Achieving non-repudiation of Web based transactions

Citation
M. Kalla et al., Achieving non-repudiation of Web based transactions, J SYST SOFT, 48(3), 1999, pp. 165-175
Citations number
20
Categorie Soggetti
Computer Science & Engineering
Journal title
JOURNAL OF SYSTEMS AND SOFTWARE
ISSN journal
01641212 → ACNP
Volume
48
Issue
3
Year of publication
1999
Pages
165 - 175
Database
ISI
SICI code
0164-1212(19991101)48:3<165:ANOWBT>2.0.ZU;2-Q
Abstract
In this paper, we describe our approach to achieve non-repudiation for Worl d Wide Web (WWW) based transactions. We designed and implemented protocols for preparing digital signatures on the server as well as the client machin e. In our design, we use the popular Pretty Good Privacy (PGP) software for preparing and verifying digital signatures. The key-contribution is the de ployment of a special purpose HTTP server, called signing server, on the cl ient machine to communicate with the WWW browser. A signing server is speci alized to handle digital signatures. This paper discusses the design and im plementation of the signing server protocol to achieve non-repudiation tran sactions in a WWW based employee information system. The technique of deplo ying special purpose HTTP servers on the client machine has many applicatio ns beyond this. It inter-operates with all types of browsers and is an attr active alternative to browser dependent plug-ins. (C) 1999 Elsevier Science Inc. All rights reserved.