Standards are supposed to guarantee security, especially in the WWW. The World Wide Web Consortium (W3C) is the main force behind standards like HTML, XML, and XML Encryption. But implementing a W3C standard does not mean that a system is secure. Researchers from the chair of network and data security have found a serious attack against XML Encryption. “Everything is insecure”, is the uncomfortable message from Bochum.
Standard for large integration projects
XML stands for “eXtensible Markup Language”, and is the industry standard for platform-independent data exchange. Companies like IBM, Microsoft and Redhat Linux use XML standards for integrating Webservice projects for large customers. XML Encryption was designed to protect the confidentiality of the exchanged data. Reason enough to have a closer look at its security.
Weak chaining of ciphertext blocks
Juraj Somorovsky and Tibor Jager exploited a weakness in the CBC mode for the chaining of different ciphertext blocks. “We were able to decrypt data by sending modified ciphertexts to the server, by gathering information from the received error messages.” The attack was tested against a popular open source implementation of XML Encrytion, and against the implementations of companies that responded to the responsible disclosure – in all cases the result was the same: the attack works, XML Encryption is not secure. Details of the attack are presented at this year’s ACM Conference on Computer and Communications Security (http://www.sigsac.org/ccs/CCS2011/techprogram.shtml).
No simple solution available
„There is no simple patch for this problem”, states Somorovsky. “We therefore propose to change the standard as soon as possible.” The researchers informed all possibly affected companies through the mailing list of W3C, following a clear responsible disclosure process. With some companies there were intensive discussions on workarounds.
Further informationProf. Dr. Jörg Schwenk, Faculty of Electrical Engineering and Information Sciences at the RUB, Chair for Network and Data Security, Tel. +49 234 32 26692
Dr. Josef König | idw
Quantum computers by AQT and University of Innsbruck leverage Cirq for quantum algorithm development
16.09.2019 | Universität Innsbruck
Artificial Intelligence speeds up photodynamics simulations
12.09.2019 | University of Vienna
Researchers from the Department of Atomically Resolved Dynamics of the Max Planck Institute for the Structure and Dynamics of Matter (MPSD) at the Center for Free-Electron Laser Science in Hamburg, the University of Hamburg and the European Molecular Biology Laboratory (EMBL) outstation in the city have developed a new method to watch biomolecules at work. This method dramatically simplifies starting enzymatic reactions by mixing a cocktail of small amounts of liquids with protein crystals. Determination of the protein structures at different times after mixing can be assembled into a time-lapse sequence that shows the molecular foundations of biology.
The functions of biomolecules are determined by their motions and structural changes. Yet it is a formidable challenge to understand these dynamic motions.
At the International Symposium on Automotive Lighting 2019 (ISAL) in Darmstadt from September 23 to 25, 2019, the Fraunhofer Institute for Organic Electronics, Electron Beam and Plasma Technology FEP, a provider of research and development services in the field of organic electronics, will present OLED light strips of any length with additional functionalities for the first time at booth no. 37.
Almost everyone is familiar with light strips for interior design. LED strips are available by the metre in DIY stores around the corner and are just as often...
Later during this century, around 2060, a paradigm shift in global energy consumption is expected: we will spend more energy for cooling than for heating....
Researchers from the Department of Atomically Resolved Dynamics of the Max Planck Institute for the Structure and Dynamics of Matter (MPSD) at the Center for Free-Electron Laser Science in Hamburg, the University of Potsdam (both in Germany) and the University of Toronto (Canada) have pieced together a detailed time-lapse movie revealing all the major steps during the catalytic cycle of an enzyme. Surprisingly, the communication between the protein units is accomplished via a water-network akin to a string telephone. This communication is aligned with a ‘breathing’ motion, that is the expansion and contraction of the protein.
This time-lapse sequence of structures reveals dynamic motions as a fundamental element in the molecular foundations of biology.
Two research teams have succeeded simultaneously in measuring the long-sought Thorium nuclear transition, which enables extremely precise nuclear clocks. TU Wien (Vienna) is part of both teams.
If you want to build the most accurate clock in the world, you need something that "ticks" very fast and extremely precise. In an atomic clock, electrons are...
10.09.2019 | Event News
04.09.2019 | Event News
29.08.2019 | Event News
18.09.2019 | Innovative Products
18.09.2019 | Physics and Astronomy
18.09.2019 | Materials Sciences