Concise Binary Object Representation (CBOR) is a binary data serialisation format specified in RFC 7049 (superseded by RFC 8949) designed to enable extremely compact encoding of structured data with a data model that is a superset of JSON. CBOR encodes values using a type-length-value scheme, eliminating the overhead of textual delimiters and key quotation, which makes it particularly well-suited for constrained environments such as IoT devices, embedded systems, and low-bandwidth protocols where minimising message size and parsing complexity is critical.

Content

  • CBOR emerged from the IETF Constrained RESTful Environments (CoRE) working group’s recognition that JSON, while excellent for web APIs, was too verbose for constrained devices communicating over lossy, low-bandwidth links such as 802.15.4 radio. Carsten Bormann and Paul Hoffman authored RFC 7049, published in 2013, synthesising lessons from MessagePack, BSON, and ASN.1 BER into a format that prioritises simplicity of both implementation and specification — the CBOR spec is deliberately kept short and unambiguous to enable single-developer implementations on microcontrollers with kilobytes of RAM.
  • The encoding uses a major-type system: each data item begins with a single byte whose upper three bits identify the type (unsigned integer, negative integer, byte string, text string, array, map, tagged value, or simple/float) and whose lower five bits encode a small immediate value or indicate that additional bytes carry the length or value. This design allows integers and short strings to be encoded in as little as one byte. CBOR tags extend the type system with semantic annotations — tag 0 for datetime strings, tag 1 for epoch-based timestamps, tag 37 for UUIDs — enabling rich semantic typing without abandoning the compact base encoding.
  • CBOR’s significance has grown well beyond IoT. The COSE (CBOR Object Signing and Encryption) framework, specified in RFC 8152, provides CBOR-native equivalents of JSON Web Signature (JWS) and JSON Web Encryption (JWE), enabling efficient cryptographic operations on CBOR payloads. The W3C Verifiable Credentials Data Model specifies CBOR-LD as a compact binary Linked Data serialisation for credentials on constrained channels. ISO 18013-5 for mDL, IETF RATS (Remote ATtestation procedureS), and 5G network slicing protocols all depend on CBOR for efficient data exchange in latency- and bandwidth-sensitive paths.
  • RFC 8949, published in 2020, superseded RFC 7049 with clarifications, improved deterministic encoding rules (CDE), and a more rigorous treatment of floating-point NaN handling. In 2024-2025, CBOR continues to solidify its position as the binary serialisation layer for decentralised identity ecosystems: OpenID4VCI and ISO-compliant credential wallets on mobile devices universally adopt CBOR for credential storage and presentation. Its role in attestation protocols for trusted computing and hardware security modules further cements its status as a foundational infrastructure primitive.