Use Cases for Authentication and Authorization in Constrained Environments
RFC 7744, “Use Cases for Authentication and Authorization in Constrained Environments”, is an Informational document published in January 2016 by L. Seitz, S. Gerdes, G. Selander, M. Mani, S. Kumar. The canonical text is published by the RFC Editor.
Abstract
Constrained devices are nodes with limited processing power, storage space, and transmission capacities. In many cases, these devices do not provide user interfaces, and they are often intended to interact without human intervention.
This document includes a collection of representative use cases for authentication and authorization in constrained environments. These use cases aim at identifying authorization problems that arise during the life cycle of a constrained device and are intended to provide a guideline for developing a comprehensive authentication and authorization solution for this class of scenarios.
Where specific details are relevant, it is assumed that the devices use the Constrained Application Protocol (CoAP) as a communication protocol. However, most conclusions apply generally.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 7744 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7743 Relayed Echo Reply Mechanism for Label Switched Path Ping
- RFC 7745 XML Schemas for Reverse DNS Management
- RFC 7742 WebRTC Video Processing and Codec Requirements
- RFC 7746 Label Switched Path Self-Ping
- RFC 7741 RTP Payload Format for VP8 Video
- RFC 7747 Basic BGP Convergence Benchmarking Methodology for Data-Plane Convergence
- RFC 7740 Simulating Partial Mesh of Multipoint-to-Multipoint Provider Tunnels with Ingress Replication
- RFC 7748 Elliptic Curves for Security