RFC 9175: Constrained Application Protocol (CoAP): Echo, Request-Tag, and Token Processing
In plain English — editorial summary, not part of the RFC
This document specifies enhancements to the Constrained Application Protocol (CoAP) that mitigate security issues in particular use cases. The Echo option enables a CoAP server to verify the freshness of a request or to force a client to demonstrate reachability at its claimed network address. The Request-Tag option allows the CoAP server to match block-wise message fragments belonging to the same request. This document updates RFC 7252 with respect to the following: processing requirements for client Tokens, forbidding non-secure reuse of Tokens to ensure response-to-request binding when CoAP is used with a security protocol, and amplification mitigation (where the use of the Echo option is now recommended).
Document record
- Document ID
- RFC9175
- Published
- February 2022
- Authors
- C. Amsüss; J. Preuß Mattsson; G. Selander
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- wit
- Pages
- 27
- Also known as
- —
- Updates:
- RFC 7252
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9443Multiplexing Scheme Updates for QUICCurrent
July 2023
- RFC 9952Application-Layer Protocol Negotiation (ALPN) ID for CoAP over DTLSCurrent
March 2026
- RFC 9956A Non-Queue-Building Per-Hop Behavior (NQB PHB) for Differentiated ServicesCurrent
May 2026
- RFC 4987TCP SYN Flooding Attacks and Common MitigationsCurrent
August 2007
- RFC 9185DTLS Tunnel between a Media Distributor and Key Distributor to Facilitate Key ExchangeCurrent
April 2022
- RFC 9031Constrained Join Protocol (CoJP) for 6TiSCHCurrent
May 2021
- RFC 9334Remote ATtestation procedureS (RATS) ArchitectureCurrent
January 2023
- RFC 9342Clustered Alternate-Marking MethodCurrent
December 2022
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?