CurrentBEST CURRENT PRACTICEIETF streamBCP247

RFC 10027: Best Current Practice for Security of Cross-Device Flows

In plain English — editorial summary, not part of the RFC

This document describes threats against cross-device flows along with practical mitigations, protocol selection guidance, and a summary of formal analysis results identified as relevant to the security of cross-device flows. It serves as a security guide to system designers, architects, product managers, security specialists, fraud analysts, and engineers implementing cross-device flows.

Document record

Document ID
RFC10027
Published
August 2026
Authors
P. Kasselman; D. Fett; F. Skokan
Status
BEST CURRENT PRACTICE
Stream
IETF
Area
sec
Pages
50
Also known as
BCP247

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/10027-best-current-practice-for-security-of-cross-device-flows