The mandatory network layer uses AES-128 in counter mode (CTR), with a mandatory CMAC signature for message authenticity. On top of that, an optional application layer offers seven modes: no application cryptography, confidentiality only, confidentiality with perfect forward secrecy, authenticity (confidentiality plus a 4-byte CMAC signature), authenticity with perfect forward secrecy, and two agnosticity modes that add a fully separate application-layer packet counter for 7 bytes of overhead. Which mode an end point uses is a device property, declared in its application layer format description, not negotiated per message.