The Messaging Layer Security Architecture
RFC 9750, “The Messaging Layer Security Architecture”, is an Informational document published in April 2025 by B. Beurdouche, E. Rescorla, E. Omara, S. Inguva, A. Duric. The canonical text is published by the RFC Editor.
Abstract
The Messaging Layer Security (MLS) protocol (RFC 9420) provides a group key agreement protocol for messaging applications. MLS is designed to protect against eavesdropping, tampering, and message forgery, and to provide forward secrecy (FS) and post-compromise security (PCS).
This document describes the architecture for using MLS in a general secure group messaging infrastructure and defines the security goals for MLS. It provides guidance on building a group messaging system and discusses security and privacy trade-offs offered by multiple security mechanisms that are part of the MLS protocol (e.g., frequency of public encryption key rotation). The document also provides guidance for parts of the infrastructure that are not standardized by MLS and are instead left to the application.
While the recommendations of this document are not mandatory to follow in order to interoperate at the protocol level, they affect the overall security guarantees that are achieved by a messaging application. This is especially true in the case of active adversaries that are able to compromise clients, the Delivery Service (DS), or the Authentication Service (AS).
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 9750 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9749 Use of Voluntary Application Server Identification in JSON Meta Application Protocol Web Push
- RFC 9751 Closing the RTP Payload Format Media Types Registry
- RFC 9748 Updating the NTP Registries
- RFC 9752 Conveying Vendor-Specific Information in the Path Computation Element Communication Protocol Extensions for Stateful PCE
- RFC 9747 Unaffiliated Bidirectional Forwarding Detection Echo
- RFC 9753 Extension for Stateful PCE to Allow Optional Processing of Path Computation Element Communication Protocol Objects
- RFC 9746 BGP EVPN Multihoming Extensions for Split-Horizon Filtering
- RFC 9754 Extensions for Opening and Delegating Files in NFSv4.2