Surf'N'Sign: Client signatures on Web documents

被引:2
作者
Herzberg, A [1 ]
Naor, D [1 ]
机构
[1] IBM Corp, Div Res, Haifa Res Lab Tel Aviv, Network Comp & Secur Grp, IL-61336 Tel Aviv, Israel
关键词
D O I
10.1147/sj.371.0061
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of World Wide Web-based systems and Web transactions has led to the need to find a mechanism that provides electronic signature capabilities as a replacement for written signatures. Such a mechanism should guarantee authentication and nonrepudiation. Many Web applications could benefit greatly from such a mechanism, e.g., banking systems, tax filing, reservation systems, and corporate procedures. This paper discusses the various approaches that could be taken to provide such a mechanism and suggests a solution that provides client commitment on Web documents by means of digital signatures. The architecture and implementation of the solution, called Surf'N'Sign, is outlined in detail. Our design of the solution gives special consideration to the semantics of such a signature and to its proper and secure use on the Web. Its prototype was implemented at the ISM Haifa Research as a plug-in to the Netscape browser and is integrated naturally into the browsing process. It provides a signing mechanism at the client, as well as the capability to archive and preview the signed documents. Surf'N'Sign lends itself to easy integration with existing applications on the Web.
引用
收藏
页码:61 / 71
页数:11
相关论文
共 12 条
  • [1] ASHOKAN A, 1997, IN PRESS J COMPUTER
  • [2] *CYL CORP, PUBL KEY CRYPT DIG I
  • [3] NEW DIRECTIONS IN CRYPTOGRAPHY
    DIFFIE, W
    HELLMAN, ME
    [J]. IEEE TRANSACTIONS ON INFORMATION THEORY, 1976, 22 (06) : 644 - 654
  • [4] HERZBERG A, 1997, P 6 WWW C APR, P239
  • [5] *INT PGP HOM PAG, PRETT GOOD PRIV
  • [6] *NETSC COMM CORP, SSL PROT
  • [7] OLIPHANT Z, 1996, PROGRAMMING NETSCAPE
  • [8] RIVEST RL, 1978, COMMUN ACM, V21, P120, DOI 10.1145/357980.358017
  • [9] Schneier B., 1995, E MAIL SECURITY
  • [10] SHEN, SECURITY SCHEME WORL