Logo des Repositoriums
 

Security Analysis of XAdES Validation in the CEF Digital Signature Services (DSS)

dc.contributor.authorEngelbertz, Nils
dc.contributor.authorMladenov, Vladislav
dc.contributor.authorSomorovsky, Juraj
dc.contributor.authorHerring, David
dc.contributor.authorErinola, Nurullah
dc.contributor.authorSchwenk, Jörg
dc.contributor.editorRoßnagel, Heiko
dc.contributor.editorWagner, Sven
dc.contributor.editorHühnlein, Detlef
dc.date.accessioned2019-03-25T09:22:03Z
dc.date.available2019-03-25T09:22:03Z
dc.date.issued2019
dc.description.abstractWithin the European Union (EU), the eIDAS regulation sets legal boundaries for crossborder acceptance of Trust Services (TSs) such as Electronic Signatures. To facilitate compliant implementations, an open source software library to create and validate signed documents is provided by the eSignature building block of the Connecting Europe Facility (CEF). We systematically evaluated the validation logic of this library with regards to XML-based attacks. The discovered vulnerabilities allowed us to read server files and bypass XML Advanced Electronic Signature (XAdES) protections. The seriousness of the vulnerabilities shows that there is an urgent need for security best-practice documents and automatic security evaluation tools to support the development of security-relevant implementations.en
dc.identifier.isbn978-3-88579-687-9
dc.identifier.pissn1617-5468
dc.identifier.urihttps://dl.gi.de/handle/20.500.12116/20997
dc.language.isoen
dc.publisherGesellschaft für Informatik, Bonn
dc.relation.ispartofOpen Identity Summit 2019
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P293
dc.subjectXML Signature
dc.subjectXSLT
dc.subjectDTD
dc.subjectDigital Signature Service
dc.subjectTrust Services
dc.titleSecurity Analysis of XAdES Validation in the CEF Digital Signature Services (DSS)en
gi.citation.endPage106
gi.citation.startPage95
gi.conference.date28.-29. March 2019
gi.conference.locationGarmisch-Partenkirchen, Germany
gi.conference.sessiontitleRegular Research Papers

Dateien

Originalbündel
1 - 1 von 1
Lade...
Vorschaubild
Name:
proceedings-08.pdf
Größe:
1.9 MB
Format:
Adobe Portable Document Format