Using Ephemeral Diffie-Hellman Over COSE with the Constrained Application Protocol and Object Security for Constrained RESTful Environments
RFC 9668, “Using Ephemeral Diffie-Hellman Over COSE with the Constrained Application Protocol and Object Security for Constrained RESTful Environments”, is a Proposed Standard document published in November 2024 by F. Palombini, M. Tiloca, R. Höglund, S. Hristozov, G. Selander. The canonical text is published by the RFC Editor.
Abstract
The lightweight authenticated key exchange protocol Ephemeral Diffie-Hellman Over COSE (EDHOC) can be run over the Constrained Application Protocol (CoAP) and used by two peers to establish a Security Context for the security protocol Object Security for Constrained RESTful Environments (OSCORE). This document details this use of the EDHOC protocol by specifying a number of additional and optional mechanisms, including an optimization approach for combining the execution of EDHOC with the first OSCORE transaction. This combination reduces the number of round trips required to set up an OSCORE Security Context and to complete an OSCORE transaction using that Security Context.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9668 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9667 Dynamic Flooding on Dense Graphs
- RFC 9669 BPF Instruction Set Architecture
- RFC 9666 Area Proxy for IS-IS
- RFC 9670 JSON Meta Application Protocol Sharing
- RFC 9671 Sieve Email Filtering: Extension for Processing Calendar Attachments
- RFC 9672 Transferring Opportunistic Wireless Encryption to the IEEE 802.11 Working Group
- RFC 9663 Using DHCPv6 Prefix Delegation to Allocate Unique IPv6 Prefixes per Client in Large Broadcast Networks
- RFC 9673 IPv6 Hop-by-Hop Options Processing Procedures