RFC 9052: CBOR Object Signing and Encryption (COSE): Structures and Process
In plain English — editorial summary, not part of the RFC
Concise Binary Object Representation (CBOR) is a data format designed for small code size and small message size. There is a need to be able to define basic security services for this data format. This document defines the CBOR Object Signing and Encryption (COSE) protocol. This specification describes how to create and process signatures, message authentication codes, and encryption using CBOR for serialization. This specification additionally describes how to represent cryptographic keys using CBOR. This document, along with RFC 9053, obsoletes RFC 8152.
Document record
- Document ID
- RFC9052
- Published
- August 2022
- Authors
- J. Schaad
- Status
- INTERNET STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 66
- Also known as
- STD96
Topics
Standards lineage
This document is one revision in a chain of 3 RFCs, each formally replacing the one before it.
- RFC 8152 (2017)
- RFC 9052 (2022)
- RFC 9053 (2022) ✓
Read the full history of CBOR Object Signing and Encryption (COSE): Initial Algorithms →
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9053CBOR Object Signing and Encryption (COSE): Initial AlgorithmsUpdated
August 2022
- RFC 9528Ephemeral Diffie-Hellman Over COSE (EDHOC)Current
March 2024
- RFC 9597CBOR Web Token (CWT) Claims in COSE HeadersCurrent
June 2024
- RFC 8392CBOR Web Token (CWT)Current
May 2018
- RFC 9942CBOR Object Signing and Encryption (COSE) ReceiptsCurrent
June 2026
- RFC 9943An Architecture for Trustworthy and Transparent Digital Supply ChainsCurrent
June 2026
- RFC 9964ML-DSA for JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE)Current
May 2026
- RFC 9054CBOR Object Signing and Encryption (COSE): Hash AlgorithmsCurrent
August 2022
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?