skip to main content
10.5555/1267549.1267563guideproceedingsArticle/Chapter ViewAbstractPublication PagesConference Proceedingsacm-pubtype
Article

Towards web security using PLASMA

Published:26 January 1998Publication History

ABSTRACT

The World Wide Web is one of the most significant multi-media applications ever developed-and therefore securing the web is one of the most pressing problems. There exist a number of approaches for securing the World Wide Web which, however, usually pursue what one might call a low level approach without being able to give adequate consideration to the specific requirements of this multi-media (or hypertext) system.

The subject of this paper is the realization of an adequate security system, which is capable of detecting the different media and structures within hypertext systems and therefore apply different cryptographic mechanisms to them; this resulted in the development of the system PLASMA (Platform for Secure Multimedia Applications).

PLASMA is a security platform designed within the frame of the Berkom R&D-programme at the Fraunhofer-IGD in Darmstadt whose prototype was developed to provide a means for secure multimedia telecommunications. In order to demonstrate the capabilities of PLASMA, it was integrated into a W3 scenario. The advantages of PLASMA when used in the World Wide Web as well as the architecture created for the integration process are described in the following section.

References

  1. {1} T. Berners-Lee, A. Luotonen, H. F. Nielsen, A. Secret (1994) The World-Wide-Web. Communications of the ACM, Vol.37 No. 8.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. {2} H. Cheng, X. Li (1996) On the application of image decomposition to image compression and encryption. Chapman & Hall, Communications and Multimedia Security II, ed. P. Horster, 116-127.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. {3} B. Fernandez, R. Nair, M. Larrondo-Petrie, Y. Xu (1996) High-Level Security Issuses in Multimedia/ Hypertext Systems. Chapman & Hall, Communications and Multimedia Security II, ed. P. Horster, 13-24.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. {4} R. Fielding, J. Gettys, J. Mogul (1996) Hypertext Transfer Protocol - HTTP/1.1. IETF draft.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. {5} A. O. Freier, P. Karlton, P. C. Kocher (1996) The SSL Protocol Version 3.0. Netscape Communications Corporation.]]Google ScholarGoogle Scholar
  6. {6} M. Gehrke, E. Koch (1992) A Security Platform for Future Telecommunication Applications and Services. Proc. of the 6th Joint European Networking Conference.]]Google ScholarGoogle Scholar
  7. {7} A. Krannig (1996) PLASMA - Platform for Secure Multimedia Applications. Chapman & Hall, Communications and Multimedia Security II, ed. P. Horster.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. {8} A. Krannig, H. Daum (1996) PLASMA - The Application Independent API. Fraunhofer-IGD Darmstadt, Technical Report.]]Google ScholarGoogle Scholar
  9. {9} Linn, J. (1993) RFC 1508 - Generic Security Service Application Programming Interface.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. {10} P. Lipp, v. Hassler (1996) Security concepts for WWW. Chapman & Hall, Communications and Multimedia Security II, ed. P. Horster.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. {11} NCSA (1996) CCI Specification. http://www.ncsa.uiuc.edu/SDG/Software/ XMosaic/CCI/cci-spec.html.]]Google ScholarGoogle Scholar
  12. {12} NCSA (1996) CGI The Common Gateway Interface. http://hoohoo.ncsa.uiuc.edu/cgi/.]]Google ScholarGoogle Scholar
  13. {13} H. Reif (Juni 1997) Secure Socket Layer: Chiffrieren und Zertifizieren mit SSLeay. IX Multiuser Multitasking Magazin.]]Google ScholarGoogle Scholar
  14. {14} E. Rescorla, A. Schiffman (1996) The Secure HyperText Transfer Protocol. IETF draft.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. {15} B. Schneier (1996) Applied Cryptography, 2nd ed. Wiley.]]Google ScholarGoogle Scholar
  16. {16} W. Schneider (1993) SecuDe: Overview. GMD-TKT Darmstadt.]]Google ScholarGoogle Scholar
  17. {17} Wray, J. (1993) RFC 1509 - Generic Security Service API : C Bindings.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  18. {18} P. Zimmermann et al. (1993) PGP. Phil Zimmermann .]]Google ScholarGoogle Scholar

Index Terms

  1. Towards web security using PLASMA

                Recommendations

                Comments

                Login options

                Check if you have access through your login credentials or your institution to get full access on this article.

                Sign in
                • Article Metrics

                  • Downloads (Last 12 months)0
                  • Downloads (Last 6 weeks)0

                  Other Metrics