|
|
|
Design and Implementation of a File Transfer and Web Services Guard Employing Cryptographically Secured XML Security LabelsAndreas Thuemmel and Knut EcksteinThe 7th IEEE Information Assurance Workshop (IAWorkshop 2006)West Point, New York, USA, June 21-23, 2006
AbstractThis publication introduces the concept of cryptographically secured, eXtended Markup Language (XML) based Security Labels, which either globally label any non-XML electronic document, or label individual sections of an XML infoset. It further describes the architecture and implementation of a guard prototype for file transfer and web services based appliations. This prototype employs the XML security labels to verify information classification prior to releasing information across a security domain boundary separating enclaves belonging to different security domains. If necessary, XML infosets containing information at multiple security levels can be redacted by the guard filtering algorithms to create a releasable subset of the original XML infoset or document.
|
|