| Internet-Draft | Single-Stack 100/50 Principle | September 2026 |
| Sun | Expires 6 March 2027 | [Page] |
This document defines two formally provable consequences of retiring the IPv4 protocol stack in a dual-stack (IPv4 and IPv6) network environment: (1) complete elimination of attacks attributable to the IPv4 protocol, and (2) a minimum 50% reduction in the count of concurrently exposed network-layer attack surfaces. Both results are established as definitional and structural derivations, independent of empirical attack-volume measurement. This document proposes standard terminology for discussing these effects and states explicitly the boundary between what is proven here and what remains an open empirical question.¶
This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.¶
Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.¶
Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."¶
This Internet-Draft will expire on 6 March 2027.¶
Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved.¶
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document.¶
Dual-stack operation of IPv4 and IPv6 is widely deployed as a transition strategy toward IPv6-only networking. This document states, in formal terms, two consequences that follow directly from retiring the IPv4 stack in such an environment. Both consequences are established by definition and by direct enumeration; neither depends on measured attack-volume data. A separate empirical question -- the relative share of attack volume historically carried by each stack -- is explicitly out of scope for the claims made in Section 3 and Section 4, and is discussed in Section 5.¶
This document defines no conformance requirements and uses no RFC 2119 key words; the terms below are used in their ordinary English sense.¶
By definition (Section 2), an IPv4-Attributable Attack requires the IPv4 stack to be present and reachable. If the IPv4 stack does not exist on a network, no packet using IPv4 addressing or IPv4 protocol mechanics can reach a host on that network.¶
Statement: Retiring the IPv4 stack yields complete (100%) elimination of IPv4-Attributable Attacks against that network.¶
Justification: This follows directly from the definition of "IPv4-Attributable Attack" in Section 2 and requires no supporting measurement.¶
In Dual-Stack Mode of Operations, a host or network concurrently exposes two independent, complete Network-Layer Attack Surfaces: the IPv4 surface and the IPv6 surface. Let S denote the count of concurrently exposed Network-Layer Attack Surfaces.¶
S(dual-stack) = 2 (IPv4 surface + IPv6 surface) S(IPv4 retired) = 1 (IPv6 surface only)¶
Statement: Retiring the IPv4 stack reduces S by (2 - 1) / 2 = 50%, taken as a minimum.¶
Justification: The reduction is stated as a minimum because the surviving IPv6 surface continues to face attacks at up to 100% of its own scope; that 100% is now the entirety of a single-stack environment, not one term of a two-stack total. The reduction in S holds regardless of the relative attack volume previously carried by each stack, because S counts exposed surfaces, not traffic or incidents.¶
Theorems I and II in Section 3 and Section 4 are definitional and structural. They do not assert, and this document takes no position on, the separate empirical question of what percentage of overall global attack volume or incident count is currently attributable to IPv4 versus IPv6. Any such claim would require direct measurement of comparative attack volume across both stacks, which is not undertaken in this document.¶
This document defines terminology and formal properties related to protocol retirement; it specifies no new protocol mechanism, message format, or implementable behavior, and introduces no new attack surface of its own. Operators retiring IPv4 in favor of IPv6-only operation should independently evaluate IPv6-specific security considerations (e.g., Neighbor Discovery security, extension header handling, and address-scanning resistance) which are outside the scope of this document.¶
This document has no IANA actions.¶