W3C backs XML-based digital signature

The premier Web standards body has recommended a way of signing documents using XML, calling its new digital signature guidelines a key tool for Web services infrastructure.

The World Wide Web Consortium's (W3C) XML Signature recommendation, developed in conjunction with the Internet Engineering Task Force ( IETF), provides a standard way of signing XML documents so that recipients can verify the identity of the sender and the integrity of the data.

Those guarantees are crucial to Web services, an area the W3C has been criticised for neglecting

"XML Signature is a critical foundation on top of which we will be able to build more secure Web services," W3C founder and director Tim Berners-Lee said in a statement. "By offering basic data integrity and authentication tools, XML Signature provides new power for applications that enable trusted transactions of all sorts."

The digital signature is just one tool in a group under construction at the W3C required for secure transactions.

While the signature verifies a sender's identity and the data's integrity, an encryption method is required to scramble the message and prevent its being read en route to the recipient. The W3C is at work on XML Encryption.

The W3C is also developing XML Key Management, which lets XML applications get keys required for the signature and encryption process.

The signature recommendation, while built in XML and designed with XML documents in mind, can be used to sign other kinds of documents as well.

Analysts hailed the new signature recommendation, formally known as XML-Signature Syntax and Processing, saying it could help ward off a Tower of Babel for digital signing methods.

"Without a standard spec, you're left to your own devices either to use a working draft or use a supplemental technology," said Matthew Berk, an analyst with Jupiter Media Metrix. "People are using all kinds of things. The whole point of having a standard is that there's one less thing we have to worry about."

The XML Signature working group is the first formal joint project between the W3C and the IETF. One step remains before the IETF process for ratifying specifications is complete, but the W3C considers the recommendation finished.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Chris Duckett Get extensions going in Firefox, redux
    Previously on Null Pointer we looked at getting extensions working in Firefox betas, and that was great until the fine folks at Firefox changed their minds.
  • Array How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • More blogs »

Tags

Back to top

Featured