC7vbjKWzFsyIrXfFc
ftBv6Zibf59ocsO1hF17Q8tvFeENPdXf2x1Gnd7uzm736KC3D+8celjo4yC0
4oQYsOqkR2rSR821MuZ9wr9XbFCyhznR5Tve8o2gDGFrdPX2d5XKycVlvMFv
WNkGe/8ow08o3V5N5IWByS2GwDVzKURCKkpvkU3aKt3C539boqXw0JjwN9JL
srtIyp6Zhj2c04QWhXRaoLEUQZpJCwaOr2rSJAVGdLGXIEwwjNHpPlhgNFbJ
RKgWPZ7mJugxLnRKbN81cVPjDC5yW2pRTibdsicjoXJ0GE2nqikUaVHRDXEf
prnbHzMcpyC4OZEyKvVM9fhTeXGUvIJWobg3LawO78pWg7VLyc8hJhv5WpnG
WvXSq2ilbmCtiJ5lsbVsH2Bs+cy1sLUdar+BHentADwOvqHtI0F0IpAbM6Pl
GMACh3FO9D3mrty6TfstwDSI+vGYDNCDyEQ3KjsnlhaibqLmK3UMGgG2DEFr
5zw64tXpzVXIKKT3lWxmTmN8nTuWN8yxouXN2ZCnELDXEa/XEa7XEfBY2N3d
M9YeuBL3K9fAk82zgh1o7XnwZzgsGYmWeGedeYJA460+RedR86xDb/NHnPvt
swjfK6+BzE4r/nzYmCeBz3lnnXlQaO4cdY6O2t3OYXuJI7PmPGQU18Eny76z
xjztHisBcRE4pRtqBX81jzG5Bt99B/fJVn4bDyligM/DtjuP/wdm5x84RXzV
PGo969Db/BHnffv5VI51VPP1D5gN1xzlo9Pu7w8O+t39fr/jORj8stJBoqMw
Gu4Mu7v7najd7x75dJDKzI8Cu6SR2NBWgensWsrJo2Z+zFYtp6qIjLiyulJx
bCyIGXKDbuzAbjbb0gNstgV5Nc6pVVqDfZzcZrav5Dc3ZFa5KFgIfqNiL5qG
p4sVl3tG1z7kCsugl9g+XFfbyIObKIk4F0YLoEqQVs80VMaP3YnYtfZi/RYr
IyapWHlzdvRaUemSFW8VUbT0t7s4nBMCImH8pC/4cC5O44ornEejXYuLiAuT
OPK0k3P0ZEXb1CGg2m32n/OLuBkXUcUttIpLSH4+eP6cV7ztg+e3ug/oQ3+R
Ng1w14V/QdE240Zh14njrPEyGKcgmVMbrW528t54DYufYnbyWHUDz88jZ//p
ZWm0Xc/sz4V510MnPrrK7IT5Z1j7crMT5vcPg+rP42YvV2XjCnDl2etLwXEJ
uE4Xu+eVyr7BV/Azd/ZyHsqHoHg/sv+0Zn84rJt9j/oKV2a/vq44f9zZ7UZD
/ArWnSvPzifuoX3kmf0xmLe6IQZmdvpqq7ddnr1u7bv+tb+Bn2Vmx+Y+i2ff
39nvg6ZP3+7v7UcHbTX7rnfff4KfJWfHXoZ1mKd97339tQeTT4H5BzOa78Q9
8+xcwJrGkAr6n3L22Wddu24fyGufte4/5ewLzjtx2uebvXTeP/HspfP+nLOb
kBBLztXJD64+4gkJsdWnN+WIbk8YnAQydjkO7uiwfdTeZb5FHGt3OKy6sTa2
ukpVLEU4dlePcKSgOif6oBtsYjmJ5UMcjw6DMtjG06biHI+OZTN1kCNeTu5b
lgkC7q0/IoTUiROB4IaKMKTPTnEbvA8C1xbS3sWmi6WHHRCpH+DCGL95XkSv
slynS2pdWVMFqpYeCyh843r1noLG9ju7u0Jj7eFwniECqKvjoS4cYI1gTHyq
3gx/SGb4XVWoZAWSM1EE9QQGHGGJDV7SKLP8XpdtI0vst8csUt501dnFaiya
p2NPdpQK4EQTwDSPAOuNgJOkuGosOxpNBVYJ+0S3IVbqwEKowzS7D7OB06SN
S4BKJKfyv0oV06EFW96QRmzkw0t0DxfQrzmU3dTQRU1bQtBVGw/d4zUP0SNM
UHHXPfLKTkdUneWOaseMooe4F4/iYuYUpxGE4KNzm23dptjAlAwxOYyYkdsw
oebxoV1b3nLRBRfYgL6wCufbIGPpWZoxQSFTphmH+fsgHbI9iMtP3gJqm9w0
hbFeKrxrF9JFNHN2lNp3rihAjkY2/Ci7i9PwM3ecxmgUM0V7eTF21QOn8Ygm
MKxvO6N6vOmIAr8HWFpmLDtrKmQ6E0sRHxQXuHfJiIr6wnDRaEhFZDnPhWiX
ZkEMUTbQUBI+NPqkiCvK6XMohbe6p4id4psNdedW1zon9XAc83EZUtRl0p9x
meL7hjTikdYRL9/8cvI6gAN8m6Sj9Aa7flq+a7ueReEsG4mBqzfz1OFDPJ6O
g2Q67mFdS8yloGkj+ci/YRQvrYjvUm1X6VV8hDsiWxOZToVqf95HsJlYklUs
gFnUhOsF6/Lmt9FA9o07EOeqWG1eSfByVSBe66uTv+KAno20to6iS0vdad1h
eCPJRhmaoqYlGmkEcijvb5Eq7Td7kSm6E/b7aTYgz7uCZQlGJImUMPIgL1UP
IxFUNdEzpmmyb8Kaau3RViJoTbivUxDLxFFIlkW9ObreCO0WTNGVnV3Bwbp9
5ksO7U5n9/Dw8Gh37zA8GvZ39g/3D/e6w/3+rhUHu8FBrGSvJRGA3ykVMyeH
niWSeYbE6A/jz9vY8HgE4dLuscQB8gWNBrJCULxPqBEYyRz4HzMPnsotmZ3D
krhqG/sX696iLuzz39rq7jB9Nr8LBBNMbhLDsq0FjUWCpGc7TArJzrwUEq+M
aaVm1YmVHx9BDt3O4SAcHu4Ojg53Bjt7g+gg2j3s7/Q7sItAFPv1ROHz8ArK
5w76ZjmyUFQRbB3ojZGYNHdfbKIxW/QYUbBeAKzZDF+Oz0WiM/3KPafxJIFI
l0uKjUoPpGXdI7O+V0xQ5xj0ZiXpUG4pb+55roPf3ELRY7c/EjNWK97MOOcs
t9zr9DLvKzY437nTXcG5s6gjz2dqwfOZeu58svY2rhH3k/X2cZ0WTzbtojY6
ny6fKqh30XyKaZ89j2vp/jzGG+Ou1t+QZ453xnXMsFum3htj3DBLTLvQLeNm
rTl7+3xpaxajda4bAou4MuZTMPPe9lgVriU4u5Z5q4BrzepLEh1dQqV6eyr1
uJmkusynVUbfSL3eZOKat0QuXldq6XZ26Z/gj0ogmSdDkDioDUzzhLPuEinY
ZkWVZGxrZHX98matL59126HOS156xbRka8VGJjI5znOwsL9kknMNJpQoNBcb
J7nSjvMoksokHM5NurCu9ICpyMi13AoJYa4kqAG3beD8Z7tQAmprPZxT5WxL
g1V/r0Yuu5ylD1hI5ytszmOdjCZ+ixVd8NuPpVIXXOs2D1BVm1/8kVpXcBA5
ogTLNuv2QzgtmvgG0WSUziLJ7zTyYhYNyaqQWiKfXfJCPpH2SmFuG01Mk3nH
FrUAWNXYkkN68nKznHg0Y7uG2ikqzzQJYzKH3KYT3VcKBh1PEwVL/xak2RZ1
ttadyKi7FDeSiXONAkMDiWfB5kNes1gKufOTsrmkPghG0Y0e2o9MSZF4mHEz
FVz2UiPxEtQIDnhcP+UXOQbn3BnoHGt7qASCuUTXlANkmkShbhHm2hwku0Or
tnpDKeisxSl06StAourInIydzpCUJ83erAn/NFDryCI+gmliVywgGkKSlYqw
XLMrv6UzqbFynwbh4B8hXlFEFNU+P6qb61Q6sara0b0ISF/XX8JmYkjYHqo2
wW+qyIXdt6o3k8ZyjnYj4McFA5yb8tIJRuEBpHDU0GiuMqlVDR4fAKUS2w07
Gs8qnELCgBzgdWZBVJzTISMyszr7qn43Uj7IV69pVTRsoV0+Tqd5GcrteVvB
zdsBG6rUFEE6Z3/EeCkeCoz1XBlQHyq3F+OS4Vxt19ad63cy1bzHnnk/67Zz
wW4Kz1qTYc3jVktzKmzhFtU2Y94uG1akGF7LqrBSZXDWvKG+VJep31zmh5X6
gstxRXQeIWf03dHY040WkitsWV8hVmAstfGERHmq3D6AOC0AoErwLeT1Fir8
scPzUVGuqPgFXRAidOVztlld8F5jWum4+Tfdc+iWYUIvNOUWt5V6h6Zil+YA
XGjQFB7RWZHqgAOiJ41FR9tFSU2oeKp6cbrF2n2lDR38+Cnhie7a9Tj3E9y3
dRgrSc3J0/Pup7yLl9p326lX3e3f7uyFp+iRNLH0AVrzVnfoYpUlEns6i8rs
qZZSFrAp4YDIb7lZ7GrQ1JfT1MrailxzPTY/D9kWwaoifN4rBo8nhhfo8q4L
5DJVijPXevpCowZIa0p8KtswdEW3yBp1kTFD6bxYh45bY4fGnjFTkSP0NXXD
VUOTKUMdT/LQs8bPFQBMCx1dqE5wwMFBKLdh5TpsJ2SXG+aCoLaCjmIJyo8c
8yHVR19HlJ8W/BAW0X04C7Ze//DLtuk6GhTTLLEGUdvs73JNwzOpYGRVJNtd
0w8bHxQoVRRIyWVn+lpHAcClOmgZ2RZzyVS1Zwf/NoK5nSsOrLtoqwlQGiPm
SOU9hNIEJpT+wuwm0tUrPMvYkibkRRYOh3FfIw67hEkFamtEwly5uCuBJVGD
Gq6tQXqfOCPrUtQNB0Zpd2wVfFWdqWsgdt7QppjfuZ2/qQBKU/UkF+7hpZSq
capuXmfDaUpXjsWtXMqoNGdwddBexu+jJY6Ln1yAvvrAAJVxZ2mDoCqzHtP+
IiO5487KKoJtwXBWKM1wmhW3XJyOei+rKeQAqCgbWqHWAEsWsY+adeR2nBVd
UaBjTJPK7ZTbpFM/x5ITaFo281hapuV0bwUXiT2lUDiMlgGxAhb+/gGoLEmR
92CAoNMGTdd5kZebcMSdMCLzeT6xA4gQRJfZVKsq2wdNKKxKfA2dYMrUx3Zq
DLOMcnc6w3VyfecB1zFZs8J/7CtOej3j66W26JrepKsUPDYjfib0NluIeHYa
6OtFZl9i46sqaaKM6FQo/3KZY1xCrJiXtT3MaryEpZs4hFOip53C9OwTtZ85
7LaWhsK1UPt2dwmIdhdBdLBXcuytXAJ6p7e/d3C436Gqhv39vW60v7M/3B+A
vHhYU+5wsNse0kOdg/aXUCm6dgkS4L7DVRl/TPNCh7irarqwiThE3VKXLzbd
fnDQoqY+OiaxcNa8omxw/S7eFHOqH+/siWPQ6xm0WFJtlepyfQDsK1/2ja5W
bhpQ8rnLTe9qWjjYM7TAqQpPVG56AcLzBfWm69C+jEuq7sJd1QW15O3iWnPt
zi0ou1btqMpnjO0RAAcU0f19qJ1/mBQgXWG0cWJJB21If8CtsKxT7qPIKz5W
z6C7BpJyoEWGcDYH3NmA3kKpjW4wVUYbZpgXfddesbTCqnUV+KFnicrzhNMt
LLRQ/9Wjo/UY/NUqL/BDTxrXZsfUrVqK4bOAI1Fo7UbAIWjliVcISPMUTZ5T
r2HVYg1Pjx0nNm9O9Ya//60D2GnwSzuNYFcharVwvWq83srgqJDBvUawfygA
mfjBpwXHKfEwr75DbcXip4oqrNZ8WLXggwHnKaMNURKU500VhO/dKgi1Px8C
uNhRLyp9SiK5vVVLkbIOfjTglLHjiYR0Jn7Kk2XLqnPBQfl10zfck8Ro+u9o
O1CTr/U5Eg+txBO46XhqFylpy8sSNFKTzV5lWaLzdFWaviAx4gsSIb4g8eEL
Eh2+ILHhCxIZviBx4QsSFb4gMWGuiHDwSUWEL0g8+DyigXsX23fc/Lv4zYJ7
1VemAQvWuy4o1Wz11k61qFPflcXC8tiTyGD1Zqz00XNM+z4HsuXXXjgCWmGM
KYGcddZicsrmF2iUN8mxxS2VqMBmsL29XrfX32n39nuHO/s73aODnU7voLd/
aOda0rm1ckjnvDU/2dj/g5u7RM4xQNTumJRSf7JvuxeQtVhnodIPvEhEjgXJ
6kzUXLBepaQG5ujOS0CelzK8u6TdVe92nQHWzslQyThKJvWbCN9NCP39KL5T
jmHT7XcBvRmCd4JbpTPDukeIaZebQHBER25CCZY5UqpHKzpwbCCzaJzeydF2
VA5VZFZFjVircY9gKzgZYftoe8zJKOzLoMRtdc/ospeF1mN9xXcPHE7L6YIm
5kZgHK6jmY9BOEgoKQb2XuGCFJrLB18Bhu5ZjvSa67PZPdhbw2fz/H4av23+
i/PT1HoAukfLHn2zmbWHnwP3LBYgPtD5HKAcQrjoBnSVzsrx9eizy16HZYJ9
5NVoRmua99x7klcsB0DflNUlLL42Fx4kuFe6g+VuULcKQ/1bT3WDPv4KxQTM
Trvzr3CFeqmi9ki9UFGwy52lVW/TWhKtOUnle9ZEM65xUq0AD/eULXfTOqfV
PlReuEdwm5kER7ugWfW69gwg4ZPO/VfucezGxjSk59Lzo6vKlASy2qs5n9TI
7T5j4NPJ8J3+0W7/sN8/7LT7XHTFz3Kcx5ZiMqtwFc1UuvU8hQw0HcNYcMYC
TUwO2/AlPgdbptjmHH5xsKzj3S9ylz3wzy13lwimXvB+FIV77r0F3GH+EWxV
hYsnk5c7Ii8fdpeWl5c4lU8hMX/pfdI/beBKndxaOUFPI7z6clHnk6mz50+g
uD7ZDbG2+Kpjkte09PS7hzW3hGPacR77vLeEVV3uM90Si6XKCsE/q2g5j34s
A+Fq18cyts+15cnSSfRYM+cLkQtTmb3Bv6ukLv8XjXBbEN72GP80j6zoxu+n
7jLFLJ4Vi/VSS1GaD6sb80Lp+WWSu609/XRF7pxHP0u9u0Xu7bU94SWX4ud3
an4GX2bJVfZZPGS+U6aunlKS42q8rKYC2ePiX11ovWGwO16WwPPM5QLL1DWw
KyJwglacVbMq5jOInedpcfaMobfVE+1lGM8YbRssFzHzjBGttRC4gTKfAwI3
PuYZw2iD5cJinjFyNpgbDdM1H356CNz2Z08LwSot0FTsyzOGxAYLQl4ObQie
JQo2CJaKdHnayJZ1mrE9LR2s05DNNGFzIfDuwtM2ZZPKrytR4rM0ZnuWXVip
OduzQLBSg7ZngWClJm3PAsFKjdqeBYKVmrV9Cn7wGSBYqWnbM8b/10LgpgA8
rxLl2KvLba3XiP+/ftKwf4F1XvT/LqtQC+f8xOpU4GhNgVaodkt90H/TqH7T
qB4HwW8a1W8ald6FL0GjOvhNo/pNo/pNo3p2CH7TqH7TqP5balRefcaXPTVP
n1kjh+qX25IutCB+3O8Ufso4cg5yiHPd8UZqKVqRHm9GYUxltMsa1kR9YZJJ
lBfdX6G84YRisOM/Vw4rjNfStTbZF2fHuyCeI1MNepoU8YhfleisLWydkcy2
WZvrx5PbKCOodY1ck7WSUlfckUyjJrcKa6tBVVVXIgMJexD43aChIAzzu5sN
29W1wg/6y9b5wbMkUJldWvK9defDCNheTZZHYDXOfMr53LQWDDpf/N6689FP
+6F2iZ5ElqXm8yS7PALOdemsfsTab2oCRtYY6m4NsNc5GnzFeBjYgnfWmYf6
UrWDra6H7J9ynnXeEYvRHwlI3QPry4DttBoFufCdalAkr61ds7a197QnO8od
mq0e64EnBHNbv0P6ytY+1SpV4Zfz5lkdtnXOT/1otd+Umy/MeTLYQumRtmF3
+9PwhDVYAmJbpIdo8O9acCG4w25/6Dm/+EoR3tAj1f7Gh77jvsae4iuWrKLg
qU6owsi315tlDSR7I3kdmU9JyYbBliU2q3+HyvWYVwPTIyn7aj4/jdQsMrgr
KS9KlHoKWVnyPX4Tlj+dNLCqkLy+NLBr1WAN6DKYJxY8Zp4VklwedbO3H4bD
Ug7MwnfWmYfn0rhTMz7hPE91e/pvs5UEZf8Q/1UFZDtJZsGJ+IwC8vPNs847
Tygg2+jfs9G/voDcWVlA5h/rgH+HCUtb+W08LAy8rvxV86Nl7TcsZC/zzpz1
PDdbWEaYXkaQfjqe8RjeYaCBd+tkaqC1/cFBv7vf73c8R57eVcJ1dBRGw51h
d3e/E7X73aMa4dp59zEwl8RtG9QqKLrYxCPnfcweLRTETc3zlSTxhbXRjTjO
ZQduQ8qnM1lTOgCnKoLa6ciLDdBaGpfOFaYykkhuvZluWKHS7rwXWK1x2pNr
V+nVtUyxIFEulMXbyRt9U+6rUtPJfLeDNqMFzR32d9tH7V0sJjbY7XRU34Lh
0KcebmztHOkkTaeOUHf1OkKUZO0YXLvB5pvLq0/b8MEsX710dCw7pl9BL7k8
Y85a+wi/wUorQSdAYNG/Rsjxsc/b4H0QuCy5vRsAJy49jJME72HR1EfC7MeS
fSQWJpIvUPrnp9UamtR8QFMinn2PXKqofZmOFFbm+Fp+q6UKAM4/jHOPIYI2
1cmcTvNF1kVLfCmfUp8uKVO2BF9AHLojrcwsPlnxwZ3O3n4/HMLtNQij9uCw
H+714YKLBuHh4WFvd+9oeBgeDfs7+4f7h3vd4X5/FyW5fStzfccpqbT6aP0l
fAQLfpS8C4hfd4hlkucxNX7FkoZKClutGhPO05HiT2ZBKO/NeysI9Fsd8xa6
yhe8tdXp7Jl6VHveqgBWpv9C3jMn7V9RzrIMqlIjBo9pUy75T1uiseZw1heM
mVvwYjmWpwo2LmBYTthwbZmAR7DMJy78OBeSL6QS5COlvbn1blYU/OZXiDSS
T62wt/PphL1PUjXyixX2PpXc5in9M5cxfpryld7kiRWij9ZmUKXyJv8C4t0n
LaBZI/rt7vYeKfrt2qLfGqP9i4l+q5fi/CRyn/XWM8h9n0vwm1v2aS6ze8bq
T8uc4Boet1o9qOVYqW6F+jmlQ19pYf/60aCYExnCB/EQrxJivqGaxjTFdhzm
UuRqVfNdUrsXTx4RIMvwwThne9jOMnd7yGcOE2RRbxqPBsvX/PqPJykcu74F
d3FgRF0x2qe351IAxQoi/vwKgpryJS5jLcl+v7O7y5L9UXs4nOdT2Njqdjzi
Ow6wRqlLfKo+DuCQ4gB2g1Nub728TH/UrhfEe19/vYRgvKRbZcnrw/JwLGvZ
XLrz68ZTsJZlGPsisbjuiDkEuqY0zGM/Whxe+iR9lqLNu+HeXLIDuquVdhe8
uk79+GCVMp6HRnAjEGuKeFaqPPtKdy599uZViV9NvvNUf67IdJ+2EnQdMT7O
vreyLvzM0txSPGOOte8zlJh+9C39JKY4ubA7h91/gQt7scf1y7uwlzFpPVNl
66dxT7rxwY84gE9hzfrk9/fnKqm9cxguoMRaX+WCN7+YK7xcgvvLucJXs9F8
yjLdS5GmdWrXss4sE6/w+e9zn33GrHqeTYYHfxqjjNbBHxMZsqJP4bNZZRYZ
P1atv87jUr2mPMCC65gBgpFCzSF9Bofj11+LsAdT2J9+DEZxXljtGvhz2u18
2pO/UJRmgMqR6MFtmMP9CnLbIBrGCZZNz2B1dzEun8gAcDFI+9MxHOvW3JJS
H2CleT+LWeZ4op+5JaTmVZda+0cXIyhXi+I10le3JPIxrvVzv/769sXpQXev
C5uy6hpFgC7VZqqbkZ5bezpnRhLZX9LtEGyBbLpdM2P1OWt++vXw6GC3HhQ9
Y7nyUd0a6bknWSONdDoK83yJGbfUoeE3tlcBwZ3xLCrC2FSkWGJGfmOVKfWM
5WpOdTNa2tt6uC1RjndGm2RWo5K5M14Mm68wr8AzY8o8Rz/xGLqxZizXh6rO
qJ94ohnPr8ObypfOjPTE42ZzZgScvU6TyEFtBavWE4/ncpc9uuPnrFE9wXPt
73bWW6azj2/SbME+0hNPtI8vU77ZuRaEb0b3iSfAKkvh7pcuVvkJPob7nR08
kRfNs1YcFcMmiWAiib2PZs3pZBAWkQ+a8owvVK2i2hkNh6Nnt1cFoTzjm4uf
F6zRzAjPOvOth1Vdi2iJGeHZp5mRa5EtNyN6zlDmXWHm8owPzpfzZ3zAeVam
nfKMutbYEjPSsyvPWp5x5nw5f8bZk6wxHQ3smmpzZ9TPrjSzy+UMu/GsUT/x
RFxOtP0mKPnjsPDNWHpi3XmNnBM+NE9u5t0d6olHXpEOVv88jTKbdKpY5Sce
Naee8aTfjyalvFt3RnnisVJA9bayFlpzWz1uoXrG70dp/30pvdadUZ7gmY72
jpT8uNNdmqdWZ+yUvqzO2Hm6Ga/if0blDGJ3Rn7CmnD5WbwzcnQ20GPtjOaJ
p6HVcu3xuhnlifUndbDaKX9ZwWrn8SJyaY2nC7F6Slh1+fZtFg2XBsCL1ebr
6bgXZXOwqp5YY2494+u0qU22/jXaTwjF7h+sjls944/ppPkyHsduaUZ7RvME
n8OD/cNH0ep5/zatfOnqVvgETXbUOdh7vG4l0YpNW6lzZ7SfeMTEesY/N6t8
zp1RP6GmW2MTPTOWioh7Zuw+1YznZz9elhvLlfaRnqiRoaLBbdpfCgIuClqx
uTp9Sdlg66nr+ZXpn3kqUW10g+ZsncfOAapYj1hobGcUGmwr1ps8SJPRLAiH
QwqfK8heja/ApGwXF2+8vBQnQxK7yLpdN1Nc5NFoGAzSKMdqqfBSP4uwo2fK
8Zz0e2HV/BlFd9GI3JBqfTKr07agFehyTaCaJOj8h8n0LLj80IyAPo+0n46C
LRaKG8HZ9curRhAV/dZ2A501MbwXoYc8zChoigd4Gc5gOV0z0Djq34ZJnI+p
GQN7UozZX1xJeWtj4wKLHQUv3/xy8lo5YdRg8M5tko7Sm1nQi9BtgK4Aq32o
nqzv7GswiPP+NBe7ubCsLhq7UDeLkyn5jdHqPxPksAMqBHzcwsRqeoULnlHo
JAzIi5PeZOHkNu4H6OG4QSCUuwixO3/xvPdUpent+Z/fXbw9P2th2MFt3dCB
NbSDflhemg3Y/2KvDZ6/A3wox9gkygr2+4SFg48sIn/QdEKeD0IFQai8LlZQ
KCNhBYyz4luH8eo0P2TpdLLOZF7ecoOj4TkAGGrnFecaH9w+bS8ddekquxIU
V7I/nU6riwMZmaeKglpUm5AB8VcKqTAkF0lcxMDe/sks5meYEVjDFtpVKOWg
VPHMdn+Pp3mBwRv9EESR6Qh4F/Aa8m2Sty2LEI4wKDKYrpkOh7qWstN2djiM
+zFgahZsEbhhMEqTGwDz1dX32KAEnhzGD9u67PKQQqbxeaC7ihuOYMqiJLpH
1heARo3VaqIMlhhs2ZQNw96hK5tw8DNnOUYPE5iFXIkp8g9glgpSuCQ4XEoK
qKGqTtPAuOlE9k9x23E4o8DuGHsaR8RYtZ87euhTpE+ukjnIIYntd6PsZtbE
4wkUccdt0afM+BtBb8qQ4g04htEMTu9jYNqDaIK9mFPx606ifgxY1ZFdVh8e
WCJ7n6cEzSQsADlJ3gI6MLipwR9vj/AzoSiYdpIC0I5LuB+ilx/oQQCCy/MW
dh7/SyOyjcNcCz+9O7u80h7K+vNn20c0k4cVhH2sUNanHSuydDDFxQICs2yK
lWroTNjhDRN8oQDocJsBuuQ93EjplQyV00hA1+N0mhQc2tAPmZvD7iE13JEr
OZ1mfbr/8umYJZOwKGXKplkLBN37iMICbWBR6kBUx8k/kI0zRLkaAEEKRnRj
4BEa5cCJwwm9A1tKG9AIJinaXmBjANFjbFkxCMfhDUDZUAsBHBE7cM7bGPf1
LoQdRcGHI0d8x5vdynk6djzPRCj1oomFZOYyTBcyC9vB6MKAZVHh9pgFBush
GSnNYlgLUJ3j4MJzAGftNso8r/h4lJqMr3o4NkkOCCAWdTF0iESIIsyyGNOh
PVsZuPwJsXObZshRBQ6YLOEZy4uw8OIizhI8Bk7nKKq6OJhmlM5FR5zue5gg
yjKYGg/zAG5hvmwIdrXdHjGQe6y/end1jfneITJ1PI0jvICmk1Gp6bq1ZMV1
XZK+cHfbzHCDx2pK689nSb9hxW44Nwexgl4pp1z3eh/NFPo5VkjH1M6QCEiq
UpzT9IcX5OONRTea5rj5tMdbzgKND8UttLkB+4OhRzM8qBjAOI6UfEsxMaZN
PbMgYrdh4mOEYaH/ZJwXQAc3hmkiD0RVJUflI85vMfgCpOHWTauBzCabJomK
Z1mOdS7DL4MrULZHYWZTFl5UPYpVAUoCjlBwKhToOoA/Cubh14EGUbZgzi94
9YqmjKAYhV8MCPzqq+CvJ69/CF4BT4bBOOpFyT5NV/ZpzuBabI7pSWkKR+/C
/CHwt0E0sm+IkwneePFDcAI8ueCEAtx7REHev+0HPJB7qaB+urO/o2KoQLAA
LMF2j0ZzhTKkmXhUlskORSDjEVkIU8E/maqp2hDo4OXyYkJAajQaUXDQxcnr
E48eacXmUCAPiT9UFpbOQJ/BQzaNA8BIr1PeQQArOB/EIMkdB29GpONJ4Dct
Nu3DQjOUTklE2Pz11//96vzli48fN62IeBgiYcsTMTNk2CJXMMcnBgTyXiE9
8iZhFpKSwft+cX79IvjLq5dwTePi8BrL36uYq5s4L4SFm/XAKln7wI831fub
8rgyS+/sHx7SBv4uePf24jiYZskx7voxzj/Ojx/Go+MkP0ZiOtbUQPo9vPGW
hwqTglwXgMFjkuYuzq9+aMH3MN9x8Prbk9/LLpL1BoCGmWgFCT4RJCEcAWC5
Hgp/jV+tu+TKQOW177e7bWW23m2jnQW3y3n9DWIB9iSzXya9hVCGwx4HFby8
VitaEZ9vSDY/DlwcE0PGsTRdEZ4qsWlKMypFxcVhEpZC4yr41KyTl75g6E0+
YAofXIlZ/mJinqSjuD9ryLYL2qYYSbp55VD9WxbrB5tSyVlxg93WvvCDw053
H9nt+QNqyPDCXQzC9M00xgjBRK4Q0aWFpehVR/ROM6N3iMq/wqOUCAt5l0fM
GNPePzjfQp9NDXSc8zU3GpG4QPGDGh2+6MGGFT4YF9WAwdv03m59WRYoUejg
IE16IXYNQcqqEANvvA3vVLi/HYCqOBzjly5PnnpR1CMMQudTzFHxSKQ9kd7p
7g4x+JXtSyRFT1LR5Rx7hpqSgYdx0XaF9F9ELtODxZ6HsFg+tyLk2aiP1VaR
aN8fTQf4vRwIHRu6YMkhCFn9ONQxwuI+zvTaG+rywH+rwzsg5/b4Rtjsu4eF
nvFPpgwLYYn/K4gX0Aebt8zQjfItxuHDxJ1IItfoZCSb0pUaOE1d4SgDURee
fIgx85z3Gd5NUYzDSqWgoYGk4nJg1MIMglHRpYlWAcCZN18wsUhsqHWps2i2
jI0J6hGXfsLBYNHm8r4JITPx4IIAYiWj+jc7cjbEIiaye8x8BKoEQVYG9GGp
DCc2EFbP9cM+SJSUVT7nCAc+l6JOQPkwmlPNQfStaAzEU2CEsJfeRebc6/R3
3M4Iz7COy1AqjkUVLgkIG74qsmmfmvgAUOfwRRyJtR+47XSc5FVmDKz+GOmK
rqFjoK1pEgPPCmDZoLnD9JkHgdbZs2ESyQyGZ6ACkg+tkYTvqRr9ZK1Sw28S
BJsCKbO4yoagwF8dlixqxLtZWyYvISlhcRGNCdqIqBr/1LkFZWnXc4qWWyeR
pxB9WQTfd0XwNDPXqa1MfMTHtCxCB90KZcdtIT0eKNXEt6+7LcDeUlCCUU/i
XKApiCl9zzlW9iOXP8cFgWfJUCsOgNy4ZmsDzMjJ19+Jlqgkmrq1qCAaN5zI
STqZjuyXdZIp7YwnwYE54KZesaZRhJOUFdoJ0GAiPnKMCkGDm70Ah9SVui6S
nA4t3YOWdOnKWXyIHRHRCJiePAnkKoqrhfUSohylXIj1hsxKZE+7QWMvaNiW
UMgymPAwBi9Hspyi0SsKRmn6nlp0pJk2BhN7EcMWkC4q7QVDpN4nFAbo44P5
85RfMoMiRAnuPKyVDIkBbF1cgMyCcg4jklGE+Jb3ivA9ym/sGzL6aulWJ9tH
TrzvDZlB8v+YhgV1GTHzo7ND+HdLdgwnwlW5VyhalfKpOAoK2/FJS3QkeVHa
iD6iJJ9mkbkb2OYtJsebVAz9gyln6gCzTIzBUN3xSm6I1EUhY7F1J8ZL/X3E
mr9ivjEKR5NROkNiQckmCDSJjNC+RHfQHUZa2dcweX8RBJfLlsQRAg2wjDjj
Koul0YyQuPKAuF1khcgpy08f4VodyKtDlcRP2W+R0ZB2ozBDC1+OJEvnqUeG
mIqEiZDdhfGI7N5xrgmOiQKwDRQ6jlmgF09caW4kJdxrpW41RCIxfF4rYkkU
cUYrXXU11IZSPd+MM3NaNSUYdzLuiZGA+DjC18CRUf+7DzPx+lqCFO6iT1ir
138UpTKtCX2y6a1hz4tGPhKCmE0XkZFxxXavxEWyLuM+4TqQcPhcxyCl3Ccg
fQ2ZgwwiuPdjENAy5BvmSLg6lNLNgpswhq24i2Gf4hGa14rbLJ3e3LrKk7pi
ms1m0Av779EsRkLEGQoRr0iIUBaCsqUQCUXZA21FyrVXiElQ5e6tYTa0tTol
a1uBKWifsN80buDCvqWcLOk/nF6enQffn/9w8frqO9hnmHvTBftP3XZ3t9lp
N7udFi58c2NDgCwt71fgM4SZO8lY67Q6v4fPtLkq2FzeuLOJb7Lr1Vh3fo+s
jDfeQtmvklNtPY0vf8SH0+wmTMS3TI+xXe8KNYs+hw8/FAGXWHAMOFs4zHbw
C4gsSIzkxyeY+my348F++SH4Jeodw69/uC2KSX787bcocwJho5ONDOItAOHb
+5tvcbxvQSmYFt9+xwDDyy+B9uDtP4yByxTpMT7zJ/WSPKXMqEHwKsz6aXAd
j9J+qNLI1Ztj/K5V0Hd/yuJWHn1H0FqshiE+TSezjKz5W7A82NoOW0qvMxSz
lSoC5zZHetJiOF7rPGc4LUBYzY3DDW7rAG6CUUDDUqsyzK4Bbk7Pv40GeMBi
YLzKajvlxFbxX+InvTgJWdUdg5ZFfD/N+H38Az06QHOasTaQ7RDzJbfKZJrl
U+IEaUPxKPJqFimPwY6MfkT1HuC1nHdRzom4wICuRrzU76/OYGf4cdAteAyA
DaCKMTlYWdz6CgkGg1/nwcvoBiSZN8jXczKkCxpQtuELnx4/kwMp328p+ilw
mCgytCOAN/Ee2BakEstRx0xpfcSt1NEke3gh+knwF/gpzXN/f9/Khv1mRPRF
M+EM38Jn+PT272HpkbbEs1KtMRFguEUwopXC/RajJUFBRrEJKOsDb/savU9f
N/jf4PUl/a7Cg/D3qx9PXr7Uv/AQ8tjVj5fvXp6Z38zrp5evXp2/PuMR4NPA
+YgH+frVyV+/Zmr4+vLN9cXl65OXX1clabwJlUkQKAOOf2HROp+eHnPT70/f
BJ3dYAvR0e10jrb518POwe42uad4NhJ66E9Ne1QeBIQOUnsBb/1wEhdwI7Jq
SYUx0BkkGPzdI382LBIRalj2qsH14E2jD84Klw2++1f4aW0Sl6Ycb6ROc3sI
oy6zJGBKr9XQBGjOo1OwiFijxG8pIQDE2QKjkqphFAjLsHcUdbaVLlopyoFC
KDBxWptdGOCNDiREcIEC4IxUXhYGkQd7tIj97U19HX37reS3X5zRVUbsFSSS
YTxgrZRxq0pNYMQ3Dd9DD9om7tpx6VHBhQepJmqcn5yLNjzyzqrfqvCSC22J
yc06FgCec+C4uO8euwQ3DP0TLuY2nTRHHCG+9hJ+TCcBR5lL8DBaOO/SGM8M
SauRKmeDlwOo2ZP59I1h6suSZ4UyTcj7pQF7Pg4iillfe/kU8r7ElmFc+rLL
Oq6sC2dp2MHuzIo5RfwNtw8F9C6xXNHem9gpbP1V22H3/0KL/49mT2L31165
Dv9fbtkHa5MyTdP8JQYQrzGoaojRLXIxXU0nqCLAoiuvvU17KOdecxwW3QXL
I6b7eMR0/2shhpIdHsMeKJNiWZb+jkIgzyd4HaD58iweAitv/hiNRmMMhMKa
PaeXV+fBFo1bxY02KK2LXCp0xrqFTr/gXArrsjm/ugbxuHpOk7s4S8nglKtE
hO0lcCyxVA9az12MaS+yA9L+KvnBDyxVtcyr5Q0InlS0Ch4pXQVawAr2W07b
Sk0nP4HE/Y4NSgiFSoSmULUVMM551c+DdR77N8z7MT97JqzPfsN4DcbT0eA5
yd2UKfjvugGo+U0THorrXLnbMtI7YTEfFR3v3ZRRE/9qYj3HRTtyJYk03J1D
jFYOJ3I9NKCjjL/p/Dfcpfr9UAfkU2yJOS2VbbmHbbFG+e+1QR+Vu+L89dnV
d/4ao+SAQBt8k+M+rEqikt6rTExl705t0dCvtK1WIDShosqOKFHu+UeAg/vZ
xUk27HPcqSrg12x3cQub7Z3gKzVAuwt/fiz5PaupLcxTZaDNoEMJW1wRkvMC
yHV6BdtSVBIj4HWnvJ5RDsmLDktWIQI8ylmch+NefDMlb76aBQ3JaC3EDJ5R
LDkQuuCLSPAcavQQDdyMHx4itxMvOdotuY1AhIbH6yLfUyuYR8yVlCinDJV6
RrEXki0bAwniMTpWI+UAd3ahw7vQtXahA3/SLpxQ1d1yqrQOV1GmT2Nbw2k9
ZioJ8mHrKFpO3eiOhQHDHF8uMXSeeKa1Ft7mhXeshbfhz49m20K9W2SbnkjA
eJTBhkzHvIHn+EeIJf4O9ru8A6ejMGPXCRUzJe/tUCydKtIJnQYq61zQWHqX
HNpzovS8r7+VWqI+hCLoVM+O+nao4n3WEEuN4NanK7/NBFMXbWYRrvU00YJL
6UvvZ3DSf5+k96NocMOaJG5l6H6GXIhtr9Hgj5vDcJRHUrNce+9Ak+5HlCKJ
aUvvg19//fX0NkPPO5DAyTj/z/83zz9inVn44s9TvBSBfwBhxIn69H+kt8j9
o+l//l8BoKbI81R/dxpmeN5/SMfRP4G5YkxpdJOl6usf/vP/yUJ0pI1grViM
lz9+E+Z9WPH17RQgL+hTxAV885//Zwb318+zpP8+gs8VemPKMWM04JPDKBqg
614FiiEzD+7Rx8J2D1Ml+uo+gpv+6xwr9aZ3zGZPbiip9+eL168vfz6xMxvO
3709/+kkOD1/eX1x2nx9/pdrDNsgK8DpX9+Avn/1e/Zi8uA/dtvdtnoiD64u
XlxcNX/EuKutHyj1I7zJov9/4BhVsDQ1MjM1guwtdgxydnQBJg1dz/wQTJWG
BqCLPI1MLTX1uACDPndCXzICAA==

-->

</rfc>
