RFC 9820 · PROPOSED STANDARD · 2025

Authentication Service Based on the Extensible Authentication Protocol for Use with the Constrained Application Protocol

Overview

RFC 9820, “Authentication Service Based on the Extensible Authentication Protocol for Use with the Constrained Application Protocol”, is a Proposed Standard document published in September 2025 by R. Marin-Lopez, D. Garcia-Carrillo. The canonical text is published by the RFC Editor.

Abstract

This document specifies an authentication service that uses the Constrained Application Protocol (CoAP) as a transport method to carry the Extensible Authentication Protocol (EAP). As such, it defines an EAP lower layer based on CoAP called "CoAP-EAP". One of the main goals is to authenticate a CoAP-enabled Internet of Things (IoT) device (EAP peer) that intends to join a security domain managed by a Controller (EAP authenticator). Secondly, it allows deriving key material to protect CoAP messages exchanged between them based on Object Security for Constrained RESTful Environments (OSCORE), enabling the establishment of a security association between them.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9820 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2025

Who Is Online

In total there are 82 users online: 0 registered, 76 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Facebook Other Bot SemrushBot YandexBot

Users active in the past 15 minutes. Total registered members: 354