<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-core-oscore-capable-proxies" target="https://datatracker.ietf.org/doc/html/draft-ietf-core-oscore-capable-proxies-07">
   <front>
      <title>OSCORE-capable Proxies</title>
      <author initials="M." surname="Tiloca" fullname="Marco Tiloca">
         <organization>RISE AB</organization>
      </author>
      <author initials="R." surname="Höglund" fullname="Rikard Höglund">
         <organization>RISE AB</organization>
      </author>
      <date month="July" day="6" year="2026" />
      <abstract>
	 <t>   When using the Constrained Application Protocol (CoAP), messages
   exchanged between two endpoints can be protected end-to-end at the
   application layer by means of Object Security for Constrained RESTful
   Environments (OSCORE), also in the presence of intermediaries such as
   proxies.  This document defines how to use OSCORE for protecting CoAP
   messages also between an origin application endpoint and an
   intermediary, or between two intermediaries.  Also, it defines rules
   to escalate the protection of a CoAP option, in order to encrypt and
   integrity-protect it whenever possible.  Finally, it defines how to
   secure a CoAP message by applying multiple, nested OSCORE
   protections, e.g., both end-to-end between origin application
   endpoints; and between an application endpoint and an intermediary or
   between two intermediaries.  Therefore, this document updates RFC
   8613.  Furthermore, this document updates RFC 8768, by explicitly
   defining the processing with OSCORE for the CoAP Hop-Limit Option.
   The approach defined in this document can be seamlessly employed also
   with Group OSCORE, for protecting CoAP messages when group
   communication is used in the presence of intermediaries.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-core-oscore-capable-proxies-07" />
   
</reference>
