RFC 9750: The Messaging Layer Security (MLS) Architecture
In plain English — editorial summary, not part of the RFC
The Messaging Layer Security (MLS) protocol (RFC 9420) provides a group key agreement protocol for messaging applications. MLS is designed to protect against eavesdropping, tampering, and message forgery, and to provide forward secrecy (FS) and post-compromise security (PCS). This document describes the architecture for using MLS in a general secure group messaging infrastructure and defines the security goals for MLS. It provides guidance on building a group messaging system and discusses security and privacy trade-offs offered by multiple security mechanisms that are part of the MLS protocol (e.g., frequency of public encryption key rotation). The document also provides guidance for parts of the infrastructure that are not standardized by MLS and are instead left to the application. While the recommendations of this document are not mandatory to follow in order to interoperate at the protocol level, they affect the overall security guarantees that are achieved by a messaging application. This is especially true in the case of active adversaries that are able to compromise clients, the Delivery Service (DS), or the Authentication Service (AS).
Document record
- Document ID
- RFC9750
- Published
- April 2025
- Authors
- B. Beurdouche; E. Rescorla; E. Omara; S. Inguva; A. Duric
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- sec
- Pages
- 41
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9605Secure Frame (SFrame): Lightweight Authenticated Encryption for Real-Time MediaCurrent
August 2024
- RFC 9770Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) FrameworkCurrent
June 2025
- RFC 9635Grant Negotiation and Authorization Protocol (GNAP)Current
October 2024
- RFC 9901Selective Disclosure for JSON Web TokensCurrent
November 2025
- RFC 9529Traces of Ephemeral Diffie-Hellman Over COSE (EDHOC)Current
March 2024
- RFC 10007Clarification to Processing Key Usage Values During Certificate Revocation List (CRL) ValidationCurrent
June 2026
- RFC 10027Best Current Practice for Security of Cross-Device FlowsCurrent
August 2026
- RFC 9470OAuth 2.0 Step Up Authentication Challenge ProtocolCurrent
September 2023
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?