首页> 外国专利> method and system for protecting a message in an xml attack the exchange in a distributed and decentralized networking system

method and system for protecting a message in an xml attack the exchange in a distributed and decentralized networking system

机译:xml中保护消息的方法和系统攻击分布式分散网络系统中的交换

摘要

A method for protecting a message from an XML rewriting attack when being exchanged in a distributed and decentralized network system between an initial sender and an ultimate receiver is provided, wherein the message comprises message elements including a number of signed message elements and is represented in a tree structure formed by the message elements with an envelope as its root with at least two children, a body and a header, the header having at least a first attack preventing header block, wherein all message elements are represented by a unique ID attribute, respectively, and the initial sender sends the message together with structure specific information of the message to the ultimate receiver, wherein the information is carried by the first attack preventing header block and comprises at least a digest value of a pre-order traversal list of the message tree and for each signed message element targeted to the ultimate receiver the ID attribute, a depth, a parent's name and the parent's ID attribute, so that the ultimate receiver when receiving the message can identify any XML rewriting attack against any one of the signed message elements by comparing the structure specific information which can be derived from the received message with the information carried by the attack preventing header block. Furthermore, an appropriate system is disclosed.
机译:本发明提供一种用于保护消息在初始发送方和最终接收方之间的分布式和分散式网络系统中交换时免受XML重写攻击的方法,其中该消息包括包含多个签名消息元素的消息元素,并以由消息元素形成的树结构,该消息元素以信封为根,具有至少两个子元素,一个主体和一个标头,该标头至少具有一个第一个防止攻击标头块,其中所有消息元素分别由唯一的ID属性表示,并且初始发送者将该消息连同消息的结构特定信息一起发送给最终接收者,其中该信息由第一防攻击头块携带,并且至少包括消息的预遍历列表的摘要值树和针对最终接收者的每个签名消息元素的ID属性,深度,父级名称和d父级的ID属性,以便最终接收方在接收消息时可以通过比较可以从接收到的消息派生的特定于结构的信息与攻击所携带的信息,来识别针对任何已签名消息元素的XML重写攻击防止头块。此外,公开了一种适当的系统。

著录项

  • 公开/公告号DE602007000919D1

    专利类型

  • 公开/公告日2009-05-28

    原文格式PDF

  • 申请/专利权人 SAP AG;

    申请/专利号DE20076000919T

  • 发明设计人 RITS MAARTEN;KADIR FAISAL ABDUL;

    申请日2007-05-18

  • 分类号H04L29/06;H04L12/22;

  • 国家 DE

  • 入库时间 2022-08-21 19:07:58

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号