An advanced certificate validation service and architecture based on XKMS

نویسندگان

  • Antonio Ruiz-Martínez
  • Daniel Sánchez-Martínez
  • C. Inmaculada Marín-López
  • Manuel Gil Pérez
  • Antonio F. Gómez-Skarmeta
چکیده

The apparition of some laws that make the electronic signature (e-signature) legally equivalent to handwritten signature (under some circumstances) has favoured its use in different fields such as e-commerce, e-government, etc. In these fields, some signed documents have to be stored and remain valid over long periods of time. For this kind of e-signatures some formats such as CAdES and XAdES have appeared. These formats specify the information to include with the e-signature. Basically, this information comprises signer’s certificates, a set of certificates up to a trust anchor, certificate validation responses, etc. That is, the information needed to determine if an electronic signature is valid. These evidences can be gathered by using different PKI-compliant protocols. However, the support of the different protocols is complex for clients. XKMS appeared with the aim of simplifying the certificate management, but XKMS only supports a simple validation mechanism that does not provide the long term information needed for the CAdES/XAdES signature. As a solution to this problem, we have extended XKMS in order to support the obtaining of long term evidences needed for CAdES/XAdES signatures. With this extension we have also defined the different components that are needed to support this kind of service. Based on the definition provided, the service has been implemented and it has been incorporated to an egovernment infrastructure based on service-oriented architectures, which is able to create and verify this kind of signatures.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Certificate Validation Scheme of Open Grid Service Usage XKMS

Current Grid Security Infrastructure using PKI based on SSO. Trust is hard to establish in a service-oriented grid architecture because of the need to support end user SSO and dynamic transient service. Open Grid Service (OGS) Security Infrastructure in Global Grid Forum will extend use of Grid system or services up to business area using XML Web Service security technology. This paper describe...

متن کامل

Distributed certificate validation in MANET

The need for certificate management in mobile ad hoc networks (MANET) is the background for this report. A prototype implementation of a distributed certificate validation service is presented and evaluated. The proposed design is based on an overlay network of proxy nodes offering certificate validation over the XKMS protocol. The proxy nodes employ cooperative caching in order to offer certif...

متن کامل

Trusted Certificate Validation Scheme for Open LBS Application Based on XML Web Services

Location-based services or LBS refer to value-added service by processing information utilizing mobile user location. With the rapidly increasing wireless Internet subscribers and world LBS market, the various location based applications are introduced such as buddy finder, proximity and security services. As the killer application of the wireless Internet, the LBS have reconsidered technology ...

متن کامل

Towards the homogeneous access and use of PKI solutions: Design and implementation of a WS-XKMS server

Nowadays, there exists certain important scenarios where different WS-* security related protocols and technologies are being used, such as e-commerce, resource control, or secure access to grid nodes. Additionally, most of these scenarios require the interaction with a trust management infrastructure (such as a PKI -Public Key Infrastructure-), usually to validate the digital certificates prov...

متن کامل

Advanced certificate validation service for secure Service-Oriented Architectures

One of the most important components in e-commerce systems is the validation of digital signatures, which implies the validation of certificates in order to check the validity status of the certificates used to create a signature. Nowadays, several mechanisms to accomplish this process exist, but there is no agreement with which particular mechanism should be used in every scenario. On the othe...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Softw., Pract. Exper.

دوره 41  شماره 

صفحات  -

تاریخ انتشار 2011