An advanced certificate validation service and architecture based on XKMS
نویسندگان
چکیده
The apparition of some laws that make the electronic signature (e-signature) legally equivalent to handwritten signature (under some circumstances) has favoured its use in different fields such as e-commerce, e-government, etc. In these fields, some signed documents have to be stored and remain valid over long periods of time. For this kind of e-signatures some formats such as CAdES and XAdES have appeared. These formats specify the information to include with the e-signature. Basically, this information comprises signer’s certificates, a set of certificates up to a trust anchor, certificate validation responses, etc. That is, the information needed to determine if an electronic signature is valid. These evidences can be gathered by using different PKI-compliant protocols. However, the support of the different protocols is complex for clients. XKMS appeared with the aim of simplifying the certificate management, but XKMS only supports a simple validation mechanism that does not provide the long term information needed for the CAdES/XAdES signature. As a solution to this problem, we have extended XKMS in order to support the obtaining of long term evidences needed for CAdES/XAdES signatures. With this extension we have also defined the different components that are needed to support this kind of service. Based on the definition provided, the service has been implemented and it has been incorporated to an egovernment infrastructure based on service-oriented architectures, which is able to create and verify this kind of signatures.
منابع مشابه
Certificate Validation Scheme of Open Grid Service Usage XKMS
Current Grid Security Infrastructure using PKI based on SSO. Trust is hard to establish in a service-oriented grid architecture because of the need to support end user SSO and dynamic transient service. Open Grid Service (OGS) Security Infrastructure in Global Grid Forum will extend use of Grid system or services up to business area using XML Web Service security technology. This paper describe...
متن کاملDistributed certificate validation in MANET
The need for certificate management in mobile ad hoc networks (MANET) is the background for this report. A prototype implementation of a distributed certificate validation service is presented and evaluated. The proposed design is based on an overlay network of proxy nodes offering certificate validation over the XKMS protocol. The proxy nodes employ cooperative caching in order to offer certif...
متن کاملTrusted Certificate Validation Scheme for Open LBS Application Based on XML Web Services
Location-based services or LBS refer to value-added service by processing information utilizing mobile user location. With the rapidly increasing wireless Internet subscribers and world LBS market, the various location based applications are introduced such as buddy finder, proximity and security services. As the killer application of the wireless Internet, the LBS have reconsidered technology ...
متن کاملTowards the homogeneous access and use of PKI solutions: Design and implementation of a WS-XKMS server
Nowadays, there exists certain important scenarios where different WS-* security related protocols and technologies are being used, such as e-commerce, resource control, or secure access to grid nodes. Additionally, most of these scenarios require the interaction with a trust management infrastructure (such as a PKI -Public Key Infrastructure-), usually to validate the digital certificates prov...
متن کاملAdvanced certificate validation service for secure Service-Oriented Architectures
One of the most important components in e-commerce systems is the validation of digital signatures, which implies the validation of certificates in order to check the validity status of the certificates used to create a signature. Nowadays, several mechanisms to accomplish this process exist, but there is no agreement with which particular mechanism should be used in every scenario. On the othe...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Softw., Pract. Exper.
دوره 41 شماره
صفحات -
تاریخ انتشار 2011