RFC 9820: Authentication Service Based on the Extensible Authentication Protocol (EAP) for Use with the Constrained Application Protocol (CoAP)
In plain English — editorial summary, not part of the RFC
This document specifies an authentication service that uses the Constrained Application Protocol (CoAP) as a transport method to carry the Extensible Authentication Protocol (EAP). As such, it defines an EAP lower layer based on CoAP called "CoAP-EAP". One of the main goals is to authenticate a CoAP-enabled Internet of Things (IoT) device (EAP peer) that intends to join a security domain managed by a Controller (EAP authenticator). Secondly, it allows deriving key material to protect CoAP messages exchanged between them based on Object Security for Constrained RESTful Environments (OSCORE), enabling the establishment of a security association between them.
Document record
- Document ID
- RFC9820
- Published
- September 2025
- Authors
- R. Marin-Lopez; D. Garcia-Carrillo
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 35
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7959Block-Wise Transfers in the Constrained Application Protocol (CoAP)Updated
August 2016
- RFC 7228Terminology for Constrained-Node NetworksCurrent
May 2014
- RFC 7744Use Cases for Authentication and Authorization in Constrained EnvironmentsCurrent
January 2016
- RFC 9011Static Context Header Compression and Fragmentation (SCHC) over LoRaWANCurrent
April 2021
- RFC 8724SCHC: Generic Framework for Static Context Header Compression and FragmentationUpdated
April 2020
- RFC 8323CoAP (Constrained Application Protocol) over TCP, TLS, and WebSocketsUpdated
February 2018
- RFC 74006LoWPAN-GHC: Generic Header Compression for IPv6 over Low-Power Wireless Personal Area Networks (6LoWPANs)Current
November 2014
- RFC 9770Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) FrameworkCurrent
June 2025
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?