Summary
- RFC 10020 applies Group OSCORE to CoAP group communication; it gives a bounded protected message a group security context.
- A group context, a valid request and even one response do not prove that every intended receiver was current, authorised, reachable, accepting or effective.
RFC 10020 is useful precisely because it does not pretend a group is a single endpoint. It specifies protected group communication for CoAP and relies on Group OSCORE. The sender can create a protected request within a shared group context. That is evidence about the message and the cryptographic rules applied to it. It is not a ledger of every receiver's present condition.
The distinction is operational. A group manager may have issued credentials; a sender may hold a current context; a request may traverse a multicast-capable path; a receiver may verify it under OSCORE. Each statement has a different owner and time. One device may be offline, another may have lost state, a third may reject the operation under local safety policy, and a fourth may execute it but fail to produce the intended physical result. Calling the message “the group action” turns those unknowns into a false collective success.
CoAP and its group-communication context preserve this restraint. CoAP, group communication, and token/request-tag processing give protocol roles to request, delivery and correlation. None assigns an application's permission or proves completion at all recipients. OSCORE adds protected fields, message binding, freshness and replay controls. Its application still decides when protection is required and what a verified message is allowed to cause.
This is Daniel Kade's editorial reading of Heng Lu's minimum-common-layer and running-code doctrine, not an IETF rule. A portable group mechanism makes later local decisions possible; it does not inherit those decisions. The evidence chain must remain: policy and membership epoch, context distribution, sender protection, transport observation, individual verification, local authorisation, actuator or service result, and independent observation.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

