Feature | IPsec | DTLS | OSCORE | OSCORE-NG |
---|---|---|---|---|
Authenticated encryption | ✅ | ✅ | ✅ | ✅ |
Sequential freshness | ✅ | ✅ | ✅ | ✅ |
True end-to-end security | ❌ | ❌ | ✅ | ✅ |
Resistance to mismatch attacks | ⚪* | ⚪* | ✅ | ✅ |
Resilience to delay attacks | ⚪* | ⚪* | ⚪* | ✅ |
Resistance to denial-of-sleep attacks | ✅ | ✅ | ❌ | ✅ |
* RFC 9175 mitigates at the cost of communication overhead