Refine
Departments, institutes and facilities
- Fachbereich Informatik (58)
- Fachbereich Wirtschaftswissenschaften (44)
- Institut für funktionale Gen-Analytik (IFGA) (33)
- Präsidium (29)
- Fachbereich Angewandte Naturwissenschaften (27)
- Institute of Visual Computing (IVC) (18)
- Fachbereich Ingenieurwissenschaften und Kommunikation (13)
- Institut für Cyber Security & Privacy (ICSP) (13)
- Fachbereich Sozialpolitik und Soziale Sicherung (6)
- Institut für Verbraucherinformatik (IVI) (6)
Document Type
- Article (107)
- Conference Object (64)
- Part of a Book (47)
- Part of Periodical (29)
- Book (monograph, edited volume) (21)
- Report (7)
- Lecture (5)
- Master's Thesis (5)
- Doctoral Thesis (4)
- Contribution to a Periodical (3)
Year of publication
- 2012 (301) (remove)
Keywords
- Wirtschaftsethik (7)
- Corporate Social Responsibility (5)
- Macht (5)
- Unternehmensethik (5)
- Ethik (4)
- ENaC (3)
- ISM: molecules (3)
- Lehrbuch (3)
- Management (3)
- Vertrauen (3)
XML Encryption and XML Signature are fundamental security standards forming the core for many applications which require to process XML-based data. Due to the increased usage of XML in distributed systems and platforms such as in SOA and Cloud settings, the demand for robust and effective security mechanisms increased as well. Recent research work discovered, however, substantial vulnerabilities in these standards as well as in the vast majority of the available implementations. Amongst them, the so-called XML Signature Wrapping attack belongs to the most relevant ones. With the many possible instances of this attack type, it is feasible to annul security systems relying on XML Signature and to gain access to protected resources as has been successfully demonstrated lately for various Cloud infrastructures and services. This paper contributes a comprehensive approach to robust and effective XML Signatures for SOAP-based Web Services. An architecture is proposed, which integrates the r equired enhancements to ensure a fail-safe and robust signature generation and verification. Following this architecture, a hardened XML Signature library has been implemented. The obtained evaluation results show that the developed concept and library provide the targeted robustness against all kinds of known XML Signature Wrapping attacks. Furthermore the empirical results underline, that these security merits are obtained at low efficiency and performance costs as well as remain compliant with the underlying standards.