XML.com: XML From the Inside Out
oreilly.comSafari Bookshelf.Conferences.

advertisement
 Resource Guide -> W3C Standards, Security -> Decryption Transform for XML Signature

Decryption Transform for XML Signature

Recommendation

Date: Oct. 3, 2002
Link: http://www.w3.org/TR/xmlenc-decrypt
Source Author or Organization: W3C

Decryption Transform for XML Signature provides a decryption transform mechanism that allows decryption and verification of a signature that has itself been encrypted in an XML document. This could be the case, for example, if two parties to a sale encrypted and signed their information in sequence (the first signature would itself be encrypted).

This document describes the functions and processing rules of the transform and discusses limitations and security concerns, such as the question of whether a signature over encrypted data increases the encrytions vulnerability to plain-text-guessing attacks.