Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework
RFC 9200, “Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework”, is a Proposed Standard document published in August 2022 by L. Seitz, G. Selander, E. Wahlstroem, S. Erdtman, H. Tschofenig. The canonical text is published by the RFC Editor.
Abstract
This specification defines a framework for authentication and authorization in Internet of Things (IoT) environments called ACE-OAuth. The framework is based on a set of building blocks including OAuth 2.0 and the Constrained Application Protocol (CoAP), thus transforming a well-known and widely used authorization solution into a form suitable for IoT devices. Existing specifications are used where possible, but extensions are added and profiles are defined to better serve the IoT use cases.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9200 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9199 Considerations for Large Authoritative DNS Server Operators
- RFC 9201 Additional OAuth Parameters for Authentication and Authorization for Constrained Environments
- RFC 9198 Advanced Unidirectional Route Assessment
- RFC 9202 Datagram Transport Layer Security Profile for Authentication and Authorization for Constrained Environments
- RFC 9197 Data Fields for In Situ Operations, Administration, and Maintenance
- RFC 9203 The Object Security for Constrained RESTful Environments Profile of the Authentication and Authorization for Constrained Environments Framework
- RFC 9196 YANG Modules Describing Capabilities for Systems and Datastore Update Notifications
- RFC 9204 QPACK: Field Compression for HTTP/3