@misc{rfc9140, series = {Request for Comments}, number = 9140, howpublished = {RFC 9140}, publisher = {RFC Editor}, doi = {10.17487/RFC9140}, url = {https://www.rfc-editor.org/info/rfc9140}, author = {Tuomas Aura and Mohit Sethi and Aleksi Peltonen}, title = {{Nimble Out-of-Band Authentication for EAP (EAP-NOOB)}}, pagetotal = 51, year = 2021, month = dec, abstract = {The Extensible Authentication Protocol (EAP) provides support for multiple authentication methods. This document defines the EAP-NOOB authentication method for nimble out-of-band (OOB) authentication and key derivation. The EAP method is intended for bootstrapping all kinds of Internet-of-Things (IoT) devices that have no preconfigured authentication credentials. The method makes use of a user-assisted, one-directional, out-of-band (OOB) message between the peer device and authentication server to authenticate the in-band key exchange. The device must have a nonnetwork input or output interface, such as a display, microphone, speaker, or blinking light, that can send or receive dynamically generated messages of tens of bytes in length.}, }