RFC 8471: The Token Binding Protocol Version 1.0
In plain English — editorial summary, not part of the RFC
This document specifies version 1.0 of the Token Binding protocol. The Token Binding protocol allows client/server applications to create long-lived, uniquely identifiable TLS bindings spanning multiple TLS sessions and connections. Applications are then enabled to cryptographically bind security tokens to the TLS layer, preventing token export and replay attacks. To protect privacy, the Token Binding identifiers are only conveyed over TLS and can be reset by the user at any time.
Document record
- Document ID
- RFC8471
- Published
- October 2018
- Authors
- A. Popov; M. Nystroem; D. Balfanz; J. Hodges
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 18
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8472Transport Layer Security (TLS) Extension for Token Binding Protocol NegotiationCurrent
October 2018
- RFC 8473Token Binding over HTTPCurrent
October 2018
- RFC 8470Using Early Data in HTTPCurrent
September 2018
- RFC 8449Record Size Limit Extension for TLSCurrent
August 2018
- RFC 8417Security Event Token (SET)Current
July 2018
- RFC 8693OAuth 2.0 Token ExchangeCurrent
January 2020
- RFC 8701Applying Generate Random Extensions And Sustain Extensibility (GREASE) to TLS ExtensibilityCurrent
January 2020
- RFC 8940Extensible Authentication Protocol (EAP) Session-Id Derivation for EAP Subscriber Identity Module (EAP-SIM), EAP Authentication and Key Agreement (EAP-AKA), and Protected EAP (PEAP)Current
October 2020
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?