Key Provisioning for Group Communication Using Authentication and Authorization for Constrained Environments
RFC 9594, “Key Provisioning for Group Communication Using Authentication and Authorization for Constrained Environments”, is a Proposed Standard document published in September 2024 by F. Palombini, M. Tiloca. The canonical text is published by the RFC Editor.
Abstract
This document defines how to use the Authentication and Authorization for Constrained Environments (ACE) framework to distribute keying material and configuration parameters for secure group communication. Candidate group members that act as Clients and are authorized to join a group can do so by interacting with a Key Distribution Center (KDC) acting as the Resource Server, from which they obtain the keying material to communicate with other group members. While defining general message formats as well as the interface and operations available at the KDC, this document supports different approaches and protocols for secure group communication. Therefore, details are delegated to separate application profiles of this document as specialized instances that target a particular group communication approach and define how communications in the group are protected. Compliance requirements for such application profiles are also specified.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9594 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9593 Announcing Supported Authentication Methods in the Internet Key Exchange Protocol Version 2
- RFC 9595 YANG Schema Item iDentifier
- RFC 9592 Retiring the Tao of the IETF
- RFC 9596 CBOR Object Signing and Encryption "typ" Header Parameter
- RFC 9591 The Flexible Round-Optimized Schnorr Threshold Protocol for Two-Round Schnorr Signatures
- RFC 9597 CBOR Web Token Claims in COSE Headers
- RFC 9590 IMAP Extension for Returning Mailbox METADATA in Extended LIS
- RFC 9598 Internationalized Email Addresses in X.509 Certificates