<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-ace-revoked-token-notification" target="https://datatracker.ietf.org/doc/html/draft-ietf-ace-revoked-token-notification-07">
   <front>
      <title>Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) Framework</title>
      <author initials="M." surname="Tiloca" fullname="Marco Tiloca">
         <organization>RISE AB</organization>
      </author>
      <author initials="F." surname="Palombini" fullname="Francesca Palombini">
         <organization>Ericsson AB</organization>
      </author>
      <author initials="S." surname="Echeverria" fullname="Sebastian Echeverria">
         <organization>CMU SEI</organization>
      </author>
      <author initials="G." surname="Lewis" fullname="Grace Lewis">
         <organization>CMU SEI</organization>
      </author>
      <date month="May" day="27" year="2024" />
      <abstract>
	 <t>   This document specifies a method of the Authentication and
   Authorization for Constrained Environments (ACE) framework, which
   allows an Authorization Server to notify Clients and Resource Servers
   (i.e., registered devices) about revoked access tokens.  As specified
   in this document, the method allows Clients and Resource Servers to
   access a Token Revocation List on the Authorization Server by using
   the Constrained Application Protocol (CoAP), with the possible
   additional use of resource observation.  Resulting (unsolicited)
   notifications of revoked access tokens complement alternative
   approaches such as token introspection, while not requiring
   additional endpoints on Clients and Resource Servers.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-ace-revoked-token-notification-07" />
   
</reference>
