计算机应用 ›› 2011, Vol. 31 ›› Issue (03): 808-811.DOI: 10.3724/SP.J.1087.2011.00808

• 信息安全 • 上一篇    下一篇

XML数字签名在工作流系统中的应用

傅德胜,王强   

  1. 南京信息工程大学 计算机与软件学院,南京210044
  • 收稿日期:2010-09-10 修回日期:2010-10-29 发布日期:2011-03-03 出版日期:2011-03-01
  • 通讯作者: 王强
  • 作者简介:傅德胜(1950-),男,江苏靖江人,教授,博士生导师,主要研究方向:信息安全;王强(1985-),男,江苏泰州人,硕士研究生,主要研究方向:信息安全。

XML digital signature application in workflow system

FU De-sheng,WANG Qiang   

  1. School of Computer and Software, Nanjing University of Information Science and Technology, Nanjing Jiangsu 210044, China
  • Received:2010-09-10 Revised:2010-10-29 Online:2011-03-03 Published:2011-03-01
  • Contact: WANG Qiang

摘要: 针对工作流系统中存在的多重签名以及对文档进行较细粒度的签名需求,提出了“签名之上的签名”的机制,建立了以该机制为核心的XML数字签名在工作流系统中的应用模型。该模型通过将待签名的文档转化为XML数据,方便了系统对待签文档的处理。在对XML文档的处理进程中,各处理节点在前任处理节点的基础上对待签XML文档进行验证和签名。最后开发了采购审批工作流系统,并通过一个典型的采购审批场景验证了该模型的正确性和有效性,为XML数字签名在工作流系统中的应用提供了可行的解决途径。

关键词: XML数字签名, 工作流, 多重签名, 部分签名, XPath

Abstract: In view of the demand for multi-signature and fine-grained signature in workflow systems, the authors proposed the "Signature on Signature" mechanism and put forward an application model of eXtensible Markup Language (XML) signature in workflow systems. In this model, the document to be signed was converted to XML format, and this facilitated the handling of the document for the system. In the processing of the XML document, every processing node signed and verified on the basis of the former processing node. In the end, a purchase approval workflow system was developed. Taking a typical purchase approval scenario for example, the validity and effectiveness of the presented model were verified, and a feasible solution was provided for the application of XML digital signature in workflow systems.

Key words: eXtensible Markup Language (XML) digital signature, workflow, multi-signature, partial signature, XPath

中图分类号: