XMLDSIG - PowerPoint PPT Presentation

1 / 11
About This Presentation
Title:

XMLDSIG

Description:

IETF-W3C-OSLO July 99. XML-DSIG. Richard D. Brown. GlobeSet, Inc. Austin TX - U.S.. Proposal for XML Digital Signature. IETF-W3C-OSLO July 99. Summary ... – PowerPoint PPT presentation

Number of Views:69
Avg rating:3.0/5.0
Slides: 12
Provided by: williamca
Category:
Tags: xmldsig | austin | texas

less

Transcript and Presenter's Notes

Title: XMLDSIG


1
XML-DSIG
  • Richard D. Brown
  • GlobeSet, Inc. Austin TX - U.S.
  • Proposal for XML Digital Signature

2
Summary
  • Objectives
  • Specification Process
  • Syntax Basics
  • Crypto-Algorithms
  • Conclusion

3
Objectives
  • Define syntax and procedures for the computation,
    verification, and encoding of digital signatures
    using XML
  • Signing XML document and element
  • Using XML for signing WEB resources

4
Specification Process - 1
5
Specification Process - 2
6
Specification Process - 3
7
Syntax Basics
ltCertificatesgt (certificate
information blocks) lt/Certificatesgt
  • ltSignaturegt
  • lt/Signaturegt

ltManifestgt (Authenticated
Attributes) lt/Manifestgt
ltValuegt (Signature Value)
lt/Valuegt
8
Signature Manifest
ltManifestgt What... How...
lt/Manifestgt
Resources Locator Digest
Attributes Name Value
Keying Material Originator Recipient
Algorithms Canonicalizer Signature Key
Agreement
9
Signature Example
  • ltSignaturegt
  • lt Manifestgt
  • ltResourcegt
  • ltLocator hrefhttp//on-the-web.xmlgt
  • ltDigestgt
  • ltAlgorithm typeurnnist-govsha1
    /gt
  • ltValuegt
  • bert456fd789lldzf24
  • lt/Valuegt
  • lt/Digestgt
  • lt/Resourcegt
  • ltOriginatorInfogt
  • ltIssuerAndSerialNumber
  • issueroGlobeset, cUS
  • number1234567890/gt
  • ltSignatureAlgorithmgt
  • ltAlgorithm typeurnnist-govdsa/gt
  • lt/SignatureAlgorithmgt
  • lt/Manifestgt

10
Crypto-Algorithms
  • Digest Algorithm
  • NIST SHA1
  • Canonicalizers
  • W3C - XML-Canonicalizer
  • IBM - DOM-Hash
  • Globeset - XHash
  • Key-agreement Algorithms
  • RSA - PKCS12 PBE
  • Key-exchange Algorithms
  • Static Diffie Hellman
  • Signature/Authentication Algorithms
  • IETF - HMAC
  • NIST - DSA
  • RSA - PKCS1
  • ECDSA

11
Conclusion
  • Current Proposal
  • Something to start with
  • Currently enters phase 3
  • First implementation (IBM Tokyo)
  • Next
  • Standard Tracks (IETF-W3C)
  • Concensus - Standard Specification
  • Standard Implementations
Write a Comment
User Comments (0)
About PowerShow.com