Number of messages 4 Messages unless: Messages lost on network (all) Initiator misguesses DH group (JFK & OIKEv2) Initiator deciding he’s “under attack” (OIKEv2) Cost of 4 Messages: Complexity of “statelessness” Complexity of Message 3 partly encrypted Messages are larger / UDP Fragmentation issues May impact “Legacy Authentication” (next) |