GI LogoGI Logo
  • Login
Digital Library
    • All of DSpace

      • Communities & Collections
      • Titles
      • Authors
      • By Issue Date
      • Subjects
    • This Collection

      • Titles
      • Authors
      • By Issue Date
      • Subjects
Digital Library Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • English 
    • English
    • Deutsch
View Item 
  •   DSpace Home
  • Lecture Notes in Informatics
  • Proceedings
  • Open Identity Summit
  • P293 - Open Identity Summit 2019
  • View Item
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   DSpace Home
  • Lecture Notes in Informatics
  • Proceedings
  • Open Identity Summit
  • P293 - Open Identity Summit 2019
  • View Item

Security Analysis of XAdES Validation in the CEF Digital Signature Services (DSS)

Author:
Engelbertz, Nils [DBLP] ;
Mladenov, Vladislav [DBLP] ;
Somorovsky, Juraj [DBLP] ;
Herring, David [DBLP] ;
Erinola, Nurullah [DBLP] ;
Schwenk, Jörg [DBLP]
Abstract
Within the European Union (EU), the eIDAS regulation sets legal boundaries for crossborder acceptance of Trust Services (TSs) such as Electronic Signatures. To facilitate compliant implementations, an open source software library to create and validate signed documents is provided by the eSignature building block of the Connecting Europe Facility (CEF). We systematically evaluated the validation logic of this library with regards to XML-based attacks. The discovered vulnerabilities allowed us to read server files and bypass XML Advanced Electronic Signature (XAdES) protections. The seriousness of the vulnerabilities shows that there is an urgent need for security best-practice documents and automatic security evaluation tools to support the development of security-relevant implementations.
  • Citation
  • BibTeX
Engelbertz, N., Mladenov, V., Somorovsky, J., Herring, D., Erinola, N. & Schwenk, J., (2019). Security Analysis of XAdES Validation in the CEF Digital Signature Services (DSS). In: Roßnagel, H., Wagner, S. & Hühnlein, D. (Hrsg.), Open Identity Summit 2019. Gesellschaft für Informatik, Bonn. (S. 95-106).
@inproceedings{mci/Engelbertz2019,
author = {Engelbertz, Nils AND Mladenov, Vladislav AND Somorovsky, Juraj AND Herring, David AND Erinola, Nurullah AND Schwenk, Jörg},
title = {Security Analysis of XAdES Validation in the CEF Digital Signature Services (DSS)},
booktitle = {Open Identity Summit 2019},
year = {2019},
editor = {Roßnagel, Heiko AND Wagner, Sven AND Hühnlein, Detlef} ,
pages = { 95-106 },
publisher = {Gesellschaft für Informatik, Bonn},
address = {}
}
DateienGroesseFormatAnzeige
proceedings-08.pdf1.904Mb PDF View/Open

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Send Feedback

More Info

ISBN: 978-3-88579-687-9
ISSN: 1617-5468
xmlui.MetaDataDisplay.field.date: 2019
Language: en (en)

Keywords

  • XML Signature
  • XSLT
  • DTD
  • Digital Signature Service
  • Trust Services
Collections
  • P293 - Open Identity Summit 2019 [19]

Show full item record


About uns | FAQ | Help | Imprint | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


About uns | FAQ | Help | Imprint | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.