@techreport{ietf-ace-pubsub-profile-09, number = {draft-ietf-ace-pubsub-profile-09}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-ace-pubsub-profile/09/}, author = {Francesca Palombini and Cigdem Sengul and Marco Tiloca}, title = {{Publish-Subscribe Profile for Authentication and Authorization for Constrained Environments (ACE)}}, pagetotal = 49, year = 2024, month = mar, day = 4, abstract = {This document defines an application profile of the Authentication and Authorization for Constrained Environments (ACE) framework, to enable secure group communication in the Publish-Subscribe (pub/sub) architecture for the Constrained Application Protocol (CoAP) {[}draft- ietf-core-coap-pubsub{]}, where Publishers and Subscribers communicate through a Broker. This profile relies on protocol-specific transport profiles of ACE to achieve communication security, server authentication, and proof-of-possession for a key owned by the Client and bound to an OAuth 2.0 Access Token. This document specifies the provisioning and enforcement of authorization information for Clients to act as Publishers and/or Subscribers, as well as the provisioning of keying material and security parameters that Clients use for protecting their communications end-to-end through the Broker. Note to RFC Editor: Please replace "{[}draft-ietf-core-coap-pubsub{]}" with the RFC number of that document and delete this paragraph.}, }