loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
15th Annual Computer Security Applications Conference (ACSAC '99)
Non-Repudiation Evidence Generation for CORBA Using XML
Phoenix, Arizona
December 06-December 10
ISBN: 0-7695-0346-2
Michael Wichert, GMD - German National Research Center for Information Technology
David Ingham, Newcastle University
Steve Caughey, Newcastle University
Electronic business transactions commonly cross organizational boundaries where there is only a limited degree of trust. In order to compensate for this lack of trust, digital signatures and encryption can be used to provide support for non-repudiation. This is achieved by generating unforgettable evidence of transactions that can be use for dispute resolution after the fact. This paper focuses on the provision of a non-repudiation service for CORBA, the industry standard middleware for distributed applications. The current OMG specification of a CORBA non-repudiation service forces the programmer to augment the application with calls to functions for generating or validating evidence. Furthermore, the application itself has to manage the exchange of this evidence between parties and its storage. The paper describes our design for a generic CORBA non-repudiation service implementation. Our approach provides a separation between the application business logic and the generation of evidence allowing non-repudiation support to be incorporated into applications with the minimum of programmer effort. The paper begins with an overview of the CORBA non-repudiation security service specification, illustrating its importance for electronic commerce. Our design is then described using the example of ordering goods over the Internet. The non-repudiation service provides the parties with evidence proving that the transaction has taken place. This proof is a XML document based on the proposed IETF Internet standard Digital Signatures for XML.
Index Terms:
Security, CORBA, XML, non-repudiation, e-commerce
Citation:
Michael Wichert, David Ingham, Steve Caughey, "Non-Repudiation Evidence Generation for CORBA Using XML," acsac, pp.320, 15th Annual Computer Security Applications Conference (ACSAC '99), 1999
Usage of this product signifies your acceptance of the Terms of Use.