Is the KIV-21 susceptible to spoofing?
RECIPe messages are unencrypted and thus are vulnerable to spoofing, and have thepotential to disclose Red destination addresses and their associations with Clearaddresses. KIV-21 uses MproxyARP to identify the KIV-21 that protects a particular Reddestination. The MproxyARP Query is addressed to the multicast address of the domainand does not require a static route to find the correct remote KIV-21. Only the multicastaddress and its PPK need be defined in advance. MproxyARP Messages areencrypted.