@misc{rfc9431, series = {Request for Comments}, number = 9431, howpublished = {RFC 9431}, publisher = {RFC Editor}, doi = {10.17487/RFC9431}, url = {https://www.rfc-editor.org/info/rfc9431}, author = {Cigdem Sengul and Anthony Kirby}, title = {{Message Queuing Telemetry Transport (MQTT) and Transport Layer Security (TLS) Profile of Authentication and Authorization for Constrained Environments (ACE) Framework}}, pagetotal = 33, year = 2023, month = jul, abstract = {This document specifies a profile for the Authentication and Authorization for Constrained Environments (ACE) framework to enable authorization in a publish-subscribe messaging system based on Message Queuing Telemetry Transport (MQTT). Proof-of-Possession keys, bound to OAuth 2.0 access tokens, are used to authenticate and authorize MQTT Clients. The protocol relies on TLS for confidentiality and MQTT server (Broker) authentication.}, }